Privacy

Your inbox stays yours.

The plain-English version of what we collect, why, on what legal basis, how long we keep it, and your rights under UK GDPR.

Last updated · 29 July 2026

01

Who we are

Subzero.money is a trading name of Saigo Limited ("Subzero", "we", "us"), a company registered in England and Wales under company number 15603435. We are the data controller for personal data processed through subzero.money and the Subzero web app.

  • Registered office: 3b Lockheed Court, Preston Farm Industrial Estate, Stockton-on-Tees, England.
  • Companies House number: 15603435.
  • Contact: privacy@subzero.money for anything data-protection related.
02

What we collect and why

Data
Account data — name, email address, avatar (from Google).

Purpose

Create your Subzero account, sign you in, keep the app secure.

Legal basis

Contract (Art. 6(1)(b) UK GDPR).
Encrypted OAuth tokens for Gmail (and, in future, Microsoft Outlook).

Purpose

Scan your inbox for subscription receipts on your behalf. Read-only scope.

Legal basis

Contract (Art. 6(1)(b)).
Extracted subscription evidence — merchant, plan, price, renewal date, currency.

Purpose

Show you every subscription you're paying for and help you cancel.

Legal basis

Contract (Art. 6(1)(b)).
Product analytics — anonymous visitor + session IDs, page views, referrer, viewport, timezone, coarse IP.

Purpose

Understand how the site is used and diagnose bugs. Only collected if you opt in.

Legal basis

Consent (Art. 6(1)(a)).
Service emails — sign-in links, sync updates, invite confirmations.

Purpose

Deliver the service you've asked for.

Legal basis

Contract (Art. 6(1)(b)).
Support correspondence.

Purpose

Answer your questions and improve Subzero.

Legal basis

Legitimate interests (Art. 6(1)(f)) — running a support desk.
Referral codes and attribution.

Purpose

Credit the friend who invited you.

Legal basis

Consent (Art. 6(1)(a)) — the referral cookie is only set once you opt in to marketing cookies.

We do not read personal email content. Our extractor only inspects messages that look like receipts, and it stores structured fields, not the message body.

03

What we never do

  • We do not sell your data.
  • We do not share it with advertisers or data brokers.
  • We do not use your inbox contents to train AI models.
  • We do not scan for anything other than receipt-shaped emails.
04

Where your data lives

Personal data is stored in the European Union on infrastructure operated by our processors (see subprocessors below). Data is encrypted in transit (TLS) and at rest. Access is scoped to the systems that need it to keep Subzero running, and every row is fenced from other accounts by row-level security.

05

Subprocessors

Provider
Supabase (via Lovable Cloud)

Role

Database, authentication, encrypted token storage

Region

EU (Frankfurt)
Cloudflare

Role

Edge hosting, DNS, DDoS protection

Region

Global CDN, EU primary
Google (Gmail API)

Role

Read-only inbox access on your instruction

Region

Global (SCCs)
Microsoft (Graph API)

Role

Read-only inbox access on your instruction (planned)

Region

Global (SCCs)
Google Gemini via Lovable AI Gateway

Role

Structured extraction of receipt fields

Region

US / EU (SCCs)
Resend (via Lovable Cloud)

Role

Transactional email delivery

Region

EU / US (SCCs)
06

International transfers

Where a subprocessor may process data outside the UK / EEA (for example, US-based AI providers), transfers rely on the UK International Data Transfer Addendum together with the EU Standard Contractual Clauses, plus supplementary technical measures (encryption, minimisation, access controls). A copy of the relevant transfer mechanism is available on request.

07

How long we keep it

Data
Account and profile

Retention

For the life of your account; deleted within 30 days of account closure.
OAuth tokens

Retention

Until you disconnect the account, or 30 days after last successful use — whichever comes first.
Extracted subscription rows

Retention

For the life of your account, or until you delete individual items.
Analytics events

Retention

Up to 90 days at row level, then aggregated.
Session records

Retention

Up to 180 days.
Support email threads

Retention

Up to 24 months.
Backups

Retention

Rolling 30-day encrypted backups; overwritten on schedule.
08

Cookies

We use a small set of first-party cookies. Non-essential cookies are only set with your consent. See the cookie policy for the full list, or open to change your mind.

09

Your rights

Under UK GDPR you have the right to:

  • Access a copy of your personal data.
  • Rectify anything that's inaccurate.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing.
  • Port your data to another service in a machine-readable format.
  • Withdraw consent for anything based on consent, at any time.

Most of these are one click away in Settings. For anything else, email privacy@subzero.money and we'll respond within 30 days.

10

Complaints

If you think we've mishandled your data, please talk to us first — but you also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113.

11

Automated decisions and profiling

Subzero uses AI to extract structured fields from receipt-shaped emails. This is not a decision that produces legal or similarly significant effects for you — it's a labelling step you can override, correct or delete at any time.

12

Children

Subzero is not directed at children under 16. If you believe a child has created an account, please contact us and we'll remove it.

13

Changes to this policy

Material changes are announced by email at least 14 days before they take effect. The current version is dated at the top of this page.

14

Contact

privacy@subzero.money — for anything you want us to change, remove or clarify.