Dueo information
Privacy policy
Dueo helps two people plan commitments, record payments and save toward goals. This policy covers the Dueo iOS and Android apps and these information pages. Dueo is operated by Ngonidzashe Mangudya. For privacy questions, contact ngmangudya@codecraftsolutions.co.za.
Information you choose to share
- Your account: your Apple or Google account identifier and the display name used in Dueo. The provider sends sign-in credentials so we can verify your identity. Dueo does not receive your Apple or Google password.
- Your space: names, commitments, dates, amounts, categories, notes, payment records, income, goals and contributions you enter. Dueo does not connect to your bank or make payments on your behalf.
- Receipts: images or documents you choose to attach. Camera and photo access are used when you choose those features.
- Reminders: if you enable notifications, a device delivery token, platform, timezone and reminder preferences. Notifications can contain commitment information and may appear on your lock screen.
- Support: the contact details and information you include when you ask for help. Please do not send passwords, sign-in codes or unnecessary financial documents.
How Dueo uses this information
We use it to authenticate you, keep your plans available across devices, share your space with the partner you invite, calculate planning totals, deliver requested reminders and respond to support requests. Session and request records also prevent replayed requests, duplicate payments and unauthorized access.
Dueo does not sell your personal information or use it for advertising. We do not use your information to track you across other companies' apps and websites. The sign-in and notification SDKs process information for their own service analytics as described below. These information pages use no tracking scripts or cookies.
Optional AI assistance
When you request a category suggestion, Dueo tries the phone's on-device intelligence when available (Apple Intelligence or Android's Gemini Nano). If it is unavailable, fails, or cannot return a valid suggestion, Dueo sends the entry title and a short note hint to Cloudflare Workers AI. Spend insights use category-level amounts and calendar months rather than transaction titles or notes. Receipt reading uses Cloudflare Workers AI.
When Automatic processing falls back to Cloudflare Workers AI for a financial or goal draft, Dueo sends the user-authored source text, which may include proposed amounts and dates. It also sends the task type, financial kind when relevant, locale, time zone and the date used to interpret the request. It does not send your account, space, membership, request or draft identifiers, or existing ledger records, to the model for these drafts.
Goal assistance is deterministic. It is calculated on your device when available, or by Dueo's Worker from the authorized saved goal and contribution records; the Worker does not send that information to an AI model. Local-only processing does not send a new inference request to Dueo's Worker or Cloudflare Workers AI.
AI suggestions do not change your financial records until you review and accept them. You do not need a personal AI account or API key. Dueo does not log plaintext AI prompts or results.
Your partner and service providers
The other member of your space can view the information and receipts in that space. Dueo does not require you to share a bank account or live together. Only share information you intend your partner to see.
Cloudflare hosts the API, database and private receipt storage. Cloudflare Workers AI processes the draft source text described above and, when you choose to read a receipt, its image or document text. Receipt reading can suggest a merchant, total, currency and date. We store receipt suggestions with the receipt. They can be inaccurate: review them before saving a payment. Reading a receipt never records a payment automatically.
Apple and Google provide sign-in; Google Firebase Cloud Messaging and Apple's push service deliver notifications when enabled. These providers process the information needed to provide their services and may process it outside your country. Their policies are available from Cloudflare, Apple and Google.
Google's sign-in SDK declares collection of account and contact information, including name, email address and phone number; approximate location; user and device identifiers; and service usage information. Google uses this information for sign-in functionality and, for some data types, service analytics. Dueo's account database stores the provider's account identifier and your display name; it does not store your Google phone number or location.
Firebase's notification SDK processes delivery identifiers and device and diagnostic information for message delivery and service analytics. Dueo does not include Google Analytics or Crashlytics. Notification registration is enabled when you choose reminders; your device token is linked to your Dueo account so we can deliver your reminders.
We use Sentry to diagnose application, API and owner-console failures. Reports include error types, code locations, app versions and operating-system details. We exclude account identity, request bodies, financial records, session tokens, screenshots and session recordings from these reports. We use this information to investigate crashes and improve reliability.
Hosting infrastructure processes request information, such as IP addresses, request times and service errors, for delivery, reliability and security. We may also disclose information when required by applicable law.
Storage and account deletion
Account and space records remain while they are needed to provide your account and shared space. The app keeps session credentials, cached plans and pending requests in platform secure storage. API connections use HTTPS and receipt access requires an authorized account. Apple refresh credentials are encrypted before database storage.
For a server-processed typed task, Dueo keeps the validated result encrypted for 24 hours from execution so the same request can be returned safely without another model call or calculation. It keeps task identity and status metadata needed for deduplication and cancellation for seven days, without the source text or plaintext result. Deleting the related account or space also deletes these task records.
Deleting your account removes your account profile, provider identity links, active sessions, membership and notification registrations. Apple access is revoked as part of deletion. Your partner retains the shared space, including its names, financial records, notes and receipts, while they remain a member. Deleting your account does not delete your partner's shared records.
When no member remains, the space and database receipt records are deleted. Private receipt files are queued for deletion, with retries if storage is temporarily unavailable. Expired sign-in challenges and deletion acknowledgments are cleaned up periodically. Session-token hashes are retained to prevent revoked credentials from being reused. Provider backups and security logs may remain subject to the hosting provider's retention practices.
Your choices
You can edit plans, leave your space, turn reminders off, revoke camera or photo permissions in device settings, or delete your account in Dueo. Uninstalling the app does not delete your account. For deletion instructions or a request without the app, visit Delete your account.
You can contact us to request access, correction or deletion of personal information, or raise a privacy concern. We will verify ownership before making account changes. This policy will be updated here when Dueo's data practices change.
