YOUR DATA, YOUR CHOICE
Privacy, in plain sight.
Your financial entries are encrypted on your device before they reach our database. You choose whether to use online storage.
Privacy policy · Last updated 26 September 2026
Who is responsible for your data?
Payday Watcher Ltd ("we", "us") operates Payday Watcher and is the controller of the personal information described here. This policy covers our website, desktop workspace and iOS app.
For privacy questions or to exercise your rights, contact customers@paydaywatcher.com. Please do not send your password, encryption key or an unencrypted financial backup.
Staff cannot read your financial entries from the stored database copy
Your expenses, subscriptions, income, payday settings and financial history are encrypted on your device using AES-256-GCM before upload. The database holds encrypted contents and an encrypted copy of the data key protected by a key derived from your password. It does not hold these financial entries or their decryption key in clear text.
When you sign in and unlock the workspace, your browser decrypts your entries so you can use them normally. Staff cannot read the stored financial entries without your decryption key. Your password is not sent to our account server in clear text; authentication uses a derived proof, which the server stores as a hash.
This protection applies to the encrypted financial copy. Account information listed below is readable to run the service. Entries are also readable on an unlocked device and in any readable backup you choose to download. Protect those devices and files.
Password recovery
Resetting a password restores account access but cannot, by itself, unlock an older encrypted copy. A previously unlocked app on its original device can retain the key needed to send your entries again. Without that key, staff cannot recover the earlier cloud copy.
What information we handle
- Optional encrypted financial storage: the encrypted snapshot you choose to upload, its revision and update information. You can keep using the local app without an account or online storage.
- Account and security information: your email, authentication hash and salt, verification and storage-consent records, account status and dates, and sign-in sessions. Session records include the device/client description, last-access time, network IP address and device-reported time zone. A time zone is not a precise or verified physical location.
- Messages you send us: your contact details and support correspondence. These messages are readable by staff handling your request.
- Service logs: our hosting and email providers may process request, delivery and security logs needed to operate and protect the service.
Spreadsheet imports are read in your browser. The merged financial data is encrypted before it is uploaded. Receipt and camera text recognition in the app is processed on the device; this feature does not send images to an external recognition service.
We do not connect to your bank or collect payment-card details through this version. Advertising and App Store subscription billing are planned features and are not currently active in this service. We will explain their data handling before enabling them.
Why we use it
- Providing the service you request: creating and verifying an account, signing you in, and responding to service requests. Our legal basis is performance of our contract with you, or steps you request before it.
- Optional online storage: storing your encrypted financial copy with your consent. You can withdraw this in Account by deleting the cloud copy and turning off sync.
- Protecting accounts: preventing abuse, limiting repeated requests, reviewing access and blocking misuse. We rely on our legitimate interests in operating a secure service, balanced against your rights.
- Legal duties and rights requests: where necessary, meeting applicable legal obligations.
We do not sell your personal information or use your financial entries for advertising. We do not make automated decisions that produce legal or similarly significant effects on you.
Hosting, email and sharing
Hostinger provides our website/database hosting and service email. Our hosting server is configured in the United Kingdom. Providers process the information needed to host the service and deliver verification or support emails. Staff with an account-administration role can review account metadata and access status, not decrypt financial entries from the database.
We may disclose information where required by law or necessary to protect the service and legal rights. Stored financial contents remain encrypted. A UK server location does not mean every provider support or subprocessor operation takes place in the UK. Where a restricted international transfer is necessary, applicable data-protection safeguards are required; contact us for information about the arrangements relevant to your data.
Cookies and your browser
The desktop workspace uses a necessary first-party sign-in cookie to maintain your session. Sessions expire after the configured lifetime, up to seven days, and you can terminate them from Account. The decrypted view locks after inactivity; locking the view is separate from signing out.
This version uses no analytics or advertising cookies. The Light / Dark choice is held in page memory and starts from your system preference when you open a page.
Retention and deletion
We retain account information while your account remains open and your encrypted copy while online storage is enabled. Deleting your cloud copy removes it from the live database and withdraws storage consent. Deleting your account removes the live account and its associated cloud copy, sessions, codes and consent records. Neither action deletes entries kept locally in your app.
Verification codes stop working after ten minutes and are replaced or removed through the verification flow. Sessions you revoke are removed; expired sessions are cleaned up when you sign in again. Support correspondence and operational logs are kept only for the time needed to address the issue, maintain security or meet applicable legal duties, considering the nature of the record and any unresolved matter.
Provider backups and logs can persist after live deletion until they expire under the provider's retention arrangements. They are not all removed instantly by an account deletion. Contact us for retention details relevant to your request.
Your choices and rights
You can export a readable backup, manage signed-in devices, terminate other sessions, delete the encrypted online copy, or delete your account from the desktop workspace. Keep exported backups secure.
Depending on the circumstances, UK data-protection law gives you rights to access, correct or erase personal information, restrict or object to processing, receive portable data and withdraw consent. Withdrawal does not affect processing already carried out lawfully. Some rights have legal exceptions, and we may need to verify your identity. Encryption means we cannot supply a readable financial copy without your key; you can export it while your workspace is unlocked.
Email customers@paydaywatcher.com to make a request. You can also read the Information Commissioner's Office guidance and complain to the ICO.
Changes to this policy
We will update this page and its date when our practices change. We will draw significant changes to account holders' attention through the service or email, and request fresh consent when required.