This policy explains what GhostSubs (“we”, “us”) accesses, what we store, how we use it, and how you can delete it. The short version: we read receipt and renewal emails with your permission, keep only the extracted subscription details, and never touch your bank accounts, card numbers, or passwords.
What GhostSubs accesses
With your permission, GhostSubs connects to your Gmail account using Google's read-only scope (gmail.readonly) together with your basic profile (name, email address, profile picture). We only read messages; we never send, modify, or delete email, and we never see your Google password.
How we use it
We search your inbox for receipts and renewal notices, pre-filter them with deterministic code, and use Google's Gemini API to identify subscriptions and extract structured details (service name, amount, currency, billing cycle, charge dates). The contents of matching emails are sent to the Gemini API solely for this identification step and are not used for any other purpose. We use the extracted data only to power features you can see: your dashboard, renewal reminders, and overlap suggestions.
Google API Limited Use disclosure
GhostSubs's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:
- only use Gmail data to provide the user-facing subscription features described on this page;
- do not transfer Gmail data to third parties except to provide those features (the Gemini identification step described above), to comply with law, or as part of a merger/acquisition with prior notice to you;
- do not use Gmail data for advertising, and do not sell it;
- do not allow humans to read your email content, except with your explicit permission for support, for security or abuse investigation, or where required by law;
- do not use Gmail data to train or improve generalized artificial intelligence or machine-learning models.
What we store
- Your Google account identifiers: account id, email address, name, and profile picture URL.
- The extracted subscription data (service, amount, dates, status).
- Gmail message IDs of the source receipts, so you can open them in Gmail and we can refresh details on demand.
- An OAuth refresh token, stored encrypted at rest (AES-256-GCM), used only to read your inbox when you run a scan or when we prepare your renewal reminders.
- A record of which reminder emails we have already sent you, so we never remind you twice about the same charge.
We do not store the full bodies of your emails, and we never ask for or store bank credentials or card numbers.
Cookies
We use two first-party cookies, both strictly necessary: a session cookie that keeps you signed in (HTTP-only, signed, expires after 30 days) and a short-lived oauth_state cookie that protects the sign-in flow against forgery (expires after 10 minutes). We use no advertising or third-party analytics cookies.
Sharing
We do not sell your data and we do not share it with advertisers. Data is processed by our infrastructure providers only as needed to run the Service: our hosting provider, our database provider, the Gemini API for the identification step, and our email provider for renewal reminders. Each receives only what is necessary for its role.
Data retention
We keep your data for as long as your account exists so your dashboard stays useful between scans. If you delete your account, everything is removed immediately (see below). If you revoke access from Google without deleting your account, we can no longer read your inbox; your previously extracted data remains until you delete it.
Deleting your data
You can delete your account and all stored data yourself at any time from the bottom of your dashboard (“Delete my account & data”). This immediately and permanently removes your profile, encrypted tokens, extracted subscriptions, scan history, and reminder records, and revokes our access to your Google account. You can also revoke access from your Google Account permissions at any time, or email arhamwani765@gmail.com and we will delete your data for you.
Security
All traffic is served over HTTPS. OAuth refresh tokens are encrypted at rest with AES-256-GCM, sessions are signed HTTP-only cookies, and access to production systems is limited to the operator of the Service. No method of storage is 100% secure, but we design so that the most sensitive item we hold — the token that can read your inbox — is useless without the encryption key.
Children
The Service is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If we change this policy, we will update the date above and, for material changes, highlight them on this page or notify you by email before they take effect.
Contact
Privacy questions or deletion requests: arhamwani765@gmail.com, or see the support page.