Privacy Policy

Last updated: July 28, 2026

Document ID: SB-LEGAL-PUB-001 Version: 1.0-draft Effective date: 2026-08-15 (Subscriber Bot's public-launch date) Publisher: Algoshred Technologies Private Limited (Burdenoff Group) Canonical location: https://subscriberbot.com/legal/privacy Status: Pre-launch draft — pending final legal review. The effective date is now final (business-confirmed 2026-07-28); the remaining gap is counsel's substantive review of the text itself. Do not represent this document as legally reviewed until that review closes — see ../status/LEGAL_READINESS.md.


Summary (plain English)

This summary is for orientation only — the binding text follows below.

  • Who we are. Subscriber Bot is operated by Algoshred Technologies Private Limited, incorporated in India and part of the Burdenoff Group. We are the controller / data fiduciary for your account, billing, and website-visitor data. For data you put into Subscriber Bot (relationships, inbox, vault, policies), you (or your workspace owner) are the controller and we are the processor.
  • The sensitive part. Subscriber Bot helps you manage subscriptions, so it connects — with your explicit, read-only, least-privilege consent — to sources such as your email and payment/bank activity. We use these connections only to discover and manage your recurring relationships. You can revoke any connection at any time, and we delete the derived tokens immediately.
  • Where it lives. Customer Data is stored on the Burdenoff platform (Microsoft Azure, India region by default). Some operational metadata transits Cloudflare's edge.
  • What we collect. Account/profile data, product activity, the relationships/communications/documents you connect or add, billing data, and support correspondence.
  • Why we use it. To run the Service (discovery, inbox, concierge, optimization, automation), keep it secure, bill you, support you, comply with law, and improve the product. We do not sell your personal data. We do not train AI models on your data, prompts, financial activity, or communications.
  • AI features (BYOK). AI reasoning uses the provider you choose, with your own API key by default. We do not resell inference and do not train on your data.
  • The Vault. Invoices, contracts, licenses, and receipts are encrypted at rest; downloads use short-lived signed URLs.
  • Universal Consent. You control marketing, newsletter frequency, and data-use preferences in one place; integrated providers inherit them. Consent is granular, revocable, and audited.
  • Subprocessors. Listed in DPA Annex 3 and at https://burdenoff.com/contracts/subprocessors (Azure, Cloudflare, email/SMS delivery, payment processors, and the AI providers you choose under BYOK).
  • Your rights. Under India's DPDP Act, GDPR, UK GDPR, and (where applicable) US state laws you can access, correct, erase, port, restrict, or object. Contact [email protected].
  • Age. Intended for users 18 and over (the product handles financial information).
  • Pre-launch. The Service is in development. We will update this Policy with at least 30 days' notice for material changes once live.
  • Grievance Officer (DPDP Act §8(10)). Vignesh T.V., Algoshred Technologies Private Limited — [email protected].

1. Who we are and how to reach us

Subscriber Bot (the "Service") is operated by Algoshred Technologies Private Limited ("Algoshred", "we", "us", "our"), part of the Burdenoff Group. Privacy contact: [email protected]. Grievance Officer: Vignesh T.V., [email protected].

2. Controller / processor roles

  • We are the controller / data fiduciary for your account, billing, and website-visitor data.
  • For data you connect or add to Subscriber Bot (relationships, inbox messages, documents, policies), you are the controller and we are the processor, acting on your instructions under the DPA.

3. Connected sources (the sensitive core)

Subscriber Bot's value comes from connecting to the places your subscriptions live. We treat these connections with the highest care:

  • Read-only and least-privilege. We request the minimum scope needed to discover and manage subscriptions (e.g. read access to subscription-related email, read access to transaction metadata).
  • Purpose-limited. Connected-source data is used only to discover relationships, populate the Universal Inbox, detect renewals/trials/price changes, and (where you authorize) perform actions.
  • Revocable. You can disconnect any source instantly; we delete the derived tokens and stop scanning immediately.
  • Not for sale, not for training. We never sell this data and never use it to train shared AI models.

4. What we collect

Account and profile data; product activity; the relationships, communications, and documents you connect or add; billing data; support correspondence; and website-visitor analytics (see the Cookie Policy).

5. Why we use it (lawful bases)

Performance of contract (running the Service), legitimate interests (security, product improvement), legal obligation (tax, compliance), and consent (connected sources, marketing). Consent can be withdrawn at any time.

6. AI features and BYOK

AI reasoning (discovery extraction, the Concierge, optimization) uses the AI provider you choose, with your own API key by default. We do not resell inference, and we do not train on your prompts, completions, financial activity, or communications.

7. Sharing and providers

We share data with our subprocessors (DPA Annex 3) and — only with your Universal Consent — with the providers you manage relationships with (e.g. to action a one-click cancel, or to share a consent preference). We do not sell personal data.

8. Data residency and security

India region by default on the Burdenoff platform; encryption at rest and in transit; least-privilege access; audit logging; and the encrypted Digital Asset Vault.

9. Your rights

Access, correction, erasure, portability, restriction, and objection under DPDP/GDPR/UK GDPR and applicable US state laws. Contact [email protected]. We respond within statutory timelines.

10. Retention

We retain Customer Data while your account is active and for a limited period afterward as required for legal/tax purposes, then delete or anonymize it. Revoking a connected source removes derived tokens immediately.

11. Children

The Service is intended for users 18 and over because it processes financial information.

12. Changes

We will post changes here and, for material changes, give at least 30 days' notice once the Service is live.

We use cookies for essential site functions and, with your consent, for analytics to improve Subscriber Bot. We don't use advertising or cross-site tracking cookies. See our Cookie Policy.

Preferences