Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how All Paid ("All Paid", "we", "us") collects, uses, and protects your personal data when you use all-paid.com. All Paid is operated by Nikola Nedeljković, an individual based in Serbia, who is the data controller for your data.
1. Who we are
The data controller is Nikola Nedeljković, based in Serbia. For any privacy question or request, contact privacy@all-paid.com.
2. What data we collect
- Account data: your email address, and a password that is managed and hashed by our authentication provider - we never see or store your password in plain text.
- Your bill-tracking content: the periods you create, the bill items within them (name, amount, due day, whether it is paid, and any payment date or note you add), and your bill templates.
- Product-interest signals:when you click an "Upgrade to Pro" or pricing action, we record that the click happened (the on-screen source, a timestamp, and, if you are signed in, your account id). This helps us gauge interest in paid features before we build them. We do not process any payments.
- Technical data: our hosting and infrastructure providers automatically process basic technical information (such as IP address and request logs) to run and secure the service. Our analytics is privacy-friendly and cookieless, and does not track you across other sites.
3. How we use your data
- To provide the service - store and display your bills and keep you signed in.
- To send essential transactional emails (welcome and password-reset messages) through our email provider.
- To understand demand for paid features, using the product-interest signals above.
- To secure the service and prevent abuse.
4. Legal bases (GDPR)
- Performance of a contract: providing the app you signed up for.
- Legitimate interests: keeping the service secure and understanding feature demand, balanced against your rights and freedoms.
- Consent: where required for any optional processing (we currently send only essential emails).
5. Cookies we use
We keep cookies to a minimum and use no advertising or cross-site tracking cookies, so no cookie-consent banner is required:
- Authentication cookies (strictly necessary): set by our authentication provider to keep you signed in.
- Password-reset cookie (ap_recovery): a short-lived cookie set only during a password reset to confirm you arrived from a valid reset link. It expires within 15 minutes.
- Analytics: cookieless - it sets no cookies and does not identify you personally.
6. Who we share your data with
We do not sell your data. We share it only with the service providers that run All Paid on our behalf (our subprocessors):
- Supabase - authentication and database hosting.
- Resend - sending transactional emails.
- Vercel - application hosting and cookieless analytics.
Some of these providers process data outside Serbia and the EEA (for example, in the United States). Where that happens, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
7. How long we keep your data
- We keep your data for as long as your account exists.
- When you delete your account (Settings, then Delete account), we immediately and permanently erase your profile and all associated periods, bill items, and templates. Residual copies may persist briefly in our providers' encrypted backups before they cycle out.
8. Your rights
Under the GDPR and Serbian data-protection law, you can:
- Access and receive a copy of your data - you can export all of it anytime from Settings, then Export.
- Rectify inaccurate data - edit your bills anytime, or contact us.
- Erase your data - delete your account from Settings, or contact us.
- Object to or restrict certain processing, and withdraw consent where processing relies on it.
To exercise any right, email privacy@all-paid.com. You also have the right to lodge a complaint with a supervisory authority - in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection, or your local authority in the EU/EEA.
9. Children
All Paid is not intended for anyone under 16, and we do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Security
Data is encrypted in transit (HTTPS). Passwords are hashed by our authentication provider and never stored in plain text. Database access is restricted and scoped to each user.
11. Changes to this policy
We may update this policy as the service evolves. We will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
12. Contact
Questions or requests: privacy@all-paid.com.