Privacy Policy
Last updated August 27, 2026
Billing Diff is operated by Draft Labs (“we”, “us”). This policy explains what we collect when you use billingdiff.draftlabs.org, how we use it, and the choices you have. Billing Diff scans your Stripe account for billing drift. We only ever read your Stripe data — we never create charges, issue refunds, move money, or change your billing.
Information we collect
We collect only what we need to run the scan and your account:
- Account details. Your email address, and — if you sign in with Google — the basic profile Google returns for authentication.
- Stripe billing data (read-only). When you connect Stripe, we read your subscriptions, prices, coupons, and trial metadata to detect drift. We access this through Stripe’s official OAuth connection and never see or store your Stripe API keys.
- Scan results. We store the output of your scans — which subscriptions are drifting, the drift type, the monthly amount, and scan metadata (subscriptions audited, flagged count, scan date).
- Payment information. If you subscribe to the $29/month plan, payment is processed by Stripe. We do not receive or store your card number — Stripe holds all card data.
- Usage analytics. We record product usage events and, for visitors who arrive from an ad, attribution parameters (such as a Google click ID and UTM tags) so we can measure which messaging works.
We do not collect your customers’ card numbers, and we never write to or modify your Stripe account.
How we use your information
- To run your billing-drift scan and show you the report.
- To re-scan daily and email you when new drift appears (paid plan).
- To create and secure your account and authenticate you.
- To process your subscription payment through Stripe.
- To operate, debug, and improve the product.
- To measure ad performance and understand which messaging converts.
Service providers we share data with
We use a small set of processors to run Billing Diff. Each receives only the data needed for its function:
- Stripe — the Stripe connection we scan, and payment processing for the paid plan.
- Supabase — authentication and our database (your account and stored scan results).
- Vercel — application hosting and delivery.
- PostHog — product analytics.
- Resend — transactional and drift-alert email.
- Google — sign-in, if you choose Google authentication.
We do not sell your personal information, and we do not share it for third-party advertising beyond the ad-measurement described above.
Data retention and deletion
You are in control of your Stripe data. From your account you can disconnect Stripe and delete your data at any time — this revokes our access and permanently deletes your stored scan results. We retain account and billing records only as long as needed to provide the service and meet legal obligations. To delete your account entirely, contact us at privacy@draftlabs.org.
How we protect your data
Data is encrypted in transit. Database access is restricted with row-level security so one account cannot read another’s data, and administrative keys are never exposed to your browser. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly by disconnecting Stripe and deleting your data, or by contacting us at privacy@draftlabs.org.
Cookies and analytics
We use essential cookies to keep you signed in and analytics to understand product usage and ad performance. We do not use third-party advertising cookies to track you across other websites.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above, and where appropriate we will notify you.
Contact us
Questions about privacy? Email privacy@draftlabs.org.