Trust

How Cosmic Bills handles your data

Accounts payable data tells anyone who reads it what your business buys, from whom, and for how much. This page sets out what is collected, what is kept, and what is not done with it.

This page is being verified before launch

The statements below are drawn from the existing Cosmic Bills terms, privacy policy and user guides. Two items are marked as requiring confirmation. Nothing on this page claims a certification, audit or security standard, because none is evidenced in the source material.

What Cosmic Bills collects from you

  • Your username and password.
  • Your name and email address, given at registration. The email address is used to communicate with you and may be added to a newsletter list you can unsubscribe from.
  • A phone number, if you choose to give one. This is optional.
  • The invoices, bills and receipts you submit for processing.

What it reads from your accounting system

Only what is needed to code a bill correctly, through the connection you authorised:

  • Your contact list, to match a document to the right supplier.
  • Chart of accounts, tax and settings data, used to choose accounts, invoice numbers and terms.
  • Your own organisation's ABN, so your own company is never treated as a supplier on its own bills.

What is exported back

  • Bills with their financial data and line detail, with the source document attached.
  • Credit notes, where the document is detected as one.
  • New suppliers extracted from your invoices.
  • New product codes, once you have entered them in Cosmic Bills.

How long documents are kept

  • Invoice documents are retained for a minimum of seven years, in line with accounting record-keeping practice.
  • If an account goes unpaid for more than a year, its data may be deleted without notice.
  • You should keep your own copies of everything you upload. Cosmic Bills does not guarantee against data loss and excludes liability for it.

Where data is hosted

TODO: VERIFY — hosting location and provider

The current privacy policy states that hosting is provided by a third party with servers in the United States and Singapore. A blog article on the same site claimed that data is kept in Australia. These cannot both be true. The article has been retired rather than republished, and this page will state the hosting arrangement once it has been confirmed in writing.

What is never done

  • Your personal, document and accounting information is not disclosed to a third party without your explicit consent, or unless compelled by a court order.
  • Payment card details are not stored. Payments are processed by Stripe.
  • Your email address is used to communicate with you and is not distributed or used in any other way.

Access, correction and erasure

While your subscription is valid you have unrestricted access to your own data through the application. You can also:

  • Request erasure of your email address, invoice documents and the data drawn from your accounting system. This ends the seven-year retention commitment.
  • Restrict processing by turning off individual services in Settings.
  • Export past document data in a commonly used, machine-readable format and take it elsewhere.
  • Object to the use of your data, and have the consequences explained to you.

Breach notification

  • Where a breach is likely to result in a risk to the rights and freedoms of individuals, notification is sent within 72 hours of Cosmic Bills becoming aware of it.

Accuracy is your call, not the software's

  • Extraction succeeds at less than 100%, and line items are not guaranteed to be extracted from every invoice.
  • You are responsible for validating extracted data before using it for accounting or any other purpose.
  • The review and approve step exists so that every bill is checked by a person before it reaches your ledger.

Connecting to your accounting system

Xero

You authorise Cosmic Bills through Xero's own consent screen and choose which organisation it may access. You can disconnect it from within Cosmic Bills or from Xero at any time.

Reckon

Reckon's API requires a dedicated user inside your own company file. You create that user and control it. You do not share your own Reckon sign-in with Cosmic Bills.

TODO: VERIFY — published API credentials

The current WordPress site publishes a specific username and password for the Reckon API user, and a shared demo account login, in plain text on a public page. Those credentials have deliberately not been carried over. They should be rotated and the old pages removed as part of the WordPress clean-up.

Google Drive access

If you connect Google Drive, Cosmic Bills reads only from a folder you create named “Cosmic BillsUpload”. Processed files are moved to a “Cosmic BillsDone” folder, which Cosmic Bills creates if it does not exist. No files in your Drive are deleted, and nothing outside that folder is read.

TODO: VERIFY — is Google Drive upload still offered?

This is described in the privacy policy but does not appear anywhere in the current user guides or product pages. Confirm whether it is still a supported route before this section is published.

Reporting a security problem

If you believe you have found a security issue affecting Cosmic Bills, email support@cosmicbills.com with enough detail to reproduce it. Please do not post it publicly first.

The full legal wording is in the privacy policy and terms of use. Where this page and those documents differ, those documents govern.

Questions about your data?

Ask before you connect, not after. We would rather answer it up front.