We don't sell your data. Ever.
Billy tracks your subscriptions — intimate data, and we treat it that way. The full promise + binding terms, in plain English.
A promise with teeth.
01 · pledge- Free forever, with no paid tier and no trial trap — optional tips from people who love the app are the whole business model, and the product is identical whether you tip or not.
- End-to-end encrypted sync means we genuinely can't read your subscription list, even if a court orders us to hand it over.
- The clients are open source under AGPL-3.0, so anyone can audit exactly what we're shipping to your device.
- One tap exports everything, one tap deletes everything — account, backups, the lot, gone within 24 hours.
- We publish a quarterly transparency report covering government requests, legal orders, and security incidents (so far: zero of each).
Encrypted everywhere.
02 · storageYour subscription list is encrypted on your device with a key derived from your passphrase, before it leaves the app. We sync only the ciphertext.
Servers: Hetzner, Frankfurt. Backups: separate rotating key, 14-day retention. No data leaves the EU.
The smallest possible footprint.
03 · what we collect| Data | Why | Visible to us? |
|---|---|---|
| Email address | Sign-in and optional renewal reminders. | yes |
| Subscription list | The whole product. E2E encrypted; key is yours. | no · encrypted |
| Bank / receipt data (optional) | Detect recurring charges. Read-only, on-device. | no · on-device |
| Crash logs | Fix bugs. Stripped of IDs; opt-out in Settings. | anonymised |
| Sign-in IP | Fraud / ATO detection. Auto-deleted after 30 days. | yes · 30d |
Off-limits.
04 · never collected- No advertising cookies or cross-site tracking of any kind.
- No device fingerprints, advertising IDs, or probabilistic matching.
- No location data — not coarse, not precise, not inferred from IP.
- No access to your contacts, photos, camera, or microphone.
- No bank passwords stored anywhere — we use read-only tokens that you can revoke at any time.
- No raw receipt emails kept on our servers — they're parsed on your device and discarded.
You own the data.
05 · your rights- Access everything we hold about you as a full JSON export, generated on demand from Settings → Privacy.
- Correct anything that's wrong — every field is editable in the app and syncs across your devices instantly.
- Delete your account in a single tap, which wipes it from our servers and backups within 24 hours.
- Take your data elsewhere in open, documented formats (JSON and CSV) that work with any spreadsheet or competing app.
- Turn off diagnostics, reminders, or any other processing at any time, from the same Privacy screen.
- Never be profiled or subjected to automated decisions — we don't build behavioural models and we don't score you.
A very short list.
06 · third parties| Hetzner | Hosting (EU) | ciphertext only |
| Plaid / Tink | Optional bank link | not stored |
| Postmark | Transactional email | email only |
| Stripe | Optional tips | tippers only |
No Google, Meta, advertising, analytics, or session-replay vendors. Ever.
Terms of use — the short, fair contract.
07 · termsThe short version: Billy is free, we try hard to keep it running, please don't do anything illegal or abusive with it, and if we break something we'll own up and fix it.
- You keep ownership of your data. We take no licence to it beyond what's technically required to sync it between your own devices.
- Use the app for yourself — one account per person, and if you want to show a household your subs, use the in-app share view rather than handing over your credentials.
- Don't attack the service: no scraping, no reverse-engineering for harm, no automated signup abuse, and no illegal content on accounts we host.
- You can leave whenever you want, with a one-tap export followed by a one-tap delete, and we won't email you asking why.
- The service is provided “as is” with no warranty — we aim for 99.9% uptime, but please keep your own exports as a backup.
- Our liability is capped at what you've paid us, which for a free product means zero. Consumer-protection law in your country still applies on top.
- Accounts that attack the service or abuse other users can be closed, and we'll email you first whenever it's safe to do so.
- Governing law is Ireland, but this doesn't override mandatory consumer rights where you live.
No quiet updates.
08 · changes & contactAny change that reduces your rights gets 30 days of notice by email and an in-app banner before it takes effect; smaller editorial tweaks are logged in the public changelog so you can see every revision we've ever made.
© 2026 Voco, LLC.