Privacy Policy
This policy explains what personal information Subwise collects, why we collect it, who we share it with, and the choices you have. It applies to the Subwise mobile app, the subwise.au website, and any support we provide by email.
- Who we are
- What we collect
- Banking data and the Consumer Data Right
- How we use your information
- Automated processing and AI
- Who we share information with
- Overseas disclosure
- Security
- Retention and deletion
- Accessing and correcting your information
- Website, cookies and analytics
- Children
- Changes to this policy
- Complaints
1. Who we are
Subwise is operated by Crist Labs Pty Ltd (ABN 99 700 686 282), an Australian company. In this policy, "Subwise", "we", "us" and "our" refer to Crist Labs Pty Ltd.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle data shared through the Consumer Data Right, we are additionally bound by the Competition and Consumer (Consumer Data Right) Rules 2020 and the CDR privacy safeguards.
You can reach us at support@subwise.au about anything in this policy, including a request to access, correct or delete your information.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account information | Email address, display name, authentication identifiers, password hash or third-party sign-in token | To create and secure your account and let you sign in |
| Banking and transaction data | Account names and types, transaction dates, amounts, merchant descriptions, balances | To identify recurring charges and calculate what you spend on subscriptions |
| Subscription records | Subscriptions you add or confirm, renewal dates, amounts, cancellations, notes | To run reminders, track changes, and show your history |
| Purchase information | Subscription tier, purchase and renewal events, platform receipts | To provide paid features and handle billing questions |
| Device and usage data | Device type and OS version, app version, crash reports, feature usage, push notification tokens | To keep the app working, fix faults, and send the alerts you ask for |
| Support correspondence | Emails you send us and our replies | To answer you and keep a record of the issue |
We do not collect your banking login credentials, and we never ask for them. See the next section.
3. Banking data and the Consumer Data Right
Subwise obtains your banking data through Australia's Consumer Data Right (CDR), also known as Open Banking. The CDR is a legislated data-sharing framework that lets you direct your bank to share specified data with a service you have chosen.
Status: Subwise is in the process of being appointed as a CDR Representative of an accredited data recipient. Until that arrangement is in place and disclosed here, Subwise does not collect CDR data. We will update this policy, and publish a separate CDR Policy as required by the CDR Rules, before any CDR data sharing begins.
How the consent works
- You choose which accounts to share and what the data will be used for. Nothing is shared until you complete an authorisation with your own bank.
- Your authorisation happens on your bank's own screens. Subwise never sees, receives or stores your banking username, password, PIN or one-time codes.
- Access is read-only. Subwise cannot initiate payments, transfer funds, or alter your accounts in any way.
- Consents are granted for a defined period and can be withdrawn by you at any time — from within Subwise, or through your bank's data-sharing dashboard.
- When you withdraw consent, we stop collecting new data and delete or de-identify the CDR data we hold, except where a law requires us to keep a record.
What we do with CDR data
We use it only for the purposes you consented to: identifying recurring charges, presenting your subscription spending, generating renewal and price-change alerts, and supporting the cancellation and negotiation features you choose to use. We do not sell your data, and we do not use it for advertising or for credit assessment.
4. How we use your information
- To provide the app: detecting subscriptions, showing your spending, sending the alerts you enable.
- To operate your account, process paid subscriptions and provide customer support.
- To keep Subwise secure — detecting fraud, abuse and unauthorised access.
- To fix faults and improve the product, using aggregated or de-identified usage information wherever it will do the job.
- To meet our legal and regulatory obligations.
We do not sell personal information, and we do not disclose it to third parties for their own marketing.
5. Automated processing and AI
Subwise uses automated rules to detect recurring transactions, and uses third-party AI language models to help draft text — for example, a suggested message when you decide to ask a provider for a better rate.
- Drafts are suggestions only. Nothing is sent on your behalf without you reviewing and choosing to send it.
- Recommendations about pricing tiers are produced by deterministic logic, not by a language model.
- Where content is sent to an AI provider for drafting, we limit it to what is needed for that task. Our AI providers are engaged under terms that prohibit using your content to train their models.
- No decision with a legal or similarly significant effect on you is made solely by automated means.
6. Who we share information with
We share personal information only with service providers who help us run Subwise, and only to the extent they need it. These currently include categories such as:
- Cloud hosting and database providers — to store and serve your data.
- Authentication providers — to sign you in securely.
- The accredited data recipient through which CDR data is obtained, once that arrangement is in place.
- App store and subscription-billing providers — to process and validate purchases.
- Crash reporting and analytics providers — to detect and diagnose faults.
- AI language model providers — for the drafting features described above.
- Email and communication providers — to send you notifications and support replies.
We may also disclose information where required by law, court order, or a regulator, or to protect the safety, rights or property of you, us or others.
7. Overseas disclosure
Some of our service providers are located outside Australia, including in the United States and the European Union. Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections.
CDR data is subject to additional restrictions under the CDR Rules, and we handle it in accordance with those restrictions.
8. Security
- Data is encrypted in transit using TLS, and encrypted at rest.
- Access to production systems is restricted, authenticated, and logged.
- We apply the principle of least privilege — systems and staff get access only to what is required.
- We do not store banking credentials at any time.
No system can be guaranteed completely secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and follow the CDR breach requirements where CDR data is involved.
9. Retention and deletion
- We keep your account and subscription information while your account is open.
- CDR data is deleted or de-identified when you withdraw consent, when the consent expires, or when it is no longer needed for the purpose you consented to — whichever comes first.
- When you delete your account, we delete your personal information within a reasonable period, except where we are required to retain records by law.
- Backups are cycled on a rolling schedule; deleted data is removed from backups as those backups expire.
You can request deletion at any time by emailing support@subwise.au, or by using the delete-account option in the app.
10. Accessing and correcting your information
Under the Australian Privacy Principles you may ask us to give you access to the personal information we hold about you, and to correct it if it is inaccurate, out of date or incomplete. Email support@subwise.au and we will respond within a reasonable period, ordinarily within 30 days.
We may need to verify your identity before acting on a request. If we refuse a request we will tell you why in writing.
11. Website, cookies and analytics
The subwise.au website is a static site. It does not set advertising or tracking cookies, does not embed third-party trackers, and serves its fonts from our own domain rather than a third-party font service. Our hosting provider processes standard server and security logs, which may include IP addresses, for the purpose of delivering and protecting the site.
12. Children
Subwise is not directed at children and is intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the effective date above and, where the change is significant, notify you in the app or by email. Continued use of Subwise after a change takes effect means you accept the updated policy.
14. Complaints
If you think we have mishandled your personal information, contact us first at support@subwise.au. We will acknowledge your complaint and aim to resolve it promptly.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- Website: oaic.gov.au
- Phone: 1300 363 992
Complaints about the handling of CDR data can also be made to the OAIC.