Bilis

Privacy Policy

Effective 1 September 2026 Last updated 26 August 2026

In short

Everything stays in the EU, on servers in France. We use essential cookies only — no analytics, no trackers, no third-party scripts or fonts. We are the controller for your account details and the processor for whatever your applications write into their logs. We never sell your data or train models on it.

1. Who is responsible

samko labs, s. r. o., Trnková 451/12, 040 14 Košice – mestská časť Košická Nová Ves, Slovakia (company ID 53928881) is the data controller for the personal data described in section 3. You can reach us about anything in this document at privacy@bilis.app.

We have not appointed a Data Protection Officer, because we do not meet the criteria in Article 37 of the GDPR. The address above reaches the people who actually handle this.

2. Two different kinds of data

This distinction runs through the whole policy, so it is worth getting straight first.

Account data We are the controller. Your name, email, team membership, billing records, and the technical data we need to run the service. We decide what to collect and why. Sections 3 to 9 cover this.
Log data We are the processor; you are the controller. Whatever your applications send to the ingest endpoint. We do not decide what goes in it and we do not use it for our own purposes. Section 10 covers this.

3. What we collect, and why

3.1 Account and profile

When you register we store your name, email address, and a password hash (we never store the password itself). If you enable two-factor authentication we store the secret and your recovery codes; if you register a passkey we store its public key and credential identifier. We record whether and when you verified your email.

Why: to create and secure your account. Legal basis: performance of a contract (Art. 6(1)(b)) and, for the security features, our legitimate interest in protecting accounts (Art. 6(1)(f)).

3.2 Teams and invitations

We store which teams you belong to and your role in each. When someone invites a colleague, we store the invited email address, the role offered, who sent it, and when it expires — and we send that person an email.

Why: to make shared access work. Legal basis: contract, and our legitimate interest in letting customers collaborate.

3.3 Projects and API keys

We store your project names and, for each API key, the name you gave it, a short non-secret prefix, a SHA-256 hash of the key, and the time it was last used. The key itself is shown once and never stored — we cannot recover it for you or for anyone else.

Why: to authenticate ingest and let you see which keys are live. Legal basis: contract.

3.4 Session and technical data

While you are signed in we store a session record containing your IP address, browser user agent, and last activity time. Our servers also keep standard access logs (IP address, timestamp, URL, response status, user agent) for a short period.

Why: to keep you signed in, to show you your active sessions, and to detect and investigate abuse and outages. Legal basis: contract and legitimate interest in the security and reliability of the service.

3.5 Billing

Paid plans are sold through Stripe Managed Payments, which makes Stripe the merchant of record. You enter your billing details and payment method with Stripe, not with us. We never see or store your card number.

What reaches us is the transaction record: your billing name and country, the tax identifier you gave at checkout where applicable, the plan, the amounts, and whether payment succeeded. Stripe is the controller for the payment data it holds under its own privacy policy, and it issues your receipts and invoices directly.

Why: to charge you and to satisfy tax and accounting law. Legal basis: contract and legal obligation (Art. 6(1)(c)).

3.6 Correspondence

If you email us, we keep the email and our reply.

Why: to answer you and to have a record of what was agreed. Legal basis: legitimate interest in supporting our users.

3.7 What we do not collect

No advertising identifiers. No behavioural profiling. No analytics or product-usage telemetry. No session recording or heatmaps. No data brokers. No automated decision-making that produces legal or similarly significant effects on anyone.

4. Cookies

Bilis uses strictly necessary cookies only. There is no analytics cookie, no advertising cookie, and nothing that requires consent — which is why you do not see a cookie banner.

Cookie Purpose Lifetime
Session cookie Keeps you signed in and carries the CSRF token that protects forms 2 hours of inactivity
Remember-me cookie Set only if you ask to stay signed in Until you sign out
Appearance preference Remembers whether you chose light or dark mode 1 year

Cookies are set with the HttpOnly and SameSite=Lax flags, and over HTTPS only.

5. Third-party content

The Bilis interface loads no third-party resources at runtime. Fonts are downloaded when we build the application and served from our own servers, so your browser never contacts a font CDN. There are no embedded analytics scripts, no tag managers, no social widgets, and no external images. Visiting bilis.app does not reveal your IP address to anyone but us and our hosting provider.

6. Who else touches the data

We do not sell personal data and we do not share it for anyone else's marketing. We share it only with the service providers below, each bound by a written data processing agreement.

Provider What for Where
OVH SAS Server hosting, storage and network for the entire service France (EU)
Stripe, Inc. and Stripe Technology Europe, Limited Merchant of record for the hosted service: checkout, payment processing, tax, invoicing, refunds, disputes and transaction support Ireland (EU) and United States
TODO email provider Transactional email (sign-in, verification, password reset, invitations) TODO — choose an EU-hosted provider

We give customers at least 30 days' notice by email before we add or replace a sub-processor. See section 6.5 of the Terms of Service for your right to object.

We may also disclose data where the law compels it — a valid court order or a lawful request from a public authority. We will tell you unless we are legally forbidden from doing so, and we will push back on requests that look overbroad. We may also share data with a professional adviser under confidentiality, or with a successor if the business is sold, in which case you will be told beforehand.

7. Where your data lives

All data — account data and log data alike — is stored on servers operated by OVH in France, inside the European Union.

We do not transfer personal data outside the EU or EEA. If that ever needs to change, we will update this policy and put a valid Chapter V transfer mechanism, such as the European Commission's Standard Contractual Clauses, in place before any transfer happens.

We use no other hosting region and no third-country sub-processor for log data.

8. How long we keep things

Data Kept for
Log records you ingest 30 days from ingest, then deleted automatically
Account and profile Until you delete your account, then up to 30 days
Backups 30 days, after which deletions propagate
Sessions Until expiry or sign-out
Server access logs Up to 90 days
Unaccepted team invitations Until they expire, then deleted
Invoices and accounting records As long as tax law requires — typically 10 years
Support correspondence 3 years from the last message

9. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected. Most of it you can edit yourself in the app.
  • Erasure — have your data deleted, subject to records we must keep by law.
  • Restriction — have us pause processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests, on grounds relating to your situation.
  • Withdraw consent — where we rely on consent, withdraw it at any time, without affecting what came before.

Email privacy@bilis.app and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you think we have got something wrong, please tell us first — but you always have the right to complain to a supervisory authority, either where you live or where we are established. Ours is the Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic) (dataprotection.gov.sk).

10. If your data is in someone else's logs

If a company uses Bilis to store its application logs, and your personal data appears in those logs, that company is the controller, not us. We host the data on their instruction and have no independent right to use it.

Please direct any request — access, erasure, anything else — to that company. If you contact us instead and we can identify the customer concerned, we will forward your request and tell you we have done so, but we cannot act on your data ourselves without their instruction. We assist our customers in responding, as our processor obligations require.

11. Security

Data is encrypted in transit with TLS and encrypted at rest. Passwords are hashed with a modern password-hashing function; API keys are stored only as SHA-256 hashes. Access to production systems is restricted to the people who need it and protected by multi-factor authentication. Every project's data is isolated at the query layer, and all database queries are parameterised.

If a personal data breach affects you, we will notify the supervisory authority within 72 hours where the GDPR requires it, and tell affected users without undue delay where the risk to them is high. Our vulnerability disclosure policy is at SECURITY.md.

12. Children

Bilis is a tool for people who run software in production. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.

13. Self-hosted instances

This policy covers bilis.app only. If you use a copy of Bilis that someone else runs on their own servers, that operator is the controller and their privacy policy applies — we have no access to their instance and no visibility into it.

14. Changes to this policy

We will update this page when our practices change. For material changes we will email the address on your account at least 30 days before they take effect, and update the date at the top. Past versions are visible in the public repository history — you can see exactly what changed and when.

15. Contact

Privacy questions: privacy@bilis.app
Security reports: security@bilis.app
Everything else: hello@bilis.app

Postal: samko labs, s. r. o., Trnková 451/12, 040 14 Košice – mestská časť Košická Nová Ves, Slovakia.