Subtrack Privacy Policy
Last updated 31 July 2026
Subtrack is a personal subscription and expense tracker published by Halibal Publishing. This policy explains exactly what the app stores, why, and who else can see it. It describes the app as it actually works rather than every possibility a template might list.
What Subtrack stores
Account
Your email address, display name, and — if you sign in with Google or Apple — the identifier that provider gives us. Passwords are stored only as a one-way hash and are never readable.
Why: to create your account, sign you in, and let you recover access.
The records you enter
Subscriptions, expenses, income, installment plans, benefits, and the amounts, dates, notes and currencies you attach to them.
Why: this is the app. It is stored so it is still there on your next launch.
Payment cards
The last four digits only, plus a nickname, bank name, and the statement and due days you choose.
Why: so you can tell your cards apart and see when a statement falls due.
Preferences
Display currency, language, time zone, reminder timing and quiet hours.
Why: to show amounts in your currency and send reminders at a sensible local hour.
Push token
A device token issued by Apple, only if you turn reminders on.
Why: to deliver the reminders you asked for. Turning reminders off removes it.
Diagnostics
Crash and error reports.
Why: to find and fix bugs. These are scrubbed — see Crash reports below.
Onboarding analytics
Which onboarding step was reached, the action taken, your app language, and a timestamp — labelled with a random identifier generated on your device.
Why: to see where new users get stuck. It is not linked to your account and carries nothing you typed.
What Subtrack never collects
- Full card numbers, expiry dates, or security codes. There is nowhere in the app to enter them, and no field in the database that could hold them.
- Bank credentials. Subtrack does not connect to your bank and cannot see your real transactions — every figure in the app is one you typed.
- Location, contacts, photos, health or fitness data.
- Advertising identifiers. Subtrack does not ask for tracking permission because it has nothing to track you with.
Crash reports
Crash reporting runs through Sentry, configured to send no personal information: the "default PII" setting is off, every report passes through a scrubber before it leaves your device, and low-level debug traces are discarded rather than attached. The purpose is a stack trace, not a record of what you were doing.
Who else processes your data
Subtrack relies on a small number of service providers, each handling data only to run the service on our behalf:
- Neon — database hosting, where your records live.
- Render — application hosting, which runs the API.
- Sentry — crash diagnostics, scrubbed as described above.
- SMTP2GO — sending account emails such as password resets.
- Apple Push Notification service — delivering reminders, if you enable them.
- Google and Apple — only if you choose to sign in with them.
Currency exchange rates come from a public rates service. No personal data is sent when they are fetched — Subtrack asks for the rates, not for anything about you.
Your control
- Export. Settings → Export expenses writes everything you have entered to a CSV file you keep.
- Correction. Every record in the app can be edited or removed at any time.
- Deletion. Settings → Delete account permanently erases your account and everything in it. It is immediate and cannot be undone; we do not keep a shadow copy.
- Reminders. Turning them off stops the notifications and discards the device token.
If you are in the UK, EU, or another region with equivalent law, these are your rights of access, rectification, erasure, and portability. You can exercise the main ones yourself in the app, without asking us or waiting.
How long it is kept
Your records are kept until you delete them or delete your account. Deleting the account removes the account and every record attached to it. Onboarding analytics are not attached to your account, so they are not tied to it and are retained only in aggregate to study where onboarding fails.
Security
Traffic is encrypted in transit. Passwords are stored only as one-way hashes. Every endpoint that touches your records requires a valid session, and sign-in endpoints are rate limited to slow down guessing. Changing your password ends every other session immediately.
Children
Subtrack is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will remove it.
Changes
If this policy changes in a way that affects what is collected or who receives it, the date at the top will change and the app will point you here. Material changes will be highlighted in the app rather than made quietly.
Contact
Questions, requests, or complaints: privacy@halibal.com