Privacy Policy

Effective Date: July 22, 2026

WhoPaid is designed to help users track jobs, payments, clients, and work records. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

Information We Collect

When you use WhoPaid, you may enter information such as client names, job titles, job types, job dates, payment amounts, payment status, partial payment history, reminder preferences, notes, and currency preferences.

If you choose to sign in with Apple, we receive your Apple-provided account identifier and, if you allow it, your email address. Apple may provide a private relay email address instead of your personal email address.

If you use paid features, invite rewards, or cloud sync features, we may store related account information such as subscription status, purchase dates, plan type, price, invite code status, reward status, and basic activity needed to determine eligibility.

We also collect limited product interaction data, such as app opens, onboarding completion, job-form progress, payment-status actions, announcement interactions, and coarse session-duration ranges. These analytics events do not include client names, job titles, notes, amounts, or other job content.

If you voluntarily complete an in-app product survey, we store your selected answers, optional written feedback, survey completion time, and reward status with your signed-in account. Survey responses are used only to understand how people discover and use WhoPaid and to improve the product. Please do not include client names, payment amounts, or other private information in optional feedback.

How We Use Information

We use your information to provide the app's core features, including saving job records, showing unpaid jobs, calculating unpaid amounts, scheduling local reminders, syncing data, verifying paid access, operating rewards, and improving WhoPaid using voluntary survey feedback.

Cloud Sync and Storage

Job records are stored on your device and backed up using our backend service provider, Supabase. Before you sign in, the backup is associated with random device-scoped identifiers rather than an account. After Sign in with Apple, those guest records can be securely claimed by and linked to your account for sync.

Purchases and Subscriptions

WhoPaid Pro purchases are processed by Apple. We do not receive or store your full payment card details. We may store purchase and subscription records needed to provide paid access, such as the product type, purchase date, expiry date, price, currency, and Apple transaction identifiers.

Data Sharing

We do not sell your personal information. We share data only with service providers needed to operate the app, including Apple for authentication and purchases, Supabase for database hosting, authentication and sync, and Google for optional rewarded ads. These providers process information under their own privacy terms.

Analytics and Tracking

WhoPaid does not send personal job content to advertising or analytics providers. Our own product analytics use privacy-limited event names and coarse duration ranges to improve onboarding and reliability.

If you choose to watch a rewarded ad, WhoPaid requests the privacy choices required for your region before loading Google Mobile Ads and requests non-personalized ads. Google may process device information, diagnostics, advertising data, and ad interactions to deliver, secure, and measure the ad. WhoPaid does not request App Tracking Transparency permission or use job records for cross-app tracking.

Data Retention

We keep your data for as long as needed to provide the app's features, unless you delete it or request deletion. Local data may remain on your device until you delete the app or remove the records.

Your Choices

You can add, edit, or delete job records inside the app. You can choose whether to sign in with Apple and whether to participate in the optional product survey. Where required, the app provides an Ad Privacy Choices control so you can review or change advertising privacy choices. You may also contact us to request account or data deletion.

Children's Privacy

WhoPaid is not intended for children under 13. We do not knowingly collect personal information from children under 13.

Security

We use reasonable technical and organizational measures to protect your data. However, no method of storage or transmission is completely secure.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above.

Contact Us

If you have questions about this Privacy Policy or your data, contact us at admin@code-stack-studio.com.