Skip to main content
SubsTrackerPro ← Back
ESENPT

Privacy Policy — SubsTrackerPro

DRAFT v2.0 — Requires review by professional legal counsel before publication. This text does not constitute legal advice.

Version: 2.0 Last updated: July 29, 2026 Traceability note: version 2.0 was published on July 13, 2026 and updated on July 29, 2026 to reflect data processing added to the product (system calendar sync, currency conversion, preferred currency, Spotlight indexing, and creator payouts). Source language: Spanish (this English version and the Portuguese version are faithful translations of the Spanish source; in case of an interpretation conflict, the Spanish version prevails unless applicable law provides otherwise).


1. Scope and data controller

This Privacy Policy describes how SubsTrackerPro ("we," "the Company," "the Service") collects, uses, stores, shares, and protects the personal data of people who use the SubsTrackerPro app (iPhone, iPad, Mac, Apple Watch, widgets, and Live Activities) and the website substrackerpro.com (together, the "Service").

Legal entity responsible for processing, registered address, and jurisdiction: [PENDING LEGAL REVIEW — LAUNCH BLOCKER: define the legal name, registered address, and jurisdiction of the entity responsible for processing before publishing this policy; must be completed with legal counsel before any public publication]. Until this information is completed and published, any request related to this policy should be directed to the contact channel in Section 15.

This policy applies to all users of the Service regardless of geographic location, and has been drafted to comply simultaneously with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and Brazil's Lei Geral de Proteção de Dados (LGPD).

2. Data we collect

We collect only the data necessary to operate the Service. We do not integrate third-party SDKs for advertising, tracking, or behavioral-analytics purposes unrelated to product functionality.

CategorySpecific dataSourceRequired
AccountEmail, name, country, preferred language, preferred display currencyEntered by the user at sign-upYes
Subscriptions and servicesService name, amount, currency, billing cycle, category, charge dateEntered by the user or extracted from a screenshot via AIYes, for core product function
Payment methods (reference only)Only the last 4 digits of the card associated with a subscription, for visual identification within the appEntered by the userNo
Savings goalsGoal name, target amount, progressEntered by the userNo
Family data (invitations)Email address of the person invited to join the shared family planEntered by the user who sends the invitation (the recipient is a third party who, at the time of the invitation, is not yet a user of the Service)No
Creator/referral programPublic display name, referral code, chosen payout method, and the details tied to that method (e.g., PayPal email address)Entered by the user when joining the programNo
System Calendar syncEach subscription's service name, amount, currency, and charge date, written as text (title/notes) into an event on the device's CalendarAutomatically generated when the user enables this optional feature (see details below and in Section 4)No
Screenshots (AI import)Image of an email, notification, or bank statement the user chooses to importVoluntarily uploaded by the userNo
Data processed by the AI CoachThe user's already-stored subscription and service data, used as context to generate recommendationsAutomatically generated from data already storedNo (optional feature)
Local security dataBiometric lock preference (Face ID/Touch ID); the biometric data itself never leaves the device and is managed exclusively by Apple's operating systemDevice settingsNo
Crypto payment dataTransaction status (pending/confirmed/failed), amount, and network used; we do not collect or store private keys or seed phrasesGenerated by the payment provider (Section 4)Only if the user subscribes to a paid plan
Local indexing (Spotlight)Each subscription's name and category, indexed by the operating system for on-device search. Happens entirely on-device via Apple's CSSearchableItem API and is never transmitted to our servers or to any third partyAutomatically generated from data already storedNo

We do not collect precise geolocation data, device contacts, or special-category data (health, ethnic origin, sexual orientation, political or religious opinions, biometric data for identification purposes), except for the purely local use of Face ID/Touch ID described above, which is not processed by us and never leaves the device.

The email address of a person invited to a family plan is collected from a third party who, at the time of the invitation, is not a user of the Service. Section 6 describes the retention and purge period applicable to invitations that are not accepted.

System Calendar sync is an optional feature the user explicitly enables. Once enabled, each subscription's name, amount, currency, and charge date are written as text into an event on the device's Calendar (via Apple's EventKit framework). That event is saved to whichever calendar the user already has configured on their system — which may belong to an iCloud, Google, or Microsoft Exchange account — so once written, that data may sync onward to that third-party account, outside this app's control (see Section 4). The user can disable this sync at any time from the app's settings, which removes any events already created.

3. AI processing

The Service offers two features that use AI models:

  1. Screenshot import: the user uploads an image (e.g., a billing email) and an AI model extracts structured subscription data (name, amount, date). The image is processed for this single purpose and is not stored permanently once extraction is complete; it is discarded after processing.
  2. AI Coach: analyzes the user's already-stored subscription and service data to generate savings recommendations and alerts. It is not used to make automated decisions with legal effects on the user (see Section 9 for the distinct case of the creator/referral program).

Data sent to these models is not used to train third-party models beyond the one-time processing of the request. Before the first use of each feature, the Service presents a specific consent notice within the app, and the user can disable both AI features at any time from Settings → Privacy and Data.

4. Who we share data with (subprocessors and third parties)

We do not sell personal data. We share data only with the following providers, strictly necessary to operate the Service, each acting as a data processor under our instructions:

ProviderRoleData processed
Supabase (infrastructure managed by Lovable Cloud)Database and authentication hostingAll account, subscription, service, and goal data described in Section 2
AI provider — [TO BE CONFIRMED: e.g., OpenAI / Anthropic / Google — pending confirmation of which provider the import-from-screenshot and ai-coach edge functions use internally]Computer-vision and natural-language processing for screenshot-based subscription import and for generating AI Coach recommendationsFor screenshot import: the image uploaded by the user, which may contain partially visible card numbers, merchant names, and amounts. For the AI Coach: the user's already-stored subscription and service data (Section 2), with no account identifiers beyond what is strictly necessary to process the request
NOWPaymentsCryptocurrency payment processorAmount, currency, generated payment address, transaction status. NOWPayments does not receive the user's email or full name beyond what is strictly necessary to process the payment
AppleApp distribution (App Store), push notifications (APNs), widget and Live Activity synchronization, local biometric authenticationTechnical device/notification identifiers necessary to deliver the Service; Apple acts under its own privacy policies for these platform services
Exchange-rate provider (open.er-api.com / ExchangeRate-API)Automated exchange-rate lookup to compute the total converted to the user's preferred display currencyReceives no personal data about the user. The request carries no session, account identifier, or subscription data — it is a fixed-URL GET with no parameters or body. The only thing the provider can infer on its own is the device's IP address and user-agent, standard to any HTTP request

Additionally, if the user enables the optional System Calendar sync (Section 2), the data written to that event may sync onward to whichever calendar account the user already has configured (e.g., iCloud, Google, or Microsoft) — this is not a processor acting on our instructions, but a third party chosen and controlled by the user, outside this app and outside our instruction.

We do not use advertising networks, tracking pixels, or third-party analytics for commercial profiling purposes. The subprocessors we currently use are those listed in this table; the specific name of the AI provider is pending internal confirmation and will be updated in this policy as soon as it is confirmed (see the placeholder in the corresponding row). Any future addition of a subprocessor other than those listed here will be disclosed through an update to this policy (Section 12).

Note on Data Processing Agreements (DPAs): before the public publication of this policy, the corresponding Data Processing Agreements must be executed and filed with each of the subprocessors listed above — Supabase/Lovable Cloud, NOWPayments, and the AI provider — as required by Article 28 of the GDPR and equivalent rules. [PENDING LEGAL — LAUNCH BLOCKER: confirm execution and filing of these DPAs before publishing this policy.]

5. Legal basis for processing (GDPR, Art. 6)

PurposeLegal basis
Create and administer the account, provide the contracted ServicePerformance of a contract (Art. 6(1)(b))
Process cryptocurrency paymentsPerformance of a contract (Art. 6(1)(b))
AI features (coach, screenshot importer)Specific consent (Art. 6(1)(a)), revocable at any time
Account security and fraud preventionLegitimate interest (Art. 6(1)(f)), balanced against user rights
Compliance with legal obligations (e.g., tax or judicial authority requests)Legal obligation (Art. 6(1)(c))
Notices about changes to the Service or this policyLegitimate interest / performance of the contract

6. Data retention

We retain personal data only for as long as necessary for the purposes described:

  • While the account is active: all data in Section 2 is retained to provide the Service.
  • After account deletion (the "Delete account" feature, available directly in the app): personal data is removed from production databases immediately, and from backups within a maximum of 30 days, after which no recoverable copy remains.
  • AI importer screenshots: not stored after extraction (see Section 3); no retention period applies because none are kept.
  • Payment transaction data: retained for the minimum period required by applicable legal, accounting, or tax obligations, even if the account is deleted before that period ends, strictly limited to the data necessary for such compliance.
  • Security and fraud-prevention logs: up to 12 months after the relevant event.
  • Unaccepted family plan invitations: if an invitation sent to a third party is not accepted within 90 days of being sent, the invited person's email address and the invitation record are automatically deleted from our systems.

7. International data transfers

The Service operates with infrastructure providers that may process data in different countries. When a transfer involves sending personal data of users in the European Economic Area, the United Kingdom, Brazil, or California to a country without an adequacy decision, appropriate safeguards under applicable law (e.g., GDPR Standard Contractual Clauses) are used in our contracts with providers.

Applicable legal framework in Venezuela. The Service's operator is domiciled in Venezuela. As of this draft, Venezuela does not have a comprehensive personal data protection law equivalent to the GDPR in force. The regulatory floor currently existing under Venezuelan law includes: (a) the constitutional right of habeas data, recognized in Article 28 of the Constitution of the Bolivarian Republic of Venezuela, which allows every person to access information about themselves or their assets held in official or private records and to know how it is used; and (b) the Special Law Against Computer Crimes (Ley Especial contra los Delitos Informáticos, 2001), which criminalizes certain conduct related to unauthorized access, appropriation, and fraudulent use of data and computer systems, without constituting a comprehensive personal data protection regime. In the absence of a Venezuelan law equivalent to the GDPR, we apply, as a more protective voluntary commitment, the GDPR, CCPA/CPRA, and LGPD standards described in the preceding sections. [PENDING LEGAL REVIEW: this section must be validated and, if necessary, expanded by Venezuelan legal counsel before this policy is published.]

8. Data security

We apply reasonable technical and organizational measures, including: encryption in transit (TLS) for all communication between the app and the backend; file-level protection (File Protection) for data stored locally on the device; optional biometric authentication (Face ID/Touch ID) for app lock, managed entirely by the operating system so the biometric data never leaves the device or becomes accessible to us; and authentication-based access control for all data hosted on the backend.

No security measure is infallible. In the event of a security breach affecting personal data, we follow the procedure described in Section 11.

9. Automated decisions — creator and referral program

The Service offers a creator/referral program that uses an automated scoring system to evaluate each participant's eligibility and benefit level, based on activity metrics and verified referrals.

Under Article 22 of the GDPR and equivalent rules, any user subject to such a decision has the right to: (a) obtain an explanation of the general logic applied; (b) request human review of the decision; and (c) contest it. These requests may be sent to the contact channel in Section 15, including the account identifier.

10. Your rights

Regardless of your location, every user can exercise the following rights, implemented directly in the app unless otherwise noted:

Under the GDPR (EEA/UK users):

  • Access: know what data we hold about you.
  • Rectification: correct inaccurate data, editable directly in the app's Settings.
  • Erasure ("right to be forgotten"): delete your account and associated data — "Delete account" button in Settings → Privacy and Data.
  • Portability: download your data in structured format (JSON) — "Download my data" button in Settings → Privacy and Data, available free of charge and without requiring a paid plan. The export includes: account profile data, subscriptions, recurring services, associated cards (last 4 digits only), savings goals, the local payment history (ledger), family plan data (invited members and their status), creator/referral program data, AI Coach insight history and usage logs, notifications, gamification streak and achievements, and category budgets along with the last-seen price recorded per subscription. Additionally, a CSV export of subscriptions exists as a convenience feature for paid-plan users.
  • Objection and restriction of processing: you may object to processing based on legitimate interest or request its restriction by contacting us.
  • Withdraw consent: at any time, for the AI features, from Settings → Privacy and Data.
  • Right to lodge a complaint with the data protection supervisory authority of your country of residence.

Under the CCPA/CPRA (California residents):

  • Right to know what categories of personal information are collected, used, and shared (see Sections 2 and 4).
  • Right to delete your personal information ("Delete account" button).
  • Right to correct inaccurate information.
  • Right to data portability ("Download my data" button).
  • Right to non-discrimination for exercising any of these rights.
  • We do not sell or "share" personal information within the meaning of the CPRA (no interest-based advertising or disclosure to third parties for commercial purposes unrelated to providing the Service), so no additional "do not sell/share" mechanism applies.
  • We do not process sensitive personal information (as defined by the CPRA) beyond what is strictly necessary to provide the Service, and we do not use it to infer characteristics about the user.

Under the LGPD (Brazil users):

  • Confirmation of the existence of processing, access, correction, anonymization, blocking, or deletion of unnecessary data or data processed in violation of the LGPD, portability, deletion of data processed with consent, information about entities with which data was shared, information about the possibility of not giving consent and its consequences, and revocation of consent.
  • Right to request review of automated decisions affecting your interests (see Section 9).
  • Right to file a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD).

To exercise any right not directly available in the app, contact us via the channel in Section 15. We will respond within the timeframes required by the law applicable to your case (e.g., one month under the GDPR, extendable; 45 days under the CCPA/CPRA, extendable; 15 days under the LGPD for confirmation of processing).

11. Security breach notification

In the event of a security breach that compromises personal data and poses a risk to the rights and freedoms of affected users, we will notify the competent supervisory authority within 72 hours of becoming aware of the incident, when required by applicable law (GDPR Art. 33, LGPD Art. 48, and equivalents). Where the risk to users is high, we will also directly notify affected users without undue delay, describing the nature of the breach, the data affected, and the measures taken.

12. Changes to this policy

When we make material changes to this policy (e.g., new processing purposes, new providers, or changes to retention periods), we will actively notify you — via an in-app notice and/or email to your registered address — before the change takes effect, stating the effective date and a summary of what changed. Continued use of the Service after the changes take effect constitutes acceptance of the updated policy; if you disagree, you may delete your account before that date.

13. Minimum age

The Service is intended for people 18 years of age or older. We do not knowingly collect data from anyone under 18. If we become aware that we have collected data from someone under 18, we will delete it as soon as possible.

14. Governing law and jurisdiction

[PENDING LEGAL REVIEW — LAUNCH BLOCKER: define the legal name, registered address, and jurisdiction of the responsible entity before publishing this policy; requires validation by legal counsel, including review of the Venezuelan framework described in Section 7.]

15. Contact

To exercise your rights, make inquiries about this policy, or report a privacy concern: [PENDING — legal/privacy contact email address].