Privacy Policy
Last updated: May 2026
Overview
SubZero is a browser-based subscription audit tool. Your financial data never leaves your device. We are not a bank, financial service, or data broker. The only personal information we hold is your email address — and only if you provided it at purchase.
What We Collect
Email address — collected at purchase for access restore purposes only. Optional: you can complete a purchase without providing an email, but you will not be able to restore access if you clear your browser.
Payment data — processed directly by Stripe. SubZero never touches your card number, billing address, or payment credentials. We receive your payment confirmation and email address from Stripe. Your email address is stored securely in our database solely to enable access recovery through the /restore page. We do not use it for marketing.
What We Explicitly Do Not Collect
- ×Bank statement contents
- ×PDF file contents
- ×Transaction strings or amounts
- ×Camera images or OCR output
- ×Bank account numbers or credentials
- ×Any financial data of any kind
Your statement is processed entirely in your browser using pdf.js and Tesseract.js. Zero bytes of your financial data are transmitted to any server at any time.
Browser Storage
SubZero stores the following data in your browser's local storage. This data never leaves your device.
subzero-unlocked— confirms a valid purchase existssubzero-session-id— the Stripe session ID used to verify accesssubzero-purchase-date— the date your purchase was confirmedsubzero-dismissed-install— remembers if you dismissed the install promptHow Local Processing Works
- 01pdf.js reads your PDF in browser memory only
- 02Tesseract.js processes images in browser memory only
- 03Matching runs against an embedded vendor database in your browser
- 04Nothing is uploaded to any server
- 05Nothing is stored on our servers
- 06When you close the tab, the data is gone
Third-Party Services
Your payment is handled directly by Stripe. SubZero receives your payment confirmation and the email address you provide at checkout. Your email is stored securely to enable access recovery via /restore. No card number, billing address, or payment credential touches our servers.
stripe.com/privacy →Stores your email address and a session token to verify your purchase. No financial data is stored.
supabase.com/privacy →Used to send access restore links when you request them. We send no marketing emails.
resend.com/privacy →Hosts the SubZero application. Basic anonymous analytics (page views, performance). No personal data collected at the hosting level.
vercel.com/legal/privacy →Data Retention
Email address: Retained until you request deletion.
Session token: Retained to verify your lifetime access.
All other data: Never collected, never retained.
Your Rights (CCPA)
You have the right to access or delete the data we hold about you at any time.
To delete your data: Navigate to www.subzeroapp.io/restore?action=delete
Or email: privacy@subzero.so
We will confirm deletion within 48 hours.
Contact
For privacy questions or data requests: privacy@subzero.so
Changes to This Policy
We will notify users of material changes via email if we have your address on file. The date at the top of this page reflects the most recent update.