Privacy Policy
Last Updated: June 28, 2026
Billr ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Billr mobile application ("App") available on Apple App Store and Google Play, and our associated website at biller.online.
1. Information We Collect
1.1 Account & Profile Information
- Registration Data: Name, business name, and email address collected when you create an account via Supabase Authentication (email/password or magic link OTP).
- Business Profile: Company name, logo, address, phone number, tax number, payment handles (Venmo, PayPal, Cash App, Zelle, bank details), invoice prefix, and default tax/discount settings you configure voluntarily.
1.2 Financial & Invoicing Data
- Invoice records, quote/estimate documents, purchase orders, client contact information, expense logs, and product/service catalog entries stored to provide core App functionality.
- We do not store, process, or have access to your credit card numbers, bank account credentials, or any payment card information. All subscription billing is processed exclusively by Apple (App Store) and Google (Play Store) via RevenueCat.
1.3 Camera & Photo Library Access
- Camera: Used to scan product barcodes and QR codes on the Products & Services screen. Camera access is requested only when you tap the scan button. We do not store, transmit, or record any video or image from your camera.
- Photo Library: Used to upload your business logo to your profile. Images are stored in your private Supabase Storage bucket, accessible only to your authenticated account.
1.4 Microphone & Voice Invoicing
- The optional Voice Invoice feature records a short audio clip via your device microphone when explicitly activated by you. Audio is transmitted over an encrypted HTTPS connection to our transcription endpoint, parsed into invoice fields, and immediately deleted upon transcription completion. We do not retain, sell, or share audio recordings.
1.5 Subscription & Purchase Data
- Subscription status (active, trial, expired) and entitlement data are managed by RevenueCat. We receive anonymised purchase validation tokens and subscription state — never your payment card details. See RevenueCat's Privacy Policy.
1.6 Usage & Diagnostic Data
- We may collect anonymised crash logs and performance diagnostics to improve App stability. This data does not include personally identifiable information.
2. App Tracking Transparency (iOS)
Billr does not use the Apple Advertising Identifier (IDFA) or any third-party advertising SDKs. We do not track you across apps and websites owned by other companies. You will not be presented with an App Tracking Transparency (ATT) prompt because Billr does not engage in cross-app tracking.
3. How We Use Your Information
- To create and maintain your account and authenticate your sessions.
- To generate, store, and export invoices, estimates, expenses, and business documents.
- To send automated payment reminder emails to your clients via Resend (see Section 5).
- To validate and manage your subscription entitlements via RevenueCat.
- To provide technical support and respond to inquiries.
- To improve App performance through anonymised crash diagnostics.
- We do not sell, rent, or share your personal data with advertisers or data brokers.
4. Data Storage & Security
- Database: All user data is stored in Supabase (PostgreSQL) with Row-Level Security (RLS) enforced at the database level. Your data is cryptographically isolated and can only be accessed using your unique authenticated session token.
- Device Storage: Session tokens and user preferences are stored in your device's secure local storage. Logging out purges all cached data, logos, and signatures from your device.
- Data Transmission: All network communications between the App and our servers use TLS 1.2+ encryption.
- File Storage: Business logos and e-signatures are stored in private Supabase Storage buckets, inaccessible without authentication.
5. Email Communications & Anti-Spam Compliance
- Payment Reminder Emails: Automated invoice payment reminders are sent to your clients using the Resend API from the domain reminders@biller.online. These emails are sent on your behalf as the business operator.
- Opt-Out: Every automated reminder email sent to your clients includes clear unsubscribe/opt-out instructions. You can also disable automated reminder sweeps at any time from your Settings panel.
- CAN-SPAM / CASL / GDPR Compliance: Reminder emails include the sender's business name, a valid reply-to address routed to your configured business email, and opt-out instructions, complying with US CAN-SPAM, Canadian CASL, and EU GDPR requirements.
6. Third-Party Services
- Supabase (database, auth, storage) — Privacy Policy
- RevenueCat (subscription management) — Privacy Policy
- Resend (transactional email) — Privacy Policy
- Expo / React Native (app framework) — Privacy Policy
7. Your Rights
7.1 Access, Correction & Portability
You can view, edit, and export all your data directly within the App. Invoice and client data can be exported as PDF or shared via standard OS share sheets.
7.2 Right to Erasure (GDPR / CCPA / App Store)
You can permanently delete your account at any time via Settings → Delete Account inside the App, or by submitting a request on our Data Deletion Request page. Initiating deletion triggers an immediate cascade that permanently removes your authentication credentials, profile, invoices, clients, expenses, logo uploads, and signatures from all databases and storage buckets. This action is irreversible.
7.3 California Residents (CCPA)
California residents have the right to know what personal data we collect, the right to delete it, and the right to opt out of the "sale" of personal information. Billr does not sell personal information. To exercise your rights, contact support@biller.online.
7.4 EEA / UK Residents (GDPR)
If you are located in the European Economic Area or United Kingdom, you have rights to access, rectification, erasure, restriction, portability, and to object to processing. Our lawful basis for processing is contract performance (to provide the App) and legitimate interest (security, fraud prevention). Contact us to exercise these rights.
8. Data Retention
We retain your data for as long as your account is active. Upon account deletion, all personal data is purged within 24 hours from active databases and within 30 days from encrypted backup systems.
9. Children's Privacy (COPPA)
Billr is a professional invoicing tool intended solely for adults aged 18 and over. We do not knowingly collect personal information from children under 13 years of age (or under 16 in the EU/UK). If we become aware that we have collected data from a child, we will delete it immediately.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will notify you of material changes by updating the "Last Updated" date and, where required by law, by providing additional notice within the App.
11. Contact Us
For privacy questions, data requests, or concerns:
- Email: support@biller.online
- Data Deletion: biller.online/delete-account.html
- Website: biller.online