Subly — what this app collects

Declaration last re-read against the code: 2026-09-05  ·  Itemised from apps/subly/privacy.yaml  ·  The policy you agree to is the Nikatru Privacy Policy.

This page lists, item by item, every category of personal data Subly collects, why it is collected, how long it is kept and who outside Nikatru touches it. It is generated from the declaration the app itself is built and audited against, so it cannot drift from what the code does without a build failing.

In one line

Subly collects 11 categories of personal data for 3 stated purposes, keeps each for a fixed period, shares none of it with anyone beyond the service providers named below, and records no network address at all.

1. What is collected

11 categories, in the vocabulary the Google Play Data safety form uses — the same words the sworn store declaration answers in, so the two cannot quietly disagree.

CategoryWhat it isWhyKept forNeeded to use the app?Shared?
LocationApproximate locationAnalytics400 daysNoNo
Personal infoEmail addressAccount management, App functionality730 daysYesNo
Personal infoUser IDsAccount management, App functionality730 daysYesNo
Financial infoPurchase historyApp functionality730 daysNoNo
Financial infoOther financial infoApp functionality730 daysYesNo
App activityApp interactionsAnalytics400 daysNoNo
App activityOther user-generated contentApp functionality730 daysYesNo
App info and performanceCrash logsApp functionality400 daysYesNo
App info and performanceDiagnosticsApp functionality400 daysYesNo
App info and performanceOther app performance dataApp functionality400 daysYesNo
Device or other IDsDevice or other IDsAnalytics, App functionality400 daysYesNo

2. Why each of those answers is what it is

Every row above carries the reason it was decided on, the file that reason was read out of, and the date it was read. They are reproduced here in full rather than summarised, because a summary of a basis is a new claim.

Location — Approximate location

The device never provides a location. The only geography that exists anywhere is inferred at the Cloudflare edge from the connection, which is why the row is collected but not required and carries Analytics alone.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

Personal info — Email address

Login is mandatory in the apps (ADR 058) and identity is one Supabase auth project for the whole portfolio (C-ONE-IDENTITY-PER-USER), so an address is the account. It is held for the account's life and erased by the schema-derived erasure route, identity last.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

Personal info — User IDs

The one identity per user across every app is a user id issued by the auth project; every app row keys on it, which is what makes erasure reach derivable from the schema rather than from a hand-kept list of tables.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

Financial info — Purchase history

Paddle is the merchant of record and will not replay a notification older than ninety days, so from day ninety-one ours is the sole surviving copy of the entitlement history a customer can be shown.

Read from tooling/legal/data-inventory.json on 2026-09-05.

Financial info — Other financial info

The subscriptions a person tracks in Subly are financial facts about them, and they are the product itself. They sit in the app's own rows and are reached by the same erasure route as everything else keyed on the user id.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

App activity — App interactions

The first-party events rail, consented per purpose and append-only, so a grant for analytics is never evidence of a grant for anything else. Swept at four hundred days by the events retention job.

Read from services/platform/migrations/0007_events_rollup.sql on 2026-09-05.

App activity — Other user-generated content

The names, amounts and renewal dates a person enters. This is the content the app exists to hold, so it lives as long as the account does and goes with it.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

App info and performance — Crash logs

Crash reports reach the self-hosted GlitchTip in Mumbai, whose event retention is bounded rather than indefinite. Self-hosted, so no third party receives them and no processor row is owed for it.

Read from tooling/legal/data-inventory.json on 2026-09-05.

App info and performance — Diagnostics

Performance and error diagnostics on the same rail as the crash reports, bounded by the same retention and carrying nothing that identifies a connection.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

App info and performance — Other app performance data

Timing and resource measurements emitted by the same instrumentation as the diagnostics row above; they are one stream answered as three rows because the Play console asks three questions.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

Device or other IDs — Device or other IDs

An install id generated on the device. It is what lets an analytics row exist at all with nothing about the connection in it, it is the identifier the consent trail is keyed on, and it is deleted with the account.

Read from apps/subly/store/android-play/data-safety.json on 2026-09-05.

3. How long each period is, and why it is that number

There are three retention periods in this portfolio and no others. They are locked: a convenience change cannot quietly extend how long personal data is kept, because the declaration will not accept a fourth value.

4. Who else touches it

4 service providers. Services Nikatru runs on its own machines are deliberately not listed: they are infrastructure this company operates, not a party the data is disclosed to.

WhoRoleWhat they do with it
cloudflareinfrastructureServes the web app, runs the Workers and holds the D1 rows.
oracle-cloudinfrastructureHosts the identity stack that issues and verifies the session.
paddlemerchant of recordTakes the payment and is the seller of record for the web channel.
resendemail deliveryDelivers the transactional email an account needs to exist.

5. What is never collected

No network address is recorded anywhere, for any of the rows above. This is not a setting: there is no column to put one in, the declaration cannot say otherwise, and a build fails if the words appear in it. It is the one identifier that would turn every analytics row into personal data, and it is the one this portfolio does not keep.

Nothing on this page is collected from anyone under 18. Nikatru does not offer any app, extension or site to children, and does not knowingly collect data from them.

6. Notice, consent and your rights

This section is the itemised notice: what is processed, for what purpose, how a consent is withdrawn, and how a complaint is made. It is generated from the same declaration as the table above, so the notice and the practice are one document.

What is processed, and for what purpose

Exactly the categories in section 1, each for exactly the purposes listed beside it, and for no other purpose. Consent is recorded separately for each purpose and the record is append-only: a consent given for one purpose is never treated as a consent for another, and withdrawing one leaves the others as they were.

How to withdraw a consent

Every consent given in the app can be withdrawn in the app, at any time, with the same number of taps it took to give. Withdrawal stops the processing that depended on it; it does not undo processing that had already happened, and it does not affect the categories marked as needed to use the app, which are held for as long as the account exists.

How to have your data erased

Deleting the account erases everything keyed to it. The reach of that deletion is derived from the database schema rather than from a list somebody keeps up to date by hand, so a new table cannot be silently missed. Start at nikatru.com/delete-account.

How to reach a person, and how to complain

The grievance contact is on nikatru.com/contact. A complaint that we do not resolve can be taken to the data-protection authority for your jurisdiction; for India that is the Data Protection Board established under the Digital Personal Data Protection Act, 2023.

This section states what this app actually does, itemised from its declaration. It is written to be plain and complete rather than to a statutory checklist: the applicable notice-content provisions have not been read line by line against it, and that gap is tracked as an open item rather than papered over with a claim of compliance.

Generated from apps/subly/privacy.yaml, declaration date 2026-09-05.