Privacy Policy

Effective 2 October 2026

This policy explains what personal data the dueby mobile app and its server (together, “dueby”) collect, how they are used, who else processes them, how long they are kept, and the choices you have. dueby is provided by Szymon Zygzuła, ul. Prezydenta Lecha Kaczyńskiego 24A/90, 80-365 Gdańsk, Poland (“we”, “us”), who is responsible for the personal data described here. You can reach us at support@zygzula.com.

In short

What we collect

Your account

When you create an account you give us a username, an email address and a password. We store the password only as a one-way cryptographic hash (bcrypt); nobody, including us, can read it back. We also record when the account was created and last changed, and give it an internal account number. You use your username or email address to sign in, and your email address to recover a forgotten password.

Signing in

Signing in gives the app a short-lived access token and a longer-lived sign-in credential. On our server we keep, for each signed-in session, a cryptographic digest of that credential (never the credential itself), when it was issued and when it expires. Sessions expire 30 days after they were last used, and end when you sign out.

Your tasks

For each task you create we store what you enter — its title, an optional description, how often it recurs, when you started tracking it, how many days of notice you want before it is due, whether it should send reminders — along with a colour dueby assigns to it and when it was created and changed. Each time you mark a task done we store the date you completed it, when that was recorded, and which account recorded it.

Please do not put information in task titles or descriptions that you would not want stored on our server, shown to people you share the task with, or — for titles — shown in a notification on your lock screen.

Shared tasks

If you share a task, we store who you invited, the access you offered them (viewer or editor), and when they were invited and joined. To invite someone you type their exact username or email address; we use it only to find their account and do not store what you typed. The people who share a task can see its title, description, schedule and history, the usernames of everyone who shares it, and who recorded each completion. An invitation shows the invitee the task’s title and colour, your username and the access offered. Your email address is never shown to other users.

Notification settings and time zone

We store whether you want notifications, which kinds (due reminders, task invitations, someone joining your task), the time of day you want due reminders, and your time zone. The app reads the time zone from your phone (for example “Europe/Warsaw”) so that reminders arrive at your local time; it is not used to locate you.

Push notifications

If you allow notifications, your phone’s operating system and Google’s Firebase Cloud Messaging service give the app a registration token — an address for sending notifications to this app on this phone. The app sends it to our server with your phone’s platform (iOS or Android), and we store it with your account, together with when it was registered, so that reminders reach you. We keep a record of which due date we last reminded you about for each task, so you are reminded only once per due date.

To create the token, the Firebase software in the app generates a Firebase installation identifier and sends it to Google, together with Apple’s push token for the app (on iPhone) and technical information such as the device model, operating-system version, language, time zone, the app’s identifier and version, and the version of the Firebase software. Google uses this information to deliver notifications. A notification we send contains a short message — for example “Change bedsheets is due” or “alice invited you to Change bedsheets” — and the internal identifier of the task, and passes through Google and, on iPhone, Apple’s Push Notification service to reach your phone.

The Firebase software also sends Google diagnostic information about itself — such as its version and the platform it runs on — which Google uses to operate and improve Firebase. According to Google, this information is not linked to your identity, and we do not receive it.

Password recovery

If you ask to reset your password, we email a six-digit code to your account’s email address. We store the code only as a hash, with when it expires (after 15 minutes) and how many attempts are left. It is deleted when it is used, replaced by a newer code, or deleted with your account. The email is sent through our email provider.

Security and server logs

Like any internet service, our server receives your phone’s IP address with each request. Our web server logs each request with the IP address, the time, the address requested (with any text you typed into the task search removed), the response, and the request’s technical headers, such as the app’s user-agent string. Passwords and sign-in tokens are never logged. The application logs errors and security events, identifying accounts by their internal number. To stop password guessing and abuse, the server counts recent sign-in, password-recovery, invitation and password-confirmation attempts per IP address, per identifier or per account; these counters are held only in the server’s memory and last at most an hour. Logs are used for security, troubleshooting and keeping dueby available.

When you contact us

If you email us, we receive your email address and whatever you write, and use them to answer you.

What we do not collect

dueby does not access your location, contacts, photos, camera, microphone, calendars or health data, does not use your phone’s advertising identifier, and contains no advertising software and no analytics software of ours.

What is stored on your phone

Deleting the app removes these from the phone. It does not delete your account.

How we use personal data

PurposeDataLegal basis
Creating and running your account, signing you in, recovering your passwordAccount details, sign-in sessions, recovery codesperformance of our contract with you (Article 6(1)(b) GDPR)
Tracking your tasks, showing what is due, the calendar and shared tasksTasks, completions, sharing records, usernamesperformance of our contract with you (Article 6(1)(b) GDPR)
Sending the notifications you asked forNotification settings, time zone, registration tokens, task titlesperformance of our contract with you (Article 6(1)(b) GDPR)
Keeping dueby secure and available, preventing abuse, restoring data after a failureIP addresses, logs, attempt counters, backupsour legitimate interest in keeping dueby secure and available (Article 6(1)(f) GDPR)
Helping you use dueby when you ask us for supportYour email and what you write performance of our contract with you (Article 6(1)(b) GDPR)
Handling requests to exercise your data-protection rightsYour email, what you write, and the data needed to confirm your identity and act on the requestour legal obligation to respond to them (Article 6(1)(c) GDPR)
Answering other messages, such as complaints, reports of abuse or security problems, and general questionsYour email and what you writeour legitimate interest in answering you and keeping dueby safe (Article 6(1)(f) GDPR)

We do not use your data for advertising, marketing, profiling or automated decisions that affect you, and we do not use it to train artificial-intelligence models.

Who else processes your data

We do not sell, rent or trade personal data. It is processed by these service providers, only to run dueby:

We use these providers only under terms that require them to protect personal data and to use it only to provide their service to us, giving the same or equivalent protection as this policy. Other dueby users see the information described under Shared tasks only when you share a task with them or accept their invitation. We may disclose personal data if the law requires it, or to protect the rights and safety of our users or others.

International processing

Our server is located in Germany. Google and Apple operate their notification services worldwide, so the data they handle for notifications may be processed in other countries, including the United States. Google LLC is certified under the EU–U.S. Data Privacy Framework, which the European Commission has recognised in an adequacy decision. Where the law requires safeguards for other transfers, they rely on those provided in those companies’ terms, such as the European Commission’s standard contractual clauses.

How long we keep it

Deleting your account

Open Settings → Delete account in the app and confirm with your password. Deletion happens immediately and cannot be undone. It removes your account, your tasks and their history, your notification settings, your sign-in sessions and your phones’ notification registrations, and it signs you out on every device. Specifically, for tasks shared between people:

After deletion your username and email address can be used for a new account. If you cannot sign in, email support@zygzula.com from your account’s email address and we will delete the account for you.

Security

All communication between the app and our server is encrypted with HTTPS. Passwords and recovery codes are stored only as hashes, sign-in credentials only as digests, and the app keeps its tokens in the phone’s secure storage. Our server accepts connections only through an HTTPS proxy, and the database is not reachable from the internet. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the authorities where the law requires.

Your choices and rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. To exercise these rights, email support@zygzula.com from the address your account uses; we may need to confirm your identity. We will respond within one month, which the law allows us to extend in some cases; if we do, we will tell you why.

You also have the right to lodge a complaint with a data protection supervisory authority. In Poland, where we are based, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl). You can also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe your rights were infringed.

Children

dueby is not directed at children. You must be at least 16 years old to create an account. If you believe a child under that age has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy when dueby or the law changes. The effective date at the top shows the current version. If a change significantly affects how we use your personal data, we will tell you in the app or by email before it takes effect.

Contact

Szymon Zygzuła, ul. Prezydenta Lecha Kaczyńskiego 24A/90, 80-365 Gdańsk, Poland
Privacy: support@zygzula.com · Support: support@zygzula.com