Privacy
Last updated 15 August 2026
PowerLens exists to give you an honest answer about your electricity plan. We're not going to be cagey about what we do with your data to get you that answer — here's exactly what we collect, why, and how to delete it.
Short version: we read your bill once, throw away the file, and keep only the numbers needed to price your plan. Nothing is ever sold. Your report is deletable at any time, by you — confirm once and it's gone permanently.
What we collect
When you upload a bill
Your bill file (PDF or photo) is sent to Anthropic's Claude API to read the numbers off it — retailer, plan name, tariff rates, daily supply charge, feed-in rate, billing period, and your usage and export in kWh. This happens once, at upload. On our side, the file itself is deleted immediately after we've read it — we never store the bill, only the extracted numbers. Anthropic, as the processor that reads it, may retain the file for up to around 30 days under their standard API terms for abuse and safety monitoring, before it's deleted on their side too — this is their retention window, not ours, and we disclose it here rather than imply the bill vanishes everywhere the instant we've read it. If you add extra bills later for a sharper verdict, each one gets the same treatment: read once, thrown away on our side, only the numbers kept.
Your email address
We ask for your email when you upload — it's where your verdict report goes, and where any payment receipt goes. That delivery is the whole purpose: providing the service you asked for. We only ever send you marketing if you expressly opt in — an untick-by-default box at upload that you have to tick yourself. If you do opt in, we record that choice with a timestamp and the exact wording you agreed to, and you can take it back at any time: every marketing email carries a one-click unsubscribe link that works immediately, no login, no questions. Your email is used by PowerLens Pty Ltd only — never sold, shared, or passed to anyone else for their marketing, ever. It's kept with your report and deleted with it: deleting your report also deletes your email and the consent record.
If you upload your meter data (NEM12)
If you choose to upload your smart meter's half-hourly usage file (a NEM12 CSV, available from your electricity distributor's portal), we read it to price time-of-use and VPP plans a bill alone can't, and to verify your verdict against your real usage. The raw file itself is never stored. We read it, keep the half-hourly numbers tied to your report, and discard the file. We keep those numbers, and this reading, until you delete your report. Your meter's identity travels with your bill NMI (see below). We match the file to your report the same privacy-preserving way, without ever storing the full number.
Your meter number (NMI)
We never store your NMI in full. What we keep is a one-way cryptographic hash (SHA-256 — so we can confirm two bills are for the same property without holding the real number), the last 4 digits masked for display (e.g. ••••1315), your distributor, and your state. The full number never touches our database and is never shown back to you or anyone else.
In the correction step, you also tell us
Your postcode (to confirm it) and your battery install date, plus whether any of four plan-eligibility conditions apply to you: you have an electric vehicle, you'd bundle gas with the same retailer, you hold a Seniors Card, or you're on a government/premium feed-in tariff. Nothing else at that step.
If you add battery details (optional)
On the meter-data page you can tell us your battery's brand and model line, its current reserve percentage, and its current operating mode. All three are optional and you can leave any of them blank. We keep them with your report and delete them with it. They help us describe your setup accurately; skipping them never blocks your verdict.
We also keep anonymous statistics about battery brands, models, modes and settings by postcode to improve our modelling. These are never linked to you or your report and are not removed when you delete your report, because they contain nothing personal.
Your report
Your report lives at a private, hard-to-guess link — no account, no login, no password to lose. Anyone holding that link can view or delete the report; we treat possession of the link as your authority to do either. That's the whole security model, by design.
If you pay
Stripe handles your card details directly — we never see or store your card number. We keep your email (to send the report and any re-run) and Stripe's own transaction reference. The transaction reference has no personal details in it.
If you subscribe to monitoring
A subscription can be bought on its own report or as the one payment that unlocks a new report and starts monitoring together — what we keep is the same either way. Because billing recurs, Stripe holds a customer record and the subscription itself; on our side we keep your email, the subscription's status and renewal date, our reference ids for the Stripe records, the details of your current plan that we check alerts against, and a manage token that we only ever send to your email.
While your subscription is active we keep your bill details and, if you uploaded it, your meter data, because we re-check them against the market every month on your behalf. If you cancel, we keep them only as long as your report exists — delete your report and everything goes with it, subscription records included (our payment records with Stripe are kept as a financial audit trail, same as for the one-off report, and aren't affected by deleting your report). Canceling disables your manage link immediately; the subscription record itself is deleted automatically 90 days after cancellation, whether or not you've deleted the report it belonged to.
If you ask for a reminder email
Just your email, and an optional install date and the date we should remind you. No name, no address, no phone number.
Behind the scenes (operational logs)
We log operational events — failed payment webhooks, rate-limit trips, extraction errors, which reports' verdicts changed on a re-run — so we can keep the service working and catch problems fast. These logs hold counts, error reasons, and report IDs only. Never your bill numbers, your email, or your NMI.
Cookies
We use one cookie. During beta, entering an access code sets a single functional cookie so you don't have to enter the code on every page. It identifies the code, not you. There are no advertising cookies, no tracking cookies, and no third-party analytics cookies on our pages. We do use Vercel Web Analytics to see, in aggregate, which pages get visited — it works without cookies and never sees your bill contents or anything else personal. When you pay, the checkout happens on Stripe's own pages and Stripe sets its own cookies there under its own policy.
Where your data is processed
Your report data is stored with Supabase, hosted in Sydney, Australia. Some processing genuinely crosses borders, and we're not going to hide that: reading your bill uses Anthropic's Claude API (a US company) — your bill image is sent there for that one read, and discarded on our side the moment we've extracted the numbers. Anthropic may hold their copy of the file for up to around 30 days under their own API terms, for abuse and trust-and-safety monitoring, before they delete it — we don't control that window, but we're disclosing it plainly rather than letting "discarded" read as instant everywhere. This is the extent of our overseas disclosure of your bill: Anthropic reads it to extract numbers, under their standard retention terms, and nothing else is done with it there. Card payments are processed by Stripe, report and reminder emails are sent via Resend, and the site itself is hosted and served through Vercel's global network — all established international providers. None of this changes what we do with your data; it just means a few processing steps briefly leave Australia in transit, the same as almost any website you use.
How long we keep things
- The bill file: deleted the moment we've read it, on our side — never stored, ever. Anthropic, who reads it for us, may hold their own copy for up to around 30 days under their standard API terms before deleting it.
- Your report (extracted numbers + verdict): kept until you delete it, or ask us to.
- Your meter data file (NEM12): deleted the moment we've read it, on our side, never stored. The half-hourly numbers we extract are kept with your report until you delete it.
- Your email and marketing-consent record: kept with your report, deleted when you delete the report. Unsubscribing from marketing takes effect immediately and is kept as a "don't email this address" record until the report itself is deleted.
- Payment reference: Stripe holds your actual payment and card records under their own retention rules — we never see your card number. Our own record — that a payment happened, for which report — has no personal details and isn't removed when you delete your report; it's an audit trail, not personal data.
- Reminder emails: kept until you unsubscribe or ask us to delete them.
- Operational logs: kept for about 90 days for troubleshooting, then deleted automatically. They never contained anything personal to begin with, so nothing further happens to them when you delete a report.
Deleting your data
Your report: open your report link and choose Delete this report. You'll be asked to confirm once — that confirmation is real: once you go through with it, this permanently removes your extracted bill data, any extra bills you added, your uploaded meter data, your email and marketing-consent record, and your payment-unlock status for that report. It can't be undone. There's no recovery, and no support process can bring it back.
Reminder emails: every reminder email has a one-click unsubscribe link that stops future emails immediately.
Marketing emails: only ever sent if you expressly opted in, and every one carries a one-click unsubscribe link that revokes that consent immediately — your verdict report and receipts still arrive as normal.
A full erasure of anything else we hold about you (including actually deleting a reminder row, not just unsubscribing): email support@powerlens.com.au, or use our Request data deletion form. We're a small team and haven't built a self-serve button for this yet — every request is handled by hand, and we treat them as urgent.
Your rights
Under the Australian Privacy Principles, you can ask what we hold about you, have it corrected, or have it deleted. The correction step in the report flow already lets you fix anything we misread from your bill before it's priced. For anything else, email support@powerlens.com.au.
Security
Every table holding your data is locked down by default — nothing is readable except by our own servers, not even by us through any public interface. Card payments never touch our servers at all; Stripe handles them directly. We don't sell your data, ever, to anyone, for any reason. If a data breach ever puts you at risk, we tell you and the OAIC promptly.
Questions
support@powerlens.com.au — a real person reads this, not a bot.