Privacy Policy — Submint: Subscription Tracker
This Privacy Policy explains how Submint: Subscription Tracker ("Submint", "the app", "we") handles your information. Submint is developed by "Rhythm Themes" ("the developer", "we", "us").
Submint is a privacy-first, on-device application. The guiding principle of this policy is simple: your data stays on your device.
🔒 Prominent disclosure: how Submint uses SMS
Submint accesses the SMS messages on your device (with the
RECEIVE_SMSandREAD_SMSpermissions) for one purpose only: to detect recurring subscriptions from your bank and UPI transaction alerts, on your device.
- SMS messages are read and parsed entirely on your device.
- The content of your SMS messages is never transmitted, uploaded, sold, or shared with the developer or any third party. It never leaves your phone.
- Submint only looks for transactional information (merchant/payee name, amount, date, and any renewal/expiry date) in bank and payment alerts. It does not read, store, or transmit personal messages for any other purpose.
- Submint does not use SMS or Call Log data for any purpose other than the core app functionality described here, and does not sell or share this data.
This disclosure is provided to comply with Google Play's Permissions policy for SMS access. You can revoke SMS access at any time (see Your controls below); the app continues to function on the data already detected.
📥 1. What data Submint accesses
a) SMS messages (RECEIVE_SMS, READ_SMS). Used to detect subscriptions from bank/UPI transaction alerts. Parsing happens on-device. From each relevant alert, the app may store — locally on your device only — the merchant/payee name, amount, currency, transaction date, any renewal/expiry date, the sender ID (e.g. "AD-HDFCBK"), and a short snippet of the message text kept for your own reference. Promotional and unrelated messages are filtered out and discarded.
b) App usage statistics (PACKAGE_USAGE_STATS — optional "special access"). If you grant it, Submint uses Android's Usage Access to read the last-opened time of the apps linked to your subscriptions, so it can flag subscriptions you appear to have stopped using. It reads only last-used timestamps for this purpose. This permission is optional — deny it and the rest of the app works normally.
c) Notifications (POST_NOTIFICATIONS). Used only to send you local renewal reminders. No content is sent anywhere.
🚫 2. What Submint does NOT do
- We do not collect, transmit, upload, or store your data on any server. There is no cloud database of your subscriptions. There is no developer account and no sign-in.
- We do not require your bank login, net-banking credentials, or any banking API. Submint never connects to your bank.
- No SMS content ever leaves your device.
- We do not sell or share your personal data with any third party.
- We do not use advertising or ad networks, and we do not track you across apps or websites.
📊 3. Analytics and crash reporting
Submint contains no third-party analytics and no crash-reporting SDKs. We do not use Google Analytics, Firebase Analytics, Firebase Crashlytics, or any comparable tool. No usage or diagnostic data is collected from the app.
[FILL if this ever changes: if you later add a crash reporter such as Firebase Crashlytics, name it here, state exactly what it collects (e.g. anonymised crash stack traces), that it is processed by Google, and update the Play Data Safety form accordingly.]
🗄️ 4. Data storage and retention
All data Submint creates — your detected subscriptions and their transaction history — is stored in a local database on your device (Android Room / your app's private storage) and in on-device app settings. It is never backed up to our servers because we have none.
- The data remains on your device until you delete it.
- Uninstalling Submint permanently deletes all of its local data.
- You can also clear the data at any time via Android Settings → Apps → Submint → Storage → Clear storage.
- Or clear it instantly in the app: Settings → Clear all data (this deletes all detected subscriptions and their transaction history).
💳 5. Payments (Submint Pro)
Optional premium features are unlocked through Google Play Billing. Submint does not see or store your payment details — all payment processing is handled by Google Play under Google's own terms and privacy policy. We receive only a signal from Google Play that indicates whether the premium entitlement is active.
⚙️ 6. Permissions and your controls
You are in control of every permission:
- SMS / Usage Access / Notifications can be granted or revoked at any time from Android Settings → Apps → Submint → Permissions (and Special app access → Usage access for usage stats).
- Revoking a permission does not delete data already stored on your device; use Clear storage or uninstall to remove it.
- The app is designed to degrade gracefully: denying optional permissions (usage access, notifications) never blocks core functionality.
🧒 7. Children's privacy
Submint is a general-purpose utility not directed at children under 13 (or the equivalent minimum age in your jurisdiction) and does not knowingly collect data from them. Because no data is collected off-device, no such data is processed by us in any case.
📝 8. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, noted in the app or store listing.
📧 9. Contact
Questions about this policy or your data: apps.rhythmthemes@gmail.com
No comments:
Post a Comment