BillMaple logo
Features How it works FAQ Contact
Back to home
Legal

Security

Security and privacy are at the core of BillMaple. This page explains how we protect your data and the steps you can take to keep your account safe.

← Back to BillMaple

Last updated: June 18, 2026

On this page

  • 1. Our approach
  • 2. Encryption
  • 3. Credential handling
  • 4. Access & infrastructure
  • 5. Read-only by design
  • 6. Payments
  • 7. What you can do
  • 8. Responsible disclosure
  • 9. Incident response
  • 10. Contact
The short version: We use bank-grade encryption, we never store your provider passwords in plain text on our servers, your session tokens stay on your own device, and we operate read-only — BillMaple can see your balance and due date, but it can never move money.

1. Our approach

BillMaple is built with a "least access" and "privacy by design" mindset. We collect the minimum data needed to run the Service, isolate sensitive information, and prefer keeping credentials on your device rather than on our servers.

2. Encryption

  • In transit: all communication between the app and our systems is protected with industry-standard TLS encryption.
  • At rest: data stored in our infrastructure is encrypted at rest.
  • On device: sensitive items are stored using hardware-backed encryption — Apple Keychain on iOS and Android Keystore on Android.

3. Credential handling

When you link a provider account, your session token is saved strictly on your own smartphone using hardware-backed local encryption. We never store your plain-text passwords or financial credentials on our servers. Account passwords for BillMaple itself are stored only as salted, one-way hashes — never in readable form.

4. Access & infrastructure

  • Access to production systems is restricted to authorized personnel on a need-to-know basis and protected by strong authentication.
  • We host on reputable cloud infrastructure with physical and network security controls.
  • We log and monitor for suspicious activity and apply security updates promptly.

5. Read-only by design

BillMaple acts only as a technical reader. We fetch your balance and due date so your dashboard stays current — typically once a month. We do not initiate payments, transfer funds, or change settings on your provider accounts. This dramatically limits what could happen even in a worst-case scenario.

6. Payments

BillMaple does not process or store full payment-card numbers. Premium subscriptions are billed securely through the Apple App Store or Google Play, which handle payment data under their own PCI-compliant systems.

7. What you can do to stay secure

  • Use a strong, unique password for your BillMaple account.
  • Enable your device's screen lock, Face ID / biometrics, and OS updates.
  • Only install BillMaple from the official App Store or Google Play.
  • Contact us immediately if you notice anything unusual.

8. Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability, please email bill@billmaple.ca with details and steps to reproduce. Please give us a reasonable time to investigate and fix the issue before public disclosure, and avoid accessing or modifying other users' data. We will acknowledge valid reports and keep you updated.

9. Incident response

We maintain an incident-response process. In the event of a data breach that poses a real risk of significant harm, we will notify affected users and the relevant authorities as required by PIPEDA and applicable law.

10. Contact

Security questions or reports: bill@billmaple.ca. General privacy questions: Privacy Policy.

Note for the BillMaple team: This page should describe the controls you actually implement. Before launch, confirm each claim (encryption, token storage, hosting, monitoring, breach process) with your engineering team and a security/legal advisor so the statements are accurate.
BillMaple logo

Smart provider & expense management for your home.

Product

Features How it works Benefits FAQ

Company

About Blog Careers Contact

Legal

Privacy Terms Security

© BillMaple. All rights reserved. · billmaple.ca · by Zeas Design