Parallel Systems · Last updated: June 15, 2026
Your receipt scans and shopping list stay on your device. Receipt scanning uses on-device OCR (Google ML Kit) — no images or text leave your phone. Your purchase history is stored on your device first and works offline; if you sign in as a Participant or Pro member, your purchases also sync to your account on our backend so they map to corporate ownership and follow you across devices. While you use billy as an anonymous Observer, nothing about your purchases leaves your device.
billy offers three levels of identity, each with different data handling:
| Tier | Identity | Data shared |
|---|---|---|
| Observer | No sign-in needed (anonymous session) | Your purchases, lists, and receipts stay on your device. Anonymous, aggregate usage and crash diagnostics may be recorded — no name, no email. |
| Participant | Google or Apple sign-in | An opaque participant ID for voting and proposals. Your email is used for authentication only and is never displayed or shared. |
| Verified (Pro) | Bank-linked via Plaid (optional) | For Pro members who choose to link a bank, we retrieve up to 24 months of transaction history (merchant, amount, date, category) to map your spending to corporate ownership data. Stored encrypted in our backend. See Bank account connections below. |
When you vote on campaigns, endorse proposals, or participate in community coordination, your actions are linked to an opaque participant ID. We never display your name or email to other users. Most community data is shown in aggregate; the exception is the text of statements you post on reasons boards, which is visible to your community (see Deliberation below).
billy collects anonymized, aggregate behavior signals to understand community demand patterns. These include: which alternatives users view, which swaps are tapped, and which searches return no results. These signals contain no user identity — they are anonymous counts used to help local businesses understand what communities need.
To prevent individual re-identification, demand signals in any community-and-category bucket are only displayed once at least five people have contributed to that bucket. Below the threshold, the bucket is hidden entirely — not shown as a low number.
When your community is thinking through a proposal, billy uses a Polis-style reasons board: people post short statements explaining their reasoning, and others react agree, disagree, or pass on each statement. The system surfaces which reasons cross groups and which divide them.
What we store on our servers when you participate:
Statements you post are public to your community by their nature. We don't show your email or name alongside them — only your opaque participant ID — but the text is visible to others. If you delete your account, your statements and reactions are removed from our servers within 30 days.
You can request deletion of a specific statement at any time by emailing privacy@abilli.app.
Linking a bank is an optional, Pro-only feature, and it is separate from receipt scanning. Receipt scanning always stays on your device (see Local-First Design above); bank linking is the one feature that does involve our server. To link a bank you must first be signed in with a Google or Apple (OAuth) account.
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Backend for community features | Opaque participant ID, votes, proposals, anonymous signals |
| Google Sign-In / Apple Sign-In | Authentication | Email address (for auth only, never displayed) |
| Google ML Kit | On-device receipt OCR | None — processing is entirely on your device |
| Open Food Facts | Product barcode lookup | Barcode numbers only |
| Plaid | Bank connection & transaction history (Pro, optional) | Securely connects your bank and retrieves up to 24 months of transactions (merchant, amount, date, category). Plaid handles authentication; we never receive your bank login. See Plaid’s end-user privacy policy. |
billy is not directed at children under 13. We do not knowingly collect any information from children.
billy does not display advertisements. We do not sell, rent, or share your personal data with any third party for marketing purposes. Our revenue model is based on businesses paying to be listed as local alternatives — not on your data.
We may update this Privacy Policy from time to time. Significant changes will be communicated via the app. The “Last updated” date at the top reflects the most recent revision.
Questions about privacy? Reach us at:
Your receipts stay on your device. Your purchases stay on your device too while you're an anonymous Observer; if you sign in, they sync to your account. Linking a bank (Pro, optional) stores your transaction history encrypted in our backend, deleted when you disconnect. Community contributions are shown under opaque IDs — never your name or email. No ads, no data sales, no third-party tracking. Ever.
See also: methodology · corrections
Parallel Systems · Gabriola Island, BC, Canada