Privacy Policy
Who we are
SubDupes is operated by AST Middle East DMCC, a company registered in the United Arab Emirates ("SubDupes", "we", "us", "our"). We are responsible for the personal data described in this policy.
This policy covers the SubDupes website (subdupes.com), web app (app.subdupes.com), mobile apps and browser extension. It explains what we collect, how we use it, who we share it with, and the choices you have.
Contact: support@subdupes.com
Effective date: 15 September 2026
The short version
We find subscriptions from receipts you forward, files you upload, or details you enter. We never ask for your bank login, and we do not request permission to read your mailbox. Some of what you send us is processed by AI providers, and we use analytics and advertising tools. This policy names all of them. We do not sell your personal data.
Information you give us
When you create an account and use SubDupes, you give us:
- Account details: your name, email address and password, which is stored hashed. If you sign in with Google, Microsoft, Apple or Facebook, we receive your name and email address from them instead.
- Profile and preferences: currency, timezone, country, notification settings and account type.
- Subscription records: the services you track, their prices, billing cycles, renewal dates, categories and notes, whether you enter them yourself, import a CSV file, or we detect them from your emails or files.
- Forwarded emails: the full content of any email you forward or BCC to your private SubDupes address, including the sender, subject, body and attachments.
- Uploaded files: bank or card statements and CSV files you upload.
- Messages: questions you ask the in-app assistant, support requests and feedback.
- Team information: the names and email addresses of people you invite to a workspace.
- Billing information: your plan and payment status. Card details are handled by our payment providers, and we never receive your full card number.
Information we collect automatically
When you use our website, app, mobile apps or extension, we collect:
- Usage events: the screens you view and the actions you take in the app, such as completing a setup step, adding a subscription, or hitting an error.
- Session recordings: records of how pages are used, including clicks, scrolling and navigation. See Analytics, recording and advertising below.
- Device and log data: IP address, browser, device type, operating system, approximate country and timestamps.
- Notification tokens: if you allow notifications, an identifier for your browser or device so we can send them.
- Cookies and similar technologies. See Cookies below.
How we find your subscriptions
Email forwarding. Every account has a private SubDupes email address. When you forward or BCC a receipt to it, our email provider receives it and passes it to our servers. We extract the vendor, amount, currency, dates and billing cycle, check whether the charge looks recurring, and save the result to your account.
Statement uploads. We read the text of an uploaded statement on our own servers. If a PDF has no readable text, for example a scanned document, we send the file to OpenAI to read it and delete it from OpenAI's storage once it has been processed.
Browser extension. The SubDupes extension adds a button to the Gmail compose window. When you click it, it adds your SubDupes address to the Bcc field of the email you are writing. It does not read your inbox or the emails you receive. It reads the SubDupes sign-in cookie only to know which account you are using.
Google and Microsoft sign-in. If you connect Google or Microsoft, we request only your basic profile and email address, and we store the resulting token in encrypted form. We do not request permission to read, send or manage your email.
AI processing
We use third-party AI providers to extract and classify subscription details and to answer questions in the in-app assistant. The text of forwarded emails and invoices is sent to OpenAI for extraction, and can include names, addresses and partial payment details that appear in those emails. Before transactions from uploaded statements are sent to OpenAI for classification, we remove account numbers, card numbers, IBANs, phone numbers and email addresses. When you use the assistant, your question, your email address and a summary of your tracked subscriptions are sent to xAI so it can answer. OpenAI and xAI process this data under their API terms.
How we use your information
We use your information to:
- Provide the service: detect, store and display your subscriptions, renewal dates and spending.
- Send the notifications you rely on: renewal reminders, price change alerts, trial expiry warnings and payment notices.
- Act on your instructions, such as sending a cancellation or negotiation request to a vendor when you turn on Autopilot for a subscription.
- Run accounts and billing: sign-in, security, fraud prevention, plan limits, trials, referrals and payments.
- Improve the product: study usage and errors to fix problems and understand which features help.
- Contact you: service announcements, support replies, and emails about getting set up and using SubDupes. You can unsubscribe from non-essential emails using the link in any of them.
- Measure advertising: understand whether our ads lead to sign-ups and subscriptions.
- Meet legal obligations, including tax, accounting and responding to lawful requests.
Legal bases
Where laws such as the GDPR apply, we rely on these legal bases:
- Contract: to provide the service you signed up for, including processing the emails you forward and the files you upload.
- Legitimate interests: to secure and improve the service, prevent fraud and understand how it is used, balanced against your rights.
- Consent: where we ask for it, such as your cookie choices on subdupes.com and push notifications. You can withdraw consent at any time.
- Legal obligation: to keep financial records and comply with the law.
Who we share information with
We share personal data with the providers that help us run SubDupes, and only what each one needs:
- Amazon Web Services: hosting, database, file storage and logs, in the United States (us-east-1).
- Resend: sending our emails, and receiving the emails you forward to your SubDupes address.
- OpenAI: extracting details from forwarded emails and scanned statements, and classifying redacted transactions.
- xAI: answering questions in the in-app assistant.
- Stripe: processing payments made on our website. Apple and Google: processing purchases made in our mobile apps.
- Google, Microsoft, Apple and Facebook: signing you in, if you choose to use them.
- Firebase Cloud Messaging, operated by Google: delivering push notifications to mobile devices.
- Sentry: error monitoring and session replay.
- PostHog: product analytics.
- Google (Tag Manager and Analytics), Microsoft Clarity, Meta and X: analytics, session recording and advertising measurement, as described below.
- Professional advisers and authorities, where the law requires it or to protect our rights.
- A buyer or successor, if SubDupes is sold or merged.
Analytics, recording and advertising
On subdupes.com, Google Analytics, the Meta pixel and the X pixel load only after you allow them in the cookie banner. You can change your choice at any time from the cookie settings button.
In the SubDupes web app, we use Google Tag Manager, Microsoft Clarity, the Meta pixel, the X pixel, PostHog and Sentry. Clarity, PostHog and Sentry can record how pages are used, including clicks and navigation. Sentry records a sample of sessions and every session in which an error occurs.
When you sign up, start a trial or subscribe, our servers send Meta a hashed copy of your email address, name and account identifier, together with your IP address and browser details, so we can tell which ads lead to sign-ups. Hashing turns your details into a coded value, which Meta can match against accounts it already holds.
We do not sell your personal data for money.
International transfers
SubDupes is operated from the United Arab Emirates, our main servers are in the United States, and several of our providers are based in the United States. Your data may therefore be processed outside the country where you live. Where the law requires it, we rely on the data protection terms our providers offer, including standard contractual clauses where available.
How long we keep information
We keep information only as long as we need it:
- Account and subscription data: for as long as your account is open.
- Uploaded statement files: deleted from our servers 7 days after upload. The transactions and subscriptions found in them stay with your account.
- Server logs: up to 60 days.
- Billing records: for as long as tax and accounting law requires.
- Deleted accounts: see Deleting your account below.
Deleting your account
When you delete your account in the app, you are signed out and your account is deactivated immediately. We currently keep the account record, your subscription data and a record of the deletion, so the account can be restored if you ask us.
If you want your data permanently erased, email support@subdupes.com from the address on your account. We will erase it within 30 days, except for records we must keep by law, such as billing records.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and get a copy.
- Correct inaccurate data. You can edit most details directly in the app.
- Have your data erased, as described in Deleting your account.
- Object to or restrict some processing, including direct marketing.
- Withdraw consent where we rely on it.
- Receive your data in a portable format.
- Complain to your local data protection authority.
Using your rights
To use any of these rights, email support@subdupes.com from the address on your account. We will reply within 30 days. We do not yet offer a self-service data export, so requests for a copy of your data are handled by email.
Security
Data is encrypted in transit and our database is encrypted at rest. Passwords are stored hashed, and sign-in tokens from Google and Microsoft are encrypted. Access to production systems is restricted. No system is completely secure. If a breach affects your personal data, we will tell you and the relevant authorities where the law requires it.
Children
SubDupes is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We update this policy when our practices change and show the new effective date at the top. If a change is significant, we will tell you by email or in the app before it takes effect.
Contact us
AST Middle East DMCC
Email: support@subdupes.com