Biling
DeutschBack to Biling

Your data, clearly explained

Privacy policy

This policy explains how Biling handles data on this website and in the Biling app. Last updated 14 August 2026.

01

Controller

Conformitas Legal GmbH, Gutenbergstraße 12, 64319 Pfungstadt, Germany. Contact: hello@biling.app.

02

Optional product analytics

Only after your affirmative permission, we use PostHog EU Cloud to understand aggregate product use and reliability. We send product-event names and limited technical context such as website or app surface, production environment, platform, app version, interface language, account state, plan, sanitized page path, and coarse campaign attribution. PostHog is a processor and data is hosted in the EU.

03

What analytics never contains

We do not send audio, transcripts, translations, names, email addresses, conversation topics, glossary entries, search text, OAuth data, guest tokens, payment credentials, exception text, stack traces, or private-conversation activity. Session replay, autocapture, surveys, heatmaps, and automatic exception capture are disabled.

04

Legal basis and storage

The legal basis for optional analytics is your consent under Article 6(1)(a) GDPR and, where device access is involved, Section 25(1) TDDDG. Before a decision, we store only the decision and policy version needed to remember your choice. The planned raw-event retention is 12 months, subject to final review.

05

Withdrawal

You can decline without losing any functionality. Use Privacy settings at the bottom of any website page, or the Analytics preference in the app, to withdraw with one action. Withdrawal stops future analytics and resets the analytics identity.

06

Operational processing

Authentication, billing, fraud prevention, translation, waitlist delivery, and necessary service security logs operate independently of optional analytics. Their processing is limited to providing and protecting Biling.

07

Account deletion

You can permanently delete your account in the app. This deletes the Auth account, profile, cloud conversations, usage sessions, shared sessions, and the Biling analytics person and events where analytics consent existed. Conversations stored locally with that account as their owner are also deleted. Unrelated device-only data and general app preferences remain.

08

Introductory-credit protection

To prevent the same login identity from repeatedly redeeming introductory minutes, we retain an indefinite keyed HMAC fingerprint after account deletion. The fingerprint is created from a normalized verified login identity with a secret held only on our backend. We do not retain the raw email address or provider identifier with this marker, cannot use the marker to contact you, and use it only to decide whether introductory minutes were already redeemed.

09

Billing records

Where legally required, immutable financial and billing records may be retained after deletion. The Auth-user link is removed, and no profile, email address, or recoverable login identity remains attached to those anonymized records.

10

Sign in with Apple

For new Apple sign-ins, Biling securely exchanges the one-time authorization code and stores the Apple refresh token encrypted so Apple authorization can be revoked during deletion. If a legacy account has no stored revocation credential, Biling still deletes the complete account immediately and shows instructions for choosing Stop Using Apple ID in Apple Account settings.

11

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time and complain to a competent data protection authority. Contact hello@biling.app to exercise these rights.

Optional product analytics

May we use privacy-focused PostHog EU analytics to understand which Biling features are useful? We do not record conversations, advertising profiles, or session replays.