Privacy
Last updated 29 August 2026 · Questions to hello@paydirt.news
1. Who runs Paydirt
Paydirt is an independent service operated by its owner under the trading name Paydirt.
The operator answers for the data described on this page. Contact: hello@paydirt.news.
2. What is stored
Reading Paydirt needs no account. An account, when you create one, stores: your email address (kept lowercased), the times of your first and most recent sign-ins, your plan (Free or Pro), your alert settings, your watchlist entries, whether you asked to be emailed when Pro launches, and, if you subscribe to Pro, the Stripe customer and subscription identifiers for your account. That is the whole account record: no name, no password, no card details.
Sign-in links are stored only as a hash of the token in the email: each is valid for 15 minutes and usable once, and token records older than a day are deleted. Sessions are stored only as a hash of the cookie value: they last 90 days, and signing out deletes the session immediately.
3. Cookies and your browser
Paydirt sets exactly one cookie: the session cookie (__Host-paydirt_session), created when you sign in and removed when you sign out. It is HttpOnly, Secure and SameSite=Lax. There are no advertising or tracking cookies. The dark-mode choice lives in your browser's localStorage and is never sent to the server.
Pages load two typefaces from Google Fonts, so your browser requests font files from Google's servers and Google receives your IP address. Pages also load a small measurement script from Cloudflare, described in section 4, which sets no cookies. The browser makes no other third-party requests.
4. Who processes data for us
Resend sends the emails: sign-in links and alert emails, from login@paydirt.news and alerts@paydirt.news with replies going to hello@paydirt.news. Email addresses appear in our logs only in masked form.
Stripe processes payments: card details go to Stripe and never reach our servers, and we keep only the plan status and the identifiers named in section 2.
Cloudflare Web Analytics counts visits: your browser loads its script, which reports the page address, the referring address, your browser and screen size, and how quickly the page loaded. Cloudflare receives your IP address to do this and does not store it. The script sets no cookies, does not fingerprint your browser, and cannot follow you to other sites, which is why Paydirt asks for no cookie consent. It exists so we can see whether anyone is reading, and nothing about it identifies you.
The web server also keeps standard access logs (IP address, URL, time) for security and capacity, rotated automatically.
5. Backups and retention
Account data is kept while the account exists. The accounts database is snapshotted nightly, and snapshots are kept for 14 days on the server with a weekly off-site copy kept for 8 weeks, so deleted data can persist inside those backups until they cycle out.
6. Your choices and rights
To see what is stored about you, receive a copy of it, correct it, or delete the account: email hello@paydirt.news from the account's address. Requests are handled manually and confirmed by reply. Deleting an account removes the account record, its sessions, and its watchlist together.
Paydirt emails you only when asked: the sign-in link you request, and alert emails if your account's settings turn them on.
7. Changes and contact
This notice can change, and the Last updated line above moves when it does. Material changes are announced by email to account holders. Questions go to hello@paydirt.news.