Privacy
Bilbee Privacy Policy
Effective 27 September 2026
In short
- We store what you enter so the product works. We don't sell it and we don't use it for anything but Bilbee.
- Your data is stored with Railway, encrypted, isolated per account.
- Third parties we use, and what they see: hosting (Railway), email delivery (Resend), receipt reading (Anthropic, for receipts you upload or forward), payments (Stripe) and, only if you use them, Google sign-in and Calendar. Each is listed in the policy below.
- Export or delete everything from your account page, any time.
- Questions: [email protected].
A plain-English summary, not a substitute for the full document.
1. Who we are
Bilbee (https://bilbee.app) is operated by Richard Morrisson (ABN 89 650 318 493), an Australian sole trader. This policy explains what personal information we collect, why, where it's stored, who else touches it, and your rights. It's written to align with the Australian Privacy Principles (APPs).
2. What we collect
Account information: your email address and a password. Passwords are hashed with scrypt via the Better Auth library. We never see or store your plain-text password beyond the sign-in request itself. If you choose Google sign-in instead, we receive basic profile details from your Google account (such as your name and email address) to create and secure your account. We never receive your Google password.
Information you store in the app:
• your business details: business name, ABN, and the bank account details and PayID you want displayed on invoices
• client records: client names, contact person names, email addresses, addresses and ABNs
• invoices, quotes and payment records
• expenses, including uploaded receipt images
• bank transaction CSV files you import
• your tax settings.
Billing information: if you choose a paid plan, you enter your card details on Stripe's checkout page, not ours. We keep a Stripe customer reference and your plan's status and renewal date, never your card number.
Connected integrations: if you connect optional integrations, we store the credentials needed to use them: your Stripe account key (so your clients can pay invoices by card) and, if you connect Google Calendar, a Google authorisation token. These are stored encrypted, and you can disconnect them at any time.
Technical information: like most online services, our servers keep standard logs that include technical details such as your IP address, and we use IP addresses for security protections like rate limiting. We also note when you last signed in or used Bilbee.
How you found us: when you sign up, we save with your new account the campaign tags on the link you arrived by (such as utm_source), an ad click identifier if the link carried one (such as Google's gclid), and the name of the website that sent you. We use these only to learn which ads and links bring people to Bilbee.
Support correspondence: if you email us (for example at [email protected]), we keep that correspondence so we can help you and keep a record of your request.
3. Information about your clients
Some of what you store in Bilbee is personal information about other people: your own clients. We store and process that information on your behalf so you can invoice and keep records. We don't use your client data for our own purposes, and we don't contact your clients except to send the invoice and quote emails you ask us to send.
You're responsible for collecting your clients' details lawfully and for telling them how you use their information, where that's required.
4. Why we collect it
We collect and use your information only for these purposes:
• providing the service: creating invoices and quotes, tracking expenses, reconciling bank transactions, calculating GST/BAS figures and tax estimates, and exports
• billing: charging for a paid plan, and knowing which plan you're on
• sending emails: invoice and quote emails to your clients, and account emails like email verification
• keeping your account secure
• learning which ads and links bring people who go on to use Bilbee, by looking at the sign-up details in section 2 alongside whether each account sends an invoice, keeps using Bilbee and pays for a plan.
We don't use analytics or advertising trackers, we don't show ads in Bilbee, and we never sell your data.
5. Where your data is stored and processed (overseas disclosure)
Bilbee is hosted on Railway, so your data, including your clients' details, is stored on Railway's servers outside Australia.
Several providers that help run Bilbee operate outside Australia. Resend delivers our email, so the invoice and quote emails you send (which can include client names, contact details and invoice contents), any receipt emails you forward, and our account emails may be processed on Resend's infrastructure, including in the United States. If you upload or forward a receipt, Anthropic processes that receipt image (in the United States) to extract the expense details. Stripe, which operates globally, including in the United States, processes the payment for a paid Bilbee plan and, if you connect Stripe to accept card payments, your clients' card payments. And if you use Google sign-in or Google Calendar, Google processes that on its own infrastructure, which operates globally, including in the United States.
Under the Australian Privacy Principles (APP 8), these are cross-border disclosures, and the privacy laws in those countries differ from Australia's. We take reasonable steps to ensure our providers handle your data, and your clients' data, consistently with the Australian Privacy Principles.
6. Third parties we use
We share data only with the service providers needed to run Bilbee:
• Railway: hosts the app and database
• Resend: sends transactional email (invoice and quote emails to your clients, and account emails like verification) and receives forwarded receipt emails if you use the receipt inbox
• Anthropic: when you upload or forward a receipt, we send the receipt image to Anthropic's Claude AI to read the vendor, date, amount and GST and pre-fill an expense draft; receipts are sent only for that extraction
• Stripe: takes the payment for a paid Bilbee plan (your name, email and card details go to Stripe for that), and, if you connect your own Stripe account, processes your clients' card payments; Bilbee never sees or stores full card numbers, and your clients' payments go directly to your Stripe account
• Google: only if you choose Google sign-in (to authenticate you) or connect Google Calendar (covered next).
Google Calendar and the Google API Services User Data Policy: if you connect Google Calendar, Bilbee requests read-only access to your calendar events (the calendar.events.readonly scope) for one purpose, to show your events on the Timesheet so you can turn them into billable time entries with a click. Bilbee never writes to your calendar, doesn't store your events on our servers (they're fetched live and shown to you), and doesn't use them for advertising or sell them. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect Google Calendar at any time from the Timesheet, which removes the stored authorisation.
We don't sell or rent your data to anyone, and we don't share it with advertisers.
7. Cookies
Bilbee uses one essential session cookie to keep you logged in. No advertising or tracking cookies.
On getbilbee.com and on Bilbee's sign-up and log-in pages, your browser keeps the campaign tags on the link you arrived by, any ad click identifier and the name of the website that sent you in session storage, which is cleared when you close the tab. They reach us when you sign up or log in, and we keep them only for a new account.
8. Public invoice links
If you generate a public link for an invoice, anyone who has that link can view the invoice, including the client details and payment details on it. Links use long random tokens designed to be unguessable, but they aren't password-protected, and there's currently no way to disable or regenerate a link once it exists (deleting the invoice removes the page). Only share links with the people who should see them.
9. How we protect your data
• Encryption in transit (HTTPS) between you and Bilbee.
• Passwords hashed with scrypt, never stored in plain text.
• Per-tenant row-level security in our Postgres database, so each account's data is isolated from every other account's.
No online service can promise perfect security, but these protections are in place and we take them seriously.
10. Data breaches
If a data breach occurs that's likely to cause you serious harm, we'll notify you promptly (including what happened, what information was involved, and what we're doing about it) and we'll notify the Office of the Australian Information Commissioner (OAIC) where required.
11. How long we keep your data
We keep your data for as long as your account is active. It's your business record-keeping, so it stays until you say otherwise.
If you delete your account (see section 12), we delete all your data and your Stripe customer record, and cancel any paid plan. Copies may persist in encrypted backups for up to about 90 days before they're gone completely. Stripe keeps its own record of past payments, as payment providers are required to.
12. Access, correction, export and deletion
• Access and correction: almost everything we hold about you is visible and editable inside the app. If there's anything you can't see or fix yourself, email us and we'll help.
• Export: download everything as a zip anytime with Export all data, on your account page.
• Deletion: use Delete account on your account page, or email [email protected] from your account's email address, and we'll delete your account and all its data (subject to the backup window above). Consider exporting first. Tax law generally requires you to keep business records for five years.
13. Complaints
If you think we've mishandled your personal information, email [email protected] and we'll look into it and respond as quickly as we can.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.
14. Changes to this policy
If we change this policy (for example, if we add a new service provider), we'll update the effective date at the top and notify you of material changes by email or in-app before they take effect.
15. Contact
Privacy questions or requests: email [email protected].