Privacy notice
Last updated 2026-09-19
Prerenew is a reminder and decision tool. It never connects to your bank, never sees your card, and never charges you. This notice lists exactly what it does store.
Who is responsible
Prerenew operates Prerenew and is the data controller for the personal data described here. Contact: hello@prerenew.com.
What we store
| Data | Why | Kept until |
|---|---|---|
| Email address | To find your vault when you sign in, and to send the reminders and digests you turn on. | You delete your vault. |
| Passkey public key and credential id | To let you sign in without a password. The private key never leaves your device. | You delete your vault. |
| Session token (hashed) | To keep you signed in for up to 30 days. | Sign-out or 30 days. |
| Time zone | So reminders respect your quiet hours and arrive in your morning, not ours. | You delete your vault. |
| Subscriptions you add | Name, price, currency, billing cycle, renewal date, notes, and whether it is a trial. This is the product. | You delete the subscription or your vault. |
| Decisions and check-ins | Your keep, pause, and cancel choices and the “did you use it?” answers, so the app can show patterns and your ledger. | You delete your vault. |
| Reminder log | Which nudges were sent, deferred, or suppressed, so the daily cap and quiet hours work. | You delete your vault. |
| Web push endpoint | A browser-issued address that lets us deliver notifications to a device you enabled. It carries no personal identifier of yours. | You disable push, the browser revokes it, or you delete your vault. |
| Settings | Reminder cap, quiet hours, display preferences. | You delete your vault. |
| Rate-limit counters | Sign-in attempts per email and per network address, to stop abuse. | 15 minutes. |
Pasted bank statements
The import feature reads statement text you paste, in memory, to spot recurring charges. We keep only the rows you confirm, reduced to a merchant name, an amount, and a billing cycle. Long digit sequences such as account numbers are stripped before matching and are never stored. The pasted text itself is not written to disk or logs.
What we do not do
- We do not connect to banks or card networks and do not use Plaid or similar services.
- We do not cancel or pause subscriptions on your behalf. Playbooks show you the provider’s own steps.
- We do not ask about, infer, or record any diagnosis. Being designed with ADHD and autistic adults is a design stance, not a data category.
- We do not sell personal data, run advertising, or use third-party analytics or tracking cookies.
- We do not send marketing email. Every email is a sign-in link or a reminder you turned on.
Legal basis
Where the GDPR or UK GDPR applies: creating and running your vault is performance of a contract (Article 6(1)(b)). Sign-in security, rate limiting, and abuse prevention are our legitimate interest (Article 6(1)(f)). Reminder emails and push notifications are sent because you asked for them and can be switched off in Settings at any time.
Who else touches the data
- Our hosting and database provider stores the records above. The database is not exposed to the public internet.
- Resend delivers transactional email when email is enabled. It receives your email address and the message content.
- Your browser vendor’s push service (for example Apple, Google, or Mozilla) relays push notifications. Payloads are encrypted to your device.
- Landing-page photographs load from Unsplash’s image CDN, which sees your IP address like any image host. The app itself loads nothing from third parties.
Where data leaves the UK or the EU, the transfer rests on the provider’s standard contractual clauses, which Resend and MongoDB include in their data processing agreements.
Your rights and the buttons that serve them
- Access and portability: Settings, then Export JSON or Export CSV. Everything we hold is in that file.
- Erasure: Settings, then Delete my vault. It deletes every record listed above immediately. There is no soft delete or retention window.
- Rectification: edit any subscription or setting in the app.
- Objection and restriction: turn off email or push in Settings, or email us.
- Complaints: you can contact your local data protection authority. In the UK that is the ICO; in the EU, the authority in your member state.
Security
Sign-in uses passkeys (WebAuthn) or single-use email links that expire in 15 minutes. Session tokens are stored hashed. Cookies are HttpOnly and SameSite. The site sends strict security headers and refuses to be framed. If we learn of a breach affecting your data we will tell you and, where required, the regulator within 72 hours.
Age
Prerenew is for adults managing their own money. You must be at least 16 to create a vault.
Changes
We will update the date at the top when this notice changes and describe material changes in the app before they take effect.