Privacy Policy
Last updated: 17 серпня 2026 / August 17, 2026
SubTracker ("we", "the app") is a subscription-tracking service by Volent. This page explains what data we collect, why, and how we protect it.
What we collect
Account: email and/or phone number, name (optional), password (stored only as a bcrypt hash — we never see it in plain text).
Subscription data you enter manually: service name, amount, currency, payment date, category, notes.
Payment-method labels ("Monobank Black", "Visa •••• 1234", etc.) — these are plain text labels, not real card numbers, balances, or a live bank integration.
If you choose to: your IMAP mailbox credentials (email + app password) to auto-detect invoices — the password is encrypted with AES-256-GCM; we don't read or store emails unrelated to invoices/receipts.
If you choose to: photos or PDFs of bank statements you upload for subscription recognition (a Premium feature) — processed via the Anthropic Claude API, not retained longer than needed for recognition.
Technical data: a device token for push notifications (if enabled), interface language, chosen theme.
A TOTP secret for two-factor authentication (if enabled) — stored encrypted.
Why we use it
To show your subscriptions, payment calendar, and spending analytics.
To send reminders before upcoming payments — by email and/or push (you choose the channel(s) in Settings, each toggled independently).
To auto-detect invoices in your mailbox or uploaded photos/statements — only if you've opted into that feature yourself.
To manage your Premium subscription via Google Play Billing.
Who we share data with
We never sell your data or share it for advertising.
Technical providers that process data on our behalf: Microsoft Graph / Resend (sending email), Anthropic (photo/statement subscription recognition), Firebase Cloud Messaging (push notifications), Google/Microsoft (if you sign in via their OAuth), Google Play (Premium payment processing).
We disclose data only when required by law.
Advertising & tracking
The app contains no ads, ad SDKs, or third-party marketing behavioral trackers.
Security
Passwords — bcrypt. IMAP passwords and the TOTP secret — AES-256-GCM. Connections — TLS. IMAP requests go through SSRF/DNS-rebinding protection.
How long we keep data
For as long as your account is active. You can delete your account and all associated data yourself, at any time: Settings → Danger zone → Delete account.
Deleting your SubTracker account
To delete your account and all data tied to it: open the SubTracker app → Settings → the "Danger zone" section at the bottom → "Delete account" button → confirm.
Deleted immediately and permanently: your account (email, phone, name, password), every subscription and reminder, tags, payment-method/bank labels, connected mailboxes together with their app passwords, device push tokens, and your two-factor authentication secret.
No additional retention period applies — data is removed from the live database as soon as you confirm.
You can also delete only specific data without deleting your whole account: disconnect a mailbox, remove individual subscriptions/tags/banks, or turn off push — all available in Settings without deleting your profile.
Children
The app isn't directed at children under 16, and we don't knowingly collect their data.
Your rights
You can view, change, or delete your data directly in the app. For data questions, use the contact below.
Changes to this policy
If we make a material change to this policy, the "Last updated" date at the top of this page will change accordingly.