Five questions we get asked most often. We answer directly and without vague statements — including what we don’t have yet.
On our server in Germany. We do not share files with third parties for marketing and do not sell data. The database and files are stored on the same server, with access via a key.
Processed files are stored while your account history remains active; deletion takes place within 30 days of your request, and backups are cleared within 14 days. You can delete them at any time — by request or from your account.
The document and its associated fields are deleted. Resubmitting the same file does not automatically restore it — you need to upload it again.
We operate in the EU and comply with GDPR: you can request access to, correction of, or deletion of your data. Send requests to [email protected]; we respond within a few business days.
If you connect your email, we request the minimum access necessary:
We do not read personal correspondence. You can revoke access at any time — with one button in your account or in your Google account settings. After revocation, we lose access immediately.
Separately: logging in to your account and connecting your email are different things. You can log in using a link from an email, without Google. Google is only needed to work with your email if you choose to do so.
We do not sell or share your documents with third parties. However, some work is performed by external services — here is the honest list:
Customer documents are not used to train models.
Honestly, so you don’t have to look for this in the contract:
For many accounting firms, this is sufficient. If it isn’t for you, it’s better to find that out now, not after payment.
Available. After following the link in the email, you can enable a digital code (4–8 digits) — then logging in also requires it. The code is stored only as a hash; after five failed attempts, login is blocked for 15 minutes.
X-Api-Key header; the key can be revoked at any timeDueBuddy · duebuddy.work · Reviews
FactsPrivacy Policy · Data Processing Agreement (DPA) · Providers
When a reminder is sent on your behalf, we may be able to see whether the recipient opened the email. This concerns a specific person, so we treat it as personal data:
For reminders to be sent on your behalf, the service connects to your mailbox through Google OAuth. We request the minimum permissions:
gmail.send) — to send a reminder from your address. This permission is required for reminders to work.gmail.readonly) — optional. This is needed to automatically find supplier invoices in your email. If you do not grant it, you can upload invoices manually; everything else will work.We do not read your correspondence. We do not request full mailbox access (mail.google.com). We do not store email contents — only the reminder sending status is saved.
You can disconnect at any time: using the “Disconnect email” toggle in your account and in your Google account settings. After disconnection, the token is invalidated and access ends.
Exactly who receives access to the data and on what grounds is described in the Providers section.
Privacy Policy · Terms · DPA · Providers
Google verification status. The app is going through Google verification. Until it is complete Google may show a "app is not verified" warning — normal for new apps, not a sign of danger. Timelines are set by Google.
Exact Google wording. gmail.send is a sensitive scope, gmail.readonly is a restricted scope. For restricted scopes Google requires a separate security assessment — we are going through it. Until it completes, Google may show an "app is not verified" warning.