Last updated 24 September 2026
Privacy policy
Subtrack is a recurring-payment tracker. This policy explains what information Subtrack accesses, why it is used, which services process it, how long it is kept, and the controls available to you. It applies to the Subtrack website, API, Gmail connection, and AI assistant.
Information Subtrack handles
Account and sign-in information
When you sign in, Google and Supabase provide identifiers and basic profile information such as your email address, display name, avatar, and account creation time. Supabase manages the sign-in session. Subtrack's API uses the verified Supabase user identifier to keep each user's records separate.
Financial organisation data
Subtrack stores information you enter or approve, including recurring-payment names, amounts, currencies, billing cadence, categories, due and lifecycle dates, shared-bill details, free trials, reminders, income preference, and essential or optional labels. Subtrack is not a bank ledger and does not connect to a bank account.
Demo sessions
The demo creates a private sandbox with sample data and no account. To limit abuse, Subtrack stores a one-way keyed hash of the visitor's network address with each demo, never the address itself. A demo expires 24 hours after it starts. Expired demos, including anything typed into the assistant, are deleted the next time a new demo starts or the service restarts. Demos cannot connect Gmail.
Assistant data
Subtrack stores assistant conversations, limited page context, proposed actions, confirmations, and cited alternative-research results so conversations survive refreshes and actions can be audited. Page context contains allow-listed route, filter, and record identifiers; it does not grant the assistant access to another user's records.
Google user data
Gmail connection is optional and separate from Google sign-in. If you connect Gmail, Subtrack requests gmail.readonly, email identity, and OpenID scopes. The Gmail scope is read-only: Subtrack cannot send, change, move, or delete email.
A scan searches likely receipt, invoice, renewal, cancellation, and trial emails from approximately the previous three months. For candidate messages it temporarily reads the message to find the amount, then keeps only the sender's domain, the date, the subject and a short excerpt of the body. Before anything is sent to Anthropic's API for classification, Subtrack removes personal details from the subject and excerpt: email addresses, phone numbers, card digits, street addresses and postcodes, account, customer and reference numbers, links, greeting names, and name parts taken from your connected Gmail address. Each excerpt sent is limited to about 320 characters. This redaction is automatic and may not catch every personal detail, which is why only short excerpts of likely receipts are ever sent. Raw Gmail messages and bodies are not stored in Subtrack's database. Subtrack stores only derived review findings, confidence and evidence summaries, scan status, the connected email address, and an encrypted Google refresh token needed for later scans.
OAuth state is one-time, hashed, bound to the signed-in user, and expires after ten minutes. The PKCE verifier and refresh token are encrypted. Authorization credentials are returned to the browser in a URL fragment, removed immediately, and are not placed in Vercel request URLs.
Subtrack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements. Google user data is used only to provide the user-facing inbox-scanning and review feature. Subtrack does not sell it, use it for advertising, or expose it to other users.
How information is used
- Operate sign-in and keep records scoped to the correct user.
- Calculate recurring-cost equivalents and forecast expected charges.
- Find possible recurring payments in Gmail for you to review.
- Show in-app reminders, free trials, data-quality warnings, and possible duplicates.
- Answer assistant questions and prepare changes that require your confirmation.
- Protect, diagnose, and improve the reliability and security of the service.
AI processing and automated decisions
Anthropic processes redacted candidate email excerpts, assistant messages, and the minimum relevant recurring-payment context needed for the requested feature. When you ask for cheaper alternatives, the payment's name, category, price and cadence, plus any requirements you give, are redacted in the same way and then used to search the web for current prices. AI results can be wrong. Gmail findings enter a review queue, and every AI-proposed data change remains inert until you confirm it. Subtrack does not make investment, credit, insurance, employment, or other legally significant decisions about users.
Service providers and disclosure
Subtrack uses Google for sign-in and optional Gmail access, Supabase for authentication, Neon for the application database, Render for the API, Vercel for the website, Anthropic for AI processing, and Frankfurter for exchange-rate data. Providers process information for their stated technical role and under their own terms and privacy practices. Information may be processed in countries where these providers operate. Subtrack may also disclose information when legally required or necessary to protect users and the service. Subtrack does not sell personal information.
Retention
- Recurring-payment records, reminders, preferences, derived Gmail findings, and assistant history remain until you delete them or delete your Subtrack app data.
- Raw Gmail message content exists only during a scan and is not retained in Subtrack's database.
- The encrypted Gmail refresh token remains until you disconnect Gmail or delete your Subtrack app data.
- One-time Gmail connection state expires after ten minutes and is consumed on use.
- Expired demo sandboxes and their hashed visitor identifier are deleted the next time a demo starts or the service restarts.
- Alternative-research cache entries stop being used after approximately 24 hours; an expired database row may remain until your app data is deleted.
- Operational and security logs may be retained for the periods configured by the relevant hosting provider. Subtrack avoids intentionally logging email bodies, OAuth credentials, assistant financial content, and raw external error bodies.
Your choices and controls
- You can use core tracking without connecting Gmail and can disconnect Gmail at any time.
- Disconnecting deletes the encrypted refresh token and attempts to revoke it with Google. Previously approved payment records remain until you delete them.
- You can approve, correct, dismiss, edit, pause, end, or delete app records from Subtrack.
- You can download an authenticated JSON export from Account. It excludes refresh tokens, OAuth credentials, shared exchange-rate cache data, and the external Supabase identity.
- You can permanently delete all user-owned Subtrack application records from Account using an exact confirmation phrase.
App-data deletion removes Subtrack's database records and signs the current browser out. It does not delete the identity held by Supabase because the current API is not configured with Supabase administrator credentials. If you sign in again, a new empty Subtrack data set can be created. This limitation will remain disclosed until external identity deletion is implemented and verified.
Cookies and local browser storage
Supabase uses browser storage and cookies needed to maintain authentication. Subtrack also stores limited interface preferences, such as theme and assistant panel size or view choice. Subtrack does not currently use advertising cookies.
Security
Controls include API verification of access tokens, user-scoped database queries, encrypted Google credentials, one-time OAuth state and PKCE, restricted CORS configuration, bounded external calls, and confirmation-gated AI actions with expiry and replay protection. Data is protected in transit using HTTPS in production. No internet service can promise absolute security.
Children
Subtrack is not directed to children. Do not use the service if you are not legally able to consent to its data handling in your location.
Policy changes
Material changes will be reflected on this page with an updated date. If a change materially affects optional Google-data use, Subtrack will provide notice appropriate to the change before relying on it.
Contact
For privacy questions, access concerns, or deletion assistance, use the operator contact listed on Subtrack's Google OAuth consent screen. A dedicated public support email must be configured before broad public release. Do not post personal or financial information in a public issue.