LegalPrivacy Policy
Last updated: February 2026
1. Introduction
Welcome to Billy ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our mobile application and website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
2.1 Mobile App
Information You Provide:
- Expense and subscription data you enter into the mobile app (stored locally on your device, and synced to the cloud if you sign in)
- Category preferences and custom categories you create
- Settings and preferences (currency, notifications, theme)
- Photos/images you capture or select for receipt scanning (stored locally on your device, and uploaded to Firebase Storage if you sign in)
- Support communications and feedback submitted through the app
Account Information (Optional):
- Google account information (name, email address, profile picture) when you choose to sign in with Google
- User profile data stored in Firebase Firestore
Household Sharing Data:
- If you create or join a household, your subscription and expense data is shared with the other household member
- Receipt photos attached to shared expenses are accessible to both household members
- Household membership information (who is in the household, roles, and permissions)
Automatically Collected Information:
- Device information (model, operating system, Android version, unique device identifiers)
- App usage data (features used, time spent in app, crash reports for debugging)
- Analytics data (collected through Firebase Analytics or similar services to improve app performance)
Permissions:
- Camera: Used only when you choose to capture photos of receipts
- Photo/Media Access: Used only when you choose to select existing photos for receipts
- Notifications: Used to send billing reminders, payment notifications, and household activity alerts (can be disabled in settings)
2.2 Website
Information You Provide:
- Email address when joining our waitlist
- Name, email, and message when using the contact form
- Comments or feedback submitted through the website
- Expense data entered in the import tool (stored only in your browser's localStorage, never sent to our servers)
Automatically Collected Information:
- Browser information (type, version, language)
- Device information (when accessing the website from a mobile device)
- Usage data (pages visited, time spent, click patterns)
- Analytics data (collected through Google Analytics - see our Cookie Policy for details)
- IP address and general location data
3. How We Use Your Information
3.1 Mobile App
We use information collected through the mobile app to:
- Provide core functionality (storing and managing your expense and subscription data)
- Sync your data across devices and with household members when you sign in
- Send billing reminders and payment notifications (if enabled in settings)
- Send push notifications about changes made by your household member (if applicable)
- Generate analytics and spending insights based on your data
- Improve app performance and fix bugs through crash reporting
- Respond to support requests and feedback
- Understand usage patterns to enhance features and user experience
Important: Your financial data (subscriptions, expenses, categories) is stored locally on your device using Room Database. If you sign in with Google, your data is also synced to Firebase Firestore (cloud database) to enable backup and household sharing features. If you use household sharing, your shared financial data and receipt photos become accessible to the other member of your household.
3.2 Website
We use information collected through the website to:
- Send notifications when the mobile app launches (for waitlist subscribers)
- Respond to contact form inquiries and support requests
- Analyze website traffic and user behavior to improve content and user experience
- Provide blog content and RSS feed functionality
- Detect and prevent technical issues
3.3 Import Tool
The expense import tool on our website allows you to enter expense data and transfer it to the Billy mobile app via QR code or CSV file. Important:
- Expense data you enter is stored only in your browser's localStorage
- This data is never transmitted to or stored on our servers
- The data is used solely to generate a QR code or downloadable file for import into the Billy app
- You can clear this data anytime using the "Clear all" button
4. Data Storage and Security
4.1 Mobile App
Local Storage: Your expense and subscription data is stored locally on your device using Room Database (Android's local database).
Cloud Storage: If you sign in with Google, your data is also stored in Firebase Firestore (Google Cloud) to enable sync and backup. Receipt photos are stored in Firebase Storage (Google Cloud). Data is encrypted at rest (AES-256) and in transit (TLS/SSL) by Google's infrastructure.
Household Sharing: If you create or join a household, your shared subscription and expense data (including receipt photos) is stored in a shared cloud location accessible to both household members. The household owner controls member edit permissions.
Security: We implement the following security measures:
- Android's built-in security features for local data
- Google Sign-In (OAuth 2.0) for authentication
- Firebase Security Rules to restrict cloud data access to authorized users
- Encryption at rest and in transit for all cloud-stored data
- Secure file handling for exported data
- Android's permission system for camera and media access
- Secure backup rules (financial data is excluded from cloud backups by default)
Device Permissions: The mobile app requests permissions only when needed:
- Camera permission: Only requested when you choose to capture a receipt photo
- Photo/Media access: Only requested when you choose to select an existing photo
- Notifications: Requested to enable billing reminders and household activity alerts (can be disabled anytime in settings)
4.2 Website
Information collected through the website (waitlist emails, contact form submissions) is stored securely on our servers. We implement appropriate technical and organizational measures to protect this information, including encryption in transit (HTTPS) and secure storage practices.
However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information:
- With your household member: If you create or join a household, your shared subscription/expense data and receipt photos are visible to the other household member. You explicitly consent to this sharing when you create or accept a household invitation
- With service providers who assist us in operating our services (including Google/Firebase for cloud infrastructure)
- When required by law or to protect our rights
- In connection with a business transfer (merger, acquisition, etc.)
- With your consent or at your direction
6. Your Rights and Choices
6.1 Mobile App
You have full control over your data in the mobile app:
- Access: All your data is accessible within the app
- Delete: You can delete individual subscriptions, categories, or all data through the app's settings. Deleting data also removes it from the cloud if you are signed in
- Export: You can export your data to CSV/JSON format at any time
- Permissions: You can revoke camera, photo, or notification permissions anytime through Android settings
- Notifications: You can disable billing reminders and household alerts in the app settings
- Sign Out: You can sign out at any time to stop cloud sync. Your local data remains on your device
- Leave Household: You can leave a household at any time, which stops data sharing with the other member
- Uninstall: Uninstalling the app removes all local data (unless you've enabled Android backup). Cloud data persists until you delete your account
6.2 Website
You have the right to:
- Request access to your personal information (waitlist email, contact submissions)
- Request deletion of your information from our systems
- Opt-out of analytics tracking (see Cookie Policy)
- Unsubscribe from waitlist notifications (reply to any email or contact us)
- Request a copy of your data
7. Cookies and Tracking Technologies
Website: Our website uses cookies and similar tracking technologies (such as Google Analytics). For detailed information about what cookies we use and how to manage them, please see our Cookie Policy.
Mobile App: The mobile app does not use cookies. However, it may use similar technologies such as device identifiers and analytics SDKs (like Firebase Analytics) to understand app usage and improve functionality. This data is anonymized and aggregated.
8. Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.