← Paydicity

Paydicity Privacy Policy

Last updated: 2026-04-25

1. Who we are

Paydicity ("the app") is a mobile application for tracking shared expenses. The data controller is:

  • Name: Javier Ignacio Belmar Tevar
  • Tax ID (NIF): 48726878K
  • Contact email: paydicity@gmail.com

2. Data we process

Data Source Purpose Legal basis
Email Sign-up form Create and authenticate the account Performance of contract
Display name Profile form Identify you to your friends Consent
Profile picture (optional) Device gallery Personalise the profile Consent
Unique tag (TZG) Generated automatically Allow user-to-user invitations Performance of contract
Friends list User actions Show your contacts in the app Performance of contract
Personal and shared expenses User actions Core functionality Performance of contract
Push notification token Expo / OS Send you reminders and alerts Consent
Preferences (language, theme, currency, separator) Local settings Personalise the experience Legitimate interest

We do not process payment data or card numbers. Paydicity records IOUs between users but does not process real-money transactions.

3. Who has access

  • Firebase / Google Cloud (Google Ireland Limited) — provides authentication, database (Firestore), storage and push notifications (FCM). Data hosted in the European region.
  • Expo Application Services (Expo, Inc., USA) — relays push notifications. Only the push token and message payload are transmitted.
  • Other Paydicity users — names, profile pictures, TZGs and expense amounts are visible to the users involved in those expenses. Your friends list is not public.

We do not sell your data. We do not use your data to train AI models.

4. International transfers

Some providers (Expo) are located in the United States. Transfers are made under the Standard Contractual Clauses approved by the European Commission as a safeguard under the GDPR.

5. Retention

We keep your data while your account is active. When you delete your account from Settings → Delete account we run the following deletion process immediately:

  • Your profile, personal expenses, personal groups and categories are deleted.
  • Shared expenses you owned are deleted for every participant.
  • In shared expenses where you were only a participant, you are removed from the list and the others keep them.
  • Your activity in the feed (expense creation, payments, etc.) is anonymised as "Deleted account" so other users' history is preserved without exposing your identity.
  • Your profile picture is removed from Storage.
  • Your Firebase Authentication record is deleted.

Our backend provider (Firebase) may retain technical logs for up to 30 days for security and fraud prevention.

6. Your rights (GDPR)

You have the right to:

  • Access and portability: from Settings → Export my data you can generate at any time a JSON file containing all your data.
  • Rectification: edit your name, photo and preferences directly in the app.
  • Erasure: from Settings → Delete account.
  • Object and restrict processing: write to paydicity@gmail.com.
  • Lodge a complaint with a supervisory authority: in Spain, the Spanish Data Protection Agency (www.aepd.es).

7. Children

Paydicity is not directed to children under 16. If we detect an account belonging to a minor, we will delete it.

8. Security

  • All traffic with the backend is encrypted via HTTPS (TLS).
  • Firestore security rules restrict each user to their own data and to the expenses they participate in.
  • Firebase App Check is enforced to block unauthorised clients from reaching the backend.
  • API keys are restricted by package name / bundle id and SHA-1 fingerprint in Google Cloud.
  • Developers do not access user data except for explicitly requested support cases.

9. Changes

We will publish any changes at this same URL and, if your rights are affected, we will also notify you inside the app.

10. Contact

paydicity@gmail.com