Privacy
How Eyebiss handles your bill and check data.
We keep the facts needed to explain your answer, not the document. This page explains what Eyebiss receives, what may be retained, and how privacy and deletion requests work.
Updated September 26, 2026
Information you choose to provide
Different check paths use different information.
Depending on the path you use, Eyebiss may receive an electricity bill, plan or Electricity Facts Label and terms information, electricity usage, service ZIP or utility area, contract timing, an early termination fee, and self-reported Quick Check answers. You do not need to provide every category for every check.
Quick Check answers are self-reported and produce a preliminary result unless supporting evidence is supplied. Eyebiss keeps unknown facts unknown rather than treating an estimate as a bill or contract term.
Raw bill lifecycle
Uploaded bill data is sent to Eyebiss for request-scoped processing.
Eyebiss uses uploaded bill bytes to extract and analyze relevant electricity information. The raw data is held for the request, not written to the production decision database, and released on both successful and failed processing paths. Eyebiss’s own record of the check marks the file as deleted and states that no raw copy was kept.
This does not mean the file never touches a server, and Eyebiss does not claim physical zero-copy processing. It means the raw uploaded file and extracted raw text are not intended to become a durable production decision record.
When you add historical bills, each PDF follows this lifecycle independently. Eyebiss retains only the minimized, sanitized billing-cycle evidence needed for continuity checks and the household history ledger; the raw historical PDFs are not stored in that ledger.
Minimized decision history
Eyebiss may retain the facts needed to reproduce and review a decision.
A sanitized decision record may include:
- decision identity and timestamp;
- input path, service ZIP or utility territory, and normalized usage history or usage-derived decision features;
- provider, plan identity, sanitized plan mechanics, contract timing, and early termination fee when relevant;
- document media type and a cryptographic content hash, but not the uploaded file or filename;
- market snapshot, public-source provenance, evidence and source versions, and projected-input policy where applicable;
- calculated scenarios, missing-information reasons, confidence, and the KEEP, WAIT, SWITCH, or NEEDS_INFORMATION outcome; and
- engine, policy, consent, memo and snapshot versions or hashes, plus review status.
Durable decision records exclude raw bill bytes and text, filenames, full service addresses, full account or ESI IDs, payment or credit information, customer contact details, OAuth credentials, and tokens. Operational logging uses a separate allowlist and is not intended to contain request bodies or raw bill content.
If you ask Eyebiss to review a check with you, or opt in to a later check-in, Eyebiss stores the email address you enter, an optional note you write, the request time and status, and the reference to your own check, for up to 30 days or until you withdraw the request. That address is used only to respond to that request; it is not used for marketing and is not shared with a provider. Ordinary analysis never requires contact details.
Retention and deletion
A household decision record has a 30-day active-store expiry.
A sanitized decision record is assigned an expiry 30 days after its decision timestamp. The active-store retention procedure removes expired household decision events. This 30-day policy does not delete the separate, non-household public market-source snapshot or Cloudflare recovery history.
You may ask Eyebiss to remove applicable information from active application storage. If possible, include the decision reference shown with your result; do not resend a full bill merely to make a deletion request. Eyebiss may retain the minimum completion evidence needed to prevent a later recovery from restoring deleted information. Linked or hashed identifiers are not anonymous.
Michael Clay Patterson handles privacy and deletion requests through an approved manual procedure. The procedure is not automated and has not been end-to-end production tested. Eyebiss does not promise a response or completion deadline.
When active deletion is completed, Cloudflare may still retain recovery history or operational logs beyond deletion from active application storage. Their retention depends on the configured platform service and plan. Active deletion does not promise immediate removal from every recoverable copy.
Optional email updates
A Watch has its own limited retention period.
If you request email updates, we keep your email address and the private check reference, decision baseline and scheduling information needed to operate that Watch while it remains active, for no longer than 400 days from its original creation. We do not silently renew that period. Unverified Watch information follows the issued verification link’s 24-hour expiry, bounded by the Watch’s original expiry. If no verification link was issued, the verification period ends 24 hours after the Watch was created.
Turning updates off stops new sending and access through RETURN links. Operations already in progress have bounded settlement periods before eligible private data can be removed; they do not permit indefinite retention. Cleanup operates independently of sending. Retryable email material keeps its original identity and contents within the existing 23-hour retry period and six-attempt limit. An uncertain delivery outcome remains uncertain; it does not authorize a replacement submission after that deadline.
After a fulfilled Watch stops sending, we may keep only the private handoff information needed by an already-issued RETURN link, until that link’s existing seven-day expiry or the Watch’s original expiry, whichever comes first. Turning updates off ends this access. The link identifies its original notification and decision; it does not extend the decision’s retention or make its evidence current. A separately expired check or decision may no longer be available.
We retain minimized pseudonymous identifiers, outcomes and used-link records for duplicate prevention, revocation and replay protection through the later of the original Watch expiry and the last issued link’s expiry, plus bounded settlement. These records are not anonymous. After private-data cleanup, they contain no email address, raw message, access token, private case credential or copied decision content.
Turning off updates does not by itself delete a separately retained check. A genuine later check creates a separately dated decision and may renew the retained check’s 30-day expiry; old decision timestamps and expiries do not change. Support requests retain their separate deadline and withdrawal behavior. You may request deletion through the privacy contact below. Active-store expiry and completed physical deletion are different. Eligible data is removed through the cleanup and deletion procedures described here.
Public electricity information
Public sources support independent calculations, not endorsements.
Eyebiss may use publicly available Texas electricity information from the Public Utility Commission of Texas, Power to Choose, transmission and distribution utility sources, and publicly posted retail electric provider disclosures. Eyebiss may normalize factual plan information, preserve source provenance, and use it for independent calculations.
Those sources remain third-party information. Their use does not imply that the PUCT, a utility, or a retail electric provider endorses Eyebiss or its decisions.
Decisioning, review, and research
Software produces the result; evidence limits and human review remain.
Eyebiss uses deterministic evidence processing and calculations to produce KEEP, WAIT, SWITCH, or NEEDS_INFORMATION when supported. Insufficient evidence causes abstention. Projected future regulated inputs remain labeled as projections, Quick Check remains preliminary, decision-grade cases receive founder review, and Eyebiss does not guarantee savings.
The current check flow records service-processing consent but does not collect optional research-use consent. Service use is not treated as permission to publish a consumer's information as research. Research participation is not required to use the check.
Electricity decisions are made before any future commerce path. Eyebiss does not rank a plan because a partner might pay it, and this policy does not claim that any affiliate relationship currently exists.
Contact
Privacy and deletion requests
Privacy or deletion requests can be sent to privacy@eyebiss.ai.
