Here’s the whole picture.
Last updated 27 July 2026
Not a summary of a policy — the actual list, both halves of it: what TrialCanary can see, and what it cannot.
This is the public version of the privacy dashboard that lives inside the app. Both are generated from the same set of facts, so they cannot drift apart.
Who we are
TrialCanary is an app that warns you before a free trial converts or a subscription renews. It is operated by [LEGAL ENTITY NAME], of [REGISTERED POSTAL ADDRESS], which is the controller of the personal data described on this page.
For anything on this page, write to privacy@trialcanary.com.
How the product works, in one paragraph
A subscriber is issued a canary address — a masked email alias of the form name@my.trialcanary.com. You use that address instead of your real one when you sign up for trials. Mail sent to it arrives in an inbox that lives inside the app. We read those messages to find the service, the amount and the date, and then we notify you before you are charged.
That is the entire data surface. We do not connect to your bank. We do not connect to your real mailbox. There is no Gmail or Outlook integration to grant, because none exists.
The alias is receive-only. It accepts mail; it never sends or forwards your mail anywhere. Messages you receive are never relayed on to another address — not yours, not anyone’s. The only email we send you is our own: the warnings you signed up for, plus account and support mail.
What we can see
- Mail sent to your canary address — the sender, the subject, and the body, until you delete it.
- Receipts you forward to us yourself, from an address you've verified.
- Anything you type in by hand: a service name, an amount, a date.
- Your email address and which plan you're on.
We also record ordinary operational data needed to run a service: your account identifier from the sign-in provider, the device token that lets us deliver a push notification, your time zone (so a 9 a.m. warning arrives at 9 a.m. where you are), and server logs. Message bodies are never written to our logs.
What we cannot see
These are stated as facts about the system, not as intentions. “We would never look at your bank” is a promise; “we cannot see your bank” is checkable, and only the second one is worth printing.
- Your bank, your card, or any account balance. We have no connection to any of them.
- Your real inbox. We have no access to Gmail, Outlook or any other mail account.
- Anything sent to an address that isn't your canary address.
- Your location, your contacts, or anything else on your device.
Why we use it
- To run the alias. Receiving, storing and showing you the mail sent to your canary address, including one-time codes.
- To find charges before they happen. Reading a receipt to extract the service, the amount, the currency and the date.
- To warn you. Sending push notifications and email three days before a charge, the day before, and on the morning of.
- To keep your account working. Authentication, billing status, support correspondence, and security.
We do not sell anything. Not your address, not your subscriptions, not aggregate anything. There is no advertising, no data broker, and no third party who receives your data in exchange for money.
AI processing is opt-in, and off until you turn it on
Most receipts are read by templates — plain pattern matching that runs on our own servers and involves no AI at all. One-time codes are always extracted this way.
When a template cannot read a receipt, we can fall back to a third-party AI model (Anthropic’s Claude Haiku) to read that one message. This only ever happens if you have explicitly consented to it in the app. Before you consent, no mail content of yours reaches any AI model, ever. If you decline — or simply never accept — parsing stays template-only, and a receipt we cannot read stays in your inbox marked as unread by us rather than being sent anywhere.
Nothing you give us trains an AI model — ours or anyone else’s. Text sent for AI parsing is read once and is not retained for training.
You can withdraw AI consent at any time in the app, and parsing reverts to templates.
How long we keep things
| What | How long | Notes |
|---|---|---|
| Mail sent to your canary address | 90 days by default | Yours to export or delete at any moment, without asking us. |
| The body of a parsed receipt | Deleted once parsed | What remains is the service, the amount and the date. |
| Anything you forward that is not a receipt | Deleted within 24 hours | We do not keep mail we had no reason to read. |
| Your detections (service, amount, date) | Until you delete them or close your account | This is the list the app exists to show you. |
| Account and billing records | While your account exists, then as required by law | Purchases are handled by Apple; we hold the entitlement status, not your card. |
If you rename your canary address, the old name keeps delivering for 30 days so nothing addressed to it is silently lost. A released name is then retired permanently and is never issued to anyone else.
Your inbox is never held hostage
This one is worth stating in a privacy policy because it is a privacy decision, not a pricing one. Once you have a canary address, you start handing it to real services — and that mailbox ends up holding verification codes and password resets for accounts that have nothing to do with us.
Reading and exporting the mail already in your canary inbox is free forever, and survives a lapsed subscription. A lapse stops detections and warnings. It never stops access to your mail.
If your subscription lapses, the alias keeps accepting new mail for 30 more days — long enough to move your logins somewhere else — and we tell you the date it stops. Everything already received stays readable and exportable indefinitely.
Export everything. Delete everything.
Export
You can export your alias mail and your tracked subscriptions from inside the app, at any time, without asking us and without paying for it.
Delete
You can delete an individual message, an individual detection, or your entire account from inside the app. “Delete everything” is immediate and it is complete: your mail, your detections, your stored bodies, your export archives and your sign-in identity all go. Afterwards, mail sent to your old canary address is rejected at the door, and the name is retired rather than recycled.
The usual rights, spelled out
Depending on where you live you may have rights to access, correct, delete, restrict or object to our processing of your data, to receive it in a portable form, and to withdraw a consent you previously gave. The first three are built into the app so you never have to ask. For anything the app does not cover, write to privacy@trialcanary.com and we will answer within 30 days. We will never charge you for a request, and we will never make the product worse for you because you made one.
Children
TrialCanary is not directed at children and is not designed for them. If we learn we hold data about a child under the applicable minimum age, we delete it.
Security
Traffic is encrypted in transit, message bodies are stored in access-controlled object storage, and secrets live in the environment rather than in code. We never write the contents of your mail to our logs.
No system is perfect. If you find a problem, tell us at support@trialcanary.com and we will treat it as urgent.
Changes to this policy
If we change something material — what we collect, how long we keep it, who processes it — we will update the date at the top of this page and tell you in the app before the change takes effect. We will not quietly broaden what we can see.
Questions about any of this?
Write to a person, not a form. Privacy and data requests: privacy@trialcanary.com. Everything else: support@trialcanary.com.