legal · privacy policy
Privacy Policy
Effective date: [EFFECTIVE DATE — set when adopted, after attorney review]
Draft — for attorney review
This document is a working draft. It has not been reviewed or approved by a licensed attorney, it is not legal advice, and it is not yet in effect. It will be adopted only after that review.
Draft — for attorney review. This document is a working draft prepared for review by a licensed attorney. It has not been reviewed by a lawyer, it is not legal advice, and it is not yet in effect. Bracketed items like
[ENTITY NAME]are placeholders the owner must fill before adoption.
The short version (plain language; the sections below control). To run a check we need your bill and a few details — sometimes sensitive ones, like a bank statement or a utility bill. We use them for exactly one thing: running the check you asked for and preparing the fix you approve. We never sell your data, never use it for advertising, and never use it to train AI models. Your documents are processed by a short, named list of infrastructure providers (AWS, Cloudflare, Stripe). Uploads that never become a check are deleted automatically, and so is a check you ran without signing in — it and its document go after 30 days. Anything in your account stays until you ask us to delete it, at any time, by emailing help@billoquy.com.
1. Who we are and what this policy covers
This Privacy Policy describes how [ENTITY NAME] (“billoquy,” “we,” “us”) handles personal
information when you use billoquy.com, app.billoquy.com, api.billoquy.com, and mcp.billoquy.com
(the “Service”). It is part of our Terms of Service. billoquy is a U.S. service for
people in the United States.
2. What we collect
We collect only what the Service needs to do its job:
- Documents you upload. Utility bills and bank or card statements — as a PDF or a photo. These can contain personal information: your name, address, account numbers, and charges and transactions (financial information).
- Details you type. What a check asks for — for example your ZIP code or your utility’s name.
- Your email address, if you sign in (sign-in is a one-time emailed link — we never have a password), set a one-time alarm on a finding in your account, or write to us.
- Payment information. Payments are processed by Stripe. We receive the payment’s status and a customer reference; we never see or store your full card number.
- Technical and usage data. IP addresses (used to rate-limit anonymous uploads and for the human-verification challenge), request logs, and a correlation ID that lets us trace a request through the system. Our logs are deliberately built not to contain your email address or the contents of your documents.
- From a connected AI assistant. If you connect an assistant via an agent key, we receive the same categories above when it starts checks for you (for example, a document it supplies by URL, which we fetch under strict safety guards).
We do not collect advertising identifiers, run third-party ad trackers, or buy data about you from data brokers.
3. How we use it
- To run your checks: parsing your uploaded document with an AI model, reading it against the relevant public record, and producing your finding.
- To prepare and deliver a fix you paid for and approved, and to email it to you.
- To operate your account: sign-in links, the follow-up that asks whether a fix landed, and the one-time alarm email you asked for on a finding.
- To keep the Service safe: rate limiting, abuse prevention, human verification of anonymous checks, and debugging via redacted logs.
- To meet legal obligations, such as keeping required payment and tax records.
What we do not do: we do not sell or rent your personal information; we do not share it for advertising; we do not use your documents or findings to train AI models; and we do not send anything you prepared to a utility or bank — a prepared fix is delivered to you, and you decide whether to send it.
4. AI processing of your documents
When a check needs to read a document, the document is sent to Amazon Bedrock (an AWS service) to be parsed by an AI model, and the model’s output becomes part of your finding. This processing is under our service agreements with AWS; per AWS’s published commitments for Bedrock, customer content is not used to train the underlying models. We do not use your documents, findings, or prepared fixes to train models of our own. AI parsing can make mistakes — which is one reason every finding cites the public record it read, and every prepared fix waits for your review.
5. Who processes your data
We use a small, fixed set of infrastructure providers (“sub-processors”) to run the Service:
| Provider | What it does with your data |
|---|---|
| Amazon Web Services | Runs the whole Service. Hosts the sites and the API, stores your uploaded documents (S3), parses them and drafts fixes (Bedrock), stores your checks, findings, fixes, and receipts (DynamoDB), runs the background workers (Lambda/SQS), and carries our email in both directions — the sign-in link, the fix we deliver to you, the follow-up and alarm notices, and our replies to a bill you forward, plus receiving and storing the mail you send to a billoquy address (SES). |
| Cloudflare | Provides the human-verification challenge on anonymous checks and sign-in (Turnstile) — nothing else. It sees the challenge, not your documents, your checks, or your email address. |
| Stripe | Processes payments. Stripe handles your card details under its own privacy policy; we receive status and a customer reference. |
| Google Fonts | The marketing site loads its typefaces from Google Fonts, which means your browser sends your IP address to Google when the page loads. No other Google service is used. |
Beyond those providers, we disclose personal information only: (a) at your direction; (b) to comply with law or valid legal process; (c) to protect the Service, our users, or others from fraud or abuse; or (d) as part of a merger, acquisition, or sale of the business — in which case this policy continues to apply and we will notify you of any change in ownership. If you connect an AI assistant, whatever the Service returns to it (your findings, fix previews) is then in that assistant’s hands, under its provider’s terms — connect only assistants you trust.
Email is ordinary email: a fix delivered to your inbox travels over standard email infrastructure, which is not end-to-end encrypted.
6. How long we keep things
| Data | How long |
|---|---|
| Uploaded document that never becomes a check (abandoned upload) | Deleted automatically by a storage lifecycle rule after 30 days, with the last copy removed within 7 days after that — you don’t have to ask, and we don’t have to remember. |
| A check you ran without signing in, and the document it used | Deleted automatically after 30 days, both halves together. It is attached to no account, so we cannot look it up for you and you cannot ask us to delete it sooner. Signing in and claiming the check is what makes it yours — and what keeps it. |
| Uploaded document attached to a check in your account | Kept while the check is in your account, so your finding stays traceable to its source; deleted on your deletion request or account deletion. |
| Checks, findings, prepared fixes, receipts in your account | Kept while your account is active — they are your record; deleted on request. |
| Bill you forward to energy@billoquy.com or fees@billoquy.com (the raw message) | Kept 7 days in a separate store, then deleted automatically. The bill inside it becomes an uploaded document and follows the rows above. |
| Mail you send to help@billoquy.com (the raw message) | Kept 90 days in a separate store, then deleted automatically, and forwarded to the inbox a person reads so we can answer you. |
| Sign-in links | Expire after 15 minutes. |
| Signed-in sessions | Expire after 30 days. |
| Agent keys | Expire after at most 1 year, or immediately when you revoke them. |
| Anonymous rate-limit counters (IP-keyed) | Expire within minutes. |
| Payment records | Kept as required for accounting, tax, and legal obligations (held with Stripe and in our records). |
7. Deleting your data
Email help@billoquy.com from the address on your account and ask. We will delete your account, your uploaded documents, and your checks, findings, fixes, and receipts, and confirm when it is done — keeping only what the law requires us to keep (chiefly payment and transaction records) and minimal records of the deletion request itself. We may need to verify the request came from you, which we do via your email address (the same way sign-in works).
If you ran a check without signing in, there is no account for us to look it up under and no address to check a request against — so this route does not reach it, and we do not ask you to rely on one that cannot. That check and its document are deleted automatically after 30 days instead. If you want it kept, sign in and claim it; from then on it is yours and the paragraph above applies to it.
8. How we protect it
- Everything moves over TLS (HTTPS), and uploads are restricted by type and size.
- No passwords exist to steal — sign-in is a one-time emailed link.
- The edge and the data plane are connected by a single least-privilege credential that can only do the narrow things the Service needs; the agent surface holds no cloud credentials and no direct database access.
- Logs carry correlation IDs, never your email address or document contents.
- Documents supplied by URL (from a connected assistant) are fetched under strict guards — HTTPS only, private-network addresses blocked, content-type allowlist, and a size cap — before they ever reach storage.
- Approval of a prepared fix is structurally restricted to a signed-in human — an agent key cannot do it.
No service can promise perfect security, but the Service is built so that the sensitive path — your documents — touches the fewest possible systems, each doing one job.
9. Your rights and choices
Whoever you are, you can: access what we hold about you, correct it, delete it (Section 7), and opt out of non-essential email. Write to help@billoquy.com to exercise any of these; we will respond within the time applicable law requires (and in any case within 45 days).
California residents (CCPA/CPRA). We adopt the CCPA/CPRA’s baseline whether or not its business thresholds currently apply to us: we do not sell your personal information and do not share it for cross-context behavioral advertising, so there is no sale/share to opt out of. We use sensitive personal information (Section 10) only to provide the Service you asked for. You have the rights to know, access, correct, delete, and to not be discriminated against for exercising them. You may use an authorized agent to submit a request; we will verify the request through your account email.
If you are in the EEA/UK. The Service is directed to the United States, but if GDPR-style rights apply to you we honor the equivalents: access, rectification, erasure, restriction, portability, and objection, with processing grounded in performing our contract with you (running your checks) and our legitimate interest in keeping the Service secure.
We do not currently respond to browser “Do Not Track” signals — there is no cross-site tracking
here for them to control. [ATTORNEY CHECK: whether Global Privacy Control handling must be stated differently given the no-sale/no-share posture.]
10. Sensitive information
Some checks only work if you hand us sensitive things: a bank or card statement with your account numbers and transactions. Our posture is strict and simple:
- It is used only to run the check you started and prepare the fix you approve — never for advertising, profiling unrelated to your check, or sale.
- billoquy is a consumer tool you use with your own records: utility and bank-fee
bills. It is a financial-document tool, not a health service — we do not collect health
information.
[ATTORNEY CONFIRM: financial-data handling posture (e.g., GLBA applicability to a consumer bill-analysis tool) and any state consumer-financial-data obligations.] - You can delete anything in your account at any time (Section 7), and a check you ran without signing in deletes itself after 30 days.
11. Children
The Service is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, email help@billoquy.com and we will delete it.
12. Where your data lives
The Service runs in the United States (AWS and Cloudflare infrastructure), and your information is stored and processed there.
13. Changes to this policy
If we change this policy, we will post the new version here with a new effective date, and — if the change is material, such as a new sub-processor category or a new use of your data — notify account holders by email or a prominent notice before it takes effect. We will never retroactively weaken the “never sold, never used to train models” commitments for data you already gave us without your consent.
14. Contact
[ENTITY NAME]
[POSTAL ADDRESS — required for privacy notices]
help@billoquy.com [owner: consider a dedicated privacy@billoquy.com alias]