BillMintly Privacy Policy

Effective August 14, 2026 · Last updated August 17, 2026

BillMintly helps users understand recurring bills, connected-account activity and potential savings. This policy explains what information BillMintly accesses, why it is used, how it is protected, and how users can remove connected data.

Information we process

BillMintly may process account identity information, profile details you provide, bills you enter, confirmed savings, connection metadata, financial transaction information returned by providers you authorize, Deep Scan purchase/status records and reports, and Google account data when you explicitly connect Gmail. BillMintly does not ask for or store your bank username or password. Bank authentication is handled by Plaid.

Google user data and Gmail access

If you choose Connect Gmail, BillMintly requests the restricted Google scope https://www.googleapis.com/auth/gmail.readonly. This is read-only access. BillMintly cannot use this permission to send, modify, or delete your Gmail messages.

BillMintly uses authorized Gmail access only to provide user-facing BillMintly features such as identifying receipts, bills, recurring charges, renewal notices and trial-related messages that can help you understand recurring costs and possible savings. When you run Gmail discovery, BillMintly asks Gmail to search recent messages for billing-related signals and retrieves matching message headers, snippets and message body content needed to identify information such as merchant, category, amount, recurrence signals and date. This message content is processed for the requested scan. BillMintly does not persist complete Gmail message bodies as bill records, and the current Gmail discovery feature does not separately download attachment files.

The Gmail discovery parser does not send Gmail message content to the BillMintly AI Money Agent. The AI Money Agent analyzes BillMintly bill records that a user has chosen to track, not Gmail message content.

Google user data is not used for advertising, sold to third parties, or used to build advertising profiles. BillMintly stores the Google OAuth access information required to keep a connection active, including an access token, refresh token when Google provides one, the connected Gmail address, granted scope, and token expiration information. These credentials are stored on the backend and are not exposed to the browser.

Google API Services User Data Policy and Limited Use

BillMintly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Access to Google user data is limited to providing and improving user-facing features that are prominent in BillMintly, maintaining security, and complying with applicable law.

Bill Inbox and AI extraction

When you choose Bill Inbox, BillMintly sends a compressed bill image or the extracted text from up to the first three pages of a PDF to its AI extraction service to identify fields such as provider, amount, due date, category and billing frequency. The extracted result is shown for your review and BillMintly does not create a bill record from that upload unless you approve and submit the normal bill form. Do not upload documents you do not want processed for this purpose.

Financial connections and Deep Scan

Authorized Plaid transaction information may be used to detect recurring charges, fee-like transactions and price changes. Full Deep Scan reports can combine the recurring bills you track with saved transaction-derived signals already available to your BillMintly account. BillMintly does not request Plaid money-movement products for these features.

Payments

Stripe hosts web checkout for Pro subscriptions and one-time Deep Scan purchases. BillMintly stores only the billing identifiers and status information needed to recognize your purchase or membership; BillMintly does not store raw card numbers or CVV values in its application database. Stripe may retain payment records under its own terms and legal obligations.

Advertising

The native iPhone Free tier can display Google AdMob banner ads only on non-sensitive screens. Pro is ad-free. BillMintly does not pass bill names, amounts, merchants, categories, Gmail content, financial transactions, bank-connection details, payment details or profile fields into ad requests. Before Google Mobile Ads starts, BillMintly disables publisher first-party ID and publisher privacy personalization and restricts ad content to the General rating. Google’s User Messaging Platform consent flow is refreshed once per launch and used where required, and the iPhone app provides an Ad privacy choices control in Plan & Security. Ad delivery and measurement may still process limited device, app, network, consent and interaction information under Google’s policies and the user’s choices. BillMintly does not request App Tracking Transparency permission for this banner implementation.

Sharing and service providers

BillMintly may use infrastructure, authentication, hosting, AI, payment and financial-data service providers to operate the service. Google user data is used only as described in the dedicated Google-data sections of this policy. The current Gmail discovery feature does not send Gmail message content to BillMintly's AI provider. Providers may process information only as necessary to deliver the applicable BillMintly service and subject to their privacy and security obligations. BillMintly does not sell personal information or Google user data.

Disconnecting Gmail and financial connections

You can disconnect Gmail from BillMintly through Connections or Profile. BillMintly attempts to revoke the stored Google OAuth token and removes its saved Gmail-token and connection records. Supported Plaid connections can also be disconnected; BillMintly removes the stored Plaid item and associated synced transaction records from the application database.

Security

Sensitive integration credentials are stored as backend secrets and are not exposed to the browser. BillMintly scopes private application records to the authenticated account. No internet service can guarantee absolute security. See the BillMintly Security Center for current controls and limitations.

Account deletion and retention

The authenticated deletion flow removes BillMintly-owned bills, profile data, savings history, Deep Scan purchase/report records, stored connection data, saved Gmail tokens and saved Plaid transaction records, and cancels any non-terminal web Pro subscription in Stripe before deletion proceeds. Account deletion does not automatically refund prior charges. Payment processors and other third parties may retain records they are independently required or permitted to keep. BillMintly otherwise retains account and connected-service data only while needed to provide the service, satisfy user requests, maintain security, resolve disputes, prevent abuse, or meet legal obligations.

Contact and updates

Questions about privacy or Google user data can be raised through the support/contact channel provided by BillMintly. This policy will be updated when BillMintly materially changes how it accesses, uses, stores, shares or deletes user information.