[ Subcharge · Legal ]
Privacy
Policy
Effective date 25 September 2026
Overview
Subcharge is a subscription, bill, card, expense and budget tracker for iOS and Android. Starting with version 1.2.0, Subcharge requires an account so your subscriptions, bills, and reminders can sync across your devices. This Privacy Policy explains what we collect, where it is processed and stored, and the choices you have, including how your card details are encrypted so that even we can't read them.
Who we are
Subcharge is provided by Aier Labs. For privacy questions, contact us at subcharge@aierlabs.com.
Your account
Creating an account is required to use Subcharge. You can sign in with Google, Sign in with Apple, or a 6-digit one-time code sent to your email.
- Account information: your email address, display name, the identifier from your chosen sign-in provider, and a Subcharge user ID we assign to your account (for example, SCRG10001)
- Device information: platform (iOS or Android) and app version, used for account security, new-device sign-in alerts, and troubleshooting
Information you add to the app
Once signed in, Subcharge lets you enter information such as:
- Subscription and bill details: names, prices, billing cycles, renewal and due dates, trial dates, categories, notes, reminder preferences, and the account a subscription is paid from
- Expenses you log: merchant or payee, amount, currency, date, category, payment method, notes, tags, and any refund, split or transfer between accounts you record
- Budgets you set: the limit, its currency, the period and start day, and which categories, tags or merchants it covers
- Accounts you add to track where money sits: the name you give it, its type (such as bank, credit card, cash or wallet), the issuing bank or institution, an opening balance, and the last four digits if you enter them. Each card you save in the vault also appears as an account, carrying the card's nickname, bank and last four digits (see "Card vault and encryption")
- Categories you create yourself, including the name, icon and colour you choose
- Payment card details you choose to save in the vault, including card name, cardholder name, card number, expiration date, CVV, bank name, card network, billing date, due date, and notes
- Documents you attach to insurance and warranty entries: photos or PDFs. Like your card details, these are end-to-end encrypted on your device before they are stored, so we cannot read them (see "Card vault and encryption")
- App preferences such as currency, exchange-rate settings, theme, onboarding status, and display name
This information is stored on our servers so it can sync across your devices. Card numbers and CVVs are handled differently from everything else you enter; see "Card vault and encryption" below.
Analytics
We use Mixpanel to understand how Subcharge is used and to improve it. When you have an account, your email address, name and Subcharge user ID are associated with your analytics profile so we can provide support and measure product usage across your devices. Our servers also add your plan status to that profile, such as whether you are on Free, on a free trial, or on Pro.
What Mixpanel receives:
- Usage events: the screens you open and the features you use, plus the app-open and session events Mixpanel's SDK records automatically
- Standard technical details Mixpanel's SDK adds to every event, such as operating system and version, device model, and app version
- Approximate location: Mixpanel derives your country and city from the IP address an event is sent from. We do not use your device's location services and never ask for location permission
- Crash and error reports: when the app hits an error it cannot recover from, it sends an error event with the error message, after removing email addresses and long runs of digits from it. These reports are linked to your account so we can find and fix what went wrong
- Sync diagnostics, such as how many records of a given type could not be read during a sync
We never send financial details (amounts, balances, card numbers, or card security codes), merchant names, or what you type into search to Mixpanel or any analytics provider. We do not use this data for advertising and do not sell it.
Advertising and attribution
Subcharge does not show ads inside the app. We do run ads to promote Subcharge on Meta's platforms (Facebook and Instagram), and we include Meta's mobile SDK so we can measure how many installs, sign-ups and subscriptions those campaigns produce.
Advertising-identifier collection is turned off, so Subcharge does not read your device advertising ID (the IDFA on iOS, the advertising ID on Android) and does not show the App Tracking Transparency prompt. On iOS, install measurement also uses Apple's SKAdNetwork, which reports campaign results to us in aggregate. We do not send Meta your name, email address or Subcharge user ID.
What Meta's SDK sends to Meta:
- Install and app-open (session) events, which the SDK logs automatically
- Three events we send ourselves: when you create an account (with the sign-in method you used), when you start a free trial of Subcharge Pro, and when you subscribe to Subcharge Pro (with the plan and its billing period, but no price)
- On iOS, the SDK also logs Subcharge Pro purchases made through the App Store automatically, and these events can include the price and currency of that purchase
Meta never receives your subscriptions, bills, expenses, budgets, accounts, card details, or documents. Meta handles the events it receives under its own privacy policy.
We do not use this to track you across other companies' apps and websites, and we do not sell your data.
How your data is stored and synced
Subcharge runs on Cloudflare's infrastructure. Your subscriptions, bills, payment history, expenses, budgets, accounts, categories you create, detected items, and settings are stored in a Cloudflare D1 database tied to your account, which is how they stay in sync across your devices.
- We do not sell your personal information.
- We do not show ads inside Subcharge. We include Meta's mobile SDK only to measure installs, sign-ups and subscriptions from ad campaigns we run, configured without your device advertising identifier; see "Advertising and attribution" above.
- If you delete your account, this data is permanently removed; see "Data retention and deletion" below.
Card vault and encryption
Sensitive card data, your full card number and CVV, is encrypted on your device before it ever leaves it, using AES-256-GCM under an Account Data Key. That key is generated on your device, stored only in your device's keychain or keystore, and is never sent to our servers.
The Account Data Key is protected by a 12-word recovery phrase, which you save when you set up the vault. That phrase is what lets you restore your encrypted cards on a new device; we do not keep a copy of it.
- Only the resulting ciphertext (your encrypted card number and CVV) is stored, in Cloudflare R2. Our servers and staff cannot read your card number or CVV.
- Documents you attach to insurance and warranty entries are protected the same way: each file is encrypted on your device with AES-256-GCM under your Account Data Key and stored only as ciphertext in Cloudflare R2. Our servers and staff cannot read them.
- Non-secret card metadata (last 4 digits, bank name, card nickname, card network, and billing dates) is not end-to-end encrypted and syncs through Cloudflare D1 like your other tracked data. Since version 1.8.0 each saved card is paired with an account you can pay from, and that account carries the card's nickname, bank and last 4 digits in the same readable form.
- If you lose your recovery phrase, we cannot recover it, and your saved cards cannot be restored on a new device. This is by design: it's what keeps your card number and CVV unreadable to us.
Smart Detection
Smart Detection can find recurring payments for you. Where it looks, and how, depends on the source:
- SMS messages (Android only): with your explicit permission, Subcharge reads financial and transactional SMS on your device to detect recurring payments. This scanning happens entirely on your device; your SMS content is never uploaded. Only the detected result (for example, merchant, amount, and billing frequency) syncs to your account.
- Pasted receipts: text you paste into the app from a payment or renewal email is parsed on your device. The text you paste is not uploaded; only the detected result syncs to your account.
- Photos and files you import: screenshots, photos and files you choose to import are read on your device. They are not uploaded; only the detected result syncs to your account.
- Forwarded emails (new in 1.2.0): you can forward a receipt to a private address unique to your account (u_<yourtoken>@in.subcharge.aierlabs.com). Unlike SMS and pasted receipts, forwarded emails are received and parsed on our Cloudflare servers, not on your device. We extract and store only the derived subscription or bill details; we do not store the full email body. This feature is opt-in: nothing is forwarded unless you choose to send it.
Nothing detected through Smart Detection is added to your tracked subscriptions or bills unless you review it and choose to add it.
Notifications
If you enable reminders, Subcharge requests notification permission and schedules renewal or trial reminders. If Smart Detection is enabled, Subcharge may also show a summary notification when new recurring payments are detected, so you can review them.
You can disable notifications in your device settings.
Emails we send
We send account-related emails from subcharge@aierlabs.com to the address on your account, including:
- A welcome email when you create your account
- A security alert when your account is signed in from a new device
- A reminder before a free trial of Subcharge Pro ends
- A download link when you ask for a copy of your data
- A confirmation when you delete your account
- Reminders about upcoming charges
- A monthly summary of your subscription and bill spending
Feedback and support
When you send feedback or a feature request from inside the app, we receive your message, the topic you picked, the reply address you give (if any), and your account email and Subcharge user ID, so we can follow up. It reaches our team as an email to subcharge@aierlabs.com. Emails you send us directly are handled the same way. We use these messages only to answer you and to improve Subcharge.
Device authentication
Subcharge may use your device passcode or biometric authentication to reveal vault details. Biometric authentication is handled by your device operating system. Subcharge does not receive or store your fingerprint, face, or biometric template.
Subprocessors
We use the following service providers to run Subcharge:
- Cloudflare: hosting and compute, our D1 database and R2 storage, Email Routing for forwarded-email detection, and sending transactional email
- Mixpanel: product analytics, including approximate location derived from IP address, and crash and error reports
- RevenueCat: in-app purchase processing and subscription status. RevenueCat holds your Subcharge Pro purchase history under your Subcharge user ID and tells our servers whether your Pro subscription is active
- Apple and Google: sign-in (Sign in with Apple, Sign in with Google), in-app purchases and billing, and the store APIs we use to validate your Pro subscription
- Meta Platforms: its mobile SDK measures installs, sign-ups and subscriptions from the advertising campaigns we run, configured without device advertising identifiers (no IDFA) and using Apple's SKAdNetwork on iOS; see "Advertising and attribution"
We also make requests to the Frankfurter API for currency exchange rates and to a logo service to load public brand logos for subscription names. These requests may reveal technical details such as your IP address or the requested logo domain to those services.
Subscriptions and payments
Subcharge Pro is an auto-renewable subscription sold through the Apple App Store and Google Play. Apple and Google handle all payment and store your payment method; Subcharge never sees your card details for a Pro purchase.
Purchases are processed through RevenueCat, which receives the store's record of your purchase and links it to your Subcharge user ID. We also validate your purchase with Apple's App Store Server API and the Google Play Developer API to determine your Pro entitlement and its expiry. This is separate from the card vault, which is for your own reference and is never used to process a payment.
Data sharing
We do not sell your personal information or share it with data brokers. Your data may still be handled by:
- The subprocessors listed above, to provide the app
- Meta, which receives install, app-open, sign-up, trial and subscription events for the campaigns we run to promote Subcharge (on iOS including the price and currency of a Subcharge Pro purchase), without your device advertising identifier; see "Advertising and attribution"
- Your device operating system and backup settings
- Legal authorities, if required by applicable law
Data retention and deletion
We retain your account data for as long as your account is active. You can delete your account at any time inside the app: go to More, then Profile, then Danger zone, and choose Delete your account. If you cannot open the app, email subcharge@aierlabs.com from the address on your account, or include your account email or member ID (for example, SCRG10001), and we will delete it for you. Step-by-step instructions are at subcharge.aierlabs.com/delete-account.
Deletion permanently removes your account and everything tied to it from our Cloudflare D1 database (subscriptions, payment history, expenses, budgets, accounts, categories, card metadata, detected items, settings, sessions, devices and entitlement records), your encrypted card vault and attached documents from Cloudflare R2, any data exports you requested, and your forwarded-email address, and you'll receive a confirmation email. This cannot be undone.
Deleting your account does not cancel a Subcharge Pro subscription; cancel it in the App Store or Google Play. Some records are held outside our database and are not removed by deletion: the purchase records Apple, Google and RevenueCat keep for a Pro purchase, analytics events already sent to Mixpanel under your Subcharge user ID, events already sent to Meta, feedback and support emails in our mailbox, and backups in your own iCloud or Google Drive, which you control (deleting in the app erases the data on that phone and turns automatic backup off, but does not remove a backup already saved there). To ask for any of these to be removed as well, contact subcharge@aierlabs.com.
You can download a copy of your data at any time from More, then Profile, under Personal data and privacy. The download link we email you expires after 7 days. To ask for it another way, contact subcharge@aierlabs.com.
Security
We use industry-standard practices to protect your data, including the on-device encryption for card secrets described above and access controls on our servers. No method of storage or transmission is completely secure, so you should use a secure device passcode, keep your device and app updated, and keep your recovery phrase somewhere safe.
Your choices
You can:
- Add, edit, archive, or delete subscription, bill, and card records in the app
- Turn Smart Detection on or off, and enable or disable SMS, pasted-receipt, or forwarded-email sources individually
- Revoke SMS or notification permission at any time in your device settings
- Change app preferences such as currency and theme
- Download a copy of your data from More, then Profile
- Delete your account at any time from More, then Profile, then Danger zone, which removes your data as described above
Children
Subcharge is not intended for children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy as Subcharge changes. If we make material changes, we will update the effective date and make the updated policy available.
Contact
For questions about this Privacy Policy, contact: subcharge@aierlabs.com.