Privacy & how SubTrace uses Gmail
What we ask for
When you sign in, Google shows a consent screen asking you to grant SubTrace the gmail.readonly scope — nothing more. This scope lets SubTrace read your messages but cannot send, delete, modify, or forward any email, and cannot touch other Google services (Drive, Calendar, Contacts, etc.).
What we actually read
When you click "Scan my inbox", SubTrace searches for messages that look like subscription billing emails — from ~100+ known subscription-service senders, or containing billing language like "renews on", "payment confirmation", or "your subscription". It reads the subject and body of only those matched messages to pull out a merchant name, amount, currency, billing frequency, and renewal date.
What we store
SubTrace stores only that extracted, structured data (merchant name, amount, currency, dates, category) in its database. It never stores the raw subject line, email body, or any other content of your messages. Your Google OAuth tokens are encrypted (AES-256-GCM) before being written to the database — see the README for the exact approach.
Cancellation links
Direct cancellation links come from a small, manually curated list we maintain. Services change their account pages over time, so these links are best-effort and may go stale — if one is broken, use the "report broken link" option on that subscription so we know to fix it.
Deleting your data
From the dashboard, "Delete my data" permanently removes every subscription and scan record SubTrace has stored for your account, and revokes the stored Gmail access token with Google. You can always sign in again later to reconnect.