Privacy Policy
Last updated: 2026-06-18 · Effective: 2026-06-01
Erasr is a Canadian subscription tracker. We help you find recurring charges in your inbox and cancel the ones you don't want. This policy explains what data we collect, why, where it lives, and how to get rid of it.
Who runs Erasr
Erasr is operated by an independent developer in Whitehorse, Yukon, Canada. Reach us at privacy@erasr.ca for any privacy question, request, or complaint.
Privacy Officer: Jean-Paul Berrel, CEO — privacy@erasr.ca. (Quebec Law 25 designation.)
What we collect
- Your email address — to create your account and send sign-in links.
- Billing emails you forward to your private Erasr inbox — to detect recurring charges. We retain the full email so we can re-parse if detection improves.
- Newsletter & marketing-email signals — to offer unsubscribe help, we also identify newsletter/marketing senders in the emails you forward and how often you open them (counts only — 30- and 90-day windows). We classify conservatively and never treat transactional mail (receipts, password resets, confirmations) as marketing. This is in addition to paid-subscription detection; you can turn the newsletter scan off on its own (see “Your choices”) while keeping paid-subscription detection.
- Detected subscriptions and your choices — which subs you've picked, snoozed, cancelled.
- Payment information — handled by Stripe; we never see or store your card number. We retain only the Stripe customer ID and the last four digits Stripe sends back.
- Limited technical data — IP and user-agent for sign-in and abuse/rate-limit prevention. Never used for advertising.
What we do NOT collect
- The full contents of your primary email inbox. If you connect Gmail, we read only the billing-keyword-matching messages described below — never your whole inbox, and never messages outside those billing keywords.
- Your bank account or transaction history.
- Email metadata for messages other than the ones you forward, or — if you connect Gmail — the billing-keyword-matching messages we read on your behalf.
- Any data we sell to advertisers, brokers, or third parties.
Where your data lives
Your data is stored in Canada. We use Supabase in their ca-central-1 (Toronto) region for the database, authentication, and edge functions. If Supabase ever changes our region we'll notify you in writing 30 days before any move.
Third-party processors
- Supabase — database, auth, edge functions (ca-central-1).
- Resend — outbound transactional email.
- Postmark — inbound email parsing for the bills you forward.
- Stripe — payment processing.
- Anthropic (Claude) — classifies whether an email is a billing email and extracts vendor + amount. We send only the email body and metadata strictly needed for classification, under Anthropic's data-processing addendum; Anthropic does not use it to train their models.
- Google (Gmail API) — when you opt in to the one-tap Gmail Connect option, the Gmail API serves us the billing-keyword-matching email content on request. The connection is your-account → your-Google-data; Google is not receiving any new data from us. Used only with your explicit OAuth grant.
- OneSignal — optional mobile push notifications, only if you opt in.
- Vercel — hosts our web app and marketing site and serves them from edge regions. Vercel sees the HTTP requests routed to
app.erasr.caanderasr.ca(URL, IP, basic headers) for the duration of serving each request. Vercel never sees the bodies of our API routes or our database contents — those live in Supabase.
Gmail connection (optional)
If you choose to connect your Gmail account via the "Connect Gmail" button (instead of setting up forwarding manually), we use Google OAuth to read your billing emails directly. This is off by default — it requires you to grant access on Google's screen, and you can disconnect any time from Settings → Gmail connection.
When you connect, we:
- Request the
gmail.modifyscope. This lets us read your email AND apply an "Erasr-processed" label so you can see in your own Gmail what we've touched. We do not send mail on your behalf, modify your messages, or delete anything. - Search your inbox only for billing-keyword matches (receipt, invoice, subscription, renewal, order confirmation, and a small set of related terms), from the last 36 months. Non-matching emails are not read or stored.
- Store the matched email subjects + bodies in the same way we store forwarded billing emails — in Supabase Toronto, RLS-scoped to your account, never sold or shared.
- Store an encrypted refresh token (AES-256-GCM at-rest with a key that lives only in our Vercel + Supabase secrets) so we can continue reading new billing emails on a daily schedule. The refresh token rotates every six months per Google's policy; we'll prompt you to reconnect when it does.
We do not:
- Read emails that don't match the billing-keyword filter.
- Use any other Gmail scope (no
gmail.send, nogmail.compose). - Share your email content with anyone outside the disclosed processors (Anthropic for classification, Supabase for storage).
- Use your email content to train any AI model. Both Anthropic and Voyage's enterprise APIs default to no-training; we use those tiers.
When you disconnect, we immediately call Google's revoke endpoint AND wipe the encrypted tokens on our side. Your stored billing emails remain in your account (you can delete them any time via Settings → Delete my data) but we stop reading new ones.
Until our app finishes Google's formal verification process (CASA Tier 2 — kicking off after first-week feedback), Google will show you an "unverified app" warning on the authorize screen. That warning is Google's; we honor the same data-handling promises whether the warning is showing or not.
Cookies & analytics
We use one set of cookies: Supabase's session cookies, which are required to keep you signed in. We do not use any analytics, advertising, or third-party tracking cookies. If we ever add product analytics (privacy-respecting or otherwise), we will email you 30 days before they activate and require your explicit opt-in — continued use will not constitute consent.
Web analytics (PostHog) — provisioned, not active. Our website is set up so it could use PostHog, a product-analytics tool — the configuration and security allowlist are in place. It is not switched on today: the PostHog code does not load and no analytics events are collected. We're telling you this now, while it's dormant, for full transparency. If we ever turn it on, the promise above still applies — 30 days' notice and your explicit opt-in first — and we'll update this notice, the app-store data-safety disclosures, and our privacy impact assessment at the same time.
Retention
We keep your account data as long as your account is active. If you delete your account, we delete personal data promptly (target within 30 days, including the deletion cascade over forwarded emails and detected subscriptions). We keep some internal aggregated statistics (e.g., "average N subs per user") to inform our roadmap; these stats contain no information tied to any individual user, are used only inside Erasr, and are never sold, shared, or licensed to any third party — including in anonymized or aggregated form. (Exact retention windows — including backups and logs — are being finalized with counsel and flagged for lawyer review.)
Learning from category corrections (optional)
When you correct a transaction's category in Erasr, two things happen:
- Your correction is remembered for your own account — the next transaction from the same vendor gets categorized the way you set it, no re-asking. This part is always on; you can clear individual learned categories any time in Settings → Learned categories.
- The vendor → category pattern (and nothing else) may help improve Erasr's defaults for everyone. This part is optional and defaults on, with this disclosure. You can turn it off any time in Settings → Learned categories.
Concretely, when you have aggregate-pattern contribution on, your corrections feed a weekly extractor that aggregates across users. A correction only enters consideration when at least five independent users have made the same correction on the same vendor. The result of that extraction — the vendor name and the category, plus an internal count — is the ONLY thing stored in our cross-user pattern table. The pattern is computed by Erasr, stored by Erasr, and used by Erasr alone. It never leaves Erasr.
Specifically, the cross-user pattern table contains:
- The vendor's name (e.g.
"tim hortons"normalized form). - The category most users have corrected it to (e.g.
"dining"). - An internal counter of how many independent users have agreed.
And specifically, the cross-user pattern table does not contain:
- Your account identifier, name, or email — never.
- Dollar amounts, dates, or any transaction details — never.
- A link back to your individual correction — never. Once the extractor runs, your contribution is one of N independent counts; there is no row identifying yours.
This is not data sale. This is not data sharing. This is not data licensing. Erasr's hero promise — your data is stored in Canada, we never sell it — applies here unchanged. The aggregate pattern is an internal mechanism for Erasr's own product to get better at categorization over time; it stays inside Erasr the same way our internal aggregated statistics do (per "Retention" above).
Patterns go through internal review before they enter Erasr's live categorization. A pattern that many users have corrected the same way does not go live automatically — a human at Erasr looks at each one and decides whether it makes sense as a general rule.
Turning aggregate contribution off keeps all your own corrections in place. It just stops them from feeding into the cross-user extractor. No retroactive removal: patterns that were extracted before you turned the toggle off remain, because your individual contribution to that pattern's count was anonymized at extraction time — there is nothing identifying yours to remove. Future corrections from you simply do not contribute.
Your choices: newsletter scanning
The newsletter/marketing scan is a separate, optional layer. You can turn it off on its own from Settings and still keep paid-subscription detection — they are independent. Newsletter classification data (sender, domain, open/send counts, engagement score) is retained under the same retention policy as paid-subscription data (above) and is included in the one-tap account-deletion cascade.
Your rights under PIPEDA
- Access the personal information we hold about you. Email us for an export.
- Correct inaccuracies in that information.
- Withdraw consent for processing at any time, which results in account deletion.
- File a complaint with the Office of the Privacy Commissioner of Canada at
priv.gc.ca.
Deleting your account
From your dashboard, Settings → Delete account. If you can't access the in-app flow, email privacy@erasr.ca from the address on your account and we process the deletion within 5 business days.
Jurisdiction
This policy is governed by the laws of the Yukon Territory and the applicable federal laws of Canada. Disputes resolved in the courts of the Yukon.
Questions? privacy@erasr.ca · See also our Terms of Service.