← Subscription OS

Privacy Policy

Last updated July 27, 2026.

What this covers

This policy describes how Subscription OS ("we", "us") collects, uses, and protects information when you use the app at subscription-os.vercel.app. By using Subscription OS you agree to this policy.

Information we collect

  • Account information: the email address you sign in with. We use it only to send you a sign-in link and, if you choose, renewal/trial reminders.
  • Subscription data you enter: subscription names, amounts, currencies, renewal dates, categories, and notes you add yourself.
  • Gmail data, only if you connect an account: a read-only OAuth token, the connected email address, and metadata (subject, sender, date) plus extracted fields (vendor, amount, renewal date) from emails that look like subscription receipts or invoices.

How we use Gmail data

If you connect a Gmail account, we request the gmail.readonlyscope solely to search for and read emails that look like subscription or invoice confirmations. We do not read, store, or otherwise access any other email in your inbox. The subject, sender, date, and body text of a matched email are sent to Anthropic's API to extract a vendor name, amount, currency, and renewal date -- we do not store the full email body, only the extracted fields plus the subject line, sender, and date shown on the review screen. You approve or dismiss every match yourself before anything becomes a tracked subscription; nothing is imported automatically. You can disconnect a Gmail account at any time from Settings, which immediately stops any further scanning of it.

Subscription OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never use Gmail data for advertising, and we never sell it.

Who else sees this data

We use the following service providers to run Subscription OS. None of them are permitted to use your data for their own purposes:

  • Railway -- hosts our Postgres database.
  • Vercel -- hosts the application and runs its serverless functions.
  • Resend -- sends sign-in and reminder emails on our behalf.
  • Anthropic -- processes matched email text to extract subscription details, as described above.
  • Google -- provides the Gmail API used for the optional Gmail import feature.

We do not sell your data to anyone, for any reason.

Data retention and deletion

We keep your data for as long as your account exists. Disconnecting a Gmail account stops future scanning but doesn't delete candidates already reviewed. To delete your account and all associated data, email us at divyansh.sharma@thecollabrix.com and we'll remove it.

Security

Data is encrypted in transit (HTTPS) between your browser, our servers, and our service providers. OAuth tokens are stored server-side and are never exposed to the browser.

Children's privacy

Subscription OS is not directed at, and is not knowingly used by, children under 13.

Changes to this policy

If we make material changes, we'll update the date at the top of this page.

Contact

Questions about this policy: divyansh.sharma@thecollabrix.com