Payday AI: Privacy Policy
Effective date: 5 August 2026 Last updated: 12 September 2026 Data controller / responsible entity: Arthur Felix Pty Ltd (ACN 700 909 235, ABN 60 700 909 235), an Australian company, trading as "Payday AI" ("we", "us", "our"). Privacy contact: support@thepayday.ai (a shared team inbox, not a personal name)
This policy explains what personal information we collect when you use Payday AI and what we do with it. Your AI assistant works with your personal graph inside your conversation. If you choose Payday AI's member features, we also store some personalisation data on our servers: things you save on the website, a record that those things have already been shown to you, the company, trend and growth pages you open while signed in and the ones your assistant looks up (with the date), the businesses returned in a per-member briefing or a recorded search, reactions you give through your assistant, the working graph that Payday AI's connector instructions tell your assistant to back up, and graph edits waiting for your assistant to collect them. When you ask for a short graph-viewer link, we also hold an encrypted display copy for that temporary link. The four metered directory tools also create a pseudonymous daily allowance count. This policy describes each of those records, why we keep it, how long we keep it, and how you can delete it.
1. Our privacy design in one paragraph
Payday AI is a directory of named businesses built by solo founders and tiny teams: what each founder says they make, with sources, alongside Payday AI's own independent estimate, shown as a range with our workings. Seven pages are free to read in full, with no signup: Cal AI's company page; three trend pages (AI image recognition, Calorie tracking, and Weight loss); and three growth-tactic pages (Influencer partnerships, UGC, and Price testing), plus the matching free rows on the Companies, Trends, and Growth pages. Browsing those free pages leaves the same basic technical trace as any other page on the site (your IP address and which page you loaded, described in section 2.4). Every public page, including company, trend, and growth-tactic detail pages, uses the first-party beacon described in section 2.4. Signed-in member pages do not use it. Payday AI does not load remotely supplied analytics code on any page. There is one paid plan, US$30 a month, no free tier. Paying gives you every other page and row, and a connector: a private web address you paste once into an AI assistant such as Claude or ChatGPT so it can look up Payday AI's data for you.
That connection is personal. Your assistant builds up a picture of what you're good at, what you own, what you're aiming for, and what you'd say no to. We call this your "graph." Your assistant works with the graph inside your AI conversation. When it asks Payday AI to make a short graph-viewer link, our server receives the display copy, encrypts it, and stores the encrypted copy under a temporary random identifier. The decryption key is returned only after the # sign in the link; browsers do not send that part back to our server, and we do not store the key. Separately, Payday AI's connector instructions tell your assistant not to ask you and to send a full working copy to our server at the end of onboarding and after changes, so a later conversation or device can restore it.
A daily-drop graph is different: it contains only member-blind public directory evidence, and its complete link is frozen with that day's drop so the briefing can arrive in one connector call.
We also store the things you save on Payday AI, a record that a saved item has already been shown to you, the company, trend and growth pages you open while signed in and the ones your assistant looks up (each with its date), per-member briefing and recorded-search history, the reactions and reasons you give through your assistant, and graph edits waiting for your assistant to collect them. Separately, we hold your account email, Stripe billing identifiers and events, subscription status, private connector credential, website session records, activation milestones, records of connector and account use, and the pseudonymous daily allowance count described in section 2.3. We never sell your personal information.
2. What we collect
2.1 To run your subscription
- Email address. Collected when you subscribe through Stripe Checkout. Used to send your payment confirmation and service emails, and to reply if you contact support.
- Payment details, handled by Stripe, not by us. Stripe is our payment processor. Stripe collects your card details directly; we never see or store your full card number. Stripe shares back with us customer and subscription IDs, your subscription status, and typically your email for payment confirmations. We also keep checkout-session digests and Stripe event IDs in the access history. Our billing-event records can include checkout-session and invoice IDs, customer and subscription IDs, the amount and currency paid, why Stripe billed the payment, failed-payment attempt counts, and the next retry time. Payday AI is sold through Stripe Managed Payments, under which Stripe is the merchant of record for your payment: the charge, the receipt and the tax on it come from Stripe. Arthur Felix Pty Ltd operates the Payday AI service you are subscribing to and is the data controller for the personal information this policy describes. Stripe's own handling of your payment details is governed by Stripe's privacy policy: https://stripe.com/privacy.
- Your connector link. A private, hard-to-guess web address you paste into your AI assistant's settings once. It identifies your subscription to our server on every call your assistant makes. By design this link does not change on its own, so treat it like a password. A replacement works immediately, but the old address normally keeps working for another 30 days and remains in our billing and access records after it stops working. If it is exposed, contact support so we can arrange a replacement.
- Your stable member identifier. We create a random internal identifier for your membership and keep it with the connector and entitlement history. Personalisation records use this identifier rather than the connector credential, so replacing a credential does not create a different member or split the member's saved data. It is not shown in page addresses or ordinary application logs.
- Correction and support messages. If you email us, including to dispute or ask about a correction, we hold whatever you send us, including your message and your email address if you give it, so we can respond.
- Correction-form records. If you submit the correction form, we store a random reference, receipt time, status, company, disputed figure, your correction detail, any name and reply address you give, your IP address, and any quarantine flag applied to suspected automated submissions.
2.2 Your graph, reactions, and queued edits
- Private hosted member-graph display and graph backups are different. Your assistant sends the display graph to Payday AI over HTTPS when it asks for a short viewer link. Payday AI encrypts it before storing it using a fresh key. We store the encrypted display copy, a random link identifier, when the link was created and will expire, and a code that ties it to the member without putting the member's identifier in the link record. The decryption key stays after the
#sign in the link; it is not persisted by Payday AI or sent back by a browser in an HTTP request or ordinary access log. The temporary encrypted copy is only for displaying that link; it is not the restorable backup. Technical note: the stored security fields include the encrypted payload, its encryption IV, and a one-way member-owner hash. The separate daily-drop graph contains only member-blind public directory evidence, and its complete link is stored in the frozen member-blind drop so that one read can return the whole briefing. Separately, Payday AI's connector instructions tell your assistant to store the fuller working graph on our server as part of your membership, so it shows on your graph page and every briefing reads it. It can include the skills, assets, goals, preferences, links, and notes your assistant put in the graph, and lets your connected assistant restore the graph in a later conversation or on another device. You can delete it at any time from your graph page or by asking your assistant. - Reactions. When you approve or reject an idea through your connected assistant, we store a reaction record. New records include the result, a plain-English reference to the idea, the idea's label and detail when available, the reason you gave in your own words, an optional person label supplied by the assistant, the Payday AI product format used, and the time. Older reaction records may instead retain a legacy internal idea identifier; that identifier is not returned in reaction history. We use that history to show your reactions on your graph page and make earlier decisions available to your connected assistant. A direct reaction-history request currently returns the most recent 50 records; the graph-page view is built separately from all reaction rows we still hold.
- Queued graph edits. When you approve, reject, edit, add, or undo something in the graph viewer, we store that single change until your assistant collects it. The short-lived edit key used by the viewer stops authorising changes after 72 hours. Its expired database row is removed the next time a key is created or checked, or by the full deletion in section 8; without either event, that unusable row can remain longer. Collecting a queued edit removes that edit from the queue. If it is never collected, it remains until you use the full deletion described in section 8.
- Links on your ideas. On your Founder Graph you can link trends, companies and growth tactics to an idea on your board, mark each tactic's status (your launch strategy, one you're trying next, one that's working, or one you've retired or that didn't work), add the months you started and stopped if you choose to, and write your own private note about a tactic. We store which ideas they belong to, the public Payday AI page identifiers of what you linked, the status and months you chose, any note you wrote, and when you last changed them. Your note is private: only you can read it, and your connected assistant does not. Your connected assistant can read your trends, companies and tactic statuses when it asks about your ideas, so its suggestions build on what you are doing, and can add, change or remove them when you ask it to, but it never reads or writes your notes. When it changes one of your lists, we also keep a record that it did, when, and the list as it was just before, so you can undo the change. They are never shown publicly.
- We do not receive your conversation itself: not the questions you ask your assistant, its reasoning, or its other answers. We receive only the records a Payday AI tool sends, such as a graph backup, a reaction, or a queued edit.
2.3 How you use the connector
- Every time your connected assistant calls Payday AI, our own connector-usage log records the date and time, the protocol action or Payday AI feature called, the outcome, a broad response-size band, a broad duration band, the product format in use where relevant, and whether the member is an internal account. It also includes a 16-character member code made from the stable member identifier and a secret monthly key. The code changes each month. Because Payday AI has the stable member identifiers and the secret, it can recompute the code and match it to a member within that month. This tells us whether the service is being used and helps us diagnose faults.
- That log does not include any part of the connector credential, the tool arguments, or the content returned. In particular, it does not record saved-item identifiers or labels, graph contents, reaction text, or queued-edit text.
- The same usage store receives fixed, content-free action names for a site view, save or removal, a sign-in code request, a successful email or Google sign-in, a checkout start, connector reset, billing-portal open, graph edit, or correction submission. The monthly member code is included when the action is tied to a known member. These action records contain no arbitrary properties supplied by the member.
- Per-member briefing and recorded-search history. When this feature is available to your membership, Payday AI briefly keeps the returned briefing so a retry can receive the identical answer. It stores when the request started and completed, the date used, identifiers used to recognise the request and retry, the exact response, and which businesses were returned and in what position. A successful directory search that returns at least one business stores when it happened and the public identifiers of those businesses, but not the search terms or the rest of the search response. These records use your stable member identifier. Payday AI uses them to continue down your queue without presenting an earlier return as a fresh discovery. To rank the queue, the server uses your current saved companies and the confirmed skills, assets, interests, goals, strengths, constraints, and dislikes in your stored graph. A confirmed constraint or dislike can lower a candidate, and a confirmed rule against an industry or type of customer can exclude it. The server does not receive your conversation, and a returned record does not prove that you read it.
- Daily directory-data allowance counter. Each call to one of the four metered directory tools uses one of the 400 Payday AI data-tool calls per membership in one UTC day, including a call whose lookup later errors. A separate allowance ledger is keyed to a one-way SHA-256 hash of your stable internal member identifier, not your raw connector link, and records only the UTC date and count. This is the same durable identifier used to key personalisation records, but only its one-way hash is written to the allowance ledger. Entries older than 31 days are deleted. The daily drop and the per-member briefing neither use nor consume this allowance, so the counter cannot lock you out of either one when that briefing is available to your membership.
2.4 When you browse the website
- Basic technical logs, such as IP address, request time, and which page or feature was called, kept to run, secure, and debug the service. Some delivery and billing fault messages can contain a masked email address or the last six characters of a connector credential, but not the full credential.
- First-party analytics beacon. Every public page, including pages with Save controls, contains a short script written into Payday AI's own page. It sends Plausible a
pageviewevent. It sends the site domain and the page origin and path; Payday AI's code deliberately leaves out the query string and fragment. The request also carries the IP address and browser user-agent that accompany an ordinary web request. Plausible says it uses those two values to calculate a daily identifier, derives approximate country, region and city plus browser, operating system and device type, then discards the raw IP address and user-agent. It says it does not use cookies or persistent identifiers. The event does not contain your query string, connector credential, stable member identifier, saves, graph, reactions, or queued edits. Payday AI does not load Plausible's JavaScript or any other remotely supplied script. It can also send one of 13 fixed action events: a click to start, one of eight named start choices, a pricing view, a payment submission, a signed-out Save click, or a source-link click. Action events send only the fixed event name and the site's root address, with no arbitrary event properties. The beacon is omitted from member pages, including your account and graph. Basic server logs described above still record the page or feature requested. - Web fonts. Pages request font stylesheets and font files from Google Fonts. That request gives Google the ordinary technical request data its privacy policy describes, including IP address, browser and device information, request time and the referrer URL the browser supplies. The font request does not contain your connector credential, stable member identifier, saves, graph, reactions, or queued edits. Blocking the font request changes the typeface, not the page's function.
2.5 When you sign in and save things
- Website saves. When you save a company, trend, or growth tactic, we store the type of item, its public page identifier and label, when you most recently saved it, and whether it is currently saved. The label comes from Payday AI's own page; the save form does not let you store arbitrary text in this record.
- Saved-item history. Saving also records that the item has already been shown to you and the time of that first save. This is sometimes called an impression. We keep that record after you remove the item from your saved list. When it asks Payday AI for your website profile, your connected assistant can read both current saves and the retained impression list, and is told never to present an item on that list as a fresh discovery. We keep one current record for each item, not a history of every time you pressed Save or Remove.
- Your graph page. The signed-in graph page brings your saves and reactions together. Only a signed-in member can request it. We mark it not to be stored by browser or shared caches. Payday AI does not load third-party scripts on this page or on the site's other pages.
- Your signed-in session. Our server stores an opaque session identifier, the connector credential it maps to, and the dates it was created and last used. Looking at a signed-in page updates that last-used date. The cookie in your browser contains an opaque, signed value rather than your saves or graph. That browser cookie expires 30 days after sign-in and is not extended by later activity. A server-side session row is removed when it is checked after 30 days without use, when you sign out, or when you use Sign out everywhere. If an expired row is never checked again, it can remain until later maintenance removes it.
- Activation milestones. Against your stable member identifier, we record only the first time we see each of these events: sign-in, connector call, website save, per-member briefing pull, and graph change. We use these timestamps to understand whether members reach the main service steps. They remain until you use the full personalisation-data deletion, which removes the row for your member identifier.
Removing one saved item removes it from your current saved list, but keeps the saved-item history described above. To delete the saved-item history and the rest of your Payday AI personalisation data, use Delete Payday AI personalisation data on your graph page or ask your connected assistant to run delete_profile. Both routes delete the same records, including encrypted temporary graph-viewer links, and remain available when a membership is no longer active. Section 8 explains exactly what that full deletion does and does not remove.
2.6 What we deliberately do not collect
- We do not run any AI processing of our own on your conversations. That happens entirely inside your own AI assistant, governed by that provider's own policy.
- We do not receive or store the decryption key held after the
#sign in a short graph-viewer link. We do receive the display copy when your assistant asks us to encrypt it for that link, as described in section 2.2. - A frozen daily evidence graph is member-blind public directory content, not a copy of your graph or conversation.
- We never see or store your full card number. Stripe holds that.
- We do not seek sensitive information such as health details or beliefs, and ask that you not put it in graph backups, reactions, reasons, queued edits, support messages, or other material you send us.
3. Why we use it (purposes)
- to provide the service and give you the features your plan covers;
- to take payment and manage your subscription, through Stripe;
- to respond to support requests and correction or dispute messages, and to send service and account emails;
- to keep the website and your connected assistant working from the same saves, graph backup, reactions, and queued edits;
- to give your connected assistant the current saves it should not describe as fresh discoveries, and to retain first-save impression history;
- to rank eligible businesses using current company saves and confirmed graph entries, remember briefing and search returns, replay a retried briefing, and keep walking down the unseen queue;
- to secure the service, apply fair-use limits, and prevent abuse or scraping;
- to diagnose faults and improve the service; and
- to meet our own legal, tax, and accounting obligations.
We rely, as applicable, on performing our contract with you, our legitimate interest in running and securing the service, and our legal obligations.
4. We do not sell your data
We do not sell, rent, or trade your personal information, and we do not share it for third-party advertising. We share personal information only with the service providers we need to run the business, and with the AI assistant provider you direct us to send your member data to through the connector. See section 6 for the full list.
5. Cookies
Payday AI's connector does not use cookies. It identifies you by the connector link described in section 2.1.
The website sets no non-essential cookies, so there is no consent banner to click. The one cookie it does set is strictly necessary: when you sign in, we set a session cookie so the site knows it is still you on the next page. The page-view beacon described in section 2.4 sets no cookie, and Payday AI does not load the analytics provider's JavaScript. If we ever add a cookie that is not strictly necessary, we will describe it here and ask your consent before setting it.
6. Who we share with (categories of recipients)
- Payment processor - Stripe, for billing and fraud prevention.
- Email provider - Postmark, for account, payment confirmation, and support email.
- Hosting and infrastructure provider - Fly.io, to run our server.
- Website analytics provider - Plausible, which receives the page-view and fixed action events described in section 2.4 from public pages. Its code does not run on Payday AI's website.
- Web-font provider - Google Fonts, which receives the technical request data described in section 2.4 when a browser asks it for font stylesheets and files.
- Your chosen AI assistant provider - when you connect an assistant and it asks Payday AI for your briefing, saved items, graph backup, reactions, or queued edits, we return the requested records to that provider at your direction. Its handling of that data is governed by its own terms and privacy policy.
- Professional advisers and authorities - our accountant and lawyer, or regulators and law enforcement where legally required.
- A successor - if the business is sold or reorganised, information may transfer to the buyer under equivalent privacy obligations.
Some of these providers process data overseas. See section 9.
7. How long we keep it
| What | How long | Why |
|---|---|---|
| Subscription and payment records (email, Stripe customer and subscription IDs, checkout-session digests, Stripe event IDs, checkout-session IDs, invoice IDs, subscription status, payment amount and currency, billing reason, failed-payment attempts and next retry time) | Kept for as long as your subscription is active, then as long as required for legal, tax, and accounting purposes. | These records operate billing and access and provide a history of Stripe payment events. |
| Your connector link | The credential is recorded in our append-only entitlement history with no automatic deletion date. Cancelling changes its access status but does not remove the record. Asking for a replacement creates a new credential; the old one normally continues to work for a 30-day grace period and remains in the entitlement history after access expires. In plain English, old connector addresses stay in our billing and access records, the replacement works immediately, and the old address normally keeps working for 30 days before it stops. | It identifies the subscription presented to our connector. A replacement requires removing and re-adding the connector in your AI assistant. |
| Stable member identifier | Kept in the append-only entitlement history with no automatic deletion date, including after cancellation, credential replacement, or personalisation-data deletion. In plain English, the member identifier stays in our billing and access records even when an address changes or stops working. | It keeps one membership tied to its entitlement events without using a changeable connector credential as the personalisation key. |
| Website saves | A current save stays until you remove it or use the full personalisation-data deletion. Removing it leaves the saved-item history described below. | This is the current saved list you see on your graph page and that your connected assistant can read. |
| Saved-item history | Removing an item from your saved list does not remove the record that it was first saved. That record stays until you use the full personalisation-data deletion. | It records the first-save impression. Your connected assistant can read this retained list when it asks for your website profile, and we do not keep a row for every press of Save or Remove. |
| Per-member briefing and recorded-search history | The exact briefing response is erased after 24 hours. Returned-business lists and search-impression rows are erased after 30 days. Briefing request and pull records are erased after 31 days. Full personalisation-data deletion removes these records sooner. Separate saves, saved-item history and signed-in page-view history can preserve a longer-lived compact record that an item was already shown, under their own rows in this table. | The short periods make retries stable and stop a recently returned business appearing as a fresh discovery. The compact state prevents saved or viewed items being presented as fresh later. |
| Graph backup | We keep the latest live backup until your assistant replaces it or you use the full personalisation-data deletion. A newer successful backup replaces the previous one in the live store; provider snapshots described below can temporarily retain an earlier copy. | A later conversation or device can restore the latest live copy. |
| Encrypted temporary graph-viewer links | A viewer link normally stops resolving after about 72 hours. It can stop sooner if a member creates more than 200 live links, because the oldest is removed. Expired records are removed when any viewer link is next checked or another link is created; without either event, an expired encrypted row can remain longer. Full personalisation-data deletion removes that member's rows from the live store. | The short link needs a temporary encrypted display payload. Payday AI does not persist the decryption key. |
| Reactions, including labels, details, and reasons | Kept until you use the full personalisation-data deletion. We do not currently expire them automatically. | They let your graph page show decisions and make those records available to connected-assistant tools. |
| Queued graph edits and graph-edit keys | A queued edit is cleared when your assistant collects it or when you use the full personalisation-data deletion. We do not currently apply a shorter automatic expiry to the edit itself. Its separate key stops authorising edits after 72 hours, but the expired key row is removed only when a key is next created or checked, during full deletion, or by later maintenance. | This is a handoff between the graph viewer and your connected assistant. |
| Links on your ideas | Kept until you remove them, permanently delete the idea, or use the full personalisation-data deletion. When your assistant changes one of your lists, the copy of that list as it was just before is kept until you press Undo or Keep on it, change that list yourself, permanently delete the idea, or use the full deletion. A link that belongs to an idea no longer on your board is removed the next time you change any link, or by the full deletion. If the file that holds them cannot be read, the full deletion leaves it untouched, tells you so, and we erase your links by hand when you email support@thepayday.ai. | They show on your ideas, let your connected assistant build on the tactics you use and change them when you ask, and let you undo a change it made. |
| Website session records | The browser cookie expires 30 days after sign-in and is not renewed when you use the site. A successful signed-in check updates the server row's last-used time. The row is removed if it is checked after 30 days without use, when you sign out, or when you use Sign out everywhere. A stale row that is never checked again can remain until later maintenance removes it. | These records let the website recognise a signed-in browser and cut off access when you sign out. |
| Activation milestones | First sign-in, first connector call, first website save, first per-member briefing pull and first graph-change times remain until you use the full personalisation-data deletion. | Shows whether a member reached the service's main steps without keeping every occurrence in this record. |
| Raw connector-usage and account-action log (section 2.3) | Raw lines, including the monthly member code where one is available, remain for about 31 days. Daily maintenance then adds their fixed event counts to member-free monthly totals and removes the raw file. Personalisation-data deletion does not target these logs. | Raw lines help diagnose recent use. Monthly totals contain event counts, not member codes, and are kept indefinitely. |
| Pseudonymous daily directory-data allowance counters (section 2.3) | Entries are kept for 31 days; entries older than 31 days are deleted by scheduled maintenance. | Enforces the 400-call per-member UTC-day limit without storing the raw connector link in the allowance ledger. The daily drop and per-member briefing are exempt. |
| Basic technical and operational logs | The application does not currently enforce one fixed automatic deletion date. Retention depends on the kind of record, routine maintenance, and the settings of the provider that holds it. | Used to run, secure, and diagnose the service. |
| Aggregated website analytics | Payday AI has not configured a separate automatic deletion period. Plausible retains the site statistics while the site account remains active, subject to that service's settings; the owner can delete the site statistics or account. | Used to understand which public pages are read and which fixed actions occur. The raw IP address and user-agent are not retained by Plausible according to its published data policy. |
| Google Fonts request data | Google applies the retention periods in its own privacy policy; they vary by the kind of data and purpose. Payday AI does not receive a copy in its member store and cannot delete Google's request logs through the personalisation-data deletion. | Used to deliver the site's typefaces. |
| Support emails | Kept until no longer needed for support, subject to any legal retention requirement. The running server has no automatic email-deletion or request-deletion workflow. | Lets us respond and keep any support record still needed. |
| Correction-form records | After 12 months, maintenance erases the submitter name, reply address, IP address and any legacy reply field. The random reference, receipt time, company, disputed figure, correction detail, status and any quarantine flag remain with no automatic deletion date. The running server has no request-deletion workflow for these records. | Keeps the substance and review state of a correction while removing its listed identity and contact fields after 12 months. |
Some connector and stable-member histories have no automatic deletion date; basic logs have no fixed date; reactions and uncollected queued edits can remain until personalisation deletion.
The periods above describe Payday AI's live product records. They sit on a Fly.io volume. Fly.io says it automatically takes daily volume snapshots and keeps them for five days by default, although a volume's actual setting can be changed. See https://fly.io/docs/volumes/snapshots/. The personalisation-data deletion removes the listed records from Payday AI's live store; it cannot rewrite an already-made provider snapshot. Deleted data can therefore remain in one of those snapshots until the snapshot expires, and restoring an older snapshot could put it back into the live store. A restored copy would need to be identified and deleted again. Payday AI does not currently create a separate backup of member personalisation data outside Fly.io.
The personalisation-data deletion does not target the separate stable member identifier, account, connector and entitlement history, pseudonymous daily allowance counters, billing, session, support, or operational records described here.
8. Your rights and choices
- Access and correction (Australian Privacy Act): you can ask what personal information we hold about you and ask us to correct it. Contact support@thepayday.ai.
- Deletion: you can cancel your subscription at any time and ask us to delete personal information we're not legally required to keep. Some records, such as billing information kept for tax purposes, must be retained regardless.
- Remove one save: use its Remove button on your graph page. This removes it from your saved list. The saved-item history remains for the reason explained in section 2.5.
- Delete your Payday AI personalisation data: use Delete Payday AI personalisation data on the signed-in graph page, or ask your connected assistant to run
delete_profile. Either route deletes your website saves, saved-item history, view and lookup history, activation milestones, per-member briefing and recorded-search history, graph backup, reactions, links on your ideas, queued edits, live graph-edit keys, and encrypted temporary graph-viewer links from the active product store. You can use the signed-in route even if your membership is lapsed or revoked. - What that full deletion does not do: it does not cancel your subscription, close your account, remove your stable member identifier, connector and entitlement history, account email or billing records, delete support messages or ordinary operational logs, remove pseudonymous daily allowance counters, or sign out the browser you are using. Those records have the separate retention and deletion rules in section 7; allowance-counter entries are deleted on their 31-day schedule. You can contact support@thepayday.ai about a separate account-deletion request. The current automatic personalisation-data deletion does not perform that account process.
- For EU/UK users: where GDPR or UK GDPR applies, you also have rights to access, correct, erase, restrict, and object to processing, to data portability, and to complain to your own supervisory authority.
- Complaints: contact us first at support@thepayday.ai. If you're not satisfied, in Australia you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Overseas / cross-border data
Some of our service providers store or process data outside Australia. Stripe and Postmark are both US-based; our hosting provider, Fly.io, may run servers in more than one country. Plausible says the visitor data used for its aggregated analytics is processed and stored in the European Union on European-owned infrastructure. Google Fonts is also an overseas provider and handles its request data under Google's privacy policy. Where processing happens outside Australia, we take reasonable steps to ensure your information is handled consistently with this policy and with Australian law.
10. Security
We take reasonable technical and organisational steps to protect personal information: using reputable providers, collecting as little as the design above allows, keeping payment details with Stripe rather than on our own systems, and applying access controls, request-size limits, rate limits, and cross-site request protections. The signed-in graph page requires an account session and is marked not to be cached. We do not load third-party JavaScript anywhere on the website because code running on any page of this origin could otherwise reach signed-in member routes. The limited analytics request described in section 2.4 is made by Payday AI's own inline code. Every public page sends it, including pages with Save controls, while member pages omit it. The first-party Save control asks whether one identified public item is saved, and the state route returns only that item's status rather than the whole saved list. We link personalisation records to a stable internal member identifier rather than using the raw connector credential as their storage key. The save, graph, reaction, and queued-edit routes do not put that stable identifier or the content of those records in a query string or application log line. Other operational logs can contain the masked identifiers described in section 2.4. Public page addresses contain public item identifiers; the address does not say whether a member saved the item.
Your connector link is a private credential, similar to a password, and by design it does not rotate on its own. If you replace a leaked link, the replacement works immediately but the old link normally keeps working for another 30 days. Telling us about the leak does not itself end the old link's validity. No system is perfectly secure and we cannot guarantee absolute security. If a data breach likely to cause serious harm occurs, we will act consistently with the Notifiable Data Breaches scheme under the Privacy Act.
11. Children
The service is intended for adults (18+) and is not directed at children. We do not knowingly collect personal information from children.
12. Applicability of the Australian Privacy Act
Small businesses under a turnover threshold are normally exempt from most of the federal Privacy Act. Whether Payday AI's own product design means we don't qualify for that exemption is a real, open question.
13. Changes to this policy
We may update this policy from time to time. We'll notify you of material changes by email or an in-service notice before they take effect. The "last updated" date at the top shows the current version.