Privacy Policy

Last updated

On this page

This Privacy Policy explains what subsonly (“subsonly,” “we,” “us”) collects, how we use it, and the choices you have. It applies to the subsonly website, apps, and services.

Our approach is simple: collect only what the product needs, keep it secure, never sell it, and give you real control. These aren’t vague promises — the mechanisms are built in.

1.What we collect

We collect only what’s needed to run the Service:

  • Account and auth data — your email and authentication details.
  • Profile content — the handle, bio, links, media, and posts you add.
  • Inbox data — conversations and the name and email a contact provides when they message you or send a request.
  • Deal and booking details — the information submitted through request and scheduling forms.
  • Usage and analytics — privacy-preserving, aggregate metrics (see below) and AI usage counts.

2.How we use it

We use this data to provide and secure the Service: to render your page, deliver messages, run scheduling, meter AI usage, prevent abuse, and improve the product. We don’t use your data for third-party advertising, and we don’t sell it.

4.Analytics

Our analytics are first-party and PII-free. We record coarse, aggregate signals — approximate country, referrer, and device type — to help creators understand their reach. We do not use third-party ad trackers, and we do not track you across other sites.

5.Cookies

We use only essential first-party cookies, primarily to keep you signed in and to secure your session. We don’t use advertising or cross-site tracking cookies, so there’s no third-party tracker following you around.

6.AI processing

AI features (such as message triage and reply drafting) process the relevant message content to generate a result, for in-product features only. We do not use your private message content to train third-party models, and AI usage is capped and metered. AI-assisted replies are always labeled as AI-generated.

7.Sharing and sub-processors

We don’t sell your personal data. We share it only with the infrastructure providers that power the Service, under agreements that limit their use of it to providing services to us:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and delivery.
  • Anthropic — the AI model that powers assisted drafting and triage.

We may also disclose data where required by law or to protect safety and rights.

8.Data retention

When you delete your account, your page goes offline immediately and your data is scheduled for deletion. We keep it for 45 days so you can change your mind — sign back in during that window to cancel — after which it is permanently erased, cascading across your profile, links, conversations, requests, bookings, and files.

Raw analytics events are kept for a bounded window and then exist only as aggregates that carry no personal information. Deleted data ages out of routine backups on the normal rotation; we don’t retain it indefinitely. Some data may be preserved longer where the law requires it.

9.Your rights

You have rights over your data, including under the GDPR and CCPA: to access it, to delete it, and to export it. Account deletion is built into the product, and you can reach us for access or export requests.

A fan or brand who messaged a creator can request deletion of their messages and personal information; we honor verified requests. To exercise any right, email us at support@subsonly.me.

10.Children

subsonly is not intended for children under 13 (or the higher minimum age where local law requires it). We don’t knowingly collect personal information from children under that age; if we learn we have, we’ll delete it. See also the eligibility section of our Terms of Service.

11.International data transfers

We operate on global cloud infrastructure, so your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for those transfers.

12.Security

Security is built into the architecture. Every creator’s data is isolated at the database level (row-level security), data is encrypted in transit, and sensitive secrets stay server-side and never reach the browser. No system is perfectly secure, but we design to minimize risk and to fail safe.

13.Changes to this policy

We may update this policy as the product evolves. When we make material changes, we’ll update the date at the top and, where appropriate, provide additional notice.

14.Contact us

Questions about your privacy or this policy? Email us at support@subsonly.me and we’ll help.

Back to top