Privacy policy
What data NoBill processes, why, on which legal basis, for how long – and your rights (Art. 13 GDPR).
Last updated:
Contents
1. Controller
Trafic Corsar [TODO: Rechtsform / legal form, e.g. GmbH, UG (haftungsbeschränkt), SAS]
[TODO: Anschrift / street, postcode, city, country]
E-mail: [TODO: Datenschutz-E-Mail, e.g. privacy@nobill.website]
Data protection officer: [TODO: Datenschutzbeauftragter, if appointed — or delete this line]
2. In short
- We never connect to your bank account.
- Screenshots are sent to our AI provider (Anthropic, USA) to be read and are not stored by NoBill.
- With your account we keep your e-mail address, your plan, your subscription list, reminder settings, a record of what each scan found (13 months) and technical data about help-chat messages – never the content of the chat.
- No advertising cookies, no third-party trackers, no selling of data. Our usage statistics are our own and cookieless.
- You can delete your account and its data yourself at any time in the app.
3. What we process, why and on which legal basis
Visiting the website. Our host Vercel processes the technically necessary data of every request (IP address, date and time, page requested, browser identification, referrer) to deliver the website, keep it secure and detect errors. Legal basis: legitimate interest in a secure, working website, Art. 6(1)(f) GDPR.
Abuse and security protection. To limit sign-in attempts, scans, chat messages and form submissions per person, our server briefly uses your IP address (and, for some limits, your e-mail address or account ID) as a counter key. The key is stored in our rate-limit store only in pseudonymised form (a keyed hash, never the plain IP or e-mail) and expires automatically with the limit window – between one minute and 24 hours. Legal basis: Art. 6(1)(f) (protection against abuse and fraud).
Bot check (only if enabled). Before a scan we can use Cloudflare Turnstile to tell people from bots. Cloudflare then processes your IP address and technical browser data; the check runs only on the scan screen in the app. Legal basis: Art. 6(1)(f).
Quiz. Your answers, the resulting estimate and a random quiz ID are stored so that the quiz can be resumed and linked to a later purchase. If you enter your e-mail address, we store it with your answers, your acceptance of the terms and the campaign tags of the link you came from (utm parameters – never advertising click IDs). Purpose: to show your estimate, to recognise your order at checkout and to understand which questions and campaigns work. Legal basis: steps prior to a contract at your request and our legitimate interest, Art. 6(1)(b) and (f). Quiz data and e-mail addresses left there without a confirmed marketing consent are deleted after 6 months.
Marketing e-mails (only with your consent). Ticking the optional box only requests consent: we send a confirmation e-mail, and only after you click its link do we record your consent (with the time of the request and of the confirmation – double opt-in). Without that confirmation you receive no marketing e-mails. You can withdraw your consent at any time, with the unsubscribe link contained in every marketing e-mail or by writing to us. Legal basis: consent, Art. 6(1)(a); keeping the proof of consent: Art. 6(1)(c) and (f). We do not send marketing e-mails at present.
Account and subscription. E-mail address, language, Stripe customer ID, plan, status and dates of your subscription, and a counter used to sign you out on all devices. For sign-in we e-mail you a single-use link valid for 20 minutes; we store only a hash of it. Purpose: performing the contract, sign-in, billing. Legal basis: Art. 6(1)(b).
Billing records. We log payments, refunds, status changes, cancellations and withdrawals (with the time we received them and, for requests via the public cancellation page, the e-mail address given), and your request that the service start immediately (with its time). Purpose: proof and statutory accounting duties. Legal basis: Art. 6(1)(b), (c) and (f).
Payment. You enter your payment details directly in Stripe's payment form; we never receive your full card number. Stripe's script is loaded only at the payment step; Stripe then also processes device and usage data for fraud prevention, partly as an independent controller (Stripe's privacy policy applies). Legal basis: Art. 6(1)(b) and (f).
Screenshots. Images you upload are reduced in size in your browser and sent to Anthropic (AI provider) to read the service, amount, currency, billing cycle and dates. NoBill does not store the images. According to its commercial terms, Anthropic does not use API data to train its models and deletes it after a limited period. Please crop out anything not needed (balance, IBAN, other people's names). We keep a record of each analysis linked to your account – the services found (name, amount, currency, cycle, category, trial, confidence) plus technical data (number and type of images, duration, AI model, amount of AI processing used, errors) – for your daily AI limit, cost control and product statistics. Legal basis: Art. 6(1)(b), and our legitimate interest in improving the service, Art. 6(1)(f).
Subscription list. Subscriptions found or entered by you (service, amount, currency, cycle, category, next charge date, trial, your keep/cancel choice) are stored on your device and – with an active plan – synchronised with our database so that we can send reminders and show the list on your other devices. Legal basis: Art. 6(1)(b).
Reminders and service e-mails. Reminder e-mails before charges use your e-mail address, your reminder settings (on/off, 1–3 days before, time zone, language) and a log of reminders sent; you can switch them off in the app or with the link in every reminder. Push notifications are sent only if you allow them in your browser; we then store the push address and keys your browser creates, together with language, time zone, device type (phone/desktop) and whether NoBill is installed as an app. Some e-mails are part of the contract and are always sent: order confirmation, reminder before your free trial or intro week turns into a paid plan, reminder before a 3- or 12-month term ends, cancellation and withdrawal receipts, sign-in links and the confirmation of an account deletion. These are not marketing. Legal basis: Art. 6(1)(b); for push additionally your consent given in the browser, Art. 6(1)(a).
Help chat (part of the paid plan). The help chat is an AI assistant, not a human. Your messages are sent to our help-chat AI provider – Anthropic or, if enabled, DeepSeek (see section 4) – together with the subscriptions in your list (with Anthropic: service, amount, currency, cycle; with DeepSeek: service names only) to generate a reply. We do not store the content of chat messages – neither your questions nor the answers; the conversation history stays only on your device. For each message we keep only technical metadata linked to your account – length in characters, number of AI tokens, AI model and provider, language, time and whether the question was outside the chat's topic – for your daily AI limit and cost control. If DeepSeek is used, we send only your chat messages, with e-mail addresses, IBANs, card and phone numbers removed automatically, plus the names of the services in your list – no account ID, e-mail address, amounts, dates or screenshots. Legal basis: Art. 6(1)(b) and (f).
Usage statistics (our own, cookieless). To run and improve NoBill – which pages and steps are used, where people drop off, which campaigns work, what the service costs us – we record usage events on our own servers in the EU. No third-party analytics or tracking provider is involved, no cookies are used and nothing is stored on or read from your device for this purpose. We do not store your IP address: our server combines IP address, browser identification and language into a one-way hash using a random key that changes every day and is deleted at the end of that day, so visits cannot be linked across days or traced back to you.
- What we record: the page and funnel step, the action (e.g. quiz started, the option you chose in a multiple-choice question, plan selected), campaign parameters (utm tags, landing page, partner page), the domain of the website that referred you, the name of the ad network if you came from an ad (e.g. "google") – never the click ID itself, country (from our host's location header), device type, operating-system and browser family, language and a coarse screen-size range. For our AI features: success or failure and the amount of AI processing used – never the content.
- What we do not record: IP addresses, the full browser identification string, e-mail addresses, screenshots or their content, chat messages, payment data, precise location, advertising click IDs, or any identifier stored on your device.
- Customers with an active plan: events are linked to your account ID (not your e-mail address) so that we can support you and understand how the product is used (Art. 6(1)(b) and (f)).
Only a small number of authorised team members can see the statistics and customer records, and every access, export and deletion is logged. Legal basis: our legitimate interest in operating, securing and improving the service and measuring our marketing, Art. 6(1)(f) GDPR. You can object at any time (Art. 21) – write to us.
Contact and support. If you write to us, we process your message and contact details to reply. Legal basis: Art. 6(1)(b) or (f).
4. Providers and recipients
We use the following processors, bound by data processing agreements (Stripe partly acts as an independent controller):
| Provider | Purpose | Location / transfer |
|---|---|---|
| Vercel Inc., USA | Hosting of website and app, server logs | USA and EU edge locations – EU-US Data Privacy Framework / Standard Contractual Clauses |
| Supabase Inc. | Database (account, list, reminders, billing log, our own usage statistics) | EU region [TODO: confirm region] |
| Upstash Inc. | Rate-limit counters (pseudonymised keys), daily AI allowance per account ID, the daily key for our statistics hash | [TODO: confirm region – choose an EU region] |
| Anthropic PBC, USA | Screenshot analysis; help-chat answers when Anthropic is the chat provider | USA – EU-US Data Privacy Framework / Standard Contractual Clauses [TODO: verify] |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd., China (only if enabled) | Help-chat answers. Data: chat messages (with e-mail addresses, IBANs, card and phone numbers removed) and service names; no screenshots, no account data | China – no adequacy decision; [TODO: Standard Contractual Clauses + transfer impact assessment – lawyer] |
| Stripe Payments Europe Ltd., Ireland | Payments, fraud prevention, customer portal for payment methods and invoices | EU; transfer to Stripe Inc., USA – Data Privacy Framework / Standard Contractual Clauses |
| Resend (Plus Five Five Inc.), USA | Sending sign-in links, receipts and reminder e-mails | USA – Standard Contractual Clauses [TODO: verify DPF / region] |
| Cloudflare Inc., USA (only if enabled) | Bot check before scans (Turnstile) | USA – EU-US Data Privacy Framework / Standard Contractual Clauses |
| Your browser's push service (e.g. Google Firebase Cloud Messaging, Apple Push Notification service, Mozilla Push Service, Microsoft Windows Push Notification Services) | Delivering push notifications you allowed – the content of the notification passes through it encrypted | depends on your browser; may be outside the EU |
Fonts and service logos are served from our own server – no requests to Google Fonts or logo services. Apart from that we only disclose data where the law requires it (e.g. to tax authorities) or to our tax advisers and auditors, who are bound to confidentiality.
Transfers outside the EU/EEA rely on an adequacy decision (EU-US Data Privacy Framework, for certified recipients) or on the European Commission's Standard Contractual Clauses (Art. 45, 46 GDPR). If the help chat runs on DeepSeek, data is transferred to China, for which there is no adequacy decision [TODO: transfer basis – lawyer]. A copy of the safeguards is available on request.
5. Retention
We delete data automatically once the purpose ends; a daily job enforces the periods below.
| Data | Retention |
|---|---|
| Screenshots | Not stored by NoBill (only processed by the AI provider, see section 3). |
| Help-chat content | Not stored by NoBill; history only on your device. |
| Help-chat metadata, scan records | 13 months, or until your account is deleted. |
| Subscription list, reminder settings, reminders sent | Until you delete them or your account is deleted. |
| Push addresses | While active; 30 days after you switch push off or the browser invalidates it. |
| Account and contract data | For the duration of the contract. Accounts without an active plan and without any change for 13 months are deleted; accounts created by a checkout that was never paid after 30 days. |
| Billing log (payments, cancellations, withdrawals) | 10 years (statutory retention); on account deletion the e-mail address is removed from it. |
| Invoices and payment records at Stripe | According to Stripe's statutory retention duties. |
| Sign-in links; links in cancellation receipts | Valid 20 minutes (sign-in) or 30 days (receipt links); deleted 30 days after they expire. |
| Quiz answers and e-mail addresses without a confirmed marketing consent | 6 months. |
| Proof of a confirmed marketing consent | Until you withdraw your consent or ask for erasure [TODO: lawyer – limit, e.g. 3 years after the last contact]. |
| Usage statistics | Raw events 13 months, afterwards only aggregated daily counts that relate to no one; the daily hash key is deleted at the end of each day. |
| Rate-limit counters | Between one minute and 24 hours (expire automatically). |
| Server logs at our host | [TODO: period per Vercel plan/settings] |
| Admin access log | 24 months. |
| Data on your device | Until you sign out, delete it in NoBill or clear it in your browser (see the Cookies page). |
6. Security
- All connections use HTTPS with HSTS; a strict Content Security Policy limits which external services the site may contact.
- Card data is entered only in Stripe's payment form and never reaches our servers.
- Sign-in links and cancellation links are single-use; only a hash of each link is stored. Your session cookie is signed, inaccessible to scripts and can be revoked per device or on all devices.
- The database is accessed only from our server; access to customer data is limited to authorised team members and logged.
- IP addresses are not stored in our statistics; in our rate-limit store they appear only as keyed hashes that expire automatically.
7. Your rights and how to use them
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)).
Delete your account yourself: in the app under "Account" → "Delete my account". This erases your account, list, reminder settings, push devices, scan records, chat metadata, quiz answers and usage events linked to it; the billing log is kept without your e-mail address (statutory duty). A running plan must be cancelled first. You receive a confirmation by e-mail.
For everything else (e.g. a copy of your data as a JSON file) write to [TODO: Datenschutz-E-Mail, e.g. privacy@nobill.website] from the e-mail address of your account – that is how we verify that the request is yours; otherwise we may ask you to confirm it from that address. We answer within one month; in complex cases this can be extended by two further months, and we will tell you if so.
You can also lodge a complaint with a data protection authority (Art. 77 GDPR), in particular in the EU country where you live or work – e.g. in France the CNIL (www.cnil.fr), in Germany the authority of your federal state. Authority competent for us: [TODO: zuständige Datenschutz-Aufsichtsbehörde am Firmensitz].
8. AI, automated decisions, age and other information
We use AI systems to read screenshots and to answer questions in the help chat. Both are clearly labelled in the app; results can contain mistakes. There is no decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR): the AI only suggests list entries, which you check and edit, and answers questions.
Your e-mail address and payment details are required to take out a subscription; without them we cannot conclude the contract. Everything else is optional.
You must be at least 18 to take out a subscription. NoBill is not directed at children; we do not knowingly process data of people under 16.
What is stored on your device is explained on the Cookies page.
We update this policy when our processing changes; the date at the top shows the current version.