Privacy Policy
Last updated: August 10, 2026
This policy explains what data PagoPilot collects, how we use it, and what rights you have. PagoPilot is an app that helps you organize bills, PagoPA notices, taxes, and other payment due dates.
Data controller
The data controller is PagoPilot's developer, reachable at hello@pagopilot.app.
Data we collect
- Account data: your email address and password (or, if you choose to sign in with Google, your name, email and profile picture provided by Google).
- Payment data: title, entity, amount, due date, category, notice number, creditor tax code, IBAN and notes you enter manually or that get extracted from an imported document.
- Uploaded documents: photos or PDFs of bills, PagoPA notices, F24 forms or receipts you import, stored in your private archive.
- Usage data: minimal technical information needed for the app to work, such as your monthly import count (to enforce the free plan's limit).
How we use your data
- To create and manage your account and give you access to your payments.
- To automatically extract details from an imported document: the file is sent to Google's Gemini API solely to read its content, and is not used by Google to train its models.
- To send you reminders and due-date notifications, shown in-app or as on-device notifications (generated locally, without a server round-trip).
- To send you service emails: account confirmation, password reset.
- To manage an optional Premium subscription (see below).
Who we share data with
We never sell your data. We only share it with the technical providers needed to run the app:
- Supabase — database, authentication and document storage.
- Google (Gemini API) — automatic reading of imported documents.
- Google Sign-In — only if you choose to sign in with your Google account.
- Resend — delivery of service emails (account confirmation, password reset).
- RevenueCat, Google Play and the Apple App Store — managing the Premium subscription. Payment is processed entirely by Google or Apple: PagoPilot never sees or stores your card details.
Data retention
We keep your data for as long as your account stays active. See below for how to request deletion of individual data or your whole account.
How to request data deletion
To delete a single payment (title, amount, due date, receipt or attached document): open it in the app and tap "Delete". It's immediate, doesn't require deleting your account, and any attached document is removed along with the payment.
To delete your entire account and all associated data (payments, uploaded documents, profile data): email hello@pagopilot.app from the email address linked to your account, with the subject "Data deletion request". We process requests within 30 days: your account, payments and uploaded documents are permanently deleted. The only exceptions are information we're legally required to retain (e.g. for tax purposes) and residual backup copies, which are overwritten within 90 days.
Your rights
If you're in the European Union, you have the right to access, correct, export or delete your data (GDPR rights). You can export your payments as a CSV file at any time from the Statistics or Settings section of the app. For any other request, contact us at the address above.
Security
Data is transmitted encrypted (HTTPS), and each user can only access their own payments and documents, enforced by database-level security policies (Row Level Security) configured on Supabase.
Children
PagoPilot is not directed at anyone under 16, and we do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the app or by email.
Contact
For any question about this policy or your data, email hello@pagopilot.app.