Effective April 6, 2026, last updated August 28, 2026

Privacy Policy

This Privacy Policy explains how QuietBill collects, uses, and protects your personal data. For the full terms governing your use, see our Terms & Conditions.

1. Who We Are

  • QuietBill is operated by Oleh Reznichenko as an individual sole trader. When this policy says "we," "us," or "our," it refers to Oleh Reznichenko.
  • Contact: nonlimit@proton.me

2. Data We Collect

  • Account information: name, email address, timezone, and authentication identifiers (GitHub OAuth, Google One Tap, passkeys/WebAuthn, or magic link).
  • Session security data: IP address and browser user agent, stored with your login sessions for abuse prevention.
  • Organization and team data: organization name, membership roles, and invitation records (inviter, invitee email, status).
  • AWS integration data: Role ARNs, External IDs, resource inventory (service and resource names), and cost and usage data retrieved from your AWS accounts via the Service.
  • Notification channel identifiers: Telegram chat ID, Slack workspace and channel metadata, email address used for alert delivery, and email notification preferences.
  • Billing records: subscription plan, payment status, and transaction references managed through our billing provider.
  • Alert history: cost anomaly alerts, daily summaries, CloudTrail event notifications, and AI-generated explanations generated on your behalf. Where a CloudTrail event names the IAM user or role that performed an action in your AWS account, that attribution (the name only, never the full ARN) appears in the alert text and is stored with it.
  • Support conversations: if you link the Telegram support bot, we keep the chat link and conversation routing data for up to 90 days.
  • Usage data: pages visited and feature interactions, collected through product analytics.

3. Data We Do Not Collect or Store

  • AWS credentials are never persisted. We access your AWS account through short-lived STS session tokens obtained via AssumeRole. Tokens are held in memory only for the duration of the API call and expire automatically within 1 hour.
  • We do not collect payment card numbers, bank account details, or other financial instrument data. All payment processing is handled by our billing provider (Merchant of Record).
  • We do not sell, rent, or trade your personal data to third parties.

4. How We Use Your Data

  • Authenticate you and manage your account. Lawful basis: performance of our contract with you (Art. 6(1)(b) GDPR).
  • Manage organization membership, team invitations, and role-based access within your organization. Lawful basis: contract (Art. 6(1)(b)).
  • Connect and monitor your AWS accounts for cost anomalies, usage trends, and resource events, and generate and deliver alerts to the channels you configure. Lawful basis: contract (Art. 6(1)(b)). Where alerts attribute an infrastructure change to an IAM user or role in your account, the basis is our and your legitimate interest in knowing who changed your infrastructure (Art. 6(1)(f)), balanced by storing only the principal's name and capping retention at 18 months.
  • Operate billing and subscription management. Lawful basis: contract (Art. 6(1)(b)); legal obligations for tax records rest with our Merchant of Record.
  • Prevent abuse, enforce our Terms, and maintain security. Lawful basis: legitimate interest in keeping the Service secure (Art. 6(1)(f)).
  • Respond to support requests. Lawful basis: contract (Art. 6(1)(b)).
  • Improve the Service through product analytics and feedback tools. Lawful basis: legitimate interest in improving a low-volume business product (Art. 6(1)(f)), balanced by cookieless collection, no stored IP addresses, and no session recording. You may object at any time (see section 9).
  • Send product onboarding emails. Lawful basis: legitimate interest (Art. 6(1)(f)), with a one-click unsubscribe in every such email.

5. Sub-Processors and Third-Party Services

  • Vercel — application hosting, edge delivery, the AI Gateway that routes our AI requests, and Vercel Web Analytics (see section 6).
  • AI model providers, reached only through Vercel AI Gateway: OpenAI, Google, xAI, and Z.ai. Prompts contain account display names, AWS resource names, cost figures, and event summaries, never your name, email, or login data. All AI requests are routed with prompt training disallowed, so providers that train on inputs are excluded.
  • Turso / LibSQL — primary database.
  • Upstash Redis — caching and rate limiting.
  • Trigger.dev — background job processing (cost checks, alert delivery, lifecycle tasks).
  • Telegram — alert delivery to Telegram channels you configure, and the optional support chat bot.
  • Slack — alert delivery to Slack workspaces you configure.
  • Google Chat — alert delivery to Google Chat spaces you configure.
  • Resend — transactional and alert email delivery.
  • Creem — billing infrastructure and Merchant of Record (collects and remits VAT/GST/sales tax). For payment and tax data, Creem acts as an independent controller.
  • UserJot — in-app feedback widget (receives your name and email so we can follow up on feedback).
  • Better Auth infrastructure services — authentication security (suspicious sign-up detection and bot protection, which process IP addresses).
  • Each sub-processor receives only the minimum data necessary to perform its function. We will notify account holders at least 30 days before adding or replacing a sub-processor that processes personal data.

6. Analytics and Error Monitoring

  • Vercel Web Analytics — product analytics. Tracks aggregate page views to improve the Service. Cookieless, does not identify you or your account (no name or email attached), and does not store IP addresses.
  • We do not use session replay or screen recording.
  • We do not use third-party error monitoring that receives your data.

7. Cookies and Session Management

  • We use only cookies that are strictly necessary to sign you in and keep your session secure. All are scoped to .quietbill.dev and configured as HttpOnly, Secure, and SameSite.
  • Session token cookie: keeps you signed in, expires after 7 days of inactivity.
  • Session cache cookie: a short-lived (5 minute) encrypted copy of your session that avoids a database read on every request.
  • Sign-in state cookies: short-lived values used during OAuth and passkey sign-in flows to prevent cross-site request forgery. They expire within minutes.
  • Authentication is managed by BetterAuth on our own infrastructure.
  • We do not use analytics cookies (our analytics is cookieless), third-party advertising cookies, or cross-site tracking cookies. Because no non-essential cookies exist, the Service does not show a cookie banner.

8. Data Retention

  • Account records, connected account metadata, and billing records are retained while your account is active.
  • Alert history is retained for 18 months, then automatically deleted.
  • Disconnected AWS accounts are soft-deleted immediately and permanently deleted 30 days later.
  • Support chat sessions expire after 90 days. Short-lived cache entries are stored with operational TTLs in caching infrastructure.
  • When you delete your account (via Settings → Danger Zone or by emailing nonlimit@proton.me), operational data is removed, including support sessions and sign-in verification records. Your profile at our feedback vendor (UserJot) is deleted within 30 days of account deletion. Our analytics (Vercel Web Analytics) never stores a profile tied to your account, so there is nothing to delete there. Backups are retained for up to 30 days, after which data is permanently purged.

9. Your Rights

  • Access: You may request a copy of the personal data we hold about you.
  • Correction: You may request correction of inaccurate personal data.
  • Deletion: You may delete your account at any time via the in-app offboarding flow, which removes all Customer Data subject to the 30-day backup retention period. An active subscription is cancelled automatically as part of deletion; no billing steps are required first.
  • Data portability: You can download your data as JSON at any time from Settings (Download your data), or request it by email.
  • Objection and restriction: You may object to or request restriction of specific processing.
  • To exercise any of these rights, contact nonlimit@proton.me. We will respond within one month, extendable for complex requests as GDPR allows (we will tell you if so). If you are in the EU or UK, you also have the right to lodge a complaint with your local supervisory authority.

10. International Data Transfers

  • The Service relies on infrastructure and vendors that operate across multiple regions. Your data may be processed outside Ukraine or your home jurisdiction.
  • Where personal data of EU or UK residents is transferred to countries without an adequacy decision, we protect it with Article 46 safeguards, principally the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for the UK, the UK Addendum, as incorporated in our vendors' data processing agreements. We are completing SCC coverage across all vendors; current status is available on request.
  • Business customers can request a data processing agreement with us (incorporating SCCs, with Ukraine as the importing jurisdiction) at nonlimit@proton.me.

11. Children's Privacy

  • QuietBill is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact nonlimit@proton.me and we will delete it.

12. Changes to This Policy

  • We may update this Privacy Policy as the product and legal requirements evolve. For material changes, we will provide at least 14 days' notice by email or in-product notification before the new policy takes effect.
  • Continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact

For privacy-related questions, data access requests, or deletion requests, email nonlimit@proton.me.

QuietBill — operated by Oleh Reznichenko