How Track-Subs handles your data. Transparent, secure, and privacy-first.
Track-Subs is operated by ALYAS GROUP. We are a subscription intelligence platform that helps people find, manage, and cancel recurring charges.
Contact: support@track-subs.com
Website: track-subs.com
| Data type | What exactly | Why |
|---|---|---|
| Account info | Email address, name (if provided via OAuth), authentication provider | Account creation and login |
| Email metadata | Sender address, subject line, date, and billing-related snippets from subscription emails | Detect and classify subscriptions |
| Subscription data | Service name, price, billing cycle, renewal date, category, cancellation status | Core product functionality |
| Notification preferences | Email, phone number (optional), notification channels and timing | Send renewal reminders |
| Payment data | Paddle customer ID, subscription status, plan type | Manage Pro subscription billing |
| Usage data | Scan count, scan timestamps, features used | Enforce plan limits, improve the product |
Our AI scan engine searches your inbox for emails matching subscription-related patterns: receipts, invoices, billing confirmations, renewal notices, and payment confirmations from known services. We process:
Emails are processed in real-time during a scan. The full email content is not stored permanently. We extract only the structured subscription data (name, price, cycle, date) and discard the raw email content after processing. The extracted data is stored in your secure user profile.
Track-Subs' use of the Gmail API adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Gmail data for providing and improving Track-Subs features directly requested by you.
Your data is stored on Supabase (built on PostgreSQL), hosted on secure cloud infrastructure. All data is encrypted at rest and in transit (TLS 1.2+).
Every database table uses Row-Level Security (RLS) policies. This means each user can only access their own data — not other users' subscriptions, scan results, or account information. Even if our application code had a bug, the database would still enforce isolation.
Gmail/Outlook access tokens are stored encrypted in the database. Refresh tokens are used to maintain your email connection without requiring you to re-authenticate. You can disconnect your email account at any time from Settings.
We use your data exclusively for:
Track-Subs uses the following third-party services to operate:
| Service | Purpose | Data shared |
|---|---|---|
| Google (Gmail API) | Email scanning | OAuth tokens; Google accesses your email on our behalf |
| Supabase | Database, authentication | All stored data (encrypted, RLS-protected) |
| Paddle | Payment processing (Merchant of Record) | Email, payment method (handled entirely by Paddle — we never see your card number) |
| Resend | Email notifications | Your email address, notification content |
| Vercel | Frontend hosting | No user data — static file serving only |
| AI providers (Groq, Gemini, Mistral) | Subscription classification (Layer 2) | Anonymized email snippets for classification — no personal identifiers sent |
Track-Subs uses zero tracking cookies and no third-party analytics. We do not use Google Analytics, Facebook Pixel, or any advertising trackers.
We use localStorage (browser-side only) for:
This data never leaves your browser and is not transmitted to any server.
Depending on your jurisdiction, you have the right to:
To exercise any of these rights, contact support@track-subs.com. We will respond within 30 days.
We implement industry-standard security measures:
No system is 100% secure. If we discover a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours.
Track-Subs is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
Your data may be processed in countries outside your own (our infrastructure providers operate globally). We ensure appropriate safeguards are in place, including compliance with applicable data protection regulations.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent version.
For privacy questions, data requests, or concerns: