RenewDate — Privacy Policy
Summary
There is no account, no bank linking, no tracking, no ads and no analytics. The subscriptions, prices, dates and notes you track are stored only on your device and never sent to us or anyone else.
Two optional features help you find subscriptions automatically. Both are off until you turn them on: email forwarding (receipts you forward are processed by our server, see below) and, on Android, reading payment notifications (processed only on your phone, nothing is uploaded).
Data stored on your device
- Your subscriptions and free trials (name, price, currency, billing dates, category, notes) and your settings.
- Reminders are scheduled as local notifications by your phone — no push server is involved.
- Widgets read the same on-device data.
- If you use automatic detection: the "Found for you" list (service, amount, dates, the sender's domain or the app that posted the notification), your private forwarding address key, and — on Android — the payment notifications' extracted details described below.
- Deleting the app (or Settings → "Delete all data") removes everything.
- Phone backups: on Android, the app opts out of Android's automatic backup to Google Drive, so this data is not copied there. On iPhone, the app's data is part of your own iCloud or computer backup if you have those turned on (that is how iOS backups work; we have no access to them). Turn off iCloud Backup for the app or the phone if you don't want that.
Network requests
- Exchange rates: once a day the app downloads the public European Central Bank reference rates from frankfurter.dev. The request contains no personal data and nothing about your subscriptions. Like any web request, the server sees your IP address; we don't receive or store it.
- "How to cancel" links open the official help page of that service in your browser. That site's own privacy policy applies.
Email forwarding (optional)
When you turn it on, the app creates a random private address (r-…@renewdate.app) on your phone. No
account, name or email address of yours is needed; the address is derived from a random key that stays on your
device, and only that key can read the results.
- What is processed: emails you forward to that address (for example receipts, free-trial, renewal, price-change and cancellation emails, and Gmail's forwarding confirmation). Our server program reads each email in memory to find the service, amount, currency, billing period and dates.
- Raw email is discarded immediately: the email itself — subject, text, attachments, other addresses — is never stored or logged. Only the structured result (service, amount, currency, dates, the sender's domain, a confidence score; for a Gmail confirmation: the code, the link and the requesting Gmail address) is kept, and only until your app fetches it — then it is deleted. Results not fetched are deleted after 30 days at the latest. Emails that contain nothing useful leave nothing behind.
- No humans read it: processing is fully automatic. We don't use the data for anything else, don't sell or share it, and don't build profiles.
- Processor: email delivery, the program and its short-term storage run on Cloudflare (Email Routing, Workers, D1). Like any web request, Cloudflare sees your IP address when the app fetches results; we don't store it.
- Optional push (Android): if enabled in the build, the app registers a Firebase Cloud Messaging token so our server can send a "new subscription found" signal (no service names). It is deleted when you turn email forwarding off.
- Turn off / delete: Settings → "Find subscriptions automatically" → "Turn off email forwarding" (or "Reset address", or "Delete all data") deletes everything waiting for your address on our server and forgets the key. Please also remove the forwarding rule in your mailbox.
Payment notifications (Android, optional)
- Only after you agree on an in-app disclosure and grant "Notification access" in Android settings.
- Banking and payment apps: notifications from a built-in list of about 80 common banking and payment apps are read by default, plus any app you add in the app. From a payment notification the app keeps only the merchant, amount, currency, time and the posting app's package name, on your phone, for at most 400 days. Payments to people (for example a transfer "to John Smith") are skipped, so people's names are not kept.
- Other apps: their notifications are checked on the phone, in memory, for a payment-like amount. If one looks like a payment, only that app's name and package name (with a count and time) are remembered, so the app can offer it in the list of apps you may add. Nothing else from those notifications is kept.
- Never read: chat messages and emails from any app, and SMS, messaging, email and social apps.
- The notification text is never stored or logged — it is dropped right after it was checked.
- Nothing is uploaded or shared — repeating charges are recognised on the phone.
- Turn it off in Settings → "Find subscriptions automatically" (stored charges are deleted) and revoke access in Android settings → Notification access. This feature doesn't exist on iPhone.
Purchases
If you buy Premium, the payment is handled entirely by the App Store or Google Play. The app uses RevenueCat to check whether Premium is active; RevenueCat receives the store receipt and a random anonymous ID created on your device — no name, email or subscription data from the app. We never see your card details. RevenueCat privacy policy.
Backups and exports
CSV exports and encrypted backups are files you create and share yourself (for example to your own cloud drive). Encrypted backups use AES-256-GCM with a key derived from your password (PBKDF2-SHA256); we cannot open them and cannot recover a lost password.
Device backups: Android's automatic Google Drive backup is turned off for this app. On iPhone, the app's data is included in your own iCloud or computer backup when you use those (see "Data stored on your device").
Your choices
- Notifications can be turned off at any time in your phone settings.
- Automatic detection is optional; each channel can be turned off at any time (see above).
- Export or delete your data at any time in Settings → Your data.
Not affiliated
Service names in the built-in catalog are trademarks of their owners and are used only to identify the services. RenewDate is not affiliated with or endorsed by any of them, and shows no logos.
Children
RenewDate is not directed to children under 13 and we do not knowingly collect their data.
Changes
If this policy changes, the new version will be posted on this page with a new date.
Contact
Questions or data requests: onlyabbos8@gmail.com