Privacy
Privacy Policy for Subs
How the Subs iOS app processes, stores, and protects your data.
Last updated: August 11, 2026
1. Controller
The controller responsible for the processing described in this privacy policy is:
Andritoi & Nothaft GbRSina Marie Nothaft & Sergio Valentino AndritoiHauptstraße 694491 HengersbergGermanysupport@trysubs.app+49 (0) 175 3488365For processing carried out by Apple or Logo.dev under their own responsibility, their respective privacy information also applies as described below.
2. Data stored on your device and in iCloud
Subscription data
Subs processes the subscription details you enter or confirm after an import. Depending on your entries, these may include the provider or service name, price, currency, billing interval, payment and renewal dates, status, category, notes, and reminder settings. The data is used to manage your subscriptions and to provide calculations, overviews, and reminders requested by you.
Subscription data is stored on your device using SwiftData. If iCloud is enabled for Subs, SwiftData synchronizes this data through CloudKit with the private database associated with your Apple Account so that it can remain up to date on your Apple devices. Apple states that, by default, only the user can access a private CloudKit database and that its contents are not visible in the developer portal. We do not operate a separate account or backend database for this data.
Financial profile, birth year, hourly wage, and settings
Information in your financial profile, your birth year, hourly wage, and app settings is used for the personalized calculations and display options you select. According to the current app design, this information remains locally on your device and is not synchronized to our servers or to CloudKit.
The legal basis, where the GDPR applies, is Article 6(1)(b) GDPR: processing is necessary to provide the app functions you request. Optional information does not have to be entered; without it, the related calculation or personalization may not be available.
3. Imports, OCR, and Apple Foundation Models
You can import subscription information from text, photos, images, documents, tables, CSV files, or PDFs. Subs processes only the content you select or capture. Text recognition (OCR), extraction, and structuring take place locally on your device. Subs uses Apple’s on-device Foundation Models framework for supported import functions—not a server model or Private Cloud Compute. Apple describes inputs and outputs of the on-device model as remaining on the device.
The source content is processed within the app for the import. You can review the result before saving it. Only the subscription information you confirm is added to Subs and stored as described in section 2; Subs does not create a server-side copy of the source document or send it to an external AI provider.
Files and images may contain personal data about other people. Please import only content you are permitted to use and that is necessary for managing your subscriptions.
4. Camera and local notifications
Camera and selected files
Camera access is used only when you choose to capture a document or image for an import. Access requires your permission. Files and photos are accessed through Apple’s system selection interfaces or the permission you grant. You can change permissions at any time in iOS Settings; withdrawing a permission prevents the related feature from working but does not affect earlier lawful processing.
Local notifications
If you allow notifications, Subs schedules reminders for upcoming payments or renewals locally on your device. Subs does not send these reminders from its own server and does not use remote push notifications for this purpose. iOS controls how notification content appears, including on the Lock Screen. You can change or revoke notification permission in iOS Settings at any time.
5. Retrieving logos through Logo.dev
To display a provider logo, your device establishes an HTTPS connection to the Logo.dev service operated by Logodev, Inc., United States. The request necessarily discloses the IP address used by your device. According to Logo.dev, it also records the requested domain or URL and the request timestamp. Subscription prices, financial-profile information, imported documents, and their contents are not part of the logo request.
We use Logo.dev to make providers easier to recognize. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is a clear and convenient presentation of subscriptions. Logo.dev states that it uses request data to deliver the service, meter usage, and monitor security, and retains usage logs only as long as necessary for service delivery, security monitoring, and billing.
Logo.dev is based in the United States. Its privacy policy states that transfers from the EEA, United Kingdom, and Switzerland are protected by the EU Standard Contractual Clauses.
6. Purchases and subscriptions through Apple StoreKit
In-app purchases and subscriptions for Subs are offered and processed through Apple’s App Store and StoreKit. Apple processes your Apple Account, payment method, billing information, and the payment itself. We do not receive your full payment-card or bank details.
StoreKit makes the transaction and entitlement information required to unlock and manage your purchase available to the app. This can include the product identifier, transaction identifiers, purchase and expiration dates, subscription and renewal status, and information about revocation or refunds. Subs uses this information only to verify and provide the purchased app features. The legal basis is Article 6(1)(b) GDPR.
Apple is responsible for the App Store payment processing under its own terms and privacy information. Purchases can be restored and subscriptions can be managed or cancelled through your Apple Account. Deleting Subs does not automatically cancel an App Store subscription.
Apple privacy policyApp Store and iTunes Store privacy information
7. Export, retention, and deletion
Export
When you use an export function, the export is created on your device and passed to Apple’s system share interface. You decide whether and where to save it or which person or app receives it. We do not receive a copy. Once shared, the privacy practices of the selected destination apply.
Retention and deletion
- Local app data remains on your device until you delete individual entries, delete all relevant data in the app, or remove the app and its local data.
- When a synchronized subscription entry is deleted in Subs, the deletion is synchronized through private CloudKit. iCloud data may also be managed and deleted through your Apple iCloud storage settings. Merely deleting the app from one device does not necessarily delete data already stored in iCloud.
- Exports remain wherever you chose to save or share them and must be deleted there separately.
- Apple retains App Store transaction data under its own legal obligations and retention rules. Logo.dev applies the retention criteria described in section 5.
If you contact us for support, we process your email address, message, and the technical information you provide to answer your request (Article 6(1)(b) GDPR or, for general inquiries, Article 6(1)(f) GDPR). We delete support correspondence when it is no longer needed for the request unless statutory retention duties or the establishment, exercise, or defense of legal claims require longer retention.
Because we have no direct access to data stored only on your device or in your private iCloud database, we cannot export or erase that data for you through a support request. You remain able to manage it in the app and in your iCloud settings.
8. No analytics, advertising, or tracking
Subs does not include analytics, advertising, or cross-app tracking SDKs. We do not create advertising profiles, access Apple’s advertising identifier for tracking, sell personal data, or share personal data for behavioral advertising. Operational information processed independently by Apple for iCloud and the App Store, and the technically necessary Logo.dev request data described above, are not used by us to analyze your use of Subs.
9. Recipients and international transfers
Subs has no developer-operated backend for the app data described above. Recipients are limited to Apple for private iCloud/CloudKit synchronization and StoreKit purchases, and Logo.dev for logo requests. Data you export is additionally disclosed to the destination you choose.
For users in the EEA, Apple identifies Apple Distribution International Limited in Ireland as the controller for Apple personal data. Apple states that international transfers are governed by Standard Contractual Clauses. The exact Apple entity and terms may vary by country and service.
10. Your rights
Where the GDPR applies, you may have rights to access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection to processing based on legitimate interests (Article 21). You may also lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the alleged infringement.
To exercise rights concerning data that we can access, contact us at the email address above. Rights concerning Apple data can be exercised through Apple’s privacy portal; Logo.dev provides contact details in its privacy policy. There is no automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR.
Our competent supervisory authority is:
Bavarian State Office for Data Protection Supervision (BayLDA)Promenade 1891522 AnsbachGermany11. Changes to this privacy policy
We may update this policy when the app, its data flows, or legal requirements change. The version published at this permanent address states its current revision date. Material changes will be communicated in an appropriate manner.