Privacy Policy
Effective 2 October 2026
This policy explains what personal data the dueby mobile app and its server (together, “dueby”) collect, how they are used, who else processes them, how long they are kept, and the choices you have. dueby is provided by Szymon Zygzuła, ul. Prezydenta Lecha Kaczyńskiego 24A/90, 80-365 Gdańsk, Poland (“we”, “us”), who is responsible for the personal data described here. You can reach us at support@zygzula.com.
In short
- We collect what dueby needs to work: your account details, the tasks you create and when you complete them, your notification settings, and — if you allow notifications — a notification address for your phone.
- dueby has no advertising and no tracking, and we use no analytics tools. We do not sell or rent personal data, and we do not use it to profile you.
- You can delete your account, and everything it holds, at any time inside the app: Settings → Delete account.
What we collect
Your account
When you create an account you give us a username, an email address and a password. We store the password only as a one-way cryptographic hash (bcrypt); nobody, including us, can read it back. We also record when the account was created and last changed, and give it an internal account number. You use your username or email address to sign in, and your email address to recover a forgotten password.
Signing in
Signing in gives the app a short-lived access token and a longer-lived sign-in credential. On our server we keep, for each signed-in session, a cryptographic digest of that credential (never the credential itself), when it was issued and when it expires. Sessions expire 30 days after they were last used, and end when you sign out.
Your tasks
For each task you create we store what you enter — its title, an optional description, how often it recurs, when you started tracking it, how many days of notice you want before it is due, whether it should send reminders — along with a colour dueby assigns to it and when it was created and changed. Each time you mark a task done we store the date you completed it, when that was recorded, and which account recorded it.
Please do not put information in task titles or descriptions that you would not want stored on our server, shown to people you share the task with, or — for titles — shown in a notification on your lock screen.
Shared tasks
If you share a task, we store who you invited, the access you offered them (viewer or editor), and when they were invited and joined. To invite someone you type their exact username or email address; we use it only to find their account and do not store what you typed. The people who share a task can see its title, description, schedule and history, the usernames of everyone who shares it, and who recorded each completion. An invitation shows the invitee the task’s title and colour, your username and the access offered. Your email address is never shown to other users.
Notification settings and time zone
We store whether you want notifications, which kinds (due reminders, task invitations, someone joining your task), the time of day you want due reminders, and your time zone. The app reads the time zone from your phone (for example “Europe/Warsaw”) so that reminders arrive at your local time; it is not used to locate you.
Push notifications
If you allow notifications, your phone’s operating system and Google’s Firebase Cloud Messaging service give the app a registration token — an address for sending notifications to this app on this phone. The app sends it to our server with your phone’s platform (iOS or Android), and we store it with your account, together with when it was registered, so that reminders reach you. We keep a record of which due date we last reminded you about for each task, so you are reminded only once per due date.
To create the token, the Firebase software in the app generates a Firebase installation identifier and sends it to Google, together with Apple’s push token for the app (on iPhone) and technical information such as the device model, operating-system version, language, time zone, the app’s identifier and version, and the version of the Firebase software. Google uses this information to deliver notifications. A notification we send contains a short message — for example “Change bedsheets is due” or “alice invited you to Change bedsheets” — and the internal identifier of the task, and passes through Google and, on iPhone, Apple’s Push Notification service to reach your phone.
The Firebase software also sends Google diagnostic information about itself — such as its version and the platform it runs on — which Google uses to operate and improve Firebase. According to Google, this information is not linked to your identity, and we do not receive it.
Password recovery
If you ask to reset your password, we email a six-digit code to your account’s email address. We store the code only as a hash, with when it expires (after 15 minutes) and how many attempts are left. It is deleted when it is used, replaced by a newer code, or deleted with your account. The email is sent through our email provider.
Security and server logs
Like any internet service, our server receives your phone’s IP address with each request. Our web server logs each request with the IP address, the time, the address requested (with any text you typed into the task search removed), the response, and the request’s technical headers, such as the app’s user-agent string. Passwords and sign-in tokens are never logged. The application logs errors and security events, identifying accounts by their internal number. To stop password guessing and abuse, the server counts recent sign-in, password-recovery, invitation and password-confirmation attempts per IP address, per identifier or per account; these counters are held only in the server’s memory and last at most an hour. Logs are used for security, troubleshooting and keeping dueby available.
When you contact us
If you email us, we receive your email address and whatever you write, and use them to answer you.
What we do not collect
dueby does not access your location, contacts, photos, camera, microphone, calendars or health data, does not use your phone’s advertising identifier, and contains no advertising software and no analytics software of ours.
What is stored on your phone
- Your sign-in tokens, in the phone’s secure storage (the iOS Keychain or Android Keystore).
- A copy of your account details, tasks and calendar as last received from our server, so that dueby works without a connection. It is deleted when you sign out or delete your account.
- Your theme choice and whether you have seen the app’s introduction.
Deleting the app removes these from the phone. It does not delete your account.
How we use personal data
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account, signing you in, recovering your password | Account details, sign-in sessions, recovery codes | performance of our contract with you (Article 6(1)(b) GDPR) |
| Tracking your tasks, showing what is due, the calendar and shared tasks | Tasks, completions, sharing records, usernames | performance of our contract with you (Article 6(1)(b) GDPR) |
| Sending the notifications you asked for | Notification settings, time zone, registration tokens, task titles | performance of our contract with you (Article 6(1)(b) GDPR) |
| Keeping dueby secure and available, preventing abuse, restoring data after a failure | IP addresses, logs, attempt counters, backups | our legitimate interest in keeping dueby secure and available (Article 6(1)(f) GDPR) |
| Helping you use dueby when you ask us for support | Your email and what you write | performance of our contract with you (Article 6(1)(b) GDPR) |
| Handling requests to exercise your data-protection rights | Your email, what you write, and the data needed to confirm your identity and act on the request | our legal obligation to respond to them (Article 6(1)(c) GDPR) |
| Answering other messages, such as complaints, reports of abuse or security problems, and general questions | Your email and what you write | our legitimate interest in answering you and keeping dueby safe (Article 6(1)(f) GDPR) |
We do not use your data for advertising, marketing, profiling or automated decisions that affect you, and we do not use it to train artificial-intelligence models.
Who else processes your data
We do not sell, rent or trade personal data. It is processed by these service providers, only to run dueby:
- OVHcloud hosts the server on which dueby’s application, database, logs and backups run, in Germany.
- Google (Firebase Cloud Messaging) delivers push notifications, using the data described under Push notifications. See Google’s Firebase privacy information.
- Apple (Apple Push Notification service) carries notifications to iPhones.
- OVHcloud sends password-recovery emails, which involves your email address and the message, and hosts the mailbox that receives the emails you send us.
We use these providers only under terms that require them to protect personal data and to use it only to provide their service to us, giving the same or equivalent protection as this policy. Other dueby users see the information described under Shared tasks only when you share a task with them or accept their invitation. We may disclose personal data if the law requires it, or to protect the rights and safety of our users or others.
International processing
Our server is located in Germany. Google and Apple operate their notification services worldwide, so the data they handle for notifications may be processed in other countries, including the United States. Google LLC is certified under the EU–U.S. Data Privacy Framework, which the European Commission has recognised in an adequacy decision. Where the law requires safeguards for other transfers, they rely on those provided in those companies’ terms, such as the European Commission’s standard contractual clauses.
How long we keep it
- Your account, tasks, completions, shared-task records and settings — until you delete them or your account.
- A task you delete is removed at once, with its history, reminders and sharing.
- Sign-in sessions — until they expire (30 days after last use) or you sign out; ended sessions are cleared the next time you sign in. At most the ten most recent are kept.
- Notification registrations — until you sign out on that phone, turn off its notification permission, the token stops working, or you delete your account. At most twenty per account are kept.
- Password-recovery codes — at most 15 minutes of validity; deleted when used or replaced.
- Server logs — for up to 30 days.
- Backups of the database are taken daily and before each update of the server, and are kept for up to 30 days and then deleted. Data you delete remains in existing backups until they are deleted, and is used only if a backup has to be restored after a failure.
- Emails with us — as long as needed to deal with your request.
Deleting your account
Open Settings → Delete account in the app and confirm with your password. Deletion happens immediately and cannot be undone. It removes your account, your tasks and their history, your notification settings, your sign-in sessions and your phones’ notification registrations, and it signs you out on every device. Specifically, for tasks shared between people:
- tasks you own are deleted for everyone who shares them;
- your membership of tasks other people own, and invitations to you, are removed;
- completions you recorded on another person’s task stay part of that task’s history, but no longer identify you; and changes you made to another person’s task as an editor (such as its title or description) remain part of their task.
After deletion your username and email address can be used for a new account. If you cannot sign in, email support@zygzula.com from your account’s email address and we will delete the account for you.
Security
All communication between the app and our server is encrypted with HTTPS. Passwords and recovery codes are stored only as hashes, sign-in credentials only as digests, and the app keeps its tokens in the phone’s secure storage. Our server accepts connections only through an HTTPS proxy, and the database is not reachable from the internet. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the authorities where the law requires.
Your choices and rights
- Notifications are optional. Turn them, or individual kinds, off in Settings → Notifications, or turn off notification permission in your phone’s settings. Everything else in dueby works without them.
- Your details can be changed in Settings, and your tasks edited or deleted at any time.
- Deletion is available in the app at any time, as described above.
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. To exercise these rights, email support@zygzula.com from the address your account uses; we may need to confirm your identity. We will respond within one month, which the law allows us to extend in some cases; if we do, we will tell you why.
You also have the right to lodge a complaint with a data protection supervisory authority. In Poland, where we are based, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl). You can also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe your rights were infringed.
Children
dueby is not directed at children. You must be at least 16 years old to create an account. If you believe a child under that age has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy when dueby or the law changes. The effective date at the top shows the current version. If a change significantly affects how we use your personal data, we will tell you in the app or by email before it takes effect.
Contact
Szymon Zygzuła, ul. Prezydenta Lecha Kaczyńskiego 24A/90, 80-365 Gdańsk, Poland
Privacy: support@zygzula.com · Support:
support@zygzula.com