BillFlow is a personal utility bill tracking application. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
By using BillFlow, you agree to the practices described in this policy.
All bill records, properties, categories, notes, and photo attachments you add to BillFlow are stored exclusively on your device in a local database. This data never leaves your device unless you explicitly initiate a Google Drive backup (see Section 4).
We do not have access to, and do not collect:
Bill amounts or payment details
Utility provider names or reference numbers
Property names or addresses
Notes, remarks, or any other bill content
Photo attachments
If you choose to enable Usage Analytics in Settings → Privacy, BillFlow collects anonymous, non-identifiable usage data through PostHog (a third-party analytics platform). This data helps us understand how the app is used and improve its behaviour and functionality.
What is collected (anonymous only):
Screen views (screen name only — no content)
Feature interactions (e.g., “bill added”, “chart viewed”, “backup initiated”)
App errors and crash reports (stack trace and app version only)
General app performance metrics
What is never collected:
Bill amounts, dates, or any financial data
Provider names, reference numbers, or notes
Property names or addresses
Photo content
Your name, email address, or any personally identifiable information
Analytics are opt-in and disabled by default. You can enable or disable them at any time from Settings → Privacy → Usage Analytics. If disabled, no data is transmitted, and the analytics SDK remains inactive.
If you enable App Lock in Settings → Security, BillFlow uses your device’s built-in biometric authentication (fingerprint, Face ID) or PIN. This authentication is handled entirely by your device’s operating system. BillFlow does not store, transmit, or have access to your biometric data or PIN.
BillFlow offers an optional Google Drive backup feature. If you choose to use it:
You will be asked to sign in with your Google account via Google’s official OAuth 2.0 flow.
BillFlow requests only the drive.appdata scope, which limits access exclusively to files created by BillFlow in a private, hidden app folder. BillFlow cannot read or modify any other files in your Google Drive.
Your backup files are stored in your own Google Drive account.
Backup files are protected by Google Drive’s own encryption and security.
Google Drive sign-in is entirely optional. All core features work without it.
For information on how Google handles your data, please refer to Google’s Privacy Policy.
All your bill data is stored locally on your device using SQLite.
No data is transmitted to any BillFlow server — there is no BillFlow server.
The only external destinations for your data are:
Your own Google Drive account (if you enable backup)
PostHog analytics servers (anonymous data only, if you opt in)
OAuth tokens for Google Drive are stored in your device’s secure credential storage (Android Keystore / iOS Keychain).
BillFlow uses the following third-party services:
Service
Purpose
Data Shared
Opt-In?
PostHog
Anonymous usage analytics
Anonymous events only (no personal or financial data)
Yes — opt-in
Google Drive API
Backup and restore
Your own backup files only
Yes — opt-in
Google Sign-In
OAuth authentication for Drive
Email address (used to authenticate; not stored by BillFlow beyond the session)
Yes — opt-in
BillFlow is an offline-first app. Your financial data is yours — it stays on your device.