Renewal Radar

Privacy

Last updated: 23 August 2026

Before launch: replace [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [JURISDICTION] and the placeholder support address below with the operator's real details. This document is not legal advice and has not been reviewed by a lawyer.

Renewal Radar is a subscription-tracking tool operated by [LEGAL ENTITY NAME] (“we”, “us”). You upload a CSV export of a card or bank statement; the app groups the recurring charges it finds, predicts when each one renews, and flags amounts that have moved. This policy describes what that means for your data. It covers the Renewal Radar web application and nothing else.

1. What we collect

Account details. Your name, your email address, the name of your workspace, and your interface language. Your password is never stored in a readable form — only a salted scrypt hash of it, which cannot be turned back into the password.

Transaction rows parsed from your uploads. For every row we read out of a CSV you upload we keep the transaction date, the description text exactly as your bank wrote it, the amount, the currency, and — only when your export contains them — the account name and the last four digits of the card. Those fields are the whole of what the parser looks at.

The corrections and notes you enter. Vendor renames and merges, forced billing cadences, category changes, seat and active-user counts, savings-ledger entries, and any free-text notes you write. These are kept so the app can replay them against future uploads instead of asking you to fix the same vendor twice.

2. What we never collect

No bank or card login credentials. No OAuth tokens and no read access to any financial account. No full card numbers — the last four digits are the most that can ever reach us, and only because your own export already contains them. We never ask you to connect an account, and the application has no code path that could use such a connection.

3. The original uploaded file

By default the CSV file you uploaded is retained so that analysis can be re-run without asking you to upload it again. You can switch this off for a workspace under Settings → Data & privacy. With it off, only the parsed transaction rows described above are kept and the original file is discarded once parsing finishes.

4. Where your data is stored

All of it lives in a single SQLite database file on the server we operate. We do not sell it. We do not share it with advertisers, data brokers, analytics vendors, or any other third party, with one exception, described next.

5. Stripe

Payments are processed by Stripe. When you subscribe to a paid plan you enter your billing details on Stripe's own checkout and customer portal pages: those details go to Stripe directly, and this application never sees or stores a card number. What we receive back and store is a Stripe customer identifier, a subscription identifier, the plan, its status, and the next renewal date — enough to know what your workspace is entitled to. Stripe's own privacy policy governs what Stripe does with the payment details you give it.

6. Deleting your data

Deleting a workspace deletes that workspace's transactions, its detected subscriptions, and its savings-ledger entries, together with the uploads, correction rules, and saved CSV layouts that belong to it. The deletion is immediate and cannot be undone, so export first if you want a copy.

7. Exporting your data

You can export everything in your workspace as CSV at any time from Settings → Data & privacy. There is no request form and no waiting period.

8. Changes to this policy

If we change how data is handled in a way that affects you, we will update the date at the top of this page and notify workspace owners by email before the change takes effect.

9. Contact

Questions about your data, or a request to have it deleted: support@example.com (placeholder — replace with the operator's real support address before launch).