Privacy Policy
Last updated: July 17, 2026 · Effective: July 17, 2026
1. Who we are
SpiteCash is a consumer-friction research project operated by Marius Visan, an independent freelancer based in Romania. We collect user-submitted evidence about digital subscriptions, free trials, cancellation flows, refund delays, and unexpected charges. Friction Alpha uses anonymized and aggregated data to create subscription-friction insights.
2. What data we collect
When you submit a bounty case, we may collect:
- Your email address for contact and bounty communication.
- Your country.
- The app or merchant name and website.
- Charge amount, currency, and charge date.
- Information about reminders, cancellation, refunds, and switching intent.
- Files you upload as evidence, such as screenshots or PDFs.
When you create a free Exit Receipt, we collect:
- The merchant name and website.
- The subscription route (website, App Store, or Google Play).
- The date and time you cancelled.
- Your next expected billing date, if you provide it.
- Your email address, used for the receipt confirmation and the follow-up described in section 4.
- A SHA-256 fingerprint of any cancellation confirmation screenshot you upload. The fingerprint is stored permanently as proof of the file's existence at that date; the file itself is deleted after 90 days.
3. What not to upload
Do not upload full card numbers, passwords, identity documents, full bank account details, or other sensitive banking information. Blurring or cropping sensitive details from your own screenshots before uploading is encouraged and does not affect the validity of your evidence. If we detect unredacted sensitive data, we may reject or delete the file.
4. Why we process this data
We process submitted data to:
- Review and validate consumer-friction events against the six published bounty criteria.
- Calculate a preliminary SpiteScore.
- Contact you about your submission or bounty eligibility.
- Send you the Exit Receipt confirmation email at creation.
- Send one follow-up email after your next billing date — only if you provided that date when creating an Exit Receipt — asking whether the cancellation really worked, with one-click outcome options.
- If you report being charged again, pre-fill a bounty case with your Exit Receipt data so you do not have to re-enter it. Submitting that case remains your choice; it is reviewed against the same six criteria as any other submission.
- Create anonymized and aggregated research reports.
- Improve our fraud prevention and evidence review workflow.
5. Legal basis
We rely on your consent for processing your submission for research purposes, given when you submit a case or create an Exit Receipt. We may also process limited operational data where necessary to run the service, prevent abuse, and maintain records of bounty approvals (legitimate interest). You can withdraw consent at any time by requesting deletion (section 9).
6. Data processors and storage
Your data is stored and processed using the following providers:
- Supabase (PostgreSQL database and file storage) — case data, Exit Receipts, and uploaded evidence.
- Railway — application hosting.
- Brevo — transactional email delivery (receipt confirmations and follow-ups). Brevo receives your email address and the message content only.
We do not sell, rent, or share your personal identity, email address, payment details, or raw uploaded evidence with any third party for advertising or marketing purposes.
7. How we use anonymized data
We may use aggregated, anonymized information in reports, dashboards, per-merchant cancellation statistics, or research outputs. Public statistics are only shown for a merchant once a minimum number of validated cases exists, so no individual submission can be identified.
8. Data retention
We keep data for the following periods:
- Evidence files (screenshots, PDFs) from bounty cases: deleted 90 days after the case decision.
- Exit Receipt confirmation screenshots: deleted 90 days after the receipt is closed or the outcome is recorded. The SHA-256 fingerprint is retained as timestamp proof.
- Your email address: kept until you ask us to delete it, or deleted after 2 years of inactivity.
- Case facts (merchant, amount, date, difficulty): kept indefinitely in anonymized, aggregated form.
- Exit Receipt outcome data (cancelled cleanly / charged again): kept indefinitely in anonymized form to power per-merchant cancellation statistics.
9. Your rights
Depending on your location (including under the GDPR if you are in the EU/EEA), you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to request portability. You may also withdraw consent where processing is based on consent. To exercise any of these rights, contact us at the address below; we respond within 30 days.
10. Changes to this policy
If we change this policy, we update the date at the top of this page. For material changes affecting how your existing data is used, we will notify you by email before the change takes effect.
11. Contact
To request access, correction, or deletion of your data, contact us at: [email protected]