NeverSubTerms of Service

Last updated 20 September 2026

Privacy Policy

This policy explains what personal data NeverSub collects, why we collect it, who we share it with, and how to exercise your rights.

1. Data we collect today for the waitlist

The live waitlist stores your email address, a normalised email key for deduplication, the categories you select, any monthly spend estimate passed from the calculator, community type, community name or private-circle interest, a legacy affiliation field when provided, your referral code, who referred you, confirmation state, a hashed confirmation token, email delivery status, bounce or complaint events, and timestamps.

The waitlist API also stores a salted hash of your IP address for rate limiting. We do not store the raw IP address for this purpose.

The confirmation token itself is not stored. Only its hash is kept, so a database copy cannot be used to confirm someone’s place on the list.

The waitlist database is PostgreSQL storage under our control, not a third-party form tool.

2. Data we expect to collect from launch

When the product launches, we expect to process account details, community verification information, rooms you create or join, bids or offers, chat messages, escrow and wallet ledger records, payout details, support messages, device and security logs, and consent records.

If a host stores access details for a room, those credentials will be encrypted at rest and revealed only through an authenticated server-side flow to eligible members of that room.

Payment instruments, bank details or KYC information may be collected by a payment partner or payout partner. We keep the references and records needed to run escrow, wallets, refunds, withdrawals, accounting and compliance.

3. Why we use personal data

We use personal data to run the waitlist, send confirmation emails, count referrals, decide which communities to open first, prevent abuse, provide customer support, create and operate rooms, hold and release escrow, process refunds and payouts, meet tax and legal duties, and keep the platform safe.

For a waitlist email address, we use it to confirm your place, keep referral attribution, and send one launch message when NeverSub is ready. We do not add it to an advertising list.

Our legal bases include your consent, steps needed to provide the service you ask for, compliance with law, and legitimate uses that are proportionate and expected in running a trust-and-payments marketplace.

You can withdraw consent for optional processing by emailing us. Withdrawal does not affect processing already completed or processing we must continue for legal, fraud-prevention, accounting or dispute reasons.

4. Who we share data with

We share email addresses with Resend for transactional email delivery. Resend sends confirmation emails and sends delivery events such as bounced or complained back to our webhook.

From launch, we will share payment, escrow, refund, wallet, payout and KYC data with payment and payout partners as needed to process money flows and comply with law.

We may share limited data with hosting providers, professional advisers, auditors, law enforcement, regulators, courts, or another entity involved in a merger or business transfer, only where there is a proper reason.

Inside the product, room members may see information needed to understand a room: host identity, room terms, membership status, payment state and messages they are allowed to access.

5. Cookies and analytics

We use third-party analytics services on the marketing site: product analytics, Microsoft Clarity session-recording and heatmap analytics, and Google Analytics. They help us understand which parts of the page people read, where they stop, which calls to action they use, and whether feature flags are working. Our product analytics instance is configured for EU processing. Other analytics processors may process data in the locations where they operate.

Session replay is enabled so we can find broken or confusing parts of the page. Form inputs are masked in replay and the waitlist email field is explicitly marked for masking, so the email address or other text you type into a form is never recorded in a replay.

We do not run advertising or marketing pixels, and we do not use the waitlist email address for ad targeting.

Referral tracking is a code in the page URL, such as ?r=CODE. That code does not contain an email address. If you sign up through it, the code is stored as the referrer for the waitlist.

You can block analytics with browser privacy controls or script blockers. You can also email [email protected] to opt out of optional analytics where we can identify your record, or to ask us to delete data linked to you.

6. How long we keep data

We keep waitlist records until launch decisions, referral perks and early access are resolved, unless you ask us to delete your record earlier and we do not need to keep it for a legal reason.

From launch, account, room, payment, escrow, wallet, tax, security and support records may be kept for as long as needed to provide the service, resolve disputes, prevent fraud, comply with law and maintain business records.

When data is no longer needed, we delete it or make it no longer identify you, unless the law requires retention.

7. Your DPDP rights

Under the Digital Personal Data Protection Act, 2023, you have rights of access, correction, erasure, grievance redressal and nomination, subject to the limits in the law.

Email [email protected] to ask what data we hold about you, correct it, delete your waitlist record, withdraw consent, nominate another person, or raise a grievance. Because the waitlist store is ours, we can delete a waitlist row directly unless a legal reason requires retention.

We may need to verify that the request comes from you before acting on it. We will respond within the period required by applicable law.

8. Security

We use practical safeguards such as token hashing, access control, server-side verification, rate limiting, encryption for sensitive room credentials from launch, and restricted operational access.

No system is perfectly secure. If we learn of a breach that affects your personal data, we will take steps required by applicable law and communicate where required.

9. Children

NeverSub is not aimed at children. If we learn that we collected personal data from a child in a way that needs parental consent and that consent is missing, we will delete or restrict the data as required by law.

10. Storage and transfers

Our waitlist store is self-hosted. Some processors, such as email or payment providers, may process data outside your country where their infrastructure requires it.

We will use processors only for the purposes described in this policy and subject to applicable data protection law, including any restrictions notified by a competent authority.

11. Changes to this Policy

We will update this Policy as NeverSub moves from waitlist to launch and as our processors, payment flows or legal duties change.

The latest version will be posted here with its last updated date. If a material change affects how we use your personal data, we will give notice through the product or by email where practical.