Privacy Policy
Last updated: July 31, 2026 · Effective: July 31, 2026
SubTap is built privacy-first. We never ask for bank or card credentials, and your subscription data lives on your device by default. This policy explains what we collect, why, and what rights you have.
Who we are
SubTap is a subscription tracking mobile application operated by Allie Ltd ("SubTap", "we", "us", or "our"), a company registered in the Republic of Cyprus.
- Company: Allie Ltd
- Registration No.: HE 460424
- VAT No.: 60076104S
- Registered address: Emmanouil Roidi 44, Kirzis Center, 3031, Limassol, Cyprus
- Contact: support@subtapapp.com
By using SubTap, you agree to the collection and use of information as described in this policy. If you don't agree, please don't use the app.
What we collect
A lightweight account (Email, Google, or Apple sign-in) is required to use SubTap — it enables encrypted sync, renewal reminders, and the AI assistant. Creating this account never involves linking a bank account, card, or any financial institution. Where a password is used, it's stored hashed and never visible to us in plain text.
We also collect:
- Subscription entries you add manually — service name, cost, billing cycle, renewal date, category, notes.
- Messages you send to the AI assistant, and the subscription context needed to answer them (see "AI assistant" below).
- Purchase receipts and access status, handled by Adapty and the app stores — we never see your card details.
- Basic device data (model, OS version, app version, crash and performance reports) needed to run and fix the app, processed by Firebase Crashlytics.
- A push notification token, only after you grant permission, used for renewal reminders.
- Anonymous product-usage events, which you can switch off at any time (see "Product analytics" below).
- Your device's advertising identifier, used only to measure which marketing channel led to your install (see "Install attribution" below).
We run no ad networks and show no ads. We never sell your data or share it with data brokers, and we never build advertising profiles or run ad targeting from anything we collect. On iOS, the app asks for Apple's App Tracking Transparency permission to measure install attribution — see "Install attribution" below for exactly what that covers and what it doesn't. Product analytics (see "Product analytics" below) is entirely separate from this and never uses your advertising identifier, regardless of your tracking answer.
Your subscription data
Subscriptions you add are stored locally on your device and, once you're signed in, synced in encrypted form to your account so they're available across your devices. You remain the source of truth — nothing is ever pulled automatically from a bank or payment provider.
AI assistant
Who receives your data. The AI assistant is powered by OpenAI. Requests reach it through OpenRouter, an AI infrastructure provider that routes the request to OpenAI on our behalf. Those two companies are the only third parties involved in the assistant.
We ask first. Before your very first message is ever sent, the app shows a confirmation dialog that names both OpenAI and OpenRouter and lists exactly what will be sent. Nothing leaves your device for either provider until you tap Continue. You can decline and keep using every other part of the app exactly the same.
What we send. When you send a message, we forward to OpenRouter — which passes it to OpenAI — only:
- the text of the message you typed;
- your currency, time zone, and today's date, so amounts and dates make sense;
- the subscription details needed to answer: service names, prices, billing cycles, renewal and trial dates, categories, status, and how often you use each one.
What we never send. Your name, email address, sign-in identifiers, device identifiers, payment methods, and the free-text notes you keep on your subscriptions are never transmitted to OpenAI or OpenRouter. Our servers strip everything outside the list above before the request leaves our infrastructure.
Retention and protection. Under our data processing agreements, both OpenRouter and OpenAI are contractually bound to protections equivalent to those in this policy, and your messages are not used to train models. OpenAI may briefly retain API request data for abuse monitoring — see openai.com/enterprise-privacy; OpenRouter's handling is described at openrouter.ai/privacy. We don't store the content of your conversations on our servers — we keep only a count of how many times the assistant was used, for rate limiting.
Withdrawing permission. Signing out clears your confirmation, so the dialog appears again (and can be declined) next time. You can also email support@subtapapp.com to withdraw it. Either way, the rest of the app is unaffected.
Product analytics
On by default, off in one tap. SubTap sends anonymous product-usage events to Amplitude, our analytics provider, to show us which features people actually use. The switch lives in Settings › Privacy; turning it off stops collection immediately and discards the identifier the events were keyed on, and changes nothing else about the app.
What an event contains: the action itself (a screen opened, a subscription added, the assistant used), plus low-detail attributes such as a subscription's category, billing cycle and currency code, your app version, OS version, device model and language. Amplitude also automatically attaches its standard technical metadata to every event: an approximate, IP-derived location (country/region/city) and mobile carrier, and — depending on platform — a vendor-scoped device identifier (iOS) or your device's advertising identifier (Android). This is Amplitude's default behavior for every app that uses it, not something SubTap adds on top.
What it never contains: your email address or name, subscription names, any amount or price, your notes, your assistant messages, or your account identifier. Events are keyed on an identifier Amplitude generates for this app install — never your account identifier and never your device's advertising identifier. Even though SubTap does request Apple's App Tracking Transparency permission (see "Install attribution" below), that permission and the resulting identifier are used only by our attribution provider, AppsFlyer — Amplitude never receives it, and product-analytics events are never linked to your SubTap account or used to track you across other apps or websites.
Where it goes. Analytics events are processed by Amplitude in the United States. Because that's outside the EU/EEA, we rely on European Commission–approved Standard Contractual Clauses for the transfer — see "Data retention & international transfers" below. Amplitude is bound by a data processing agreement, does not use your data for advertising, and is not permitted to sell it. Our legal basis is our legitimate interest in understanding and improving how SubTap is used (GDPR Art. 6(1)(f)) — you can object at any time by switching it off in Settings › Privacy.
Install attribution
What this is for. We use AppsFlyer to measure which marketing channel (for example, a specific ad or referral link) led to someone installing SubTap. This tells us whether our marketing spend is working — it does not personalize your experience inside the app, and it is completely separate from the product-analytics events described above.
On iOS, this is why the app shows Apple's App Tracking Transparency prompt. If you allow tracking, AppsFlyer uses your device's advertising identifier (IDFA) to attribute your install to a marketing source; because that identifier can be linked across apps, Apple classifies this as "tracking," which is why the App Store listing for SubTap says data may be used to track you. If you decline, AppsFlyer still runs, but falls back to non-tracking, probabilistic attribution that does not use the IDFA. On Android, an equivalent advertising identifier may be used the same way, without a separate prompt.
What this never does: build an advertising profile beyond attributing your one install, run or personalize ads (we show none), or feed your product-analytics activity — Amplitude never receives your advertising identifier, and AppsFlyer never receives the subscription or assistant data described elsewhere in this policy. You can change your ATT answer at any time in iOS Settings › Privacy & Security › Tracking; this has no effect on product analytics or any other part of the app.
How we use your information
We use what we collect to run and improve SubTap: syncing your data across devices, sending renewal reminders you've opted into, powering the AI assistant, processing purchases, understanding which features are used (switchable off in Settings › Privacy), preventing fraud and abuse, and meeting legal obligations. We rely on contract performance (to deliver the app), legitimate interests (security, fraud prevention, improving the service), and consent (notifications, AI assistant use, product analytics) as our legal bases under GDPR. Nothing in SubTap involves automated decision-making with legal or similarly significant effects on you.
How we share your information
We don't sell, rent, or trade your personal data. We share it only with:
- Service providers who help us run the app — our cloud hosting provider (encrypted sync storage), Adapty (purchases), OpenRouter and OpenAI (AI assistant — only if you confirm you want to use it), Amplitude (product analytics — unless you switch it off), Google Firebase (Crashlytics crash and performance diagnostics, and Cloud Messaging for push), and Apple (push notifications). Each is bound by a data processing agreement requiring protections equivalent to those described here.
- Authorities, if required by law, court order, or to protect the rights and safety of SubTap, our users, or others.
- A successor, if SubTap is ever acquired or merged — we'd notify you first.
- Anyone else, only with your explicit consent.
Data retention & international transfers
We keep your data while your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where the law requires us to keep something longer (e.g. billing records under Cyprus tax law). Subscription data stored locally on your device is removed as soon as you delete the app or your account.
Allie Ltd is based in Cyprus (EU), but some processors — OpenAI, Amplitude, Adapty, Google Firebase, and parts of our cloud infrastructure — operate outside the EU/EEA, including in the US. Where data leaves the EU/EEA, we rely on European Commission–approved Standard Contractual Clauses or other appropriate safeguards. Analytics data reaches the US unless you switch analytics off, which you can do at any time in Settings › Privacy.
Your rights
Under GDPR and equivalent laws, you can:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data — do this yourself any time in Settings, or ask us via the account deletion page.
- Export your data in a portable format, any time, from Settings.
- Object to or restrict certain processing.
- Withdraw consent at any time, without affecting anything processed before.
You can also turn product analytics on or off in Settings › Privacy, and disable biometric lock, notifications, or sync individually from Settings. For anything else, email support@subtapapp.com — we respond within 30 days. If you're in the EU/EEA, you can also complain to the Cyprus data protection authority (dataprotection.gov.cy, commissioner@dataprotection.gov.cy).
If you're a California resident, you have similar rights under the CCPA/CPRA, including the right to know, to delete, and to opt out of the sale or sharing of personal information. We don't sell personal information. Product-analytics events (Amplitude) are never shared for cross-context behavioural advertising — they're never used for ads, never linked to your account, and never combined with data from other companies; you can stop analytics collection at any time by switching it off in Settings › Privacy. Your device's advertising identifier is disclosed to our attribution provider, AppsFlyer, solely to measure install sources (see "Install attribution" above), never to serve or personalize ads; you can opt out of this at any time by declining or resetting the App Tracking Transparency permission in iOS Settings › Privacy & Security › Tracking.
Children
SubTap is meant for people 18 and over. We don't knowingly collect data from anyone under the age of digital consent in their country (13–16 depending on where you are) without verifiable parental consent. If you're a parent and think your child has given us personal data, email support@subtapapp.com and we'll delete it and close the account.
Security
We encrypt data in transit (TLS 1.3) and at rest (AES-256), support optional biometric lock on your device, and limit internal access to personal data on a need-to-know basis. No system is 100% secure, and we can't guarantee absolute security — but if a breach affects your rights, we'll notify you and the relevant authority as GDPR requires.
Changes
We may update this policy from time to time. We'll update the date above and, for changes that affect your rights, notify you in the app at least 30 days before they take effect.
Contact
Questions? Email support@subtapapp.com.
Allie Ltd, Emmanouil Roidi 44, Kirzis Center, 3031, Limassol, Cyprus (Reg. No. HE 460424, VAT 60076104S).