Legal

Privacy Policy

Last updated 7 October 2026

Billery helps businesses create and send invoices, quotes and receipts. This policy explains what information we collect when you use Billery, including through ChatGPT and our API, what we do with it, and the choices you have. We don't sell your data, and we don't use advertising or analytics trackers.

Who we are

Billery is built and run by Dominic Eburuoh, an independent developer based in the United Kingdom, trading as Billery. In this policy, "Billery", "we" and "us" mean Dominic Eburuoh.

For your account and business details, we are the controller under UK data protection law. For the details you add about your own customers, you are the controller and we process that information on your behalf as your processor (see Information about your customers).

Questions or requests: support@billery.io.

What we collect

Your account

  • Your name and email address.
  • Your password, which we store only as a one-way hash. If you sign in with Google or Apple instead, we receive your name, email address and an account identifier from them, never your password.

Your business profile

  • Business name, address, phone number, website, VAT and company numbers, logo, and a short description.
  • The payment or bank details you choose to print on your documents.
  • Document settings such as numbering prefixes, default currency and what appears on each document.

Your documents

  • The invoices, quotes and receipts you create, including line items, prices, dates, notes and status.

Messages to the Billery assistant

  • What you type or say to the assistant, so it can create documents and customers for you. Your chat history is kept in your browser tab and is not stored on our servers. Voice input uses your browser's built-in speech recognition, which your browser's provider (such as Google or Apple) may process. We receive only the resulting text, never the audio.

Billing

  • If you subscribe to Pro, Stripe processes your payment. We receive your Stripe customer and subscription identifiers and subscription status. We never see or store your full card details.

Developer and integration data

  • API keys you create, which we store only as a hash, along with a short prefix so you can recognise them.
  • Webhook endpoints you register.
  • Authorisations you grant to apps such as ChatGPT, whose access tokens we store only as hashes.

Technical information

  • Our hosting provider keeps standard server logs, such as IP address, browser type and the pages requested, to run and secure the service.

Information about your customers

When you add customers, you give us their name, email address and optionally phone number, address and notes. We use this only to provide Billery to you: storing it, putting it on your documents and emailing documents when you ask us to send them. You are responsible for having a lawful basis to share your customers' details with us and for telling them how you use their information. If one of your customers contacts us about their data, we will refer them to you and help you respond.

How we use information

  • To provide Billery (performance of our contract with you): creating, storing and sending your documents, running the assistant, the API and integrations, and managing your subscription.
  • To keep Billery secure and working (our legitimate interests): preventing fraud and abuse, rate-limiting the API, fixing problems and improving the product.
  • To communicate with you: service emails such as password resets and billing notices. We don't send marketing emails without your consent.
  • To meet legal obligations: for example, keeping billing records for tax purposes.

We don't sell personal information, and we don't use it for advertising.

AI features

The assistant and the "generate line items" feature send your request to OpenAI, along with the context needed to fulfil it, such as your customer names, currency and business details. OpenAI processes it under its API terms to return a result. Under those terms, data sent through the API is not used to train OpenAI's models. Everything the assistant creates is saved as a draft. Nothing is sent to your customers until you choose to send it.

Using Billery in ChatGPT and other apps

You can connect your Billery account to ChatGPT or another app that supports the Model Context Protocol (MCP). When you do:

  • You sign in to Billery and approve the connection. The app receives an access token and never sees your Billery password.
  • The app can search and create customers, create invoices, quotes and receipts, list your recent documents, get share links and send documents when you ask it to. Results, such as customer names, amounts and links, are returned to that app.
  • We receive only what the app sends us to carry out a request, not your wider conversation with it.
  • Information returned to ChatGPT is handled by OpenAI under its own privacy policy. Other apps are handled under their providers' policies.
  • You can disconnect at any time from the app's settings, or by emailing us to revoke access.

Who we share information with

We use these service providers to run Billery. Each processes data only on our instructions:

  • Vercel: hosts the website and app.
  • Supabase: hosts our database, located in the EU (Ireland).
  • OpenAI: powers the assistant and AI drafting.
  • Stripe: handles subscription payments.
  • Resend: delivers emails, including documents you send to customers.
  • Google and Apple: only if you choose to sign in with them.

We also share information:

  • Where you direct us to: with the customers you send documents to, with anyone you give a document's share link to (anyone with the link can view that document), with webhook endpoints you configure, and with apps you connect.
  • Where the law requires it, or to protect the rights, safety and property of our users or others.
  • If our business changes hands: as part of a merger or acquisition, under the same protections set out in this policy.

International transfers

Some of our providers are based in, or access data from, the United States. Where personal information leaves the UK, we rely on adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework, or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

How long we keep information

  • We keep your account, business profile, customers and documents for as long as your account is open.
  • When you ask us to delete your account, we delete it and everything in it within 30 days. Encrypted backups are overwritten on a rolling basis shortly after that.
  • We keep billing records for as long as tax law requires, which is usually six years.
  • App access tokens stop working when they expire, or straight away if you ask us to revoke them. API rate-limit records are removed automatically after about ten minutes.

Security

All traffic to Billery is encrypted with HTTPS. Passwords are hashed with bcrypt, and API keys and app access tokens are stored only as hashes. Every request is checked so that you can reach only your own data. No system is perfectly secure. If we become aware of a breach that affects you, we will notify you and the regulator as the law requires.

Your rights

Under UK data protection law, you can ask us to:

  • give you a copy of your personal information
  • correct information that is wrong (you can edit most of it yourself in the app)
  • delete your information
  • restrict or object to how we use it
  • give you your information in a portable format

To make a request, email support@billery.io from the address on your account. We will respond within one month. If you're unhappy with how we handle your information, you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies and local storage

Billery uses only what it needs to work. These are cookies that keep you signed in and protect forms against cross-site attacks, plus browser storage for your light or dark theme and your current assistant conversation. We don't use advertising or analytics cookies, so there's nothing to opt out of. Stripe sets its own cookies on its checkout pages.

Children

Billery is a business tool and is not intended for anyone under 18.

Changes to this policy

If we make significant changes, we will email you or show a notice in the Billery app before they take effect. The date at the top shows when this policy was last updated.

Contact

Dominic Eburuoh, trading as Billery. Email: support@billery.io.