Last updated: 13 September 2026
RecurLens is a subscription tracker for individuals, freelancers, and small teams. This policy explains the baseline for the hosted invite-only beta. If you self-host RecurLens, you are responsible for your own privacy and compliance obligations.
The hosted RecurLens beta is limited to people aged 18 or older because supporting minors would require child/parental-consent practices that are not currently defined for the hosted service. If you self-host RecurLens, you are responsible for setting the age policy and any practices required for your deployment.
We collect account information you provide directly, such as username, email address, password authentication metadata, workspace names, member roles, subscription names, costs, renewal dates, categories, notes, reminder settings, and CSV import/export data you choose to upload.
We also collect operational information needed to run and secure the service, including essential session identifiers, request metadata, error logs, device/browser metadata, and timestamps for authentication, workspace, invite, and Agent/API activity.
We use your information to provide RecurLens, authenticate users, create and manage workspaces, track recurring subscription costs, send or display reminders, support CSV import/export, prevent abuse, debug errors, and improve reliability.
We do not sell your personal information or use workspace subscription data for advertising profiles.
Workspace data is visible only to authorized members according to their role. Workspace invitations are bound to the invited email address and remain usable until accepted, expired, or revoked.
For the hosted beta, Vercel hosts the website, Railway hosts the API, and Supabase provides authentication and the database. Account confirmation and password-reset emails use Supabase Auth; the API sends renewal reminder emails through Resend.
PDF receipt bytes and unconfirmed receipt text stay in your browser, are discarded after draft extraction, and are not sent to a model provider. Only record fields you explicitly confirm are sent to the API and retained through the existing subscription or purchase service.
When enabled for the hosted beta, Vercel Web Analytics uses the standard Next.js integration to send page-view data for full loads and client-side transitions to Vercel. The operator sees anonymous, aggregated page views and visitors. Vercel documents that data points may include the page URL/path, referrer, filtered query parameters, timestamp, geolocation, device/OS, browser, device type, and script version. The RecurLens integration adds no custom events, account identity linkage, or age data, and Vercel states that Web Analytics does not use cookies.
Sentry is not enabled for the hosted beta. YouTube tracking and video embedding are not enabled for the hosted beta; the product tour uses the bundled video. Self-hosted operators may configure different providers or optional integrations and are responsible for their own disclosures.
In Settings, Delete account requires password verification. Deletion is blocked while a workspace you own still has other members. When allowed, you leave workspaces owned by others, your owned workspaces and local account are soft-deleted, and RecurLens attempts to delete the matching Supabase Auth account.
Deleted subscriptions, categories, workspaces, and accounts may remain soft-deleted, and copies may remain in operator backups. Permanent-deletion and backup-expiry periods for the hosted beta have not yet been approved or published.
CSV export covers the supported current subscription and purchase fields. It does not include complete account, membership, reminder, audit, history, or deleted-record data and is not a complete recovery backup.
Agent/API audit and usage metadata are configured in code for 90 days by default. The operator must confirm the hosted value and the request process for retained data before this notice is finalized.
We use reasonable technical and organizational safeguards, including authentication, authorization checks, row-level security policies, input validation, rate limiting, and production CORS configuration. No internet service can be guaranteed perfectly secure.
You are responsible for protecting your credentials, using strong passwords, and sharing workspace invites only with people you trust.
Depending on your location, you may have rights to access, correct, export, delete, or object to certain processing of your personal information. Any requests are subject to applicable law and the contact-channel status below.
Self-hosted operators are responsible for their own privacy notices, processor agreements, backups, retention policies, and legal compliance for their deployments.
RecurLens uses essential session cookies set through Supabase to keep you signed in, refresh authentication, and protect access to private pages. The application code does not use these cookies for advertising. Whether any optional deployment adds other cookies must be confirmed by the operator.
The hosted RecurLens beta is operated by an individual based in Kurnool, Andhra Pradesh, India. Questions and privacy requests can be sent to recurlens@gmail.com. The operator's legal identity, retention schedule, and rights-request process are not yet published. This informational beta draft is not a final service notice.
The operator should obtain qualified legal review for the actual service, users, locations, and processing before treating this notice as launch-ready.