Legal

Privacy Policy

Effective date: September 19, 2026 · Applies to the Subik app for iPhone and Android and to this website.

The short version. Subik asks for read-only access to your Gmail so it can find subscription receipts. Receipts are parsed on our servers in the EU and only the structured result — merchant, amount, currency, billing cadence, dates — is kept. Your email content is never stored, never read by a person, never sold, and never used for advertising or to train AI. You can disconnect a mailbox or delete your whole account from inside the app at any time.

1. Who we are

Subik is developed and operated by The Oat Labs, an independent software studio based in Israel, operated by Omer Attias (“The Oat Labs”, “we”, “us”). We are the controller of the personal data described in this policy.

Contact for anything privacy-related: subik@theoatlabs.com. Postal correspondence can be arranged through that address.

2. What Subik does

Subik is a subscription tracker. You sign in, connect the Gmail mailbox your receipts arrive in, and Subik scans it for payment receipts and renewal notices to build a list of the services you pay for. You can also add subscriptions by hand. Subik then shows spend totals, charge history and reminders before renewals. Subik does not connect to your bank, cards or payment providers and does not initiate or cancel any payment.

3. Information we collect

3.1 Account information

You sign in with Sign in with Apple or Google Sign-In. We receive the name and email address you choose to share (Apple’s “Hide My Email” relay addresses work) and a provider account identifier. We create a Subik account keyed to a random user ID and store your display name, chosen language and preferred currency.

3.2 Gmail data (Google user data)

To scan a mailbox, Subik requests the Google OAuth scope https://www.googleapis.com/auth/gmail.readonly (“View your email messages and settings”). This scope is read-only: Subik can never send, delete, label or modify email.

What a scan reads. Our server searches the mailbox for messages that look like payment receipts, invoices, trial or renewal notices, and reads the matching messages (headers and body) to extract subscription facts. The content is processed in memory and discarded when the scan finishes.

What we keep from a scan.

  • Structured subscription records: merchant name, amount, currency, billing cadence (weekly, monthly, quarterly, yearly), last and next charge dates, trial end date, detection status, and a per-subscription charge history derived from receipts.
  • The Gmail message identifiers of the receipts each subscription was derived from. These are opaque IDs used to avoid processing the same receipt twice and to let you re-check a detection. They contain no message content.
  • Mailbox metadata: the connected Gmail address, connection status, and the time of the last scan.
  • The OAuth refresh token Google issues, stored encrypted in a dedicated secret vault, referenced only by a random identifier. Every read of a token is audit-logged (function, secret ID, user ID, time, outcome — never the token itself).

What we never keep. Raw email bodies, subjects, sender or recipient addresses, attachments, contacts, or any message that was not a receipt. Nothing from your mailbox is written to logs.

3.3 Subscriptions you add manually

Merchant name, amount, currency, cadence, dates and category — stored exactly like detected subscriptions, marked as manual.

3.4 Purchases

Subik Pro and scan-credit packs are sold through the Apple App Store and Google Play. Purchases are processed by RevenueCat, which validates store receipts on our behalf. We store your entitlement state (plan, expiry, credit balance) and RevenueCat’s pseudonymous customer ID. We never receive your card or bank details — Apple and Google handle payment.

3.5 Notifications

Reminder settings you choose, and — if you allow notifications — a device push token so we can deliver reminders and scan updates through Apple’s and Google’s push services (via Expo’s push relay).

3.6 Usage analytics (optional)

To understand which features are used, Subik sends a small set of product events (for example “scan completed”, “paywall viewed”) with counts and booleans, tied to your random Subik user ID, to PostHog (EU Cloud). By design these events cannot carry merchant names, amounts, email addresses or message content. You can turn analytics off in Settings → Privacy & Data → Share usage data.

3.7 Crash and error reports

When the app crashes or hits an error, a report (stack trace, device model, OS and app version, your random user ID) is sent to Sentry (EU data centre). Reports are scrubbed of personal data before they leave the device.

3.8 Technical data

Our servers receive the usual request metadata (IP address, timestamps, app version) to operate and secure the service. Exchange rates for currency conversion are fetched from a public rates API without any personal data.

4. Google user data and the Limited Use requirements

Subik’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means:

  • Gmail data is used only to provide and improve Subik’s subscription-detection feature, which is visible and central in the app.
  • We do not transfer Gmail data to anyone, except to our infrastructure processors listed in section 6 as needed to run the feature, for security investigations, or when the law requires it.
  • No person at The Oat Labs reads your email. The only exceptions are if you explicitly ask us to look at a specific message to debug a problem, or where it is strictly necessary for security or legal compliance.
  • Gmail data is never used for advertising, never sold, never shared with data brokers, never used to assess credit-worthiness, and never used to develop, improve or train generalized AI or machine-learning models.

You can revoke Subik’s access at any time: in the app under Settings → Privacy & Data → Connected inboxes → Revoke (which revokes the token with Google and deletes it from our vault), or from your Google Account permissions page.

5. How we use information and why we may

PurposeDataLegal basis (EU/UK users)
Create and secure your accountAccount information, technical dataPerformance of our contract with you
Detect and track subscriptionsGmail data, subscription records, mailbox metadataYour consent (the Google permission screen), which you can withdraw at any time
Send reminders you asked forReminder settings, push tokenPerformance of our contract; your device-level consent to notifications
Sell and honour Pro and creditsPurchase and entitlement dataPerformance of our contract
Fix crashes and keep the service secureCrash reports, technical data, vault audit logOur legitimate interest in a reliable, secure service
Understand feature usageUsage analyticsYour consent, via the in-app toggle
Answer support requestsWhatever you send usOur legitimate interest in helping you
Comply with lawAs requiredLegal obligation

We do not use your data for automated decisions with legal or similarly significant effects, and we never sell personal data.

6. Who we share data with

We share data only with the service providers that run Subik, under contracts that limit them to processing on our instructions:

ProviderRoleLocation
SupabaseDatabase, authentication, server functions and the encrypted secret vaultFrankfurt, Germany (EU)
GoogleGoogle Sign-In; the Gmail API you authoriseGlobal
AppleSign in with Apple; App Store billing; push notifications (APNs)Global
Google PlayAndroid billing; push notifications (FCM)Global
RevenueCatPurchase validation and entitlementsUnited States
Expo (EAS)Push-notification delivery relay; app updatesUnited States
SentryCrash and error reportingEuropean Union
PostHogProduct analytics (if enabled)European Union
CloudflareHosting of this website and our support email routingGlobal

Gmail message content is processed only within Supabase’s EU infrastructure and Google’s own services. It is never sent to RevenueCat, Expo, Sentry, PostHog or Cloudflare.

We may also disclose data if required by law, to enforce our Terms, to protect the rights and safety of users, or as part of a merger or acquisition — and in that last case, only after telling you and, for Google user data, only with your explicit prior consent.

7. International transfers

Your account data and subscription records are stored in the EU. Some providers above operate in the United States or globally; where personal data leaves the EU, UK or Israel, we rely on the providers’ standard contractual clauses, the EU–US Data Privacy Framework where the provider is certified, or an adequacy decision (the EU recognises Israel as providing adequate protection).

8. How long we keep data

  • Account, subscriptions, mailbox metadata, tokens: for as long as your account exists. Deleting your account (section 10) removes them immediately; encrypted database backups are overwritten within 30 days.
  • Gmail message content: not retained — processed in memory during a scan only.
  • Disconnected mailbox: the token is revoked with Google and deleted at once; subscriptions already detected stay in your account until you delete them.
  • Crash reports: 90 days.
  • Usage analytics: no longer than 12 months.
  • Purchase records: kept by Apple, Google and RevenueCat for as long as required to honour refunds, disputes and accounting law.
  • Support emails: up to 24 months after the conversation ends.

9. Security

All traffic is encrypted in transit (TLS). Data is encrypted at rest. Every database table is protected by row-level security so that your rows can only be read by you. OAuth tokens live in a separate encrypted vault, referenced only by random identifiers, and every access is audit-logged. Server functions that touch Gmail data run with the minimum privileges needed and talk only to Google’s APIs and our own database. No system is perfectly secure; if we learn of a breach affecting you we will notify you and the relevant authorities as the law requires.

10. Your rights and choices

Wherever you live, you can:

  • See and export your data — everything Subik holds about you is visible in the app; email us for a machine-readable copy.
  • Correct data — edit any subscription, your name, language and currency in the app, or ask us.
  • Disconnect GmailSettings → Privacy & Data → Connected inboxes → Revoke.
  • Turn off analyticsSettings → Privacy & Data → Share usage data.
  • Delete your accountSettings → Privacy & Data → Delete Account, or follow the account-deletion instructions if you no longer have the app. Deletion revokes your Gmail token with Google, wipes the vault secret, and removes your account and every row that belongs to it.
  • Withdraw consent, object, or restrict processing — email us. Withdrawing consent does not affect processing that already happened.
  • Complain — to your local data-protection authority. In Israel that is the Privacy Protection Authority; in the EU, the authority of your member state.

We answer requests within 30 days. We may ask you to confirm the request from the email address on your account.

11. Notice under the Israeli Protection of Privacy Law

In accordance with section 11 of the Protection of Privacy Law, 5741-1981 (as amended):

  • No legal duty. You are not legally required to provide any information to Subik. Providing it — and granting Gmail access — is voluntary and depends on your consent.
  • Purpose. The information is requested to operate the Subik service as described in sections 2 and 5: identifying you, detecting and tracking your subscriptions, sending reminders you ask for, processing purchases, and keeping the service secure.
  • Consequences of refusal. Without an account you cannot use Subik; without Gmail access, automatic detection is unavailable and you can only add subscriptions manually; without notification permission you will not receive reminders.
  • Recipients. The information is transferred to the service providers listed in section 6, for the purposes stated there, and otherwise only as the law requires.
  • Controller and contact. The Oat Labs (Omer Attias), Israel — subik@theoatlabs.com.
  • Right of access and correction. You are entitled to inspect the information held about you and to request that inaccurate, incomplete or outdated information be corrected or deleted, as set out in sections 13 and 14 of the Law. Section 10 above explains how.

12. Children

Subik is not directed to children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.

13. Changes to this policy

When we change how we handle Google user data or make any other material change, we will update the effective date above and tell you in the app before the change takes effect. Earlier versions are available on request.

14. Contact

The Oat Labs · Israel · subik@theoatlabs.com · subik.theoatlabs.com/support