Privacy policy
Last updated: July 2026
The short version
SubSaver reads billing emails to find your subscriptions. We keep billing metadata (merchant, amount, dates), never the emails themselves. You can disconnect and erase everything at any time. We never sell data. That's the whole business model: you pay us a small subscription; your data pays nobody.
What we collect
Account: your email address and name (from sign-in). Mailbox access: with your consent, read-only OAuth access to Gmail (gmail.readonly) or Outlook (Mail.Read). OAuth tokens are encrypted with AES-256-GCM at rest. Billing metadata: for detected subscriptions we store the merchant, amount, currency, billing cycle, and relevant dates — extracted from email headers and snippets during scanning. Email bodies are processed transiently and never stored. Payments: handled by our payment provider (Stripe or Polar); we never see your card number.
What we never do
We never send, delete, modify, or forward your email. We never store message content. We never sell or share personal data with advertisers. We never use your data to train AI models.
Google API Services disclosure
SubSaver's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights (GDPR)
Access, rectification, erasure, portability, and objection — exercise any of them from Settings or by emailing support@subsaver.help. Disconnecting a mailbox deletes its tokens immediately; deleting your account removes all associated data within 30 days.
Data processors
Hosting (Vercel), database (managed PostgreSQL), transactional email (Resend), payments (Stripe/Polar), error monitoring (Sentry), product analytics (PostHog, EU-hosted). Each processes data solely on our instructions.
Contact
Data controller: SubSaver. Questions: support@subsaver.help.