Your data, clearly.
Subabot is an open-source RSS monitoring tool. This page explains how this version handles the information needed to run your monitors.
Your workspace
You can create a workspace without an email address or password. The browser saves a workspace access key in local storage. The backend uses that key to authorize access to your workspace. Anyone with the key can access the workspace, so treat it like a password.
Browser storage is specific to this browser and site. Clearing it can remove your access to the workspace. Download your private recovery file from settings before changing browsers or clearing site data.
What the backend stores
- Monitor names, feed URLs, keyword rules, and their settings.
- Matching feed items, including their titles, links, available content, source details, and read or saved state.
- Operational information such as the last feed check and delivery errors.
- An optional Slack incoming webhook URL that you explicitly connect.
Running your own instance puts this data on your server. A hosted instance stores it on the instance operator’s infrastructure. This software does not provide a guarantee about another operator’s policies or retention.
Feed providers and Slack
The backend requests the public feed URLs that you add. Feed providers receive normal request information, including the server’s IP address. The contents and availability of those feeds are controlled by their publishers.
If you connect Slack, matching items can be sent to your selected incoming webhook. Slack then processes the message under its own privacy policy. A Slack webhook is a credential. It is not included in a public monitor configuration.
Sharing is your choice
Monitors stay within your workspace unless you choose to publish a shareable configuration. Publishing makes the selected monitor’s name, description, feed URLs, keyword rules, and matching stories available to people with the link. Do not publish feed URLs containing private tokens or information you do not want to disclose.
A recipient may copy a shared configuration. Removing a share cannot remove copies that someone already made.
Analytics and AI
This version does not include third-party advertising or analytics scripts. It does not send monitor content to an AI provider. Server operators and hosting providers may maintain operational request logs according to their own configuration.
Removing information
You can delete monitors through the app. Clearing browser storage removes the local workspace key; it does not by itself delete records on the server. If you run your own instance, you control the database and its backups. For data handling questions on another instance, contact that instance’s operator.
Questions and source code
You can inspect the implementation in the Subabot repository or contact the creator through Doruk Gezici’s GitHub profile. Do not post workspace keys, private feed URLs, or Slack webhooks in public issues.
Updated 11 October 2026. Applies to the functionality shipped with this version.