Last updated: March 10, 2026
SubTracker ("we", "us", "our") takes your privacy seriously. This policy explains what data we collect, how we use it, who we share it with, and how you can control it. Plain English — no legal walls.
We do not sell your data. We do not use your compliance documents to train AI models.
SubTracker uses the following third-party providers. Each has its own privacy policy governing how they handle data:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and document storage |
| Vercel | Application hosting and edge delivery |
| Stripe | Payment processing and subscription management |
| Resend | Transactional emails (alerts and invitations) |
| Anthropic (Claude API) | AI-powered extraction of dates and fields from compliance documents |
| Sentry | Error monitoring and performance tracing |
You have the right to know what personal information we collect, request deletion of your data, and opt out of any sale of your data (we don't sell it, but the right exists). To exercise these rights, email privacy@subtracker.io.
You have the right to access, correct, or delete your personal data, object to processing, and request data portability. Our lawful basis for processing is contract performance (to deliver the service) and legitimate interests (to improve the platform). To submit a request, email privacy@subtracker.io. We respond within 30 days.
We use industry-standard security practices: TLS in transit, encrypted storage at rest, access controls, and regular security reviews. That said, no system is perfectly secure. If you discover a vulnerability, please report it to security@subtracker.io.
We'll notify you by email if we make material changes to this policy, at least 14 days in advance. The updated policy will always be at subtracker.io/privacy.
Privacy questions or requests: privacy@subtracker.io
General: hello@subtracker.io