Privacy Policy
Last updated: September 1, 2026
The short version: SubForge never sees your bank credentials, never shows ads, and never sells your data. Bank linking is optional and read-only — it runs through Plaid, helps surface recurring charges and bank-attention states, and without it SubForge touches no financial accounts at all. Your subscriptions, your data, your call. That's the deal.
1. Who we are
SubForge ("SubForge," "we," "us") provides a subscription-tracking application for iOS and the website subforge.ai. Questions about this policy: support@subforge.ai.
2. Information we collect
- Account information. SubForge requires an account so your subscriptions can be monitored, synced, and backed up. We collect your email address and — if you sign in with Apple or Google — the name those providers share, plus an internal account identifier. Sign-in runs through Google Firebase, which also processes technical details such as your IP address and device information to keep sign-in secure and prevent abuse. If you sign in with Google, the Google Sign-In software in the app processes information under Google's privacy policy; Google's published disclosure for that software covers contact details (including a phone-number category), approximate location, device and account identifiers, and usage data. SubForge itself does not ask for your phone number or your location.
- Subscription records you enter. Service names, prices, billing cycles, renewal dates, categories, and notes that you type into the app. These are stored in our cloud database (Google Firebase) and synced across your devices.
- Optional bank connection (Pro). If you choose to connect a bank account for automatic subscription detection, the connection is made through Plaid, a third-party bank-connection provider. You authenticate directly with your bank inside Plaid's secure interface — SubForge never sees or stores your bank credentials. From the connection we receive and store only read-only recurring-charge information (merchant, amount, billing cadence, dates, institution names, and account metadata needed to manage your connected banks) used to suggest subscriptions and alert you when a bank needs attention, plus secure access tokens kept server-side, encrypted at rest, and inaccessible to client apps. You can disconnect a bank at any time in Settings. Disconnecting asks Plaid to revoke SubForge's access to that bank and removes the stored access token and connection data for it from your account. If the revocation cannot be confirmed, SubForge records the failure for investigation; you can email support@subforge.ai to check its status. Subscriptions you already chose to track remain unless you delete them. Plaid's handling of your data is described in Plaid's End User Privacy Policy.
- Purchase information. If you buy SubForge Pro, the transaction is processed entirely by Apple's App Store, and by Google Play if Android becomes available. Our subscription-management provider, RevenueCat, receives receipt information and your account identifier to confirm your entitlement and to power its customer-history and reporting tools. Apple and RevenueCat keep their own purchase records under their own policies. We never see your card details.
- Push notification tokens. To deliver bank-powered alerts, SubForge registers your device with Firebase Cloud Messaging and stores a device-specific push token together with your device platform and time zone. The token is used to route notifications to your device. Firebase also keeps its own installation identifiers for message delivery.
- Crash and diagnostic data. We use Google Firebase Crashlytics to detect and fix crashes: when the app crashes it sends a diagnostic report including the error, a stack trace, device model, OS version, and app version. Crash reports are not linked to your account. If a bank connection attempt fails, we also record a diagnostic report with Plaid's session and error details, which can be tied to your account for troubleshooting. Some provider software in the app, such as Google Sign-In and Firebase, reports usage and diagnostic information to its provider to operate and improve that provider's service. SubForge does not use advertising SDKs, and none of this data is used to track you across other companies' apps or websites.
- Activity history. SubForge stores app and bank-powered activity events, such as alerts, imports, bank attention, and disconnect history, so the Home Activity feed can show recent account history. The app displays the newest 100 events; older events may remain in your account history until bank/item cleanup or account deletion.
- Settings and in-app actions. SubForge keeps account-linked state that makes the app work the way you left it: which activity events you have read, which bank suggestions you accepted or dismissed, and your notification preferences.
Our App Store privacy label reflects all of the above. In Apple's categories, SubForge and the provider software it includes collect contact information, financial information, your subscription records, account and device identifiers, purchase history, usage data, and diagnostics. Two categories on that label come only from Google's sign-in software: approximate location and a phone-number category, neither of which SubForge asks for itself. None of this data is used for tracking or advertising.
3. What SubForge itself never collects
- Your bank credentials — even with an optional bank connection, sign-in happens directly between you and your bank via Plaid; SubForge never receives usernames, passwords, or full account numbers.
- Bank data of any kind unless you explicitly connect an account — without a connection, SubForge has no access to financial accounts at all.
- Screenshots, PDFs, and CSVs you import are used only for the import you initiate. Screenshot text is processed on-device, and imported files are not stored by SubForge. If you add a candidate, only the resulting subscription record is stored.
- Your contacts, or photos beyond the screenshot you explicitly pick, which stays on-device.
- Your location. The app never asks for location permission and does not record where you are. (Google's sign-in software is the one exception noted in section 2.)
- Advertising identifiers for cross-app tracking. SubForge contains no third-party advertising.
4. How we use information
To provide the service (sync, backup, restoring purchases), to send the renewal and trial reminders you configure, to respond to support requests, and to improve the app. Local renewal and trial reminders are scheduled on your device. Server-sent push notifications are used for bank-powered alerts such as price changes, possible duplicate subscriptions, new recurring charges, stopped-charge prompts, new bank accounts, bank disconnects, and reconnect requests. We do not sell or rent personal information, full stop.
5. Sharing
We share data only with the service providers that make SubForge run: Google Firebase (authentication, database, and crash reporting — acting as our processor, including Firebase Cloud Messaging for push alerts), Apple and Google (sign-in, if you use Sign in with Apple or Google, and payment processing), Plaid (optional bank connections, as described above), and RevenueCat (purchase entitlements). Each provider handles data under its own terms and privacy policy. We may disclose information if required by law. If SubForge is ever acquired, data would transfer under this same policy's protections. We never sell personal information.
6. Data retention & deletion
Your data is yours to delete:
- In-app: Settings → Danger zone → Delete account deletes your sign-in account and starts an automatic cleanup that removes your subscriptions, activity, bank connection data, and other account records from our servers and asks Plaid to revoke any connected banks. This runs in the background and normally finishes shortly after you delete the account. Settings → Erase all subscriptions clears your subscription records at any time. Bank disconnect controls ask Plaid to revoke access and remove that bank's connection data; accepted subscriptions stay in your list unless you delete them.
- What deletion does not do: it does not cancel a SubForge Pro subscription — manage or cancel that in your App Store settings, or billing continues. Apple and RevenueCat keep their own purchase records, and our service providers (including Google Firebase) may retain data for a limited time under their own retention and backup schedules. If a bank revocation cannot be confirmed, SubForge records the failure for investigation.
- By email: request deletion at support@subforge.ai and we'll complete it within 30 days, or write to check the status of a deletion or bank revocation.
7. Security
Data is encrypted in transit (TLS) and protected at rest by Google Firebase's infrastructure. Client access to cloud records is restricted by account-based security rules.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information we maintain about you. If you are a California resident, these rights are guaranteed under the California Consumer Privacy Act (CCPA). We do not sell personal information or share it for cross-context behavioral advertising. To make a privacy request, email support@subforge.ai.
9. Children
SubForge is not directed to children under 13, and we do not knowingly collect personal information from them.
10. International users
SubForge is operated from the United States, and our own server functions run in a Google Cloud region in the United States. The providers we rely on — Google Firebase, Apple, Google Sign-In, Plaid, and RevenueCat — process data on their own infrastructure under their own terms, which may include locations outside the United States for some services. By using SubForge you consent to processing in the United States and by these providers.
11. Changes
We'll post any changes to this policy here and update the date above. Material changes will be highlighted in the app.