Privacy Policy
Last updated: August 5, 2026
This page contains important information about your rights and obligations. If anything here conflicts with rights that cannot be waived under applicable law, those rights apply.
1. Overview
This Privacy Policy explains how Frobly collects, uses, stores, shares, and protects personal information when you use our website, apps, subscription tracking tools, import/audit features, billing pages, and related services.
Frobly is operated by Panon Valley LLC.
Controller/contact: Panon Valley LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States, privacy@frobly.com.
2. Important note
Frobly helps you organize subscription and recurring payment information. Do not upload information that is not needed for this purpose. Do not upload full card numbers, security codes, government IDs, passwords, or data belonging to someone else unless you are authorized to do so.
3. Information we collect
Account information
- email address;
- password hash if you use email/password login;
- Google or Apple account identifiers if you use social sign-in — we store the provider's stable account identifier and your email address, not your Google or Apple profile name or picture;
- account preferences and settings, such as your preferred currency;
- your plan and entitlement status.
Frobly does not ask for or store a real name, display name, postal address, or phone number for your Frobly account. If you buy Guard, Stripe collects a name and billing address at checkout for payment and tax purposes and holds them under its own controls — see section 8.
Subscription and audit information
These are the subscriptions you track in Frobly, such as a streaming service or a gym — not your Frobly plan.
- merchant/subscription names;
- amounts, currencies, billing cycles, renewal dates, trial end dates, categories, notes, cancellation links, and status;
- reminder settings for each tracked subscription;
- the results of each statement scan: the recurring-charge candidates we detected, the dates that matched each candidate, and which candidates you imported;
- a summary of each scan — counts of rows parsed, rejected and reviewed, any warnings, the column names detected in a CSV, and the number of pages processed.
Statement files you upload (web CSV and text-PDF import)
When you upload a CSV or text-based PDF statement, the file is read in memory to extract transactions and is then discarded.
- We do not store the uploaded file. No copy of your statement file, and no image of it, is written to our servers or our database.
- We do not store the individual transaction rows read out of it. What is saved is the detected recurring-charge candidates and the scan summary described above.
- A detected candidate does include a merchant name derived from the transaction description, together with the amount, currency, and the dates that matched.
Statement scanning in the Frobly mobile apps works differently and is described in section 9a.
Gmail, if you choose to connect it
Connecting a Gmail mailbox is optional. If you never connect one, nothing in this subsection applies to you and Frobly never sees any email. What we store when you do connect one:
- an encrypted copy of the authorization Google issues us — see section 10 for how it is protected. We never see or store your Google password;
- a masked form of the mailbox address, such as
m•••@gmail.com, so you can recognize which account you connected. The full address is not stored; - one-way, keyed digests of the mailbox identifier and of the identifier of each message we have already read. These cannot be reversed into an address or a message, and their purpose is described below;
- the information we extract from billing-related messages: the service or merchant name, the amount, the currency, the billing cycle, renewal and trial-end dates, the kind of event (receipt, renewal, trial ending, cancellation, price change, failed payment, refund, plan change), and the sending domain — for example
netflix.com. The sender's full address is not stored; - progress and outcome records for each mailbox scan: how many messages were looked at, and counts of what was found.
What we do not store: your messages. Message bodies are read in memory only, long enough to extract the fields listed above, and are then discarded. No copy of any message, subject line, snippet or body is written to our servers or database. Attachments are never opened — not invoice PDFs, not images, not anything; there is no code in Frobly that reads an attachment's contents.
Payment and billing information we hold
When you buy Guard, Frobly stores only the references it needs to know what you are entitled to:
- your Stripe customer ID and subscription ID;
- the price ID of the plan you bought (Guard monthly or Guard yearly);
- the subscription status, the current billing period's start and end, whether it is set to cancel at period end, whether it is paused, and when it was canceled;
- a short record of the Stripe events we have processed — the event's identifier, type, and timestamps.
Frobly does not receive or store your card number, card security code, card brand, or the last four digits of your card. Payment details are collected and held by Stripe/Link as merchant of record — see section 8.
Technical and usage information
- IP address;
- device/browser/app information;
- operating system;
- log data;
- approximate location derived from IP;
- pages or features used;
- error, security, and diagnostic events.
Support communications
- messages you send to support;
- attachments you choose to provide;
- information needed to respond to your request.
Cookies and local storage
We may use cookies, local storage, or similar technologies for login sessions, security, preferences, analytics, and service functionality.
4. How we use information
We use information to:
- create and secure accounts;
- provide subscription tracking, imports, audits, dashboards, and reminders;
- find subscriptions and billing changes in a Gmail mailbox you chose to connect, and — on Guard — keep watching it for new billing email (section 9b);
- process payments and manage plans;
- prevent abuse, fraud, and unauthorized access;
- troubleshoot bugs and provide support;
- improve Frobly's reliability and usability;
- comply with legal, tax, accounting, security, and dispute obligations;
- communicate service, billing, security, and policy updates.
5. Legal bases for processing
Depending on your location, we process personal information under these legal bases:
- Contract: to provide Frobly and paid features you request.
- Consent: where required, such as optional permissions, certain cookies, or connecting third-party accounts.
- Legitimate interests: to secure, maintain, debug, improve, and prevent abuse of the service.
- Legal obligations: to comply with tax, accounting, consumer protection, payment, and lawful request obligations.
- Legal claims: to establish, exercise, or defend legal rights.
6. Google API and Limited Use disclosure
If you connect Google services or use Google sign-in, Frobly may receive information authorized by you and permitted by Google. Two separate, independently revocable authorizations exist: Google Sign-In, and — if you choose it — read-only Gmail access for subscription discovery, described in full in section 9b.
Frobly's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized artificial intelligence or machine learning models. We only use Google user data to provide or improve user-facing Frobly features that you choose to use, secure the service, comply with law, or as otherwise permitted by Google's policies and disclosed to you.
This applies to Gmail data specifically. Data obtained through Gmail access is used solely to find and describe your subscriptions and recurring charges inside Frobly. It is not used for advertising, not sold, not transferred to anyone except the infrastructure providers that host the service, and not sent to any large language model or third-party AI provider, whether for a result or for training. Humans do not read your mail; access to production systems is limited to what is needed to operate and secure them, and to what the law requires.
7. How we share information
We may share information with:
- hosting and infrastructure providers;
- database, storage, monitoring, and security providers;
- Stripe and Link, which sell and process the Guard subscription as merchant of record (section 8);
- authentication providers such as Google and Apple;
- Google's Gemini API, if you use the optional AI statement reader — it receives the statement image you chose, and nothing else (section 9c);
- email/support providers;
- analytics or diagnostics providers, if enabled;
- professional advisers, auditors, accountants, lawyers, or insurers;
- authorities or third parties where required by law, lawful process, safety, fraud prevention, or protection of rights;
- successors in a merger, acquisition, financing, restructuring, or sale of assets.
We do not sell personal information.
8. Payment processing — Stripe and Link
The Guard subscription is sold using Stripe's Managed Payments, which makes Stripe, through Link, the merchant of record for the payment. Checkout and your receipts may show that the purchase was "Sold through Link".
This means Stripe collects and controls the payment data: your payment method, the name and billing address it requires for payment and tax purposes, the transaction and order records, receipts and invoices, and any refund or dispute records. Stripe processes that information under its own terms and privacy policy, and retains or deletes it according to its own policies, legal obligations, and Managed Payments processes — not according to this Policy. Payment, order-history and refund support for the transaction is handled by Link support.
Panon Valley LLC does not process card payments and does not receive or hold your payment credentials. What Frobly holds is the small set of billing references listed in section 3, which is what lets us know whether your account is entitled to Guard.
Deleting your Frobly account does not, by itself, delete the records Stripe/Link holds about the payment. To ask about the data Stripe/Link holds, contact Stripe or Link directly.
9. Retention
We keep personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the service, maintaining records, resolving disputes, preventing fraud, complying with law, and enforcing agreements.
What we actually keep:
- Uploaded statement files — not kept at all. A CSV or text-PDF you upload is read in memory and discarded. No copy is written to our servers or database. Statement images and PDF pages on mobile never reach us in the first place (section 9a).
- Individual transaction rows — not kept. The rows read out of a statement are used to detect recurring charges and are not stored. What is stored is the detected candidates and the scan summary.
- Scan records (audits) and tracked subscriptions — kept until you delete them or delete your account. They are not automatically expired, and they are not deleted if your Guard subscription ends. Deleting a tracked subscription or deleting your account removes them.
- Account data — kept while your account exists. On deletion it is anonymized rather than kept (section 13).
- Billing records held by Frobly — retained after account deletion. The billing record described in section 3 is the record of a payment relationship that actually existed. It is kept, marked as belonging to a deleted account, for tax, accounting, dispute, fraud-prevention and legal purposes. It contains no name, no address and no card data, and it grants no access to anything.
- Stripe event records — kept for 90 days. The short log of processed payment events is automatically deleted 90 days after it is received. It holds an event identifier, an event type and timestamps.
- Payment data held by Stripe/Link — governed by Stripe, not by us. See section 8.
- Email messages — not kept at all. If you connect Gmail, message bodies are read in memory and discarded; no message, subject, snippet or attachment is written to our servers or database (section 9b).
- What was extracted from your mail — kept until you delete it, disconnect and delete it, or delete your account. The detections and their supporting evidence are yours to remove at any time from within the app.
- The mailbox pairing record — retained permanently, including after account deletion. When an account is deleted, the link to you is removed and what remains is a one-way keyed digest and a few timestamps: no address, no authorization, no message and nothing that identifies you. It is kept so that deleting and re-registering an account cannot be used to obtain another free scan of the same mailbox (section 9b).
- Email security-audit records — kept for 90 days, then deleted automatically. These record that an action happened — a mailbox was connected, an authorization was revoked, a scan was refused — using an account identifier, an action name and an error code. They contain no mailbox address, no message, no sender, no subject, no authorization and no IP address.
- Email scan progress records — kept for 30 days after the scan finishes, then deleted automatically. The one initial scan of a mailbox is the exception: it is kept for as long as the connection exists, because it holds the summary you are entitled to see.
- Server and security logs — retained for a limited period for security, fraud prevention, debugging, and legal protection. We do not log statement text, transaction descriptions, account numbers, the rows you submit, or any mailbox address, message, subject or sender.
- Support messages — retained as needed to handle your request and to maintain business records.
We may keep information longer than described above where we are required or permitted to do so — for example to comply with a legal, tax or accounting obligation, to establish or defend a legal claim, to handle a payment dispute or chargeback, or to prevent fraud and abuse.
9b. Connecting Gmail — what Frobly can and cannot do
Availability. Gmail connection is being prepared and is not switched on yet. This section describes it in advance so it is documented before anyone can use it. Until it is enabled and you connect a mailbox yourself, Frobly holds no email data of any kind about you.
The permission Google gives us, stated honestly
You connect a mailbox through Google's own consent screen. Frobly never asks for, sees, or stores your Google password.
The permission Frobly requests is read-only: gmail.readonly. Frobly cannot send, edit, delete, label or move any message, and does not request access to your Contacts, Calendar or Drive.
Being straight with you about the scope: Google's read-only permission covers your whole mailbox. There is no Google permission that grants access to billing email only. So the technical access Frobly is granted is broader than what Frobly uses it for. What limits us to billing mail is our own processing, not a restriction Google enforces: Frobly searches your mailbox for billing-related messages over a fixed window of the last 12 months and processes only what that search returns. We are describing a self-imposed limit, and you should judge it as one.
This authorization is separate from Google Sign-In. They use different Google applications, are consented to at different times, and are revoked independently. Signing in with Google does not give Frobly access to your mail, and connecting your mailbox does not change how you sign in. You can disconnect your mailbox and stay signed in, or revoke Frobly's mailbox access directly from your Google Account's Third-party apps page at any time.
What happens to your messages
- Messages are fetched, read in memory, reduced to the fields listed in section 3, and discarded.
- Full message bodies are not retained. Neither are subject lines, snippets, sender addresses or message identifiers in readable form.
- Attachments are not downloaded or processed.
- Your mailbox content is never used for advertising, is never sold, and is never used to profile you.
- Your mailbox content is not sent to a large language model or any third-party AI provider. Detection is done by deterministic rules running on Frobly's own servers. If that ever changes, this Policy will change first.
Free and Guard
- On Free you receive an aggregate result only — how many possible subscriptions, trial signals and billing changes were found. No service names, amounts, dates or evidence are shown or sent to your device.
- On Guard those details are unlocked for review, correction and import, and Frobly can keep watching the connected mailbox for new billing email.
- Nothing is added to your tracked subscriptions until you confirm it.
One mailbox, permanently
A Frobly account connects one Gmail mailbox. Once the first scan of that mailbox begins, the pairing between your account and that mailbox becomes permanent:
- you can disconnect and reconnect the same mailbox as often as you like — including to repair an expired connection;
- a different mailbox cannot be connected afterwards through the app, and there is no self-service way to change it;
- a mailbox that has already had its one free scan cannot receive another one through a different Frobly account.
This exists to stop the one free scan being farmed by rotating through mailboxes or accounts. It is enforced with the one-way keyed digest described in section 3 — a record that contains no address, no token and no message. Please connect the mailbox you actually want to track.
Disconnecting, and deleting email data
- Disconnect stops all monitoring, deletes the stored authorization from our systems, and asks Google to revoke it. Subscriptions you already confirmed stay in your account. The permanent mailbox pairing described above is retained.
- Delete email data removes the detections and the supporting evidence Frobly derived from your mail. Subscriptions you already confirmed stay in your account, and the permanent mailbox pairing is retained — so this cannot be used to obtain a second free scan.
- Deleting your account follows section 13, which includes the mailbox steps.
9a. On-device statement scanning (Frobly mobile apps)
The Frobly apps for iPhone and Android can read a bank or card statement from photos, screenshots, or a scanned PDF. There are two readers, and they work differently. This section describes the on-device one; section 9c describes the optional AI reader, which sends the image you choose to Google.
- With the on-device reader, your statement images are not uploaded to Frobly for text recognition. The recognition runs locally on your phone. No third-party text-recognition service receives your images.
- While a scan is in progress, the app writes temporary working copies of the pages into its own private storage on the device. Frobly deletes those copies when the scan finishes or is abandoned. Frobly does not delete photos or files you selected or created yourself — those remain under your control and your device's control.
- After you review the extracted rows, the transaction details you choose to submit are sent to Frobly — the date, description, amount, currency, and whether the row is money in or money out — so that we can look for recurring charges. Nothing is submitted until you confirm.
- Card and account numbers detected inside a description are removed before a row can be submitted.
- The resulting audit and any subscriptions you choose to import are stored in your account, as described elsewhere in this policy. Frobly does not store the original statement images or rendered pages.
Text recognition is not perfect. You review and correct the extracted rows before anything is submitted, and Frobly does not guarantee that every charge or subscription is detected.
9c. AI statement reading (optional)
Frobly also offers an optional AI reader for statement photos and screenshots. You choose the image and confirm its currency; Frobly then sends that image through its own backend to Google's Gemini API, which reads the transactions out of it and returns them. This is the one place where a statement image leaves your device.
- Only the image you selected is sent, and only when you use this reader. The on-device reader in section 9a still sends no image at all.
- Frobly does not keep the image. It is held only for as long as the request takes and is not saved to Frobly's storage afterwards. The transactions read out of it, and any audit or subscriptions you import, are stored in your account as described elsewhere in this policy.
- Frobly uses Google's Gemini API on a paid plan, and asks Google not to retain the request. Under Google's current terms for the paid service, content sent this way is not used to improve Google's products. Google's own handling of the request is governed by Google's terms, not Frobly's — we do not control it and make no promise about it beyond this.
- Google is a processor for this feature. See section 11 for international transfers.
AI reading is not perfect either. You see and can correct what it read before anything is saved as a subscription.
10. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, authentication, logging, and least-privilege practices where appropriate.
Mailbox authorizations get specific protection. If you connect Gmail, the authorization Google issues is encrypted before it is stored, using AES-256-GCM with a key held only in the server's environment and never in our source code. Each stored authorization is cryptographically bound to the account and connection it belongs to, so a copied record cannot be made to work for a different account. It is kept in its own separate store that no page-rendering or reporting code ever reads, it is decrypted only for the moment a request to Google is made, and it is never written to a log or returned by any part of the app. Deleting it — which disconnecting and account deletion both do — ends the access.
No system is perfectly secure. You are responsible for protecting your account credentials and devices.
11. International transfers
Frobly and our service providers may process information in countries other than where you live. Where required, we rely on appropriate safeguards or legal mechanisms for cross-border transfers.
12. Your privacy rights
Depending on your location, you may have rights to:
- access your personal information;
- correct inaccurate information;
- delete your information;
- export or receive a copy of your information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of certain uses where applicable;
- lodge a complaint with a data protection authority.
To make a request, contact privacy@frobly.com. We may need to verify your identity before responding.
13. Account deletion — what actually happens
You can delete your account yourself from Profile → Delete account in the app, or by contacting privacy@frobly.com. Deletion runs in a fixed order, and we describe it here precisely rather than promising that everything disappears.
- Your Guard subscription is canceled first. If the payment provider cannot be reached or the cancellation fails, the deletion is refused and nothing is removed — your account, data and subscription are left exactly as they were and you can try again. This ordering exists so a deleted account can never leave a live recurring charge behind.
- Mailbox access is ended. If you had connected Gmail, monitoring is stopped, we ask Google to revoke the authorization, and the stored authorization is deleted from our systems whether or not Google could be reached — the local deletion is the part we guarantee. The detections and evidence derived from your mail are deleted with it. The mailbox pairing record is retained in the anonymized form described in section 9.
- Your tracked subscriptions and your scan/audit records are deleted. Subscriptions you imported from email are ordinary tracked subscriptions and are deleted here like any other.
- Your identity is anonymized and disabled. Your email address is replaced with a non-deliverable placeholder, your password hash and any Google or Apple account identifiers are cleared, and the account is disabled so nobody can sign in as it. The record itself is kept in an anonymized state rather than erased, because other records reference it.
- The billing record is retained and marked as belonging to a deleted account, as described in section 9. It contains no name, no address and no card data.
Deletion does not remove the payment data held by Stripe/Link. As merchant of record, Stripe holds the transaction, receipt, tax and refund records for your purchase and retains or deletes them under its own policies and legal obligations. Contact Stripe or Link about that data.
We may also retain information where required or permitted for legal, tax, accounting, security, fraud-prevention, dispute or backup reasons. Backups are not rewritten on request; information removed from live systems can persist in backups until they age out.
14. Children
Frobly is not intended for children and may only be used by adults. We do not knowingly collect personal information from children. If you believe a child provided information to Frobly, contact privacy@frobly.com.
15. Automated decisions
Frobly may automatically classify transactions or suggest possible subscriptions. These suggestions are for organization only and may be inaccurate. Frobly does not make legal, credit, employment, insurance, or similarly significant automated decisions about you.
16. Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as appropriate.
17. Contact
Privacy questions and requests: privacy@frobly.com.