Privacy Policy
Effective September 13, 2026 · Version 2026-09-13.v4
This policy explains what EnergyWiz collects, why, who it goes to, and what you can do about it. EnergyWiz is operated by Axolotl Advisors LLC.
1. What we collect
Information you give us
- Account identity. Your email address. If you sign in with a password, the password itself is handled by our authentication provider (Supabase) and is never visible to us. If you sign in with Google, we receive your email address and basic profile identifiers from Google, not your Google password.
- Utility account details. Customer name, utility account number, meter number, service address, billing address, rate class, and tax jurisdiction. Most of this is read automatically out of the bills you provide.
- Bill documents. Complete PDF bills, stored as you gave them to us.
- Usage data. Interval electricity data — typically one reading every 15 minutes — and gas usage data, from Green Button files or your utility’s data export.
- Utility login credentials, only if you choose to save them for automated data retrieval. See Section 4.
- Supply contract details you enter for third-party energy suppliers, and any budget targets you set.
Information we generate or collect automatically
- Calculated results — modeled bills, comparisons, projections, and insights derived from the above.
- Audit records. We log permission changes on shared accounts, downloads of bill PDFs and usage files, edits to account information, and consent changes. These records include your user identifier, your IP address, and your browser’s user-agent string. They exist so an account owner can see who touched their data, and so we can investigate a security incident.
- Weather data for your service location’s area, retrieved from public government sources, used to weather-normalize your usage. We send a location to those services; we do not send them anything identifying you.
- Error diagnostics. When something breaks we capture the error to our monitoring provider (Sentry), with personal data scrubbed before it is sent.
A note on how sensitive interval data is
We want to be direct about this rather than bury it. Fifteen-minute electricity readings are revealing. Over time they can indicate when a home is occupied or empty, roughly when people wake and sleep, when large appliances run, and when a household is away. We treat this as the most sensitive category of data in the system, and we protect it accordingly (Section 5). It is also why we do not share it.
2. Why we use it
| Purpose | Data used |
|---|---|
| Calculate your bills under alternative rate plans | Bills, usage data, account details |
| Produce insights, projections, and weather-normalized comparisons | Bills, usage data, weather data |
| Retrieve your data from your utility on your behalf | Utility credentials, portal session |
| Authenticate you and enforce who can see which account | Email, account permissions |
| Send account email (invitations, password resets) | Email address |
| Security, abuse prevention, and incident investigation | Audit records, IP address, user-agent |
| Improve our rate models — only with your separate, per-account consent | Bills including full bill documents, usage data |
What we do not do
- We do not sell your personal information.
- We do not share your personal information with third parties for their own marketing, and we do not serve advertising.
- We do not use your identifiable data for anything beyond operating and improving EnergyWiz for you — and we do not use your identifiable bills to improve our rate models without the separate opt-in below.
De-identified and aggregated data is treated differently, and we would rather say so here than leave you to find it in the Terms. See “De-identified and aggregated data” below.
Model improvement, specifically — and how to turn it off
One use needs spelling out, because it is on unless you turn it off. We use your bills and usage data to check and improve our rate models — comparing what we calculated against what you were actually billed is how we find modeling errors, and it is the main reason the calculations are as accurate as they are. This includes complete, unredacted bill documents, which carry your name, service address, and utility account number, and it includes automated analysis by an AI agent.
This is on by default.
To opt out:
- Open the account settings for a utility account (the ✎ beside the account name, or the Add data panel) and clear “Help improve rate models”. It takes effect immediately.
- The setting is per utility account, so if you have several you will need to clear it on each. A single control covering every account you own is planned.
- Opting out stops future use. It does not retroactively unwind modeling work already done, and it does not reach de-identified or aggregated data already derived (see above) — once that no longer relates to you, we cannot find it to remove it.
Every change in either direction is recorded in an immutable log with a timestamp, the wording in force at the time, and the IP address it came from — so there is always a record of what you chose and when, including a decision to opt out.
De-identified and aggregated data
Separately from all of the above, we create de-identified and aggregated data from your bills and usage, and we use it for analytics, benchmarking, research, improving our rate models and other products, and publishing statistics about energy usage and rate plans. We may share or publish it. This does not depend on the opt-in above, and it is not limited to improving EnergyWiz.
What that does and doesn't mean:
- It must not identify, or be reasonably capable of being associated with, you, your household, or your accounts.
- We will not attempt to re-identify it, we will keep it in de-identified form, and we require the same by contract of anyone we share it with.
- Anything published or shared is aggregated across enough accounts that no individual’s usage can be picked out.
- It is not your personal information once de-identified, so it is not covered by the access, correction and deletion rights in Section 7 — and deleting your account does not remove it, because by then nothing connects it to you.
We want to be honest about the limits of the word “de-identified.” Detailed interval usage is hard to anonymize well: a household’s consumption pattern is close to a fingerprint, and stripping a name off a file is not enough on its own. That is why our commitments above are about aggregation thresholds and a binding promise not to re-identify, rather than about the label.
3. Who we share it with
We share data with service providers who run parts of the infrastructure, and only as needed for them to do so:
| Provider | Role | What it handles |
|---|---|---|
| Supabase | Authentication, database, file storage | Identity, all stored account data, bills, usage files |
| Fly.io | Application hosting | Data in transit and in process |
| Vercel | Website hosting | Requests to the site |
| Resend | Email delivery | Email address, message content |
| Sentry | Error monitoring | Diagnostics, with personal data scrubbed |
We also transmit your utility credentials to your utility’s own website when retrieving your data at your direction — that is the point of saving them.
Otherwise, we share personal information only: with other users you have explicitly granted access to an account; when you ask us to; when required by law or valid legal process; or in connection with a merger, acquisition, or sale of assets, in which case we will give you notice before your data becomes subject to a different policy.
All of our providers are located in the United States.
4. Utility credentials
Saving your utility login is optional; EnergyWiz works fully if you upload bills and usage files yourself.
If you do save them:
- They are encrypted before storage, using a per-account key that is itself protected by a master key held separately from the database. A copy of the database alone does not yield your password.
- They are decrypted only in memory, only at the moment of signing in to your utility on your behalf.
- They are never written to logs or error reports, and are never sent to your browser after you save them.
- The session your utility issues after login is also stored encrypted, so we do not need to re-use your password on every retrieval.
- You can delete them at any time from account settings. Deletion removes them from our systems.
- Each use is recorded in the account’s audit log.
- Saving credentials is not permission to change your utility service. We use them to read your data. If we ever offer to submit a rate-plan change for you, that will take a separate, explicit yes to that specific action — see the Terms of Service, Section 3.
5. How we protect data
- Encrypted in transit (HTTPS) everywhere.
- Encrypted at rest. Bill documents and usage files live in private storage that issues no public links; access goes through short-lived signed URLs after we have checked your permission.
- Access control enforced in two independent layers — the application checks your permission on every request, and the database enforces row-level security underneath it, so a bug in one is caught by the other.
- Downloads of bills and usage files are recorded and visible to the account owner.
- Utility credentials get the additional protections in Section 4.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law, including New York’s SHIELD Act.
6. How long we keep it
- Your account data — for as long as your account exists. When you delete a utility account it is held recoverable for 30 days, then permanently deleted along with its stored documents and usage files.
- Your user profile — deleted on request, as described in Section 7.
- Audit records — one year, then deleted.
- Consent records — retained as long as we operate the service. These are deliberately immutable: a record of what you authorized is only worth anything if it cannot be quietly rewritten, including by us. They contain no billing or usage data.
- Backups — deletions propagate to live systems immediately, but data may persist in encrypted backups for up to 30 days before those age out.
7. Your choices and rights
You can, at any time and from within the application:
- See and correct the account information we hold.
- Export a copy of your data in a machine-readable format.
- Delete a utility account and its data, or your entire user profile.
- Withdraw the model-improvement consent, per account.
- Remove saved utility credentials without deleting anything else.
- Revoke access you granted to another person.
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have rights to know, access, correct, delete, and to not be discriminated against for exercising them. We honor these requests for everyone regardless of where you live, because it would be strange not to. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.
To make a request that you cannot complete in the app, email privacy@energywiz.net. We will respond within 45 days. We may need to verify your identity, which normally means confirming control of your account email.
8. Children
EnergyWiz is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
9. Changes to this policy
We will update the version and effective date above when this policy changes, and ask you to review it in the application when the change is material. Prior consent records keep the version of the wording that was in force when you agreed to it.
10. Contact
Axolotl Advisors LLC — privacy@energywiz.net