Last updated: April 11, 2026
Cancelette uses passwordless magic link authentication powered by Supabase. We never store passwords. Sign-in links expire after 1 hour and can only be used once. Sessions are managed via secure, httpOnly cookies that cannot be accessed by JavaScript.
When you connect Gmail, Cancelette requests the minimum required permissions:
We never read full email body content — only subject lines and snippets. Raw email data is processed in memory and immediately discarded. We never store email content. You can revoke Gmail access at any time from your Google Account settings.
We take security seriously. If you discover a vulnerability in Cancelette, please report it responsibly:
We will acknowledge your report within 48 hours and keep you updated on our progress.
Zero bank credentials. Cancelette never asks for your bank login, bank account number, or any financial credentials. We track subscriptions through Gmail receipts only. If any app claiming to be Cancelette asks for your bank password — it is not us.