KryptoHead.com
Privacy Policy
Last updated: 27 August 2026

Privacy Policy

This policy covers the applications published at KryptoHead.com that link to it, currently the Subscriptions Tracker (the “Apps”). The Retirement Planner runs on the same infrastructure but publishes its own privacy policy, because it stores saved scenarios and its own activity records that this policy does not describe.

The short version

You sign in with Google. We store your name, email address and profile picture so the Apps know who you are, plus whatever you choose to save inside them. Your records are private to your account. We do not sell your data, we do not run advertising, and we do not share your information with anyone beyond the infrastructure providers that run the service. Email kryptosubs@gmail.com to get a copy of your data or have it deleted.

1. Who we are

The Apps are operated by the owner of KryptoHead.com (“we”, “us”). For any privacy question, request or complaint, contact kryptosubs@gmail.com. We are the controller of the personal data described below.

2. What we collect

We collect three categories of information, and nothing else.

CategoryWhat it isWhy we have it
Account Your name, email address, profile picture URL and Google account identifier, received from Google when you sign in. To identify your account, show who is signed in, and keep your records separated from everyone else's.
Content you create Whatever you enter in the Apps. In the Subscriptions Tracker that is the subscription name, category, cost, currency, billing cycle, renewal date, status, notes, and any card-credit amount, cycle and source you record. It is the service. Without it the Apps have nothing to show you.
Usage A page-view record each time you open a page while signed in: timestamp, page path, referring page, browser user-agent string, and your account. To understand basic usage and spot problems. There is no advertising or cross-site tracking of any kind.

We ask Google only for your basic profile — name, email address and picture. We do not request access to your Gmail, Drive, Calendar, contacts or any other Google service, and we could not read them if we wanted to.

What we never collect

Where the GDPR or UK GDPR applies, our lawful bases are performance of a contract (we cannot provide the Apps without your account and your content) and legitimate interests (basic usage records, to keep the service working and secure). Where consent is the applicable basis, you give it by choosing to sign in, and you can withdraw it at any time by asking us to delete your account.

4. Where your data is stored

The Apps run on Vercel and store data in a Neon PostgreSQL database hosted in the United States (AWS us-east-2). Sign-in is handled through Google. These three companies process data on our behalf as service providers; they are not permitted to use it for their own purposes.

If you are located outside the United States, using the Apps means your information is transferred to and stored in the United States.

5. Who we share it with

Nobody. We do not sell, rent, trade or otherwise disclose your personal information, and we do not share it with advertisers, data brokers or analytics networks. The only parties that touch your data are the three infrastructure providers named above.

The single exception is a legal one: if we were served with a valid court order, subpoena or equivalent legal demand, we would comply. We would tell you first unless legally prohibited from doing so.

6. Cookies

The Apps set one cookie: an encrypted session cookie that keeps you signed in between page loads. It is essential — sign-in cannot work without it. Google may set its own cookies on Google's pages during the sign-in step, governed by Google's privacy policy.

There are no advertising cookies, no tracking pixels, and no third-party analytics scripts. Clearing the session cookie simply signs you out.

7. How long we keep it

8. Your rights

Whatever jurisdiction you are in, you can ask us to:

Email kryptosubs@gmail.com and we will respond within 30 days. There is no charge. If you are in the EEA or UK you also have the right to complain to your local data protection authority; if you are in California, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising any right above.

You can also revoke the Apps' access to your Google account at any time from your Google account permissions page. That stops future sign-ins but does not delete data already stored — email us for that.

9. Security

All traffic is encrypted in transit over HTTPS. Data is encrypted at rest by our database provider. Every database query is scoped to the signed-in account on the server, so one account cannot read or modify another's records. Administrative views are restricted to a single named account.

No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify affected users and any required regulator without undue delay.

10. Children

The Apps are not directed at children and are not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us with personal data, email us and we will delete it.

11. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your information, we will make a reasonable effort to notify you by email before it takes effect.

12. Contact

Questions, requests or complaints: kryptosubs@gmail.com.