Privacy Policy

Your privacy is fundamental to everything we do at Subrosa. This policy explains how we collect, use, and protect your personal information.

Last Updated: January 17, 2026

Subrosa ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Password (stored in encrypted form)
  • Display name or username
  • Profile information (optional)
  • Role preferences within relationships (Dominant/Submissive)
  • Timezone and language preferences

1.2 Usage Data

We automatically collect certain information when you use the Service:

  • Features accessed and actions taken within the app
  • Date and time of access
  • Time spent on various features
  • Error logs and performance data
  • Interaction patterns with other users (within your relationships)

1.3 Device Information

We may collect information about your device, including:

  • Device type and model
  • Operating system and version
  • Unique device identifiers
  • Mobile network information
  • IP address
  • Browser type (for web access)

1.4 User-Generated Content

Content you create or share within the Service:

  • Chat messages and communications
  • Tasks, habits, punishments, and rewards you create
  • Notes, journals, and contracts
  • Photos and media you upload
  • Voice recordings and other attachments

1.5 Location Data

If you enable location features, we may collect your device's location data. This is only collected with your explicit consent and is used for features like location tracking and geofencing within your relationships. You can disable location sharing at any time in your device settings.

1.6 Financial Information

If you use our financial features (such as the Findom module), we may collect bank account information through our third-party payment processor, Teller. We do not store your full banking credentials on our servers. Please refer to Teller's privacy policy for information about how they handle your financial data.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Create and manage your account
  • Facilitate communication between relationship partners
  • Send you notifications related to your activities and relationships
  • Process and track tasks, habits, punishments, and rewards
  • Provide customer support and respond to inquiries
  • Analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues and security threats
  • Enforce our Terms of Service and protect users
  • Comply with legal obligations

Important: We never use your personal content (messages, photos, tasks, etc.) for advertising purposes or share it with third parties for marketing.

3. Data Sharing and Third-Party Services

3.1 Relationship Partners

Information you create within a relationship (tasks, messages, photos, etc.) is shared with your relationship partner(s) as part of the core functionality of the Service. You control what information you share within each relationship.

3.2 Service Providers

We work with trusted third-party service providers who assist us in operating the Service:

  • Supabase: Our primary database and authentication provider. Supabase stores your account data, user-generated content, and handles secure authentication. They maintain SOC 2 Type II compliance. Learn more at supabase.com/privacy
  • Teller: Our banking integration partner for financial features. Teller securely handles bank account connections and transaction data. Learn more at teller.io/privacy
  • Cloud Infrastructure: We use industry-standard cloud providers to host our services with appropriate security certifications

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders, etc.)
  • Government requests that comply with applicable law
  • Protection of our rights, privacy, safety, or property
  • Emergency situations involving potential threats to safety

3.4 Business Transfers

If Subrosa is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.

4. Data Security

We implement robust security measures to protect your personal information:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Encryption at Rest: Your data is encrypted when stored in our databases using AES-256 encryption
  • Secure Authentication: We use JWT-based authentication with secure token management
  • Password Security: Passwords are hashed using industry-standard algorithms and are never stored in plain text
  • Row-Level Security: Our database implements row-level security policies ensuring you can only access data you're authorized to view
  • Regular Security Audits: We conduct regular security assessments and penetration testing
  • Access Controls: Strict access controls limit employee access to user data on a need-to-know basis

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using industry best practices.

5. Your Rights and Choices

5.1 Access Your Data

You have the right to request a copy of the personal information we hold about you. You can access most of your data directly through the app settings, or contact us for a complete data export.

5.2 Correct Your Data

You can update your account information at any time through the app. If you need to correct other information, please contact us.

5.3 Delete Your Data

You can request deletion of your account and associated data at any time. Upon deletion:

  • Your account will be deactivated immediately
  • Your personal data will be deleted within 30 days
  • Some data may be retained for legal or legitimate business purposes
  • Anonymized/aggregated data may be retained for analytics

5.4 Data Portability

You have the right to receive your data in a structured, commonly used, and machine-readable format. Contact us to request a data export.

5.5 Withdraw Consent

Where we process your data based on consent, you may withdraw that consent at any time. This includes opting out of optional features like location tracking or push notifications.

5.6 Opt-Out of Communications

You can manage your notification preferences in the app settings. You can opt out of non-essential communications while still receiving important account-related messages.

6. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

6.1 Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Processing for our legitimate business interests (e.g., security, fraud prevention, service improvement)
  • Consent: Processing based on your explicit consent (e.g., location tracking, marketing communications)
  • Legal Obligation: Processing required to comply with applicable laws

6.2 Your GDPR Rights

In addition to the rights listed in Section 5, GDPR provides you with:

  • Right to Restriction: Request that we limit the processing of your data
  • Right to Object: Object to processing based on legitimate interests
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

6.3 International Data Transfers

Your data may be transferred to and processed in countries outside the EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

6.4 Data Protection Officer

For GDPR-related inquiries, you may contact our Data Protection Officer at privacy@subrosaapp.com

7. CCPA Compliance (California Users)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

7.1 Right to Know

You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.

7.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions permitted by law.

7.3 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights. We will not deny you goods or services, charge you different prices, or provide a different level of quality based on your privacy choices.

7.4 Do Not Sell My Personal Information

We do not sell your personal information. Subrosa has never sold user data and has no intention of doing so. We do not share your data with third parties for their direct marketing purposes.

7.5 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We will require verification of both your identity and the agent's authorization.

7.6 Contact for CCPA Requests

To exercise your CCPA rights, contact us at privacy@subrosaapp.com or use the in-app privacy settings. We will respond to verified requests within 45 days.

8. Cookie Policy

We use cookies and similar tracking technologies to improve your experience on our website and app. Cookies are small data files stored on your device that help us:

  • Keep you signed in to your account
  • Remember your preferences and settings
  • Understand how you use our Service
  • Improve performance and functionality

8.1 Types of Cookies We Use

  • Essential Cookies: Required for basic functionality (authentication, security)
  • Functional Cookies: Remember your preferences and personalization
  • Analytics Cookies: Help us understand usage patterns (privacy-focused analytics only)

8.2 Managing Cookies

You can manage cookie preferences through our cookie consent banner or your browser settings. Note that disabling essential cookies may affect the functionality of the Service.

For more detailed information about our use of cookies, please see our Cookie Policy.

9. Age Restrictions

18+ Only

Subrosa is intended solely for adults aged 18 years and older. We do not knowingly collect personal information from anyone under the age of 18. If you are under 18, you may not use this Service.

If we learn that we have collected personal information from a person under 18, we will take immediate steps to delete that information. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@subrosaapp.com

10. Data Retention

We retain your personal information for as long as necessary to:

  • Provide the Service and maintain your account
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Support legitimate business operations

10.1 Retention Periods

  • Active Accounts: Data is retained while your account is active
  • Deleted Accounts: Personal data is deleted within 30 days of account deletion
  • Backups: Backup data is purged within 90 days of deletion request
  • Legal Records: Some data may be retained longer if required by law (e.g., financial records, legal disputes)
  • Anonymized Data: Aggregated, anonymized data may be retained indefinitely for analytics and service improvement

10.2 Chat and Message Retention

Chat messages and in-app communications are retained while your account and relationship are active. You may delete individual messages. When a relationship is ended, both parties retain access to their own data but shared content visibility may be affected.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will notify you via email and/or in-app notification
  • We will update the "Last Updated" date at the top of this policy
  • For significant changes, we may require you to acknowledge the updated policy before continuing to use the Service

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@subrosaapp.com

General Support: support@subrosaapp.com

Data Protection Officer: dpo@subrosaapp.com

We aim to respond to all privacy-related inquiries within 5 business days.

By using Subrosa, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Service.