Billback ("we", "our", or "us") is a mobile and web application that helps individuals track work-related expenses and generate reimbursement PDFs. This Privacy Policy explains what information we collect, why we collect it, how it is stored and shared, and the rights you have over it. It applies to the Billback web app at billback.app and any Billback mobile application distributed through the Google Play Store or Apple App Store.
Billback is operated by NEXTWV INC. For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), the data controller is:
We do not collect: precise or approximate GPS location, contacts, SMS, call history, microphone audio, health data, financial account credentials, bank account numbers, or the Android Advertising ID. We do not use third-party advertising or cross-app tracking SDKs.
The Android app declares only one runtime permission:
When you tap to attach a receipt, the app opens Android's built-in system picker. From there you can take a new photo using your device's Camera app or choose an existing image from your gallery via the Android Photo Picker. In both cases the system handles capturing and selecting the image, then returns the chosen photo to Billback. Billback itself does not request access to your camera, photo library, or device storage, and it never accesses the camera in the background.
When you scan a receipt, the image is uploaded to our backend and forwarded to a third-party AI inference provider for text extraction. The provider uses a vision-capable language model to extract merchant name, amount, date, and line items. We have configured this provider so that receipts are not retained beyond the processing step and are not used to train any model. Extracted text and the receipt image are then stored in your Billback account and are visible only to you.
We do not use your data for advertising, we do not track you across other apps or websites, and we do not sell or rent your data.
We share data only with the following sub-processors, strictly for the purposes described:
provider.data_collection: "deny") so it is routed only to providers that do not retain or train on your image. Inputs are processed in-memory for the duration of a single request, then discarded. The specific model may change; any replacement is likewise sent under the same no-retention flag.A current list of specific sub-processors is maintained at this URL and updated when changes occur. You can also request the latest list by emailing appbillback@gmail.com.
These providers operate primarily in the United States, so your data may be transferred to and processed there. International transfers rely on the Standard Contractual Clauses (SCCs) offered by each provider and, where applicable, the EU-US Data Privacy Framework. We do not sell your personal data to any third party.
All data in transit is encrypted via HTTPS/TLS. Data at rest is encrypted by our infrastructure providers. Authentication tokens are managed by our authentication provider; we never store raw passwords. We apply the principle of least privilege to internal access. No system is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required (GDPR Art. 33) and notify affected users without undue delay via the email address associated with your account.
You may permanently delete your Billback account and all associated data at any time:
Deletion removes your account record, all expense data, and receipt images from our active systems. Residual copies in backups are overwritten on the cycle described in Section 9.
Subject to applicable law, you have the right to:
To exercise any of these rights, email appbillback@gmail.com. We will respond within 30 days.
EU / EEA / UK residents (GDPR): you have the right to lodge a complaint with your local supervisory authority if you believe we have violated your rights.
California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising.
Billback is intended for adult users tracking work-related expenses. The service is not directed at children under 13 (under 16 in the EU/EEA). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact appbillback@gmail.com and we will delete it promptly.
We do not make decisions about you based solely on automated processing that produces legal or similarly significant effects.
We may update this policy from time to time. We will notify you of material changes via the app or email before they take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of Billback after the effective date constitutes acceptance of the updated policy.
Questions, requests, or complaints:
NEXTWV INC.
Billback
appbillback@gmail.com