Privacy Policy

Last updated: May 10, 2026

We wrote this in plain language. If something is unclear, email us at [email protected].

What we collect

We collect only what's needed to run the app:

  • Account info: Email address, name (optional), encrypted password hash
  • Subscription data: AI tool names, plan names, costs, renewal dates — what you manually enter
  • Usage logs: Dates and counts you log yourself for each tool
  • Preferences: Budget, currency, notification settings, theme
  • Session data: IP addresses (hashed), browser type, login timestamps
  • Support messages: If you contact us

We do not connect to your bank, access your email, or scrape data from other services.

Why we collect it

  • To provide the subscription tracking and analytics features
  • To send you renewal reminders and security alerts (transactional, required)
  • To detect suspicious activity and protect your account
  • To send product updates if you've opted in (marketing, optional)
  • To improve the product through aggregated, anonymized usage analytics

How long we keep it

Active accounts

As long as you have an account

After deletion

PII deleted within 7 days of grace period expiry; anonymized analytics retained indefinitely

Audit logs

1 year for security compliance

Backups

Purged within 30 days of account deletion

Who we share it with

We do not sell your data. Ever.

We share it only with:

Infrastructure providers: Hosting, database, file storage (under DPA agreements)
Email provider: To deliver transactional emails (Resend or Postmark)
Payment processor: Stripe processes payments — we store only a customer ID reference
Law enforcement: Only when legally required and narrowly scoped

Your rights (GDPR & CCPA)

You have the right to:

Access

Download all your data (Settings → Privacy → Download my data)

Correct

Update your profile in Settings at any time

Delete

Request full account deletion (Settings → Security → Delete account)

Portability

Your data export is in JSON format, machine-readable

Object

Opt out of marketing emails at any time

Restrict

Contact us to limit how we process your data

California Residents (CCPA)

You have the right to know, delete, and opt out of sale (we don't sell) under CCPA.

To exercise any right, email [email protected]. We respond within 30 days.

Cookies

We use cookies for authentication, preferences, and analytics (if you consent). See our Cookie Policy for the full list.

Security

  • Passwords are hashed with bcrypt (cost factor 12)
  • All data is encrypted in transit (TLS 1.3)

Contact us

Privacy questions: [email protected]

Conduit LLC
123 Main St, San Francisco, CA 94102