Privacy Policy

Last updated: 28/07/2026

Who is responsible for your data

Subgent is operated by Coding Moon ApS (CVR 39889641), Uraniavej 2, 1. sal, 1878 Frederiksberg C, Denmark. Coding Moon ApS is the data controller for the personal data processed through Subgent. You can reach us at info@subgent.com for any privacy matter.

What we collect

To detect your subscriptions, Subgent processes the bank transactions you choose to share with us — either by connecting your bank account through our Open Banking provider (GoCardless Bank Account Data) or by importing a CSV file.

  • Your email address and basic profile (name, avatar).
  • Bank transaction data (dates, amounts, descriptions).
  • Bank connection metadata (institution, consent expiry).

Why we process your data and our legal basis

Under the GDPR we rely on the following legal bases:

  • Providing the service — to detect subscriptions and show your dashboard, we process your account and transaction data on the basis of our contract with you (GDPR Art. 6(1)(b)).
  • Bank connections — when you connect a bank via Open Banking, we process the transaction data you share on the basis of your explicit consent (GDPR Art. 6(1)(a)), which you can withdraw at any time.
  • Security and audit logs — to keep your account secure and prevent abuse, we process limited connection and sync metadata on the basis of our legitimate interests (GDPR Art. 6(1)(f)).
  • Sign-in emails — we send magic sign-in links to authenticate you on the basis of our contract with you.

What we never do

  • We never store your bank login credentials.
  • We never expose Open Banking access tokens to your browser.
  • We never cache private banking data at the edge.
  • We never run third-party analytics on your financial pages.

Who we share data with

We never sell your data. We share it only with the service providers (processors) that operate Subgent on our behalf, each under a data processing agreement:

  • GoCardless (Bank Account Data) — licensed Open Banking access to your bank transactions.
  • Vercel — application hosting (functions run in Frankfurt, fra1).
  • PlanetScale — database hosting in the EU (eu-central-1).
  • Resend — sending sign-in and reminder emails.
  • Google Cloud KMS — managing the encryption key that protects your data.
  • Vercel Analytics — privacy-friendly, aggregate usage statistics; never run on your financial pages.

Where your data lives

Subgent is EU-first. Application functions run in Frankfurt (fra1) and data is stored in the EU (eu-central-1). Sensitive provider data is encrypted at rest.

Your personal data is stored and processed within the EU. Where a provider may process limited data outside the EU/EEA, it is covered by the EU Standard Contractual Clauses.

How long we keep your data

  • Detected subscriptions and the transactions linked to them: kept until you delete them or close your account.
  • Transactions that are not part of a subscription: automatically deleted after 180 days.
  • Account and profile data: kept while your account is active.
  • Audit logs: kept for up to 12 months for security.
  • When you delete your financial data or account, the data is removed and your bank consent is revoked.

How your data is protected

In plain terms: your transactions are yours alone. No one can sit and read through your bank data — not other people who use Subgent, and not the people who build it.

  • Other users can never see your data. Everything you import or connect is tied to your account and only shown to you.
  • Even we can't read your transactions. The names and descriptions are scrambled (encrypted) using a key kept in a separate, locked vault — so even someone with a copy of the database just sees gibberish, and every time the app unlocks data it leaves a record.
  • We don't keep the full record from your bank — only the few details needed to recognise a recurring payment.
  • Anything that isn't a subscription is permanently deleted after 180 days. We keep your detected subscriptions, and not much else.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Erase your data (the “right to be forgotten”).
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent for bank connections at any time.

To exercise any right, contact info@subgent.com. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).

Cookies

We use only the cookies needed to keep you signed in. We do not use advertising or cross-site tracking cookies.

Your control

You can delete all of your financial data, or your entire account, at any time from your account page. Deleting financial data also revokes your bank consent with our Open Banking provider.

Audit logging

We keep audit logs of bank connection and sync events for security. We avoid logging raw transaction data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the date above.

Contact

Coding Moon ApS, Uraniavej 2, 1. sal, 1878 Frederiksberg C, Denmark. For any privacy question or to exercise your rights, contact info@subgent.com.