Terms of Service
Effective date: 2026-09-01 Last updated: 2026-09-01
These Terms of Service ("Terms") govern your use of the SubTrack mobile application and related services (collectively, the "Service"), provided by Anotherlabs, a sole proprietorship based in Türkiye ("we", "us", "Anotherlabs").
By creating an account or otherwise using the Service, you agree to these Terms and to our Privacy Policy. If you do not agree, do not use the Service.
1. Eligibility
You must be at least 13 years old (or 16 in the EEA / UK, depending on local law) to use the Service. If you use the Service on behalf of a business or other entity, you represent that you have authority to bind that entity to these Terms.
2. Your account
You are responsible for:
- Keeping your login credentials confidential.
- All activity that occurs under your account.
- Providing accurate and current account information.
If you suspect unauthorized access, contact febraistanbul@gmail.com immediately.
We may suspend or terminate accounts that we reasonably believe violate these Terms, applicable law, or that pose a security risk to other users or to the Service.
3. The Service
SubTrack helps you track recurring subscriptions, receive renewal reminders, and optionally analyze bank transactions to identify recurring charges.
The Service is provided "as is". We do not guarantee that:
- Renewal reminders will always be delivered on time. Notification delivery depends on third-party push providers (Apple, Google) and on your device's connectivity and OS settings. Do not rely on SubTrack as the sole source of truth for cancellation deadlines.
- Imported bank transactions are complete or accurate. Bank-connection data is provided by a third-party open-banking provider and may be delayed, incomplete, or miscategorized.
- The Service will be uninterrupted, error-free, or available in every country.
The Service is a personal finance assistant. It is not financial, tax, legal, or accounting advice.
4. Subscriptions and payments
4.1 Free and paid tiers
Some features of the Service are free. Other features require a paid subscription that you purchase through the Apple App Store or Google Play.
4.2 Billing
All paid subscriptions are billed by the store (Apple or Google), not by Anotherlabs directly. Pricing, currency, taxes, free trial length, and renewal terms are shown to you in-store at the moment of purchase.
Paid subscriptions auto-renew at the end of each billing period unless you cancel at least 24 hours before the end of the current period, as required by the store's standard rules. You can manage or cancel your subscription at any time through your Apple ID or Google Play account settings.
4.3 Refunds
Refunds for in-app purchases are handled by Apple or Google according to their respective refund policies. Anotherlabs cannot directly issue store refunds. For consumer-protection complaints in Türkiye, you retain your statutory rights regardless of these Terms.
4.4 Price changes
We may change the price of paid subscriptions. Price increases will be communicated through the store at least as far in advance as the store's rules require. Continued use of the paid subscription after a price change takes effect constitutes acceptance of the new price.
5. Acceptable use
You agree not to:
- Use the Service to violate any law or the rights of any third party.
- Reverse engineer, decompile, or attempt to extract the source code of the Service, except where this restriction is prohibited by law.
- Probe, scan, or test the vulnerability of the Service, except under a responsible-disclosure security report sent to febraistanbul@gmail.com.
- Interfere with or disrupt the Service, the servers, or the networks connected to the Service.
- Use the Service to send spam, malware, or unsolicited content.
- Resell, sublicense, or commercially exploit the Service without our written permission.
- Submit data that you do not have the right to submit (including transaction data of a person other than yourself).
We may suspend or terminate accounts that violate this section.
6. Your content
You retain ownership of the subscription data, notes, and other content you add to the Service ("Your Content").
You grant Anotherlabs a limited, worldwide, royalty-free license to host, store, transmit, display, and process Your Content solely to operate, secure, and improve the Service for you. We do not use Your Content for advertising, and we do not sell Your Content.
You are solely responsible for the legality and accuracy of Your Content.
7. Bank-connection feature
The optional bank-connection feature is provided through a regulated open-banking provider disclosed in-app at the moment of connection. By using this feature you authorize that provider to access transaction data from the bank account(s) you select, on a read-only basis, for the purpose of identifying recurring charges within the Service.
You may disconnect the bank link at any time. See the Privacy Policy for retention details.
8. Third-party services
The Service relies on third-party platforms (Apple, Google, Cloudflare, our hosting provider, Resend, open-banking provider). Your use of those platforms is subject to their own terms. Anotherlabs is not responsible for outages, errors, or policy changes of those third parties.
9. Intellectual property
The Service, including its software, design, trademarks, and content (other than Your Content), is owned by Anotherlabs or its licensors and is protected by intellectual-property law. These Terms do not grant you any rights in our intellectual property other than the limited right to use the Service as offered.
10. Disclaimers
To the maximum extent permitted by law, the Service is provided "as is" and "as available" without warranties of any kind, express or implied, including without limitation warranties of merchantability, fitness for a particular purpose, accuracy of bank-connection data, or non-infringement.
Anotherlabs does not warrant that:
- The Service will meet your specific requirements;
- The Service will be uninterrupted, timely, secure, or error-free;
- Any defects will be corrected.
You use the Service at your own risk and you are solely responsible for cancelling subscriptions you no longer want.
11. Limitation of liability
To the maximum extent permitted by law:
- Indirect damages excluded. Anotherlabs is not liable for indirect, incidental, special, consequential, exemplary, or punitive damages — including lost profits, lost savings, lost data, missed subscription cancellation deadlines, or business interruption — even if advised of the possibility of such damages.
- Aggregate cap. Anotherlabs' total aggregate liability arising out of or relating to the Service is limited to the greater of (a) the amount you paid Anotherlabs for the Service in the 12 months preceding the event giving rise to the claim, or (b) USD 50.
Nothing in these Terms limits liability that cannot be limited by law, including liability for fraud, gross negligence, willful misconduct, or your statutory consumer rights in your country of residence.
12. Indemnification
You agree to defend, indemnify, and hold harmless Anotherlabs from any claim, liability, damage, loss, and expense (including reasonable legal fees) arising out of or in any way connected with (a) your use of the Service, (b) your violation of these Terms, or (c) your violation of any applicable law or third-party right.
13. Termination
You may stop using the Service and delete your account at any time from in-app settings.
We may suspend or terminate your access to the Service if:
- You materially breach these Terms.
- We are required to do so by law.
- The Service is discontinued.
Upon termination, the sections that by their nature should survive (including ownership, disclaimers, limitation of liability, indemnification, and governing law) will survive.
14. Changes to the Terms
We may update these Terms from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be notified in-app or by email at least 14 days before they take effect, except for changes required by law, which may take effect immediately. Continued use of the Service after a change means you accept the updated Terms.
15. Governing law and disputes
These Terms are governed by the laws of the Republic of Türkiye, without regard to conflict-of-laws rules.
If you are a consumer resident in the EEA, UK, Türkiye, or another jurisdiction whose mandatory consumer law applies, that law continues to apply in addition to these Terms, and nothing in these Terms removes the consumer protections of your country of residence.
Disputes that cannot be resolved informally shall be submitted to the courts of Istanbul (Çağlayan) Adliyesi, Türkiye, except where a consumer's right to bring proceedings in the courts of their country of residence applies.
You may also use the European Commission's Online Dispute Resolution platform at https://ec.europa.eu/consumers/odr/ if you are a consumer in the EEA.
16. Miscellaneous
- Entire agreement. These Terms and the Privacy Policy are the entire agreement between you and Anotherlabs about the Service.
- Severability. If any provision is held unenforceable, the remaining provisions remain in effect.
- No waiver. Failure to enforce a provision is not a waiver of that provision.
- Assignment. You may not assign these Terms without our consent. We may assign these Terms in connection with a business transfer.
- Notices to us. Send notices to febraistanbul@gmail.com.
Anotherlabs (sole proprietorship, Türkiye) Email: febraistanbul@gmail.com
Privacy Policy
Effective date: 2026-09-01 Last updated: 2026-09-01
This Privacy Policy describes how Anotherlabs (a sole proprietorship operating under the trade name "Anotherlabs", based in Türkiye; referred to as "we", "us", or "Anotherlabs") collects, uses, and shares information when you use the SubTrack mobile application and related services (collectively, the "Service").
If you do not agree with this policy, do not use the Service.
1. Who we are
- Trade name: Anotherlabs
- Form: Sole proprietorship (şahıs şirketi), Türkiye
- Contact for privacy inquiries, data access requests, and complaints: febraistanbul@gmail.com
- App: SubTrack
For users in the European Economic Area, the United Kingdom, or Türkiye (KVKK), Anotherlabs acts as the data controller for the personal data described below.
2. Data we collect
We only collect what is necessary to operate the Service. We do not sell personal data and we do not share it with advertisers or data brokers.
2.1 Account data
When you create an account, we collect:
- Email address
- A hashed password (we never store your password in clear text; passwords are hashed using industry-standard algorithms)
- Display name
- Preferred currency and timezone
- Email verification status
If you sign in with Apple or Google, we receive an opaque external identifier and an email address from that provider. We do not receive your provider password.
2.2 Subscription tracking data
The Service exists to help you track recurring subscriptions (e.g. Netflix, Spotify). You enter this data yourself. It includes:
- Subscription name, merchant, category, currency, amount, billing cycle, renewal date, notes
- Optional price history and plan history you record
- Optional tags you create
2.3 Optional bank-connection data
If you choose to connect a bank account through the Service's optional bank-linking feature, we receive transaction data from a regulated open-banking provider for the sole purpose of helping you identify recurring charges. Specifically we receive and store:
- Bank account identifiers (masked account numbers, account names, currencies)
- Transactions (date, merchant string, amount, currency)
- Normalized merchant aliases the Service derives from transactions
You can disconnect a bank link at any time from in-app settings. When you disconnect, the underlying provider access token is revoked and the imported transactions are deleted within 30 days, except where law requires us to retain a record.
We do not receive or store your online-banking username or password. The bank link is performed by the regulated open-banking provider directly with your bank.
2.4 Billing data
When you purchase a subscription on the App Store or Google Play, the store handles the payment. We receive from Apple/Google:
- A purchase receipt or transaction identifier
- Product identifier
- Renewal/expiration status
- The store-side subscriber identifier
We do not receive your full credit card number or store payment details on our servers.
2.5 Device and technical data
- Push notification tokens (Apple Push Notification service / Firebase Cloud Messaging), used only to deliver reminders you have enabled.
- Approximate device language and locale.
- IP address and user agent are recorded on authentication, admin actions, and support tickets for security and abuse prevention. IP addresses are retained for up to 90 days unless tied to an active security investigation.
- Crash and error events (no personal content, just stack traces and request identifiers).
2.6 Support data
If you contact support from within the app, we receive the message you send, your account email, and the user-agent of the device used to send the ticket.
2.7 What we do not collect
- We do not access your contacts, photos, calendar, microphone, or location.
- We do not use third-party advertising SDKs.
- We do not use cross-app or cross-site tracking. We do not participate in any "Identifier for Advertisers" (IDFA) data flow.
- We do not run third-party analytics that build a personal profile across apps.
3. How we use your data
We use the data described above to:
- Create and authenticate your account.
- Operate the core subscription-tracking features you use.
- Send reminders and renewal notifications you have enabled.
- Process in-app purchases and verify your subscription entitlements.
- Detect and prevent abuse, fraud, and brute-force attacks.
- Respond to support requests.
- Comply with legal obligations (tax, accounting, lawful requests).
We do not use your data for advertising and we do not perform automated decision-making that produces legal effects on you.
4. Legal bases (EEA / UK / Türkiye)
For users in the EEA, the United Kingdom, or Türkiye, our legal bases under the GDPR / UK GDPR / KVKK are:
- Performance of a contract — operating the account and features you sign up for.
- Legitimate interests — securing the Service against abuse, preventing fraud, debugging, and direct service-related communications.
- Consent — optional features like push notifications, bank linking, and optional email categories. You can withdraw consent at any time without affecting prior processing.
- Legal obligation — retention of billing records as required by tax and consumer-protection law.
5. Sharing your data
We share personal data only with the categories of processors strictly required to deliver the Service:
| Purpose | Recipient | Region |
| Cloud hosting and database | Servers we operate ourselves at a hosting provider in Istanbul, Türkiye | Türkiye |
| CDN and edge security | Cloudflare | Global edge |
| Transactional email delivery | Resend | United States / EU |
| Push notification delivery | Apple (APNS), Google (Firebase Cloud Messaging) | Apple/Google regions |
| In-app purchase processing | Apple App Store, Google Play | Apple/Google regions |
| Bank-connection data (only if you opt in) | Regulated open-banking provider disclosed in-app at the moment of connection | EU/EEA |
| Crash and error telemetry | Self-hosted; no third-party analytics SDK | — |
Each recipient processes personal data only on our instructions, under a written data-processing agreement where required by law.
Your data is processed on servers we operate in Türkiye. Transactional email, push delivery and in-app purchase processing remain with the providers listed above and may involve transfers to the United States or to Apple's and Google's regions; where those providers offer them, such transfers are covered by Standard Contractual Clauses. If you are in the EEA or the UK, note that your data is transferred to Türkiye, which is not covered by a European Commission adequacy decision; we rely on Standard Contractual Clauses and the safeguards described in section 9 for that transfer.
We do not sell personal data and we do not share personal data for cross-context behavioral advertising.
6. Retention
| Data | Retention |
| Account profile | Until you delete the account, plus up to 30 days for soft deletion / recovery |
| Subscription entries you create | Until you delete them or delete the account |
| Bank-connection imported transactions | Up to 24 months after import, or until you disconnect the bank link (then deleted within 30 days) |
| Push tokens | Refreshed regularly by the OS; revoked on logout or account deletion |
| Authentication audit logs (IP, user-agent) | Up to 90 days |
| Support tickets | Up to 24 months after the ticket is closed |
| Files attached to support tickets | Deleted 90 days after the ticket is closed; the correspondence itself is kept for the period above |
| Export files you generate (PDF/CSV) | Deleted 90 days after the export is created, from both our records and the storage they are written to |
| Billing records | As required by Turkish tax and consumer law (typically up to 10 years) |
| Backups | Encrypted backups roll over within 35 days |
When you delete your account, we delete or anonymize the above within the retention windows. Some data must be kept for the legal periods listed.
7. Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your personal data (subject to legal retention obligations).
- Restrict or object to certain processing.
- Receive a portable copy of your data (account profile + subscription entries) in JSON or CSV.
- Withdraw consent for optional features at any time.
- Lodge a complaint with your local data protection authority (in Türkiye: KVKK; in the EU: your national DPA; in the UK: ICO).
You can exercise most of these rights directly from the app:
- Export my data: Settings → Export
- Delete my account: Settings → Account → Delete account
For anything else, write to febraistanbul@gmail.com. We respond within 30 days.
8. Children
The Service is not directed at children under 13 (or under 16 in the EEA / UK, depending on local law). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
9. Security
We protect your data with:
- TLS 1.2+ in transit (TLS 1.3 on modern clients).
- Password hashing using industry-standard algorithms; we never store plain-text passwords.
- Encryption at rest for sensitive fields (push tokens, outbox payloads).
- Two-factor authentication for our admin panel; rate limiting and brute-force lockout on auth endpoints.
- Encrypted, regularly tested backups.
No system is perfectly secure. If you discover a security issue, contact febraistanbul@gmail.com with the subject line "security". We do not pursue good-faith security researchers who report vulnerabilities responsibly.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be notified in-app or by email before they take effect. Continued use of the Service after a change means you accept the updated policy.
Anotherlabs (sole proprietorship, Türkiye) Email: febraistanbul@gmail.com
For data protection inquiries, please include the word "privacy" in the subject line.