Last updated 24 September 2026

Privacy policy

Subtrack is a recurring-payment tracker. This policy explains what information Subtrack accesses, why it is used, which services process it, how long it is kept, and the controls available to you. It applies to the Subtrack website, API, Gmail connection, and AI assistant.

Information Subtrack handles

Account and sign-in information

When you sign in, Google and Supabase provide identifiers and basic profile information such as your email address, display name, avatar, and account creation time. Supabase manages the sign-in session. Subtrack's API uses the verified Supabase user identifier to keep each user's records separate.

Financial organisation data

Subtrack stores information you enter or approve, including recurring-payment names, amounts, currencies, billing cadence, categories, due and lifecycle dates, shared-bill details, free trials, reminders, income preference, and essential or optional labels. Subtrack is not a bank ledger and does not connect to a bank account.

Demo sessions

The demo creates a private sandbox with sample data and no account. To limit abuse, Subtrack stores a one-way keyed hash of the visitor's network address with each demo, never the address itself. A demo expires 24 hours after it starts. Expired demos, including anything typed into the assistant, are deleted the next time a new demo starts or the service restarts. Demos cannot connect Gmail.

Assistant data

Subtrack stores assistant conversations, limited page context, proposed actions, confirmations, and cited alternative-research results so conversations survive refreshes and actions can be audited. Page context contains allow-listed route, filter, and record identifiers; it does not grant the assistant access to another user's records.

Google user data

Gmail connection is optional and separate from Google sign-in. If you connect Gmail, Subtrack requests gmail.readonly, email identity, and OpenID scopes. The Gmail scope is read-only: Subtrack cannot send, change, move, or delete email.

A scan searches likely receipt, invoice, renewal, cancellation, and trial emails from approximately the previous three months. For candidate messages it temporarily reads the message to find the amount, then keeps only the sender's domain, the date, the subject and a short excerpt of the body. Before anything is sent to Anthropic's API for classification, Subtrack removes personal details from the subject and excerpt: email addresses, phone numbers, card digits, street addresses and postcodes, account, customer and reference numbers, links, greeting names, and name parts taken from your connected Gmail address. Each excerpt sent is limited to about 320 characters. This redaction is automatic and may not catch every personal detail, which is why only short excerpts of likely receipts are ever sent. Raw Gmail messages and bodies are not stored in Subtrack's database. Subtrack stores only derived review findings, confidence and evidence summaries, scan status, the connected email address, and an encrypted Google refresh token needed for later scans.

OAuth state is one-time, hashed, bound to the signed-in user, and expires after ten minutes. The PKCE verifier and refresh token are encrypted. Authorization credentials are returned to the browser in a URL fragment, removed immediately, and are not placed in Vercel request URLs.

Subtrack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements. Google user data is used only to provide the user-facing inbox-scanning and review feature. Subtrack does not sell it, use it for advertising, or expose it to other users.

How information is used

AI processing and automated decisions

Anthropic processes redacted candidate email excerpts, assistant messages, and the minimum relevant recurring-payment context needed for the requested feature. When you ask for cheaper alternatives, the payment's name, category, price and cadence, plus any requirements you give, are redacted in the same way and then used to search the web for current prices. AI results can be wrong. Gmail findings enter a review queue, and every AI-proposed data change remains inert until you confirm it. Subtrack does not make investment, credit, insurance, employment, or other legally significant decisions about users.

Service providers and disclosure

Subtrack uses Google for sign-in and optional Gmail access, Supabase for authentication, Neon for the application database, Render for the API, Vercel for the website, Anthropic for AI processing, and Frankfurter for exchange-rate data. Providers process information for their stated technical role and under their own terms and privacy practices. Information may be processed in countries where these providers operate. Subtrack may also disclose information when legally required or necessary to protect users and the service. Subtrack does not sell personal information.

Retention

Your choices and controls

App-data deletion removes Subtrack's database records and signs the current browser out. It does not delete the identity held by Supabase because the current API is not configured with Supabase administrator credentials. If you sign in again, a new empty Subtrack data set can be created. This limitation will remain disclosed until external identity deletion is implemented and verified.

Cookies and local browser storage

Supabase uses browser storage and cookies needed to maintain authentication. Subtrack also stores limited interface preferences, such as theme and assistant panel size or view choice. Subtrack does not currently use advertising cookies.

Security

Controls include API verification of access tokens, user-scoped database queries, encrypted Google credentials, one-time OAuth state and PKCE, restricted CORS configuration, bounded external calls, and confirmation-gated AI actions with expiry and replay protection. Data is protected in transit using HTTPS in production. No internet service can promise absolute security.

Children

Subtrack is not directed to children. Do not use the service if you are not legally able to consent to its data handling in your location.

Policy changes

Material changes will be reflected on this page with an updated date. If a change materially affects optional Google-data use, Subtrack will provide notice appropriate to the change before relying on it.

Contact

For privacy questions, access concerns, or deletion assistance, use the operator contact listed on Subtrack's Google OAuth consent screen. A dedicated public support email must be configured before broad public release. Do not post personal or financial information in a public issue.