Privacy Policy

Last updated: 3 October, 2026


Welcome to Billpal 👋

Billpal e.U. ("we", "us") operates https://billpal.io (the "Service"). For full company details, see our Imprint. This policy explains what data we collect, why, who we share it with, and what rights you have.

The DPA applies when you use the Service. It is part of the Terms. Generate a PDF on that page if you need a copy for your file.

1. Who is responsible

Your workspace data. Invoices, receipts, mailbox captures, WhatsApp media, portal sessions, contacts, and similar records in a workspace are processed on your instructions. You (or, if you are an accountant putting client files in Billpal, your client) are the controller of that data. Billpal is the processor. The DPA is the processing contract.

If you use Billpal for your own company, you are the controller. If you are a CPA or similar advisor and your clients' documents live in your workspaces, you warrant you may instruct us to process that data. Your clients remain controllers of their own files unless you have another arrangement with them.

Our own data. For your Billpal login, billing, product emails, security, and visits to billpal.io, Billpal is the controller.

2. What we collect

  • Account information: name, email, language, profile photo, and the company details you enter for a workspace (legal name, VAT ID, domain, aliases, logo, chart of accounts).
  • Workspace members: emails and roles of people you invite.
  • Documents: invoices, receipts, credit notes, reminders, and other files you upload, we import from email or a portal, or you send on WhatsApp. We store the file and extracted fields (amounts, dates, line items, tax, supplier and customer details, payment references).
  • Contacts: suppliers and customers, including names, tax IDs, addresses, and similar fields from documents or imports (including DATEV-style CSV).
  • Email: we are not a mail client. Our email server in Germany syncs a copy of a connected mailbox until you disconnect. We look for invoices and receipts. We read a message when we need to tell if it is a billing document, or to save an invoice that arrived as a webpage. The app keeps the imported file plus IDs so we do not import the same document twice. Gmail and Microsoft use read-only OAuth. IMAP passwords are stored on that email host in Germany so sync can run. Forwarded messages arrive at docs.billpal.io; Cloudflare email forwarding sees those messages.
  • WhatsApp: if you connect WhatsApp, we store your phone number, recent messages for agent context, files you send, and transcript-only text from voice notes in our database (not the audio). WhatsApp on Billpal is document capture plus product FAQ. It does not look up your invoices or account data.
  • Portals: you paste a vendor URL and sign in once in a browser on our portal server in Germany. We do not store your password. The session cookies stay on that server so capture can download PDFs later. The agent sees the pages needed to find invoices. Capture runs are screen-recorded so you can watch the replay. Sign-in is not recorded.
  • Support: tickets and attachments you send us.
  • Payment information: subscriptions are processed by Stripe. We do not see or store your full card number.
  • Technical data: hashed IP for rate limiting and security, browser and device information, and Cloudflare Turnstile on signup, login, and forgot-password.

3. How we use it

  • Provide the Service: capture, extract, categorize, contacts, rules, export, and workspace collaboration.
  • Decide whether a document is incoming or outgoing using the workspace company identity.
  • Process subscriptions and invoices we issue to you.
  • Send transactional email (verification, billing, security, support).
  • Send product updates about Billpal. We add trial accounts to that list. You can unsubscribe in those emails.
  • Fix bugs, keep the product running, and stop abuse.
  • Maintain security (rate limits, bot checks, abuse prevention).

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

4. AI processing

Document files and related capture content (email, WhatsApp, portal pages, and a supplier's public homepage) are sent to paid AI APIs so we can identify documents, extract fields, categorize, draft a short supplier summary, run portal capture, or answer a product question.

  • Documents, email, WhatsApp, categorization, supplier summaries, and the product FAQ run on Google Gemini through Vertex AI in the EU. Google may keep a prompt its safety systems flag for up to 90 days to check for abuse, stored in the EU. See the Google Cloud Data Processing Addendum.
  • Portal capture runs on OpenAI in the United States, Scaleway in France, and Google in the EU. For the transfer to the US we rely on Standard Contractual Clauses and the EU-US Data Privacy Framework.

Results are suggestions. You can review and override them. We may skip mail that is not a billing document.

We do not use your documents to train Billpal models. Google, OpenAI, and Scaleway do not train on this API data under their paid terms. Providers may keep data briefly to detect abuse.

5. Workspace processors

We do not sell your data. The providers below process workspace data on our instructions when you use those features. Links are to their privacy policy and, where they publish one, their DPA. The DPA authorizes this list only, not Billpal's own vendors in the next section.

We email account owners at least 14 days before adding or replacing a workspace processor. Object via support@billpal.io. If we cannot agree, we stop the affected feature or you can leave.

  • Vercel (app hosting, functions in Frankfurt). PrivacyDPA
  • Supabase (database, auth, file storage, in Ireland). PrivacyDPA
  • Hetzner (servers in Germany for email sync and portals). IMAP passwords and mailbox sync live on the email server until you disconnect. Portal session cookies live on the portal server until you delete the portal. PrivacyDPA
  • Trigger.dev (background jobs: email, pipeline, portals, exports, in Frankfurt). PrivacyDPA
  • Google (Gemini on Vertex AI in the EU; Gmail OAuth; optional Google login; supplier favicons). PrivacyCloud Data Processing AddendumGoogle processor DPA
  • OpenAI (portal capture, United States). PrivacyDPATrust portal
  • Scaleway (portal capture, France). PrivacyContracts and DPA
  • Meta (WhatsApp Cloud API). PrivacyWhatsApp Business terms
  • Decodo (network proxy for the portal browser, Lithuania). It carries the encrypted connection to the vendor site and sees which site that is, not the pages. PrivacyDPA
  • Firecrawl (a supplier's public homepage only, and only when our own fetch of that page is not usable. Used the first time we see the domain, so we can draft a short company summary). Privacy. No public DPA.
  • Brandfetch (supplier logos from a domain). Privacy. No public DPA.
  • logo.dev (supplier logos from a domain). PrivacyDPA
  • Cloudflare email forwarding (docs.billpal.io receives forwarded invoice mail; Cloudflare sees those messages). PrivacyDPA

Some of these are in the United States or elsewhere outside the EEA. Where we transfer personal data out of the EEA, we rely on that provider's DPA, Standard Contractual Clauses, the EU-US Data Privacy Framework where they participate, or an equivalent safeguard.

6. Our own vendors

Billpal is controller for these. They are outside the workspace DPA.

  • Plausible (cookieless analytics on the public site and account pages, not the signed-in app). Privacy
  • Loops (Astrodon Corporation; transactional email and product updates). PrivacyDPA
  • Stripe (subscriptions and our invoices to you). PrivacyDPA
  • Cloudflare Turnstile (bot check on signup, login, and forgot-password). PrivacyDPA
  • Upstash (Redis for rate limiting; hashed IP). PrivacyDPA

Some of these are in the United States or elsewhere outside the EEA. Where we transfer personal data out of the EEA, we rely on that provider's DPA, Standard Contractual Clauses, the EU-US Data Privacy Framework where they participate, or an equivalent safeguard.

7. Cookies & analytics

  • Essential cookies only: login and operation of the Service. No consent needed. There is no sitewide cookie banner.
  • If you arrive on an affiliate link (?via=), we ask before setting a Rewardful cookie. If you decline, we do not set that cookie. If you create an account through the link, we still record which affiliate sent you, so they can be paid when you subscribe.
  • Plausible on the public site and account pages (not the signed-in app). Cookieless. No analytics cookies.

8. Legal basis

  • Contract: creating an account and delivering the Service (Art. 6(1)(b) GDPR).
  • Legitimate interest: security and product-update emails, with unsubscribe in those emails (Art. 6(1)(f)).
  • Legal obligation: tax retention of our billing records (Art. 6(1)(c)).

Where we are processor of workspace data, we process on your documented instructions (the Terms, this policy, and the DPA).

9. Your rights

Under GDPR, you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Delete your data. You can do this in Settings or by contacting us.
  • Export your data. CSV/ZIP exports are built into the app for documents and contacts. For a wider copy, email support@billpal.io.
  • Restrict or object to certain processing.
  • Object to processing based on legitimate interest, including product-update emails. Unsubscribe in those emails.
  • Withdraw consent where consent is the basis (the affiliate cookie).
  • Lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).

10. Data Retention

  • We retain your data for as long as your account is active or as needed to provide the Service.
  • Billing records are kept as required by Austrian tax law (up to 7 years). Stripe is the tax archive for invoices and settlements. After you delete a Billpal account we keep a minimal record that the account existed, then delete it when that window ends.
  • Unused overage credits are forfeited when you delete an account. They are not refunded and they are not moved to anyone else.
  • When you delete your user login, your personal data is removed. Documents that belong to a workspace stay with that workspace, without your name attached.
  • When you delete an account, you choose Transfer or Delete for every workspace you own. Transfer moves that workspace to another member immediately. Delete removes that workspace's data. Other people's logins stay.
  • Third-party provider access (email connections, portal sessions) is revoked as part of deletion. Private credentials never transfer.

The synced mailbox copy is dropped when you disconnect. Documents we imported, and the IDs we need to avoid duplicates, stay until you delete the workspace or the document. Portal sessions are deleted when you delete the portal connection or the account. Capture recordings are deleted after 30 days. WhatsApp files follow the document and the chat until deletion. Voice audio is not stored; the transcript follows the chat.

11. Security

  • All data is encrypted in transit (TLS) and at rest.
  • Gmail and Microsoft: OAuth, read-only. We do not receive those mailbox passwords.
  • IMAP: the mailbox password is stored on our email host in Germany, not in the public app database.
  • Billpal login: every account needs a second factor, a 6-digit code from an authenticator app (TOTP).
  • Portal: we do not store the vendor password. Session cookies stay on our portal server in Germany. Capture runs keep a session recording for 30 days. Login is not recorded.
  • IMAP passwords and mailbox OAuth tokens on the German email host are encrypted at rest with AES-256.
  • We use bot protection, rate limiting, and row-level access controls.

12. Children's Privacy

The Service is for businesses. You must be at least 18. We do not knowingly collect personal information from children. If you believe we have, contact us so we can delete it.

13. Updates & Contact

  • We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email.
  • For any questions, contact us at support@billpal.io

Thank you for using Billpal! 🙏