This Privacy Policy explains what the Subcel app (the “App”) does with your information. Subcel is operated by an individual developer (contact details at the end of this policy), who is the data controller for the purposes of the GDPR and UK GDPR.
Subcel has no account, no server and no database of yours. Everything you enter — your subscriptions, their prices, their dates, your settings — is stored on your own device and nowhere else. We cannot see it, we cannot recover it, and there is nothing of yours for us to hand over to anyone.
The App keeps the following on the device itself, in its own private storage:
Only the payment method type is ever stored — “card”, “wallet” and so on. Subcel never asks for and never stores a card number, an expiry date or a CVV.
On first launch the App fills the list with a few demo subscriptions so the charts and the calendar have something to show. They are ordinary entries: delete them and they are gone.
Subcel contains no analytics SDK, no advertising SDK, no crash reporter and no tracking of any kind. There is no sign-up, so we never learn your name or your email address. We do not build a profile of you, we do not track you across apps or websites, and we have no personal data of yours to sell or rent — not as a policy position, but as a fact about how the App is built.
Three requests, and no more. None of them carries your subscription list.
To show every subscription in one currency, the App downloads a public table of exchange rates once a day from
jsDelivr (cdn.jsdelivr.net), falling back to a mirror hosted on Cloudflare
Pages. It is an anonymous request for one public file. Nothing about you or your subscriptions is sent; as with
any web request, the server sees your IP address. If it fails, the App uses yesterday's cached rates or a built-in
table, and carries on.
When you search for a service's logo, the name you typed (and, for a Cyrillic name, its transliterations) is sent to Brandfetch's public catalogue search, and the image you pick is downloaded from Brandfetch's servers. Only the name is sent — not the price, not the dates, not anything else about the subscription. This is optional: skip the logo and the App draws a monogram instead.
If you buy Subcel Pro, purchase handling goes through RevenueCat. It receives an anonymous identifier generated for that installation, your purchase receipt and basic device and country information — enough to tell the App whether Pro is active and to restore it on a new device. It never receives your subscription list. Payment itself is handled entirely by Apple or Google; we never see your payment card details.
Charge reminders are local notifications, scheduled by your device from data that never leaves it. No server is involved, so they work in airplane mode. Permission is asked in context — when you set up a reminder — and never at launch.
| Provider | What it receives | Where |
|---|---|---|
| RevenueCat, Inc. | Purchase receipts and an anonymous installation identifier — only if you buy Pro | United States |
| Apple Inc. / Google LLC | Payment processing for a purchase | Global |
| Brandfetch (Brandfetch AG) | The service name you type when you look for a logo | Switzerland / EU |
| jsDelivr / Cloudflare, Inc. | An anonymous request for the public currency-rate file | Global CDN |
Each of these receives data under its own privacy policy. We will update this table whenever a provider is added or removed.
Because nothing of yours is stored on a server, there is no database of yours to transfer anywhere. The limited purchase data above is processed by providers in the United States and elsewhere; where personal data is transferred out of the European Economic Area or the United Kingdom, those transfers rely on the European Commission's Standard Contractual Clauses, which our providers incorporate into their agreements with us.
Your data stays on your device for as long as you keep the App installed. Deleting the App deletes all of it — there is no copy anywhere else, and nothing to restore. Purchase records held by RevenueCat, Apple or Google are kept under their own retention rules, because they are part of a billing relationship rather than something we hold.
Delete an individual subscription in the App, or remove the App to delete everything at once. There is no account to close and no request to send us. See Your data and how to delete it for the details, including what to do about an active subscription.
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to receive a copy in a portable format, to have it deleted, and to object to or restrict processing. In Subcel's case those rights are largely satisfied by the design: the data is already in your hands, and we hold none of it. For the purchase data described above, email us and we will help. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decision-making. If you are in the EEA or the UK you also have the right to lodge a complaint with your local data protection authority.
Subcel is intended for a general audience and is not directed to children. It collects nothing from anyone, but if you believe a child has used the App in a way that concerns you, contact us.
Your data sits in the App's private storage, protected by your device's own sandbox and, where you have enabled it, its encryption. Requests to the internet are made over HTTPS. Keep a device passcode: anyone holding an unlocked phone can open the App.
We may update this policy as the App changes. The date and version at the top reflect the latest revision. If a change materially affects what leaves your device or who receives it, we will say so in the App.
Questions, requests or complaints about your privacy? Email mail@timeofjohnny.com. We aim to reply within a few business days.