R Recurr
Back to Recurr

Privacy Policy

Last updated: February 13, 2026

At [COMPANY NAME] ("we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Recurr subscription management application ("Service"). Recurr is built with a local-first architecture. Free data stays on your device, paid plans can also stay local-only or add optional cloud sync, and we do not access your bank account or scrape your financial data.

Please read this Privacy Policy carefully. By using the Service, you consent to the practices described in this policy. If you do not agree with this policy, please do not use the Service.

1. Information We Collect

1.1 Information You Provide

When you create an account or use our Service, you may provide:

  • Account Information: Email address and password used for authentication via Supabase Auth.
  • Subscription Data: Names, prices, billing cycles, renewal dates, and notes for subscriptions you track.
  • Categories: Custom categories you create to organize your subscriptions.
  • Payment Methods: Labels and types of payment methods (e.g., "Visa ending in 1234"). We do not store full card numbers, CVVs, or bank account details.
  • Notification Preferences: Your chosen notification settings, including reminder timing and frequency.
  • Feedback: Any feedback, feature requests, or support messages you submit.

1.2 Information Collected Automatically

When you use the Service, we may automatically collect:

  • Device Information: Browser type, operating system, and device type for compatibility purposes.
  • Usage Data: General usage patterns to improve the Service (e.g., which features are used most).
  • Error Logs: Technical error information to diagnose and fix issues.

1.3 Information We Do NOT Collect

Recurr is designed with privacy at its core. We do not collect:

  • Full credit card or bank account numbers
  • Social Security numbers or government IDs
  • Location data or GPS coordinates
  • Contacts, photos, or files from your device
  • Browsing history outside of Recurr
  • Data from other applications on your device

2. Local-First Architecture

Recurr follows a local-first design philosophy. This means:

  • Primary Storage: Your subscription data is stored locally in your browser using localStorage and IndexedDB. The application works fully offline.
  • You Own Your Data: Your data exists on your device first. You can use Recurr without ever creating an account or syncing to the cloud.
  • No Bank Access: Recurr does not connect to your financial accounts, and it does not scrape account activity from third parties.
  • No Server Dependency: Core functionality (adding, editing, viewing subscriptions) does not require an internet connection or our servers.
  • Data Portability: You can export your data at any time from the Settings page and import backups or statement files when needed.

3. Cloud Sync via Supabase

If you choose to create an account, you may enable cloud sync. This is entirely optional. You can remain local-only on a paid plan, or turn on sync for backup and multi-device access.

3.1 What Gets Synced

When cloud sync is enabled, the following data is transmitted to and stored on Supabase servers:

  • Subscription records (names, amounts, billing cycles, dates)
  • Categories and payment method labels
  • Notification preferences
  • Application settings (theme, currency, display preferences)

3.2 Security Measures

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Data at rest is encrypted on Supabase infrastructure.
  • Row Level Security (RLS) policies ensure you can only access your own data.
  • Authentication tokens are securely managed and automatically refreshed.

3.3 Disabling Sync

You can disable cloud sync at any time from the Settings page. When disabled, your data remains only on your local device. You may also request deletion of your cloud-synced data.

4. Third-Party Services

We use the following third-party services to operate Recurr:

Supabase

Purpose: Authentication, database hosting, and cloud sync.

Data Shared: Email address (for authentication), synced subscription data (if cloud sync is enabled).

Privacy Policy: supabase.com/privacy

Stripe

Purpose: Payment processing for Pro subscriptions, Team plans, and Lifetime purchases.

Data Shared: Email address and payment information necessary to process transactions. Payment details are handled directly by Stripe; we do not see or store your full card credentials.

Privacy Policy: stripe.com/privacy

Anthropic (Planned)

Purpose: AI-powered features for subscription insights and recommendations.

Data Shared: If enabled, anonymized or aggregated subscription data may be sent to generate insights. No personally identifiable information will be shared without your explicit consent.

Privacy Policy: anthropic.com/privacy

We carefully vet all third-party service providers and only share the minimum data necessary for them to perform their functions.

5. Cookies and Tracking

5.1 Essential Cookies

Recurr uses only essential cookies and local storage required for the application to function. These include:

  • Authentication session tokens (if logged in)
  • Theme preference (dark/light mode)
  • Application state and settings stored in localStorage

5.2 Analytics

We may use privacy-respecting analytics to understand aggregate usage patterns (e.g., which features are popular). We do not use invasive tracking tools, build advertising profiles, or sell data to third parties.

5.3 No Third-Party Tracking

Recurr does not include third-party advertising trackers, social media tracking pixels, or cross-site tracking mechanisms. We do not participate in ad networks or data broker ecosystems.

6. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your account registration and authentication
  • Enable cloud sync and multi-device access (when opted in)
  • Process payments for Pro subscriptions, Team plans, and Lifetime purchases via Stripe
  • Send you subscription renewal reminders and notifications (based on your preferences)
  • Respond to your feedback and support requests
  • Improve and optimize the Service
  • Detect, prevent, and address technical issues or abuse
  • Comply with legal obligations

7. Data Retention

7.1 Local Data

Data stored locally on your device persists until you clear your browser data, uninstall the application, or manually delete it through the Settings page. We have no access to or control over your locally stored data.

7.2 Cloud Data

If you use cloud sync, your synced data is retained as long as your account is active. Upon account deletion:

  • All cloud-synced subscription data is permanently deleted within 30 days.
  • Authentication records are removed from Supabase.
  • Payment records are handled according to Stripe's retention policy and applicable financial regulations.

7.3 Backup and Logs

Automated backups may retain data for up to 90 days after deletion for disaster recovery purposes, after which they are permanently purged.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in Transit: All network communications use TLS 1.2+.
  • Encryption at Rest: Cloud-stored data is encrypted on Supabase infrastructure.
  • Access Controls: Row Level Security (RLS) ensures strict data isolation between users.
  • Authentication Security: Passwords are hashed using industry-standard algorithms. We support secure session management with automatic token refresh.
  • Rate Limiting: Login and signup endpoints are rate-limited to prevent brute-force attacks.
  • Minimal Data Collection: We collect only the data necessary to provide the Service.

While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.

9. Your Rights

9.1 Rights Under GDPR (European Economic Area)

If you are located in the EEA, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format. Recurr's export feature facilitates this directly.
  • Right to Object: Object to processing of your data for certain purposes.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

Our legal basis for processing your data includes: performance of a contract (providing the Service), your consent (optional features like cloud sync), and legitimate interests (improving the Service and preventing abuse).

9.2 Rights Under CCPA/CPRA (California)

If you are a California resident, you have the right to:

  • Know: Request disclosure of the categories and specific pieces of personal information we collect.
  • Delete: Request deletion of your personal information.
  • Correct: Request correction of inaccurate personal information.
  • Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-Discrimination: You will not be discriminated against for exercising your privacy rights.
  • Limit Use of Sensitive Data: Direct us to limit our use of sensitive personal information.

To exercise any of these rights, contact us at [COMPANY EMAIL]. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA/CPRA).

9.3 International Data Transfers

If you are located outside the United States, your data may be transferred to and processed in the United States or other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required by applicable law.

10. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we discover that a child under 16 has provided us with personal information, we will promptly delete it. If you believe a child has provided us with personal data, please contact us at [COMPANY EMAIL].

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify registered users via email for significant changes.
  • Provide a prominent notice within the application.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

[COMPANY NAME]

Email: [COMPANY EMAIL]

Address: [COMPANY ADDRESS]

For GDPR-related inquiries, you may also contact our Data Protection Officer at [COMPANY EMAIL]. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Terms of Service Back to Recurr

© 2026 [COMPANY NAME]. All rights reserved.

R
Recurr
Home Blog Guides
About Freelancers Research Founder note Privacy Policy Terms of Service

Built local-first. Free stays on your device. Paid sync is optional. See the privacy policy for details.