Privacy Policy
SubPulse (“we”, “our”, “the app”) is a personal subscription tracker for Android. This policy explains what data we collect, why, how it is stored, and your controls.
1. Who we are
SubPulse is operated by the SubPulse team. Privacy contact: info@thesubpulse.com
2. What Google user data we access
When you connect Gmail, SubPulse accesses email content (sender, subject, body) only to detect subscription and billing-related emails. We do not access contacts, calendar, or other Google data. We cannot send, delete, or modify your email. We request only the minimum scope: gmail.readonly.
3. Other data we collect
- Account data: email, display name, username, sign-in identifiers (email/password or Google Sign-In)
- Subscription data: service name, cost, currency, billing cycle, renewal dates, category, notes, optional card nickname / last-4 digits you type yourself (not full card numbers; we do not process payments)
- Email content: only if you link Gmail or IMAP.
- Household data: if you join a household, membership and shared subscription summaries
- Basic diagnostics to keep the app stable
4. How we use data
- Show subscriptions, renewals, analytics, and reminders
- Sync data when you are signed in
- Detect subscriptions from linked email after you opt in Household sharing only if you opt in
- Google Play Billing for purchases
5. How we protect data
- Encryption in transit (HTTPS/TLS) between the app, our servers, and Google APIs
- Much email analysis happens on-device (rules + on-device/assisted classification)
- When needed, limited content may be sent to Google Gemini via a paid API key (not used to train models; not retained beyond the request)
- Extracted subscription fields are stored in the app database; raw email bodies are not kept as a mail archive
IMAP credentials stay on-device in Android Keystore–backed storage and are not uploaded - Account/sync data is stored with Supabase under access controls
- We do not sell or rent your data to advertisers
6. Sharing
We do not sell personal data. We use infrastructure providers only to run the service (e.g. Supabase, Google for Sign-In / Gmail / Play Billing).
7. Your controls
- Connect or disconnect Gmail/IMAP anytime in the app
- Export subscriptions as CSV
- Delete your account in Privacy Centre (removes cloud account data and signs you out)
- Revoke Google access in your Google Account permissions
8. Retention
Data is kept while your account is active. Deleting your account removes associated server data as described in the app.
9. Children
SubPulse is not directed at children under 13 (or the minimum age in your country).
10. Changes
We may update this policy. The “Last updated” date will change when we do.
11. Contact
Privacy questions: info@thesubpulse.com