Effective Date: March 28, 2026
Last Updated: 2026-06-23
• Email address (required for account creation)
• Password (stored in encrypted form — we never see your plain-text password)
• Display name or username (if provided)
• Bill amounts, item names, and expense records you enter
• Bill-splitting records and assignments between people
• Recurring bill information (amounts, due dates, categories)
• Payment method preferences
• Receipt images you choose to scan (processed temporarily, not stored permanently)
• Text extracted from receipts via AI processing
• Device type and operating system (for app compatibility)
• App usage patterns and crash reports (for improvement purposes)
• Session tokens for authentication (stored securely on your device)
We use your personal data strictly for:
• Creating and managing your account
• Providing the bill-splitting and expense tracking features
• Displaying your financial records within the App
• Improving App performance and fixing bugs
• Sending service-related notifications (with your consent)
• Complying with legal obligations under Philippine law
We do NOT use your data for targeted advertising or sell it to third parties.
Our receipt scanning feature uses:
• Google Cloud Vision API — to extract text from receipt images
• Anthropic Claude AI — to structure extracted text into usable data
When you scan a receipt:
• Your receipt image is transmitted securely to Google's servers for text extraction
• Extracted text (NOT the image) is sent to Anthropic for structuring
• These third parties process your data under their own privacy policies
• We do not store receipt images permanently after processing
By using the scanning feature, you consent to this processing. You may use the App without scanning receipts if you prefer not to use these services.
Your data is stored using Supabase, a trusted cloud infrastructure provider with enterprise-grade security. Our security measures include:
• All data transmitted over HTTPS/TLS encryption
• Passwords hashed using industry-standard bcrypt encryption
• Row-Level Security (RLS) — you can only access your own data
• Regular security monitoring and vulnerability assessments
• Strict access controls — our team cannot read your financial data
No security system is 100% impenetrable. In the event of a data breach, we will notify affected users without undue delay, and within 72 hours where required by applicable law (including RA 10173 and, for EU/UK users, the GDPR).
Where the GDPR applies, we process your personal data on these legal bases:
• Performance of a contract — to create your account and provide the App's core bill-splitting features
• Consent — for optional features like receipt scanning, which you can decline and still use the App
• Legitimate interests — to maintain security, prevent fraud, and improve the App, balanced against your privacy rights
We DO NOT sell, rent, or share your personal data with third parties for advertising or marketing purposes, and we do not sell or share it as those terms are defined under the CCPA/CPRA. We share data only with:
• Service providers essential to operate the App (Supabase for hosting/database, Google Cloud Vision and Anthropic for receipt scanning) — each processes your data under their own standard data processing terms, which incorporate Standard Contractual Clauses or equivalent safeguards for any international transfer of your data
• Law enforcement or government authorities when required by applicable law or valid legal process
• Successors in the event of a merger or acquisition — you will be notified in advance
Bill-splitting data (who owes what) that you choose to share via the App's share function is shared at your own discretion.
Under the Data Privacy Act of 2012, you have the following rights:
• Right to be Informed — how your data is collected and used
• Right to Access — request a copy of your personal data
• Right to Rectification — correct inaccurate or outdated data
• Right to Erasure — request deletion of your personal data
• Right to Data Portability — receive your data in a readable format
• Right to Object — opt out of certain data processing activities
• Right to Lodge a Complaint — with the National Privacy Commission (NPC)
Self-service: you can instantly download a copy of your personal data at any time from Manage → Account → Export My Data, and permanently delete your account and data from Manage → Account → Delete Account. For any other request, or if you'd rather we handle it directly, contact us at privacy@billmo.app — we will respond within 15 business days.
We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion:
• Your personal information is deleted within 30 days
• Anonymized, aggregated data (with no personal identifiers) may be retained for analytics
• Data required by law to be retained will be kept for the legally required period
billmo is strictly intended for users aged 18 and above. We do not knowingly collect or process personal data from individuals under 18 years of age. If we discover that a minor has registered, we will immediately delete their account and associated data. If you believe a minor has registered, please contact us immediately at privacy@billmo.app.
The App uses local device storage (AsyncStorage) solely for:
• Maintaining your authenticated session so you stay logged in
• Storing app preferences locally on your device
We do not use third-party tracking cookies or behavioral analytics tools.
We will notify users of any material changes to this Privacy Policy through an in-app notification at least 14 days before changes take effect. Continued use of the App after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions, requests, or complaints:
Data Protection Officer (DPO)
Email: privacy@billmo.app
General Support: hello@billmo.app
You also have the right to file a complaint with the National Privacy Commission (NPC) of the Philippines at www.privacy.gov.ph if you believe your data privacy rights have been violated.
In addition to your rights in Section 6, you have the right to lodge a complaint with your local data protection supervisory authority. Your data may be transferred to and processed in the Philippines and the United States, where our service providers (Supabase, Google, Anthropic) operate; these transfers are covered by Standard Contractual Clauses or equivalent safeguards under each provider's standard terms. We do not currently have a dedicated EU or UK representative appointed under Article 27 GDPR / UK GDPR — for any GDPR-related request, contact privacy@billmo.app directly and we will respond within 30 days.
You have the right to know what personal information we collect, request its deletion, correct inaccuracies, and not be discriminated against for exercising these rights. We do not sell or share your personal information, so there is no "opt-out of sale" to exercise. To make a request, use the self-service tools in Section 6 or email privacy@billmo.app.