DueBuddy

← DueBuddy

Security and data

Five questions we get asked most often. We answer directly and without vague statements — including what we don’t have yet.

Where are my documents stored?

On our server in Germany. We do not share files with third parties for marketing and do not sell data. The database and files are stored on the same server, with access via a key.

How long are documents stored?

Processed files are stored while your account history remains active; deletion takes place within 30 days of your request, and backups are cleared within 14 days. You can delete them at any time — by request or from your account.

Who has access to the documents?

What happens when I delete something?

The document and its associated fields are deleted. Resubmitting the same file does not automatically restore it — you need to upload it again.

What about GDPR rights?

We operate in the EU and comply with GDPR: you can request access to, correction of, or deletion of your data. Send requests to [email protected]; we respond within a few business days.

What we access from Gmail

If you connect your email, we request the minimum access necessary:

We do not read personal correspondence. You can revoke access at any time — with one button in your account or in your Google account settings. After revocation, we lose access immediately.

Separately: logging in to your account and connecting your email are different things. You can log in using a link from an email, without Google. Google is only needed to work with your email if you choose to do so.

Who we use (providers)

We do not sell or share your documents with third parties. However, some work is performed by external services — here is the honest list:

Customer documents are not used to train models.

What we don’t have yet

Honestly, so you don’t have to look for this in the contract:

For many accounting firms, this is sufficient. If it isn’t for you, it’s better to find that out now, not after payment.

Two-factor login

Available. After following the link in the email, you can enable a digital code (4–8 digits) — then logging in also requires it. The code is stored only as a hash; after five failed attempts, login is blocked for 15 minutes.

How files are transferred

DueBuddy · duebuddy.work · Reviews

FactsPrivacy Policy · Data Processing Agreement (DPA) · Providers

Email tracking

When a reminder is sent on your behalf, we may be able to see whether the recipient opened the email. This concerns a specific person, so we treat it as personal data:

Access to your email

For reminders to be sent on your behalf, the service connects to your mailbox through Google OAuth. We request the minimum permissions:

We do not read your correspondence. We do not request full mailbox access (mail.google.com). We do not store email contents — only the reminder sending status is saved.

You can disconnect at any time: using the “Disconnect email” toggle in your account and in your Google account settings. After disconnection, the token is invalidated and access ends.

Exactly who receives access to the data and on what grounds is described in the Providers section.

Privacy Policy · Terms · DPA · Providers

Google verification status. The app is going through Google verification. Until it is complete Google may show a "app is not verified" warning — normal for new apps, not a sign of danger. Timelines are set by Google.

Exact Google wording. gmail.send is a sensitive scope, gmail.readonly is a restricted scope. For restricted scopes Google requires a separate security assessment — we are going through it. Until it completes, Google may show an "app is not verified" warning.