Legal

Privacy Policy

Last updated April 2026 · Questions? [email protected]

Who we are

Subkept is a subscription tracking service operated by an independent developer. The service is accessible at subkept.com. For privacy-related enquiries, contact [email protected]. References to 'we', 'us', or 'our' in this policy refer to the operator of Subkept.

What personal data we collect

We collect your email address when you create an account, used solely for authentication and to send renewal reminder notifications you have configured. We collect subscription data that you manually enter into the app, including service names, prices, billing cycles, start dates, and optional notes. We do not collect payment information. All payments are processed directly by our payment processor and we receive only a confirmation of successful payment. We may store basic session data such as login timestamps to maintain account security.

How we use your data

Your email is used to authenticate your account and to send the specific reminder notifications you enable in your settings. Your subscription data powers the dashboard, spending summaries, trial countdowns, and reminder system. We do not use your data for advertising, profiling, AI training, or any purpose other than delivering the service to you. We do not sell your data to any third party.

Legal basis for processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data are: (a) contractual necessity, because we need your email and subscription data to provide the service you signed up for; (b) consent, for optional email notifications, which you can enable or disable at any time in your account settings; and (c) legitimate interests, to maintain the security and integrity of the service.

Data storage and retention

Data is stored on Supabase infrastructure. We retain your personal data for as long as your account remains active. If you delete your account, all associated data is permanently removed from our systems within 30 days. We do not retain backup copies of deleted account data beyond this period.

Cookies and local storage

Subkept uses only technically necessary session cookies required to maintain your authenticated login state. We do not use advertising cookies, tracking pixels, third-party analytics scripts, or any technology that monitors your behavior across other websites or apps. We do not use Google Analytics or any equivalent service.

Third-party services

We use the following third-party services to operate Subkept: (1) Supabase, for database and authentication infrastructure; (2) a payment processor (such as Polar, Paddle, or Lemon Squeezy), used to securely process subscription payments; we never see or store your payment card details. Each of these providers maintains their own privacy policy and security standards. We do not integrate with any advertising networks, data brokers, or social media tracking systems.

Your rights (GDPR / UK GDPR)

If you are a resident of the EEA or UK, you have the following rights regarding your personal data: Right of access: you may request a copy of the data we hold about you. Right to rectification: you may update your data at any time within the app. Right to erasure: you may delete your account and all associated data at any time via the app settings. Right to data portability: you may export your subscription data as a CSV at any time from your dashboard. Right to restriction: you may request that we limit how we process your data. Right to object: you may opt out of non-essential communications at any time. To exercise any of these rights, contact us at [email protected]. We aim to respond within 30 days.

Data security

We use industry-standard security practices including row-level security on all database tables, HTTPS encryption for all data in transit, and secure authentication managed by Supabase Auth. While no internet-based service can guarantee absolute security, we take reasonable and appropriate precautions to protect your data.

Children's privacy

Subkept is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a minor has created an account, contact us at [email protected] and we will promptly delete the account and associated data.

Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the app before the changes take effect. Continued use of the service after changes constitutes your acceptance of the updated policy.

Contact

For any privacy questions, data subject requests, or concerns, contact us at [email protected]. We aim to respond to all privacy enquiries within 5 business days.

© 2026 Subkept. All rights reserved.