Last updated: August 2026
This policy explains what personal data SubMate collects, why, and how we protect it.
Access credentials are encrypted at rest (AES-256-GCM) with a key that never touches the database. Payment screenshots are stored in private object storage with signed, expiring URLs. Every sensitive admin action is written to an audit log.
We keep order and subscription records for as long as your account is active and as required for tax and fraud-prevention purposes. Read notifications are periodically removed.
You can request a copy of your data, ask us to correct it, or delete your account at any time by contacting support@submate.tech.