It can be safe to let an app scan your inbox for subscriptions if the permission is read-only OAuth, the app does not store message bodies, and you can revoke access. Handing over a password is not that. Unwanted Subscription signs in with Google or Microsoft, reads receipts, and discards the mail.

Password vs OAuth

Never type your Gmail password into a subscription app. Google and Microsoft both offer OAuth: you sign in on their page, grant a scope, and can revoke it later in Google Account → Security → Third-party access, or Microsoft’s app permissions list.

Unwanted Subscription requests read-only mail. It cannot send as you, cannot delete, cannot change labels. That is the difference between a scanner and a hijack.

What should never be kept

A copy of the inbox. Full message bodies. Attachments. A searchable archive “for later.” If a product needs those, it is not a subscription finder. It is an email host. We analyze receipts in memory and return a list. We do not store the emails. Tokens exist so you are not forced to sign in every scan. Disconnect deletes them. That is spelled out in the Privacy Policy.

What stays on the phone

The subscription list, reminders, and settings live on that iPhone or iPad. There is no cloud backup of your keep/cancel choices. Delete local data in Profile, or delete the app, and that copy is gone.

When you should not connect mail

Shared inboxes you do not own. Work accounts your employer forbids. If you are not allowed to grant third-party read access, use a statement upload instead. PDF is processed and discarded; CSV never leaves the device.

iCloud

There is no iCloud Mail connect. That is an Apple platform limit, not a feature we skipped. Use Gmail, Outlook, or a file.

If you want the product without the inbox, that path is first-class. The inbox is optional. The list is the point.

Stop paying for what you don’t use.

Free on the App Store. Ready when you are.