← BillLighter

Privacy in the current beta

Last updated: 8 September 2026.

Who runs BillLighter

BillLighter is a Hammant Labs project operated by Jon Hammant. Contact jon@hammant.io about your information or this beta.

Try an audit without an account

The anonymous audit on the home page processes the bill entries and usage answers in your browser tab. Those entries are not sent to our server or an AI provider. Export the report to keep it; refreshing or closing the tab clears it.

Choose to save your audits

When account access is available and you choose to create a household, we store your sign-in identifier, household currency, consent record, normalised bill entries and usage answers. The pasted import text is processed to create your bill entries and is not retained. Saved audits stay in your account until you delete the audit or account. We use this information to provide the saved-audit service you request.

Reviewing provider support

Service names from saved bills also enter a private support review queue, together with a market hint from your household currency. Authorised operators can review those labels and counts of distinct households to decide which services to support. We do not copy bill amounts, usage answers or email and chat content into this queue. Labels may contain personal information if you enter it, so use service names without account numbers or personal details. An unrecognised label is not automatically published in the shared provider catalogue or sent to an AI model. Deleting the saved bill or account removes its queue entry and its contribution to future counts.

Sign-in and processors

Clerk provides email-code sign-in and processes your email address, verification and session information. BillLighter does not ask you to create a password. Railway hosts the website, saved data and background worker. These providers process ordinary connection and security information to operate their services and may process information outside your country under their applicable data protection terms. Their information is available at Clerk privacy and Railway privacy.

Negotiation walkthrough

If you try a saved example case, we store its fictional bills, case timeline, example offers and your approval decisions so you can leave and return. The walkthrough does not contact a real provider, use a provider password, submit data to an AI model or take a payment.

Optional learning from outcomes

The results page separates offers, approvals and savings verified against subsequent bills. You may explicitly choose to let your real results contribute to grouped provider estimates and reviewed negotiation improvements. This analytical record uses prices, terms, provider/product/country, outcomes and execution cost where known. It excludes raw emails, chats, names and account numbers. The source record remains linked to your household for access, withdrawal and deletion; it is not an anonymous source record. Grouped estimates require at least 20 distinct participating households and are internal in this beta. Fictional examples never qualify. Withdrawing excludes your results from future calculations, while previously reviewed strategy versions are not automatically reversed.

Email, provider accounts and payments

Mailbox scanning, live provider browsers, AI negotiations and charging are not enabled in this release. Connecting a mailbox or provider account will require a separate choice and an updated notice before those features launch. We do not sell your data or use bill entries to train a general AI model.

Export and deletion

Your account has export and deletion controls protected by fresh sign-in verification. Deleting your account removes active household bills, examples and approvals and starts deletion of your Clerk identity. A minimal deletion record and opaque sign-in identifier are retained to prevent an old session recreating the account and to track processor cleanup. Infrastructure backups and provider security logs may age out separately under the providers’ retention terms; we do not promise instantaneous removal from every backup.

Website requests

No session replay or behavioural analytics is installed. Authentication uses necessary cookies. Fonts are currently requested from Google Fonts, which receives ordinary network request information. Avoid putting personal details in URLs.

Your choices

You can use the anonymous audit, correct usage answers, export saved information, delete an audit or request account deletion. Contact us for access, correction or deletion help. You may also contact your local data protection authority, including the UK Information Commissioner’s Office.