Privacy policy
2026-10-02
This document is not ready to publish: the operator, contact address or governing law has not been configured on this server.
1. What we hold
Your email address, and the settings you choose (time zone, language, notification channel and timing).
For each document: the fields extracted from it — merchant, amount, currency, order reference, purchase date and the deadlines — together with the short quoted passage each date came from, plus the subject line and sender where the document arrived as email.
Where a document arrived as forwarded email, from a connected mailbox or as an uploaded PDF: the full text that was read — the message body, or the text extracted from the PDF — is stored encrypted with that document, so you can check what the system actually read. The PDF file itself is not stored. Entries you type in yourself have no original text.
If you link a messaging account, the identifier that platform gives us so we can send to you. If you connect a mailbox, tokens that allow read-only access, stored encrypted.
For abuse prevention: a one-way hash of the email address and source address used in sign-in and sign-up attempts, kept for a few hours. The addresses themselves are not stored in that record.
2. What we do not do
Mailbox access is read-only: we never send, modify or delete anything in your mailbox.
We do not sell your data, and we do not use the contents of your documents to train models.
3. Why we hold it
To provide the service you asked for: reading your documents, working out the deadlines, and reminding you. Where the law requires a lawful basis, that basis is the performance of our agreement with you, and — for abuse prevention — our legitimate interest in keeping the service usable.
4. Who else processes it
Google, through the Gemini API (extracting fields from document text), Stripe (payments — card details go to Stripe, never to us), Resend (receiving forwarded mail and sending sign-in messages), Telegram or LINE (only if you enable that channel), and Linode (the server itself).
Each of them only receives what that function needs. Our server is located in Singapore.
5. How long
A document — including its original text — and its deadlines are kept until twelve months after its last deadline, then deleted automatically; warranty information is often needed after the warranty itself has expired. Delete a document earlier and it goes immediately.
Deleting your account removes everything associated with it. An audit record that an account was deleted, containing only an identifier and a timestamp, is retained.
6. Your choices
Export everything as a JSON file from your settings at any time. Delete individual documents, or your whole account, yourself.
If you want to ask about any of this — including access, correction or a complaint — write to [contact not configured].
7. Security
Each account's data is isolated at the database level, not only in application code. Mailbox tokens are encrypted at rest. Access to the server is by key only.
No system is perfect. If we discover a breach affecting your data, we will tell you.