Legal · Updated September 30, 2026
Privacy Policy
Dip is an AI agent that helps you lower recurring bills, built and operated by Quintin Tech LLC, a Pennsylvania limited liability company. This policy describes what we collect, what we never collect, where it lives, who we share it with, and what you can do about it. Plain language; no boilerplate.
Version 1.3 — effective September 30, 2026.
What we collect
- Email. Either via Sign in with Apple or an email magic link on Android / web. We use it to authenticate you and to send transactional messages (call summaries, approvals, receipts).
- Bill metadata you enter or upload. Provider name, your current rate, the service address (when needed — trash, internet, electric). Nothing more than what we need to negotiate.
- Voice recordings of calls Dip places on your behalf. Our calling partner Vapi retains recordings for 90 days and then deletes them. We keep the resulting transcript on our side so you have a record of what was agreed to.
- Plaid transaction data. Only if you opt in to bank linking. We use it to spot bills and rate changes. We never sell or share the data, and we use Plaid only in read mode — we do not initiate transfers or modify your bank account.
- Subscription state via Stripe. Plan, period dates, customer id. We do not store your card number; Stripe does.
What we don't collect
- Your phone number — Dip doesn't call you back.
- Your full legal name, unless you explicitly share it on a call (some providers ask).
- Tracking inside the Dip app. The app contains no advertising SDKs. (Our marketing website, dip.bot, is different — see “Our website, the waitlist, and advertising” below.)
- Advertising identifiers (IDFA / AAID).
- Contacts, photos, calendars, location.
Our website, the waitlist, and advertising
This section is about our marketing website, dip.bot, and people who join our waitlist. It does not change anything above about the Dip app.
The waitlist. If you join the waitlist, we collect your email address and which page or campaign you came from. We use it to send you an invite and to tell you when Dip launches. It is stored in Supabase. Email privacy@dip.bot to be removed.
The Meta Pixel. On dip.bot we use the Meta Pixel, a tool from Meta Platforms, Inc., to measure whether our ads on Facebook and Instagram work and to show Dip ads to people likely to be interested. When you visit dip.bot, the pixel sends Meta the pages you view, whether you joined the waitlist, your IP address, browser and device information, and Meta cookie identifiers. We do not send Meta your email address. Meta may connect this information to your Meta account and uses it under its own Privacy Policy.
Meta lead forms. If you sign up through a form inside Facebook or Instagram, Meta collects the email address you enter and passes it to us, and we add it to the waitlist.
What never goes to Meta or any ad platform. The pixel runs only on dip.bot's public marketing pages. It does not run on the pages where you log in, sign up, or manage your account or billing, and it is not in the Dip app. We never send any advertising platform your bank or Plaid data, your bills, your account details, or anything from calls Dip makes for you.
Your choices. If your browser sends a Global Privacy Control (GPC) signal, the pixel never loads for you. You can also turn it off for this browser here. You can manage how Meta uses your information for ads in your Meta ad preferences.
How we share data with providers during negotiation
When Dip calls a provider on your behalf, the provider's representative will typically ask for information to authenticate you and to discuss your account. Dip discloses only what's necessary, which usually includes:
- Your name and the name on the account.
- The account number and the service address on file.
- Identity-verification answers (last 4 of SSN, date of birth, security-question answers) when the provider requires them. We never disclose your full SSN.
We do not share your email, phone number, bank or card details, or any data from Plaid with the provider. The Letter of Authorization you sign before adding a bill is the consent basis for this disclosure.
How we use Plaid
If you link a bank account, we use Plaid to receive transaction data so we can identify recurring bills and detect rate changes. Plaid is a processor that connects to your bank on your behalf; their use of the data is governed by Plaid's End User Privacy Policy. You can review the accounts you've connected and revoke Plaid's access at any time through the Plaid Portal or from inside the Dip app. Revoking access in Plaid Portal immediately stops Plaid from sharing new data with us; data we've already received is retained per the retention windows below until you delete your Dip account.
Where it lives, and how long
- Supabase (Postgres). Encrypted at rest. Hosted in the US. Account data, bill metadata, and call transcripts. Retained while your account is active and deleted within 30 days of account deletion, except where we're legally required to retain longer (typically tax and dispute-resolution records, up to 7 years).
- Vapi. Call audio and live audio. 90-day retention, then deletion. Transcripts move to our Supabase storage and follow the Supabase retention window.
- Stripe. Subscription state. Retained per Stripe's policies and as required for tax and accounting (typically 7 years). No card details stored by us.
- Anthropic (Claude). LLM inference for the agent. Per Anthropic's API policy, your data is not used to train their models. Anthropic does not retain inputs/outputs beyond the inference window for API customers.
- Plaid. Bank transaction data is pulled by Plaid from your bank, passed to us, and stored in Supabase under the same retention window as your other account data. Revoking Plaid access in Plaid Portal stops new data from flowing.
Subprocessors
The vendors named above are our subprocessors. We will update this policy and notify users by email at least 30 days before any new subprocessor begins receiving user data, so you can object or delete your account before that happens.
Financial data and the Gramm-Leach-Bliley Act (GLBA)
If you link a bank account, Dip receives nonpublic personal financial information about you through Plaid. We treat this information as protected under the GLBA and its Safeguards Rule, and we maintain a written information-security program with administrative, technical, and physical safeguards — including encryption in transit and at rest, access controls, vendor due diligence on each subprocessor named above, and a written incident-response plan.
How we use your financial data. We use Plaid-derived transaction data only to identify your recurring bills, detect price changes, and support negotiating those bills for you. We do not: sell it; use it for advertising or cross-context behavioral advertising; share it with the providers we negotiate with; or use it to train AI models unrelated to providing you the service.
Retention and revocation. You can revoke Plaid's access at any time from the Dip app or the Plaid Portal. Revoking access immediately stops Plaid from sharing new data with us. Data we already received is retained under the retention windows described above and is deleted within 30 days of deleting your Dip account, except records we are legally required to keep.
Your choices. Linking a bank account is optional. You can use Dip by adding bills manually or by photo instead, without connecting Plaid.
AI disclosure and call recording
When Dip calls a provider on your behalf, the agent identifies itself at the start of the call as an AI assistant acting on your behalf, and discloses that the call is being recorded. We do not secretly impersonate humans. The recording is made with your consent (granted in the Letter of Authorization you sign before adding a bill) and with the provider representative's consent (requested at the start of every call). If the representative declines to be recorded, Dip will stop recording or end the call.
A number of US states have all-party (sometimes called “two-party”) consent requirements for recording phone conversations, and may include criminal as well as civil liability for violations. Our practice is to disclose recording and request consent at the start of every call, in every state, so we don't rely on the user's location to determine which standard applies.
Your rights
- Delete your account. Email us or use the in-app option. All data is purged within 30 days, including call recordings and transcripts on our side, except records we're legally required to keep (typically tax and dispute records).
- Export your data. Email us. We'll send a machine-readable archive within 30 days.
- Revoke negotiation authority. Removing a bill in the app revokes Dip's Letter of Authorization for that account. Deleting your account revokes it for all accounts.
- California residents (CCPA / CPRA): You have the right to know the categories of personal information we collect (listed above under “What we collect” and “Our website, the waitlist, and advertising”), the sources (you, Plaid, Stripe, providers, Meta lead forms), the purposes (operating the service, negotiating on your behalf, billing, security, and measuring and targeting our ads), and the third parties we share it with (our subprocessors, and Meta for website visitors). You have the right to request deletion and to opt out of sale or sharing of personal information.
We do not sell personal information. Our use of the Meta Pixel on dip.bot counts as “sharing” personal information (internet activity on dip.bot and device identifiers) for cross-context behavioral advertising under California law. You can opt out with a Global Privacy Control signal, which we honour automatically, or with the Do not share my personal information control above. Data from the Dip app — including bank, bill and call data — is never shared for advertising. To exercise any CCPA right, email privacy@dip.bot. - GDPR / EU: Dip is currently US-only. If we expand, we'll update this section before accepting EU signups.
Children
Dip is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, email privacy@dip.bot and we will delete it.
Contact
Privacy questions, deletion requests, exports — all go to privacy@dip.bot. A real person reads that inbox.
Changes to this policy
If we make a meaningful change (new data type, new vendor, new retention window), we'll notify you by email and update the “Updated” date and version at the top of this page. Cosmetic edits don't bump the version.