Privacy Policy
Last updated: September 15, 2026
CFMS Bills Status is not affiliated with the Government of Andhra Pradesh, APCFSS, or any government department. It is an independent service run by a private individual. It reads bill status information from the CFMS portal and presents it more conveniently. It is not an official government service, and nothing shown here is an official pay or payment statement.
This policy describes how CFMS Bills Status (www.cfmsbillsstatus.online) handles your information. It is written to match what the service actually does. Where a limit or a retention period is stated, it is enforced in the software, not just promised here.
1Using the site without an account
You can check a single bill from the home page without creating an account. When you do, your browser is sent to the official CFMS portal to display that bill. The bill number is not processed by our servers for this, and no personal information is collected.
Your recent bill numbers are kept in your own browser so the history list works. Clearing your browser storage removes them. If you are logged in, that history is also saved to your account so it follows you between devices — see section 2.
2What we store when you create an account
An account is required for bulk checking, saved history, and automatic tracking. We store:
- Account details — username, email address, an optional mobile number, and your password stored only as a bcrypt hash. We never hold your password in a readable form.
- Security question answers, if you set them, also stored only as hashes.
- Your role and subscription status, so the service knows which features you have.
- Bill numbers you searched or saved, with an optional label of your choosing and the time you searched.
- Bulk-check batches you created — the batch name and the list of bill numbers in it.
- The time of your last login.
We do not ask for, and have no use for, your Aadhaar, PAN, bank account number, or date of birth.
3CFMS credentials, if you choose to store them
Automatic tracking needs to sign in to CFMS on your behalf, so it needs your CFMS username and password. Storing them is entirely optional. Every other feature — single checks, bulk checks, saved history — works without them.
If you choose to store them:
- They are encrypted at rest using AES-256-GCM before being written to the database. The encryption key is held separately in the server environment and is not stored in the database.
- They are used for one purpose only: signing in to CFMS to refresh the status of the bills you chose to track. This runs automatically about once every six hours, and when you press Refresh yourself.
- They are never displayed back to anyone, including the site administrator, and are never shared with any third party.
- We record when you gave consent, the wording version you agreed to, and the IP address you gave it from, so there is a record of what you agreed to and when.
- If sign-in fails repeatedly — for example after you change your CFMS password — automatic checking is disabled and the failure is recorded, so a wrong password is not retried indefinitely against CFMS.
Please consider whether your department permits storing CFMS credentials with a third-party service. If it does not, do not use this feature.
4Bill status records
When a bill is checked, the service keeps a record of that bill's progress so it can show you a timeline and detect changes. A record holds the bill number, the stage it has reached, the office and designation handling it, the dates of each stage, the DDO and treasury office, and the gross, deduction and net amounts.
Two deliberate limits apply. The names of government officers are not stored — only their designation, such as "Senior Accountant". And a beneficiary's bank account number is stored only as the last four digits, never in full.
These records describe a government bill rather than a person's account, and are not linked to the user who looked the bill up. They are automatically deleted 365 days after they are created.
5Department discount verification
If you apply for the verified government staff discount, you submit your CFMS ID and upload supporting documents, such as recent salary paybills. These are stored only so the application can be checked by hand.
The uploaded documents are erased as soon as the application is decided — approved, rejected, or reopened. The outcome and the date are kept; the documents are not.
6Service logs
To keep the service working and to see how heavily it is used, each check is logged with the number of bills, how long it took, whether it succeeded, and which account ran it. These logs contain no bill contents and no personal details beyond the account. They are automatically deleted after 90 days.
Aggregate monthly statistics about treasury processing times are also kept. These contain no personal information and no bill numbers, and are not deleted.
7Payments
If you subscribe to a paid plan, payment is handled by Razorpay. Card and bank details are entered on Razorpay's systems and are never seen by, or stored on, this service. We keep the payment record — the amount, the plan, the date, and Razorpay's reference identifiers — because that is what a subscription and a refund request need.
8How long we keep things
9What we delete automatically, and why
Keeping every record forever costs money and increases the harm if anything ever went wrong, so some things are deleted on a timer whether you ask or not.
- Saved bill history and bulk-check batches are kept for 90 days on a free account, then deleted. Each entry is aged individually, so your recent searches are always there — it is the older ones that go. While you have a Pro subscription, nothing is aged out.
- Stored CFMS credentials are deleted after 90 days without a login, even if you are a subscriber. A password nobody is using cannot help you and can only ever be a risk. Your account and history are untouched; you simply re-enter it when you return.
- Bills you are actively tracking are never aged out while tracking is on. Only tracking you have already stopped is cleared.
So if your free period or subscription ends, you have three months in which subscribing again brings your full history back. After that, the older entries are genuinely gone and we cannot restore them.
10Deleting your data
Your CFMS credentials. Go to Settings → CFMS Credentials and press Delete. They are removed immediately and automatic checking stops at once. You do not need to ask anyone.
Tracked bills and saved history. Delete them individually from the Tracked Bills page and from your history list.
Your whole account. There is no self-service delete button yet, so email the contact in section 12 from the address on your account and ask for deletion. When an account is deleted we remove your account record, your stored CFMS credentials, your tracked bills and their history, your saved bill history, your bulk-check batches, your service logs, and any department verification record.
One thing is not removed, and it is fair that you know why: the bill status records described in section 4 are keyed to a government bill rather than to your account, and are shared by everyone who checked that bill. They hold no link to you. They are deleted automatically 365 days after they were created.
Deletion is permanent. We do not keep a backup copy of a deleted account to restore later.
11Cookies, advertising and third parties
We use a cookie to keep you logged in. Google AdSense may set cookies to show and measure advertising; you can control this through Google Ad Settings. Paid plans remove advertising.
We do not sell your data, and we do not share it for advertising. The only third parties involved in running the service are our hosting provider, our database provider, Razorpay for payments, and Google for advertising. Bill data comes from the CFMS portal, which is operated by APCFSS and governed by its own terms.
12Contact and grievances
For any question about your data — access, correction, deletion, or a complaint — contact:
Please write from the email address registered to your account, so we can be sure the request is yours. We aim to reply within seven days.
13Changes to this policy
If this policy changes, the date at the top changes with it. If a change affects how your CFMS credentials are used, you will be asked to agree again before automatic checking continues.