IDLE / PRIVACY

Privacy Policy

What Idle does

Idle is a subscription-management application designed to help users identify recurring subscriptions, understand recurring spending, and reach relevant cancellation pages or instructions.

Account information

When you create an Idle account, authentication is provided through Supabase. Idle may process your email address, account identifier, and subscription records associated with your account.

Google and Gmail data

If you choose to connect Gmail, Idle requests the Google Gmail read-only permission. This permission allows the service to read Gmail messages for the purpose of identifying subscription-related receipts, renewal notices, free-trial notices, and recurring billing information. The permission does not allow Idle to send, modify, or delete Gmail messages.

Idle uses Gmail-derived information only to provide and improve the subscription-detection and subscription-management features requested by the user. Derived subscription records may include information such as a service or merchant name, recurring amount, renewal information, message source, status, and a cancellation URL when available.

Google API Services User Data Policy

Idle's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How connection credentials are handled

Google OAuth credentials used to maintain a Gmail connection are handled by server-side Supabase Edge Functions rather than being placed in the public website source code. Gmail refresh tokens are encrypted before being stored in the application's private backend storage.

Sharing and selling data

Idle does not sell Gmail data. Gmail data is not used for advertising. Data is shared with service providers only as needed to operate the application, such as Supabase for authentication, database, and server-side infrastructure, and Google for Gmail authorization and API access.

Data retention and deletion

Subscription records remain associated with your account until they are removed or the account data is deleted. Gmail connection information is retained only as needed to provide the connected-inbox feature. A production release of Idle should provide a clear way to disconnect Gmail and request account-data deletion.

Security

Idle uses authentication, database access controls, server-side secrets, and encrypted storage for Gmail refresh tokens. No internet service can guarantee absolute security, but the application is designed to avoid exposing private server credentials in client-side code.

Changes to this policy

This policy may be updated as Idle's functionality changes. The date at the top of this page will be updated when material changes are made.

Contact

For privacy questions or requests, use the developer contact email listed on Idle's Google OAuth consent screen.