The short version
Your subscriptions
Names, prices, billing cycles, renewal dates, categories, notes, payment methods and income entries live in a database on your phone. Nothing leaves it unless you sign in.
Stays on device
Optional backup
If you sign in, the same records are copied to your private area of our database so you can restore them after reinstalling or on a second phone. You can delete this at any time.
Only if you sign in
No bank connection
SubDesk does not connect to your bank, does not read your transactions, and never asks for a card number, an IBAN or an account number. There is nothing in the app that could collect one.
Not collected
We do not sell your data, and we never have.
SubDesk shows advertising supplied by Google. In the European Economic Area, the United Kingdom and Switzerland you are asked, before any ad loads, whether Google and its partners may use your data for personalised advertising — and whatever you answer, the app works exactly the same. You can change that answer at any time in Settings → Ad privacy options. See section 05.
Who we are
SubDesk is an independent Android application published on Google Play under the package name app.subdesk. For the purposes of the EU and UK General Data Protection Regulation, the developer of SubDesk is the data controller for the personal data described in sections 03 and 04, and can be reached at mardevlopm@gmail.com.
Where SubDesk shows advertising, Google acts as an independent controller for the advertising data it collects. That relationship is described in section 05.
This policy covers the SubDesk Android app and this website. It does not cover any other app or site you reach through a link from either of them.
What SubDesk stores on your device
Everything you enter is written to a local database on your phone. The app is usable without an account, and in that mode none of the following ever leaves the device:
- Subscriptions — service name, price, currency, billing cycle, next renewal date, start date, trial state, category, colour, notes, and how many ways a cost is split.
- Payments you have recorded against a subscription, and the price-change history the app keeps so past months stay accurate.
- Recurring income entries, if you use the income feature.
- Payment method labels — the name you give a card or account, such as "Visa · personal". Never a number.
- App settings: your main currency, theme, language, reminder time and notification preference.
Uninstalling SubDesk deletes this local database. If you have not signed in, uninstalling is a complete erasure.
Notifications. Renewal reminders are generated on your device by a scheduled job. Nothing is sent to a server to produce one, and the reminder text is never transmitted anywhere.
What is stored in your account
Signing in is optional and the app tells you so. When you do sign in — with an email address and password, or with Google — two things happen.
Firebase Authentication
Google's Firebase Authentication holds your email address, a unique account identifier, the sign-in method you used, and sign-in timestamps. If you sign in with a password, Firebase stores a cryptographic hash of it. SubDesk never receives, sees or stores your password.
Cloud Firestore
A copy of the records in section 03 is written to a private area of our database, addressed by your account identifier. Security rules on the server allow that area to be read and written by your account and by no other, including us in the ordinary course of running the app.
Your account area is also where your settings copy lives, so a reinstall restores the app in the state you left it. The app writes a backup only when it has an internet connection, and only after you have signed in — it does not queue writes to be sent later without telling you.
You can remove all of this yourself. See Delete your data.
Advertising and your consent choices
EEA · UK · SwitzerlandSubDesk is free and is funded by advertising supplied by Google AdMob. Ads appear as a banner on the home screen and as clearly labelled units inside some lists, and occasionally as a full-screen ad between screens.
The consent message
If you are in the European Economic Area, the United Kingdom or Switzerland, SubDesk shows Google's consent message the first time you open the app, before any advertising SDK is allowed to request an ad. It is built with Google's User Messaging Platform and follows the IAB Europe Transparency & Consent Framework, so the choices you make there are passed on to Google's advertising partners.
If you do not consent to personalised advertising, SubDesk does not initialise the advertising SDK for personalised use, and Google serves non-personalised ads or none at all. No feature of the app is withheld, degraded or delayed because of your answer.
Changing your mind. Open Settings → Ad privacy options inside the app. The same form reopens and your new choice takes effect immediately — ads already on screen are discarded and reloaded under the new setting. The row appears whenever your region requires it to be available.
What Google may collect. Subject to your choice, Google and its partners may process your device's advertising identifier, IP address, coarse location derived from that address, device and app information, and interactions with ads, in order to select, deliver, measure and report on advertising and to detect fraud. Google's own explanation is at business.safety.google/privacy, and the current list of advertising partners is available from the consent message itself and at Google's certified partner list.
Your advertising ID. Android lets you reset or delete the advertising identifier at any time in Settings → Privacy → Ads on your phone. That control belongs to the operating system and works independently of anything SubDesk does.
What SubDesk itself does not do. SubDesk does not run its own analytics, does not build a profile of you, does not share the contents of your subscription list with any advertiser, and does not use anything you typed into the app to target an ad. The advertising layer is kept entirely separate from your data: it never reads the local database or your account.
Services SubDesk relies on
These are the only third parties the app communicates with. Each one is listed with what it receives and why.
| Service | Receives | Purpose | Their policy |
|---|---|---|---|
| Firebase Authentication | Email address, account identifier, sign-in metadata | Signing you in and keeping you signed in | Policy |
| Cloud Firestore | Your subscription, payment, income and settings records | Optional backup and restore across devices | Policy |
| Google AdMob | Advertising identifier, IP address, device and ad interaction data — subject to your consent | Serving and measuring the ads that fund the app | Policy |
| Google User Messaging Platform | Your consent choices and the region signal used to decide whether to ask | Collecting and storing your advertising consent | Policy |
| Logo.dev | The brand name of a service you added, and your IP address, as part of the image request | Showing a recognisable logo next to a subscription | Policy |
| Frankfurter | Currency codes only, and your IP address as part of the request | Converting foreign-currency subscriptions to your main currency | Site |
Logo.dev and Frankfurter are contacted for the display of logos and exchange rates only. Neither request contains your account identifier, your prices, or anything that identifies you beyond the ordinary network metadata any web request carries.
Legal bases for processing
If you are in the EEA or the UK, we rely on the following bases under Article 6(1) GDPR:
- Contract (Art. 6(1)(b)) — storing your subscriptions and settings, and backing them up to your account, in order to provide the app you asked for.
- Consent (Art. 6(1)(a)) — personalised advertising and the storing of, or access to, information on your device for that purpose. Given through the consent message and withdrawable at any time in Settings.
- Legitimate interests (Art. 6(1)(f)) — serving non-personalised advertising, keeping the service secure, and preventing invalid or fraudulent ad traffic. Balanced against your rights, and never used as a substitute for consent where consent is required.
Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
How long data is kept
- On your device — until you delete the record or uninstall the app.
- In your account — until you delete the data or the account. Deleting the account removes the stored records; see Delete your data.
- Your consent choice — stored on your device by the User Messaging Platform. Google re-asks periodically as the framework requires, and you can reset it yourself in Settings.
- Advertising data held by Google — governed by Google's own retention schedules, not by us.
Your rights
Under the GDPR and comparable laws you have the right to access your data, to correct it, to erase it, to restrict or object to processing, to withdraw consent, and to receive your data in a portable format.
Directly in the app
- Access and portability — Settings → Export data writes every record to a JSON file you keep.
- Correction — edit or delete any subscription, payment or income entry at any time.
- Withdraw consent — Settings → Ad privacy options.
- Erasure — Settings → Account → Delete account, or uninstall if you never signed in.
By email
Write to mardevlopm@gmail.com from the address on your account. We answer within 30 days, as the GDPR requires. If you are not satisfied, you may complain to your national data protection authority; in the UK that is the ICO.
Children
SubDesk is a personal finance tool for adults. It is not directed to children, it is not enrolled in Google Play's Designed for Families programme, and we do not knowingly collect personal data from anyone under the age of 16 — or under the higher age of digital consent set by their country. The advertising request SubDesk sends is not tagged for under-age treatment, because the app is not offered to under-age users at all. If you believe a child has given us data, write to mardevlopm@gmail.com and we will delete it.
Security
Every network request the app makes uses HTTPS. Your account area on the server is protected by rules that check the identity of the caller on every single read and write, and those rules reject any document containing a field that looks like a credential — a password, a PIN, a card number, an IBAN or a token — regardless of what a client tries to send.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.
International transfers
Firebase Authentication, Cloud Firestore and Google AdMob are operated by Google, which processes data on servers in several countries including the United States. Where data is transferred out of the EEA or the UK, Google relies on the European Commission's Standard Contractual Clauses and the safeguards described in its own privacy resources.
Changes to this policy
If this policy changes, the effective date at the top of the page changes with it and the previous version stays in the repository's history, which is public. For a change that materially affects how your data is used, we will ask again through the app rather than rely on you re-reading this page.
Contact
SubDesk
Privacy questions, access requests and deletion requests: mardevlopm@gmail.com
Every revision of this policy is public: github.com/mar-devl/subdesk-legal