Trimio Privacy Policy

Effective date: April 27, 2025 · Last updated: September 4, 2026

Thank you for choosing Trimio. This Privacy Policy explains how Trimio collects, uses, stores, protects, and shares your information when you use the Trimio mobile application and related services (the "Service"). By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Who We Are

Trimio is operated by Ismael Naranjo, based in Vienna, Austria, who acts as the data controller under the General Data Protection Regulation (GDPR). You can reach us at Trimio@subtrimio.com.

2. Information We Collect

We collect only what's necessary to operate Trimio: account information (email address, encrypted password, account creation date, and account identifier: passwords are hashed using bcrypt and never stored in plain text); the subscription data you manually enter (service name, billing amount and currency, billing cycle, renewal date, and category); premium subscription information from RevenueCat (subscription status, purchase and expiration dates, premium entitlement status, and anonymous customer identifiers: we never receive or store your payment card details, as all payments are processed by Google Play Billing); device and diagnostic information (device model, OS version, app version, crash reports, and anonymous performance metrics); and product usage analytics (which in-app actions you take, such as completing onboarding or adding a subscription, linked to an internal account identifier rather than your name or email) to help us maintain and improve the Service.

3. How We Use Your Information

We use your information to create and manage your account, authenticate your identity, deliver the core subscription tracking features, verify active Premium subscriptions, send renewal reminder emails and notifications where enabled, improve application performance and stability, detect and prevent fraud or abuse, respond to support requests, and comply with legal obligations. We do not sell your personal information and do not use it for advertising purposes.

4. Legal Basis for Processing (GDPR)

Account creation and authentication, storing the subscription data you enter, and verifying Premium subscription status are necessary for the performance of a contract (Art. 6(1)(b) GDPR). Sending renewal reminder emails relies on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of prior processing. Crash reporting, diagnostics, product usage analytics, and fraud prevention rely on our legitimate interest in maintaining and improving a stable and secure service (Art. 6(1)(f) GDPR). Any processing required to comply with legal obligations relies on Art. 6(1)(c) GDPR.

5. Third-Party Service Providers

Trimio uses a small number of trusted providers to operate the Service, each bound by appropriate data processing agreements: Railway (cloud hosting infrastructure, United States), RevenueCat (subscription management, United States), Google Play Billing (payment processing, United States), Sentry (crash reporting and diagnostics, United States), PostHog (product usage analytics, European Union), and Brevo/Sendinblue (transactional and reminder emails, European Union).

6. International Data Transfers

Some of our service providers are located in the United States. When your personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with GDPR Chapter V. For transfers to US-based providers (Railway, RevenueCat, Google, Sentry) we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or an equivalent transfer mechanism where applicable. PostHog and Brevo/Sendinblue process data within the EEA, so no such transfer mechanism is needed for them.

7. Payments

All purchases are handled by Google Play Billing, and subscription validation is performed using RevenueCat. Trimio never has access to your credit or debit card details, bank account information, or any other payment credentials.

8. Data Security

We implement appropriate technical and organizational safeguards, including HTTPS encrypted communication, secure password hashing (bcrypt), restricted server access, secure cloud infrastructure (Railway), regular software updates, and access controls to protect personal information. No online service can guarantee absolute security. If you become aware of any security concern, contact us immediately at Trimio@subtrimio.com.

9. Data Retention

We retain personal information only for as long as necessary to provide the Service, maintain your account, fulfill contractual obligations, comply with applicable laws, resolve disputes, and prevent fraud. When you delete your account, your personal information is permanently deleted within 30 days, unless a longer retention period is required by applicable law.

10. Account Deletion

You may permanently delete your account at any time through the Account Settings screen inside the app. If you cannot access your account, contact us at Trimio@subtrimio.com. Once processed, your personal information will be permanently deleted within 30 days unless legal obligations require otherwise.

11. Your Privacy Rights

Under the GDPR, you have the right to access a copy of the personal information we hold about you, rectify inaccurate or incomplete information, request erasure of your personal information, restrict how we process your information, object to processing based on legitimate interests, receive your data in a structured, commonly used, machine-readable format (available to all users regardless of subscription tier), and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us at Trimio@subtrimio.com. We aim to respond within the timeframe required by applicable law, generally within 30 days.

12. Right to Lodge a Complaint

If you believe we have not handled your personal information in accordance with applicable law, you have the right to lodge a complaint with the competent supervisory authority. For users in Austria, this is the Österreichische Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Vienna, Austria (www.dsb.gv.at, dsb@dsb.gv.at). We encourage you to contact us first so we can address your concern directly.

13. Data Sharing

We do not sell, rent, lease, or trade your personal information. We share information only when necessary to operate the Service through our listed providers, process Premium subscriptions, provide customer support, detect fraud or abuse, comply with legal obligations, or protect the rights, safety, and security of our users or our business.

14. Children's Privacy

Trimio is not intended for children under the age of 14. In accordance with Article 8 of the GDPR as implemented under Austrian law, we do not knowingly collect personal information from children under 14 without verifiable parental consent. If we become aware that personal information has been collected from a child under 14 without appropriate consent, we will promptly delete that information.

15. Cookies and Analytics

Trimio does not use advertising cookies or advertising identifiers, and does not sell or share analytics data with advertisers. Crash and performance diagnostics are anonymous. Product usage analytics (via PostHog, hosted in the EU) are linked to an internal account identifier so we can see, for example, where people drop off during onboarding, but never to your name, email, or the specific subscriptions you track, session recording and automatic screen capture are both turned off. The Trimio website at subtrimio.com uses the same EU hosted PostHog to count page views and whether a visit led to an account being created. It sets no cookies and stores nothing on your device, it honours the Do Not Track setting in your browser, and it never sends anything you type into a form.

16. Business Transfers

If Trimio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. Any successor will remain bound by the commitments in this Privacy Policy.

17. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. When significant updates are made, we will revise the "Last Updated" date and notify users within the application where appropriate. Continued use of the Service after an update constitutes acceptance of the revised Privacy Policy.

18. Contact Us

For any questions, requests, or concerns regarding this Privacy Policy or our privacy practices, contact us at Trimio@subtrimio.com. We aim to respond to all privacy-related inquiries within 30 days.