subThis

Privacy Policy

Effective 2026-06-13 · v1.1.0

Effective: 2026-06-13 · Version: 1.1.0

subThis is a personal-utility app that helps you track your subscriptions by forwarding confirmation emails to a single address. This policy explains what data we hold, how long, and what we deliberately do not do.

Status: v1 placeholder. Content will be reviewed by counsel prior to Phase 3 public launch (per PRD §10.4). Pre-public-launch users (Phase 1 / Phase 2) operate under the terms below.

What we collect

  • Your email address — used as your account identifier and as the sender we recognize when you forward.
  • Parsed subscription records — vendor, amount, frequency, next renewal date, plan name if present — extracted from your forwarded emails.
  • Forwarded email content — temporarily, for the parsing step only. Deleted within 24 hours of receipt. A log row confirming deletion persists indefinitely (we keep the record of that we deleted, not the content itself).
  • Basic auth / support logs — IP address, user agent, timestamps around sign-in events, support tickets. Used for security and support.

What we do NOT do

  • We do NOT connect to your bank. No Plaid, no credential access.
  • We do NOT read your inbox. We only receive what you forward.
  • We do NOT sell your data. Ever.
  • We do NOT use your data to train AI. Vendor templates are built from anonymized aggregate parse failures, never from specific user content.
  • We do NOT retain forwarded email content beyond 24 hours — except a narrow operator-review case (max 30 days, with explicit user consent per message).

How long we keep things

DataRetention
Forwarded email content (raw)24 hours, then purged
Parsed subscription recordsUntil you delete them or close your account
Account + profile90 days after account closure, then permanently deleted
Login audit events (including IP addresses)365 days, or deleted on account erasure (whichever is sooner)
AI usage logs (paid tier only)730 days; de-identified on account erasure (user ID nulled)
Error logs180 days, or deleted on account erasure (whichever is sooner)
Support correspondenceRetained de-identified (user ID nulled) for dispute resolution — see account deletion section

Your rights

You can at any time:

  • Export your data — full JSON dump from settings.
  • Delete individual subscription records.
  • Close your account (full data deletion 90 days later) — see below.
  • Request a data subject access report — email support@subthis.app.

Account deletion and the right to erasure

You can permanently delete your account at any time, without contacting support.

How to delete your account

Go to Settings → Delete my account. The screen shows you exactly what will be erased and what the 90-day grace window means. When you are ready, click "Delete my account" — we send an 8-digit code to your email address. Enter the code to confirm. You are signed out immediately.

The 90-day grace window

After you confirm deletion, your account enters a 90-day grace period. During that time, your data is intact and the account is fully recoverable: sign back in and click "Restore my account" to cancel the deletion. If the 90 days pass without a restore, a nightly process permanently erases the account.

You receive a confirmation email at request time that states the exact erasure date and how to undo.

What is permanently erased

When the grace period ends, the following are permanently and irrecoverably deleted (no soft-delete, no backup copy):

  • Your account and profile
  • All subscription records and their billing history
  • All email addresses registered on the account
  • Email one-time verification codes
  • Renewal-detection records
  • Notification records
  • Monthly snapshot records
  • Billing events and subscription-billing records
  • AI-generated insights
  • Trial waitlist entries
  • Inbox connection records
  • Sign-in history (login events — including IP addresses)
  • Error log entries associated with your account
  • Your Supabase Auth record (sign-in is no longer possible)

The Postgres foreign-key cascade handles deletion automatically; no data from the above list survives.

What is retained in de-identified form

Two categories of data persist after erasure, but are disconnected from your account — your user ID is removed and no record of your name, email address, or other identifying information is retained alongside them:

Anonymized usage metrics. Aggregate AI-usage records and email-parsing event records are kept as operational data (cost analytics, accuracy tracking). After erasure these rows have no user ID; they cannot be linked back to you.

Support correspondence. If you submitted support tickets, those records are retained (user ID nulled) for dispute resolution and fraud defense, on a legitimate-interest basis. The ticket body may contain personal information you wrote in free text (e.g., your name or email address in a message you sent). We cannot scrub free-text fields of your submissions without losing the ability to investigate disputes. If this is a concern, do not include personal information in support messages beyond what is necessary to resolve your issue.

The deletion audit record

One PII-free row persists in our internal audit log indefinitely: a record that a deletion was requested and completed, containing only an anonymized user identifier and timestamps. It contains no name, no email address, and no recoverable personal data. This record is required to demonstrate compliance with deletion requests.

Sub-processors

  • Supabase — database + auth + file storage
  • Resend — transactional email + inbound webhook
  • Google (Gemini API) — AI parsing fallback + monthly insights (paid tier only)
  • Stripe — payments (paid tier only)
  • Vercel — hosting

Each processor holds only the minimum data required to perform their role.

Contact

support@subthis.app