Due Privacy Policy

Contents

Version 2026.1 — Effective 9 October 2026 Replaces the Privacy Policy dated 21 January 2021.

The short version

  • Your reminders and timers stay on your device. We do not have a copy and cannot read them.
  • If you turn on sync, they go to your own iCloud or Dropbox account — not to us.
  • We collect usage statistics to understand which features get used and to fix bugs. They carry a device identifier and are never linked to your name, email address or any account. No reminder content. We switch off precise location, carrier and advertising identifier collection at the source, and do not store your IP address with them.
  • You can turn analytics off. Nothing else in the App changes when you do.
  • Like any website, our servers record the IP address of each request they receive, for a limited time. Section 9 explains what is kept and for how long.
  • We do not sell your data, we do not show advertisements, and we do not track you across other apps or websites.

If you use a version of Due earlier than 26.5. This policy describes Due 26.5 and later. Earlier versions differ in three ways: they have no Share Analytics switch; their usage statistics go to Amplitude only, which works out an approximate country from the network address they arrive from, instead of receiving your time zone; and the support email they pre-fill lists your purchase dates in full instead of a short status code. Updating to 26.5 removes these differences.

The rest of this document is the detail behind those statements.

1. Who we are

Due Pte. Ltd., 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051, is the controller of the personal data described here.

Contact: privacy@dueapp.com

This policy covers the Due app for iPhone, iPad, Mac and Apple Watch, including its widgets, extensions and companion features (the "App"), and the website at www.dueapp.com.

2. Your reminders and timers

Everything you create in Due — titles, notes, times, recurrence, completion history — is stored on your device. We do not operate a service that holds your reminders, and we have no way to read them. Due passes a copy to your Apple Watch directly from your iPhone; that transfer is between your own devices.

If you allow Due to access your Contacts, Calendars or Reminders, it uses that access on your device only — for example, to create a birthday reminder from a contact you pick. Nothing read from them is sent to us.

If you turn on synchronization, your data is copied to the service you choose:

ServiceWhere your data goesGoverned by
iCloudYour own iCloud account, in Apple's private databaseApple's Privacy Policy and Terms
DropboxYour own Dropbox account, in the "Apps/Due App" folderDropbox's Privacy Policy and Terms
No syncNowhere — the device only—

In both cases the data sits in your account with that provider. Due does not hold the credentials to it and does not receive a copy. Due does not add encryption of its own to the synced copy; it is protected by that provider's security. If you do not accept those providers' terms, do not enable sync.

Sharing a reminder as a link. If you use Due's share feature to send a reminder as a web link, the reminder's title, due date and time, repeat rule and time zone are carried inside the link itself, and some links also carry your language and the date written out in it. When the recipient opens a link at the add.dueapp.com address, our web server necessarily receives those values as part of the request, because it needs them to draw the page.

We do not retain them. The page is generated and the request is discarded. Nothing is written to a database, and our web server is configured not to record the address of the request — only the page that was asked for — in its access logs. We do not use the contents for any purpose beyond drawing that page.

Two honest qualifications. If the server logs a diagnostic error while handling a request, that entry can include the full address, including the title; those diagnostic logs are kept on the server for up to about three weeks. And full-disk backups of our server are retained for up to two weeks, so a log entry may persist in a backup image until it expires.

Link previews. When you paste one of these links into a messaging app, that app shows a preview card with the reminder and its due date. That preview is not produced by us: the messaging service's own servers fetch the link and read the description out of the page. This means the reminder's title is disclosed to that messaging service — Apple, Meta, Slack or whoever operates it — and may be cached on their systems under their own privacy policies. This is how link previews work everywhere on the web, and we cannot switch it off from our side.

They do, however, leave your device, and anyone holding the link can read them — so share links deliberately, as you would any message containing the same words. Links using the due:// scheme are handled entirely on your device, generate no preview, and never reach us or anyone else at all.

3. Usage analytics

We collect usage statistics to understand how Due is used — which features people reach for, which they never find, and where the App is going wrong.

These are sent to our own server in Germany and to Amplitude (Amplitude, Inc.), an analytics provider that processes them on our behalf under its own privacy terms.

These are the only usage statistics Due collects. There is no advertising network, no third-party crash reporter, and no other analytics service in the App. Due's widgets, Apple Watch app and extensions send no statistics of their own.

What we deliberately do not collect

We switch these off in the analytics software:

  • IP address — not stored with your usage statistics.
  • Precise location (latitude/longitude), city and region
  • Mobile carrier
  • Advertising identifier (IDFA) and vendor identifier (IDFV)

We also enable Amplitude's COPPA control, which suppresses these categories as well.

What we do collect

  • A device identifier created by the analytics software. It is not your Apple ID or your device's serial number.
  • Which features of the App you use, and when. We record that a feature was used, never what your reminders or timers say: no titles, no notes, no dates.
  • Your app settings — for example your theme and snooze preferences — and simple counts, such as how many reminders and timers you have.
  • Purchase status — whether an Upgrade Pass is active, the dates of your purchases and when a pass ends, the version of Due first purchased, how many in-app purchases have been made and, if you leave a tip, which of the three tips you chose. This describes the purchase, not you, and never includes payment details, prices or transaction numbers.
  • Diagnostic and performance information — app version, operating system version, device model, language and region settings, counters we use to chase specific bugs, and technical error messages, which can occasionally include the name of a file.
  • Your device's time zone setting.

We never send reminder or timer content to Amplitude or to our own server. Where an internal identifier for a reminder appears, it is a random UUID that means nothing outside your own database.

Turning it off

  • iPhone, iPad: in Due, go to Settings → Privacy → Share Analytics
  • Mac: in Due, go to Settings → General → Share Analytics

Analytics is on unless you turn it off. Turning it off stops collection immediately and discards the device identifier described above; if you later turn analytics back on, a new one is created. Statistics recorded on your device but not yet uploaded when you turn it off stay on the device and are not uploaded while analytics is off. No feature of the App depends on it.

What this corresponds to in Apple's terms

The App's privacy manifests declare seven categories — Coarse Location, Product Interaction, Other Usage Data, Purchase History, Device ID, Performance Data and Other Diagnostic Data — all of them not linked to your identity and not used for tracking.

4. Our notification service

We run a small notification service at api.dueapp.com. The App uses it in two situations:

  • Background sync for Dropbox. If you sync with Dropbox and turn on Background Sync, the service wakes your other devices when you make a change.
  • Actions outside the App on iPhone and iPad. When you mark a reminder done from a widget, or add or complete one through Siri or Shortcuts, the App asks the service to wake Due on the same device so that the change is saved and synced. This applies whichever sync option you use.

If you use Due for Mac with iCloud or without sync, the App never contacts this service.

No reminder or timer content is sent to this server, ever. The notifications it sends contain no content, only a signal telling Due to sync.

It receives:

  • your device's Apple Push Notification token — an address Apple issues for delivering notifications to that one app on that one device;
  • for Dropbox sync only, a scrambled identifier for your Dropbox account. It lets the server recognize that two devices belong to the same person, and cannot be turned back into your Dropbox identity;
  • your platform (iOS or Mac) and the kind of build.

For Dropbox background sync, the service keeps the push token and the scrambled identifier so that it knows which devices to wake. That record is deleted when you unlink Dropbox, when Apple tells us the device no longer accepts notifications, and in any case automatically after 365 days in which the device has not contacted the service.

We cannot find this record from an email. It holds a push token and a scrambled identifier — deliberately nothing that identifies a person — so if you write to us asking us to delete "my" record, we have no way to tell which one is yours. The reason we cannot answer the question is the same reason the record reveals so little about you.

The two routes that do work:

  • Unlink Dropbox in the App, which has the record deleted.
  • Do nothing. It is deleted automatically after 365 days without the device contacting the service.

5. Purchases

Where you buy through Apple — an Upgrade Pass or a tip — the purchase is handled by Apple. We never see your payment details.

The App Store receipt is read and validated on your device. It is not uploaded to us. On the Setapp version of Due for Mac there is no in-app purchase at all — access comes with your Setapp subscription.

Refunds and billing. Apple handles all payment, billing and refunds for App Store purchases; Setapp does the same for Setapp subscriptions. Please take any refund or billing question directly to them — we cannot access, change or refund a purchase, and there is nothing you need to send us.

6. Support and diagnostic logs

If you email us for help, we receive whatever you send: your email address, your message, and any attachment.

When you start an email to us from inside Due, it is pre-filled with technical details to help us answer: the app version, your device model, operating system version, language, time zone, your app settings, and a short code describing your purchase status. You can read and delete any of it before you send.

Due can produce a diagnostic log to help us investigate a problem. The log is never sent automatically. It is created only when you ask for it, and it is placed in an email, or saved as a file, that you review and send yourself.

Please know what a log contains. To make bug reports readable we mask reminder titles, but the masking is partial: a long title appears as its first and last few characters, and a title of eight characters or fewer appears in full. A log therefore may contain fragments of your reminders, and short reminders in their entirety. Read a log before you send it, and redact anything you would rather we not see.

Support correspondence is ordinary email, held in our email system. We keep it for as long as needed to resolve the issue and to handle any follow-up.

7. If you use Due through Setapp

Setapp is operated by MacPaw Way Ltd. (Republic of Cyprus). In data protection terms, Due and Setapp are two separate, independent controllers — neither processes personal data on the other's behalf.

  • Your Setapp account, subscription and billing are Setapp's, governed by Setapp's own Privacy Notice. We have no access to them.
  • Setapp collects its own usage information about the apps in its catalog, including through software it supplies for inclusion in the Setapp version of Due, under its own notice and outside our control.
  • Everything described in this policy about how Due handles data applies to the Setapp version too.

The App does not use Setapp's AI Gateway or any other artificial intelligence service, and sends nothing to any AI model provider.

8. Website and newsletter

The www.dueapp.com website and its help center are separate from the App.

Newsletter. There is a sign-up form on our blog. If you use it, we collect the email address you give us and use it only to send the newsletter. The list is held by Mailchimp (Intuit Inc.), who send it on our behalf under their own privacy terms. Every email carries an unsubscribe link, and you may also write to privacy@dueapp.com to be removed.

Website analytics. Our website does not use any analytics service. Our web server keeps logs of the requests it receives; section 9 describes them.

Embedded content. Some pages include content served by other companies: product videos from YouTube (Google) and Vimeo, and a banner from Setapp. When a page containing them loads, your browser connects to those companies, which receive your IP address and may set cookies under their own privacy policies.

Help center. Our help articles are hosted by Zendesk. Reading them requires no account and we do not ask you to identify yourself.

9. Web server logs

Like any web server, ours keeps a log of the requests it receives — from visitors to our website, and from the App when it contacts our servers.

Each entry records the IP address the request came from, the date and time, the page that was asked for, the page you came from, and the type of browser or device. An IP address is personal data, so we are telling you plainly that we hold it, for the period set out in section 14. On our website, an entry also includes any campaign tags in the link you arrived by and, if you use the site's search box, what you searched for.

These logs exist to keep the servers running and to defend them against abuse. We do not use them to build a profile of you, and we do not combine them with anything else.

10. When we may have to share information

We do not sell your information, and we do not share it for advertising. There are three narrow situations in which it may leave us.

Service providers. The companies named in this policy — Amplitude for analytics, Backblaze for encrypted server backups, Zendesk for our help center, Mailchimp for the newsletter — process data on our behalf, only to do the job we engaged them for, and under their own obligations to us.

If the law requires it. We may disclose information if we are legally obliged to: a valid order from a court or public authority, or where disclosure is necessary to comply with a legal obligation, to establish or defend a legal claim, or to protect someone's safety.

In practice there is very little to give. We do not hold your reminders. The records we do keep carry no name, email address or account. Server logs hold IP addresses, which could in principle be matched against records held by someone else, such as an internet provider — but we hold nothing to link one to a person ourselves, and the logs are short-lived. The exception is support correspondence, which you sent us from your own email address and which we can therefore locate. Where we are permitted to tell you about such a request, we will.

If the business changes hands. If Due Pte. Ltd. is involved in a merger, acquisition or sale of assets, information may transfer to the buyer as part of it. We would give notice before that happened, and the data would remain subject to a policy no less protective than this one.

11. Security

We take appropriate technical measures to protect the information we hold.

  • Everything the App sends to us and to our service providers travels over encrypted connections (HTTPS/TLS).
  • Our servers are access-controlled, kept patched, monitored, and rate-limited against abuse. Backups are encrypted.
  • The design does most of the work: your reminders never reach us, and the records we do keep — an analytics identifier, a push token, a scrambled account identifier, and short-lived server logs — are deliberately not linked to your identity, so there is little of consequence to lose.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we ever become aware of a breach affecting your personal data, we will act on it and notify you and the relevant authority where the law requires.

WhatWhy we may process it
Operating the App on your devicePerformance of our contract with you (Art. 6(1)(b) GDPR)
Notification service recordsPerformance of our contract — you asked for the feature
Usage analyticsOur legitimate interest in understanding and improving the App (Art. 6(1)(f)), balanced by the data-minimising measures in section 3 and the opt-out
Web server logsOur legitimate interest in keeping our servers running and secure (Art. 6(1)(f))
Support correspondence and logsPerformance of our contract, and your consent when you choose to send a log
NewsletterYour consent (Art. 6(1)(a)), withdrawable at any time

13. Your rights

You may ask us to give you a copy of, correct, or delete the personal data we hold about you; to restrict or object to our processing; and to withdraw consent where we rely on it. Write to privacy@dueapp.com.

Where we cannot identify you, and what to do instead. In practice we hold very little, and what we do hold is deliberately not tied to your identity: an analytics identifier, a push token and a scrambled account identifier if you use Dropbox background sync, and server logs keyed only by IP address. None of it carries your name, your email address or your account.

That means we usually cannot locate "your" data from an email, because there is nothing in it to match you against. Data protection law recognizes this situation: where a controller genuinely cannot identify the person behind a record, it is not required to acquire extra information purely to be able to, and the access and erasure rights do not apply to that record unless you can supply something that identifies it. We would rather tell you this plainly than imply a search we cannot perform.

You are not left without a remedy. Both records are under your control from inside the App, which holds the identifiers we lack:

WhatHow to deal with it yourself
Analytics identifierTurn Share Analytics off. Collection stops and the identifier is discarded.
Background sync recordUnlink Dropbox, which has the record deleted. It also expires by itself after 365 days.

The analytics identifier is not connected to you or to any account. Statistics recorded under it are deleted after 18 months, as section 14 sets out.

If you believe we hold something about you that is identifiable — support correspondence, for example, which does carry your email address — write to privacy@dueapp.com and we will act on it in the ordinary way.

What happens in our backups. When we delete something at your request, it goes from the live system straight away. Encrypted backup images taken before then still contain it until they are replaced on our schedule, which takes up to about 120 days. During that time the data is put beyond use: it is not read, not used for any purpose, and the backup exists only to restore the service after a failure.

Your reminders are not ours to produce or delete: they are on your device and in your own iCloud or Dropbox account.

No automated decision-making. We do not make decisions about you by automated means, and we do not profile you. Nothing in Due scores, ranks or categorizes people.

If you are in the EEA or UK you may also complain to your local data protection authority — you do not have to come to us first, though we would rather you did.

14. Retention

  • Analytics: usage statistics carry an identifier that is not connected to you or to any account — not to you, and not to us either. Amplitude deletes them after 18 months under its retention settings. Where they pass through our own server, the submissions as received are kept there for 90 days, and the processed form for 18 months. Turning Share Analytics off stops collection; it does not erase statistics already collected, which remain under an identifier that is no longer connected to anything.
  • Notification service records: the device record is deleted when you unlink Dropbox, when Apple reports the device no longer accepts notifications, or automatically after 365 days of inactivity.
  • Web server logs: for our own services, kept on the server for up to about three weeks, and able to persist in a full-disk backup image for up to two weeks longer — so gone within six weeks at most.
  • Backups: we take encrypted backups of our servers, stored with Backblaze (Backblaze, Inc., United States). A record deleted from the live system stays inside those backup images until they are replaced on schedule. We keep three months of backup history, and the second, tamper-proof copy is reconciled monthly, so a deleted record is gone from every copy within about 120 days. For as long as it remains in a backup it is put beyond use: never read, never used for any purpose, and held only so that the service can be restored after a failure.
  • Support correspondence: kept in our email system, and not deleted on a schedule. This is the one thing here that does identify you, because you wrote to us from your own address — so it is also the one thing we can find and remove on request. Write to privacy@dueapp.com and we will delete it.
  • Your reminders: kept by you, for as long as you keep them.

15. International transfers

We are based in Singapore. Our own server — the notification service and the analytics server — is located in Nuremberg, Germany, within the European Union. Our encrypted server backups are stored with Backblaze in the United States. The service providers named in this policy operate in other countries, including the United States, so the data they handle for us is transferred there.

16. Children

Due is not directed at children under 13 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, write to privacy@dueapp.com and we will delete it.

17. Changes

We may update this policy. The version number and effective date at the top change with it, and where a change is material we will give reasonable notice — which may include asking you to review it in the App.

18. Contact

Due Pte. Ltd. 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 privacy@dueapp.com

The English text of this policy prevails over any translation.