PolicyForge

    Privacy Policy

    Last updated: July 31, 2026 | Effective: July 30, 2026

    Privacy Policy

    Effective date: July 30, 2026

    Last updated: July 31, 2026

    Paidly (“Paidly,” “we,” “our,” or “the app”) is a subscription-management app for iOS and Android. This Privacy Policy explains how Paidly handles information in the app and on usepaidly.app.

    1. Privacy at a Glance

    • Paidly does not require a Paidly account.
    • Subscription records, budgets, notes, and Gmail-derived subscription details are stored in a SQLite database inside your device’s app sandbox, not in a Paidly backend.
    • Optional Gmail scanning uses read-only Google authorization. Message processing occurs on your device.
    • Paidly does not send Gmail message data or values derived from Gmail messages to Firebase Analytics, logo providers, or a Paidly server.
    • If Usage Analytics is enabled, pseudonymous app-interaction and diagnostic data is sent to Google Firebase Analytics. You can disable it in Settings → Usage Analytics.
    • Paidly does not sell personal information or use Gmail data for advertising.

    2. Information Handled on Your Device

    Paidly stores the following information locally so that app features work:

    • subscription names, prices, currencies, billing cycles, and billing dates;
    • categories, labels, payment-method labels, notes, and notification preferences;
    • budgets and app preferences;
    • locally generated insights, savings suggestions, and price-change history; and
    • subscription details you choose to import from Gmail, a screenshot, CSV, or backup.
    This information is kept in a SQLite database within the operating system’s app sandbox. Paidly does not add application-level encryption to that database. Device-level protections depend on your operating system, device settings, passcode, and backup configuration.

    Exports and backups are created only when you request them. After you share an export or backup, its handling is controlled by the destination you select.

    3. Optional Gmail Integration

    What Paidly accesses

    If you choose to connect Gmail, Paidly requests the Google OAuth scope:

    https://www.googleapis.com/auth/gmail.readonly

    Paidly uses this read-only permission to run targeted searches for subscription and billing messages. An initial scan searches approximately the previous 12 months and processes up to 1,000 matching messages. For matching messages, Paidly requests:

    • the Subject header;
    • the From header;
    • the short message snippet supplied by Gmail; and
    • text content from the message’s text/plain or text/html body parts.
    Paidly does not call Gmail’s attachment-download endpoint or process parts identified as attachments. It does not send email, modify email, or delete email.

    How Gmail data is used

    Paidly processes the requested Gmail headers, snippets, and text message bodies in memory on your device to identify possible subscription names, prices, currencies, billing cycles, charge dates, and trial information. Scan results are shown to you for review, and only the subscriptions you approve are saved to the local database.

    Raw Gmail fields, transient scan results, and Gmail-derived values are not sent to:

    • Paidly or a Paidly backend server;
    • Google Firebase Analytics;
    • Logo.dev, Clearbit, or another logo provider;
    • advertising services; or
    • AI or machine-learning model providers.
    Remote logo requests are disabled for Gmail scan results and subscriptions imported from Gmail.

    Optional Price Watch

    Price Watch is off by default. If you explicitly enable it after connecting Gmail, Paidly may perform an incremental read-only Gmail scan on app launch when approximately seven days have passed since the prior Price Watch scan. The first Price Watch scan checks approximately the previous 30 days; later scans check messages since the previous scan. Processing remains on your device. Price Watch may create a local notification if it detects a possible price change.

    You can turn Price Watch off at any time in Settings.

    Disconnecting Gmail

    You can disconnect Gmail in Settings → Gmail → Disconnect Gmail. Doing so revokes Paidly’s Google authorization and turns off Price Watch. Subscriptions you previously chose to import remain in the local database until you delete them.

    You can also revoke access from Google Account permissions.

    Google API Services User Data Policy

    Paidly’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

    Paidly uses Google user data only to provide the user-facing Gmail subscription-detection and optional Price Watch features described above. Paidly does not sell Google user data, use it for advertising, use it to determine creditworthiness or lending decisions, or use it to train generalized AI or machine-learning models.

    Humans do not access Google user data through Paidly. Paidly does not operate a server that receives Gmail message data. The exceptions permitted by Google’s policy—such as access with a user’s affirmative agreement for a specific purpose, for security, to comply with law, or after aggregation and anonymization for internal operations—do not occur during Paidly’s normal Gmail processing.

    4. Analytics and Diagnostics

    If Usage Analytics is enabled, Paidly uses Google Firebase Analytics to collect pseudonymous information such as:

    • app and device metadata made available by the Firebase SDK, such as app version, device type, operating system, language, and approximate region;
    • screen views and feature-interaction events;
    • Paidly Pro entitlement status; and
    • non-content preferences such as selected currency, theme, whether a budget is configured, and general app-engagement counters.
    Paidly configures Gmail events so they do not include Gmail message fields, detected service names, prices, billing dates, scan-result counts, subscription counts, spending totals, or other Gmail-derived values. Paidly does not send locally stored subscription values to Firebase Analytics.

    Firebase may assign an app-instance identifier and receive your IP address as part of the network request. Paidly does not use analytics for advertising or cross-app tracking.

    You can stop future Firebase Analytics collection in Settings → Usage Analytics. Analytics collected before you opt out may remain according to Paidly’s Firebase configuration and Google’s retention and deletion practices.

    5. Purchases

    Apple App Store or Google Play processes purchases. Paidly uses RevenueCat to manage purchase entitlements. Depending on the platform, these providers may process:

    • an app-user or installation identifier;
    • product and entitlement identifiers;
    • transaction and purchase-receipt information; and
    • device, app, and diagnostic information needed to process or restore purchases.
    Paidly does not receive your complete payment-card number. Apple, Google, and RevenueCat handle information under their own privacy policies.

    6. Logos, Currency Rates, Notifications, and Website Requests

    For subscriptions that were not imported from Gmail, Paidly may request a company logo from Logo.dev or Clearbit. The provider may receive the requested service domain, your IP address, and ordinary request metadata. Remote logo requests are disabled for Gmail-derived subscriptions.

    Paidly requests exchange rates from open.er-api.com. That provider may receive your IP address, requested currency codes, and ordinary request metadata. Paidly does not include a subscription name, price, or Gmail data in the exchange-rate request.

    Renewal, trial, budget, and Price Watch notifications are scheduled and delivered using device and operating-system notification services.

    When you visit usepaidly.app or a PolicyForge-hosted policy page, the relevant hosting provider may receive ordinary web-request data such as IP address, browser type, requested page, and timestamp. Paidly does not use advertising cookies in the app.

    7. Purposes and Legal Bases

    Paidly handles information to:

    • provide the app features you request and perform our agreement with you;
    • remember your settings and maintain local records;
    • process purchases and restore entitlements;
    • improve reliability and understand feature use when analytics is enabled;
    • protect the app and prevent fraud; and
    • comply with applicable law.
    Where applicable, our legal bases are performance of a contract, your consent, our legitimate interests in operating and improving the service, and compliance with legal obligations. You can withdraw consent for Gmail access and disable optional analytics without affecting earlier lawful processing.

    8. Sharing and Selling

    Paidly does not sell personal information. Paidly does not share personal information for cross-context behavioral advertising.

    Limited information may be processed by Google Firebase, RevenueCat, Apple, Google Play, Logo.dev, Clearbit, open.er-api.com, notification services, and website or policy hosting providers for the purposes described above. These providers may process information in countries other than your own and under their own terms and privacy policies.

    We may disclose information if required by applicable law or valid legal process. If Paidly is involved in a merger, acquisition, financing, or sale of assets, the limited business records and service-provider data we control may be transferred subject to this Policy. Locally stored subscription and Gmail data is not available to Paidly to transfer.

    9. Retention

    • Local subscription and preference data: remains on your device until you delete it, clear app data, restore the device, or uninstall Paidly, subject to your operating system’s backup behavior.
    • Transient Gmail scan data: remains in app memory only as needed to complete and display the scan. Approved subscription fields become local subscription records.
    • Google authorization: managed by the native Google sign-in libraries and remains until it expires, you disconnect Gmail, or access is otherwise revoked.
    • Analytics: retained according to Paidly’s Firebase configuration and Google’s applicable retention controls.
    • Purchase data: retained by Apple, Google, and RevenueCat according to their policies and applicable legal obligations.

    10. Security

    Paidly minimizes collection by keeping subscription and Gmail processing on your device. Network requests use HTTPS/TLS. Google authorization is managed by native Google sign-in libraries and device security facilities.

    No method of storage or transmission is completely secure. You should protect your device with a passcode or biometric lock, keep its operating system current, and handle exported CSV and backup files carefully.

    11. Your Choices and Rights

    In the app, you can:

    • view, edit, export, and delete subscription records;
    • disable Usage Analytics;
    • disable Price Watch;
    • disconnect Gmail and revoke Google access; and
    • uninstall Paidly to remove app data from the device, subject to operating-system backups.
    Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing of personal information controlled by Paidly, to withdraw consent, and to lodge a complaint with a data-protection authority. Because Paidly does not hold your local subscription or Gmail data on a server, we cannot retrieve or delete that data remotely.

    To make a privacy request concerning information controlled by Paidly, email support@usepaidly.app. We may need to verify your request and may retain information when required by law.

    12. Children

    Paidly is not directed to children under 13, or under the higher minimum age required in their country. We do not knowingly collect children’s personal information. If you believe a child has provided personal information, contact us at support@usepaidly.app.

    13. International Processing

    Service providers may process limited analytics, purchase, and request data in the United States or other countries. Where required, transfers are subject to safeguards provided by applicable law and the relevant service provider. Subscription records and Gmail message processing remain on your device as described above.

    14. Changes

    We may update this Policy to reflect changes to Paidly, our providers, or applicable law. We will update the date above and provide additional notice in the app when appropriate. Material changes apply prospectively from their stated effective date.

    15. Contact