Privacy Policy

Last updated: August 5, 2026

1. Overview

This Privacy Policy explains how Frobly collects, uses, stores, shares, and protects personal information when you use our website, apps, subscription tracking tools, import/audit features, billing pages, and related services.

Frobly is operated by Panon Valley LLC.
Controller/contact: Panon Valley LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States, privacy@frobly.com.

2. Important note

Frobly helps you organize subscription and recurring payment information. Do not upload information that is not needed for this purpose. Do not upload full card numbers, security codes, government IDs, passwords, or data belonging to someone else unless you are authorized to do so.

3. Information we collect

Account information

Frobly does not ask for or store a real name, display name, postal address, or phone number for your Frobly account. If you buy Guard, Stripe collects a name and billing address at checkout for payment and tax purposes and holds them under its own controls — see section 8.

Subscription and audit information

These are the subscriptions you track in Frobly, such as a streaming service or a gym — not your Frobly plan.

Statement files you upload (web CSV and text-PDF import)

When you upload a CSV or text-based PDF statement, the file is read in memory to extract transactions and is then discarded.

Statement scanning in the Frobly mobile apps works differently and is described in section 9a.

Gmail, if you choose to connect it

Connecting a Gmail mailbox is optional. If you never connect one, nothing in this subsection applies to you and Frobly never sees any email. What we store when you do connect one:

What we do not store: your messages. Message bodies are read in memory only, long enough to extract the fields listed above, and are then discarded. No copy of any message, subject line, snippet or body is written to our servers or database. Attachments are never opened — not invoice PDFs, not images, not anything; there is no code in Frobly that reads an attachment's contents.

Payment and billing information we hold

When you buy Guard, Frobly stores only the references it needs to know what you are entitled to:

Frobly does not receive or store your card number, card security code, card brand, or the last four digits of your card. Payment details are collected and held by Stripe/Link as merchant of record — see section 8.

Technical and usage information

Support communications

Cookies and local storage

We may use cookies, local storage, or similar technologies for login sessions, security, preferences, analytics, and service functionality.

4. How we use information

We use information to:

5. Legal bases for processing

Depending on your location, we process personal information under these legal bases:

6. Google API and Limited Use disclosure

If you connect Google services or use Google sign-in, Frobly may receive information authorized by you and permitted by Google. Two separate, independently revocable authorizations exist: Google Sign-In, and — if you choose it — read-only Gmail access for subscription discovery, described in full in section 9b.

Frobly's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized artificial intelligence or machine learning models. We only use Google user data to provide or improve user-facing Frobly features that you choose to use, secure the service, comply with law, or as otherwise permitted by Google's policies and disclosed to you.

This applies to Gmail data specifically. Data obtained through Gmail access is used solely to find and describe your subscriptions and recurring charges inside Frobly. It is not used for advertising, not sold, not transferred to anyone except the infrastructure providers that host the service, and not sent to any large language model or third-party AI provider, whether for a result or for training. Humans do not read your mail; access to production systems is limited to what is needed to operate and secure them, and to what the law requires.

7. How we share information

We may share information with:

We do not sell personal information.

8. Payment processing — Stripe and Link

The Guard subscription is sold using Stripe's Managed Payments, which makes Stripe, through Link, the merchant of record for the payment. Checkout and your receipts may show that the purchase was "Sold through Link".

This means Stripe collects and controls the payment data: your payment method, the name and billing address it requires for payment and tax purposes, the transaction and order records, receipts and invoices, and any refund or dispute records. Stripe processes that information under its own terms and privacy policy, and retains or deletes it according to its own policies, legal obligations, and Managed Payments processes — not according to this Policy. Payment, order-history and refund support for the transaction is handled by Link support.

Panon Valley LLC does not process card payments and does not receive or hold your payment credentials. What Frobly holds is the small set of billing references listed in section 3, which is what lets us know whether your account is entitled to Guard.

Deleting your Frobly account does not, by itself, delete the records Stripe/Link holds about the payment. To ask about the data Stripe/Link holds, contact Stripe or Link directly.

9. Retention

We keep personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the service, maintaining records, resolving disputes, preventing fraud, complying with law, and enforcing agreements.

What we actually keep:

We may keep information longer than described above where we are required or permitted to do so — for example to comply with a legal, tax or accounting obligation, to establish or defend a legal claim, to handle a payment dispute or chargeback, or to prevent fraud and abuse.

9b. Connecting Gmail — what Frobly can and cannot do

The permission Google gives us, stated honestly

You connect a mailbox through Google's own consent screen. Frobly never asks for, sees, or stores your Google password.

The permission Frobly requests is read-only: gmail.readonly. Frobly cannot send, edit, delete, label or move any message, and does not request access to your Contacts, Calendar or Drive.

Being straight with you about the scope: Google's read-only permission covers your whole mailbox. There is no Google permission that grants access to billing email only. So the technical access Frobly is granted is broader than what Frobly uses it for. What limits us to billing mail is our own processing, not a restriction Google enforces: Frobly searches your mailbox for billing-related messages over a fixed window of the last 12 months and processes only what that search returns. We are describing a self-imposed limit, and you should judge it as one.

This authorization is separate from Google Sign-In. They use different Google applications, are consented to at different times, and are revoked independently. Signing in with Google does not give Frobly access to your mail, and connecting your mailbox does not change how you sign in. You can disconnect your mailbox and stay signed in, or revoke Frobly's mailbox access directly from your Google Account's Third-party apps page at any time.

What happens to your messages

Free and Guard

One mailbox, permanently

A Frobly account connects one Gmail mailbox. Once the first scan of that mailbox begins, the pairing between your account and that mailbox becomes permanent:

This exists to stop the one free scan being farmed by rotating through mailboxes or accounts. It is enforced with the one-way keyed digest described in section 3 — a record that contains no address, no token and no message. Please connect the mailbox you actually want to track.

Disconnecting, and deleting email data

9a. On-device statement scanning (Frobly mobile apps)

The Frobly apps for iPhone and Android can read a bank or card statement from photos, screenshots, or a scanned PDF. There are two readers, and they work differently. This section describes the on-device one; section 9c describes the optional AI reader, which sends the image you choose to Google.

Text recognition is not perfect. You review and correct the extracted rows before anything is submitted, and Frobly does not guarantee that every charge or subscription is detected.

9c. AI statement reading (optional)

Frobly also offers an optional AI reader for statement photos and screenshots. You choose the image and confirm its currency; Frobly then sends that image through its own backend to Google's Gemini API, which reads the transactions out of it and returns them. This is the one place where a statement image leaves your device.

AI reading is not perfect either. You see and can correct what it read before anything is saved as a subscription.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, authentication, logging, and least-privilege practices where appropriate.

Mailbox authorizations get specific protection. If you connect Gmail, the authorization Google issues is encrypted before it is stored, using AES-256-GCM with a key held only in the server's environment and never in our source code. Each stored authorization is cryptographically bound to the account and connection it belongs to, so a copied record cannot be made to work for a different account. It is kept in its own separate store that no page-rendering or reporting code ever reads, it is decrypted only for the moment a request to Google is made, and it is never written to a log or returned by any part of the app. Deleting it — which disconnecting and account deletion both do — ends the access.

No system is perfectly secure. You are responsible for protecting your account credentials and devices.

11. International transfers

Frobly and our service providers may process information in countries other than where you live. Where required, we rely on appropriate safeguards or legal mechanisms for cross-border transfers.

12. Your privacy rights

Depending on your location, you may have rights to:

To make a request, contact privacy@frobly.com. We may need to verify your identity before responding.

13. Account deletion — what actually happens

You can delete your account yourself from Profile → Delete account in the app, or by contacting privacy@frobly.com. Deletion runs in a fixed order, and we describe it here precisely rather than promising that everything disappears.

  1. Your Guard subscription is canceled first. If the payment provider cannot be reached or the cancellation fails, the deletion is refused and nothing is removed — your account, data and subscription are left exactly as they were and you can try again. This ordering exists so a deleted account can never leave a live recurring charge behind.
  2. Mailbox access is ended. If you had connected Gmail, monitoring is stopped, we ask Google to revoke the authorization, and the stored authorization is deleted from our systems whether or not Google could be reached — the local deletion is the part we guarantee. The detections and evidence derived from your mail are deleted with it. The mailbox pairing record is retained in the anonymized form described in section 9.
  3. Your tracked subscriptions and your scan/audit records are deleted. Subscriptions you imported from email are ordinary tracked subscriptions and are deleted here like any other.
  4. Your identity is anonymized and disabled. Your email address is replaced with a non-deliverable placeholder, your password hash and any Google or Apple account identifiers are cleared, and the account is disabled so nobody can sign in as it. The record itself is kept in an anonymized state rather than erased, because other records reference it.
  5. The billing record is retained and marked as belonging to a deleted account, as described in section 9. It contains no name, no address and no card data.

Deletion does not remove the payment data held by Stripe/Link. As merchant of record, Stripe holds the transaction, receipt, tax and refund records for your purchase and retains or deletes them under its own policies and legal obligations. Contact Stripe or Link about that data.

We may also retain information where required or permitted for legal, tax, accounting, security, fraud-prevention, dispute or backup reasons. Backups are not rewritten on request; information removed from live systems can persist in backups until they age out.

14. Children

Frobly is not intended for children and may only be used by adults. We do not knowingly collect personal information from children. If you believe a child provided information to Frobly, contact privacy@frobly.com.

15. Automated decisions

Frobly may automatically classify transactions or suggest possible subscriptions. These suggestions are for organization only and may be inaccurate. Frobly does not make legal, credit, employment, insurance, or similarly significant automated decisions about you.

16. Changes

We may update this Privacy Policy from time to time. If changes are material, we will provide notice as appropriate.

17. Contact

Privacy questions and requests: privacy@frobly.com.