Privacy Policy
Effective July 30, 2026
PayDown is built local-first on purpose: the most private place for your
financial data is your own device, so that's where it stays.
The short version
- Your debts, payments, and schedules are stored on your device, in the app's private database.
- We never ask for bank logins, card numbers, or account credentials — PayDown has no bank linking.
- No accounts are required to use the app. No ads, no analytics, no selling data.
Data stored on your device
Everything you enter or import — account names, balances, APRs, payment
schedules, payment history, notes — lives in a local database on your phone,
protected by your device's built-in encryption. Deleting the app deletes this
data. It is not transmitted to us.
AI intake — where your data goes
There is no LLM embedded in the app, and the core tracker never needs one:
balances, schedules, and payoff math are computed on your device. The only
data that can ever leave the phone is the optional AI intake — when
you paste statement text or dictate a debt instead of typing it. That one
piece of text goes to whichever provider you pick in settings:
- PayDown's hosted parser (the default): your pasted text
is sent over TLS to our parsing service, which forwards it to Anthropic's
API, returns the extracted numbers, and keeps nothing — our server stores
only an anonymous monthly usage counter (a random install id and a count),
never the text. Anthropic's API terms apply to the request they process.
- Your own Anthropic API key: requests go directly from
your phone to Anthropic. The key lives in your device's secure keychain
and never touches our servers.
- Your own server (e.g. Ollama): requests go to hardware
you control. Nothing touches our infrastructure at all.
Voice entry becomes text using your device's speech recognition (Apple's
service, per your iOS settings), then that text follows the same provider
choice above. Skip AI intake entirely and the app works fine — it's four
numbers typed by hand. Extracted results are stored on your device; the
pasted or spoken text itself is not retained by PayDown either way.
Optional cloud sync (when available)
If you choose to create an account to sync between devices or use the web
dashboard, your payment data is stored encrypted at rest with row-level
security so that only your account can read your rows. Sync is opt-in —
local-only remains the default — and you can delete your cloud data and
account at any time.
This website
- Registration: if you sign up, we store your email address to send occasional PayDown updates. We don't share or sell it. You can delete your account yourself — the link appears in the site header when you're signed in — or just ask.
- Registration & comments: signing in uses an email magic link or an optional password. If you comment, the display name and comment you write are public.
- Update emails: optional — a checkbox at registration. Every email includes a one-click unsubscribe.
- Visit counting: we count page visits as (page path, day, count) and nothing else — no IP addresses, no cookies, no fingerprinting, nothing per-visitor.
- No advertising or cross-site tracking cookies.
What we don't do
- No bank credentials, no Plaid, no account linking.
- No selling or sharing personal data with third parties for marketing.
- No ads and no third-party analytics in the app today. If that ever changes, this policy will change first and say so plainly.
Contact
Questions or deletion requests: andrewlanecarr@gmail.com.