Privacy Policy
Effective date: July 7, 2026
This policy explains what information Duebird ("we", "the Service") collects, how it is stored and protected, who it is shared with, and the choices you have. The short version: we collect only what the product needs to work, we never sell your data, and we do not use your data for advertising.
1. Information we collect
Account information. Your name, email address, and password. Passwords are hashed by our authentication provider — we never see or store them in plain text.
Business data you enter. Clients and their contact details, proposals, invoices, recurring schedules, notes, email templates, and follow-up history. This includes personal information about your clients (names, email addresses) that you choose to store. You are responsible for having a lawful basis to store your clients' information.
Usage records.Activity events inside your workspace (for example, "follow-up email sent") that power the activity feed and rate limiting, and standard technical logs (IP address, browser type) kept by our hosting provider for security and debugging.
What we do not collect: we do not process or store payment card details, bank credentials, or client funds, and we do not use advertising trackers or analytics cookies.
2. How your data is stored and protected
- All data is stored in a managed PostgreSQL database (Supabase) and is encrypted at rest and in transit (HTTPS/TLS everywhere, enforced with HTTP Strict Transport Security).
- Every workspace is isolated with database-level row security policies: your data is only readable by members of your workspace, enforced by the database itself, not just the application.
- Authentication is handled by Supabase Auth with secure, HTTP-only session cookies.
- The application enforces rate limiting and input limits to protect against abuse.
No system is perfectly secure, but if we learn of a breach affecting your personal data, we will notify you without undue delay.
3. Services we rely on (subprocessors)
We share data with a small number of service providers, only as needed to run the product:
- Supabase — database and authentication (stores all account and business data).
- Vercel — application hosting and delivery.
- OpenAI— only when you click to generate an AI email draft, the relevant context (client name, invoice or proposal details, your chosen tone) is sent to OpenAI's API to produce the draft. Under OpenAI's API terms, this data is not used to train their models.
- Resend — email delivery, only when you send a follow-up email through the platform.
- Google — only if you explicitly connect your Gmail account for sending (optional feature; see section 4).
We never sell your data to anyone, for any purpose.
4. Google user data (optional Gmail connection)
If you choose to connect a Gmail account, we store the OAuth tokens Google issues so we can send emails on your behalf, and your Gmail address so we can show you which account is connected. We request only the permission to send email (gmail.send) — we cannot read your inbox. Tokens are stored encrypted at rest, are accessible only to your user account, and are deleted when you disconnect Gmail or delete your account.
Duebird's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Cookies
We use only essential cookies: the session cookies required to keep you signed in. We do not use advertising, analytics, or cross-site tracking cookies, which is why you do not see a cookie consent banner.
6. How long we keep data
We keep your data for as long as your account is active. When you delete individual records (clients, invoices, proposals), they are removed from the live database. When your account or workspace is deleted, all associated business data is deleted with it; residual copies in encrypted backups expire on the backup provider's rotation schedule.
7. Your rights and choices
Wherever you are located, we extend the same rights to you:
- Access & portability — export your clients, proposals, and invoices at any time with the built-in CSV export.
- Correction — edit any record directly in the app.
- Deletion — delete individual records in the app, or email us to permanently delete your entire account and workspace. We complete deletion requests within 30 days.
- Objection or complaint — contact us with any concern; if you are in the EU/UK you may also lodge a complaint with your local data protection authority.
For any of these, email karmawk6@gmail.com from the address on your account.
8. Your clients' data
When you store information about your clients in the Service, you are the data controller for that information and we process it on your instructions. If one of your clients asks you to delete their information, you can do so directly in the app; deleting a client removes their contact details from your workspace.
9. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16.
10. Changes to this policy
If we make material changes to this policy, we will update the effective date above and take reasonable steps to notify you before the changes take effect.
11. Contact
Privacy questions or requests: karmawk6@gmail.com. See also our Terms & Conditions.