Back to home

Privacy Policy

Effective date: August 15, 2026 · Last updated: August 15, 2026

Subzar ("Subzar," "we," "us," or "our") operates the Subzar application at subzar.com (the "Service"). This policy explains what information we collect, how we use it, what we store, and the choices you have — including how the optional Gmail connection works.

1.What Subzar Is

Subzar is a personal subscription manager. It helps you keep a list of your recurring subscriptions, highlights ones you may no longer use, shows what they cost you, and links you to the provider's own cancellation or plan-change page. Subzar never cancels, pauses, or changes a third-party subscription for you.

2.Information You Provide

Account information. Your email address and name, and a password that is stored only as a salted hash by our authentication provider. If you sign in with Google, we receive your email address and basic profile information from that sign-in.

Subscription information. Anything you enter or confirm about a subscription: service name, amount, currency, billing cycle, category, usage frequency, last-used date, renewal or trial dates, notes, cancellation links, and the status you set (active, cancelled, restored, downgraded).

Optional profile settings. Notification preferences, an optional phone number, and email addresses you save for your own reference.

3.Information Collected Automatically

When you use the Service, our hosting and database providers process standard technical information needed to deliver and secure the app — IP address, browser and device information, and request logs. We use this only to operate the Service, debug problems, and prevent abuse. Subzar does not use advertising trackers.

4.Google / Gmail Integration

Connecting Gmail is optional. The Service is fully usable without it. A Gmail connection is only created after you explicitly start it in Settings → Connected accounts and grant access on Google's own consent screen.

Scopes we request. Subzar requests exactly two Google scopes, and no others:

  • https://www.googleapis.com/auth/userinfo.email — to show which Gmail address is connected.
  • https://www.googleapis.com/auth/gmail.readonly — read-only access used to look for messages that may represent subscriptions, recurring charges, renewals, trials, price changes, or billing receipts.

Subzar cannot send, modify, or delete your email. The read-only scope does not permit it, and the Service contains no such functionality. Subzar never emails anyone on your behalf.

Scans are manual. A mailbox scan runs only when you press “Scan Gmail”. There are no automatic or background scans today.

What we store from Gmail. Message content is processed in memory during a scan; only the following derived fields are saved to your account, and only when present:

  • Service or merchant name
  • Amount and currency
  • Billing frequency
  • Next renewal date, trial flag, and trial end date
  • A cancellation URL for that service, where known
  • A confidence score for the detection
  • The sender address and limited subject information used as evidence
  • The date of the evidence message and how many messages matched

Subzar does not store full email bodies, message snippets, attachments, or Gmail message IDs.

Nothing is added automatically. Scan results are saved as pending findings and shown to you for review. A subscription is created only when you edit and confirm a finding. Dismissing a finding creates nothing.

How the connection is protected. Google authorization happens on Google's servers. Subzar's server exchanges the authorization code for a per-user connection credential held by the Lovable connector gateway; the reference to that credential is encrypted (AES-256-GCM) before it is stored, and it is only ever decrypted inside server-side code. Google tokens and connection credentials are never sent to, or stored in, your browser.

Disconnecting. Open Settings → Connected accounts and press “Disconnect”. Subzar revokes the connection at the gateway, deletes the stored encrypted connection reference, marks the inbox connection revoked, and deletes your pending Gmail findings. Subscriptions you already added — manually or from a confirmed finding — are kept, because they are now your own records.

Limited Use. Subzar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising or personalized advertising, we do not use it to train generalized AI models, and we do not allow humans to read it except where you explicitly ask us to for support, where required by law, or for security purposes.

5.How We Use Your Information

  • Operate the dashboard, spend and waste calculations, and review queue
  • Show renewal and free-trial reminders you have enabled
  • Present Gmail findings for your confirmation
  • Authenticate you and keep accounts secure
  • Respond to support requests and fix defects

We do not sell personal information, and we do not use your data for advertising or personalized advertising.

6.Service Providers We Use

These are the providers used by the current production implementation:

  • Supabase — authentication and database hosting for your account and subscription data.
  • Lovable — application hosting and the connector gateway that holds the per-user Google authorization.
  • Google — only if you choose to connect Gmail or sign in with Google.

Subzar does not currently process payments, and no payment processor receives your information today.

7.When We May Disclose Information

  • To the service providers listed above, to run the Service
  • To investigate or prevent security incidents, abuse, or fraud
  • Where required by law, regulation, or valid legal process
  • In connection with a merger, acquisition, or sale of assets, where legally permitted and subject to this policy

8.Retention and Deletion

We keep your account and subscription data for as long as your account exists. Pending Gmail findings are deleted when you dismiss them or when you disconnect Gmail. You can delete individual subscriptions at any time from the dashboard, and clear locally cached data from Settings.

To delete your account and the personal data associated with it, email hello@subzar.com from the address on your account with the subject “Delete my account”. We will confirm and remove your account, subscriptions, connected-inbox records, and findings, except for limited records we must retain for legal or security reasons.

9.Security

Data is encrypted in transit (HTTPS) and at rest by our database provider. Access to your rows is enforced at the database level so one user cannot read another user's data. Google connection credentials are additionally encrypted with an application key held only in the server environment. No system is perfectly secure, and we cannot guarantee absolute security.

10.Children's Privacy

Subzar is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has given us information, contact us and we will delete it.

11.International Users

Subzar is operated using cloud infrastructure that may process and store data in countries other than yours, including the United States. By using the Service you understand your information may be transferred to and processed in those countries under this policy.

12.Your Privacy Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent (for example, by disconnecting Gmail). Californian residents may opt out of the sale or sharing of personal information — we do not sell or share personal information. To exercise a right, email hello@subzar.com.

13.Changes to This Policy

We may update this policy as the Service changes. Material changes will be announced in-app or by email before they take effect, and the “last updated” date above will change.

14.Contact

Privacy questions and data requests: hello@subzar.com