Security-First Approach
BillBouncer implements industry-standard security practices to ensure your subscription data and personal information remain safe and private.
Our Security Measures
Data Encryption
- TLS/SSL encryption for all data in transit
- AES-256-GCM encryption for bank connection tokens
- Bcrypt hashing with 12 rounds for password storage
- Stripe-managed encryption for payment processing
Authentication & Access
- OAuth 2.0 integration with Google
- Session management with secure cookies
- CSRF protection on all forms
- Rate limiting to prevent brute-force attacks
Secure Data Storage
- Data isolation per user account
- Secure cloud infrastructure hosting
- Health monitoring endpoint for system status
Privacy & Data Control
- Data minimization - we only collect what's necessary
- No selling or sharing of your personal data
- Right to deletion - delete your account anytime
- Transparent practices - clear privacy policy
Your Security: Best Practices
Help Us Keep Your Account Secure
While we implement robust security measures, your actions also play a crucial role in maintaining account security.
Password Security
- •Use a strong, unique password with at least 12 characters
- •Include uppercase, lowercase, numbers, and symbols
- •Never reuse passwords across different services
- •Consider using a password manager
- •Change your password if you suspect compromise
Account Safety
- •Never share your login credentials with anyone
- •Log out when using shared or public devices
- •Be cautious of phishing attempts via email
- •Verify URLs before entering credentials
- •Review account activity regularly
Device Security
- •Keep your devices updated with latest patches
- •Use antivirus software and firewalls
- •Avoid using public Wi-Fi for sensitive operations
- •Enable device encryption and screen locks
- •Back up your data regularly
Recognizing Threats
- •Watch for suspicious emails claiming to be from us
- •Verify sender addresses before clicking links
- •Don't download unexpected attachments
- •Report suspicious activity immediately
- •Be skeptical of urgent requests for information
Security Concerns?
If you discover a security vulnerability or have concerns about your account security, please contact us immediately. We take all reports seriously and respond promptly.
Last updated: January 2026
For more information, see our Privacy Policy and Terms of Service