Last updated: May 11, 2026
Cancelette uses passwordless magic link authentication powered by Supabase. We never store passwords. Sign-in links expire after 1 hour and can only be used once. Sessions are managed via secure, httpOnly cookies that cannot be accessed by JavaScript.
When you connect Gmail, Cancelette requests the minimum required permissions:
We never read full email body content — only subject lines and snippets. Raw email data is processed in memory and immediately discarded. We never store email content. We do not use your Google user data to train generalized AI models. You can revoke Gmail access at any time from your Google Account settings. Cancelette's use and transfer to any other app of information received from Google APIs will adhere to the Google API Service User Data Policy, including the Limited Use requirements.
We take security seriously. If you discover a vulnerability in Cancelette, please report it responsibly:
We will acknowledge your report within 48 hours and keep you updated on our progress.
Zero bank credentials. Cancelette never asks for your bank login, bank account number, or any financial credentials. We track subscriptions through Gmail receipts only. If any app claiming to be Cancelette asks for your bank password — it is not us.