The short version
- We do collect data
- Payverly has accounts, and your invoices, clients and business details are stored on our servers so they follow you across devices.
- We don't sell it
- We do not sell your data and we do not share it with data brokers.
- We don't track you
- The app does not ask for permission to track you across other companies' apps or websites. Ads are shown; how they are chosen is explained in section 6.
- No payment details
- Payverly does not process payments. We never see or store card or bank credentials.
- You can delete it
- Settings → Delete account (at the bottom of Settings) erases your account and its data. You can also request deletion without the app. See how long we keep it.
1. Who we are
Payverly is invoicing and client-management software for freelancers and small businesses, published by AVMDEVS LLC ("we", "us"). This policy covers the Payverly mobile app on iOS and Android and the website at payverly.app.
For anything in this policy, you can reach us at privacy@payverly.app.
2. What we collect
Only what the app actually needs in order to work. There is no hidden collection beyond the categories below.
Your account
- Your name and email address.
- Your password, stored only as a salted bcrypt hash — we cannot read it.
- If you sign in with Google or Apple: the identifier that provider gives us, plus the name and email they release to us. We never receive your Google or Apple password.
- If you use the app as a guest: a random identifier generated on your device, so your work is not lost before you create an account. No name or email is required.
Your business profile
- Business phone number, postal address and tax/VAT identifier, if you enter them — these are printed on the invoices you issue.
- Your uploaded logo and signature images.
- Preferences: currency, locale and date format, invoice header/footer text, accent colour, light/dark appearance, invoice and receipt numbering, and notification settings.
Your business records
- Invoices and receipts: line items, quantities, rates, discounts, tax rates, totals, currency, issue and due dates, notes, and whether an invoice has been emailed.
- Clients you add — see section 3.
- Catalog and inventory: products, variants, add-ons, brands, suppliers, stock levels, branches and warehouses, where you use those features.
Support
- The subject and contents of any support ticket you open, and the replies in that conversation.
Device and technical data
- A push notification identifier and a device identifier and platform (iOS/Android), so that notifications can be delivered to the right device. These are removed when you sign out or delete your account.
- An advertising identifier (Android's advertising ID), used by Google to serve, measure and cap ads — see section 6.
- In-app events (for example, which screens are opened and which features are used) to understand how the app is used — see section 6.
- Standard server logs, including your IP address, generated when your app talks to our API. These are used for security, abuse prevention and debugging.
When you visit payverly.app
- Our web server keeps standard access logs — your IP address, browser, the page requested and the time — for security and troubleshooting.
- The website uses no cookies, no analytics and no third-party trackers, and loads its fonts from our own server, not from Google.
- If you switch between light and dark, that choice is saved in your own browser and never sent to us.
Payverly does not collect your contacts, your location, your photo library beyond the specific images you choose to upload, your health or fitness data, or your browsing activity in other apps.
3. Data about your clients
When you add a client, you may enter their name, email address, phone number and address. That information is about someone else, so it is worth being precise about the roles:
- You decide what client information to enter and why. In data-protection terms you are the controller of it.
- We store and process it on your behalf, so you can issue invoices to those clients. We act as your processor for that data.
We do not market to your clients, do not contact them on our own behalf, and do not use their details for anything other than providing the app to you. If you delete a client, or delete your account, their record is removed with it.
4. Why we use it
| Purpose | What it uses | Legal basis (EEA/UK) |
|---|---|---|
| Run your account | Name, email, password or social identifier | Performance of a contract |
| Create and store your invoices, clients and catalog | Business profile, business records | Performance of a contract |
| Sync your data and settings across your devices | Account, business profile, preferences | Performance of a contract |
| Reset your password | Email address, one-time code | Performance of a contract |
| Send you notifications you have enabled | Push identifier, device identifier | Consent (you can turn it off) |
| Answer your support requests | Ticket contents, account email | Performance of a contract |
| Keep the service secure and prevent abuse | Server logs, IP address, rate-limit counters | Legitimate interests |
| Understand how the app is used so we can improve it | In-app events | Legitimate interests |
| Show ads, which is how the app stays free | Advertising identifier | Consent where required |
5. Who we share it with
We do not sell your data. We share it only with the service providers that make specific features work, and only the data each one needs:
| Provider | What it is for | What it receives |
|---|---|---|
| OneSignal | Delivering push notifications | Push and device identifiers, notification contents |
| Google (AdMob) | Serving ads | Advertising identifier (Android), ad requests |
| Google (Sign-In) | Signing in with Google, if you choose it | The sign-in request; Google tells us your identifier, name and email |
| Apple (Sign in with Apple) | Signing in with Apple, if you choose it | The sign-in request; Apple tells us your identifier and, if you allow it, name and email |
| Amplitude | Product analytics | In-app events |
| Our email provider | Sending account email such as password-reset codes | Your email address and the contents of that message |
| Our hosting provider | Running the servers and database | Stores the data described in this policy |
| Our file-storage provider | Storing the logo and signature images you upload | Those image files |
We may also disclose data where we are legally required to, or where it is necessary to protect our rights or someone's safety. If Payverly is ever transferred to another company, your data may transfer with it, and we will tell you before that happens.
6. Ads and analytics
Payverly is free, with no subscription, trial or paid tier. Ads are how it is funded.
The app does not ask to track you. It never presents Apple's App Tracking Transparency prompt, so on iPhone Google cannot use Apple's advertising identifier, and ads are chosen from the context and coarse signals rather than a cross-app profile.
On Android, Google may use your device's advertising ID to choose and measure ads, which can make them personalised. You can reset that ID or turn off ad personalisation in your Android settings (Settings › Google › All services › Ads, or Settings › Privacy › Ads, depending on your phone).
On both systems an advertising identifier, where available, is also used to count and cap ad impressions and to detect fraud.
Analytics are aggregate and product-focused: which screens are opened, which features are used, whether an action succeeded. We use them to decide what to fix and build next. We do not use analytics to build advertising profiles, and we do not send your invoice contents, client details or business figures to our analytics provider.
If you are in the EEA, the UK or Switzerland, the app does not currently ask for advertising consent, so Google shows only limited ads there: ads that do not use personal data to personalise them.
7. Sending email as you
Payverly can email an invoice to your client from your own address, using your own mail server. If you use that feature:
- You give us your mail server's host, port, username and password.
- Your password is encrypted before it is stored, using AES-256-GCM with a key held outside the database. It is never returned to the app, never shown in our admin tools, and never included in logs.
- We use those credentials for one purpose only: connecting to your mail server to send the message you asked us to send, and to verify the connection when you press "test".
- You can remove the credentials at any time from Settings → Email sending.
Because the message is sent through your own mail server, your email provider's own privacy terms apply to it as well.
8. How we protect it
- All traffic between the app and our servers is encrypted in transit using HTTPS/TLS.
- Your session token is stored in the device's secure storage — the iOS Keychain or the Android Keystore — not in plain application storage.
- Passwords are stored only as salted bcrypt hashes.
- Mail-server passwords are encrypted at rest with authenticated encryption, as described above.
- Every request for your data is checked against your signed-in session on the server, so one account cannot read another's records.
- Sensitive endpoints — sign-in, password reset, email sending — are rate-limited against brute-force and abuse.
No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
9. How long we keep it
We keep your account and business records for as long as your account exists, because they are the product — your invoice history is not something we can quietly expire.
When you delete your account (Settings → Delete account, or by request):
- Your account, business profile, invoices, receipts, clients, catalog, stock records and support tickets are erased from our database.
- Your push notification registrations are deleted, so notifications stop immediately.
- We keep a minimal deletion record containing only your former account identifier, how you signed in (email, Google, Apple or guest) and the dates the account was created and deleted — no name, email address or password. It exists only to show that the deletion happened.
- Ordinary backups and server logs age out on their normal cycle, so a copy may persist briefly in them after deletion.
If you want the deletion record removed as well, email us at privacy@payverly.app and we will do so unless we are legally required to keep it.
Invoices you sent before deleting are your business records: keep your own copies (the PDFs you shared) if your tax rules require you to retain them — we cannot recover them after deletion.
10. Your rights and choices
In the app, at any time, you can:
- See and correct everything in your account and business profile, from Settings.
- Turn notifications off, from Settings → Notifications or your device settings.
- Delete your account, from Settings → Delete account — or request it without the app.
Depending on where you live, you may also have the right to access a copy of your data, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we relied on it. To exercise any of these, email privacy@payverly.app — we will respond within the time your law requires, and we will not charge you or reduce your service for asking.
If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data-protection authority.
We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing for you to opt out of in those terms.
11. Children
Payverly is a business tool and is not directed at children. We do not knowingly collect data from anyone under 13 (or the minimum age in your country). If you believe a child has created an account, contact us and we will remove it.
12. Changes to this policy
If we change how we use your data, we will update this page and change the "last updated" date above. For a significant change we will tell you in the app or by email before it takes effect, rather than relying on you to re-read this page.
13. Contact
Questions, requests, or anything in this policy that does not match what you see in the app:
- Email: privacy@payverly.app
- Support: in the app, under Settings → Support