Paidly.To
Privacy Terms Download

Privacy Policy

Effective date: May 22, 2026  ·  Last updated: July 23, 2026

Short version: Paidly.To keeps your primary bill database encrypted on your device. When you choose bank linking, encrypted sync, subscriptions, or notifications, our service and the providers listed below process the minimum data needed to provide those features. We never sell your data, and you can request deletion from inside the app.

1. Who We Are

Paidly.To ("Paidly.To," "we," "us," or "our") is an independent iOS application that helps individuals track recurring bills and payment due dates. We are not affiliated with any bank, financial institution, or financial services provider.

If you have questions about this Privacy Policy, contact us at privacy@paidly.to.

2. Information We Collect

2a. Bill and Payment Data

When you add bills manually or import them from your bank, Paidly.To stores the primary copy of the following information locally on your device, encrypted using SQLCipher:

  • Biller names, amounts, and due dates
  • Payment history and notes
  • Account numbers (stored separately in the iOS Keychain)
  • Notification preferences

If you enable multi-device sync or device-to-device transfer, an encrypted copy of selected bill and payment data is transmitted through our service. The sync encryption key is created and retained on your devices; our server stores the encrypted payload but is not designed to decrypt its contents. Beginning with version 1.3, Plaid transaction history used for recurring-bill detection is stored in the app's encrypted on-device database. During the compatibility rollout, older supported app versions may continue to use the encrypted server cache described below until they upgrade.

2b. Bank Data via Plaid

If you choose to link a bank account, Paidly.To uses Plaid, a trusted financial data network, to access your bank information on your behalf. When you connect a bank, Plaid may access:

  • Transaction history (to detect recurring bills and subscriptions)
  • Account balances and account details
  • Credit card minimum payment amounts and due dates
  • Loan and mortgage payment information

Bank linking is entirely optional. You may use Paidly.To without connecting any bank account.

Plaid's handling of your data is governed by Plaid's End User Privacy Policy. We encourage you to review it.

2c. Server-Side Service Data

Paidly.To uses a backend service because Plaid access tokens and other provider credentials must not be embedded in a mobile app. Depending on the features you use, our server may store or process:

  • A randomly generated installation ID, a hashed authentication token, and device-attestation public-key records
  • Plaid item IDs, encrypted access tokens, institution details, non-sensitive update state, and transient account, balance, liability, and transaction responses needed to update the app
  • Encrypted cached transaction records for linked items that still use a supported pre-1.3 compatibility protocol
  • End-to-end encrypted sync payloads and limited sync metadata
  • Subscription entitlement, product, expiration, and RevenueCat customer and event identifiers
  • Push notification tokens, delivery tickets, and queued notification metadata
  • Short-lived webhook, security-challenge, and retry records used to operate the service reliably

Plaid access tokens are encrypted using AES-256-GCM before being stored in PostgreSQL on Render. When a version 1.3 device first uses device-held transaction storage, Paidly.To deletes that linked item's legacy server transaction cache and later webhook events only mark the item as ready for the device to refresh. Transaction pages for those items pass through server memory over TLS and are not durably stored by Paidly.To. Cached records retained for supported older app versions, push credentials, and queued notification content use authenticated encrypted fields and are removed under the deletion and compatibility policies described here; copies in provider backups expire under the provider's backup-retention schedule. We do not request or store your bank username or password, and we do not persist full bank account or payment-card numbers. Some service records are created even if you do not link a bank, including the anonymous installation, security, subscription, and notification records described above.

2d. Information We Do Not Collect

Paidly.To does not collect:

  • Your name, email address, or phone number
  • Advertising IDs or cross-app tracking identifiers
  • Location data
  • Usage analytics or crash reports (beyond what Apple provides)
  • Any data for advertising or marketing purposes
  • Payment card numbers or billing information (all subscription billing is handled directly by Apple)

3. How We Use Your Information

We use the information described above solely to provide the Paidly.To service, specifically to:

  • Display your bills, due dates, and payment history within the app
  • Schedule local reminders and send service notifications about bills or bank connections
  • Connect to Plaid to retrieve bank and transaction data on your request
  • Enable end-to-end encrypted multi-device sync (if you choose to use it)
  • Process your subscription through Apple's In-App Purchase system (Apple handles all payment data; we receive only a confirmation of your subscription status)

We do not use your financial data for credit scoring, underwriting, employment screening, tenant screening, advertising, or any other purpose beyond the bill-tracking service you requested.

4. How We Share Your Information

We do not sell or rent your personal or financial data. We disclose data to service providers only as needed to operate the features you request, as follows:

Plaid

When you link a bank account, we share your request with Plaid so that Plaid can retrieve the relevant bank data. Plaid acts as an independent data processor and is governed by its own privacy policy.

Infrastructure Providers

Our server runs on Render (render.com). Render hosts our API server and PostgreSQL database. Render may have incidental access to server data in the course of providing hosting services. Render's privacy policy governs their data handling.

Subscriptions and Notifications

Apple processes App Store subscriptions and payment information. RevenueCat receives anonymous installation and subscription-status information so Paidly.To can determine which features are available. Expo's push notification service processes push tokens and notification content when remote notifications are enabled.

Logos and Branding

When Paidly.To retrieves a biller logo, our server may send the biller's website domain to Logo.dev. We do not send Logo.dev your Plaid token, bank credentials, or account number.

Legal Requirements

We may disclose information if required by law, regulation, court order, or government authority, or to protect the rights, property, or safety of Paidly.To, our users, or the public.

5. Data Retention

  • On-device bill data — retained until you delete it from the app or uninstall Paidly.To.
  • On-device Plaid transaction history and potential-bill candidates — retained while the associated bank remains linked and paid access remains active. Removing the bank, using Delete All My Data, or a verified downgrade to Free deletes this device-held history; imported bills remain unless you delete them.
  • Server-side Plaid connection and compatibility data — encrypted connection records are retained while the associated bank remains linked. Supported older app versions may retain encrypted transaction-cache rows until the item upgrades, disconnects, or is revoked.
  • Encrypted sync data — retained while the financial workspace has an approved device, or until the workspace owner deletes the entire workspace.
  • Push data — inactive push tokens are removed after 90 days; short-lived delivery and retry records are removed after processing or their operational retention period.
  • Subscription and security records — retained while needed to provide access, prevent fraud, comply with legal obligations, and resolve purchase or deletion requests.
  • Delete All My Data — using Settings → Delete All My Data always deletes local app data and removes that device's notification and access records. If other approved devices remain, shared encrypted sync data and Plaid connections stay available to them. The workspace owner can instead choose Delete Entire Workspace, which removes shared financial and sync records and queues every linked Plaid item for revocation. A workspace with no remaining approved device is deleted automatically. Paidly.To retains the anonymous installation authentication, device-attestation, deletion-cleanup, and subscription records needed to secure the service, finish provider cleanup, and restore purchases. Provider records that Apple, RevenueCat, or Plaid must retain under their own legal obligations are governed by their policies.

6. Data Security

We take the security of your data seriously:

  • On-device bill data and version 1.3 Plaid transaction history are encrypted at rest using SQLCipher (AES-256). The encryption key is stored in the iOS Keychain and never leaves your device.
  • Account numbers entered in the app are stored separately using the iOS Keychain with this-device-only accessibility. Paidly.To displays and exports masked values by default.
  • Communications between the app and our server use TLS (HTTPS) encryption in transit.
  • Plaid access tokens are stored encrypted (AES-256-GCM) in our database with access controls restricting access to authorized systems only.
  • Encrypted Plaid transaction-cache rows for supported pre-1.3 items, verified Plaid webhook payloads, push credentials, and queued notification content use AES-256-GCM authenticated-encryption fields.
  • Plaid access tokens are automatically rotated when Plaid detects a security event. Our server listens for Plaid's signed rotation webhooks and immediately replaces any rotated token — the old token is invalidated on Plaid's side at the same time.
  • We do not have access to your bank login credentials. These are handled directly by Plaid.

No method of transmission or storage is 100% secure. If you believe there has been a security incident involving your Paidly.To data, please contact us immediately at privacy@paidly.to.

7. Your Rights and Choices

Disconnecting Your Bank

You can disconnect any linked bank account at any time from Settings → Connected Banks → Remove. Paidly.To deletes that bank's device-held transaction history and potential-bill candidates, requests revocation from Plaid, and removes the server connection, compatibility cache, and related imported bills. If revocation is temporarily unavailable, the connection is blocked in Paidly.To and retried without discarding the encrypted token needed to complete the request.

You can also review connections through my.plaid.com.

Deleting All Your Data

You can permanently delete local bill data and remove a device from its financial workspace from Settings → Delete All My Data. When other approved devices remain, their shared encrypted data and bank connections are not disrupted. The workspace owner may explicitly choose Delete Entire Workspace to remove shared records and disconnect every linked bank for all devices. The app reports whether the server request completed; a failed request is not presented as a successful deletion. Anonymous security, purchase-restoration, and provider-cleanup records are retained as described in Section 5. These actions cannot be undone after completion.

California Residents (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know — the categories and specific pieces of personal information we have collected about you.
  • Right to Delete — request deletion of your personal information (use the in-app Delete All My Data feature or contact us at privacy@paidly.to).
  • Right to Opt-Out of Sale — we do not sell personal information, so there is nothing to opt out of.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any CCPA rights.

To exercise any of these rights, contact us at privacy@paidly.to. We will respond within 45 days.

8. Children's Privacy

Paidly.To is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information to us, please contact us at privacy@paidly.to and we will promptly delete it.

9. Third-Party Links and Services

The app may display links to biller payment websites or allow you to open your bank's app. These third-party services have their own privacy policies, and we are not responsible for their data practices.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will provide notice through the app. Your continued use of Paidly.To after any changes constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, data requests, or concerns, please contact:

Paidly.To
Email: privacy@paidly.to
Response time: within 10 business days

Paidly.To
Privacy Policy Terms of Service Contact

© 2026 Paidly.To. All rights reserved.