Privacy Policy
Last updated: 12 August 2026
Subby is built so that your subscription list stays on your phone. This policy explains the few things that do leave it, why, and what control you have.
It replaces an earlier version which said your data never leaves your device unless you back it up. That is no longer accurate: Subby now offers an optional AI screenshot import, shows ads on the free plan, reports crashes, and measures which adverts brought people to the app. This document describes what the app actually does today.
Who we are
POCKET IMPLEMENTATION S.R.L., a Romanian limited liability company with its registered office at Aleea Giurgeni, Sector 3, Bucharest, Romania, is the data controller responsible for the processing described here.
Email: support@subby.online
What stays on your device
Everything you type into Subby — your subscriptions, prices, payment dates, categories, payment methods, notes, reminders and payment history — is stored in a database on your device. We never receive it. There is no Subby account, no login, and no server-side copy of your subscription list.
Reminders are scheduled locally by your phone. Subby does not use push notifications, so no server knows when or what you are reminded about.
What leaves your device
AI screenshot import (PRO, optional)
If you choose to import subscriptions from a screenshot, that image is resized on your device and sent over an encrypted connection to our server at api.subby.online, which forwards it to OpenAI to extract the subscription details. The extracted text comes back to your app for you to review before anything is saved.
- This only happens when you actively pick an image. Subby never scans your photo library.
- Our application code does not write the image to disk; it is held only for the seconds the request takes and discarded when the response is returned.
- We tell OpenAI not to store the request, and your image is never used to train models. OpenAI may still hold it briefly for abuse monitoring before deleting it.
- Legal basis: performance of the service you asked for (Art. 6(1)(b) GDPR).
Because a screenshot may contain more than subscriptions, only send images you are comfortable sharing.
Ads (free plan only)
The free plan shows ads served by Google AdMob. Depending on the choice you make in Settings → Privacy & Ads (and, on iOS, the App Tracking Transparency prompt), these are personalised or non-personalised. Personalised ads involve Google using an advertising identifier from your device, and for that purpose Google acts as an independent controller under its own privacy policy.
You can turn ads off entirely by buying PRO. PRO users see no ads and no advertising identifier is used.
Legal basis: your consent, which you can change at any time in Settings → Privacy & Ads.
Install attribution and ad measurement
To understand which adverts bring people to Subby, the app reports a small number of events to two advertising platforms.
Meta (both Android and iOS). We use Meta App Events to report: app opened, purchase completed, subscription started, free trial started, and first-run setup completed. Each event carries the amount and currency where relevant, plus a Meta-generated anonymous device identifier and — only where you have allowed it — your device's advertising identifier. On iOS we also use Apple's SKAdNetwork, which gives Meta an aggregated, privacy-preserving install measurement without identifying you.
TikTok (Android only). TikTok App Events reports the same conversion moments — purchase, subscription, trial start, registration — plus install, app launch and a two-day retention signal that the SDK sends by itself. It is not present in the iOS app at all.
Nothing starts until consent is resolved. Both SDKs ship inert. They are only started after the Google consent flow returns a usable answer; if it has not resolved, or you refused, they stay off — and an unresolved state is treated as "no", never as permission. On iOS your advertising identifier is attached only if you allowed tracking at the App Tracking Transparency prompt. Where US state privacy laws apply we start both SDKs in their Limited Data Use mode.
You can turn this off at any time in Settings ▸ Privacy, independently of your ads choice, and it stays off — the setting follows you to a new device.
For people in the EEA, the UK and Switzerland, Meta Platforms Ireland Limited acts as an independent controller of the data it receives under its own privacy policy, and TikTok Technology Limited together with TikTok Information Technologies UK Limited act as joint controllers with us for the measurement data TikTok receives.
Legal basis: your consent, which you can withdraw at any time using the setting above.
Analytics and crash reports
Subby uses Firebase Analytics and Firebase Crashlytics (Google) to count screen views and feature usage and to receive crash diagnostics. These are tied to a randomly generated app instance identifier, not to your name or email.
Anti-abuse
Requests to our AI import endpoint carry a Firebase App Check token (Play Integrity on Android, App Attest or DeviceCheck on iOS). It proves the request came from a genuine copy of Subby and is not linked to you.
Purchases
RevenueCat processes your PRO entitlement on our behalf and issues an anonymous purchase identifier. Neither RevenueCat nor we ever see your card details — the Apple App Store and Google Play handle payment.
Icon requests (PRO, optional)
If you ask us to add a service icon, we receive the service name and website you typed, plus your IP address for rate-limiting. These records are deleted after about 90 days.
Currency rates
The app downloads exchange rates once a day. This request contains no information about you or your subscriptions.
The subby.online website
This policy covers the Subby apps and the subby.online website. The site behaves differently from the app, so here is what it does.
Analytics only if you accept. The website uses Google Analytics 4 with Google's Consent Mode v2. Everything starts denied: no analytics cookies are set, and Google's analytics script is not even loaded, until you accept the cookie banner. If you decline, everything stays denied — Google may still receive a cookieless, non-identifying ping, which is how Consent Mode is designed to work, and it cannot be tied to you.
Two things we keep in your browser. Your consent choice is stored in your browser's localStorage under subby_consent for up to 180 days, after which the banner asks again. Your light or dark theme preference is stored the same way under subby-theme. Both are functional preferences that stay in your browser — they are not tracking, and clearing your site data removes them.
The cost calculator runs entirely in your browser. The amounts and service names you type are never transmitted, to us or to anyone else. If you accepted analytics, we record only coarse usage buckets — roughly how many rows you filled in, and which band the annual total fell into — never a name and never an amount.
Store links carry campaign parameters. The App Store and Google Play buttons append a campaign tag (a Google Play install referrer, an Apple campaign token) so the stores can tell us which page an install came from. That measurement happens store-side, in your store account; it is not a website cookie and it does not identify you.
Backups go to your own cloud
Google Drive and iCloud backups are written directly from your device to your own storage — Drive's private app folder, or your iCloud container. They do not pass through our servers and we cannot read them. Deleting them is done from your Google or Apple account. Local backups stay on your device.
International transfers
OpenAI, Google (Firebase, AdMob, Drive), Apple, RevenueCat, Meta and TikTok are based in, or process data in, the United States and other countries outside the EEA. Transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as set out in each provider's own terms.
How long we keep things
We hold almost nothing. Icon requests are deleted after about 90 days. We do not store screenshots. Analytics and crash data follow Firebase's own retention periods. Your subscription data lives on your device for as long as you keep the app — uninstalling deletes it.
Your rights
Under the GDPR you can request access to, correction of, deletion of, or restriction of your personal data, and object to processing.
Being honest about what this means here: there is no account, so we never learn your name or email unless you write to us. Most of what we hold is keyed to pseudonymous identifiers rather than to you. If you want to exercise a right, the identifiers you can actually give us are:
- your Support ID (Settings → About), which is the anonymous purchase identifier; and
- the Firebase app instance identifier, which resets if you reinstall.
Email support@subby.online with one of those and we will do what we can. You can also delete most data yourself: uninstalling removes everything local, changing your ad choice in Settings stops personalised advertising, turning off attribution in Settings ▸ Privacy stops the Meta and TikTok events, and backups are deleted from your own Google or Apple account.
You have the right to complain to a supervisory authority — in Romania, the ANSPDCP (dataprotection.ro), or the authority where you live.
Children
Subby is not directed at children and we do not knowingly collect data from anyone under 16.
Changes
We may update this policy; the current version is always in the app and at subby.online. If a change is material we will say so in the app.
Contact
support@subby.online — POCKET IMPLEMENTATION S.R.L., Romania.