Legitimate interest (Art 6(1)(f)) — security, fraud prevention, crash diagnostics. We balance our interest against your privacy and minimize collection.
Consent (Art 6(1)(a)) — push notifications, Telegram delivery, marketing emails. You can withdraw consent in Settings at any time.
4. Storage and security
Data is stored on servers in Germany (Hetzner). Transport encryption: TLS. Passwords: bcrypt. Database access is restricted to the backend service.
5. Third-party services
Paddle — web payments and Merchant of Record. Privacy.
Google Play Billing — Android in-app subscriptions. Privacy.
Apple App Store — iOS in-app subscriptions (when iOS launches). Privacy.
Cloudflare Turnstile — sets cookies for bot challenge during sign-up.
landing_variant — functional cookie that remembers which homepage variant you saw (A/B test). 30 days. No personal data.
We do not set advertising or analytics cookies.
7. Your rights
Access — your data is visible in the app's Settings.
Correction — editable in Settings.
Deletion — request via Settings → Account → Delete or by emailing support@subtick.net.
Export — subscription data export available in Settings.
Withdraw consent — toggle notifications off in Settings.
8. Data retention
We retain your data for as long as your account is active. After deletion request:
A 7-day grace period during which you can cancel the deletion.
After grace period, account, subscription, and notification data are permanently deleted.
Payment records: currently also deleted at this point. We are working on retaining anonymized payment records for tax and legal compliance (up to 7 years), but until that is implemented, payment data is deleted alongside the account.
9. International transfers
Primary data storage is in the EU (Germany). Some third parties (Firebase, Paddle, Mailtrap) may process data outside the EU under standard contractual clauses or equivalent safeguards.
10. Children
SubTick is not intended for users under 16. We do not knowingly collect data from children.
11. Changes
We may update this policy. Material changes will be notified by email to registered users.