Back to Saaszly

Saaszly legal

Privacy Policy

Last updated: May 5, 2026

Saaszly helps users detect and manage subscriptions from Gmail. The product is designed to turn billing signals into subscription metadata while keeping users in control of connected accounts and detected data.

What We Access

With your permission, Saaszly uses read-only Gmail access to scan for subscription, billing, renewal, trial, receipt, and invoice emails. We do not send email, modify email, delete email, or use Gmail data for advertising.

What We Store

Saaszly may store subscription metadata such as service name, sender, subject, billing amount, currency, billing frequency, renewal dates, confidence score, Gmail source links, review feedback, and invoice files when available.

What We Do Not Store

We do not intentionally store private conversation threads as user-facing records. Email bodies are processed for subscription detection and reduced into subscription metadata.

AI Processing

Saaszly may send relevant email text snippets to AI providers to classify and extract subscription information. Detections can be reviewed, corrected, rejected, or deleted by the user.

Data Controls

Users can disconnect Gmail and delete detected subscription data from Settings. Organization members can control whether their subscription data is visible to their organization.

Your Rights

You can exercise your data rights directly from Settings. Access & portability: “Download my data” exports everything we store about you as a JSON file. Erasure: “Delete Account” permanently removes your account and all associated data, and revokes Saaszly’s Gmail access at Google. Disconnecting Gmail or deleting detected data are narrower controls in the same place. Requests are actioned immediately; see our Data Deletion page for step-by-step instructions, or email support@saaszly.com.

Data Retention

We keep subscription metadata while your account is active so the dashboard stays current. Scan-event records (sender, subject, and detection score only) are retained to avoid re-processing the same email; negative results expire after 30 days. When you delete detected data or your account, the corresponding records are removed promptly. Gmail access tokens are encrypted at rest and discarded when you disconnect or delete your account.

Sub-processors

Saaszly relies on a small set of service providers to operate, and shares only the data each needs: Google (Gmail API, read-only inbox access), Supabase (encrypted database hosting), Vercel (application hosting), Resend (transactional and notification email), and an AI provider (Google Gemini, OpenAI, or Anthropic) for classifying and extracting subscription details from email snippets. We do not sell personal data or use it for advertising.