What you get
- Your subscriptions live in private on-device storage by default — nothing syncs on its own.
- No bank scraping, no card access — Suby just helps you track, nothing more.
- Anything you choose to back up is encrypted in transit (TLS) and at rest (AES-256), in a private area only your account can reach.
- Export or back up your own data any time, free and account-free — your data never sits behind a paywall.
In detail
On-device by default
Your subscriptions, prices, notes, tags and payment-method labels are written to a local database inside the app's private storage — the app data directory on Android, the app container on iOS. Nothing syncs to a server on its own; the only copies that leave are ones you start yourself, by taking a backup or sharing a subscription with someone.
Encrypted the moment it leaves your phone
The only data that ever leaves your device is data you choose to send — a cloud backup, or a subscription you share. When it does, it travels over TLS and is stored encrypted at rest with industry-standard AES-256, in a private per-user area only your signed-in account can reach. We're straight about the limit too: cloud backup is encrypted in transit and at rest, not end-to-end — the section below spells out exactly what leaves your device and what doesn't.
An encrypted Vault for the details you reach for
Keep the logins, licence keys and one-off codes tied to your subscriptions in Suby's Vault. Each secret is sealed with AES-256 and stored only as ciphertext — on your device, in your backup and on our servers alike — never as readable plaintext. Prefer your own password manager? Link to it instead and Suby stores nothing at all.
No bank access, ever
Suby has no bank or card connection, and no code to add one — you type subscriptions in, or read them off a screenshot. A "payment method" in Suby is just a label: a name, a colour, an emoji and an optional expiry month. Never a card number.
Three permissions on Android
The Android build declares internet, network state and notifications. That is the entire list — no storage, camera, contacts or location. Renewal reminders are worked out on your own phone from the local database, so no server ever needs to know your billing dates.
Backups you can hold
Create backup lets you tick exactly which subscriptions go in, then hands the file to your system save dialog — it lands wherever you choose, as readable JSON. Export as CSV does the same for spreadsheets, with columns for price, your share, currency, period, next payment, status, tags and payment method. Both are free and neither needs an account.
Cloud backup only if you ask
Nothing is uploaded until you open Cloud backup and tap Back up now — there is no background sync and no automatic upload. Restoring adds the backup to what is already on your device and never removes your current subscriptions. Cloud backup requires Premium and a signed-in account with an email address.
How it works
-
Start with no account
Onboarding asks two things: your main currency, and whether to allow notifications. Tap Let's Go — or Skip — and you land on the dashboard. There is no sign-up wall; signing in is an optional "Already have an account?" link you can ignore forever.
-
Add subscriptions, and they stay put
Price, billing period, description, tags, which card pays for it — all of it is written straight to the local database. It reads fine with no connection, and totals keep converting using the last exchange rates Suby cached.
-
Take your own copy
Settings, then Backup & export, then Create backup. Pick which subscriptions to include, confirm, and your system save dialog opens with a suby_backup filename ready. Export as CSV sits in the same list, and Restore backup reads a .json file back in — letting you choose which subscriptions to bring over, and merging rather than overwriting.
-
Add cloud backup if you want it
Same list, Cloud backup. Without Premium the row shows a Premium chip; signed out it shows Sign in. Inside, Back up now uploads a single file tied to your account, and Restore asks "Restore from cloud?" before merging it into what you already have.
Questions
Do I need an account?
No. Suby works fully without one — add subscriptions, get renewal reminders, see your statistics, back up to a file. An account is needed for exactly two things: cloud backup, and sharing a subscription with someone else. Both need a real signed-in account with an email address. Separately, when you use a feature that calls Suby's server — screenshot import, the email scan, or looking up a service that isn't in the catalogue yet — the app creates an anonymous session so the request can be authenticated. It carries no name and no email.
Which of this is free?
Create backup, Restore backup and Export as CSV are free, with no account and no limit — your own data shouldn't sit behind a paywall. Cloud backup is Premium. Screenshot import gives you three free imports and then asks for Premium; the Gmail scan is Premium from the start and uses Google's read-only mail scope, with the access token held in memory for the scan and never saved — only the address of the account you scanned is kept, so the screen can show it.
Can Suby keep my logins and licence keys?
Yes — Suby's Vault stores the login, licence key or promo code for a subscription encrypted with AES-256, as ciphertext only and never as readable plaintext, in your backup and on our servers alike. Or link to your existing password manager and Suby keeps nothing at all. It's there so the detail you need is one tap away — a tracker with a vault, not a password-manager replacement.
So what actually leaves my device?
The service catalogue is downloaded and cached. If you add a service Suby doesn't know, its name plus a category hint and your country go to our server so it can find a logo and website. Screenshot import and the email scan send that image, or the selected email text, to our server, which passes it to Anthropic's Claude to read — the image itself is never stored, only a usage row with the model, duration, token counts and how many items were found. Cloud backup, if you tap it, stores one JSON file under your user ID, protected by your account; it is not end-to-end encrypted. And Suby sends product analytics (Amplitude, Firebase) and crash reports (Sentry, Crashlytics) — some of those events include a service name and the price you entered, and there is no in-app analytics opt-out today.

