Trust & data
How to trust a finding — and what we do with your data
A finding is only useful if you can check it. billoquy is built so you can: every dollar traces to a public record, we are plain about what we can and cannot check yet, and nothing acts on your behalf without your approval.
Findings cite the record
Each check reads one kind of bill against one public record — the utility tariff database or CFPB fee guidance. A completed finding carries its citations: for each one, a label, the source, and — where the source is a public URL — a link. You can open the record and check the work yourself, or hand the citation to someone who will.
The checks page lists the exact record each check cites, and the MCP returns those citations on every finding, so an assistant relays the source alongside the number.
Honest about coverage
We would rather say "not yet" than invent a number
billoquy's checks read real public records, and we are building out the data pipelines behind them region by region. Where a check cannot run on your input yet — an area whose public data isn't loaded — it resolves to an honest "not yet available" — never a fabricated finding — and nothing is charged.
The same honesty runs through the API and the agent surface: an unavailable check returnsunsupported with the reason, and a check that could not complete reportsfailed plainly rather than guessing.
The approval firewall
billoquy prepares; you approve. Every prepared fix waits in your account until you release it, and that boundary is enforced at the layer that matters — the edge refuses to approve on anything but a human session. An AI assistant you connect can prepare, but can never approve, file, send, or pay. There is no send button you did not press.
How your data is handled
- Documents. Uploads are limited to PDFs and images and capped in size; anonymous uploads are rate-limited. When an assistant supplies a document by URL, that URL is fetched under strict guards (https only, a blocklist for private/loopback/metadata addresses, a content-type allowlist, and a byte cap) before it ever reaches storage.
- Sign-in. Authentication is passwordless — a one-time link to your email. Your email address is not written to our logs; only that a link was requested.
- Agent keys. A key an assistant uses is owner-scoped to your account, created by you, shown once, and revocable by you at any time. The agent surface holds no cloud credentials and no direct database access — it is a pure client of the same API the app uses, so it cannot slip past a guardrail.
- Traceability. Every request carries a correlation id through the system, so an issue can be traced end to end without exposing what you uploaded.
What we do with your documents — in one breath
Your bill is used for exactly one thing: running the check you asked for and preparing the fix you approve. It is never sold, never used for advertising, and never used to train AI models. An upload that never becomes a check is deleted automatically, and so is a check you ran without signing in — it and its document go after 30 days, because nothing ties them to you to delete on request. Everything in your account is kept until you ask — email help@billoquy.com and it's done. ThePrivacy Policy spells out every system your document touches and how long each thing is kept; the Terms of Service cover the rest.
What this is not
billoquy is decision support built on public records — not legal, tax, or financial advice. It compares your bills against the public record and prepares a fix. Nothing is ever sent on its own: an artifact waits in your account until you approve it. When you approve it, it comes back to you — the prepared letter, plus the provider's intake desk and the address, form or number we verified for it, so you know exactly where to send it. You are the one who sends it, always. We surface the sources and the math so that the decision, and the approval, stay yours.