BillMintly Security Center
BillMintly is designed to help you understand recurring costs without giving the app permission to move your money.
Bank connections
BillMintly uses Plaid transaction access to identify recurring charges, fees and price changes. Bank authentication is handled through Plaid and supported financial institutions. BillMintly does not ask you to type a bank username or password into a BillMintly form.
BillMintly's Plaid configuration requests Transactions, not payment-initiation or transfer products.
Payments
Web subscription and one-time Deep Scan checkout is handled through Stripe-hosted checkout. BillMintly does not store raw card numbers or CVV values in its application database.
Pro may include a 30-day free trial for eligible new subscriptions. The selected price and renewal cadence are shown before checkout.
Gmail
Gmail is optional. BillMintly requests gmail.readonly. It cannot use that permission to send, edit or delete Gmail messages. Disconnecting Gmail removes the saved BillMintly connection and attempts to revoke the stored Google token.
Advertising privacy
The native iPhone Free tier can show a Google AdMob banner on Home, Savings and Money Lab only. Pro is ad-free. BillMintly sends a plain ad request and does not attach bill names, amounts, merchants, Gmail content, Plaid or financial transactions, payment details, profile fields, keywords or custom targeting. Publisher first-party ID and publisher privacy personalization are disabled before initialization, and ad content is restricted to the General rating. Ads are removed from sensitive screens and while a modal is open. Google UMP is refreshed once per launch and controls required consent and privacy choices; BillMintly does not request App Tracking Transparency permission for this implementation.
Your control
Connected bank and Gmail integrations can be disconnected from BillMintly. Profile also provides an authenticated account-deletion flow that removes BillMintly-owned bills, profile, savings, Deep Scan reports and stored connection data, subject to the details in the deletion page.
Abuse protection and incident reporting
BillMintly applies user-scoped server limits before costly AI, Gmail, Plaid, checkout, reminder-test and feedback actions run. Repeated limit hits are recorded as bounded security telemetry without exposing financial details in the owner dashboard.
To report a suspected security issue, email nrsteinert84@gmail.com. Do not include passwords, API keys, bank credentials or full account numbers.
Retention and deletion
Bills, verified savings and connected financial records remain available while the account or connection is active. Disconnecting Plaid removes the related Plaid Item and locally stored transactions; disconnecting Gmail removes the saved token. Authenticated account deletion removes BillMintly-owned account data.
Short-lived Google authorization setup state is valid for 15 minutes and purged after one hour. Rate-limit state is purged after 48 hours, and bounded security-event telemetry after 30 days.
What we do not claim
No internet service can guarantee absolute security. BillMintly does not claim a security certification, independent penetration-test result, Google OAuth approval or bank partnership unless that milestone has actually been completed and published.
Security roadmap
BillMintly uses least-privilege access, account-scoped authorization, backend secret storage, automated QA, user-scoped abuse limits and scheduled cleanup. A formal independent application-security review remains a launch milestone before any certification or penetration-test claim is made.
Privacy Policy · Terms & Conditions · Account deletion · Back to BillMintly
Last updated August 14, 2026.