Paid Privacy Policy

Effective date: August 6, 2026

Last updated: August 6, 2026

This Privacy Policy explains how Terrasoft Inc ("Terrasoft," "we," "us," or "our") handles information in connection with the Paid mobile application (the "App"), the account and billing service, and the Paid website at [https://usepaid.vercel.app](https://usepaid.vercel.app).

1. The short version

Paid remains local-first for your work. Invoices, estimates, client records, business details, saved items, expenses, selected images, and generated documents are stored on your device. Those records are not uploaded to or synchronized with Terrasoft's backend.

If you choose Sign in with Apple, Terrasoft's separate backend verifies the Apple identity token and creates an authenticated billing session. The backend stores limited account and entitlement data, not your invoice or client database. Eligible signed-in users in the United States may be offered Stripe billing when Terrasoft enables the production switch. Apple in-app purchase remains the fallback for users who are outside the eligible flow or whose eligibility cannot be confirmed. The production Stripe switch is currently off.

The current release has no active product analytics or advertising provider. PostHog, Meta, and TikTok are not active.

2. Information handled locally on your device

Depending on how you use Paid, the App may locally handle:

This content can include personal information about your customers or other people. You are responsible for providing required notices and having a lawful basis to use it.

Contacts you select

If you use the contact picker, the App may access the contact you select and copy available name, email, phone, and postal-address fields into a local client record. The feature is intended to use only the contact you choose, not upload your address book. Depending on the iOS access path, iOS may ask for Contacts permission. You can manage access in iOS Settings.

Images you select

If you choose a photo, the App may locally store the image you select, such as a business logo or receipt image. The receipt feature downsizes and recompresses a local copy. iOS may provide a limited photo picker or ask for Photos permission. You can manage access in iOS Settings.

Notifications

With your permission, the App schedules local notifications for invoice follow-up and certain purchase reminders. Notification content may include an invoice number, customer name, amount, payment status, due timing, or subscription amount and timing. Depending on your iOS settings, this content may be visible on the lock screen. Paid does not send invoice content to a Terrasoft notification server.

3. Account and authentication information

Sign in with Apple is optional for local invoicing but is required for the eligible Stripe billing path. When you sign in:

1. Apple provides the App with an identity token and an Apple-scoped user identifier. Apple may provide your email address and, generally only on the first authorization, your name. The email may be an Apple private relay address.

2. The App sends the identity token to Terrasoft's backend over HTTPS. The backend verifies its signature, issuer, audience, and validity with Apple.

3. Terrasoft stores the Apple-scoped subject and email address provided in the verified token. The backend does not store the identity token as an account record.

4. The backend returns a signed, expiring Terrasoft session token. The App stores that token in the iOS Keychain using device-only protection and sends it to authenticate billing and entitlement requests.

The App also stores the Apple-scoped user identifier and any provided name and email in local preferences. Signing out removes the local Terrasoft session token and locally saved Apple sign-in fields. Signing out does not delete the backend account record, cancel a Stripe subscription, or delete local invoices.

Signing in does not back up or synchronize invoices, clients, receipts, or other local business content.

4. Billing and transaction information

Stripe web billing

When the production switch is enabled, Terrasoft may offer Stripe Checkout to an authenticated user whom the service confirms is eligible in the United States. The App opens Stripe Checkout in Safari and returns through a Paid deep link. Stripe collects and processes payment method, billing, transaction, tax, fraud-prevention, and related information under Stripe's privacy policy. Terrasoft does not receive your full card number.

Terrasoft's backend stores or processes the information needed to manage access, including:

The service may also receive a two-letter country signal or trusted infrastructure country result to decide whether web billing is eligible. Network providers may process IP address and request metadata for routing, security, and country determination.

A return to the App does not by itself grant access. Terrasoft verifies the Checkout session and relies on authenticated entitlement responses and Stripe's signature-verified webhooks for purchase, renewal, payment failure, cancellation, and refund status.

Apple in-app purchase

Apple processes App Store subscriptions and lifetime purchases for the fallback path. Terrasoft does not receive your full payment-card or bank-account details. Through StoreKit, the App receives product and verified entitlement information needed to show offers, complete or restore a purchase, and determine access. Apple separately handles transaction, device, account, tax, and fraud-prevention information under Apple's policies.

5. Website and support information

Paid's public website and legal pages are hosted by Vercel at [https://usepaid.vercel.app](https://usepaid.vercel.app). The pages do not intentionally run Terrasoft product analytics or advertising trackers. Vercel may process IP address, browser and device details, requested URL, timestamps, and security or delivery logs to host and protect the site.

If you contact support, Terrasoft receives the information you choose to send, such as your email address, message, attachments, and diagnostic context. Do not send customer records, complete invoices, bank details, tax identifiers, identity tokens, session tokens, or full payment details unless Terrasoft provides an approved secure method.

6. How we use information

We use information to:

Local business content is used on your device to provide invoice, estimate, client, expense, reporting, PDF, export, and reminder functions. Terrasoft does not remotely use that content because the backend does not receive it.

7. Service providers and disclosures

We disclose limited information to providers that perform services for Paid:

We may also preserve or disclose information in our possession if reasonably necessary to comply with law or legal process, protect rights and safety, investigate fraud or abuse, or complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. The current App has no active analytics, advertising, or attribution provider.

8. Storage, retention, and deletion

Local content

Invoice and business content is stored in local App files. Receipt images are stored as compressed local image data. Preferences and some sign-in fields are stored in local preferences. The Terrasoft session token is stored in the iOS Keychain. Apple may include some App data in an iCloud or computer device backup depending on your settings. We do not control those backups.

Local information remains until you edit or delete it, reset App data, or remove the App, subject to iOS behavior and backups. Deleting a document does not remove copies you exported or shared. Deleting the App generally removes its local container, but a later device restore may restore backed-up data.

Backend account and billing records

We retain backend account, entitlement, subscription, and event records while the account or purchase is active and as reasonably needed to provide access, process billing, prevent fraud and duplicate events, resolve disputes, maintain financial records, enforce agreements, and comply with tax, accounting, and legal duties. Stripe, Apple, Google Cloud, Vercel, and support providers retain information under their own policies and our configured service terms.

You may request deletion of Terrasoft's backend account data by emailing brennan@terrasoft.co. Signing out or deleting the App does not itself send a backend deletion request and does not cancel a subscription. Before requesting deletion, cancel any Stripe subscription through the customer portal and retain records you need. We will delete or deidentify information that is not required for an active entitlement or a permitted retention purpose. We may retain transaction, refund, fraud-prevention, security, tax, accounting, and legal records where permitted or required. Deletion of the backend account does not delete local App content, Apple records, Stripe records that Stripe must retain, or copies you shared.

9. Security

We use iOS Keychain protection for the Terrasoft session token, HTTPS for backend requests, Apple identity-token verification, signed and expiring backend sessions, authenticated billing endpoints, server-selected Stripe prices, signature-verified Stripe webhooks, and event deduplication. Google Cloud hosts the production backend data environment. No method of storage or transmission is completely secure, and we cannot guarantee that information will never be lost or accessed without authorization.

Protect your device and Apple Account with a strong passcode and current software. Never share a Paid session token or Stripe portal link. Export independent copies of local records you must retain.

10. Your choices and privacy rights

You can:

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information Terrasoft controls, and to appeal or complain to a regulator. To request access, correction, deletion, or a copy of backend account and billing information, email brennan@terrasoft.co. We may verify your identity, for example through the associated Apple credential or email, before completing a request.

Terrasoft generally cannot retrieve, export, or delete your local invoice and client database because it is not sent to us. The in-app reset control may not clear every separately stored preference or Tools-library record. For the most complete local deletion, first export anything needed, cancel billing separately, sign out, and then delete the App.

11. Your role when handling customer data

When you put another person's information into Paid, you generally decide why and how it is used. You are responsible for your privacy notices, permissions, security, retention, and responses to that person's rights. Terrasoft is not your legal adviser and does not remotely host that local customer database.

12. Children's privacy

Paid is intended for adults conducting business and is not directed to children under 13. We do not knowingly collect personal information online from children under 13. If you believe a child has provided personal information to us, contact brennan@terrasoft.co.

13. International processing

Apple, Stripe, Google Cloud, Vercel, and email providers may process information in the United States and other countries under their policies and contractual safeguards. Web billing is currently designed for eligible United States users only, but authentication, Apple billing, website hosting, and support may involve international processing. Local invoice and client data remains on your device unless you choose to export or share it.

14. Analytics and future changes

The App contains an analytics event layer, but no analytics provider key is active. PostHog, Meta, and TikTok collection is not active. Before activating analytics or advertising, Terrasoft must assess consent requirements, update this Policy and App Store disclosures, identify providers and purposes, and configure appropriate controls.

We may update this Policy as Paid or the law changes. We will update the date above and provide additional notice or request consent where required. A future change that uploads or synchronizes invoice, client, receipt, or other local business content would require a new privacy review and updated notice before collection begins.

15. Contact

Controller and operator: Terrasoft Inc

Address: 333 Main St, Redwood City, CA

Privacy questions and requests: brennan@terrasoft.co

Support: brennan@terrasoft.co