← Back

Privacy & how SubTrace uses Gmail

What we ask for

When you sign in, Google shows a consent screen asking you to grant SubTrace the gmail.readonly scope — nothing more. This scope lets SubTrace read your messages but cannot send, delete, modify, or forward any email, and cannot touch other Google services (Drive, Calendar, Contacts, etc.).

What we actually read

When you click "Scan my inbox", SubTrace searches for messages that look like subscription billing emails — from ~100+ known subscription-service senders, or containing billing language like "renews on", "payment confirmation", or "your subscription". It reads the subject and body of only those matched messages to pull out a merchant name, amount, currency, billing frequency, and renewal date.

What we store

SubTrace stores only that extracted, structured data (merchant name, amount, currency, dates, category) in its database. It never stores the raw subject line, email body, or any other content of your messages. Your Google OAuth tokens are encrypted (AES-256-GCM) before being written to the database — see the README for the exact approach.

Cancellation links

Direct cancellation links come from a small, manually curated list we maintain. Services change their account pages over time, so these links are best-effort and may go stale — if one is broken, use the "report broken link" option on that subscription so we know to fix it.

Deleting your data

From the dashboard, "Delete my data" permanently removes every subscription and scan record SubTrace has stored for your account, and revokes the stored Gmail access token with Google. You can always sign in again later to reconnect.