Privacy Policy

Last updated 29 September 2026

Who this covers

YourLoop is the subscription tracker at useyourloop.com. This policy describes the product as it works today. YourLoop does not publish a company registration number or a postal address.

You can use YourLoop by adding subscriptions yourself. Connecting Gmail is optional and starts only after you choose it.

Google access starts with your consent

YourLoop does not read Gmail unless you click Connect Gmail and approve Google’s consent screen. You can refuse, and you can disconnect later.

The consent screen asks for these scopes, and no others:

  • openid, email, and profile — so YourLoop can tell which Google account you connected and show that account’s email address.
  • gmail.readonly — so YourLoop can search and read mail for automatic subscription discovery and later sync.

YourLoop does not request permission to send, delete, label, or otherwise change your mail.

Why gmail.readonly is needed

Finding a subscription means reading the message, not only its labels. The amount, merchant, billing period, and renewal date are usually in the body or in an invoice PDF. Google’s narrower Gmail scopes do not include that content. gmail.readonly is the read-only scope that allows YourLoop to read it. YourLoop uses that access only for subscription discovery and continuous sync.

What Gmail data is accessed

After you connect, YourLoop does two kinds of reads:

  • First scan. YourLoop searches about the last 180 days for messages that look like receipts, invoices, renewals, trials, or billing notices, and reads up to 250 of those messages.
  • Later sync. While Gmail stays connected, YourLoop checks for newly arrived messages (an hourly job, and when you choose Sync now) and reads up to 100 of them per run. That is how renewals, price changes, and cancellations are noticed. A new message is read so YourLoop can decide whether it is a subscription. Messages that are not are discarded.

For a message being parsed, YourLoop reads the subject, sender, date, snippet, and plain-text body. HTML is reduced to text and then dropped. If the message has an invoice PDF, YourLoop may download up to two PDFs, extract their text, and discard the file bytes. It does not run optical character recognition on scanned images.

YourLoop also reads the Google account id and email address for the account you connected.

What is stored, and what is not

Raw email bodies are not saved. HTML, PDF files, and attachment bytes are not saved. YourLoop does not keep a copy of your mailbox.

What is stored, when a message is treated as a subscription, is structured billing data:

  • Gmail message id, thread id, sender address, subject, and received time
  • Provider, plan name, amount, currency, billing interval, renewal date, and parser notes such as an invoice id or a price change

The subject line and sender are kept so you can see where a suggestion came from. Importing a suggestion creates a subscription record (name, price, currency, cycle, and next payment date). Subscriptions you type in yourself are stored the same way.

The connection record stores the Google account id, the Google email address, the granted scopes, connection status, and the last sync time.

OAuth tokens

Google access tokens and refresh tokens are encrypted with AES-256-GCM before they are stored. The encryption key stays on the server. Tokens are not shown in the app.

When you disconnect Gmail in Discover, YourLoop asks Google to revoke the grant and deletes the encrypted tokens. The connection is marked disconnected. Subscriptions you already imported, and discovery rows already saved, stay until you remove them or delete your account. Revocation is attempted even if Google does not accept it; the tokens are still deleted from YourLoop.

You can also revoke YourLoop at Google Account permissions. Deleting your YourLoop account removes the stored tokens, but it does not itself call Google’s revoke endpoint. Disconnect Gmail first, or revoke access on that Google page, if you want the grant removed at Google.

Deleting your account

In Settings → Account, you can permanently delete the YourLoop account by typing your email to confirm. That deletes the login and, through database cascade, the profile, subscriptions, reminder history, Gmail connection (including tokens), discoveries, and sync events stored for that account.

Who else receives data

YourLoop does not sell Google user data and does not use it for advertising. It does not send Gmail content to a third-party AI model. Parsing runs on YourLoop’s servers with YourLoop’s own rules.

Processors that handle data needed to run the product:

  • Supabase stores the database and authentication data, in the EU (Frankfurt). That includes account records, encrypted tokens, and the subscription metadata described above.
  • Vercel hosts the site. Gmail messages are parsed in YourLoop server functions, currently in Frankfurt, and are not written to a mailbox archive.
  • Resend sends YourLoop’s own email: sign-in and password messages, and renewal reminders to the email address on your YourLoop account. A reminder can include a subscription name, price, and date that you saved or that was extracted from a billing email. Resend does not receive your mailbox or OAuth tokens.
  • Google receives the OAuth consent and the Gmail API calls you approved.
  • Public logo and icon services may be asked for a brand image using a company name or domain. They are not sent message bodies or tokens.

Google API Services User Data Policy

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means:

  • Google user data is used only to provide subscription discovery, sync, and the subscription records you keep in YourLoop.
  • It is not sold, not used for ads, and not used to train generalized AI models.
  • It is transferred only to the processors above, and only to run those features, secure the service, or comply with law.
  • Email bodies are not stored, so they are not available for later human review. The subject and billing fields that are stored exist so the product can show you what it found.

Other account data

If you create an account without Google, YourLoop stores the email and password credentials through Supabase Auth, plus profile settings (name, currency, time zone, and reminder choices), subscriptions you add, and reminder delivery records. YourLoop does not connect to your bank or card accounts.

Changes

If this policy changes, the updated date above will change with the page at /privacy. The terms describe use of the product.