Security & Privacy

Your financial records are private. Explore how Subly secures your subscription database locally and during cloud synchronization.

Local Database Encryption

All subscription records and configurations are saved on-device using SQLite with SQLCipher encryption, keeping your financial statements shielded from unauthorized local apps.

Zero-Knowledge Cloud Sync

Cross-device data synchronization employs AES-256 end-to-end encryption. Your encryption keys are generated locally from your login password and are never shared with our servers.

No Banking Integration

By deliberate choice, Subly never requests credentials for your credit cards or bank accounts. This shields you from credentials leaks and guarantees 100% financial privacy.

Secure Authentication

We use Firebase Authentication protocols supporting OAuth and Google Sign-In. We never store raw login passwords on our backend infrastructure.

Encryption Standards

Subly compliance parameters align with the highest financial industry guidelines. All transit pipelines use TLS 1.3 protocols, preventing eavesdropping or man-in-the-middle exploits during cross-device synchronization cycles.

Our storage engines are designed to be completely containerized. Database operations occurring on Android are kept within private app sandboxes, isolated from external storage cards or malicious applications.

In the event of a security vulnerability discovery, our response engineers initiate isolation operations to secure authentication vectors within 1 hour. Bug bounty and security disclosures can be forwarded directly to security@subly.app.