Privacy Policy

We believe in keeping this plain and readable. Here is exactly what we collect, why, and what you can do about it.

Effective date: 1 July 2026 · Last updated: 1 July 2026

1. Who we are

Pear (“Pear,” “we,” “us,” or “our”) is a subscription-detection service that scans your Gmail inbox to identify recurring payments you may have forgotten about. We are the data controller for the personal data described in this policy.

Contact: hello@pear.so

2. What data we collect

We collect the minimum data necessary to provide the service:

  • Account information. When you sign up, we store your email address and, if provided via Google Sign-In, your display name and profile picture URL.
  • Subscription metadata. When you connect Gmail and run a scan, we extract and store: the vendor name, billed amount, billing frequency (monthly/annual), currency, and approximate billing date. We do not store the raw subject line, email body, or any other email content.
  • Payment confirmation. When you purchase a scan, Stripe confirms the transaction. We store a record of the purchase (timestamp and a Stripe session ID) but never your card details — those stay with Stripe.
  • Usage data. We store the date and status of each scan so you can see when your last scan ran.

3. How we use your data

We use your data to:

  • Provide the subscription-detection service you paid for.
  • Display your scan results on your dashboard.
  • Send transactional emails (payment receipt, scan completion). We do not send marketing emails without your explicit opt-in.
  • Maintain and improve the accuracy of the AI classification model (using only aggregate, non-personal metrics — never your individual emails).

4. How AI classification works

During a scan, the subject line and sender address of each email is sent to the Claude API (Anthropic, Inc.) to determine whether it is a subscription billing email. The email body is not included in this step.

During a Deep Scan (to find costs for subscriptions initially marked as “cost unknown”), the plain-text content of a single billing email may be sent to the Claude API. This data is processed and immediately discarded — it is not stored by Pear.

Anthropic does not use API inputs to train its models. See anthropic.com/privacy.

5. Legal basis for processing (GDPR)

If you are located in the European Economic Area, our legal bases are:

  • Contract performance (Article 6(1)(b)) — processing your email metadata is necessary to deliver the scan you paid for.
  • Legitimate interests (Article 6(1)(f)) — storing a purchase record and running aggregate service analytics.
  • Consent (Article 6(1)(a)) — for any optional communications you opt into.

6. Third-party processors

We share data with the following sub-processors to run the service. Each is contractually bound to process data only on our instructions:

  • Google LLC — Gmail API access during scans. OAuth 2.0, read-only scope.
  • Anthropic, Inc. — AI classification of email subject lines/senders and Deep Scan text. API data not used for model training.
  • Supabase Inc. — Database and authentication. Hosted on AWS EU region. SOC 2 Type 2 certified.
  • Stripe, Inc. — Payment processing. PCI DSS Level 1 certified. We receive only a session confirmation, not card data.
  • Vercel Inc. — Application hosting. SOC 2 Type 2 certified. Traffic served over TLS 1.2+.

7. Data retention

We retain your subscription metadata and account information for as long as your account is active. If you delete your account, all associated data is deleted within 30 days. Purchase records are retained for 7 years as required by EU tax law.

8. Your rights (GDPR)

If you are in the EEA, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data (“right to be forgotten”).
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Restriction — ask us to restrict processing in certain circumstances.

To exercise any of these rights, email hello@pear.so with the subject line “Data Request.” We will respond within 30 days.

You also have the right to lodge a complaint with your local supervisory authority. In Ireland, this is the Data Protection Commission: dataprotection.ie.

9. Cookies

We use only essential cookies required to keep you logged in (a session cookie from Supabase). We do not use advertising or analytics cookies.

10. Children

Pear is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. Changes to this policy

If we make material changes, we will notify you by email or by displaying a prominent notice on the site at least 14 days before the change takes effect. The “Last updated” date at the top of this page reflects the most recent revision.

12. Contact

Questions about this policy or your data: hello@pear.so