Last updated 17 July 2026. Cogmentis Ltd (company no. 6508060) is the data controller and is registered with the Information Commissioner's Office.
Payment records: amounts, currency, reference, timestamps, quote identifiers and the payment preimage. Merchant settings: a public key (never your twelve words, which stay in your browser), a payout Lightning address, a display name, Lightning address handles, webhook endpoints and their signing secrets, hashed API keys and notification topics. IP addresses, briefly, for rate limiting. If a payment arrives as a nostr zap, the zap request (which carries the sender's public key) is kept and its receipt is published back to relays; that is how zaps work, by design.
Names, postal addresses, emails, passwords, card numbers, identity documents or seed words. We never ask for any of them.
Your device keeps your sign-in words (so it can renew its session), your theme choice, the keypad's last-used currency, and on pay pages a short-lived recovery backup of an in-flight payment. Cookies: a session cookie when signed in and a small display preference on the history page. No tracking cookies.
Any analytics we use are aggregate and cookieless. The reverse proxy keeps no access logs, and application logs exclude the secret part of payment URLs.
Payment records are kept for around six years to satisfy UK accounting rules. Rate-limit entries and expired sessions are purged automatically.
We process this data to provide the service (contract), to prevent abuse (legitimate interests) and to keep required records (legal obligation). UK GDPR gives you rights of access, correction and erasure; erasure of payment records is limited while accounting law requires us to keep them. Questions or complaints: support@paidinsats.com, or the ICO at ico.org.uk.