Short version: Paidly.To keeps your primary bill database encrypted on your device. When you choose bank linking, encrypted sync, subscriptions, or notifications, our service and the providers listed below process the minimum data needed to provide those features. We never sell your data, and you can request deletion from inside the app.
Paidly.To ("Paidly.To," "we," "us," or "our") is an independent iOS application that helps individuals track recurring bills and payment due dates. We are not affiliated with any bank, financial institution, or financial services provider.
If you have questions about this Privacy Policy, contact us at privacy@paidly.to.
When you add bills manually or import them from your bank, Paidly.To stores the primary copy of the following information locally on your device, encrypted using SQLCipher:
If you enable multi-device sync or device-to-device transfer, an encrypted copy of selected bill and payment data is transmitted through our service. The sync encryption key is created and retained on your devices; our server stores the encrypted payload but is not designed to decrypt its contents. Beginning with version 1.3, Plaid transaction history used for recurring-bill detection is stored in the app's encrypted on-device database. During the compatibility rollout, older supported app versions may continue to use the encrypted server cache described below until they upgrade.
If you choose to link a bank account, Paidly.To uses Plaid, a trusted financial data network, to access your bank information on your behalf. When you connect a bank, Plaid may access:
Bank linking is entirely optional. You may use Paidly.To without connecting any bank account.
Plaid's handling of your data is governed by Plaid's End User Privacy Policy. We encourage you to review it.
Paidly.To uses a backend service because Plaid access tokens and other provider credentials must not be embedded in a mobile app. Depending on the features you use, our server may store or process:
Plaid access tokens are encrypted using AES-256-GCM before being stored in PostgreSQL on Render. When a version 1.3 device first uses device-held transaction storage, Paidly.To deletes that linked item's legacy server transaction cache and later webhook events only mark the item as ready for the device to refresh. Transaction pages for those items pass through server memory over TLS and are not durably stored by Paidly.To. Cached records retained for supported older app versions, push credentials, and queued notification content use authenticated encrypted fields and are removed under the deletion and compatibility policies described here; copies in provider backups expire under the provider's backup-retention schedule. We do not request or store your bank username or password, and we do not persist full bank account or payment-card numbers. Some service records are created even if you do not link a bank, including the anonymous installation, security, subscription, and notification records described above.
Paidly.To does not collect:
We use the information described above solely to provide the Paidly.To service, specifically to:
We do not use your financial data for credit scoring, underwriting, employment screening, tenant screening, advertising, or any other purpose beyond the bill-tracking service you requested.
We do not sell or rent your personal or financial data. We disclose data to service providers only as needed to operate the features you request, as follows:
When you link a bank account, we share your request with Plaid so that Plaid can retrieve the relevant bank data. Plaid acts as an independent data processor and is governed by its own privacy policy.
Our server runs on Render (render.com). Render hosts our API server and PostgreSQL database. Render may have incidental access to server data in the course of providing hosting services. Render's privacy policy governs their data handling.
Apple processes App Store subscriptions and payment information. RevenueCat receives anonymous installation and subscription-status information so Paidly.To can determine which features are available. Expo's push notification service processes push tokens and notification content when remote notifications are enabled.
When Paidly.To retrieves a biller logo, our server may send the biller's website domain to Logo.dev. We do not send Logo.dev your Plaid token, bank credentials, or account number.
We may disclose information if required by law, regulation, court order, or government authority, or to protect the rights, property, or safety of Paidly.To, our users, or the public.
We take the security of your data seriously:
No method of transmission or storage is 100% secure. If you believe there has been a security incident involving your Paidly.To data, please contact us immediately at privacy@paidly.to.
You can disconnect any linked bank account at any time from Settings → Connected Banks → Remove. Paidly.To deletes that bank's device-held transaction history and potential-bill candidates, requests revocation from Plaid, and removes the server connection, compatibility cache, and related imported bills. If revocation is temporarily unavailable, the connection is blocked in Paidly.To and retried without discarding the encrypted token needed to complete the request.
You can also review connections through my.plaid.com.
You can permanently delete local bill data and remove a device from its financial workspace from Settings → Delete All My Data. When other approved devices remain, their shared encrypted data and bank connections are not disrupted. The workspace owner may explicitly choose Delete Entire Workspace to remove shared records and disconnect every linked bank for all devices. The app reports whether the server request completed; a failed request is not presented as a successful deletion. Anonymous security, purchase-restoration, and provider-cleanup records are retained as described in Section 5. These actions cannot be undone after completion.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
To exercise any of these rights, contact us at privacy@paidly.to. We will respond within 45 days.
Paidly.To is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information to us, please contact us at privacy@paidly.to and we will promptly delete it.
The app may display links to biller payment websites or allow you to open your bank's app. These third-party services have their own privacy policies, and we are not responsible for their data practices.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will provide notice through the app. Your continued use of Paidly.To after any changes constitutes acceptance of the updated policy.
For any privacy-related questions, data requests, or concerns, please contact:
Paidly.To
Email: privacy@paidly.to
Response time: within 10 business days