SubSense

Effective July 28, 2026

Privacy policy

This policy explains what SubSense processes, why it is needed, how connected-source data is protected, and the controls available to you.

1. Scope and role

SubSense is a subscription intelligence application. It helps you review recurring payments, renewal dates, price changes, usage evidence, and cancellation records. SubSense does not move money, hold funds, provide credit, or ask for banking passwords or OTPs.

2. Data we process

Account and profile data

Email address, display name, authentication identifiers, region, currency, time zone, and preferences.

Subscription and financial records

Subscription names, amounts, billing cycles, renewal dates, payment labels, transaction descriptions, transaction amounts, merchant information, and your review decisions.

Imported and connected-source data

Data you explicitly upload or authorize through a supported bank, Account Aggregator, Gmail, receipt, statement, or CSV connection. Available providers depend on region and production approval.

Security and diagnostics

Session information, connection status, sync history, audit events, error codes, and device notification tokens required to operate and secure the service.

3. How data is used

SubSense does not sell personal data and does not use connected financial or Gmail data for advertising.

4. Connected providers and consent

Provider connections are optional. Before a connection begins, SubSense explains the source and permission requested. Provider credentials and refresh tokens are handled server-side and encrypted. You can disconnect a source from the app.

Gmail, bank, and Account Aggregator access is enabled only after the required provider approval. Unavailable sources are not represented as connected and are never replaced with sample transactions.

5. Sharing and processors

Data is shared only with service providers needed to operate SubSense, such as authentication, database, hosting, notification, monitoring, and explicitly selected financial or email providers. Each processor receives only the data needed for its role. Data may also be disclosed when required by law or to protect users and the service.

6. Retention

Workspace records are retained while your account is active or until you delete them. Raw import files use limited retention and are removed by an automated retention process after processing or expiry. Security and audit records may be retained for a limited period where needed for fraud prevention, compliance, and dispute handling.

7. Security

SubSense uses encrypted transport, row-level database access controls, encrypted provider credentials, secure device session storage, authenticated webhooks, restricted server secrets, audit records, and optional device biometrics. No system can guarantee absolute security, so keep your device and account credentials protected.

8. Your controls

Account deletion removes the active workspace and initiates deletion of associated cloud records, subject to narrowly required legal or security retention.

9. Children

SubSense is not directed to children under 13, or a higher minimum age where local law requires it. Do not use the service if you cannot legally consent to these practices.

10. Changes and contact

Material changes will be reflected by a new effective date and, where appropriate, an in-app notice. Privacy and account requests can be started from the in-app Help Center or the official Support page.