Privacy Notice
Last updated on 30 September 2026. This notice explains how IsMyPayRight handles data when you use the website, public API, and optional payslip upload feature.
ChatGPT and other AI integrations
When you use the IsMyPayRight plugin, the AI service sends the calculation inputs you provide to our server and receives the result. Unlike calculations performed wholly in your browser, these inputs are processed on our hosting infrastructure. The plugin accepts financial figures, not payslip files. Do not send names, addresses, National Insurance numbers, bank details or credentials.
The plugin calculation handlers process figures in memory without saving them to a database or logging their contents. For abuse prevention, the public integration stores a hash of the connecting client address and short-lived rate-limit counters in Upstash Redis. Hosting providers may also retain operational request metadata. A hashed address is not guaranteed anonymous.
Your conversation, tool inputs and results are also handled by the AI service under its own privacy terms and your account or workspace settings. IsMyPayRight does not control that retention. The plugin does not access your HMRC account or employer systems, change payroll, or transmit payslip files to our extraction provider.
Sharing offer, inflation and tax-threshold results
The Offer, Real Pay and Tax Cliffs tools calculate in your browser. They do not require an account or save your entered figures to a database. Real Pay may request a public archived inflation snapshot, without sending your pay.
Copy link puts the entered figures in a URL fragment. Fragments are not sent in ordinary HTTP requests, but anyone you give the link to can read the figures. Hiding gross salary on an image does not hide it in the accompanying link. Downloaded PNG images are generated locally. Shared result links also include public headline figures in an og query, so our server can create social-preview images. Our hosting provider and social platforms may log and cache those figures. Gross salaries are excluded from Offer preview data unless you choose to include them; they remain in the full restoration fragment. Preview data contains no names, emails or free-text notes. Nothing is posted to social media automatically.
We remove URL queries and fragments from analytics URLs, exclude these forms from session replay, and send only tool names and action names for their consented usage events. Session replay remains off after financial tools are visited during a tab session. Following a link to the existing full calculators may send calculation inputs to our server to obtain the estimate.
1. Who is responsible for this site
IsMyPayRight.co.uk is operated by Dan Harrison. For privacy questions, data requests, or concerns about this notice, contact privacy@ismypayright.co.uk.
This notice applies to the website, the public API, the IsMyPayRight plugin, and the optional website payslip upload feature.
2. Cookies, consent, and tracking
Until you opt in through our privacy banner, PostHog tracking, session recordings and Vercel tool-use events remain off. Vercel continues to measure aggregate page views and site performance without cookies. Your consent choice is stored in your browser (localStorage, for up to 12 months). You can change or withdraw your consent at any time using the "Cookie settings" link in the footer; withdrawal takes effect immediately.
With your consent, we use PostHog (hosted on PostHog Cloud EU) to understand aggregate usage patterns. This stores a small number of first-party identifiers (cookies/localStorage) so your browser can be distinguished between visits. Vercel Analytics additionally measures page views and Core Web Vitals without cookies. We use this information solely to improve this website; it is not shared for anyone else’s purposes, used for advertising, or sold.
With analytics consent, Vercel also counts starts and successful results for the calculator, payslip checker, reverse calculator and two-payslip comparison. These events contain only the tool name and action, with no salary, tax code, payslip details or result values. We remove query strings and fragments from analytics URLs.
With your separate consent, we also record a reconstruction of some visits (mouse movement, scrolling, clicks, and page structure) to diagnose bugs and usability problems. Input masking is enabled for recordings. Financial calculator and checker routes are excluded from replay, and replay stays off after one is visited during a tab session. Masking alone is not a guarantee of anonymity. Recordings are kept on PostHog’s EU infrastructure and deleted after PostHog’s standard retention period for recordings.
For aggregate product improvement we also capture coarse usage signals about how the calculator, payslip checker, guides, salary pages, and other tools are used. Examples include a salary band (e.g. £30,000–£40,000, never the exact figure), the prefix of any tax code you enter (such as L, BR, K or D0, never the full code), the UK region, whether you reached the bottom of a guide, which internal links you followed between pages, and which engine fields flagged a difference. These signals are bucketed or categorical to reduce detail. Analytics identifiers may still distinguish a browser; we do not treat these records as guaranteed anonymous.
3. What personal data may be processed
Depending on how you use the site, the product may process calculator inputs, payslip-check figures, uploaded payslip files, API request metadata, IP address, user agent, timestamps, and request identifiers.
Calculator inputs and payslip check figures are processed in memory to deliver results and are not stored in any database. The site does not maintain user accounts.
Shared links can include calculation state in the URL. If you share a link, anyone with that link may be able to see the scenario values encoded in it.
4. How the data is used
Data is processed to deliver calculator results, validate payslip figures, enforce API rate limits, prevent abuse, troubleshoot issues, and monitor service performance.
If you use payslip upload, the uploaded file is sent to Google Gemini (an AI extraction service) to attempt field recognition. The extracted values are returned to you for review before you submit a payslip check. IsMyPayRight does not store the uploaded file after extraction is complete.
5. Legal bases
PostHog analytics, session recordings and Vercel tool-use events run only with your consent (UK GDPR Article 6(1)(a)). For the rest of the service, where UK GDPR or similar law applies, the likely legal bases are legitimate interests for running, securing, and improving the service, and contract or pre-contract processing where API or product access is being supplied to you.
If a particular integration or commercial arrangement uses a different legal basis, that will be described in the relevant product or customer documentation.
6. Third-party services and processors
The two-payslip comparison processes manually entered figures in the browser without saving a history. Optional uploads use the extraction service described below. The site uses third-party infrastructure and service providers. These currently include:
Vercel for hosting, analytics, and performance monitoring. Upstash Redis for API rate limiting. Unkey for API key verification. PostHog for consent-based product analytics and session recordings, configured to use PostHog Cloud EU. EU hosting alone does not guarantee that all processing or support access stays within the EU/UK; provider terms and transfer safeguards also apply. Google Gemini for payslip image and PDF field extraction.
These services may process data needed to perform their role. Each has its own privacy policy governing how it handles data.
7. Payslip uploads
Payslip uploads are used to extract likely field values so you can review them before running a payslip check. When you upload a payslip image or PDF, it is sent to Google Gemini for field recognition. The file is processed in transit and is not stored by IsMyPayRight after extraction.
Uploaded files should not be treated as long-term secure document storage. Avoid uploading more information than necessary. If your payslip contains particularly sensitive personal information and you are not comfortable sharing it with a third-party extraction service, use manual entry instead.
8. Retention
This site is designed around transient calculation use rather than permanent user accounts. Calculator inputs and results are not stored in any database.
Operational logs, analytics events, rate-limit data, and third-party service records may persist for the retention periods used by those systems. Where a service stores data for a defined period, that retention is determined by the relevant provider.
9. International transfers
Some service providers used by the site may process data outside the UK. Where that happens, the site relies on the safeguards and transfer mechanisms provided by those services under applicable law.
10. Your rights
If applicable law gives you rights of access, correction, deletion, restriction, objection, portability, or complaint to a supervisory authority, you can contact privacy@ismypayright.co.uk to make a request.
Because the product does not require user accounts and does not store calculator or checker data, the practical scope of any data request is limited to operational logs and analytics records that may be held by the third-party services listed above.
11. Changes to this notice
This notice may be updated as the product, infrastructure, or commercial model changes. Significant updates may also be noted on the public status page.

