Privacy
Last updated 21 August 2026
DueVigil sends payment reminders on your behalf. That means it holds two kinds of data: yours, and that of the people you invoice. This page says exactly what is stored, who else touches it, and how to remove it.
What we store about you
The email address and password you sign up with, handled by our authentication provider. We never see the password itself.
If you sign in with Google instead, Google tells us your email address and your name, and nothing else. Those two are used to create your account and to recognise you when you come back. DueVigil never gets access to your Gmail, your contacts, your calendar, or anything else in your Google account, and it cannot act on your behalf there.
Your business name, reply-to address, default currency, default payment terms, and whether you want the daily digest and weekly summary. That is the whole of your profile.
What we store about the people you invoice
Only what you type in: the client's name, an optional contact person, their email address, and the invoices you record against them — number, amount, currency, issue and due dates, an optional link, and an optional short note that goes into the reminder.
We also keep the notes you write yourself, and any message a recipient leaves when they use the "I already paid" link.
Recipients never have an account and are never asked to make one.
What we keep about the emails
For every reminder: when it was scheduled, when it was sent, and what our email provider reported back — delivered, opened, bounced, or marked as spam.
That record exists for one reason. If reminders start bouncing, sending must stop, both to protect the recipient and to keep the sending domain usable for everyone else on it.
We do not read the contents of your emails, and there is no way to browse them from inside the product.
Your responsibility for recipients
You are responsible for having a genuine business reason to contact the people you add: an invoice you issued to them. DueVigil is not for lists you bought, scraped, or inherited.
Every reminder carries an unsubscribe link that works without logging in. Once someone uses it, DueVigil never emails them again for any invoice, from you or from anyone.
Who else processes it
Supabase stores the database and handles sign-in. Resend sends the email. Vercel runs the site. Sentry receives error reports, configured not to send personal data with them.
Paddle handles payment. They are the seller of record for DueVigil, which means that when you subscribe you are buying from them and they invoice you. Your card details go to Paddle and never reach us: we are told that an account is paid and until when, and nothing more.
Nothing is sold, and nothing is shared with anyone else.
Cookies and tracking
One cookie keeps you signed in, and one remembers which language you chose. Neither follows you anywhere.
There is no analytics, no advertising network, and nothing that tracks you across other websites. The only third-party script anywhere in the product is Paddle's, which loads on the settings page to draw the payment window; it sets its own cookies for the payment and for fraud checks, and it is not loaded on any other page.
Keeping and deleting
Your data stays while your account exists. Ask us to delete the account and everything above goes with it: clients, invoices, reminders, notes and delivery records.
You can also delete individual invoices and archive clients at any time from inside the app.
Questions, or a request to delete your data: hello@duevigil.com. We answer every message ourselves.