Subtrack Privacy Policy
Last updated 25 September 2026 · Türkçe
Subtrack is a personal subscription and expense tracker published by Halibal Publishing. This policy explains exactly what the app stores, why, and who else can see it. It describes the app as it actually works rather than every possibility a template might list.
What Subtrack stores
Account
Your email address, display name, and — if you sign in with Google or Apple — the identifier that provider gives us. Passwords are stored only as a one-way hash and are never readable.
Why: to create your account, sign you in, and let you recover access.
The records you enter
Subscriptions, expenses, income, installment plans, benefits, and the amounts, dates, notes and currencies you attach to them.
Why: this is the app. It is stored so it is still there on your next launch.
Services picked without a price
If you picked a service during setup and left without giving it a price, we keep its name and currency until you price it or dismiss it.
Why: so it is still waiting for you next time, on any device signed into your account — not just the one you set up on.
Payment cards
The last four digits only, plus a nickname, bank name, and the statement and due days you choose.
Why: so you can tell your cards apart and see when a statement falls due.
Preferences
Display currency, language, time zone, reminder timing and quiet hours.
Why: to show amounts in your currency and send reminders at a sensible local hour.
Push token
A device token issued by Expo, the service that delivers our notifications — collected if you allow notifications on this device — and a record of the reminders we sent you.
Why: to deliver the reminders you asked for, and to avoid sending the same one twice. Turning reminders off stops them being sent; deleting your account removes the token and the record.
Apple sign-in status
If you sign in with Apple, Apple tells us when its private relay stops or resumes forwarding mail to you, when you revoke Subtrack's access, or when you delete your Apple Account. We keep a log of each notification — the identifier Apple gives us for you, what changed, and when — for 90 days, with no email address and nothing else Apple sent us.
Why: so we stop mailing an address Apple has told us it will not deliver to, and so an account left with no password, no Google link and no working Apple sign-in can still be reached — or, after 30 days with none of those, removed rather than left behind forever.
Diagnostics
Crash and error reports.
Why: to find and fix bugs. These are scrubbed — see Crash reports below.
Onboarding analytics
Which onboarding step was reached, the action taken, your app language, and a timestamp — labelled with a one-off label that exists only while the app is open.
Why: to see where new users get stuck. It is not linked to your account, carries nothing you typed, and nothing about it is saved on your device. Close the app and the label is gone, so two visits are not recognised as the same person.
What Subtrack never collects
- Full card numbers, expiry dates, or security codes. There is nowhere in the app to enter them, and no field in the database that could hold them.
- Bank credentials. Subtrack does not connect to your bank and cannot see your real transactions — every figure in the app is one you typed.
- Location, contacts, photos, health or fitness data.
- Advertising identifiers. Subtrack does not ask for tracking permission because it has nothing to track you with.
What is kept on your phone
Subtrack stores only what it needs to work the way you asked it to:
- Your sign-in. Session tokens, held in the device keychain so you are not asked to sign in every time.
- A copy of your own records, so the app opens and works without a connection. It is placed where the system excludes it from backups.
- Your settings and progress — your language, whether you have finished onboarding, what you entered while setting up, and whether you have already been asked about notifications, so you are not asked twice.
Nothing is stored for analytics. There are no advertising or tracking identifiers, and no identifier that survives closing the app. Signing out or deleting your account clears your sign-in and the copy of your records; your settings and progress stay on the device, so the app opens in the language you chose rather than starting over.
Crash reports
Crash reporting runs through Sentry, in the app and on the server, configured to send no personal information: the "default PII" setting is off in both, reports from the app pass through a scrubber before they leave your device, and neither sends the contents of the variables a crash happened inside. The purpose is a stack trace, not a record of what you were doing.
Who else processes your data
Subtrack relies on a small number of service providers, each handling data only to run the service on our behalf:
- Neon — database hosting, where your records live.
- Render — application hosting, which runs the API.
- Sentry — crash diagnostics, scrubbed as described above.
- SMTP2GO — sending account emails such as password resets.
- Expo — delivering reminders, if you enable them. A reminder names the subscription it is about and its amount, so Expo and then Apple carry that text on the way to your phone.
- Apple Push Notification service — the final step of delivering those reminders to an iPhone.
- Google and Apple — only if you choose to sign in with them.
- Have I Been Pwned — checking a new password against known breaches. Only a short, partial fingerprint of the password is sent, never the password itself, and never your email address.
Neon, Render, Sentry, SMTP2GO and Expo process data on our behalf, under a contract that holds them to protection equivalent to this policy. Google and Apple act on their own account when you choose to sign in with them. Have I Been Pwned receives only the first five characters of a password's fingerprint, which identifies nobody, over a public endpoint used under its published terms.
Currency exchange rates come from a public rates service. No personal data is sent when they are fetched — Subtrack asks for the rates, not for anything about you.
Your control
- Export. Two, both in Settings. Export expenses writes your expenses and income to a CSV file you keep. Export all my data writes your account's records — cards, subscriptions, installments, benefits, price history, services picked without a price, and your profile — to a JSON file. It carries what you entered, not our operational records such as the log of reminders sent.
- Correction. Records can be edited or removed at any time, with a few exceptions that keep your own history honest: a charge that already counts as paid — marked by you, settled by its card, or paid automatically on its date — and the furthest-ahead charge of a subscription, which the app would simply regenerate. To end a subscription, cancel it rather than deleting its charges.
- Deletion. Settings → Delete account permanently erases your account and everything in it. It is immediate and cannot be undone, and we keep no copy of our own. Our database provider keeps short-term backups so the service can be recovered after a failure; deleted data disappears from those within 30 days, and they are never used to restore an account.
- Reminders. Turning them off stops the notifications. The device token is removed when you delete your account.
You can exercise access, correction, erasure and export yourself in the app, without asking us or waiting. Where data protection law gives you further rights, writing to the address below is enough to use them.
How long it is kept
Your records are kept until you delete them or delete your account. Deleting the account removes the account and every record attached to it. Onboarding analytics are not attached to your account, and are not removed when it is deleted, because there is nothing in them that points back to you. Each step is kept as its own row for twelve months and then deleted.
Each Apple sign-in notification we log is kept for 90 days and then deleted. If Apple tells us your Apple Account was deleted and the account it leaves behind has no password, no Google link and no other way to reach it, we keep it for 30 days in case that changes, then delete it the same way Settings → Delete account would.
Security
Traffic is encrypted in transit. Passwords are stored only as one-way hashes. Every endpoint that touches your records requires a valid session, and sign-in endpoints are rate limited to slow down guessing. A password you set or change in Settings, or reset by email, is checked against known breaches before it is accepted; if that check cannot be reached, the password is allowed rather than locking you out of your own account. Changing your password means every other device will need to sign in again.
Children
Subtrack is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will remove it.
Changes
If this policy changes in a way that affects what is collected or who receives it, the date at the top will change. The current version is always available in the app, under Settings → Privacy policy.
Who is responsible
Subtrack is published by Halil İbrahim Algül, trading as Halibal Publishing, who is the data controller for everything described above.
Contact
Questions, requests, or complaints: privacy@halibal.com