Privacy Policy
Effective date: 23 May 2026 · AnyABEX (Pty) Ltd · Registration No. [Reg No] · South Africa
Summary: We collect only what we need, we never sell your data, we never use your conversations to train AI, and you can request deletion of your data at any time. Full details below.
1. Who We Are
This Privacy Policy governs the collection and use of personal information by AnyABEX (Pty) Ltd ("AnyABEX", "we", "us", "our"), a company registered in the Republic of South Africa, operating the BillSource AI platform accessible at billsource.ai and the BillSource billing platform at billsource.com.
We are committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA), Act 4 of 2013, and applicable international data protection standards.
Contact our Information Officer: privacy@billsource.ai · +27 12 661 0385
2. Information We Collect
We collect personal information in the following categories:
- Account information: Name, email address, and Google account identifier when you sign in via Google OAuth.
- Usage data: Message counts, session timestamps, plan tier, and feature interactions — used solely for billing and service improvement.
- Conversation content: Questions and responses in your Billi chat sessions, stored temporarily to provide session continuity.
- Payment information: Processed exclusively by Paystack (a Stripe company). We do not store card numbers or banking details.
- Technical data: IP address, browser type, device type and referral URL — used for security monitoring and analytics.
- Documents you upload: Files you upload to your personal knowledge base remain your property and are not shared.
3. How We Use Your Information
- To provide, operate and improve the BillSource AI and Billi services
- To authenticate your identity and manage your account and subscription
- To enforce usage limits and plan entitlements
- To send transactional emails (account, billing, security alerts)
- To comply with legal obligations under South African and applicable law
- To detect, prevent and investigate security incidents or fraud
We do not use your conversations or documents to train AI models. Your data is never sold to or shared with advertisers.
4. AI Data Processing
Billi is powered by Anthropic's Claude API. When you send a message to Billi:
- Your message is transmitted to Anthropic's API for processing
- Anthropic explicitly does not train on API customer data per their usage policy
- Responses are returned and may be stored temporarily to maintain conversation context
- We recommend you do not include sensitive personal or financial data in Billi conversations
Anthropic's Privacy Policy is available at anthropic.com/privacy.
5. Data Sharing and Sub-processors
We share your data only with the following categories of sub-processors, strictly for service delivery:
- Railway — Cloud infrastructure hosting (SOC 2 Type II certified, GDPR compliant)
- Anthropic — AI model processing via Claude API (does not train on API data)
- Flowise — Open-source AI orchestration layer that routes your messages to the appropriate Billi associate before passing to the Claude API. Self-hosted on Railway — no third-party data sharing
- Paystack — Payment processing (PCI-DSS Level 1 certified, a Stripe company, SA regulated)
- Google — Authentication via OAuth (Google Workspace)
- Resend — Transactional email delivery (SOC 2 compliant, DKIM/SPF verified)
We do not sell, rent or otherwise disclose your personal information to third parties for marketing purposes.
6. Data Retention
- Account data: Retained for the duration of your subscription plus 3 years for legal compliance
- Conversation history: Retained for 12 months on paid plans, 30 days on free plan
- Uploaded documents: Retained until you delete them or close your account
- Payment records: Retained for 5 years as required by South African tax law
7. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate personal information
- Request deletion of your personal information (subject to legal retention requirements)
- Object to the processing of your personal information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, email privacy@billsource.ai. We will respond within 30 days.
Information Regulator (South Africa): inforegulator.org.za · complaints.IR@justice.gov.za
8. International Data Transfers
Your data may be processed in the United States where Railway and Anthropic infrastructure is located. Both providers maintain EU-US Data Privacy Framework certification and GDPR-compliant data processing agreements. By using BillSource AI you consent to this transfer on the basis of adequate safeguards.
9. Security
We implement appropriate technical and organisational measures including encryption in transit (TLS), encryption at rest, access controls, audit logging, and regular security reviews. Our infrastructure provider Railway holds SOC 2 Type II certification. See our Trust Centre for full details.
10. Cookies
We use only functional cookies necessary for authentication and session management. We do not use advertising or tracking cookies. You may disable cookies in your browser settings but this will prevent login functionality.
11. Children's Privacy
BillSource AI is intended for business use by persons 18 years and older. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact privacy@billsource.ai immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email to registered users at least 30 days before taking effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
AnyABEX (Pty) Ltd
Information Officer
Email: privacy@billsource.ai
International: +27 12 661 0385
Technical: 012 661 0385
Website: billsource.com