Legal

Privacy Policy

This Policy explains what information BillUtilityAI handles, why it is used, and the choices available to you.

Effective October 7, 2026

1. Scope

This Privacy Policy applies to BillUtilityAI’s website, account system, personal-finance tools, AI features, and related support communications. It does not replace the privacy terms of independent third-party services you choose to use.

2. Information we handle

Account information may include your name, email address, preferred currency, a hashed password for password-based accounts, and account-provider details needed for Google Sign-In. BillUtilityAI does not store your plain-text password.

Financial information may include income and expense transactions, amounts, dates, optional descriptions, category names, budgets, currency, calculations, and recent history. Profile and preference information may include a profile image, selected theme, palette colors, and notification state.

AI-related records may include generated summaries or savings tips, generation type, timestamps, usage counts, cached results, category totals, transaction counts, budget status, and trend information used to create a requested analysis.

Technical and browser information may include an authentication token in local storage, temporary OAuth state and nonce values in session storage, request metadata, error details, and basic security or rate-limit records. If you contact us, we also handle the contents of that communication.

3. How information is used

We use information to create and secure accounts, authenticate sessions, display and calculate your financial records, synchronize your profile across devices, apply appearance preferences, maintain recent activity history, generate requested AI insights, enforce usage limits, troubleshoot errors, and improve service reliability.

We may also use information to respond to support, privacy, or security requests and to meet obligations that apply to operating the service.

4. Browser storage and cookies

BillUtilityAI uses browser local storage for the authentication token, theme preferences, and limited notification state. Session storage may hold temporary Google OAuth state, nonce, sign-in mode, and currency values during authentication. Clearing browser data or signing out can remove some of these values.

Google Sign-In or other external services may use cookies or comparable technologies under their own policies. BillUtilityAI does not currently operate a first-party behavioral advertising or cross-site tracking system.

5. AI processing

When you request an AI insight, BillUtilityAI may send selected financial aggregates to the Google Gemini API. Depending on the feature, those inputs can include currency, income and expense totals, category names and totals, transaction counts, budget usage, and prior trend information. Passwords and profile-image bytes are not intentionally included in AI prompts.

Google handles API data under its own terms and privacy materials. Those practices can depend on the service configuration and plan, so you should review the current provider documents instead of assuming a single retention or training rule applies in every case.

6. Sharing and disclosure

BillUtilityAI may disclose information to infrastructure, database, authentication, and AI service providers only as reasonably needed for them to perform services. Information may also be disclosed to address security incidents, protect people or the service, comply with a valid requirement, or support a business transition with appropriate safeguards.

BillUtilityAI does not sell your personal information and does not share it for cross-context behavioral advertising. Financial records are not made public through the normal service.

7. Retention

Transaction, category, and budget history shown by the history feature is designed to retain the current month and the previous two months—a total window of three calendar months. The underlying current financial records remain while your account needs them or until you change or delete them.

A saved profile image remains with your account until it is replaced or the related account data is deleted. AI outputs, usage records, cached analyses, security records, and support messages may be kept for as long as reasonably needed for their stated purpose. When an in-app account deletion request is submitted, access is disabled immediately and the account is scheduled for permanent deletion 72 hours later; automated cleanup removes accounts after the scheduled time has passed. Authentication values in browser storage remain until they expire, are replaced, you sign out, or browser data is cleared.

Deletion from active systems may not remove data immediately from backups or provider systems; residual copies can remain for a limited operational period before routine deletion or overwrite.

8. Your choices and requests

You can update many transactions, categories, budgets, profile details, profile images, and appearance settings within the service. You may sign out to remove the active authentication token from local storage. If you use the in-app account controls to request deletion, access is disabled immediately and deletion is scheduled for 72 hours later. The deletion request cannot be cancelled through the service, and the account cannot be recovered after submission.

Depending on the rights available to you, you may ask to access, correct, export, restrict, object to, or delete personal information. Send a request to the contact address below. We may need to verify your identity, and some requests may be limited where retention or processing remains necessary.

9. Security

BillUtilityAI uses measures such as password hashing, authenticated requests, input validation, file-type and size checks for profile images, security headers, access controls, rate limits, and restricted cross-origin access where configured.

No storage or transmission method is completely secure. Protect your account credentials and device, and contact us if you suspect unauthorized access.

10. International processing and age

The service and its providers may process information in locations other than where you live. Privacy protections and access rules can differ between locations, and reasonable safeguards are used where required.

BillUtilityAI is intended for people who are at least 18 years old. We do not knowingly seek personal information from anyone under 18 years of age. If you believe such information was provided, contact us so it can be reviewed and addressed.

11. Changes and contact

We may update this Privacy Policy as BillUtilityAI, its providers, or applicable requirements change. The effective date above identifies the current version. For material changes, we will use a reasonable notice method within the service or through available contact information.

This Policy is written without selecting a particular forum or location for privacy requests. Available non-waivable rights remain in place. Questions or privacy requests may be sent to the contact address below.