Skip to content

Security & privacy

Your receivables are your business

Who owes you money, and how much, is sensitive commercial information. Here is exactly what Duebay stores, how it's protected, and what we don't yet offer.

Principles

How Duebay treats your data

Your invoices and contacts are scoped to your account

Invoices, customers, sequences, run logs and settings live in Postgres with Row Level Security on every table, keyed to the account that owns the rows. Another account's data isn't reachable through the app, the API, or a leaked query, because the database itself enforces the boundary.

Reminders carry your identity, and we keep the log

Chasing emails are sent through our email processor (ThreadCamp) with your name and your reply address, so replies go to you, not us. Every send is recorded against its invoice: which step, what text, when. That log is your audit trail in a dispute.

The free tools send us nothing

The late fee calculator, DSO calculator and aging report generator run the engine client-side in your browser. There is no upload request behind them, which you can verify in your network tab. A CSV you test there never reaches our servers.

Statement links are tokenized and read-only

A customer statement page is reachable only by its unguessable token link, shows only that customer's invoices, and can't change anything. Regenerating the link invalidates the old one.

Single-key API auth, revocable any time

The API and MCP server use one bearer key per environment (dc_live_... / dc_test_...). Rotate or revoke a key instantly from your account if it's ever exposed; the key value itself is shown only once, at creation.

Late-fee output is cited, and it is not legal advice

Duebay computes late fees and interest from state statutes and the terms on your invoice, and shows the citation behind every number. It is general information, not legal advice: statutes change and contracts vary, so confirm with counsel before relying on a figure in a dispute. Where a rule could not be verified, Duebay says "verify with counsel" rather than guessing.

What we don't yet offer

  • SOC 2 or similar third-party security certification.
  • Self-hosted or on-premise deployment.
  • SSO/SAML sign-in.

We'd rather say this plainly than let silence imply a posture we haven't earned.

FAQ

Security questions

What data do you store?

Your account details; the invoices and customer contacts you import (amounts, dates, names, billing emails); your sequences and their send log; API usage records (endpoint, timestamp, status) for rate limiting and the inspectable request log; and billing status via Stripe. We store what the product needs to chase invoices and show you the record of it, and nothing speculative.

Do you sell or share my data?

No. We don't sell personal information, run ads, or share your data beyond the processors that operate the service: Supabase (database and auth), ThreadCamp (outbound email), and Stripe (billing), each bound to use it only to provide their service to us.

Who can see my customers' information?

Your account, and that's the design, not a policy promise: Row Level Security scopes every invoice, contact, sequence and log row to the owning account at the database layer.

Is my data encrypted?

All traffic runs over HTTPS/TLS, including API and MCP calls and every email handoff to our processor. Data at rest lives in managed Postgres (Supabase).

Do you have a SOC 2 report?

Not yet, and we'd rather say that plainly than imply a compliance status we haven't earned. If SOC 2 is a hard requirement for you, contact us before importing data that would require one.

Can I delete everything?

Yes. Deleting an invoice or customer removes it and its send history; deleting your account removes your data, except billing records we're legally required to keep. Deletion requests go to the address on the privacy page.

Read the full privacy policy

Details on what we collect, why, and how to delete it.