Privacy policy.
How DueDocs collects, uses, stores, and discloses personal information when you organise documents and create reminders.
Scope and our approach
DueDocs is an individual document-organisation and reminder service. This policy applies to the website, web application, installed progressive web app, and related support communications.
DueDocs is designed to handle documents that may be personal or sensitive. We aim to collect only what is needed to provide the features you choose and to explain where third-party processing occurs.
Information we collect
- Account information: email address, display name, sign-in method, country, timezone, and account-security events.
- Files you provide: receipt images, invoices, IDs, policies, medical documents, and other files you deliberately upload.
- Document information: title, category, collection name, merchant, date, amount, currency, warranty details, notes, and fields you confirm.
- Reminder information: warranty, subscription, renewal, expiry, recurrence, notification timing, and optional related documents.
- AI information: extraction requests, suggested fields, your corrections, provider/model used, processing status, and operational usage information.
- Technical information: IP address, browser/device details, timestamps, request identifiers, security logs, and diagnostic events.
- Billing information: plan and payment status if paid plans are enabled. Payment-card details are handled by the payment provider and are not stored by DueDocs.
Sensitive documents and identifiers
Personal and medical documents may contain sensitive information under applicable privacy law. Only upload a document when you have the right and authority to do so.
When you enter a personal document number during document review, it is masked in your browser before it is ever sent to our servers. Only the masked value (for example, “•••• •••• 4821”) is transmitted and stored; the number you typed is never received by DueDocs in raw form and therefore never appears in stored fields, logs, analytics, or emails. This client-side masking does not apply to the original uploaded file, which may still visibly contain the number and is therefore treated as sensitive.
How we use information
- Authenticate you and secure your account.
- Upload, store, preview, download, organise, search, and export your documents.
- Create and deliver reminders you request.
- Run optional AI extraction after you explicitly select it.
- Present AI suggestions for your review and retain your confirmed corrections.
- Enforce usage limits, prevent fraud or abuse, troubleshoot failures, and maintain service integrity.
- Meet legal obligations and respond to valid legal requests.
We do not sell personal information. We do not use confirmed AI suggestions as tax, legal, medical, accounting, or insurance advice.
AI processing and automated suggestions
AI is optional and user-triggered. When you select AI extraction, the relevant file and extraction instructions are sent to our configured AI provider. DueDocs uses Anthropic as the primary provider and automatically retries with OpenAI as a fallback if the primary provider fails on that request.
AI processing may occur outside your country of residence, including in the United States or other locations used by those providers. Provider location, retention, and data-control terms may change, so their current commercial API privacy terms should also be reviewed.
AI never automatically confirms final document data. Every suggestion is presented for review, and you can edit, reject, or ignore any field and enter information manually instead.
Service providers and disclosure
| Provider type | Purpose | Information involved |
|---|---|---|
| Supabase | Authentication and database | Account details, document metadata, reminders, and access-control records |
| Cloudflare R2 | Private object storage | Original files, thumbnails, temporary exports, and object metadata |
| Anthropic / OpenAI | Optional AI extraction | Files and extraction context submitted when you request AI |
| Vercel | Application hosting | Web requests, operational logs, and application processing |
| Resend | Transactional email | Email address and the content of account or reminder messages |
| Sentry | Error monitoring | Error details, device/browser information, and a short session replay recording when an error occurs (not on ordinary visits) |
| Stripe | Subscription billing | Billing identity, payment status, and payment information handled by Stripe |
We may also disclose information when required by law, to respond to a valid court or regulatory request, to protect people or the service from serious harm, or as part of a business restructure subject to appropriate privacy safeguards.
Storage, access, and cross-border handling
DueDocs currently uses a private Cloudflare R2 bucket configured in the Oceania region for original files. Application hosting, authentication, email, payments, support, and AI providers may process or replicate information in other countries according to their infrastructure and terms.
DueDocs is used from many countries, including Australia, India, the United States, Canada, and the United Kingdom. Wherever you live, your information may be transferred to and processed in countries other than your own, and those countries may provide different privacy protections than your local law.
Files are not publicly accessible. Upload, download, and preview access are all granted only through authenticated, short-lived signed links generated after an ownership check on the requesting account. See our Security page for important limits and technical detail.
Retention and deletion
Documents and confirmed records are retained while your account exists or until you request deletion, subject to plan and legal requirements. Generated exports and abandoned uploads are intended to have shorter retention periods.
DueDocs does not silently delete original files. User-requested destructive deletion requires confirmation. Backups, security logs, billing records, or legally required records may remain for a limited period after account deletion.
Your choices and rights
- Access and correct your account and confirmed document information.
- Choose manual entry instead of AI extraction.
- Download your original files. Self-service export of collection and account data is available on paid plans; free accounts can request a copy of their data at support@duedocs.com and we will provide it within a reasonable period.
- Change or cancel reminders.
- Request deletion of documents or your account, subject to confirmation and legal retention.
- Opt out of non-essential marketing communications if introduced.
Depending on where you live, you may have additional statutory rights — for example under the Australian Privacy Act, the EU/UK GDPR, US state privacy laws such as the California Consumer Privacy Act, Canada’s PIPEDA, or India’s Digital Personal Data Protection Act 2023. Where those laws apply to you, we honour verified requests to access, correct, delete, or port your personal information in accordance with them.
We may need to verify your identity before processing a privacy request.
Cookies and analytics
DueDocs uses essential cookies or local storage for authentication, security, app installation, and preferences. We do not intend to use cross-site advertising trackers. Any product analytics must exclude document contents, unmasked identifiers, API keys, and signed file links.
Children
DueDocs is intended for people aged 18 or over. We do not knowingly provide accounts to children or intentionally collect their information.
Data incidents and complaints
We will investigate suspected privacy or security incidents and provide notifications where required under applicable law, including Australia’s Notifiable Data Breaches scheme, the EU/UK GDPR, and other local breach-notification regimes where they apply.
DueDocs is operated by Consulting Cadets Pty Ltd (ABN 73 683 393 508) of Epping, Victoria, Australia. Privacy questions and complaints can be submitted to support@duedocs.com. We aim to acknowledge complaints within 5 business days and to resolve them within 45 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you live elsewhere, to your local privacy regulator — for example the ICO in the United Kingdom, your EU supervisory authority, the Office of the Privacy Commissioner of Canada, or the Data Protection Board of India.
Changes to this policy
We may update this policy as the product, providers, or law changes. Material changes will be communicated by email or in-app notice before they take effect where appropriate.