STAGING · TEST MODE This is a staged prototype. Not a live product. The demo uses synthetic sample data only.

Staged policy

Privacy

Your bank statement is about as sensitive as data gets. Here's exactly what SubZap would — and wouldn't — do with it.

What we collect

To run a scan, SubZap needs your transaction data — a statement export (CSV) or receipt scan. That's it. No account logins, no bank credentials.

What we use it for

Statement uploads are used only to detect your subscriptions and flag trap patterns. Detection results are shown to you and used to generate cancellation letters you choose to send.

What we never do

  • We never sell your data — not to advertisers, data brokers, or anyone.
  • We never share your statement with merchants.
  • We never contact merchants on your behalf.
  • We never use your data for credit, lending, or insurance decisions.

Retention

Design commitment: scans are processed and the raw statement is deletable at any time from your account — a subscription killer shouldn't hold your data hostage. Production retention and Australian data-residency policy would be finalised before launch.

Staging note: this prototype processes no real statements. The demo scan runs on synthetic sample data. This page describes design commitments for a production service, which would need Australian Privacy Principles (Privacy Act 1988) compliance work — including a solicitor-reviewed policy — before touching real data.

Contact

Questions about this policy: hello@example.com