BillerAPI Privacy Policy
How we collect, use, and protect information when you use our platform. Last updated: April 2, 2026.
What we collect from customers
Account information (name, email, organization), API keys and client secrets for authentication, billing information processed via Stripe, usage metrics for metering and invoicing, and support communications.
What we process for end users
We process end user data on behalf of our customers as a data processor. Depending on the integration, this can include email addresses, biller portal credentials, bill data, bill documents, and payment information. Credential-protection controls and their integration-specific scope are described on the Security page. We access end user data through customer and consumer-authorized product flows.
How we use data
Customer data is used to provide the Service, process payments, communicate about updates, and prevent abuse. End user data is used solely to provide bill discovery, retrieval, and payment services. We do not use end user data for advertising, profiling, or any unrelated purpose. We do not sell or rent any personal information.
Third-party processors
The service uses third-party infrastructure, identity, AI-processing, and payment providers for applicable product workflows. The current DPA and an executed customer agreement, rather than this summary, identify the processors and commitments that apply to a customer.
Data retention
Customer account data is retained while the account is active and deleted within 30 days of closure. End user bill data follows customer-configured retention policies or is deleted on request. Biller credentials are deleted when connections are revoked. Usage logs are retained for 90 days. You can retrieve or delete end user data via our API at any time.
AI processing
We use Anthropic's Claude AI to extract structured data from bill documents. This processing is performed solely to provide the extraction service. Your data is not used to train AI models (per Anthropic's API data processing terms). Only bill content is processed — never credentials or payment information.
Security
The service uses AWS-managed storage-encryption capabilities, HTTPS for public API endpoints, service access controls, and operational monitoring at documented boundaries. Coverage varies by service, environment, and integration. This summary is not a certification or a guarantee that every data path uses the same control. See the Security page for current detail.
Your rights
Customers can access, export, or delete their data via the dashboard or API. End users should contact the customer application they use; customers can retrieve or delete end user data via our API. California residents have CCPA rights — we do not sell personal information. Contact privacy@billerapi.com to exercise any data rights.
Questions?
Contact privacy@billerapi.com for Data Processing Agreements, vendor assessments, or privacy questions. All data is processed in the United States (AWS us-east-1).