Privacy Policy
Draft — pending legal review. This document describes the system as built and is awaiting sign-off by our Cyprus counsel before public launch.
StillPaying helps you find recurring charges hiding in your email. To do that, you connect your mailbox and we read billing mail only. This policy explains exactly what we access, what we keep, what we never keep, and how to remove it all.
1. Who we are
StillPaying is operated by Millennials Group Limited (company number HE 396314), registered in the Republic of Cyprus at Arch. Makariou III, 1, Mitsi Building 3, Floor 2, Flat/Office 202, 1065 Nicosia, Cyprus. We are the data controller for the personal data described here. Contact: privacy@stillpaying.io.
2. Google user data: what we access and why
When you choose Continue with Google, Google shows you a consent screen listing exactly what you are granting. We request these scopes and no others:
| Scope | What it allows | Why we need it |
|---|---|---|
openid, email, profile | Your email address and basic account identity | To create your account and know which mailbox results belong to |
gmail.readonly | Read-only access to Gmail messages and settings | To find receipts, invoices and renewal notices so we can list your recurring charges and their amounts |
We cannot send email as you, delete your mail, or modify your mailbox in any way. The read-only scope does not permit it, and we do not request any scope that would.
We do not read your whole mailbox
We do not download or index your inbox. We ask Gmail only for messages matching billing-shaped searches — Gmail's own “Purchases” category, and subjects or phrases such as receipt, invoice, renewal, payment confirmation, was charged and auto-renew — limited to the last 12 months. Personal correspondence that does not match those searches is never retrieved by our systems.
3. What we store — and what we never store
We never store the contents of your emails. A candidate message is fetched, analysed in memory, and discarded within seconds. Only the structured facts below are written to our database.
For each recurring charge we detect, we keep:
- The merchant name, the amount and the currency
- The date of the charge and the billing interval we inferred
- The Gmail message identifier (an opaque ID — not the message itself), so the same receipt is never counted twice
- A short excerpt (at most 300 characters) showing the line the amount came from, so we can explain a result and correct mistakes. It is encrypted at rest.
We also store your email address, your subscription status, and a log of every time our system accessed your mailbox (see §7).
Your Google credentials
Google gives us a token rather than your password — we never see, receive, or store your Google password. That token is encrypted with a key held in Google Cloud's key management service and is stored only in ciphertext. It is decrypted only inside a single isolated service that is not reachable from the public internet, and it is never written to logs or error reports.
4. Google API Services Limited Use disclosure
StillPaying's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without exception:
- We do not sell, rent, or trade Google user data.
- We do not use Google user data for advertising of any kind.
- We do not use Google user data to train generalised or public artificial-intelligence models. (See §5 for the narrow, per-message AI processing we do perform.)
- Humans do not read your mail. The only exceptions permitted by Google's policy are: with your explicit consent for a support request you initiate, where necessary for security purposes such as investigating abuse, or where required by law.
5. Automated processing (including AI)
Most receipts are read by our own rule-based parsers. When a billing email cannot be parsed that way — an unusual format, or a language our parsers do not cover — the text of that single message may be sent to our AI processor, Anthropic, to extract the merchant, amount and billing interval.
Anthropic processes that content solely to return the result to us. Under our commercial terms, that content is not used to train Anthropic's models. No message is sent to any AI system for advertising, profiling, or any purpose other than reading the billing facts of that one email.
6. Sharing and subprocessors
We do not sell your data or share it with advertisers. We use a small number of service providers that process data on our behalf under contract:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Cloud (EU) | Hosting, database, encryption keys | All stored data |
| Anthropic | AI reading of unparseable billing emails | The text of individual billing messages (§5) |
| Stripe | Subscription payments | Your email address and payment details (we never see card numbers) |
| Postmark | Sending alert and account emails | Your email address and the alert contents |
Our servers and database are located in the European Union (Belgium). Where a provider processes data outside the EU, that transfer is covered by Standard Contractual Clauses.
7. Access logging
Every time our systems access your mailbox, we write an audit record of what was requested and when. This lets us prove our access was limited to what this policy describes, and detect misuse. Audit records contain no message content.
8. How long we keep things
- Email contents: never stored — discarded within seconds of analysis.
- Charge records and your account: kept while your account is open, so we can show history and detect price rises.
- After you disconnect or delete your account: your access token is revoked immediately and all data derived from your mailbox is permanently deleted within 30 days.
- Payment records: retained as long as tax and accounting law requires.
9. Your rights
Under the GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. You can disconnect at any time — both from your StillPaying settings and independently from your Google account's third-party access page, which revokes our access instantly regardless of anything we do.
To exercise any right, email privacy@stillpaying.io. We respond within 30 days. You also have the right to complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or your local supervisory authority.
10. Cookies
We use one cookie: a signed session cookie that keeps you logged in. It contains an internal account identifier and your email address — no tracking identifiers. We do not use advertising or third-party tracking cookies.
11. Security
- All traffic is encrypted in transit (TLS) and all data is encrypted at rest.
- Access tokens are additionally encrypted with a separately managed key and isolated in a service with no public internet access.
- Automated scanning for vulnerabilities and leaked secrets runs on every code change.
- If a breach affects your data, we will notify you and the relevant authority as required by law.
12. Children
StillPaying is not directed at children under 16 and we do not knowingly collect their data.
13. Changes
If we change how we handle your data, we will update this page and, for material changes, email you before the change takes effect.