Legal & privacy
Privacy policy
How BillFoldify collects, uses, protects, and manages information across our app and website.
Last updated 22 September 2026
BillFoldify is a personal finance app operated by Rhombus Technologies Pte. Ltd., Singapore (“we”, “us”, or “our”). This policy explains how we access, collect, use, store, and share personal information when you use the BillFoldify app, sign in with Google, visit billfoldify.com, or contact us.
For privacy questions or requests, email reachus@billfoldify.com.
1. Information we collect and why
- Account information: your name, email address, account identifier, and profile information you provide. We use this to create and manage your account, authenticate you, and communicate about your account or support requests.
- Financial information you enter: financial accounts and balances, income, expenses, transaction dates and descriptions, categories, tags, budgets, goals, and recurring payments. We use these records to provide transaction tracking, summaries, budgeting, and other finance features you choose.
- Uploaded documents: receipts, invoices, bank statements, images, and the information they contain, such as merchant names, purchased items, amounts, dates, and account details. We process these files to extract and organize financial records. Upload only documents you want processed.
- Family and shared profiles: profile details, invitations, relationships, and financial records associated with profiles you create or join. We use them to provide shared account and profile features according to access permissions.
- Support and website messages: the contact details and message content you submit, used to respond to your enquiry.
- Technical information: service request and error logs, network information such as IP addresses, and app or browser information supplied with requests. We use these to operate the service, diagnose problems, and prevent misuse.
2. Google sign-in: data accessed and used
When you choose Google sign-in, Google authenticates you and shares identity information through Amazon Cognito, our authentication provider. This includes your Google account identifier, email address and verification status, and basic profile information made available by Google, such as your name and profile picture. The identity permissions are openid, email, and profile.
We use this information to identify you, create or sign you into your BillFoldify account, associate your financial records with that account, and provide account communications. Authentication identifiers and session tokens support sign-in and authorized access. Your Google password is entered with Google and is not provided to BillFoldify.
Google sign-in does not give BillFoldify access to your Gmail messages, Google Drive files, Google Calendar, or Google Contacts. Documents you upload to BillFoldify are supplied by you separately from Google sign-in.
BillFoldify’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing features described here. We do not sell Google user data or use it for advertising, data brokerage, creditworthiness assessments, or lending decisions. We do not use Google Workspace API data to develop, improve, or train non-personalized artificial intelligence or machine learning models.
3. Document processing and artificial intelligence
When you use invoice or receipt extraction, BillFoldify sends the uploaded image or PDF and relevant category information to Google’s Gemini API to identify document details and suggest structured financial records. This processing is separate from Google sign-in. The document may contain personal or financial information, which is included in the processing request. Uploaded bank statements are also processed to extract transactions.
We store uploaded files and extracted results to make them available in your account. Automated extraction can make mistakes; review the results before relying on them. You can enter financial records manually without uploading a document.
4. Who receives information
- Amazon Web Services (AWS): provides authentication through Amazon Cognito, application hosting, databases, file storage, operational logging, and email delivery. Account information, financial records, uploads, and technical data are processed through these services as needed to operate BillFoldify.
- Google: provides Google sign-in, Gemini document extraction, and reCAPTCHA protection for our website contact form. Each receives the information needed for the feature described in this policy.
- People with shared-profile access: financial records and profile information associated with a shared profile are available to people authorized to access that profile.
- Authorized support and operations personnel: may access information when necessary to respond to your request, maintain the service, or investigate security issues, subject to applicable access restrictions.
- Legal disclosures: information may be disclosed where required by applicable law or legal process, or as necessary to address fraud or security threats, subject to the restrictions that apply to Google user data.
We do not sell or rent your personal information. We do not disclose Google user data to advertising networks or data brokers. Service providers receive information for the functions described above. Processing may take place outside your country through our service providers.
5. Storage and protection
Account identity information is maintained through Amazon Cognito, financial and profile records in our backend databases, and uploaded documents and extraction results in AWS storage. The app also stores session information and preferences on your device.
We use HTTPS for communication with our service, authentication checks to restrict access to account data, and access permissions for backend services and shared profiles. Deletion requests revoke active sessions and restrict account access as described below. No system can guarantee absolute security; protect your device and do not share passwords or verification codes.
6. How long we retain information
We retain account information, including Google sign-in identity information, financial records, uploaded documents, and extracted results while your account is active to provide your account history and the features you use. Support messages and operational logs are retained as needed to handle enquiries, operate and protect the service, and meet applicable legal obligations. Account deletion follows the process below.
You can remove BillFoldify’s Google access through your Google Account connections settings. Removing Google access prevents future access under that authorization; it does not itself delete information already stored in BillFoldify or replace an account deletion request.
7. Account and personal data deletion
You may request deletion at any time, regardless of subscription status, from Settings > Delete account in the BillFoldify App or through the email request pathway on our account deletion page.
- After you confirm the request in the App, BillFoldify immediately blocks access to account data and revokes active sessions. During the retention period, a verified primary account holder who signs in is restricted to reactivating the account or keeping deletion scheduled and signing out.
- Before permanent deletion begins, selecting Reactivate account cancels the pending deletion and restores account access. Once purging or permanent deletion has begun, the request cannot be reversed and the account cannot be restored.
- BillFoldify permanently deletes the profile, authentication identity, financial accounts, transactions, budgets, categories, goals, recurring payments, family records, tags, invoices, uploaded documents, extraction files, bank statements, and other account-owned content within 90 days.
- During that period, the data is inaccessible and is retained only to complete secure deletion, comply with law, prevent fraud, resolve disputes, and protect the service.
- After deletion, BillFoldify may retain a non-identifying audit record of the request and its completion. Information required by law may be retained for the applicable legal period.
- Encrypted backup copies remain only until they expire under our normal backup lifecycle. A deleted account will not be restored into the active service from a backup.
For deletion support, contact reachus@billfoldify.com. Do not email passwords, verification codes, financial records, or identity documents.
8. Your choices and requests
You choose whether to use Google sign-in, upload documents, or use shared profiles. You can update information through the app where editing is available. Contact reachus@billfoldify.com to request access to, correction of, or deletion of personal information, or for help exercising privacy rights available in your location. We may need to verify your account ownership before fulfilling a request.
9. Website cookies and local storage
Our website contact form uses Google reCAPTCHA to reduce spam and automated abuse. reCAPTCHA may collect browser, device, and interaction information and use cookies as described in Google’s Privacy Policy and Terms of Service. You can control cookies in your browser; blocking them may affect the contact form. You may contact us by email instead. The app uses local storage for preferences and session information.
10. Policy updates and contact
We will publish changes on this page and update the date above. If we materially change how we collect or use personal information, including Google user data, we will provide a prominent website or in-app notice and request consent where required before applying the new use.
Responsible organization: Rhombus Technologies Pte. Ltd., Singapore.
Privacy contact: reachus@billfoldify.com.