IDLE / PRIVACY
Privacy Policy
Last updated: August 21, 2026
What Idle does
Idle is a subscription-management application designed to help users identify recurring subscriptions, understand recurring spending, and reach relevant cancellation pages or instructions.
Account information
When you create an Idle account, authentication is provided through Supabase. Idle may process your email address, account identifier, and subscription records associated with your account.
Google and Gmail data
If you choose to connect Gmail, Idle requests the Google Gmail read-only permission. This permission allows the service to read Gmail messages for the purpose of identifying subscription-related receipts, renewal notices, free-trial notices, and recurring billing information. The permission does not allow Idle to send, modify, or delete Gmail messages.
Idle uses Gmail-derived information only to provide and improve the subscription-detection and subscription-management features requested by the user. Derived subscription records may include information such as a service or merchant name, recurring amount, renewal information, message source, status, and a cancellation URL when available.
Google API Services User Data Policy
Idle's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How connection credentials are handled
Google OAuth credentials used to maintain a Gmail connection are handled by server-side Supabase Edge Functions rather than being placed in the public website source code. Gmail refresh tokens are encrypted before being stored in the application's private backend storage.
Sharing and selling data
Idle does not sell Gmail data. Gmail data is not used for advertising. Data is shared with service providers only as needed to operate the application, such as Supabase for authentication, database, and server-side infrastructure, and Google for Gmail authorization and API access.
Data retention and deletion
Subscription records remain associated with your account until they are removed or the account data is deleted. Gmail connection information is retained only as needed to provide the connected-inbox feature. A production release of Idle should provide a clear way to disconnect Gmail and request account-data deletion.
Security
Idle uses authentication, database access controls, server-side secrets, and encrypted storage for Gmail refresh tokens. No internet service can guarantee absolute security, but the application is designed to avoid exposing private server credentials in client-side code.
Changes to this policy
This policy may be updated as Idle's functionality changes. The date at the top of this page will be updated when material changes are made.
Contact
For privacy questions or requests, use the developer contact email listed on Idle's Google OAuth consent screen.