Unsubfox

Unsubfox · Updated September 27, 2026

Privacy

This Privacy Policy explains how Unsubfox handles personal information when you visit our website, complete a quiz, use your account or connected-mailbox features, make a purchase, or contact us. It also explains your choices and rights. Reading this notice, using the service or accepting our Terms of Service does not constitute consent to every use of your information.

support@unsubfox.com

Who is responsible

Synctech sp. z o.o. is the controller responsible for Unsubfox. Its registered name is SYNCTECH SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, registered office Plac Bankowy 2, 00-095 Warszawa, Poland, KRS 0001081502, NIP 7011186644. Contact support@unsubfox.com for privacy questions and rights requests, or write to that address.

Your email provider, payment provider and merchants may separately determine how they use information for their own services. Their privacy notices also apply to that processing.

Information we collect

Account information includes your email address, name where supplied, account identifier, verification status and preferences. Quiz and saved-plan information includes your answers, email, selected plan, progress and campaign attribution. Financial-organization information includes merchant names, subscription prices, billing periods, recorded payments, renewal dates, expenses, budgets and notes. We obtain these from you, connected email or a bank account you choose to connect.

Mailbox information includes the connected address and connection status, message sender and reply-to details, subjects, bodies, dates, message and thread identifiers, and correspondence. Merchant requests may include your reason, supporting evidence, contact details, order or account references and last four card digits. Do not provide passwords, full card numbers or security codes.

Stripe supplies membership, payment-status, customer, subscription and invoice records. Stripe processes payment details entered in its checkout or portal. We also receive support messages, authentication and security information, device/browser information, identifiers and selected usage events. IP addresses and submitted email addresses can be used for abuse prevention.

Messages and documents can contain information about others, including merchant staff and people named on bills. We receive this from your mailbox, your submission or the correspondent. Avoid providing information about others that is unnecessary for your request.

Connected email and artificial intelligence

Connecting Gmail or Outlook is optional. Composio manages the connection using the permissions presented during authorization. It permits reading messages and sending correspondence for authorized requests. An initial discovery search can cover the preceding year. Messages may be retrieved before relevance is determined; Outlook discovery retrieves messages before filtering them. Access is therefore not confined to emails already identified as receipts.

We store fetched messages, extracted facts and relevant correspondence. Message content and request information are sent to OpenRouter and the model provider handling the request for extraction, drafting and interpretation. This happens outside your device. Results can be incorrect. Some follow-ups are sent automatically within a request you authorize; connecting email alone does not authorize cancellation.

You can review information, stop a request or contact support about an error. Stop or finish an active request before disconnecting its mailbox. You can also revoke access through Google or Microsoft. Disconnection does not recall sent messages, cancel membership or automatically erase stored records.

Emails may contain sensitive information, including health or religious information. We do not ask you to supply it for ordinary subscription management. Processing special-category information requires an additional legal condition; ordinary mailbox authorization is not blanket consent for it or for information about other people.

Information received through Google APIs is subject to Google's API Services User Data Policy and applicable Google Workspace requirements, including Limited Use restrictions. Those restrictions limit permitted uses, transfers and human access. Mailbox authorization does not authorize advertising uses or general-purpose AI training.

Google API Services User Data Policy
Google Workspace API User Data and Developer Policy

Purposes and legal bases

Contract and requested pre-contract steps, Article 6(1)(b) GDPR: creating your account, preparing an order or saved plan you request, processing payment, supplying necessary subscription-management features and sending service communications. Mailbox processing falls within this basis only to the extent necessary for the feature you request; mailbox access is separately authorized.

Legitimate interests, Article 6(1)(f): proportionate account protection, abuse investigation, support outside a contract and establishing or defending legal claims. Necessary incidental information about correspondents may be processed in our and our customer's interest in handling an authorized request, subject to balancing their rights. A customer's contract does not provide a blanket basis for other people's information.

Legal obligations, Article 6(1)(c): accounting and tax records, responding to lawful requirements, privacy rights and required notices. Necessary permission and suppression records support accountability and respect withdrawals; limited evidence may also be needed for legal claims.

Consent, Article 6(1)(a), is required for optional processing where consent is the applicable basis, including optional analytics and promotional emails. Device access and electronic marketing also have separate permission requirements. This notice does not supply those permissions. Withdrawal does not affect earlier lawful processing.

Information necessary for a particular feature is voluntary, but without it we may be unable to supply that feature. Manual features do not require a mailbox connection. Refusing optional marketing does not prevent purchasing or using the core service.

Who receives information

Providers include Supabase Pte. Ltd. for database and authentication; Sampark, Inc., trading as Composio, for mailbox connections; OpenRouter, Inc. and the model providers handling requests for AI processing; and Stripe Payments Europe, Limited and, where applicable, Stripe Technology Europe, Limited for payment services.

Plus Five Five, Inc., trading as Resend, delivers emails; Migadu-Mail GmbH handles configured reply mailboxes; Vercel Inc. hosts the public website; and PostHog provides product analytics. Hosting and communications providers can receive information needed to deliver and protect those services.

Providers can act as processors or, for particular purposes, independent controllers. Merchants receive the information necessary for requests you authorize. Advisers and authorities may receive information for applicable legal duties or claims. A business transfer remains subject to data-protection law and applicable Google-data restrictions.

We do not offer customer data for sale. Advertising disclosures can nevertheless fall within legal definitions of sale or sharing even without payment. Before introducing materially different advertising uses, we will explain them and obtain any required permissions; promotional-email permission does not authorize them.

International processing

Information can be processed outside Poland and the European Economic Area, including in the United States. PostHog EU Cloud stores customer-user data in Germany, while Resend stores email data in the US. OpenRouter and model providers can process information internationally. An EU hosting region does not mean all provider access and processing remain in the EEA.

Where required, international transfers need an applicable adequacy decision or appropriate safeguards, such as European Commission standard contractual clauses and any necessary supplementary measures. Contact support@unsubfox.com for information about a transfer and a copy of the applicable safeguards, subject to necessary redactions.

Cookies, storage and analytics

Cookies and browser storage support authentication, account security, quiz progress, offers and navigation. Quiz cookies last up to 30 days; offer cookies up to 365 days; authentication-cookie settings can permit up to 400 days, although tokens or sessions can expire sooner. Session storage generally lasts for the browser session; browser restoration can extend it.

Where enabled, PostHog measures selected events such as quiz progress, connection success and request outcomes using browser and account identifiers. Identifiers are pseudonymous, not necessarily anonymous. Session recording and automatic click capture are disabled. Selected event fields exclude names, email addresses, mailbox content, merchant names, amounts and refund reasons. Campaign and advertising-click identifiers can be stored separately with saved plans.

Some local storage, including analytics identifiers, has no automatic expiry. Browser analytics is configured to respect Do Not Track; this does not necessarily stop server-generated events or constitute Global Privacy Control support. Browser settings can block or remove storage, but do not erase server records or replace required consent. Contact us about analytics information or privacy choices.

Emails and marketing

Account, payment, security and merchant-request messages are service communications. Unsubfox promotional emails can include news, offers and saved-plan reminders and require the applicable permission. You can unsubscribe through the promotional email or contact support@unsubfox.com. We keep necessary suppression information to respect your choice. Unsubscribing from promotions does not stop essential service messages.

Retention and deletion

Retention depends on the purpose, your account and requests, legal obligations and any specific dispute. Account records, extracted subscription facts and correspondence support your account history and ongoing requests. Fetched messages and provider copies can remain after analysis; stopping a scan or disconnecting a mailbox does not automatically delete them.

Support and complaint records are retained as needed to handle the issue and any justified follow-up or claim. Security and claim evidence must be limited to the relevant purpose. Permission and minimal suppression records may remain after withdrawal to demonstrate compliance and prevent renewed marketing.

Ordinary accounting records generally have a five-year statutory period starting with the following financial year. Tax records ordinarily remain until five years after the end of the year payment was due, subject to extensions. Union OSS records, where applicable, have a ten-year period. Imported merchant receipts are not automatically our accounting records.

You may request erasure at support@unsubfox.com. Some records must remain for legal duties or specific claims; we explain applicable exceptions and limit their use. Processor copies and backups have separate retention and deletion processes. Account closure, membership cancellation and mailbox disconnection are separate actions.

Your privacy rights

GDPR applies to processing in the context of our Polish establishment, including for people outside the EEA. Subject to its conditions, you can request access, correction, erasure, restriction and portability, withdraw consent, and object to processing based on legitimate interests. You can object to direct marketing at any time. Where the law provides these protections, you can seek human intervention, express your view and challenge a decision based solely on automated processing that has legal or similarly significant effects.

Email support@unsubfox.com. We may seek proportionate identity verification. Requests are normally free and answered within one month. Where legally permitted for complex or numerous requests, we explain within that month why up to two additional months are needed.

You may complain to the President of Poland's Personal Data Protection Office at uodo.gov.pl or another competent supervisory authority. You need not complain to us first.

Where a US state privacy law applies, additional rights may include opting out of sale, advertising sharing, targeted advertising or covered profiling, limiting certain sensitive-information uses and freedom from unlawful discrimination. Authorized agents and appeals are available where the law provides them. Send requests or appeals to the same email. Applicable shorter deadlines apply; a US deadline does not extend a GDPR deadline.

Polish Personal Data Protection Office (UODO)

Security

We use sign-in and account-access checks. Application error records exclude raw mail bodies and provider response payloads; infrastructure-provider logs are separate. No method of transmission or storage is completely secure.

Children

Unsubfox is intended for adults aged 18 or over. Contact us if you believe a child has provided personal information so we can assess and address it.

Changes to this policy

We update this notice when practices or legal requirements change. Material changes are communicated by email or a prominent in-app notice, with advance notice where required. A changed policy does not itself supply consent for a new purpose.