Payday AI: Privacy Policy

Effective date: 5 August 2026 Last updated: 12 September 2026 Data controller / responsible entity: Arthur Felix Pty Ltd (ACN 700 909 235, ABN 60 700 909 235), an Australian company, trading as "Payday AI" ("we", "us", "our"). Privacy contact: support@thepayday.ai (a shared team inbox, not a personal name)

This policy explains what personal information we collect when you use Payday AI and what we do with it. Your AI assistant works with your personal graph inside your conversation. If you choose Payday AI's member features, we also store some personalisation data on our servers: things you save on the website, a record that those things have already been shown to you, the company, trend and growth pages you open while signed in and the ones your assistant looks up (with the date), the businesses returned in a per-member briefing or a recorded search, reactions you give through your assistant, the working graph that Payday AI's connector instructions tell your assistant to back up, and graph edits waiting for your assistant to collect them. When you ask for a short graph-viewer link, we also hold an encrypted display copy for that temporary link. The four metered directory tools also create a pseudonymous daily allowance count. This policy describes each of those records, why we keep it, how long we keep it, and how you can delete it.


1. Our privacy design in one paragraph

Payday AI is a directory of named businesses built by solo founders and tiny teams: what each founder says they make, with sources, alongside Payday AI's own independent estimate, shown as a range with our workings. Seven pages are free to read in full, with no signup: Cal AI's company page; three trend pages (AI image recognition, Calorie tracking, and Weight loss); and three growth-tactic pages (Influencer partnerships, UGC, and Price testing), plus the matching free rows on the Companies, Trends, and Growth pages. Browsing those free pages leaves the same basic technical trace as any other page on the site (your IP address and which page you loaded, described in section 2.4). Every public page, including company, trend, and growth-tactic detail pages, uses the first-party beacon described in section 2.4. Signed-in member pages do not use it. Payday AI does not load remotely supplied analytics code on any page. There is one paid plan, US$30 a month, no free tier. Paying gives you every other page and row, and a connector: a private web address you paste once into an AI assistant such as Claude or ChatGPT so it can look up Payday AI's data for you.

That connection is personal. Your assistant builds up a picture of what you're good at, what you own, what you're aiming for, and what you'd say no to. We call this your "graph." Your assistant works with the graph inside your AI conversation. When it asks Payday AI to make a short graph-viewer link, our server receives the display copy, encrypts it, and stores the encrypted copy under a temporary random identifier. The decryption key is returned only after the # sign in the link; browsers do not send that part back to our server, and we do not store the key. Separately, Payday AI's connector instructions tell your assistant not to ask you and to send a full working copy to our server at the end of onboarding and after changes, so a later conversation or device can restore it.

A daily-drop graph is different: it contains only member-blind public directory evidence, and its complete link is frozen with that day's drop so the briefing can arrive in one connector call.

We also store the things you save on Payday AI, a record that a saved item has already been shown to you, the company, trend and growth pages you open while signed in and the ones your assistant looks up (each with its date), per-member briefing and recorded-search history, the reactions and reasons you give through your assistant, and graph edits waiting for your assistant to collect them. Separately, we hold your account email, Stripe billing identifiers and events, subscription status, private connector credential, website session records, activation milestones, records of connector and account use, and the pseudonymous daily allowance count described in section 2.3. We never sell your personal information.

2. What we collect

2.1 To run your subscription

2.2 Your graph, reactions, and queued edits

2.3 How you use the connector

2.4 When you browse the website

2.5 When you sign in and save things

Removing one saved item removes it from your current saved list, but keeps the saved-item history described above. To delete the saved-item history and the rest of your Payday AI personalisation data, use Delete Payday AI personalisation data on your graph page or ask your connected assistant to run delete_profile. Both routes delete the same records, including encrypted temporary graph-viewer links, and remain available when a membership is no longer active. Section 8 explains exactly what that full deletion does and does not remove.

2.6 What we deliberately do not collect

3. Why we use it (purposes)

We rely, as applicable, on performing our contract with you, our legitimate interest in running and securing the service, and our legal obligations.

4. We do not sell your data

We do not sell, rent, or trade your personal information, and we do not share it for third-party advertising. We share personal information only with the service providers we need to run the business, and with the AI assistant provider you direct us to send your member data to through the connector. See section 6 for the full list.

5. Cookies

Payday AI's connector does not use cookies. It identifies you by the connector link described in section 2.1.

The website sets no non-essential cookies, so there is no consent banner to click. The one cookie it does set is strictly necessary: when you sign in, we set a session cookie so the site knows it is still you on the next page. The page-view beacon described in section 2.4 sets no cookie, and Payday AI does not load the analytics provider's JavaScript. If we ever add a cookie that is not strictly necessary, we will describe it here and ask your consent before setting it.

6. Who we share with (categories of recipients)

Some of these providers process data overseas. See section 9.

7. How long we keep it

WhatHow longWhy
Subscription and payment records (email, Stripe customer and subscription IDs, checkout-session digests, Stripe event IDs, checkout-session IDs, invoice IDs, subscription status, payment amount and currency, billing reason, failed-payment attempts and next retry time)Kept for as long as your subscription is active, then as long as required for legal, tax, and accounting purposes.These records operate billing and access and provide a history of Stripe payment events.
Your connector linkThe credential is recorded in our append-only entitlement history with no automatic deletion date. Cancelling changes its access status but does not remove the record. Asking for a replacement creates a new credential; the old one normally continues to work for a 30-day grace period and remains in the entitlement history after access expires. In plain English, old connector addresses stay in our billing and access records, the replacement works immediately, and the old address normally keeps working for 30 days before it stops.It identifies the subscription presented to our connector. A replacement requires removing and re-adding the connector in your AI assistant.
Stable member identifierKept in the append-only entitlement history with no automatic deletion date, including after cancellation, credential replacement, or personalisation-data deletion. In plain English, the member identifier stays in our billing and access records even when an address changes or stops working.It keeps one membership tied to its entitlement events without using a changeable connector credential as the personalisation key.
Website savesA current save stays until you remove it or use the full personalisation-data deletion. Removing it leaves the saved-item history described below.This is the current saved list you see on your graph page and that your connected assistant can read.
Saved-item historyRemoving an item from your saved list does not remove the record that it was first saved. That record stays until you use the full personalisation-data deletion.It records the first-save impression. Your connected assistant can read this retained list when it asks for your website profile, and we do not keep a row for every press of Save or Remove.
Per-member briefing and recorded-search historyThe exact briefing response is erased after 24 hours. Returned-business lists and search-impression rows are erased after 30 days. Briefing request and pull records are erased after 31 days. Full personalisation-data deletion removes these records sooner. Separate saves, saved-item history and signed-in page-view history can preserve a longer-lived compact record that an item was already shown, under their own rows in this table.The short periods make retries stable and stop a recently returned business appearing as a fresh discovery. The compact state prevents saved or viewed items being presented as fresh later.
Graph backupWe keep the latest live backup until your assistant replaces it or you use the full personalisation-data deletion. A newer successful backup replaces the previous one in the live store; provider snapshots described below can temporarily retain an earlier copy.A later conversation or device can restore the latest live copy.
Encrypted temporary graph-viewer linksA viewer link normally stops resolving after about 72 hours. It can stop sooner if a member creates more than 200 live links, because the oldest is removed. Expired records are removed when any viewer link is next checked or another link is created; without either event, an expired encrypted row can remain longer. Full personalisation-data deletion removes that member's rows from the live store.The short link needs a temporary encrypted display payload. Payday AI does not persist the decryption key.
Reactions, including labels, details, and reasonsKept until you use the full personalisation-data deletion. We do not currently expire them automatically.They let your graph page show decisions and make those records available to connected-assistant tools.
Queued graph edits and graph-edit keysA queued edit is cleared when your assistant collects it or when you use the full personalisation-data deletion. We do not currently apply a shorter automatic expiry to the edit itself. Its separate key stops authorising edits after 72 hours, but the expired key row is removed only when a key is next created or checked, during full deletion, or by later maintenance.This is a handoff between the graph viewer and your connected assistant.
Links on your ideasKept until you remove them, permanently delete the idea, or use the full personalisation-data deletion. When your assistant changes one of your lists, the copy of that list as it was just before is kept until you press Undo or Keep on it, change that list yourself, permanently delete the idea, or use the full deletion. A link that belongs to an idea no longer on your board is removed the next time you change any link, or by the full deletion. If the file that holds them cannot be read, the full deletion leaves it untouched, tells you so, and we erase your links by hand when you email support@thepayday.ai.They show on your ideas, let your connected assistant build on the tactics you use and change them when you ask, and let you undo a change it made.
Website session recordsThe browser cookie expires 30 days after sign-in and is not renewed when you use the site. A successful signed-in check updates the server row's last-used time. The row is removed if it is checked after 30 days without use, when you sign out, or when you use Sign out everywhere. A stale row that is never checked again can remain until later maintenance removes it.These records let the website recognise a signed-in browser and cut off access when you sign out.
Activation milestonesFirst sign-in, first connector call, first website save, first per-member briefing pull and first graph-change times remain until you use the full personalisation-data deletion.Shows whether a member reached the service's main steps without keeping every occurrence in this record.
Raw connector-usage and account-action log (section 2.3)Raw lines, including the monthly member code where one is available, remain for about 31 days. Daily maintenance then adds their fixed event counts to member-free monthly totals and removes the raw file. Personalisation-data deletion does not target these logs.Raw lines help diagnose recent use. Monthly totals contain event counts, not member codes, and are kept indefinitely.
Pseudonymous daily directory-data allowance counters (section 2.3)Entries are kept for 31 days; entries older than 31 days are deleted by scheduled maintenance.Enforces the 400-call per-member UTC-day limit without storing the raw connector link in the allowance ledger. The daily drop and per-member briefing are exempt.
Basic technical and operational logsThe application does not currently enforce one fixed automatic deletion date. Retention depends on the kind of record, routine maintenance, and the settings of the provider that holds it.Used to run, secure, and diagnose the service.
Aggregated website analyticsPayday AI has not configured a separate automatic deletion period. Plausible retains the site statistics while the site account remains active, subject to that service's settings; the owner can delete the site statistics or account.Used to understand which public pages are read and which fixed actions occur. The raw IP address and user-agent are not retained by Plausible according to its published data policy.
Google Fonts request dataGoogle applies the retention periods in its own privacy policy; they vary by the kind of data and purpose. Payday AI does not receive a copy in its member store and cannot delete Google's request logs through the personalisation-data deletion.Used to deliver the site's typefaces.
Support emailsKept until no longer needed for support, subject to any legal retention requirement. The running server has no automatic email-deletion or request-deletion workflow.Lets us respond and keep any support record still needed.
Correction-form recordsAfter 12 months, maintenance erases the submitter name, reply address, IP address and any legacy reply field. The random reference, receipt time, company, disputed figure, correction detail, status and any quarantine flag remain with no automatic deletion date. The running server has no request-deletion workflow for these records.Keeps the substance and review state of a correction while removing its listed identity and contact fields after 12 months.

Some connector and stable-member histories have no automatic deletion date; basic logs have no fixed date; reactions and uncollected queued edits can remain until personalisation deletion.

The periods above describe Payday AI's live product records. They sit on a Fly.io volume. Fly.io says it automatically takes daily volume snapshots and keeps them for five days by default, although a volume's actual setting can be changed. See https://fly.io/docs/volumes/snapshots/. The personalisation-data deletion removes the listed records from Payday AI's live store; it cannot rewrite an already-made provider snapshot. Deleted data can therefore remain in one of those snapshots until the snapshot expires, and restoring an older snapshot could put it back into the live store. A restored copy would need to be identified and deleted again. Payday AI does not currently create a separate backup of member personalisation data outside Fly.io.

The personalisation-data deletion does not target the separate stable member identifier, account, connector and entitlement history, pseudonymous daily allowance counters, billing, session, support, or operational records described here.

8. Your rights and choices

9. Overseas / cross-border data

Some of our service providers store or process data outside Australia. Stripe and Postmark are both US-based; our hosting provider, Fly.io, may run servers in more than one country. Plausible says the visitor data used for its aggregated analytics is processed and stored in the European Union on European-owned infrastructure. Google Fonts is also an overseas provider and handles its request data under Google's privacy policy. Where processing happens outside Australia, we take reasonable steps to ensure your information is handled consistently with this policy and with Australian law.

10. Security

We take reasonable technical and organisational steps to protect personal information: using reputable providers, collecting as little as the design above allows, keeping payment details with Stripe rather than on our own systems, and applying access controls, request-size limits, rate limits, and cross-site request protections. The signed-in graph page requires an account session and is marked not to be cached. We do not load third-party JavaScript anywhere on the website because code running on any page of this origin could otherwise reach signed-in member routes. The limited analytics request described in section 2.4 is made by Payday AI's own inline code. Every public page sends it, including pages with Save controls, while member pages omit it. The first-party Save control asks whether one identified public item is saved, and the state route returns only that item's status rather than the whole saved list. We link personalisation records to a stable internal member identifier rather than using the raw connector credential as their storage key. The save, graph, reaction, and queued-edit routes do not put that stable identifier or the content of those records in a query string or application log line. Other operational logs can contain the masked identifiers described in section 2.4. Public page addresses contain public item identifiers; the address does not say whether a member saved the item.

Your connector link is a private credential, similar to a password, and by design it does not rotate on its own. If you replace a leaked link, the replacement works immediately but the old link normally keeps working for another 30 days. Telling us about the leak does not itself end the old link's validity. No system is perfectly secure and we cannot guarantee absolute security. If a data breach likely to cause serious harm occurs, we will act consistently with the Notifiable Data Breaches scheme under the Privacy Act.

11. Children

The service is intended for adults (18+) and is not directed at children. We do not knowingly collect personal information from children.

12. Applicability of the Australian Privacy Act

Small businesses under a turnover threshold are normally exempt from most of the federal Privacy Act. Whether Payday AI's own product design means we don't qualify for that exemption is a real, open question.

13. Changes to this policy

We may update this policy from time to time. We'll notify you of material changes by email or an in-service notice before they take effect. The "last updated" date at the top shows the current version.