Privacy Policy

Comprehensive transparency on how RenewGuard processes, secures, and respects your personal data under the EU General Data Protection Regulation (GDPR).

Effective date: August 16, 2026

1. Data Controller & Governance

RenewGuard ("we", "our", or "us") operates the subscription management platform available at renewguard.net and renewguard.pages.dev. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Controller responsible for your personal data is:

Panagiotis Koletsos (RenewGuard Data Governance)

Email: [email protected]

Location: Athens, Hellenic Republic (European Union)

2. Categories of Personal Data & Retention Periods (GDPR Art. 13(2)(a))

We adhere strictly to the principle of data minimization (GDPR Article 5(1)(c)). We only collect data necessary to provide and secure our subscription tracking services. Under GDPR Article 13(2)(a), the criteria and retention periods governing each category are detailed below:

Account & Identity Data

Data Collected: Email address, display name, account password (stored securely as salted argon2/bcrypt hashes by Supabase Auth), and MFA TOTP secret keys.

Retention Period: Retained for the active duration of your account. Permanently erased immediately upon self-service account deletion (or within 30 days of a verified unauthenticated request). Encrypted disaster recovery database backups rotate on a strict 30-day lifecycle with zero residual retention.

Subscription & Financial Records

Data Collected: Service names, categories, costs, billing frequencies, renewal dates, payment history, and payment method aliases (e.g., "Visa •••• 4242").

Retention Period: Retained for active subscription management. Permanently purged immediately upon individual record deletion by the user or upon complete account erasure.

Notification & User Preferences

Data Collected: Preferred currency, monthly budget limits, date formatting, email reminder preferences, and consent choices.

Retention Period: Retained for the active lifecycle of your account. Affirmative cookie and telemetry consent records are retained for up to 1 year or until explicitly modified or revoked.

Security & Session Metadata

Data Collected: IP addresses (processed temporarily for rate limiting and bot mitigation via Cloudflare Turnstile), browser user-agent, session timestamps, and authentication audit logs.

Retention Period: Active session tokens and account activity records are retained during account tenure or until session revocation / account deletion. Edge bot mitigation and transient IP logs are retained for a maximum of 30 days in platform diagnostic logs.

3. Legal Bases & Processing Purposes (GDPR Art. 6)

We process your personal information only when backed by an explicit statutory legal basis with defined storage criteria:

  • Contractual Necessity (Art. 6(1)(b)): To operate your account, track subscriptions, compute spending analytics, and dispatch renewal reminders you configured. Storage criteria: Retained for the duration of the active service contract and purged immediately upon account termination.
  • Legitimate Interests (Art. 6(1)(f)): To maintain application security, mitigate brute-force and DDoS attacks, prevent fraud, and ensure database integrity. Storage criteria: Security event and rate-limiting metadata retained for up to 30 days.
  • Explicit Consent (Art. 6(1)(a)): For non-essential analytics and marketing communications, managed via our granular Cookie Consent Banner. Storage criteria: Consent records retained for up to 1 year or until consent is affirmatively withdrawn.
  • Legal Obligations (Art. 6(1)(c)): To comply with statutory data retention and legal audit requests where mandated by applicable EU or member state laws. Storage criteria: Retained strictly for statutory limitation periods required by law.

4. Authorized Subprocessors & Data Transfers

We partner with enterprise infrastructure providers governed by Data Processing Agreements (DPAs) incorporating the European Commission’s Standard Contractual Clauses (SCCs):

SubprocessorPurpose & Data CategoriesLocationTransfer Mechanism & Retention
Supabase Inc.PostgreSQL Database, Auth, Edge Functions (Account data, subscriptions, payments)EU (Frankfurt) / USEU-US DPF / Standard Contractual Clauses (Active account tenure; immediate cascading erasure upon deletion; 30-day backup cycle)
Cloudflare Inc.Turnstile Bot Defense, Edge CDN, DNS (IP addresses, request headers)Global Edge NetworkEU-US DPF / Standard Contractual Clauses (Transient request processing; edge security diagnostics retained max 30 days)
Resend Inc.Transactional Email & Renewal Reminders (Email addresses, reminder notifications)US / EU RelaysStandard Contractual Clauses (Transient dispatch; delivery and bounce audit logs retained max 30 days)
OpenAI, LLCAI Subscription Comparison & Optimization Insights (Service names, categories, monthly costs, usage frequency, ratings)United StatesEU-US DPF / SCCs (Zero retention for model training; API transient processing with zero persistent storage)

5. Your Statutory Data Subject Rights

Under GDPR Chapter III, you possess strong, actionable rights regarding your personal data:

Right of Access & Portability (Arts. 15 & 20): You can export a full, structured machine-readable JSON copy of all your records anytime from Account Settings > Export Personal Data.

Right to Erasure / To Be Forgotten (Art. 17): You can permanently delete your account and all associated subscriptions, payments, and activity records with zero residual retention via Account Settings > Danger Zone, or without signing in via our public Account Deletion Request page.

Right to Rectification (Art. 16): You can modify your profile name, subscription details, budget, and notification settings directly in the web app.

Right to Withdraw Consent (Art. 7(3)): You can modify or revoke cookie and telemetry consent at any time via the Cookie Policy page or consent manager.

Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) or your local EU supervisory authority:

Hellenic Data Protection Authority (HDPA) • Kifissias 1-3, 115 23 Athens, Greece • www.dpa.gr