Privacy Policy
Submo: Cancel Subscriptions · Last updated August 24, 2026
Submo: Cancel Subscriptions
Last updated: August 24, 2026
This Privacy Policy describes how MO TECH L.L.C-FZ, the data controller, and Mobileocean Bilişim Yazılım A.Ş., a related operating company (together, "Submo," "we," "us," or "our"), collect, use, and share information when you use our website and web application at submoapp.com (the "Service" or "Website"). Their distinct contact roles are listed in Section 13.
Please read this Policy before using the Service. Where we rely on consent, including for optional bank connections where required, we ask for that consent separately and you may withdraw it without losing access to unrelated core features.
1. Information We Collect
1.1 Information you provide
-
Subscription data: Information you enter into the Service about your subscriptions, such as service names, plan types, prices, currencies, billing cycles, and renewal dates.
-
Preferences: Reminder settings, notification preferences, and other in-product configuration.
-
Support communications: If you contact us, we collect the information you provide (such as your email address and the content of your message).
-
Account information: You create an account (with an email address and password, or by signing in with Google or Apple) so we can keep your membership and saved subscriptions. We collect your name and email address for this. Payments are processed by Stripe. We never collect or store your full payment card number or your bank login credentials.
-
API keys and agent access: If you create an API key (or an agent starts checkout on your behalf), we store only a one-way hash of the key, a display prefix, last-used time, and the actions performed with it. An agent using your key can read and change the same subscription data you can in the dashboard. You can revoke a key at any time from Account.
-
Paid cancellation notices: If you buy a cancellation notice, we collect the sender name and postal address, the provider you identify, account-matching details such as the subscription email and billing address, your requested timing, reason or note, and the resulting letter. We retain the verified provider address, the exact address snapshots used for mailing, and provider delivery-status identifiers so we can fulfil the order, provide a dispatch record, investigate delivery failures, and administer the stated refund guarantee.
1.2 Information collected automatically
When you use the Service, we and our service providers may automatically collect:
- Device and browser information: Browser type and version, operating system, language, region, time zone, and similar technical identifiers.
- Usage data: Pages viewed, features used, session duration, crash logs, and diagnostic data.
- Purchase and subscription status: Transaction identifiers and subscription state (e.g., trial, active, cancelled) received from Stripe (and, where used, our subscription infrastructure provider), used to unlock Premium features and analyze subscription performance. We do not receive your payment card details.
- Approximate location: We may infer your approximate region from your IP address for localization and analytics. We do not collect precise GPS location.
1.3 Notifications
With your permission, we send reminders such as renewal notices by email or, where supported, push notifications. You can disable these at any time in your account or device settings.
1.4 Connecting Gmail, connecting a bank, and uploading statements (optional)
These features run only when you explicitly choose to use them, to help you discover subscriptions you may have forgotten:
- Gmail (Google account): If you choose "Connect Gmail," we ask for your permission for read-only access to your Gmail (the
https://www.googleapis.com/auth/gmail.readonlyscope). We use this access solely to run targeted searches for subscription receipts, renewals, memberships, and recurring-billing messages and show you possible recurring charges. The first scan runs when you connect; while the connection remains active, a throttled refresh may run when you visit your dashboard so saved price, cycle, and renewal information can stay current. For messages returned by those searches, we process the sender, subject, date, snippet, and message body in memory to identify the service, charged amount, currency, and billing cycle. While a scan is running we may show you a compact preview of those same messages (sender, subject, date, and snippet) so you can see which emails were read. On each suggested subscription we may also show a short excerpt of the message body around the extracted amount or billing cycle so you can check our reading. We do not fetch messages outside those targeted search results, and we never store full message bodies. Compact discovery results may retain the inferred subscription details plus the evidence subject, sender, and that short body excerpt, and that short inbox preview, for no longer than 90 days; subscriptions you choose to add remain as ordinary subscription records. We store the Google OAuth token encrypted only while the connection is active. To keep results accurate, short excerpts of those matched messages may be analyzed by an AI model operated by our inference provider (OpenRouter, Inc.), acting as our processor, solely to confirm that a message reflects a recurring paid subscription; these excerpts are processed transiently, are routed only to zero‑data‑retention endpoints, are not retained by the provider, and are never used for advertising or to train models. We do not sell Gmail data, use it for advertising, or use it to develop, improve, or train generalized artificial‑intelligence or machine‑learning models, and we do not transfer it to any third party other than the inference processor described above. You can disconnect in Submo Account or revoke access at myaccount.google.com/permissions. - Direct bank connection through Plaid: If you affirmatively choose "Connect bank," Plaid asks you to select and authenticate with your financial institution. Submo does not receive or store your bank username or password. Plaid provides Submo with read-only account and transaction information for up to 24 months, which may include institution and account identifiers, account names and types, transaction dates, merchant or transaction descriptions, amounts, currencies, and recurring-payment patterns. We use this information only to identify recurring subscriptions for your review. We store an encrypted Plaid connection token and limited connection metadata while the connection remains active. Raw discovery-scan results are deleted no later than 90 days after the scan; only subscriptions you choose to add remain as ordinary subscription records. You can disconnect at any time, which instructs Plaid to revoke the connection and deletes our stored token. We do not use Plaid data for advertising, lending, eligibility decisions, or generalized model training.
- Bank or card statements: If you upload a statement (PDF), we parse it in memory on our server to detect recurring charges. The uploaded file itself is not stored. Compact discovery results are deleted no later than 90 days after the scan; subscriptions you choose to add remain as ordinary subscription records.
Google API Services User Data Policy: Limited Use. Submo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. How We Use Information
We use the information we collect to:
- provide, operate, and maintain the Service, including reminders and subscription insights;
- compose, review, mail, track, and support a paid cancellation notice that you instruct us to send;
- identify recurring subscriptions from optional Gmail, statement, or read-only Plaid data that you choose to provide;
- process and verify purchases and manage Premium access;
- analyze usage to understand how the Service is used and to improve features, performance, and stability;
- diagnose and fix crashes, bugs, and technical issues;
- personalize your experience, including language and regional formatting;
- communicate with you, including responding to support requests;
- measure the effectiveness of our marketing campaigns (where permitted);
- comply with legal obligations and enforce our Terms of Use.
3. Legal Bases for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Performance of a contract: to provide the Service and its features to you;
- Legitimate interests: to improve the Service, ensure security, and understand usage, where these interests are not overridden by your rights;
- Consent: for optional processing such as bank connections, where required; you may withdraw consent at any time;
- Legal obligation: where processing is necessary to comply with applicable law.
4. Sharing of Information
We do not sell your personal information. We share information only in the following circumstances:
-
Service providers: We use third-party providers to support the Service's operation, such as:
- Plaid, which facilitates optional read-only bank connections and supplies account and transaction data after you authorize your financial institution;
- analytics providers (e.g., app usage analytics and event tracking, including Google Analytics on the Website);
- payment processing for web purchases (Stripe), which processes your card details under its own privacy policy; we do not receive or store your full card number;
- physical print and mail fulfilment (PostGrid), which receives the sender and recipient postal addresses and the cancellation-letter content only when an operator prepares or sends a notice you purchased;
- subscription and purchase infrastructure providers (e.g., RevenueCat) to validate purchases and manage subscription status;
- push notification delivery (OneSignal) so renewal reminders and price-change alerts can reach a signed-in device;
- AI inference (OpenRouter, Inc.), acting as our processor for two optional features: confirming email-scan results (short, redacted excerpts of matched billing emails, processed transiently on zero‑data‑retention endpoints that do not train on inputs) and the AI Advisor (which receives only your saved subscription records — service names, prices, billing cycles, renewal dates, and status — and never Gmail, bank, or statement content);
- crash reporting and performance monitoring services;
- attribution and marketing measurement services (where permitted).
These providers process data on our behalf under contractual obligations and only for the purposes described in this Policy.
-
Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of our users, ourselves, or others.
-
Business transfers: In connection with a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
5. Data Retention
We retain information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law:
- account and saved subscription records remain while your account is active and are deleted when you complete account deletion, subject to limited backup expiry;
- Plaid connection tokens and Google OAuth tokens remain only while the relevant connection is active and are deleted when you disconnect or delete your account;
- completed or failed discovery scans, including raw Plaid-derived results, are automatically deleted within 90 days;
- uploaded statement files and Gmail message content are processed transiently and are not retained;
- password-reset links expire after one hour and only a one-way hash is stored;
- API key hashes remain while the key is active and are deleted with the account; checkout poll tokens and connect links expire automatically;
- paid cancellation-notice orders, address snapshots, provider mail references, and fulfilment audit evidence are ordinarily retained for up to 24 months after dispatch or closure, and may be retained longer only where reasonably required for payment disputes, fraud prevention, tax, or other legal obligations;
- security and administrative logs are ordinarily retained for 90 days, with restricted archives retained for up to 12 months where justified for security or legal needs; and
- production backups target expiry within 35 days, subject to the cloud provider's backup lifecycle.
Use the in-product account deletion control, follow the steps at Delete account, or contact us to request deletion.
6. Data Security
We implement reasonable technical and organizational measures designed to protect your information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you;
- Rectification: request correction of inaccurate or incomplete data;
- Erasure: request deletion of your personal data;
- Restriction and objection: request that we restrict processing or object to processing based on legitimate interests;
- Portability: request your data in a structured, commonly used, machine-readable format;
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing;
- Complaint: lodge a complaint with your local data protection authority.
To delete your account and associated data, follow the steps at Delete account. To exercise any of these rights, contact us at [email protected]. We will respond in accordance with applicable law.
California residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, and correct personal information, and the right to opt out of the "sale" or "sharing" of personal information. We do not sell personal information for money. To the extent that the use of advertising or analytics identifiers constitutes "sharing" under California law, you can limit it with browser privacy or content-blocking controls on the Website. We do not discriminate against you for exercising your rights.
9. Tracking and Advertising Identifiers
On the Website, Google Analytics and Mixpanel measure product usage and campaign performance by default, and Google Ads receives purchase-conversion events. Where a signed-in email is available, Submo sends Google only its SHA-256 hash for enhanced conversion measurement, not the raw email. These services may use cookies, local storage, and device or campaign identifiers. You can limit this tracking with browser privacy controls or content-blocking tools. This does not affect core Service features or optional bank connections.
10. Children's Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
11. Third-Party Links and Services
The Service may contain links to third-party websites or reference third-party services, including Plaid and your financial institution when you choose a bank connection. When you purchase a mailed cancellation notice, PostGrid acts as our print-and-mail processor and the named subscription provider receives the finished notice as the intended recipient. Those third parties process information under their own terms or privacy policies, and we encourage you to review them where applicable.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date above. Material changes will be communicated through the Service or other appropriate means. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
13. Contact Us
If you have questions or requests regarding this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- MO TECH L.L.C-FZ (data controller): Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
- Mobileocean Bilişim Yazılım A.Ş. (operating company): Atatepe Mah. 3511 Sk. No: 11 İç Kapı No: 19, Atakum/Samsun, Türkiye