Subly — what this app collects
This page lists, item by item, every category of personal data Subly collects, why it is collected, how long it is kept and who outside Nikatru touches it. It is generated from the declaration the app itself is built and audited against, so it cannot drift from what the code does without a build failing.
Subly collects 11 categories of personal data for 3 stated purposes, keeps each for a fixed period, shares none of it with anyone beyond the service providers named below, and records no network address at all.
1. What is collected
11 categories, in the vocabulary the Google Play Data safety form uses — the same words the sworn store declaration answers in, so the two cannot quietly disagree.
| Category | What it is | Why | Kept for | Needed to use the app? | Shared? |
|---|---|---|---|---|---|
| Location | Approximate location | Analytics | 400 days | No | No |
| Personal info | Email address | Account management, App functionality | 730 days | Yes | No |
| Personal info | User IDs | Account management, App functionality | 730 days | Yes | No |
| Financial info | Purchase history | App functionality | 730 days | No | No |
| Financial info | Other financial info | App functionality | 730 days | Yes | No |
| App activity | App interactions | Analytics | 400 days | No | No |
| App activity | Other user-generated content | App functionality | 730 days | Yes | No |
| App info and performance | Crash logs | App functionality | 400 days | Yes | No |
| App info and performance | Diagnostics | App functionality | 400 days | Yes | No |
| App info and performance | Other app performance data | App functionality | 400 days | Yes | No |
| Device or other IDs | Device or other IDs | Analytics, App functionality | 400 days | Yes | No |
2. Why each of those answers is what it is
Every row above carries the reason it was decided on, the file that reason was read out of, and the date it was read. They are reproduced here in full rather than summarised, because a summary of a basis is a new claim.
Location — Approximate location
The device never provides a location. The only geography that exists anywhere is inferred at the Cloudflare edge from the connection, which is why the row is collected but not required and carries Analytics alone.
Personal info — Email address
Login is mandatory in the apps (ADR 058) and identity is one Supabase auth project for the whole portfolio (C-ONE-IDENTITY-PER-USER), so an address is the account. It is held for the account's life and erased by the schema-derived erasure route, identity last.
Personal info — User IDs
The one identity per user across every app is a user id issued by the auth project; every app row keys on it, which is what makes erasure reach derivable from the schema rather than from a hand-kept list of tables.
Financial info — Purchase history
Paddle is the merchant of record and will not replay a notification older than ninety days, so from day ninety-one ours is the sole surviving copy of the entitlement history a customer can be shown.
Financial info — Other financial info
The subscriptions a person tracks in Subly are financial facts about them, and they are the product itself. They sit in the app's own rows and are reached by the same erasure route as everything else keyed on the user id.
App activity — App interactions
The first-party events rail, consented per purpose and append-only, so a grant for analytics is never evidence of a grant for anything else. Swept at four hundred days by the events retention job.
App activity — Other user-generated content
The names, amounts and renewal dates a person enters. This is the content the app exists to hold, so it lives as long as the account does and goes with it.
App info and performance — Crash logs
Crash reports reach the self-hosted GlitchTip in Mumbai, whose event retention is bounded rather than indefinite. Self-hosted, so no third party receives them and no processor row is owed for it.
App info and performance — Diagnostics
Performance and error diagnostics on the same rail as the crash reports, bounded by the same retention and carrying nothing that identifies a connection.
App info and performance — Other app performance data
Timing and resource measurements emitted by the same instrumentation as the diagnostics row above; they are one stream answered as three rows because the Play console asks three questions.
Device or other IDs — Device or other IDs
An install id generated on the device. It is what lets an analytics row exist at all with nothing about the connection in it, it is the identifier the consent trail is keyed on, and it is deleted with the account.
3. How long each period is, and why it is that number
There are three retention periods in this portfolio and no others. They are locked: a convenience change cannot quietly extend how long personal data is kept, because the declaration will not accept a fourth value.
- 400 days — raw, event-level data — the floor is one year, set by the DPDP Rules 2025, and the ceiling is the 425-day industry maximum.
- 730 days — the money rail — our copy has to outlive the payment provider’s own 90-day replay window and the outer card-dispute window.
4. Who else touches it
4 service providers. Services Nikatru runs on its own machines are deliberately not listed: they are infrastructure this company operates, not a party the data is disclosed to.
| Who | Role | What they do with it |
|---|---|---|
| cloudflare | infrastructure | Serves the web app, runs the Workers and holds the D1 rows. |
| oracle-cloud | infrastructure | Hosts the identity stack that issues and verifies the session. |
| paddle | merchant of record | Takes the payment and is the seller of record for the web channel. |
| resend | email delivery | Delivers the transactional email an account needs to exist. |
5. What is never collected
No network address is recorded anywhere, for any of the rows above. This is not a setting: there is no column to put one in, the declaration cannot say otherwise, and a build fails if the words appear in it. It is the one identifier that would turn every analytics row into personal data, and it is the one this portfolio does not keep.
Nothing on this page is collected from anyone under 18. Nikatru does not offer any app, extension or site to children, and does not knowingly collect data from them.
6. Notice, consent and your rights
This section is the itemised notice: what is processed, for what purpose, how a consent is withdrawn, and how a complaint is made. It is generated from the same declaration as the table above, so the notice and the practice are one document.
What is processed, and for what purpose
Exactly the categories in section 1, each for exactly the purposes listed beside it, and for no other purpose. Consent is recorded separately for each purpose and the record is append-only: a consent given for one purpose is never treated as a consent for another, and withdrawing one leaves the others as they were.
How to withdraw a consent
Every consent given in the app can be withdrawn in the app, at any time, with the same number of taps it took to give. Withdrawal stops the processing that depended on it; it does not undo processing that had already happened, and it does not affect the categories marked as needed to use the app, which are held for as long as the account exists.
How to have your data erased
Deleting the account erases everything keyed to it. The reach of that deletion is derived from the database schema rather than from a list somebody keeps up to date by hand, so a new table cannot be silently missed. Start at nikatru.com/delete-account.
How to reach a person, and how to complain
The grievance contact is on nikatru.com/contact. A complaint that we do not resolve can be taken to the data-protection authority for your jurisdiction; for India that is the Data Protection Board established under the Digital Personal Data Protection Act, 2023.