Privacy Policy
Effective date: 9 July 2026
This Privacy Policy describes how DUXME (“we”, “us”) processes personal data when you use DUXME (“Service”) at duxme.app.
Data controller: IT-SIMPLE KAJETAN SZYMCZAK, NIP 5272849574
Contact: admin@duxme.app (see §11)
We process data to provide the Service, secure it, and comply with law.
1. Data we collect
Depending on how you use the Service, we may process:
- Account data: email address, username, and authentication identifiers from our auth provider (Supabase). When you sign in with Google, we collect and process specific data from your Google account, including: email address, your unique Google user ID, and profile picture (avatar).
- User Content: maps, places, categories, descriptions, images, and other content you add.
- Usage and technical data: IP address, device/browser type, approximate location derived from IP, timestamps, and similar diagnostics.
- Communications: messages you send us (e.g. support) and, if you opt in, your subscription to newsletters or product updates.
- Payment-related data: when you purchase paid features, Polar processes payment details; we typically receive limited billing metadata (e.g. subscription status, transaction identifiers) rather than full card numbers.
2. How we use data
- Provide, maintain, and improve the Service (including sync, sharing, and search).
- Authenticate you, prevent fraud and abuse, and secure the Service.
- Communicate with you about the Service, security, or legal notices.
- Send marketing or product emails only if you have opted in; you can unsubscribe anytime.
- Analyze usage in aggregated or pseudonymous form to understand product performance.
- Comply with legal obligations and enforce our Terms of Service.
3. Analytics and cookies
We use PostHog for product analytics and error reporting. Our configuration is intended to minimize direct identification: we aim to use anonymous or pseudonymous identifiers rather than tying analytics to your real name or email. Session recording is disabled in our application configuration; if it were enabled in the future, form fields and sign-in widgets (including Google OAuth) would be masked so that tokens and credentials are not captured.
If we change analytics to identify logged-in users by user ID or similar, we will update this Policy accordingly.
The Service may use cookies or local storage for session, preferences, and analytics. You can control cookies through your browser settings; some features may not work without necessary cookies.
4. Google services
Sign in with Google (OAuth)
When you sign in with Google, we request the OAuth scopes: openid, email, and profile. Through these scopes we access: your email address, your unique Google user ID, and your profile picture (avatar).
We use this data solely to authenticate you and create and operate your account in the Service (e.g. user identification, displaying your avatar).
We store it in our database (Supabase) linked to your account for as long as the account is active, and for any period required by law after deletion.
We share it only with subprocessors that help us run the Service (e.g. Supabase — hosting and authentication). We do not sell Google account data or use it for advertising.
Data limitation: we use Google user data only as described in this Policy; we do not use it for purposes not disclosed here.
Google Maps Platform (server-side API)
Map, place search, and import features use Google Maps Platform / Places on the server side (application API key). We do not access your Google account for these features and do not request additional OAuth scopes (e.g. Calendar, Gmail, Drive).
Search queries, place selections, or import data may be sent to Google under Google’s terms. Google processes that data as described in Google’s privacy documentation. We do not control Google’s processing.
Limited Use (Google API Services requirement):
DUXME's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing and subprocessors
We share data with service providers who help us run the Service (“subprocessors”), including:
- Supabase (hosting, database, authentication).
- Polar (payments and billing for paid features).
- Resend or similar providers (transactional and, where applicable, marketing email delivery).
- PostHog (analytics and error reporting).
- Google (OAuth sign-in — scopes
openid,email,profile; server-side Maps Platform / Places). - Hosting and infrastructure providers (e.g. Vercel) where the app is deployed.
6. International transfers
Some subprocessors may process data outside your country (including the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, in addition to provider terms.
7. Retention
We keep data as long as needed to provide the Service and for legitimate purposes (security, legal claims, accounting). You may request deletion of your account and associated personal data subject to legal retention requirements.
8. Your rights
Depending on your location (including the EEA/UK), you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. You may withdraw consent for marketing at any time.
To exercise rights, contact us below. You may also lodge a complaint with your local data protection authority.
9. Children
The Service is not directed at children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal data from children.
10. Changes
We may update this Policy; we will change the effective date above. For material changes, we may provide additional notice (e.g. in-app or by email).
11. Contact
For privacy and data-protection enquiries: admin@duxme.app
For privacy requests, email us from the address associated with your account where possible so we can verify your request.