[ Subcharge · Legal ]

Privacy
Policy

Effective date 29 July 2026

01

Overview

Subcharge is a subscription, bill, and card tracker for iOS and Android. Starting with version 1.2.0, Subcharge requires an account so your subscriptions, bills, and reminders can sync across your devices. This Privacy Policy explains what we collect, where it is processed and stored, and the choices you have — including how your card details are encrypted so that even we can't read them.

02

Who we are

Subcharge is provided by Aier Labs. For privacy questions, contact us at subcharge@aierlabs.com.

03

Your account

Creating an account is required to use Subcharge. You can sign in with Google, Sign in with Apple, or a 6-digit one-time code sent to your email.

  • Account information: your email address, display name, the identifier from your chosen sign-in provider, and a Subcharge user ID we assign to your account (for example, SCRG10001)
  • Device information: platform (iOS or Android), device model, and app version, used for account security, new-device sign-in alerts, and troubleshooting
04

Information you add to the app

Once signed in, Subcharge lets you enter information such as:

  • Subscription and bill details: names, prices, billing cycles, renewal and due dates, trial dates, categories, notes, and reminder preferences
  • Payment card details you choose to save in the vault, including card name, cardholder name, card number, expiration date, CVV, bank name, card network, billing date, due date, and notes
  • App preferences such as currency, exchange-rate settings, theme, onboarding status, and display name

This information is stored on our servers so it can sync across your devices. Card numbers and CVVs are handled differently from everything else you enter — see "Card vault and encryption" below.

05

Analytics

We use Mixpanel to understand how Subcharge is used and to improve it. When you have an account, your email address and name are associated with your analytics profile so we can provide support and measure product usage across your devices. We never send financial details — amounts, balances, card numbers, or card security codes — to Mixpanel or any analytics provider. We do not use this data for advertising and do not sell it.

06

How your data is stored and synced

Subcharge runs on Cloudflare's infrastructure. Your subscriptions, bills, payment history, detected items, and settings are stored in a Cloudflare D1 database tied to your account, which is how they stay in sync across your devices.

  • We do not sell your personal information.
  • We do not run ads or use advertising SDKs.
  • If you delete your account, this data is permanently removed — see "Data retention and deletion" below.
07

Card vault and encryption

Sensitive card data — your full card number and CVV — is encrypted on your device before it ever leaves it, using AES-256-GCM under an Account Data Key. That key is generated on your device, stored only in your device's keychain or keystore, and is never sent to our servers.

The Account Data Key is protected by a 12-word recovery phrase, which you save when you set up the vault. That phrase is what lets you restore your encrypted cards on a new device — we do not keep a copy of it.

  • Only the resulting ciphertext (your encrypted card number and CVV) is stored, in Cloudflare R2. Our servers and staff cannot read your card number or CVV.
  • Non-secret card metadata — last 4 digits, bank name, card network, and billing dates — is not end-to-end encrypted and syncs through Cloudflare D1 like your other tracked data.
  • If you lose your recovery phrase, we cannot recover it, and your saved cards cannot be restored on a new device. This is by design — it's what keeps your card number and CVV unreadable to us.
08

Smart Detection

Smart Detection can find recurring payments for you. Where it looks, and how, depends on the source:

  • SMS messages (Android only): with your explicit permission, Subcharge reads financial and transactional SMS on your device to detect recurring payments. This scanning happens entirely on your device — your SMS content is never uploaded. Only the detected result (for example, merchant, amount, and billing frequency) syncs to your account.
  • Pasted receipts: text you paste into the app from a payment or renewal email is parsed on your device. The text you paste is not uploaded; only the detected result syncs to your account.
  • Forwarded emails (new in 1.2.0): you can forward a receipt to a private address unique to your account (u_<yourtoken>@in.subcharge.aierlabs.com). Unlike SMS and pasted receipts, forwarded emails are received and parsed on our Cloudflare servers, not on your device. We extract and store only the derived subscription or bill details — we do not store the full email body. This feature is opt-in: nothing is forwarded unless you choose to send it.

Nothing detected through Smart Detection is added to your tracked subscriptions or bills unless you review it and choose to add it.

09

Notifications

If you enable reminders, Subcharge requests notification permission and schedules renewal or trial reminders. If Smart Detection is enabled, Subcharge may also show a summary notification when new recurring payments are detected, so you can review them.

You can disable notifications in your device settings.

10

Emails we send

We send account-related emails from subcharge@aierlabs.com to the address on your account, including:

  • A welcome email when you create your account
  • A security alert when your account is signed in from a new device
  • A confirmation when you delete your account
  • Reminders about upcoming charges
  • A monthly summary of your subscription and bill spending
11

Device authentication

Subcharge may use your device passcode or biometric authentication to reveal vault details. Biometric authentication is handled by your device operating system. Subcharge does not receive or store your fingerprint, face, or biometric template.

12

Subprocessors

We use the following service providers to run Subcharge:

  • Cloudflare — hosting and compute, our D1 database and R2 storage, Email Routing for forwarded-email detection, and sending transactional email
  • Mixpanel — product analytics
  • Apple and Google — sign-in (Sign in with Apple, Sign in with Google), in-app purchases and billing, and the store APIs we use to validate your Pro subscription

We also make requests to the Frankfurter API for currency exchange rates and to a logo service to load public brand logos for subscription names. These requests may reveal technical details such as your IP address or the requested logo domain to those services.

13

Subscriptions and payments

Subcharge Pro is an auto-renewable subscription sold through the Apple App Store and Google Play. Apple and Google handle all payment and store your payment method — Subcharge never sees your card details for a Pro purchase.

We validate your purchase with Apple's App Store Server API and the Google Play Developer API to determine your Pro entitlement and its expiry. This is separate from the card vault, which is for your own reference and is never used to process a payment.

14

Data sharing

We do not sell your data or share it with advertisers or data brokers. Your data may still be handled by:

  • The subprocessors listed above, to provide the app
  • Your device operating system and backup settings
  • Legal authorities, if required by applicable law
15

Data retention and deletion

We retain your account data for as long as your account is active. You can delete your account at any time from within the app.

Deleting your account permanently removes your data from our Cloudflare D1 database, your encrypted card vault from Cloudflare R2, and your forwarded-email address, and you'll receive a confirmation email. This cannot be undone.

To request a copy of your data, or to ask us to delete it outside the app, contact subcharge@aierlabs.com.

16

Security

We use industry-standard practices to protect your data, including the on-device encryption for card secrets described above and access controls on our servers. No method of storage or transmission is completely secure, so you should use a secure device passcode, keep your device and app updated, and keep your recovery phrase somewhere safe.

17

Your choices

You can:

  • Add, edit, archive, or delete subscription, bill, and card records in the app
  • Turn Smart Detection on or off, and enable or disable SMS, pasted-receipt, or forwarded-email sources individually
  • Revoke SMS or notification permission at any time in your device settings
  • Change app preferences such as currency and theme
  • Delete your account at any time, which removes your data as described above
18

Children

Subcharge is not intended for children under 13. We do not knowingly collect personal information from children.

19

Changes to this policy

We may update this Privacy Policy as Subcharge changes. If we make material changes, we will update the effective date and make the updated policy available.

20

Contact

For questions about this Privacy Policy, contact: subcharge@aierlabs.com.