Privacy Policy

Last updated: April 15, 2026

This policy explains what data DueCycle collects, how we use it, who we share it with, and how you can manage it. If you have questions, email us at hello@duecycle.app.

1. Who We Are

DueCycle is a service for recurring home-maintenance reminders (filter changes, smoke-detector checks, etc.). We keep things simple: no subscriptions, one-time purchase, minimal data.

2. What Data We Collect

2.1. Data You Provide

  • Email — for magic-link authentication and email notifications.
  • Your tasks — title, interval, notes, notification time, due dates. You create these yourself.
  • Preferences — theme (light/dark), language, daily notification time.

2.2. Data Collected Automatically

  • Push subscription— your browser's endpoint and crypto keys, if you enable push notifications. Required to deliver them to you.
  • Payment metadata — from Plata by Mono we receive payment status and transaction ID. We do not store or see your full card details.
  • Technical logs — Sentry collects frontend/backend errors (stack trace, URL, browser version, IP). Used solely for diagnostics.
  • Anonymous analytics — Plausible counts aggregated metrics (page views, country, referrer). No cookies, no fingerprinting, no link to your account.

3. How We Use the Data

  • Provide the service — show your tasks, calculate next due dates.
  • Send reminders (email via Resend, push via Web Push API).
  • Process the one-time payment for paid features.
  • Keep the service secure (detect abuse).
  • Improve the product based on anonymous aggregate statistics.

We never sell your data and we do not share it with advertising networks.

4. Who We Share Data With

We rely on these trusted partners:

  • Supabase — database and authentication. Your email and tasks are stored here.
  • Vercel — web app hosting.
  • Resend — transactional email delivery.
  • Plata by Mono — processing the one-time payment.
  • Plausible — privacy-friendly analytics (EU-hosted, no cookies).
  • Sentry — error monitoring.

Each of these services has its own privacy policy and processes data under a confidentiality agreement with us. We do not share your data with anyone outside this list.

5. Cookies and Local Storage

We use the bare minimum:

  • Auth session cookie (essential) — keeps you logged in.
  • Language cookie (NEXT_LOCALE) — remembers your language choice.
  • LocalStorage — stores theme preference and transient UI state.

No marketing or tracking cookies.That's why we don't show a cookie banner.

6. Your Rights

You have the right to:

  • Access and export your data.
  • Correct inaccurate information.
  • Delete your account and all associated data.
  • Unsubscribe from email notifications (link in every email).
  • Disable push notifications (in settings or browser).

To exercise these rights, email privacy@duecycle.app. We respond within 30 days.

7. Data Retention

We retain your data while your account is active. After you delete your account, all personal data is removed within 30 days. Anonymized aggregate metrics may be retained longer.

8. Security

  • All connections use HTTPS.
  • We never store passwords (we use magic links).
  • The database uses Row-Level Security — you see only your data.
  • Database backups are encrypted.

No system is 100% secure. In the event of a data breach, we will notify you within 72 hours.

9. Children

DueCycle is not intended for users under 16 years. We do not knowingly collect data from children. If you learn a child has created an account, contact us.

10. Changes to This Policy

We may update this policy. We will notify you of material changes by email at least 30 days before they take effect. The last-updated date is shown at the top of the page.

11. Contact

Questions, complaints, deletion requests: privacy@duecycle.app.