Byllo
Privacy policy
Byllo is local-first. Your bills and money live on your device, not on our servers.
Last updated: 27 July 2026
The short version: your financial data lives on your device. Byllo works without an account, doesn’t sell data, and doesn’t show ads. This website sets no cookies and runs no analytics — the only thing it collects is an email address, and only if you type one into the waitlist form.
The sections below spell that out precisely.
1. Who we are
This policy covers the Byllo app and this website, bylloapp.com. Byllo is an independently built app; “we” and “us” mean the people behind Byllo. You can reach us any time at therestlessmallu@gmail.com.
Byllo has not launched yet. The sections about the app describe how it is built and how it will behave when it ships; the sections about this website describe how it works today.
2. What Byllo is
Byllo is a personal bills-and-money companion. You add bills, income, loans, and money lent or borrowed; Byllo reminds you, shows what’s safe to spend, and helps you stay on top of things calmly.
3. This website
The site you’re reading is a set of static pages. There are no accounts, no cookies, no analytics scripts, no advertising pixels, and no trackers of any kind. Three things are still worth naming honestly:
- The waitlist form. If you enter your email address to hear about launch, that address passes through FormSubmit, a form-relay service whose only job is to deliver it to our inbox. It then lives in our email, nowhere else — there’s no database and no mailing-list tool behind it. We use it for one purpose, to tell you when Byllo is available, and we don’t sell it, share it, or add you to any other list. Ask us and we’ll delete it; see Data deletion.
- Hosting. The site is hosted on Vercel, which keeps routine server logs — including IP addresses — for security and reliability, as any web host does.
- Fonts. The page loads the Inter typeface from Google Fonts, so your browser makes a request to Google’s servers, which reveals your IP address to them. Nothing else about you is sent.
4. Data you put into Byllo — stored on your device
Everything you enter in the app (bills, amounts, due dates, income, loans, lent/borrowed records, the account balance you type during a balance check, notes, settings) is stored locally on your device in the app’s private storage. By default:
- No account is required to use Byllo.
- We do not upload, sync, or receive this data. It never reaches our servers, because there are none for your financial data.
- Deleting the app deletes this data — see Data deletion.
5. SMS on Android (optional, consent per message)
On Android, Byllo can offer to capture a bill or expense from a bank SMS. This uses Android’s SMS User Consent API, which means:
- Byllo cannot read your inbox. The system shows you a prompt for one specific message, and Byllo sees that message only if you tap Allow — every single time.
- The message is parsed on your device to pre-fill a bill or expense. It is never uploaded, stored in raw form, or used for any other purpose.
- Declining changes nothing; SMS capture is a convenience, not a requirement.
- On iOS this feature does not exist; entry is manual.
6. Optional services you can choose to connect
- Export to Google Drive: if you choose Drive as an export destination, you’ll be asked to sign in to Google at that moment — never before. Byllo requests the narrowest scope needed to save the export file you asked for. We do not read your Drive contents.
- Export to iCloud (iOS): uses your device’s existing Apple account; we receive nothing.
- CSV share: uses your device’s share sheet; the file goes wherever you send it.
7. Notifications
Reminders are scheduled locally on your device. We don’t operate a push server for reminder content. You can change or disable reminders in Settings or in your system settings.
8. Purchases
Subscriptions and any one-time purchases are processed by the Apple App Store or Google Play. We never see or store your card details. The stores share limited, non-card transaction information with us — for example, that a subscription is active — so the app can unlock Pro features. Manage or cancel any subscription in your store account settings.
9. Third-party services inside the app
Byllo uses a small number of standard services. None of them receive the financial data you enter:
- Firebase Crashlytics (crash reporting) — collects crash logs and device information so we can fix what broke.
- Firebase Analytics (product analytics) — records which features are used, so we know what to improve. It never collects the bills, amounts, or balances you enter.
- RevenueCat (subscription infrastructure) — keeps track of whether a Pro subscription is active, so your purchase works across your devices.
10. What we don’t do
- We don’t sell or rent your data. There is nothing to sell — your financial data stays on your device.
- We don’t show ads, and don’t share data with advertisers or data brokers.
- We don’t use your data to train AI models.
11. Children
Byllo is a personal-finance tool intended for people aged 13 and over. It is not directed at younger children, and we do not knowingly collect personal information from them. If you are under 18, please check with a parent or guardian before giving us your email address on this site.
If you believe a child has sent us personal information, write to therestlessmallu@gmail.com and we’ll delete it.
12. Your rights and choices
Because your data is on your device, you are in direct control: you can view, edit, export (CSV, iCloud, or Drive), or delete everything from within the app, or by deleting the app. The only thing we might hold is a waitlist email address, and you can have that removed at any time.
Depending on where you live — for example under India’s DPDP Act 2023, the GDPR in the EU, or the CCPA in California — you may have additional statutory rights, such as access, correction, or erasure. For anything you can’t already do yourself, contact therestlessmallu@gmail.com.
13. Security
Data is stored in the app’s private, OS-protected storage. You can additionally enable a device-level app lock in Settings. No method of storage is 100% secure, but keeping your data off servers removes the largest risk surface.
Found a vulnerability? Email therestlessmallu@gmail.com with “SECURITY” in the subject line, rather than posting it publicly. Tell us how to reproduce it, which app version and OS you saw it on, and the impact as you understand it. We’ll acknowledge within 72 hours, keep you updated, and credit you in the release notes if you’d like — or keep you anonymous.
14. Changes to this policy
If we change this policy, we’ll update the date at the top of this page and, for material changes, tell you in the app before they take effect.