Legal
Privacy Policy
The short version. We keep the email address you sign in with and the subscriptions you enter. We never connect to your bank. We do not sell your data, we do not run ads, and there is no analytics or tracking software in the app or on this site. If you switch email forwarding on, we read the text of the emails you forward to find the subscription in them, and we delete that text after 30 days. You can delete your account from Settings, and everything goes with it.
Who we are
Subscription Scout is made by Tala Labs LLC, a limited liability company registered in New Jersey, United States, at 971 US Highway 202N, Ste N, Branchburg, NJ 08876.
Tala Labs LLC is the controller of the personal data described here. That means we decide what is collected and why, and we are the ones you hold to this document.
Subscription Scout is an app for keeping track of the subscriptions you already pay for. It tells you what renews and when. It is a tracker and nothing else — it does not connect to a bank, it does not move money, and it never cancels anything on your behalf.
What we collect, and why
Your email address
You sign in with an email address, and we send a six-digit code to it. We keep that address for as long as your account exists. It is how you sign in, how we send you a code, and how we reach you about the service. We need it to give you an account at all.
Your phone number, only if you give one
Settings has an optional phone number field. Its only purpose is sending you reminders by SMS. If you do not want SMS reminders, leave it empty, and nothing is missing.
The subscriptions you enter
This is the product. When you add a subscription we store what you typed or picked: the service, the price, the currency, the billing cycle, the payment date, a free-trial end date if there is one, the category you filed it under, and whether it is active or archived. We also store your primary currency, your language, and whether you have finished onboarding.
We use it to draw your list, add up your totals, and work out when to remind you. We do not use it for anything else.
Your device, if you turn reminders on
To send a push notification we need to store the notification token your device gives us, plus its time zone, its language and the app version. The time zone is what makes a reminder arrive in the morning where you are rather than where our server is. We also keep a log of which reminders were sent, so the same reminder is not sent twice.
Emails you forward, only if you switch forwarding on
See Forwarded emails below. This is off until you turn it on, and it is the only part of the product where text you did not type yourself reaches us.
Your plan
If you buy a paid plan we store which plan you are on, whether it is active, where it came from, and when the current period ends. That is what unlocks the paid features. Purchases themselves are handled by Apple — see the Terms. We never see or store your card number.
What we do not collect
There is no analytics, no advertising software, no crash-reporting service and no third-party tracking code in the iOS app, in the web app, or on this website. We have not put a tracker in this product and we do not intend to. This page makes no external requests of any kind.
The app and the web app do use your browser or device storage to keep you signed in and to remember whether you chose the light or the dark theme. That data stays on your device. It is not a tracking cookie and it is not shared with anyone.
Forwarded emails
Email forwarding is off by default, and it stays off until you switch it on. No forwarding address exists for your account until you enable it. If you never enable it, nothing in this section applies to you.
How it works
When you switch it on, we give you a personal address at subscriptionscout.com. You forward a subscription receipt or a renewal notice to it. We read the text, find the service, the price, the billing cycle and the next payment date, and put the result in front of you as a proposal. Nothing is added to your list until you confirm it.
Only the email address you sign in with may write to that address. Mail from anyone else is dropped without being read, and we do not reply to it.
What we keep, and what we throw away
- We keep, for 30 days: who the message was from, who it was to, the subject, the date, its message identifier, and the body as plain text.
- We drop attachments at the door. They are never stored, never opened and never sent anywhere.
- We never store the raw message. Only the plain-text body is kept, and it is capped in size.
- After 30 days the text is deleted. What survives is the subscription you confirmed, which is a row you approved rather than a copy of your mail.
An automated service outside this product reads the text
To find the subscription in an email we send the text of that email to Groq, an AI provider in the United States. Groq processes the text and returns what it found. We have Groq's zero data retention setting switched on, which means Groq does not keep the text after answering and does not use it to train anything.
This is the one place in the product where the content of a message you forwarded leaves our servers. It is also the reason forwarding is opt-in: you should be able to read that sentence and decide.
We reply to the address you forwarded from
After each forward we send you one short email saying what happened. That reply never quotes the email you sent — it states only the fields we read out of it.
What we never do
- We never connect to your bank. Not now, not in a later version. It is a deliberate product decision, not a missing feature. Your own record is the only source of truth in this app.
- We never sell your data, and we never share it with anyone for their own marketing.
- We show no advertising, and we do not build advertising profiles.
- We do not track you across apps, sites or devices. There is no analytics or tracking software in the product.
- We never cancel a subscription for you, or act on your accounts with any service. The app reports; you act.
Where your data lives
Your account and your subscriptions are stored on a server we run in Falkenstein, Germany, in the European Union. The disk that holds the database is encrypted.
We take a nightly backup of the database. The backup is encrypted on our own machine before it leaves it, and the encrypted copy is stored with Backblaze B2 in the United States. Backblaze holds ciphertext it cannot read.
Some of the services we depend on are in the United States. Every one of them is named in the next section.
Who else touches it
These are the only companies that process your data on our behalf. Each of them does one job.
| Who | What they do | Where |
|---|---|---|
| Hetzner | Hosts the server your account and subscriptions live on. | Germany (EU) |
| Resend | Sends your sign-in codes and reminder emails, and receives the emails you forward. | United States company; mail is received in Ireland, and Resend's own account data and logs are held in the US. |
| Groq | Reads the text of an email you forwarded, to find the subscription in it. Zero data retention is switched on. | United States |
| Backblaze | Stores our encrypted nightly backups. | United States |
| Apple | Distributes the app and takes payment for the paid plan. Apple's own privacy policy governs what Apple does with a purchase. | Apple's own regions |
Where data reaches a processor in the United States, the transfer is covered by that processor's data processing agreement, which incorporates the European Commission's Standard Contractual Clauses. Groq's agreement is in place. Resend's is being signed, and no email from a member of the public is forwarded through the service until it is.
We do not use any other processor. If that changes, this list changes with it, and the change is dated at the bottom of this page.
How long we keep it
| What | How long |
|---|---|
| Your account and your subscriptions | Until you delete your account. |
| After you delete your account | Hidden immediately. Erased in full, including reminder logs, within 30 days. |
| The text of a forwarded email | 30 days, then deleted. |
| Attachments on a forwarded email | Never stored at all. |
| A forwarding address you renamed | The old name is remembered for 30 days, only so we can explain why mail to it stopped arriving. It never routes anything. |
| Encrypted backups | On a rolling schedule, so a deletion can take up to a further 30 days to disappear from every backup copy. |
The 30-day delay on account deletion is deliberate. It is what makes an accidental deletion survivable. From your side the account and the list are gone the moment you confirm.
Your rights
Depending on where you live, the law gives you rights over your personal data. We honour these for everyone, wherever you are.
- See it. Everything we hold about you is on your own screen: your email address, your phone number, your currency, your subscriptions, and any forwarded email waiting for review. There is nothing behind the app that you cannot see in it.
- Correct it. Every field is editable in the app. Fix it there and it is fixed everywhere.
- Delete it. Settings → Account → Delete account. It is immediate from your side and complete within 30 days.
- Get a copy. There is no export button yet. Write to us and we will send you your data in a machine-readable file. This is honest about where the product is: the button is coming, and the right does not wait for it.
- Object, or ask us to stop. Write to us. Switching email forwarding off in Settings stops that part immediately, on your own, without asking anyone.
- Complain. If you are in the European Union or the United Kingdom you may complain to your national data protection authority.
We answer requests within 30 days.
Children
Subscription Scout is not for children. You must be at least 16 to use it, or older if the law where you live sets a higher age for agreeing to this.
We do not knowingly collect data from anyone under that age. If you believe a child has given us data, write to us and we will delete it.
How we protect it
- Everything between your device and our server travels over TLS.
- The disk holding the database is encrypted, and so is every backup.
- The database enforces, row by row, that you can read and write your own rows and nobody else's. It is not a rule in the app that a clever client could get around — it is a rule in the database.
- We sign you in with a one-time code sent to your email. There is no password to be reused or leaked.
No system is perfect. If something happens that puts your data at risk, we will tell you, and we will tell the relevant authority where the law requires it.
Changes to this policy
If we change this policy we will change the effective date at the top and raise the version number. If a change matters — a new processor, a new kind of data, a new purpose — we will tell you in the app or by email before it takes effect.
We will not start using data we already hold for a new purpose without telling you first.
Contact
Tala Labs LLC, 971 US Highway 202N, Ste N, Branchburg, NJ 08876, United States.
For anything in this policy — a question, a request, a complaint — write to contact@talalabs.co.