Privacy Policy
Last updated: 1 October 2026
Overview
SubTracker ("we", "us", "our") is an Australian subscription tracking service. We take your privacy seriously. This policy explains what data we collect, how we use it, and your rights regarding that data.
What We Collect
Account information: When you sign up via Clerk (our authentication provider), we store your email address and display name. This is used to identify your account and send you renewal reminder emails.
Subscription data: The subscription details you save (merchant name, amount, frequency, category, renewal date, business/personal tag) are stored in our database (Convex) and associated with your account.
Payment information: Payments are processed by Stripe. We store a reference to your Stripe session for fulfilment purposes. We never see or store your card details.
Bank Statement Processing
When you upload a bank statement, we use OpenAI's GPT models, with Anthropic's Claude as the fallback, to decide which merchants are subscriptions. Your statement file is deleted as soon as the scan finishes. The results are held for up to 24 hours so you can come back to them, then deleted; only the subscriptions you approve are kept.
What we learn from scans. When you answer "yes" or "no" to a doubtful merchant in review, we keep a merchant-level note (the billing name, the brand, its website, and whether it is a subscription) so the next scan recognises it. That note is never linked to you and never contains your charges, amounts, dates or account. We also record counts about each scan (how many subscriptions were found, how long it took, which engine ran) with no merchant names or charge lines. For merchants we cannot identify, we may look the billing name up on the public web; the lookup sends the billing name only.
Refund cases
Starting a case does not change how we handle your bank statement. Your statement file is deleted as soon as the scan finishes. The results are held for up to 24 hours so you can come back to them, then deleted; only the subscriptions you approve are kept. When you build a case, the specific charge lines you tick are also saved as your evidence: their date, the raw statement descriptor, and the amount. Those saved lines are the charges the merchant letter quotes, and they appear on your case record as your attested evidence.
Your authority and signature. When you sign the authority to send a letter, we record the name you typed, the time you signed, and the IP address you signed from, as evidence that you authorised the correspondence. We keep this on the case.
The details you give to locate the account. The case letter includes the information a merchant needs to find you: your name, the email address on your account with that merchant, and, if you provide them, your membership number and home club. You supply these during intake, and they are stored on the case because they form part of the letter we send on your behalf.
Correspondence on your case. We record the letter we send and any follow-up. When the merchant replies to the case address, we store the reply on your case, including who it came from, its subject, and its content, and we forward you a copy. Inbound email to the case address passes through and is retained by our email provider, Resend, in the ordinary course of delivering it. Outbound case email is sent through Resend as well.
The verification record. Every letter links to a verification page at a unique, unguessable web address for that case. Anyone who has the link can view it; there is no login. The page shows the letter as it was sent, but with the identity lines redacted: the email address on your merchant account, your membership number, and your home club are withheld, appearing as "[withheld on this public record]" rather than their real values. What it shows is the letter body with those lines withheld, the delivery timestamps, the follow-up timestamps, the name of the person who signed the authority, and the time they signed. It does not show the IP address recorded with your signature. Keep the link private if you do not want the letter visible to whoever holds it.
Founder notifications. Case activity, such as a letter sending, a follow-up going out, a check-in, or a fee refund, generates an internal notification to SubTracker's founder so cases can be monitored. These notifications reference the case and the merchant.
Third-party services for cases. In addition to the services listed below, cases use:
- Resend: delivery of outbound case letters and receipt of inbound merchant replies to the case address. Inbound and outbound case email transits and is retained by Resend. See Resend's Privacy Policy.
- Stripe: the upfront case fee, and the automatic refund of that fee under the guarantee. See Stripe's Privacy Policy.
Retention and deletion of case data. Case records, their evidence lines, the authority signature, and the correspondence are retained while your account is active and while a case may need to be evidenced or a fee refund processed. Deleting your account removes your case data along with the rest of your account. The verification page for a case stops resolving once the underlying case is removed.
Third-Party Services
- Clerk: Authentication and user management. See Clerk's Privacy Policy.
- Convex: Real-time database for storing your subscription data. See Convex's Privacy Policy.
- OpenAI: GPT models for subscription detection. Statement text is sent to OpenAI's API. See OpenAI's Privacy Policy.
- Anthropic: Claude, the fallback model for subscription detection. See Anthropic's Privacy Policy.
- Exa: billing names of unrecognised merchants are looked up on the public web. See Exa's Privacy Policy.
- Resend: Transactional email delivery for renewal reminders. See Resend's Privacy Policy.
- Stripe: Payment processing. See Stripe's Privacy Policy.
- Google Analytics and Google Ads: we measure visits, scans started and purchases, and which ad or page a visitor came from, to see what brings customers. Both set cookies in your browser. Google receives counts, such as how many subscriptions a scan found, never your statement, merchant names or amounts from it. See Google's Privacy Policy.
Email Reminders
We email you a weekly list of tracked subscriptions renewing in the next 7 days, and a reminder the day before a yearly or quarterly charge. You can switch to daily reminders or turn them off from any reminder email.
Data Retention
Your subscription data is retained for as long as your account is active. If you delete your account, all associated data (subscriptions, upload history) will be permanently removed. Your statement file is deleted as soon as the scan finishes. The results are held for up to 24 hours so you can come back to them, then deleted; only the subscriptions you approve are kept.
Your Rights
You can:
- Access all your stored subscription data through the dashboard
- Edit or delete any subscription at any time
- Export your data as CSV
- Request account deletion by contacting us
Data Security
We use industry-standard security practices including encrypted connections (HTTPS), authenticated API endpoints, and secure third-party services. We do not require or store bank login credentials. SubTracker works with downloaded statement files only.
Changes to This Policy
We may update this policy from time to time. Changes will be reflected on this page with an updated date. Continued use of SubTracker after changes constitutes acceptance of the revised policy.
Contact
For privacy-related questions, contact us at chris@subtracker.com.au.