Privacy policy
Last updated
SubEye is a subscription tracker for iPhone. You type in what you pay and it tells you what that costs. It has no access to your bank, no access to your email, and it does not go looking for subscriptions on your behalf — so the only data it holds is the data you gave it.
Who is responsible
SubEye is built and operated by Yehor Hunko, an individual based in Ukraine, acting as the data controller. For anything in this policy, write to privacy@subeye.cc.
What SubEye collects
- Your email address and your name or username. Supplied when you create an account, or by Google, GitHub or Apple if you sign in through one of them.
- An account identifier issued by Clerk, the authentication provider. It is what links your subscriptions to you.
- The subscriptions you enter: service name, website, amount, currency, billing period, payment dates, category, price history and any note you write. All of it typed by you.
- Technical data that any web request carries — an IP address and a device user agent — seen by the services listed below while a request is being served.
- Diagnostics, when something goes wrong: if the app crashes, the stack trace with your device model and OS version. If you buy SubEye Pro, the App Store receipt for that purchase. Neither carries anything you typed.
There is no advertising identifier, no location data, no contacts, no photos, and no advertising or product-analytics SDK in the app. Two SDKs do ship inside it — crash reporting and purchases — and both are listed below.
Who else processes it
SubEye is a small app on ordinary infrastructure. These are every third party involved and what each one receives.
- Clerk — authentication (United States)
- Holds your email address, your name, your password or the link to your Google, GitHub or Apple sign-in, and issues the account identifier. Clerk is where your account actually lives.
- Neon — database (European Union, Frankfurt)
- The Postgres database that stores your subscriptions and your account identifier. It does not store passwords.
- Cloudflare — API hosting (global edge network)
-
Runs the SubEye API at
app.subeye.cc. Every request from the app passes through it, which means Cloudflare sees your IP address. - PostHog EU — server error telemetry (European Union)
- Receives exceptions raised by the SubEye API so faults can be found and fixed, keyed by your account identifier. It is not product analytics and there is no session recording. It sees only what happens on the server; a crash inside the app goes to Sentry instead.
- Sentry — crash reporting (European Union)
- Receives the stack trace of a crash in the app, with your device model and OS version, keyed by your account identifier. That is all of it: no subscription names, no amounts, no notes, no email address, no screenshots and no session recording.
- Brandfetch — brand logo search
- Receives the text you type into the brand picker. Described in full below.
- Google — logo images
-
Service logos are loaded as favicons from
google.com/s2/favicons. That request discloses the website domain of the subscription and your IP address. It carries nothing you typed and no account identifier. - RevenueCat — purchases (United States)
- Receives the App Store purchase receipt, the store transaction and the account identifier used as the app user id, if you buy SubEye Pro. It is what makes "you bought Pro" survive a reinstall or a new phone. It receives no subscription data and no email address.
- Apple — the App Store
- Handles the purchase if you buy SubEye Pro, under Apple's own privacy policy. SubEye never sees your payment details.
The brand logo search, specifically
When you add or edit a subscription you can search for a service by name to
attach its logo. What you type in that field is sent to api.brandfetch.io, along with your IP address, because that is how the search runs.
Nothing else goes with it. No account identifier, no email address, no subscription data, no token. The results are used to draw the list on screen and are never written to disk. If you would rather not use it, leave the website field empty and type the service name yourself — the app works exactly the same without a logo.
Why any of this is held
To operate the service you asked for: to keep you signed in, to store the subscriptions you entered, to add them up correctly, and to remind you before a renewal. Under the GDPR that is performance of a contract for your account and your data, and legitimate interest for keeping the service working and secure.
Your data is not sold, not shared with advertisers, not used to profile you, and not used to train anything. There is no tracking across apps or websites, and no third-party advertising or analytics SDK inside the app.
Renewal reminders are scheduled on your device by iOS. There is no push server and no notification token, so no one — including SubEye — learns when a reminder fires.
How long it is kept, and how to delete it
Your subscriptions are kept for as long as your account exists. Delete a subscription in the app and it is removed from the database.
Deleting your account in Settings removes the account and every subscription in it. Deletion happens at Clerk first, which then notifies the SubEye API, which purges every row belonging to that account from the database. It is a real deletion, not a flag, and it cannot be undone. Backups roll off within 30 days.
Your rights
SubEye serves the European Union and Ukraine, so the GDPR and Ukraine's Law on Personal Data Protection apply. You have the right to access a copy of your data, to correct it, to have it erased, to receive it in a portable form, to restrict or object to processing, and to complain to your supervisory authority.
Erasure is available immediately and without asking anyone: Settings → Delete account. For everything else, write to privacy@subeye.cc and expect an answer within 30 days.
Children
SubEye is not directed at children and does not knowingly collect data from anyone under 16. If you believe a child has created an account, write to privacy@subeye.cc and it will be deleted.
Changes
If this policy changes, the date at the top of this page changes with it. A change that materially affects what is collected or who processes it will be announced in the app before it takes effect.