Privacy & Data Handling

Privacy at PaySubscriptions

What we store, which outside services are involved, and how you can delete your account or ask for a copy of your data — in plain language.

What we store

Your account holds your email address, your password stored as a one-way hash (never in readable form), and the settings you choose: main currency, account time zone, and reminder preferences. Your subscriptions hold what you enter yourself: name, billing cycle, amounts and currencies, next payment date, expense category, and any optional note.

PaySubscriptions never connects to your bank, never scans your inbox, and never discovers subscriptions automatically. Everything in your account is there because you typed it in, and removing an entry here does not cancel anything with its provider.

Your data is not for sale

Account and Subscription data is not sold.

Running the service necessarily involves a small number of external services, listed in the next section. Each of them receives only the data it needs to do its job — account and subscription records are never handed to advertisers, data brokers, or analytics profiles.

External services and what each receives

Every automatic request on the web discloses the visitor's IP address, browser information, and the visited page address to the host serving it. Beyond that baseline, each service below receives only what is listed:

  • Umami Cloud analytics (cloud.umami.is). Cookieless page-view counts on every page. Receives the page address, the referring page, and device and browser metadata. It does not receive your account or subscription details.
  • Google Fonts. Provides the interface typefaces loaded on every page. Receives font file requests tied to the visited page.
  • Font Awesome stylesheet via the Cloudflare CDN (cdnjs.cloudflare.com). Provides the icons used across the site. Receives stylesheet requests tied to the visited page.
  • Google reCAPTCHA, on the contact page only. Spam protection for the contact form. Google receives risk-analysis signals when the form is shown; when you submit, our server sends Google the one-time token and your IP address for verification. Your name, email address, subject, and message are never sent to Google.
  • Mail delivery. Account emails — registration verification, password resets, and contact-form messages to the maintainer — are sent through the configured mail provider (an SES-compatible service in production). Those emails contain the recipient and sender addresses, the subject, and the message body by design, and carry no tracking pixels or externally hosted content.
  • Product-updates newsletter via the shared gprodb.com list. A separate opt-in (see below): only the subscriber's email address is forwarded to the external mailing provider, together with the mailing project identifier and routing key.
  • BuyMeACoffee support link, on the pricing page only. A plain link you can choose to follow. Nothing is sent there unless you click it.

How your data is stored

Your account and subscription records live in the application's database so you can reach them through a browser. There is no application-level field encryption at rest: names, amounts, notes, and your email address are stored as plain database columns. Only your password gets stronger treatment — it is stored as a one-way hash and cannot be read back.

We describe this plainly on purpose: the protection your data has is access control on the account and the servers, not per-field encryption.

Deleting your account

You can delete your account yourself at any time from the account deletion page. Deletion permanently removes your profile and login, your subscriptions and categories, your subscription limits, pending password-reset requests, and your reminder preferences, and it discards queued account emails waiting to be sent. It takes effect immediately and cannot be undone.

The product-updates newsletter is a separate opt-in handled through our shared gprodb.com list. Deleting your account does not unsubscribe that list — please unsubscribe there separately if you no longer want those emails.

Getting a copy of your data

A copy of your data is available as a manual email request — there is no self-service download. Send the contact form from your account email address with the subject “Data export request”. The maintainer checks that the sender address matches the account, then replies to that same address with your account profile, subscriptions with their categories, expense categories, and limits as a JSON file. Password hashes are never included, and the newsletter list is separate and is never included.

If you are planning to delete your account, ask for the copy first so nothing is lost.

The newsletter is a separate opt-in

The product-updates signup in the footer is an optional, separate opt-in to the shared gprodb.com newsletter list, run by an external mailing provider. Creating an account never subscribes you, deleting your account never unsubscribes you, and asking for a data export never touches the list. To stop those emails, unsubscribe through the newsletter list itself — deleting your PaySubscriptions account will not do it.

Questions

Anything unclear about how your data is handled? Contact the maintainer.