Security & Privacy

We don't want your data.

Security isn't just a feature; it's a fundamental requirement. Because we ask for permission to scan your inbox for receipts, we believe in radical transparency about how we protect your information.

We minimize risk by relying on enterprise-grade infrastructure and simply not storing sensitive data in the first place.

Read-Only Email Access

When you connect your email (Gmail, Outlook, etc.), we request the strictest read-only scopes available.

  • We can scan headers and bodies to find subscription receipts.
  • We immediately discard the email body after extracting the vendor and amount.
  • We CANNOT send emails on your behalf.
  • We CANNOT delete or modify your emails.

Enterprise-Grade Infrastructure

We don't roll our own cryptography. We rely on industry leaders to handle the hardest parts of security:

Supabase Auth

Handles all authentication, password hashing, and OAuth flows. Sessions are secured using HTTP-only cookies to prevent XSS attacks.

Row Level Security (RLS)

Our PostgreSQL database enforces strict policies at the row level. A user can fundamentally only access data tied to their own unique user ID.

PCI-Compliant Billing

SubNuke never touches your credit card data. All payments and subscription management for our Pro tiers are processed exclusively by LemonSqueezy / Stripe, acting as our Merchant of Record. They handle the compliance, we just listen for secure webhooks.