Trust & Security

Your invoices are yours.
We just help you make sense of them.

Handing invoice data to an outside tool is a big ask. Here is exactly how we protect it, who can see it, and how you stay in control at every step.

Our promises

Eight commitments, in plain English

Each of these is enforced by our architecture — not just a policy statement. If any of these ever stop being true, we will notify every customer by email within 24 hours.

Your data is encrypted end-to-end

TLS 1.2+ in transit, AES-256 at rest. Passwords are bcrypt-hashed — even we cannot read them. Backups are encrypted and rotated on a 30-day cycle.

Hosted in India

Primary database and file storage are hosted in India-region infrastructure. Your bills stay under Indian data-protection law (DPDP Act, 2023).

Every support access is logged and visible to you

If our team ever opens your workspace for support, we record who, when, why, and whether sensitive fields were revealed. You see this list in Settings → Privacy → Access Log — no hidden peeks.

Sensitive fields are masked by default

When support views your workspace, GSTIN and invoice amounts are automatically masked into ranges (e.g. "₹10k–50k"). Full unmasking requires an explicit written reason — also logged.

One-click delete. Zero questions.

Settings → Danger Zone → Delete My Data wipes every bill, vendor, invoice, and staff record we hold for you. Backups are purged within 30 days.

Multi-tenant isolation, always

Every query in our backend is scoped to your workspace by design. Other users on Ease My Bill literally cannot see, search, or reference your data — enforced at the database layer.

Immutable audit log for every account action

Logins, exports, deletions, password changes, and admin access are appended to a tamper-evident log inside your workspace. Auditors and CAs can review it any time.

We never share, sell, or train on your data

No third-party advertising trackers. No AI model training. Our AI provider processes your bills under API terms that explicitly forbid training on your inputs.

How we are built

The path your bill takes

  1. 1
    You upload a bill (photo or PDF)
    Transferred over TLS 1.2+. We generate a per-file SHA-256 hash so duplicate uploads are detected without keeping copies.
  2. 2
    The file lands in your isolated tenant workspace
    Every backend query is scoped by owner_email. There is no unscoped code path that reads bills across tenants — enforced by the ORM layer.
  3. 3
    OCR runs on our AI provider (API tier — no training)
    The image and a strict prompt are sent to our AI over a private API. The API terms explicitly prohibit training on this input. The response returns to us and never leaves your workspace.
  4. 4
    Extracted data stored in your workspace, encrypted at rest
    MongoDB Atlas (India region) with AES-256 disk encryption. Original bill images stored in GridFS with the same encryption.
  5. 5
    Only you and your invited team see it
    Support access is opt-in and audited. Every read by our team creates an entry in your Access Log (Settings → Privacy) with reason and timestamp.
You stay in control

Four self-serve tools inside the app

Access Log
See every time our support team viewed your workspace, with the exact reason.
Export Everything
Excel, Tally XML, JSON — one click, no format lock-in.
2FA & Session Control
Enable TOTP-based two-factor login and revoke sessions from any device.
Delete My Data
Wipe your entire workspace with a single confirmation. Backups purged within 30 days.
Common questions

Answers we hear most often

Can Ease My Bill employees see my invoices?

Only under two conditions: (1) you explicitly enable support access, or (2) a support engineer opens your workspace with a documented reason — which is recorded and shown to you in Settings → Access Log. Amounts and GSTIN are masked into range buckets by default. Nothing else, no other path.

Where is my data stored?

MongoDB Atlas (India region) for structured data, GridFS-backed object store for original bill images/PDFs. Both encrypted at rest with AES-256. We prefer India-region infrastructure everywhere possible.

What happens if I stop using Ease My Bill?

Deactivate anytime — no cancellation fee. Your data remains accessible for 90 days so you can export it. After 90 days, it is permanently deleted from primary storage and rotates out of backups within another 30 days. Or use Delete My Data to nuke it immediately.

Do you train AI models on my invoices?

No. Our AI provider operates under API-tier terms that forbid training on customer inputs. We do not run any internal model training on tenant data.

Are you compliant with Indian data-protection law?

Yes — we follow the Digital Personal Data Protection Act, 2023. You have rights to access, correct, port, and delete your data. Grievance mailbox: support@easemybill.com (7-day SLA).

Can I get a signed DPA or NDA?

Yes — for annual plans and enterprise customers. Email support@easemybill.com with your entity details and we will send a countersigned Data Processing Agreement within 3 business days.

What about payment card data?

We never see it. Razorpay collects and stores payment instruments directly under RBI regulations. We only receive transaction IDs and settlement status.

What if there is a data breach?

DPDP Act mandates notification within 72 hours. Our incident-response process: contain, notify affected tenants by email, publish a post-mortem on our status page, and file a Data Protection Board report within the statutory window.

Need a signed DPA or a security review?

We happily provide Data Processing Agreements, custom security questionnaires, and architecture walkthroughs for annual and enterprise customers. Write to us — we usually respond the same day.

Founding 100
68 seats left · ₹249/mo lifetime