Privacy Policy

Last updated: August 19, 2026

1. What We Collect

We collect and store:

  • Account information you provide: your display name, business name, and email address
  • Information you choose to enter about individuals you manage using the platform, including names, contact details, notes, financial history, and task or agreement records
  • Basic usage and audit data (such as login times and account activity) used for account security

2. How We Protect It

Data is stored on Google Cloud infrastructure (via Firebase), which encrypts data at rest and in transit at the infrastructure level. Access to your account requires your login credentials, and every account's data is isolated from every other account.

We are building an additional layer of encryption for our most sensitive fields (legal names, private notes, and safewords) at the application level, so that data would be unreadable even to us without your account key. That additional layer is not live yet; today those fields are protected by the infrastructure-level encryption described above, the same as the rest of your account, but not by a separate application-level key. We will update this page the day that additional protection ships.

3. Who Can Access Your Data

Only you can access your account's data through normal use of the service. SubServe staff do not access account content as a matter of course. The only exception is a support request you initiate yourself: if you ask us for help with something that requires looking at your account, we do so only for as long as needed to resolve it.

4. Your Rights

You can delete an individual profile from your roster at any time from within the app; that deletion is immediate and permanent, not a soft delete with a recovery window. Gifts and other records already logged against that profile are kept for your own accounting, but no longer show that individual's name once it's deleted.

There is not yet a self-service way to export or permanently delete your entire account. Until that exists, contact us at the address below and we will handle either request by hand.

5. Data Retention

We keep your account's data for as long as your account is active. If you ask us to delete your account, we will delete the underlying data; we do not currently have an automatic retention window built into the product, so this happens as a manual request rather than on a fixed schedule.

6. Third-Party Processors

We rely on the following third parties to run SubServe:

  • Google Cloud Platform / Firebase, for hosting, our database, and account authentication
  • Vercel, for hosting the website itself
  • Namecheap Private Email, to send account and notification emails from the subserv.me domain
  • A payment processor, once billing goes live, to handle your subscription payment to us. We will update this section with the processor's name when that happens.

7. Breach Notification

If we confirm a security breach affecting your data, we will notify you without unreasonable delay, and in any case as required by applicable law.

8. Contact

Questions about this policy, or requests to export or delete your data, can be sent to contact@subserv.me. We can also be reached by mail at 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801.