Skip to content

Legal

Privacy Policy

Last updated 2026-09-20

This policy describes how Duebay ("we", "us") collects, uses and protects information when you use our website, API and MCP server (the "Service"). Duebay tracks the invoices you import, computes aging and late fees, and sends reminder emails you configure. It is not a law firm, a collections agency or a lender, and provides no legal advice.

A note about your customers' information

When you import invoices, you give us personal information about people who are not our users: your customers' names, billing email addresses and balances. We process that data only on your instructions, to show you your receivables and to send the reminders you configure, under terms that bind us to that purpose. We never contact your customers for our own purposes, never use their details for marketing, and never sell them. Statement pages are read-only and reachable only by their tokenized link.

Information we collect

  • Account information: your name, email address and password (or sign-in provider identifier) when you create an account.
  • Invoice and customer data: the invoices you import (numbers, amounts, dates, status) and the customer contacts attached to them (names, billing emails), stored until you delete them.
  • Sequence activity: which reminder steps were sent for which invoice, when, and with what content, the send log that serves as your audit trail.
  • API usage data: for calls made with your key, the endpoint, timestamp and response status, used for rate limiting, billing and the inspectable request log. The key value itself is shown only once, at creation, and can be rotated or revoked at any time.
  • Billing information: if you subscribe to a paid plan, payment is processed by Stripe; we store your plan, billing status and Stripe customer reference, never your full card number.

The free tools (late fee calculator, DSO calculator, aging report generator) run in your browser and send us nothing, not even the CSV you test with.

How we use your information

  • To operate the Service: compute aging, DSO and late fees, run your reminder sequences, enforce API rate limits and monthly allowances.
  • To send the reminder emails you configure, through our email processor, with your reply address.
  • To send account and billing notifications (a password reset, a receipt).
  • To process payments via Stripe and meter usage-based API overage.
  • To diagnose and fix bugs, and to keep the Service secure and prevent abuse, including by automated or agent traffic.

We do not sell personal information, and we do not use your invoice or customer data to train models.

Data storage & security

Your data is stored in Supabase (managed Postgres), with every table protected by Row Level Security scoping rows to the account that owns them, and access otherwise restricted to what is needed to operate the Service. All traffic uses transport encryption (HTTPS/TLS). See the security page for the fuller picture, including what we do not yet offer.

Data retention & your choices

You can delete an invoice or a customer (which removes its send history), revoke an API key, or delete your account at any time. If you close your account, we honor deletion requests and remove your account, invoice and contact data within a reasonable period, except where we're required to retain billing records for tax or legal purposes.

Cookies & analytics

We use a small number of cookies required to keep you signed in. There is no advertising tracker and no session recording on this site.

Third parties

We share data with the vendors that operate the Service on our behalf: Supabase (database, auth and storage), ThreadCamp (outbound reminder and account email), and Stripe (billing), each bound to use it only to provide their service to us.

Children

The Service is intended for businesses and the people and agents working on their behalf, and is not directed to, or knowingly used by, children under 16.

Changes to this policy

If we make a material change to this policy, we'll update the date above and, where appropriate, notify you by email.

Contact

Questions about this policy or your data, including requests to access, export or delete it, can be sent to [email protected].

For how the data is actually held and what we do and don't have access to, see the security page.