BIMA

Privacy Policy

Last updated: 17 September 2026

This document is a working draft provided for transparency. It should be reviewed by qualified legal counsel before it is relied upon.

This policy explains how BIMA — Book Ideas, Management & Assistance (“BIMA”, “we”) handles personal data when you use bima.my and the BIMA application. We are based in Malaysia and process personal data in accordance with the Personal Data Protection Act 2010 (PDPA). Wherever you live, we also extend the core rights described in the EU General Data Protection Regulation (GDPR) to all users.

The short version

  • Your manuscripts and notes are yours. They are private unless you share them.
  • We do not sell personal data, and we do not use your writing to train AI models.
  • Your book is sent to our AI provider only when you run an assistant action.
  • You can export your work and delete your account at any time.

1. What we collect

Account information

Your name, email address, password (stored only as a secure hash), profile details you add, timezone, language, plan, and notification preferences.

Your content

Books, chapters, snapshots, beats, story-bible entries, ideas, comments and files you create or upload.

Security and usage data

Sign-in times, IP address and browser/device information for active sessions; an audit record of security-relevant actions (such as sign-ins, invitations and role changes); counts of assistant credits used; and email delivery logs. We use this to keep accounts secure, enforce plan limits and support you.

Payment information

If you subscribe, Stripe collects your payment details. We receive only limited information such as the plan, billing status and the last digits of your card.

Messages to us

Anything you send through the contact form or by email.

2. How we use it

  • To provide the Service: saving your work, syncing it across devices, generating exports and running assistant requests you initiate.
  • To secure accounts: verifying email addresses, sending sign-in alerts, detecting abuse and investigating incidents.
  • To communicate: service and billing emails, invitations, and — only if you have not opted out — occasional product news.
  • To operate the business: billing, support, and aggregate, non-content metrics about how the Service is used.
  • To comply with legal obligations.

We rely on the performance of our contract with you, our legitimate interests in running a secure service, your consent where we ask for it, and legal obligations.

3. The writing assistant

When you use an assistant action (for example continue, rewrite, critique or a continuity check), we send the request together with the relevant context from your book — such as the current chapter, earlier chapters and story-bible entries — to Anthropic's Claude API to generate the response. The assistant does not run in the background. Anthropic acts as our service provider and does not use this data to train its models under our commercial terms.

4. Who we share data with

We share personal data only with service providers that help us run BIMA, under contracts that limit their use of it:

ProviderPurposeWhen
Cloudflare, Inc. (R2)Storage of uploaded files: covers, research material, images and generated exports, in a private bucket.When you upload or export a file
Anthropic PBC (Claude)Generating writing-assistant responses from the parts of your book needed for the request.Only when you invoke an assistant action
Our SMTP email providerDelivering account emails: verification, password resets, sign-in alerts, invitations and receipts.When an email is sent to you
Stripe, Inc.Processing subscription payments and storing payment card details.When you subscribe to a paid plan
Our hosting providerRunning the application servers and PostgreSQL database that store your account and manuscript text.Always, to provide the Service

We also share data with people you choose — collaborators, team members and anyone holding a beta-reader link you create — and with authorities where required by law. Some providers process data outside Malaysia; where they do, we take steps required by the PDPA to ensure it remains protected.

5. Storage and security

Data is encrypted in transit (HTTPS). Uploaded files are held in a private Cloudflare R2 bucket and are only reachable through short-lived signed links issued to authorised users. Passwords are hashed, two-factor authentication is available, sessions can be reviewed and revoked in Settings, and access to production systems is restricted to authorised staff. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as the law requires.

6. How long we keep it

  • Account data and Your Content: for as long as your account is active.
  • After you delete your account: removed from the live service promptly, and from backups on our normal rotation.
  • Security, audit and email logs: kept for a limited period for security and troubleshooting.
  • Billing records: kept for as long as tax and accounting laws require.

7. Your rights

Under the PDPA — and, as a matter of policy, the GDPR-style rights we extend to everyone — you can:

  • Access the personal data we hold about you and obtain a copy;
  • Correct inaccurate or incomplete data;
  • Delete your account and data;
  • Export your manuscripts in open formats (portability);
  • Object to or limit certain processing, and withdraw consent (for example to product emails or sign-in alerts);
  • Complain to the Personal Data Protection Commissioner of Malaysia or your local data-protection authority.

Most of this can be done directly in your account settings. For anything else, contact privacy@bima.my. We may need to verify your identity before acting on a request.

8. Cookies

We use strictly necessary cookies to keep you signed in, to remember your language and to protect forms, and local storage to remember preferences such as light or dark mode. We do not use advertising cookies.

9. Children

The Service is not directed at children under 13, and we do not knowingly collect their personal data.

10. Changes

We will post updates to this policy here with a new “last updated” date, and notify you of material changes by email or in the app.

11. Contact

Privacy questions or requests: privacy@bima.my, or use our contact form.