YOUR DATA, YOUR CHOICE

Privacy, in plain sight.

Your financial entries are encrypted on your device before they reach our database. You choose whether to use online storage.

Privacy policy · Last updated 26 September 2026

Who is responsible for your data?

Payday Watcher Ltd ("we", "us") operates Payday Watcher and is the controller of the personal information described here. This policy covers our website, desktop workspace and iOS app.

For privacy questions or to exercise your rights, contact customers@paydaywatcher.com. Please do not send your password, encryption key or an unencrypted financial backup.

Staff cannot read your financial entries from the stored database copy

Your expenses, subscriptions, income, payday settings and financial history are encrypted on your device using AES-256-GCM before upload. The database holds encrypted contents and an encrypted copy of the data key protected by a key derived from your password. It does not hold these financial entries or their decryption key in clear text.

When you sign in and unlock the workspace, your browser decrypts your entries so you can use them normally. Staff cannot read the stored financial entries without your decryption key. Your password is not sent to our account server in clear text; authentication uses a derived proof, which the server stores as a hash.

This protection applies to the encrypted financial copy. Account information listed below is readable to run the service. Entries are also readable on an unlocked device and in any readable backup you choose to download. Protect those devices and files.

Password recovery

Resetting a password restores account access but cannot, by itself, unlock an older encrypted copy. A previously unlocked app on its original device can retain the key needed to send your entries again. Without that key, staff cannot recover the earlier cloud copy.

What information we handle

Spreadsheet imports are read in your browser. The merged financial data is encrypted before it is uploaded. Receipt and camera text recognition in the app is processed on the device; this feature does not send images to an external recognition service.

We do not connect to your bank or collect payment-card details through this version. Advertising and App Store subscription billing are planned features and are not currently active in this service. We will explain their data handling before enabling them.

Why we use it

We do not sell your personal information or use your financial entries for advertising. We do not make automated decisions that produce legal or similarly significant effects on you.

Hosting, email and sharing

Hostinger provides our website/database hosting and service email. Our hosting server is configured in the United Kingdom. Providers process the information needed to host the service and deliver verification or support emails. Staff with an account-administration role can review account metadata and access status, not decrypt financial entries from the database.

We may disclose information where required by law or necessary to protect the service and legal rights. Stored financial contents remain encrypted. A UK server location does not mean every provider support or subprocessor operation takes place in the UK. Where a restricted international transfer is necessary, applicable data-protection safeguards are required; contact us for information about the arrangements relevant to your data.

Cookies and your browser

The desktop workspace uses a necessary first-party sign-in cookie to maintain your session. Sessions expire after the configured lifetime, up to seven days, and you can terminate them from Account. The decrypted view locks after inactivity; locking the view is separate from signing out.

This version uses no analytics or advertising cookies. The Light / Dark choice is held in page memory and starts from your system preference when you open a page.

Retention and deletion

We retain account information while your account remains open and your encrypted copy while online storage is enabled. Deleting your cloud copy removes it from the live database and withdraws storage consent. Deleting your account removes the live account and its associated cloud copy, sessions, codes and consent records. Neither action deletes entries kept locally in your app.

Verification codes stop working after ten minutes and are replaced or removed through the verification flow. Sessions you revoke are removed; expired sessions are cleaned up when you sign in again. Support correspondence and operational logs are kept only for the time needed to address the issue, maintain security or meet applicable legal duties, considering the nature of the record and any unresolved matter.

Provider backups and logs can persist after live deletion until they expire under the provider's retention arrangements. They are not all removed instantly by an account deletion. Contact us for retention details relevant to your request.

Your choices and rights

You can export a readable backup, manage signed-in devices, terminate other sessions, delete the encrypted online copy, or delete your account from the desktop workspace. Keep exported backups secure.

Depending on the circumstances, UK data-protection law gives you rights to access, correct or erase personal information, restrict or object to processing, receive portable data and withdraw consent. Withdrawal does not affect processing already carried out lawfully. Some rights have legal exceptions, and we may need to verify your identity. Encryption means we cannot supply a readable financial copy without your key; you can export it while your workspace is unlocked.

Email customers@paydaywatcher.com to make a request. You can also read the Information Commissioner's Office guidance and complain to the ICO.

Changes to this policy

We will update this page and its date when our practices change. We will draw significant changes to account holders' attention through the service or email, and request fresh consent when required.