Security and privacy

How BillGutter handles your information

Your bills can include account numbers, charges, medical balances, and service details. BillGutter limits access to signed-in workspaces, keeps important activity in history, and gives you paths to export or request deletion.

Private workspaces

Only authorized workspace members can see its bills and reports.

Approval before changes

BillGutter does not quietly change services or accounts.

Export and deletion paths

You can export workspace data and request deletion from Settings.

Questions customers ask first

Clear answers before you upload

Can anyone else see my bills?

Only authorized members of your workspace can access its bills, actions, and reports.

Where is my information stored?

BillGutter stores application data in its production database and document storage. Third-party processors may process data in their own infrastructure.

Will AI train on my documents?

BillGutter uses OpenAI's API for analysis when AI is enabled. OpenAI says API inputs and outputs are not used to train its models by default unless the customer opts in.

Can I export my information?

Authorized users can download a workspace export from Settings.

Can I delete my information?

Deletion requests are reviewed so shared ownership, billing records, backups, and sensitive bill history are handled carefully.

Can someone change my services without me?

No. BillGutter prepares the next step, but high-impact changes require approval before anyone acts.

How is information protected in transit?

BillGutter uses HTTPS when information moves between your browser and the service.

How long are backups kept?

Backup copies may remain until normal backup rotation removes them. Legal, billing, security, fraud-prevention, tax, or dispute records may be retained when required.

Third-party processors and AI

BillGutter may use third-party services to analyze documents, process payments, and deliver notifications. Upload only documents that belong to you, your household, or an organization that has authorized you to review them.

OpenAI

When AI analysis is used, BillGutter may send extracted bill text, relevant bill fields, and document context to OpenAI to identify charges, terms, and possible actions. Account numbers and sensitive details are not guaranteed to be redacted before extraction or analysis. AI-assisted analysis cannot currently be disabled at the individual workspace level.

Stripe

Stripe is used for billing and subscription management when a paid plan is selected.

Resend

Resend can deliver account, approval, reminder, and administrative emails.

n8n

n8n can run automation workflows for reminder delivery and future intake workflows.

AI disclosure

What AI may see

BillGutter only makes claims it can support. OpenAI publishes its API data-use position at openai.com/policies/how-your-data-is-used-to-improve-model-performance.

What may be sent

Extracted bill text, provider names, line items, dates, totals, fees, discounts, renewal language, and document context needed to produce the analysis.

Full documents

Complete files may be processed by extraction services before analysis so text can be read from PDFs, images, statements, or EOBs.

Model training

OpenAI states that API inputs and outputs are not used to train OpenAI models by default unless the customer opts in to data sharing.

Human access

BillGutter staff access should be limited to operational, support, security, billing, or abuse-prevention needs.

Redaction

BillGutter does not currently guarantee automatic redaction before extraction or AI analysis. Treat uploaded documents as sensitive.

Processing location

BillGutter uses third-party processors that may process data outside your state or country.

Important limits

No unsupported compliance claims

HIPAA

BillGutter is not HIPAA compliant at this time. Do not use it as a regulated medical-records system or upload documents that your organization requires to be processed under a HIPAA business associate agreement.

SOC 2

BillGutter does not currently claim SOC 2 certification.

Legal or financial advice

BillGutter provides analysis and workflow support. It does not replace professional legal, tax, insurance, medical billing, or financial advice.

Download your workspace data

Use Settings to download a JSON export of the current workspace. The export avoids password hashes, invite token hashes, and Stripe identifiers.

Open settings

Request deletion carefully

Deletion requests are reviewed before removal to prevent accidental loss of shared workspace or billing records. BillGutter confirms the request, identifies any records that must be retained, and communicates the expected completion timeline.

Acknowledgement target: BillGutter aims to acknowledge deletion requests within 2 business days.

Deletion target: After ownership, billing, security, and legal-retention checks, BillGutter targets completion within 30 days.

Backups: Encrypted backup copies may remain until normal backup rotation removes them.

Required retention: Billing, security, fraud-prevention, tax, legal, or dispute records may be retained when required.

Request review
Security and Privacy | BillGutter