SubWise is built with a privacy-first architecture. SMS messages are parsed entirely on your device. Raw SMS content is never transmitted to, stored on, or accessible by our servers.
1. Overview
SubWise ("we," "our," or "the app") is a subscription management application developed by flashthelazydeveloper. SubWise helps you track, manage, and optimise your recurring subscriptions by automatically detecting them from your bank transaction SMS messages.
This Privacy Policy explains what data we collect, how we use it, and the choices you have. By using SubWise, you consent to the practices described in this policy.
2. Data We Collect
| Data Type | Details | Where Processed |
|---|---|---|
| Account Information | Name, email address (via Google Sign-In) | Server |
| Subscription Metadata | Platform name, amount, billing cycle, billing date, category | Server |
| Payment Method Labels | Label you assign (e.g. "My HDFC Card") — no card numbers, CVV, or bank credentials | Server |
| SMS Content | Bank transaction SMS messages from your inbox | On-Device Only |
| Device Token | Firebase Cloud Messaging (FCM) token for push notifications | Server |
| App Preferences | Dark mode setting, notification preferences | Server |
We do not collect: bank account numbers, credit/debit card numbers, UPI PINs, passwords, OTPs, precise location, contacts, photos, or any biometric data.
3. SMS Data & On-Device Processing
This is the most important section of our privacy policy. SubWise's core feature is detecting subscriptions from your bank transaction SMS messages. Here is exactly how it works:
What we read
With your explicit permission, SubWise reads SMS messages in your device's inbox that originate from recognised bank sender IDs (e.g. sender IDs like VK-SBIBNK, AD-HDFCBK, VM-ICICIB, and similar). We filter for transaction-related messages containing keywords such as "debited," "credited," "spent," and currency indicators like INR, Rs., or ₹.
Where parsing happens
All SMS parsing and pattern matching occurs entirely on your device. SubWise uses on-device code to scan, filter, and extract subscription-related information. Your raw SMS messages are never transmitted to our servers or any third-party service.
What leaves your device
After on-device parsing, only the following derived metadata is sent to our server — and only after you review and confirm each detected subscription:
- Platform/merchant name (e.g. "Netflix," "Spotify")
- Transaction amount (e.g. ₹199)
- Estimated billing date
- Estimated billing cycle (monthly, yearly, etc.)
- A one-way hash of the SMS (for deduplication — not the SMS content itself)
User control
You are always in control. Before any detected subscription metadata is sent to our server, you can review, edit, confirm, or reject each detection. You can also revoke SMS permission at any time through your device's Settings, and SubWise will continue to function for manually-added subscriptions.
4. How We Use Your Data
We use the data we collect solely to provide and improve SubWise's core functionality:
- Display and manage your confirmed subscriptions
- Calculate spending analytics and projections
- Send push notification reminders before billing dates
- Provide cancellation guides and support information for platforms
- Sync subscription data across your devices
- Authenticate your account securely
We do not use your data for advertising, profiling, credit scoring, selling to third parties, or any purpose unrelated to subscription management.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data to anyone. We share limited data with the following service providers, strictly to operate SubWise:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication (Google Sign-In) | Email, name, auth tokens |
| Firebase (Google) | Push notifications | FCM device token only |
| Fly.io | Backend hosting | Encrypted API requests |
| AWS (RDS) | Database hosting | Encrypted stored data |
These providers are bound by their own privacy policies and process data on our behalf only to deliver their respective services.
We may disclose data if required by law, regulation, legal process, or enforceable governmental request.
6. Data Storage & Security
Your data is stored on secure servers hosted by AWS (PostgreSQL database on Amazon RDS). We implement the following security measures:
- Encryption in transit: All data transmitted between the app and our servers uses TLS/HTTPS encryption
- Encryption at rest: Database is encrypted using AWS RDS encryption
- Authentication: All API endpoints require valid JWT tokens issued by Clerk
- Access control: User data is isolated — you can only access your own subscriptions and account data
- No raw SMS storage: SMS messages are never written to our database or logs
7. Data Retention & Deletion
Retention
We retain your account data and subscription data for as long as your account is active. Detected subscription candidates that you reject are deleted immediately and are not retained.
Account Deletion
You can request complete deletion of your account and all associated data at any time by emailing us — Mail Us with your deletion request.
Upon receiving a deletion request, we will permanently delete all your data — including your account information, all subscriptions, payment method labels, notification preferences, and device tokens — within 30 days. This action is irreversible.
Certain data may be retained beyond this period only if required by applicable law or to resolve disputes.
8. Your Rights
You have the following rights regarding your data:
- Access: View all your subscription and account data within the app at any time
- Correction: Edit any subscription details, payment methods, or profile information
- Deletion: Delete individual subscriptions or your entire account
- Portability: Export your subscription data (coming soon)
- Withdraw consent: Revoke SMS permission through Android Settings at any time without affecting other app functionality
- Opt out of notifications: Disable push notifications per type within the app or through device settings
9. App Permissions
| Permission | Why We Need It | Required? |
|---|---|---|
| READ_SMS | To scan your inbox for bank transaction messages and auto-detect subscriptions. Parsing is entirely on-device. | Optional |
| RECEIVE_SMS | To detect new bank transaction SMS in real-time for ongoing subscription detection. | Optional |
| Notification Access | To monitor transaction notifications for real-time subscription detection (alternative to SMS). | Optional |
| POST_NOTIFICATIONS | To send you billing reminders and alerts before upcoming charges. | Optional |
| INTERNET | To communicate with our server for authentication, syncing subscriptions, and receiving push notifications. | Required |
All sensitive permissions (SMS, Notifications) require your explicit consent before they are activated. SubWise functions fully for manual subscription management without any sensitive permissions.
10. Children's Privacy
SubWise is not directed at or intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected data from a child under 18, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you through the app or via email before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
Your continued use of SubWise after any changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please reach out: