Trust and privacy
Bill Calendar Privacy Policy
This policy explains what BUPARK LLC handles when you visit bill-calendar.com or use Bill Calendar, why it is handled, and the controls available to you.
Effective and updated: July 14, 2026
Information you provide
You may provide account information such as an email address and authentication credentials, bill names, dates, expected amounts, recurrence, notes, payment-status evidence, notification preferences, and support messages. Passwords are stored using a one-way password hash rather than readable text.
Guest bills remain in the browser storage of the device where they were created. If you sign in and choose server sync, eligible bill data and preferences are stored for your account. Avoid placing bank credentials, full payment-card numbers, government identifiers, or other unnecessary sensitive data in bill names or notes.
Information generated through use
The service and its infrastructure process technical information needed to operate securely and reliably, such as request time, IP address, browser or device characteristics, requested route, response status, session and security records, and bounded error or performance information. This operational information is used to deliver requests, diagnose failures, prevent abuse, and maintain the service. When privacy-safe product analytics are enabled, Bill Calendar accepts only allowlisted product milestone information rather than arbitrary bill names, amounts, bank data, email addresses, tokens, or free-form notes. Allowlisted analytics events are retained for no more than 90 days and can be disabled in account preferences.
Connected banks and Plaid
If you choose an available connected-bank feature, Plaid provides the connection experience. Bank credentials are entered into Plaid Link and are not collected by Bill Calendar. Bill Calendar receives authorized connection and transaction information needed to identify potential recurring items and maintain the connection. Plaid access tokens are encrypted at rest on the server and are not returned by the connected-bank API.
To provide an authorized connection, Plaid may collect account-holder contact information, such as name, email address, phone number, and postal address, together with account and balance details required by its Transactions product. Bill Calendar does not receive those Plaid contact fields or unmasked account or routing numbers. Plaid handles that information under its End User Privacy Policy.
You can disconnect an eligible bank connection from the service and may also use the Plaid Portal. Disconnecting does not necessarily delete data that must be retained for security, legal, dispute, or system-integrity purposes, and does not alter a financial institution's own records.
Subscriptions and payment providers
Premium purchases may be handled by the checkout or app-store provider shown to you, such as Stripe or Apple. Those providers collect payment credentials under their own policies. Bill Calendar receives purchase, subscription, entitlement, and transaction identifiers needed to confirm access, prevent fraud, reconcile provider events, and provide support. Bill Calendar does not receive a full payment-card number from those hosted purchase flows.
Google advertising on the website and iOS app
On bill-calendar.com, Google-served AdSense ads are limited to eligible, substantive public guide articles. The interactive web application, login and account screens, navigation, alerts, forms, empty states, privacy, terms, support, and about pages do not include an AdSense placement.
In the Bill Calendar iOS app, confirmed Free-plan users may see a Google AdMob banner in eligible main app views. Premium users and users whose entitlement is still being resolved do not generate an ad request. The app asks Google's User Messaging Platform for the applicable privacy choice and does not request an ad until Google reports that ads may be requested. Publisher ad personalization and publisher first-party identifiers are disabled. Bill Calendar does not request App Tracking Transparency permission or intentionally access Apple's advertising identifier for cross-app tracking. Google may still process app- or developer-bounded device identifiers, IP-derived coarse location, diagnostics, ad-interaction data, and advertising data to serve ads, prevent fraud, cap frequency, and produce aggregated measurements.
Third-party advertising vendors, including Google, may use cookies and related identifiers to choose and measure ads using a visitor's earlier visits to bill-calendar.com or other websites. Google advertising cookies allow Google and its partners to select ads using visits to this site and other sites on the Internet. These technologies may also limit repeated ads, detect fraud and abuse, and support personalized advertising where permitted and selected.
Advertising technology may use web beacons, pixel tags, device or browser information, and IP address information to deliver and measure ads and understand interactions. An IP address may be used for approximate location and security purposes. Availability of personalized or non-personalized advertising depends on applicable requirements and consent choices.
You can opt out of personalized advertising through Google Ads Settings. Other third-party vendors or ad networks may serve or measure ads through Google and may use their own cookies; review Google's current ad technology partner information and the privacy or opt-out information linked for each vendor. Where available, the Digital Advertising Alliance opt-out page provides additional choices for participating companies.
Learn how Google uses information from sites and apps that use its services at How Google uses information from sites or apps that use our services. Browser controls may also let you delete or block cookies, although doing so can affect site functions and advertising preferences.
iOS app data and notifications
The iOS app may process an account email address and user ID; bill and other user-entered content; connected-bank recurring-item information; purchase and entitlement history; an installation or device identifier used for sync and notification delivery; and limited product-interaction events when account analytics is enabled. These categories are linked to the signed-in account when needed to provide the feature and are not used by BUPARK LLC to track users across other companies' apps or websites.
If you enable remote notifications, the app and service process an Apple Push Notification service device token, the owning account identifier, delivery state, and notification preferences. Notification permission can be changed in iOS Settings, and available Bill Calendar notification and analytics preferences can be changed in Profile. Product analytics uses fixed event, surface, and outcome categories rather than bill names, amounts, bank credentials, or free-form notes, and stops when the account analytics preference is disabled.
How information is used
- Provide calendar, sync, reminder, subscription, support, and connected-bank features you request.
- Authenticate accounts, maintain sessions, enforce entitlements, and protect the service from abuse.
- Process user-reviewed changes and keep data consistent across supported devices.
- Diagnose failures, measure reliable operation, and improve product workflows.
- Comply with law, enforce terms, and respond to valid legal process.
Sharing and service providers
BUPARK LLC uses service providers to operate hosting, email delivery, subscriptions, bank connectivity, notifications, security, and advertising. They receive information needed for their role and process it under their own terms or agreements. Information may also be disclosed when required by law, to protect users or the service, during a business transaction subject to appropriate safeguards, or with your direction.
We do not ask users to send passwords, bank credentials, Plaid access tokens, or full payment-card numbers through support email.
Retention and deletion
Retention depends on the data and its operational purpose. Active account and bill data is kept while needed to provide the service. Security, subscription, notification, sync, support, and provider records may be kept for bounded periods needed for service operation, reliability, reconciliation, abuse prevention, legal obligations, or dispute handling. The current operational policy limits allowlisted analytics events to 90 days. Provider and financial-institution records are controlled by those providers.
Account deletion from Profile revokes sessions and schedules server-side deletion. Some provider cleanup can continue asynchronously so that disconnection and subscription obligations are handled safely. A privacy deletion request does not automatically cancel an external subscription. App Store subscriptions must be canceled separately through Apple settings, and other hosted subscriptions must be managed through the applicable provider controls.
Your controls
Current product controls let you update or delete individual bills, change available notification and analytics preferences, sign out, revoke supported sessions, disconnect an eligible bank connection, manage synced account data, and request account deletion. Account deletion removes the Bill Calendar account and associated service data covered by the deletion flow after required verification; limited records may be retained where needed for security, legal obligations, fraud prevention, subscription reconciliation, or dispute handling. You can manage an App Store subscription through Apple subscription settings. Deleting the account does not cancel that external subscription. For account-level access, correction, or deletion assistance, email the privacy contact below. We may verify your identity and handle the request subject to applicable law, security needs, and provider or record-retention obligations.
Security and international processing
We use administrative and technical safeguards intended to protect information, including one-way password hashing, hashed server records for session and recovery tokens, secure session controls, access controls, encryption for sensitive provider tokens, and HTTPS in production. No online service can promise absolute security. Information may be processed in the United States and other locations where service providers operate, subject to applicable protections.
Policy changes and contact
We may update this policy as the service, providers, or legal requirements change. The date at the top shows the latest published version. Material changes may also be communicated in the service when appropriate.
Privacy contact and editorial owner: BUPARK LLC, Washington State, United States. Email support@bill-calendar.com. Updated July 14, 2026.