This policy explains how Unsub collects and uses personal data when you visit unsub.cash, create an account, or use the service. It also explains the cookies and browser storage we use and your rights under the General Data Protection Regulation (GDPR).
1. Controller and contact
Unsub, based in Norway, is the controller for the processing described in this policy. You can contact us at privacy@unsub.cash.
2. Who this policy covers
Unsub is intended for consumers aged 18 or older in the European Economic Area. We do not knowingly permit people under 18 to create accounts. If you believe an underage person has provided personal data, contact us so we can investigate and delete it where appropriate.
3. Data we collect
Account and authentication data
- Name, email address, email-verification status, profile image, and account timestamps.
- Password hash, or Google account identifiers and authorization tokens if you use Google sign-in.
- Two-factor authentication secrets, backup codes, and related security state.
- Session tokens, expiry, IP address, browser or device information, and active-session history.
- Account role, onboarding state, and security restrictions.
- Date of birth while we check that you are at least 18. We use it only for the check and do not retain it. If the check passes, we store the completion time, the self-declared check method, the minimum age applied, and the applicable policy version.
For email registration, Unsub automatically derives a Gravatar URL using an unsalted MD5 hash of your normalized email address. This identifier may be matched against known email addresses. Loading the image causes your browser to contact Gravatar. Google and Gravatar process data under their own privacy terms.
Subscription and preference data
- Services, aliases, notes, start dates, trial details, statuses, and cancellation reasons.
- Plans, prices, currencies, billing cycles, price history, and projected or recorded transactions.
- Reminder settings, notification preferences, preferred currency, and delivery history.
- Generated statistics and projections based on the information in your account.
These records describe payments to third-party services. Unsub does not currently connect to your bank or process payments for those subscriptions.
Content and interaction data
- Custom services, cancellation-guide suggestions, edits, text, links, and uploaded images.
- Guide votes, review decisions, and contribution history.
- In-app notifications, read or archive state, delivery attempts, and provider responses.
- Support, privacy, export, deletion, and other messages you send to us.
Calendar data
If you create a calendar feed, we store a protected feed token, creation and last-use timestamps, and any revocation state. The feed may disclose subscription names, dates, prices, and currencies to anyone or any calendar provider with the private feed URL.
Technical and usage data
- IP address, user agent, requested pages, timestamps, referrer, and security events.
- Rate-limit records, operation status, diagnostic logs, and queued-job status or errors.
- Page URL, title, hostname, referrer, screen size, and browser language for web analytics.
- Aggregated service metrics such as operation results, environment, and currency pair.
CSV import data
If CSV import is made available, a file may include sensitive financial information such as transaction dates, amounts, currencies, descriptions, and counterparties. Unless the import screen states otherwise, Unsub will process the file only to identify recurring payments, will not store the raw CSV or a complete transaction list, and will retain only limited suggestion data and subscriptions you choose to keep. Do not include account numbers, card numbers, balances, or unrelated information where you can remove them before import.
Purchase data
If a paid import feature is offered, the checkout will identify the payment processor and the data required before collection. Unsub will receive purchase status, entitlement, and transaction references needed to provide support and meet accounting obligations. Payment card details will be handled by the identified payment processor, not stored by Unsub unless the checkout expressly says otherwise.
4. How we obtain data
We receive data directly from you, generate it through your use of Unsub, receive limited identity data from Google if you choose Google sign-in, and receive delivery or status data from providers that operate parts of the service. The age-attestation record is generated when your self-declared date of birth passes the eligibility check. Subscription projections are generated from the records you enter.
5. Why we process data and our legal bases
- Provide the service and perform our contract: create and secure your account, confirm that you meet the contractual minimum age, retain evidence that the check was completed, store subscription records, generate statistics, provide calendar feeds, deliver requested reminders, process imports, and provide purchased features.
- Legitimate interests: prevent abuse, maintain security and reliability, diagnose errors, understand aggregate service usage, improve features, review community contributions, and establish or defend legal claims. We balance these interests against your rights and use data proportionately.
- Legal obligations: respond to lawful requests and retain transaction, tax, or accounting records where required.
- Consent: where we specifically ask for it, including any optional processing that cannot rely on another legal basis. You may withdraw consent at any time without affecting earlier lawful processing.
We do not use your account data to send third-party advertising or sell personal data.
6. Cookies, browser storage, and analytics
Unsub uses the following technologies:
- Authentication cookies: session and security cookies needed to sign you in, protect your account, and provide requested features. Blocking them may prevent the account area from working.
- Age-precheck cookie: a necessary, signed eligibility record used to carry a successful age check into email or Google registration. It contains no date of birth and expires after ten minutes.
- Sidebar cookie: a functional cookie named sidebar_state that remembers whether the navigation is open for up to seven days.
- Theme storage: browser local storage that remembers your visual theme until you clear site data or change the setting.
- Cookieless analytics: an Umami-compatible script sends page and browser details to analytics self-hosted by Unsub on its infrastructure in Germany. It does not set an analytics cookie. The receiving server also receives network information such as your IP address.
We use cookieless analytics based on our legitimate interest in understanding and improving Unsub. You may object to this processing by contacting privacy@unsub.cash. You can clear or block cookies and local storage through browser settings, although necessary features may then stop working.
7. Providers and other recipients
We disclose data only as needed to operate Unsub or meet legal obligations, including to:
- Hetzner, which hosts Unsub's core infrastructure and self-hosted analytics in Germany;
- Scaleway Transactional Email for account, security, reminder, notification, and request emails;
- Bunny.net Storage in Falkenstein for service logos and guide images;
- Google when you choose Google sign-in, and Gravatar when a Gravatar profile image is loaded;
- a payment processor identified at checkout if paid features are introduced;
- Featurebase if you choose to follow the external feedback link;
- fxratesapi.com for currency-pair exchange rates; and
- professional advisers, authorities, courts, or a successor operator where lawfully required.
Unsub uses Mistral AI for restricted administrative tools that extract service details and draft cancellation-guide content from public service websites. These tools are designed not to send user subscription records or account identifiers to Mistral. Foreign-exchange rate requests contain currency pairs rather than account identifiers.
8. International transfers
Unsub's core infrastructure and self-hosted analytics are hosted by Hetzner in Germany. We prefer providers and processing locations in the EEA. Some other providers may process data from other countries. Under GDPR, a restricted transfer must be supported by an adequacy decision, approved contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Contact us for information about the locations and safeguards relevant to your data.
9. Retention
- Account and subscription data is generally kept while your account is active.
- Dates of birth submitted for age checks are not retained. A failed check does not store the date or result. A signed successful precheck expires after ten minutes, while the resulting age-attestation record is kept with the account until the account is deleted.
- Expired sessions and verification data are retained only as needed for authentication and security cleanup.
- Rate-limit records are scheduled for deletion after seven days.
- Completed queued jobs are kept for up to seven days and failed jobs for up to 30 days.
- Guide contributions and review history may remain after account deletion without account attribution.
- Legal, purchase, security, and dispute records are kept for the applicable statutory period or while a claim may be pursued.
Data may remain in backups, object storage, or a provider's systems after account deletion. Retention in those systems depends on technical recovery requirements, provider terms, legal obligations, and security needs. We use necessity, legal obligations, security risk, and limitation periods to set retention where no fixed period is listed.
10. Account deletion and export
You can start verified account deletion from account settings. Deletion removes account-linked data from active systems, subject to the retention described above. Published contributions may remain anonymized, and temporary copies may remain in backups, delivery-provider records, security logs, or queued jobs until their retention periods expire.
Account settings provide a subscription CSV export and a way to request a broader copy of your personal data. We may verify your identity before fulfilling a request. Contact privacy@unsub.cash if the available export does not cover the data you need.
11. Your GDPR rights
Depending on the circumstances, you may have the right to:
- access your personal data and receive a portable copy;
- correct incomplete or inaccurate data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent where processing relies on consent; and
- complain to the Norwegian Data Protection Authority (Datatilsynet) or your local EEA supervisory authority.
Send requests to privacy@unsub.cash. We may request information necessary to verify your identity. Rights can have legal exceptions, which we will explain if they apply.
12. Security
We use technical and organizational measures intended to protect personal data, including access controls, protected authentication credentials, encrypted calendar tokens, and restricted administrative access. No internet service can guarantee absolute security. Contact support@unsub.cash promptly if you believe your account has been compromised.
13. Third-party websites
Unsub links to subscription providers, cancellation resources, calendar applications, and feedback services that we do not control. Their privacy policies apply when you visit or provide data to them.
14. Changes to this policy
We may update this policy when the service, providers, or law changes. We will update the date above and provide reasonable notice of material changes through Unsub or by email. Where required, we will ask for consent before new processing begins.
15. Contact
Contact privacy@unsub.cash with privacy questions or requests. The contractual terms for using Unsub are available in our Terms of Service.