Privacy policy

Your bill, our promises.

This is the plain-English version of our privacy policy. We’ve tried to write it the way we’d explain it at a bus stop — no jargon, no get-out clauses.

Last updated: 27 April 2026Effective from: 27 April 2026Version 1.0
The short version

1. Who we are

BillLuma is currently operated by Gaurav Srivastava, a sole trader trading as BillLuma. We’re based in India and we serve UK households.

We’re the data controller for the personal information described in this policy — that means we decide what’s collected and what happens to it.

Later in 2026 we plan to incorporate as BillLuma Ltd, a UK limited company. When that happens, we’ll update this policy and email anyone on our mailing list to let them know.

We’re registered with the UK’s Information Commissioner’s Office under registration number (pending — to be added once issued).

2. What we collect

We collect different things at different points. Here’s the full list.

When you upload an energy bill

When you give us your email

When you visit the site

3. What we don’t collect

To be specific:

4. Why we collect it

UK GDPR requires us to have a lawful basis for using your data. Here are ours, by data type.

5. How long we keep it

6. Who else sees it

BillLuma is built on a small set of services, each chosen for a specific job. Every one of them is bound by a data processing agreement that limits what they can do with your data. Here’s the full list.

ServiceWhat it doesWhereWhat it sees
VercelHosts the websiteUSAPage traffic and request metadata
SupabaseDatabase and accountsFrankfurt, EUEmail address and the five anonymised fields
AnthropicReads the bill (AI parser)USABill content, in transit only — never stored, never used for training
ResendSends our emailsIreland, EUEmail address, send and delivery events
UpstashRate-limits abuseEUHashed IP address for 24 hours
PlausibleAnonymous analyticsEUPage visits and country — no IP, no cookies
CloudflareEmail routing for hello@billluma.co.ukDistributedInbound email metadata and contents
About the AI parser. When your bill is sent to Anthropic for reading, we attach a header called anthropic-no-store. This instructs Anthropic not to keep the data for any purpose, including training their models. The bill exists in their systems only for the seconds it takes to extract the five fields.

We don’t sell your data. We don’t share it with advertisers, brokers, or anyone outside the list above.

7. International transfers

Two of our processors — Vercel and Anthropic — are based in the United States. The bill content is therefore briefly processed in the US during the parse, and our website traffic is served from US infrastructure.

These transfers are covered by the UK’s International Data Transfer Addendum (IDTA) and the EU’s Standard Contractual Clauses (SCCs), which are the legally-recognised mechanisms for moving personal data outside the UK and EU.

BillLuma itself is operated from India. The personal data we hold (your email and the five anonymised fields) lives in our EU-region database — it doesn’t sit on a laptop in Delhi.

8. Your rights

Under UK GDPR you have the following rights, free of charge:

To use any of these, email hello@billluma.co.uk and we’ll respond within 30 days. We won’t ask for ID unless we genuinely can’t verify it’s you — and even then, we’ll ask for as little as possible.

9. Cookies and tracking

We don’t use tracking cookies, advertising cookies, or any third-party tracker.

The only cookies on the site are essential session cookies from Supabase that keep you logged in if you have an account. These are exempt from consent rules under PECR because they’re strictly necessary to deliver the service you’ve asked for.

Plausible, our analytics tool, is cookieless by design. Which is why you don’t see a consent banner — there’s nothing to consent to.

10. Children

BillLuma is for UK adult households. We don’t knowingly collect personal data from anyone under 18. If you think a child has used our service or given us their email address, please email hello@billluma.co.uk and we’ll delete it immediately.

11. Changes to this policy

If we change anything material — particularly anything that affects what we collect, how long we keep it, or who else sees it — we’ll do two things:

  1. Email everyone on our list with a plain-English summary of what’s changing and why.
  2. Post a notice on the site for at least 30 days before the change takes effect.

Small clarifications and typo fixes will just appear in the next version, with the date updated at the top.

12. Contact and complaints

For anything privacy-related — questions, requests, complaints, the lot:

Email us first

hello@billluma.co.uk

We aim to reply within three working days, and we’ll always acknowledge your message even if a full response takes longer.

Not happy with our response?

You have the right to complain to the UK’s data protection regulator. They are:

The Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Web: ico.org.uk

You’re welcome to go to them directly — but if you give us a chance to put it right first, we’ll do our best to.