Disney+N

subsswitch

Stop overpaying for
subscriptions

Privacy Policy

Last updated: July 21, 2026

Controller / Operator: Q-CONSULT MARKETING LTD

Registered address: 187, Office 1, Level 3, Triq Nazju Ellul, Gzira Malta

VAT: MT28140713

This Privacy Policy explains how Q-CONSULT MARKETING LTD ("Q Consult", "we", "us", "our") collects, receives, accesses, uses, stores, discloses, deletes and otherwise processes personal data in connection with SubSSwitch, including the website at subsswitch.app, the SubSSwitch mobile application, user account portal, integrations, communications and support services (together, the "Service").

We are the controller of personal data processed for the purposes described in this Privacy Policy, except where another party acts as an independent controller under its own terms and privacy notice, for example your bank, email provider or a third-party merchant that you choose to access through an affiliate recommendation.

This Privacy Policy is intended to satisfy transparency requirements under the General Data Protection Regulation (Regulation (EU) 2016/679), the Maltese Data Protection Act (Chapter 586 of the Laws of Malta), the Google API Services User Data Policy including Limited Use requirements, and applicable Maltese and EU data protection laws.

1. Controller and Contact Details

Controller: Q-CONSULT MARKETING LTD

Registered address: 187, Office 1, Level 3, Triq Nazju Ellul, Gzira Malta

VAT: MT28140713

Privacy contact: privacy@subsswitch.app

General support: support@subsswitch.app

We have not appointed a statutory Data Protection Officer unless and until an assessment determines that appointment is legally required. Privacy queries and data subject rights requests should be sent to privacy@subsswitch.app.

2. Summary of Our Privacy Commitments

  • We use personal data only for defined, disclosed and lawful purposes.
  • Bank connections, bank statement uploads and email inbox scanning are optional features. Each data source requires a separate affirmative user action. Where personal data is transmitted to a third-party AI provider, we obtain separate explicit permission before the transmission.
  • We do not initiate payments, transfers or withdrawals.
  • We do not sell or rent personal data.
  • We do not use bank, Gmail, Outlook, iCloud or statement data for third-party advertising. We never request or store the primary password for your Apple Account. If you connect iCloud Mail using an App-Specific Password, we use that credential only to maintain the email connection selected by you.
  • We do not use Gmail, Outlook, iCloud, bank or statement data to train AI or machine-learning models.
  • We minimise raw source data, apply filtering before AI processing where feasible, and retain only the data needed to provide the Service or meet legal/security obligations.
  • We use anonymised or aggregated data for analytics where individuals are no longer identifiable; where data remains capable of re-identification, we treat it as personal data.
  • We use processors only under appropriate contractual and technical safeguards.

3. Personal Data We Process

CategoryExamplesSourcePurpose
Account dataName, email address, account ID, login method, account status, password hash where email/password login is used.Provided by user or received from Google/Apple authentication.Create and manage Account, authenticate user, provide support, secure Service.
Subscription dataMerchant name, billing amount, currency, billing cycle, renewal date, category, subscription status, notes.Entered by user or detected from connected data sources.Provide dashboards, reminders, insights and subscription history.
Bank transaction dataMerchant, amount, date, account identifier/token, category, transaction description, recurring patterns.Plaid after user authorisation.Detect recurring subscriptions and provide Service.
Uploaded bank statementsCSV, Excel, OFX, QFX, PDF or other supported statement files and extracted text/transaction lines.Uploaded by user.Extract subscription-related transactions; support detection and troubleshooting.
Email inbox dataSender, subject, date, limited body excerpts, merchant identifier, amount, renewal/billing terms from subscription-related emails.Gmail, Outlook/Microsoft 365 or iCloud Mail after separate user consent.Detect subscription confirmations, receipts, renewal notices and cancellation notices.
Screenshot / import dataScreenshots or lists of subscriptions uploaded by the user; extracted merchant/amount/date fields.Uploaded by user.Import and structure subscription records.
AI processing inputs and outputsMinimised email excerpts, transaction lines, screenshot content, extraction prompts, extracted subscription fields.Generated through use of AI-assisted extraction.Classify and extract subscription information.
Usage and device dataPages/screens visited, feature usage, session duration, device/browser type, country-level location, error events.Generated by use of Service.Security, troubleshooting, analytics, product improvement and abuse prevention.
Communications dataSupport emails, requests, complaints, preferences and related correspondence.Provided by user or generated through support interactions.Respond to requests, keep records, comply with obligations.
Security and log dataIP address, timestamps, authentication logs, access logs, system events, token activity, audit logs.Generated by infrastructure and Service.Security monitoring, fraud prevention, incident response and troubleshooting.
Email connection credentialsOAuth access and refresh tokens, provider account identifiers, and iCloud App-Specific Password/IMAP credentialsUser and connected email providerAuthenticate the connection, maintain authorised inbox access and stop access when disconnected

4. Optional Features and Separate Consents

The following features are optional. Declining them does not prevent you from using manual subscription-management features, although it may limit automatic detection functionality.

FeatureUser action requiredCan be withdrawn?Effect of withdrawal
Bank connectionUser authorises connection via supported provider.Yes.Automatic bank-based subscription detection stops; previously extracted subscription records may remain unless deleted.
Bank statement uploadUser uploads a file.Yes, by deletion request or account deletion.Uploaded file and extracted data are deleted according to retention/deletion rules; future statement-based detection stops.
Email inbox scanningSeparate affirmative opt-in for each connected email account before inbox access begins.Yes, through Settings → Connected Accounts.Future inbox scanning stops and the stored OAuth token, App-Specific Password or other email connection credential is deleted from active systems. Previously extracted subscription records remain until deleted by the user or in accordance with the retention rules.
AI-assisted extractionSeparate explicit opt-in is obtained before any email data, bank-statement-derived transaction data, screenshot or other personal data is transmitted to a third-party AI provider.Where based on consent, yes.Future transmission to the AI provider stops. Manual subscription management and any non-AI features remain available.
Analytics cookiesCookie banner consent.Yes.Non-essential analytics are disabled.
Affiliate recommendationsDisplayed in Service; click/action is voluntary.Not applicable to display where necessary for Service, but users may choose not to click.No third-party sign-up or merchant interaction occurs unless user acts.

5. How We Use Personal Data and Legal Basis

PurposeData usedLegal basis under GDPR
Account creation, login and account managementAccount data, authentication data, security logs.Performance of contract; legitimate interests in account security; legal obligation where applicable.
Manual subscription managementManual subscription data and related account data.Performance of contract.
Bank-based subscription detectionRead-only bank transaction data received through Plaid, or supported provider.User consent/authorisation for connection and performance of contract to provide the requested feature.
Bank statement extractionUploaded statement file and extracted transaction lines.Performance of contract and user consent for optional upload/processing.
Email inbox scanningLimited email data from connected account.Consent under Article 6(1)(a) GDPR for connecting the email account and conducting ongoing inbox scanning requested by the user.
AI-assisted extractionMinimised excerpts, transaction lines, screenshots and extracted fields.Consent under Article 6(1)(a) GDPR for transmitting personal data to the disclosed third-party AI provider. Performance of contract may apply to the subsequent storage and display of the subscription information extracted at the user's request.
Affiliate recommendationsManually entered subscription data, merchant/category, price and user preferences. Gmail-, Outlook-, iCloud Mail-, bank- and bank-statement-derived data are not used to personalise affiliate recommendations.Legitimate interests in operating the free/freemium Service and offering relevant alternatives, subject to transparency and user control; performance of contract where recommendations are part of requested Service.
Service communicationsEmail address, account status, system events.Performance of contract; legitimate interests; legal obligation for required notices.
Security, fraud prevention and abuse preventionSecurity logs, IP address, access records, token activity, system events.Legitimate interests in protecting users, systems and Service; legal obligation where applicable.
Analytics and product improvementUsage data; anonymised or aggregated analytics where possible.Consent for non-essential cookies/analytics; legitimate interests for strictly necessary service diagnostics and aggregated/anonymised analysis.
Compliance with laws and regulatory requestsRelevant account, transaction, log and communication data.Legal obligation; establishment, exercise or defence of legal claims where applicable.

6. Bank Data and Open Banking Providers

If you connect a bank account, the connection is provided by Plaid Financial Ltd. Plaid Financial Ltd. may act as an independent controller or processor depending on the feature and its applicable terms. Its services are subject to its own terms and privacy notice.

We receive read-only transaction and account information necessary for subscription detection. We do not initiate payments, transfers or withdrawals. We use bank transaction data exclusively to identify and display recurring subscription charges, track subscription history and provide related features.

Bank transaction data may reveal sensitive inferences about spending habits, health, beliefs, lifestyle, family relationships, employment, financial position or other private matters. We therefore apply enhanced access controls, data minimization and retention limits.

7. Bank Statement Uploads

If you upload a bank statement file, the file is encrypted at application layer using AES-256-GCM before storage. Files are stored in our own database hosted in the European Union, currently Railway, EU West / Amsterdam region, running on Google Cloud Platform europe-west4, subject to vendor configuration and updates.

Uploaded files are not stored in public URLs and should be accessible only through authenticated API endpoints after ownership checks. We process the uploaded statement file within SubSSwitch systems to extract subscription-related transaction data. The bank statement file itself is not sent to the third-party AI provider. Only extracted subscription-related transaction data, such as merchant, amount and date, may be transmitted to the AI provider after the required user permission has been obtained. Account balances, account numbers, personal identifiers and non-subscription transactions are not sent to the AI provider.

Uploaded bank statement files are deleted 90 days after upload unless deleted earlier through account deletion or a valid erasure request. Extracted subscription transactions are retained according to the retention table below.

8. Email Inbox Scanning

Inbox scanning is optional and separate from account login. It requires an active user choice and, where applicable, provider OAuth authorisation or app-specific password configuration.

  • Gmail: accessed through Google OAuth using the gmail.readonly scope or another limited scope if later substituted.
  • Outlook/Microsoft 365: accessed through Microsoft Graph API.
  • iCloud Mail: accessed through an App-Specific Password / IMAP where offered. We do not request or store the primary password for your Apple Account. The connection provides technical access to all emails in the connected iCloud Mail mailbox. SubSSwitch does not process every email. We use automated filtering to identify emails that are potentially relevant to subscriptions and process only those relevant emails for subscription detection and extraction.

We filter inbox data for subscription-related patterns such as merchant senders, receipt markers, renewal keywords and transactional email indicators. We do not store full email content, attachments or full headers in the production database. We store only extracted subscription metadata required to display and manage subscriptions.

Because inboxes may contain third-party data and potentially sensitive information, access is restricted to automated extraction and strict operational controls. Routine human reading of inbox data is prohibited.

9. Google API Services User Data Policy and Limited Use

Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use requirements.

  • We use Gmail data only to provide or improve user-facing subscription-management features that are prominent in the Service.
  • We do not use Gmail data for serving ads, retargeting, personalised advertising, or third-party marketing.
  • We do not sell Gmail data or transfer it to data brokers, information resellers or advertising platforms.
  • We do not use Gmail data to train generalised AI or machine-learning models.
  • We transfer Gmail-derived data only to processors necessary to provide the Service, including AI extraction under strict data minimisation and contractual controls, and only as described in this Privacy Policy.
  • Humans do not read Gmail data except where the user gives specific consent for support, where necessary for security or abuse investigation, or where required by law.

10. AI Processing

We may transmit limited subscription-related data to Anthropic PBC or another disclosed AI processor for extraction and classification, after obtaining the user's separate explicit permission. AI processing is used to identify, classify and organise subscription-related information.

  • Emails: sender, subject and a relevant excerpt of the message body of up to approximately 1,400 characters may be transmitted for extraction. Full emails, attachments and full email headers are not sent to the AI provider.
  • Bank statements: the uploaded statement file is processed within SubSSwitch systems and is not transmitted to the AI provider. Only extracted subscription-related transaction data, such as merchant, amount and date, may be transmitted. Account balances, account numbers, personal identifiers and the statement file itself are not sent to the AI provider.
  • Screenshots: subscription-related screenshots uploaded by the user may be transmitted for extraction. Screenshots should be processed in memory where feasible and not retained unless necessary for the feature and disclosed to the user. Data transmitted to Anthropic may be retained by Anthropic for up to 30 days in accordance with the applicable provider terms and data processing arrangements.

AI providers must be contractually prohibited from using API-submitted personal data to train their general models. The current policy is no AI model training from Gmail, Outlook, iCloud, bank or statement data.

AI processing may take place in the United States or other third countries. Transfers are governed as described in the International Transfers section.

11. Data Minimisation, Pseudonymisation and Anonymisation

We collect, access and retain only the data reasonably necessary for the feature selected by the user. Raw Source Data should be processed transiently and reduced as soon as technically feasible to Extracted Subscription Data.

Where technically feasible, analytics and operational reports should use anonymised or aggregated data that no longer identifies users. If data can still be attributed to a user by using additional information, it is pseudonymised rather than anonymised and remains personal data subject to GDPR.

Subscription dashboards remain linked to the Account because the user needs to view and manage their own subscription records. Analytics, product metrics, affiliate reporting and management dashboards should be anonymised or aggregated unless identifiable data is strictly necessary and authorised.

12. Recipients and Sub-Processors

We disclose personal data only where necessary for the Service, where legally required, or where the user chooses to interact with a third-party service. Current sub-processors and relevant third-party providers include:

ProviderRoleLikely location / transfer note
Railway CorporationHosting infrastructure; EU West / Amsterdam region running on Google Cloud Platform europe-west4.EU hosting; operational support may involve US-based personnel/sub-processors.
Plaid Financial Ltd.Open banking/account information connection.UK/EU/US depending on account and provider terms; safeguards required.
Anthropic PBCAI-based extraction/classification.United States; SCCs/DPF and supplementary measures required.
Google LLCSign in with Google, Gmail OAuth access, Firebase Analytics if consented, cloud subprocessing through Railway.EU/US/global; DPA/SCCs/DPF as applicable.
Microsoft CorporationOutlook/Microsoft 365 integration.EU/US/global; DPA/SCCs/DPF as applicable.
Apple Inc.Sign in with Apple and iCloud Mail integration where enabled.EU/US/global; DPA/SCCs/DPF as applicable.
Resend, Inc.Transactional email delivery.United States; DPA/SCCs/DPF as applicable.
Merchants / affiliate partnersOnly where user clicks or signs up through a recommendation.Independent controllers under their own terms and privacy notices.

We do not sell or rent personal data. We do not disclose personal data to third-party advertisers for their own advertising purposes.

13. International Transfers

Our primary production infrastructure is intended to be hosted in the European Union. Some providers or their support teams may be based in the United States or other third countries. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as EU Standard Contractual Clauses, Data Processing Agreements, the EU-US Data Privacy Framework where applicable, transfer risk assessments and supplementary technical measures including encryption, access controls and data minimisation.

We do not disclose email-derived, bank-derived or bank-statement-derived data to affiliate partners.

Users may request further information about applicable transfer safeguards by contacting privacy@subsswitch.app, subject to confidentiality and security limits.

14. Data Retention

Data categoryRetention period / criterion
Account dataFor the life of the Account and deleted upon account closure, subject to legal, security, backup and dispute-retention limits.
Manual subscription dataFor the life of the Account unless deleted earlier by the user or through account deletion.
Extracted subscription and bank transaction dataUp to 12 months for subscription history unless the user deletes it or closes the Account earlier, subject to backup rotation and legal/security retention.
Uploaded bank statement filesDeleted 90 days after upload by automated job unless deleted earlier through account deletion or valid erasure request.
Email message contentNot stored in the production database; processed transiently for extraction. Extracted subscription metadata may be retained according to subscription-data retention.
AI prompts and outputsAI inputs and outputs transmitted to Anthropic may be retained by Anthropic for up to 30 days in accordance with the applicable provider terms and data processing arrangements. Personal data transmitted by SubSSwitch to Anthropic is not used to train Anthropic's general AI models. Extracted subscription data retained by SubSSwitch is subject to the applicable retention periods described in this section.
Screenshots uploaded for importProcessed for extraction and not retained unless required for the feature and disclosed in the relevant user flow.
Application and access logsUp to 6 months for security, troubleshooting and audit purposes unless longer retention is required for security incident investigation, legal claims or legal obligations.
Support communicationsAs long as necessary to respond and maintain records, generally up to 24 months unless legal reasons require longer retention.
BackupsEncrypted backups and point-in-time recovery snapshots may persist for the hosting provider's standard backup window before being overwritten in the normal rotation. Deleted data may remain in backups temporarily but is not restored to production except for continuity/security reasons.
Anonymised/aggregated analyticsMay be retained indefinitely where individuals are no longer identifiable.
Email connection credentialsRetained only while the relevant email account remains connected. Deleted from active systems when the user disconnects the account or deletes their SubSSwitch account.

15. Security Measures

  • TLS 1.2 or higher for data in transit between user device, Service and processors.
  • Inter-service traffic protection within hosting infrastructure where supported, including WireGuard or equivalent provider-level controls.
  • Database-level encryption at rest by hosting provider.
  • Application-level AES-256-GCM encryption for sensitive fields including OAuth tokens, access/refresh tokens and IMAP credentials where stored.
  • Application-level encryption for uploaded files before database storage.
  • Passwords stored using one-way hashing, currently bcrypt with appropriate cost factor; no reversible password storage.
  • Need-to-know access restrictions for production systems and personal data.
  • Two-factor authentication for administrative access to hosting, repositories and critical tools.
  • Access logging, audit logging and review of privileged access.
  • Segregation of duties and separate handling of production data and development/testing environments.
  • Regular review, testing and evaluation of technical and organisational measures.
  • Incident response process and breach assessment workflow.

16. Account Deletion and Revoking Access

You may delete your Account through Settings → Delete Account where available or by contacting support@subsswitch.app. You may exercise data protection rights by contacting privacy@subsswitch.app.

When your Account is deleted, we delete active production account data and associated records, revoke supported third-party connections where programmatically possible, delete stored tokens and credentials, and delete uploaded files stored in our database. Deletion is subject to backup rotation, legal obligations, security-retention requirements and any lawful retention required for dispute handling or compliance.

  • Google/Gmail access: may be revoked through Google permissions at https://myaccount.google.com/permissions.
  • Microsoft/Outlook access: Microsoft may require manual revocation at https://account.live.com/consent/Manage if programmatic revocation is unavailable.
  • Apple/iCloud access: app-specific passwords may be revoked through account.apple.com → Sign-In and Security → App-Specific Passwords.
  • Plaid: disconnect through SubSSwitch connected-account settings where available or through my.plaid.com.

Disconnecting a connected service stops future access to data from that service. It does not automatically delete subscription information previously extracted and stored by SubSSwitch. You may delete that data separately or request deletion in accordance with this Privacy Policy.

17. Your GDPR Rights

Subject to applicable legal conditions and exemptions, you have the following rights:

  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing based on legitimate interests.
  • Right to withdraw consent at any time where processing is based on consent.
  • Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects, unless lawful conditions are met.
  • Right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta or another competent EU supervisory authority.

Requests should be sent to privacy@subsswitch.app. We will normally respond within one month of receipt. Where a request is complex or numerous requests are made, the period may be extended in accordance with GDPR. We may request information to verify your identity before acting on a request.

18. Automated Processing and Profiling

The Service uses automated processing to detect recurring payments, classify merchants, estimate renewal dates and display recommendations. This processing is intended to assist the user and does not itself cancel subscriptions, initiate payments, bind the user to third-party services, determine eligibility for credit, insurance, employment, housing or public benefits, or produce legal effects concerning the user.

Users remain responsible for reviewing and confirming detected information and deciding whether to cancel, switch or subscribe to third-party services.

19. Cookies and Analytics

We use essential cookies and similar technologies for authentication, security, session management and Service operation. Essential cookies do not require consent where strictly necessary.

We use analytics cookies or similar analytics technologies, including Google Firebase Analytics where enabled, only after user consent through the cookie banner or consent mechanism. Analytics is disabled until accepted, and users may decline or withdraw consent at any time. We do not use advertising cookies unless this Privacy Policy and the cookie notice are first updated and valid consent is obtained where required.

20. Children

The Service is intended for users aged 18 and above. We do not knowingly collect or process personal data of persons under 18. If we become aware that such data has been collected, we will delete it unless another lawful basis requires retention.

21. Data Breaches

We maintain an incident response process. Where a personal data breach occurs, we will assess the risk to affected individuals and notify the competent supervisory authority and/or affected users where required by GDPR and applicable law.

22. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice at least 30 days before taking effect where practicable, unless earlier implementation is required for legal, security, provider or urgent operational reasons. The "Last updated" date above indicates the current version.

23. Contact and Supervisory Authority

Q-CONSULT MARKETING LTD
187, Office 1, Level 3, Triq Nazju Ellul, Gzira Malta

Privacy matters: privacy@subsswitch.app. General support: support@subsswitch.app.

Maltese supervisory authority: Office of the Information and Data Protection Commissioner (IDPC), Malta, idpc.org.mt