Privacy Policy
1. Who we are
Justduedate7 ("Justduedate7", "we", "us") is operated by a sole proprietor based in Israel. Contact: justduedate7@gmail.com.
We are the "controller" (or, under Israeli law, the "database controller") of the personal data described in this policy.
2. What Justduedate7 does
Justduedate7 connects, at your direction, to accounts you choose — such as Gmail, Google Calendar, Microsoft Outlook, ClickUp, Monday.com, Slack and Asana — and shows your emails, events and tasks as one prioritized list, using AI to score what likely needs your attention first.
Providing your information to us is voluntary. You choose which accounts to connect. If you choose not to connect an account, the Service will simply not show items from that source.
3. The data we process
3.1 Account data
When you sign in with Google or Microsoft we receive your name, email address and profile picture. We use this to create and secure your account.
3.2 Connected content — what we access and what we store
When you connect a source, we access it read-only and process:
| Source | What we access | What we store | What we do not store |
|---|---|---|---|
| Gmail / Outlook | Recent message list; subject, sender, date; the body text of a limited number of recent messages, read transiently for AI scoring | Subject, sender, date, a link back to the message, priority score, a short AI-generated reason | The message body. Raw email bodies are not persisted after scoring |
| Google / Outlook Calendar | Upcoming events: title, time, attendees, link | Event title, time, link, score | Full event descriptions beyond what is displayed |
| ClickUp, Monday.com, Slack, Asana | Tasks/items you select: title, due date, status, link | Title, due date, source, link, score | Attachments and full item content beyond what is displayed |
Plain-language summary of our "read-and-discard" approach: we do not persist raw email bodies. Bodies of a limited number of recent emails are read transiently, sent to our AI provider for priority scoring, and discarded after scoring. What remains stored is the metadata listed above and short AI-generated explanations. Because an AI explanation summarises why an item seems urgent, it can reflect information that appeared in the underlying message. We retain these explanations only as described in Section 9.
3.3 OAuth tokens
The access tokens that let us read your connected accounts are stored server-side only, encrypted using Google Cloud KMS. They are never exposed to your browser. We do not store your passwords.
3.4 Payment data
Payments are handled by Paddle, our Merchant of Record. When you subscribe, your purchase is made from Paddle and Paddle processes your payment and billing details as an independent data controller under its own privacy notice (paddle.com/legal/privacy). We do not receive or store your full card details. We receive subscription status, plan and country information needed to operate your account.
3.5 Technical and usage data
Server logs (IP address, timestamps, request outcomes, error events) for security, abuse prevention and reliability. Log content is minimised and we do not intentionally record message content in logs. On our public marketing website we also use Google Analytics 4 for aggregate statistics, loaded only with your consent — see Section 10 and our Cookie Notice.
3.6 Support and communications
Emails you send us, and records of consents and notices (see Section 12).
4. Other people's data in your connected accounts
Your mailbox and calendar naturally contain personal data about other people — senders, recipients, meeting attendees. When you connect an account, we process that data solely to show and prioritize your items. We do not use it to build profiles of those people, do not contact them, do not sell it, and do not use it for advertising or to train AI models. If you are connecting a work account, you are responsible for ensuring you are permitted to do so (see our Terms of Service). Because we have no relationship with these individuals, this policy is our public notice to them; they may exercise the rights in Section 11 against the data we hold.
5. AI processing
- Relevant content (titles, senders, dates, deadlines and, for a limited number of recent emails, transiently read body text) is sent to Google's Gemini API (paid tier) to generate priority scores and short explanations.
- Under the paid tier of the Gemini API, Google does not use these prompts or responses to improve its models. Google may retain prompts/responses for up to 55 days solely for abuse monitoring, where authorised Google staff may review flagged content.
- We do not use your personal data, or any data obtained through connected accounts, to train or develop AI or machine-learning models (including large language models). AI is used for inference only — to score and explain items for you.
- AI outputs are labelled as AI-generated in the product. AI scores can be wrong; the Service is an assistive tool, and you remain responsible for your own deadlines and decisions.
- If AI processing fails or is unavailable, your items are shown without AI prioritization.
More detail: How Our AI Works.
6. Google user data — Limited Use disclosure
The use of information received from Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we only use Google user data to provide and improve the user-facing features of Justduedate7 that are visible in the app; we do not transfer or sell Google user data to third parties such as advertisers, data brokers or information resellers; we do not use Google user data for advertising; we do not allow humans to read your Google user data unless (a) you have given explicit consent to view specific data, (b) it is necessary for security purposes (such as investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymised. We do not retain user data obtained through Google Workspace APIs to develop, improve, or train non-personalized AI and/or machine-learning models.
7. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Provide the Service you signed up for (accounts, sync, dashboard, AI prioritization of your items) | Account data, connected content, tokens | Contract (Art 6(1)(b)) |
| Processing personal data of third parties that appears in your connected content, solely to display and prioritize your items | Connected content | Legitimate interests (Art 6(1)(f)) — assessed in our Legitimate Interests Assessment |
| Billing and subscription management | Subscription status, plan, country | Contract; legal obligations |
| Security, abuse prevention, incident response | Technical data, tokens, logs | Legitimate interests |
| Service emails (receipts, trial reminders, renewal notices, security and service notices) | Account data | Contract; legal obligations |
| Marketing emails (optional) | Email address | Consent (opt-in); you can withdraw at any time |
| Legal compliance and defence of claims | As required | Legal obligation; legitimate interests |
Under Israeli law (Privacy Protection Law 5741-1981), the notice required by section 11 is given in Sections 1–6 of this policy: provision of data is voluntary; the purposes and recipients are described here; and your rights of access and correction are described in Section 11.
We do not intentionally collect special-category (sensitive) data. Connected content may incidentally include sensitive information contained in your own correspondence; we minimise its persistence as described above, do not use it to infer characteristics about anyone, and do not use it for any purpose other than showing and prioritizing your items.
8. Who receives data
- Google Cloud / Firebase (Google LLC and affiliates) — hosting, authentication, database, encryption and AI (Gemini API), as our processor under the Google Cloud Data Processing Addendum. Google's subprocessors: firebase.google.com/terms/subprocessors and cloud.google.com/terms/subprocessors
- Paddle — Merchant of Record for payments, an independent controller (Section 3.4)
- Connected source providers (Google, Microsoft, ClickUp, Monday.com, Slack, Asana) — we call their APIs at your direction; your relationship with them is governed by their terms
- Professional advisers and authorities — where required by law, to protect rights, or in connection with a business transfer (in which case this policy's protections continue to apply and, for Google Workspace data, any transfer will comply with Google's Limited Use requirements)
We do not sell personal data. We do not share personal data for advertising. We have not sold or shared personal data in the preceding 12 months.
A current list of our subprocessors is published at Subprocessors.
9. Retention
| Data | Retention |
|---|---|
| Account data | While your account is active; deleted within 30 days of account deletion |
| Stored item metadata and scores | While the source is connected; refreshed on each sync; deleted when you disconnect the source or delete your account |
| AI-generated explanations | Up to 30 days |
| Transient email bodies | Not stored; discarded after scoring |
| OAuth tokens | Until you disconnect the source or delete your account, then deleted and revoked (see Section 10) |
| Consent, acceptance and billing records | 7 years, to comply with legal obligations and defend claims |
| Server logs | 90 days |
| Backups | Purged on Google Cloud's deletion cycle (up to 180 days) |
10. Disconnecting and deleting
- Disconnect a source at any time in the app; we stop syncing it and delete its stored items and token. You can also revoke our access from the provider's side (e.g. myaccount.google.com/permissions).
- Delete your account by emailing justduedate7@gmail.com. We delete your data and revoke provider access where the provider supports revocation. For providers without a revocation API, we delete our stored tokens and data, and recommend you also remove Justduedate7's access in that provider's settings.
- Step-by-step guide: Managing & Deleting Your Data.
11. Your rights
Depending on where you live, you have rights to access, correct, delete, export, restrict or object to our processing of your personal data, and to withdraw consent. Under Israeli law you have rights to access and correct your data. California residents: Section 14. We do not discriminate against you for exercising rights.
To exercise rights, email justduedate7@gmail.com. We will verify your request (normally by confirming control of your account email) and respond within the time required by law (one month under GDPR/UK GDPR, extendable as permitted). If you are an EU/UK resident you may complain to your supervisory authority (for the UK: the ICO, ico.org.uk); in Israel, to the Privacy Protection Authority. UK users may also use our complaints procedure: email justduedate7@gmail.com with the subject "Privacy complaint" — we acknowledge within 30 days and respond without undue delay.
12. Consent and acceptance records
We keep records of your acceptance of the Terms, your privacy notices, per-integration connection consents, and any marketing opt-in (version, timestamp, method). We keep only what is needed to evidence the consent.
13. International transfers
We operate from Israel. Israel benefits from a European Commission adequacy decision, so personal data may flow from the EEA/UK to us without additional safeguards; we comply with the Israeli regulations applying to EEA-origin data. Our processors are in the United States and elsewhere: Google processes data in the US (Firebase Authentication data is processed exclusively in US data centres) and globally, under the EU–US Data Privacy Framework and/or Standard Contractual Clauses incorporated in the Google Cloud Data Processing Addendum. Our primary database region is London (europe-west2), in the EU. Transfers from Israel abroad are made under the safeguards permitted by the Israeli Privacy Protection (Transfer of Data Abroad) Regulations 5761-2001 (contractual undertakings from our processors).
14. California disclosures (CalOPPA)
Categories of personal information collected: identifiers (name, email); internet/electronic activity (metadata of connected items, logs); commercial information (subscription status); inferences limited to item priority scores. Categories of third parties with whom shared: our processors (Google) and payment provider (Paddle), as described in Section 8. We do not sell personal information. You may review and request changes to your personal information as described in Section 11. We notify users of material changes as described in Section 16. Do Not Track: our Service does not currently respond to browser Do Not Track signals. This policy's effective date appears at the top.
15. Children
The Service is for adults (18+) and is not directed at children. We do not knowingly collect data from anyone under 18. If we learn we hold such data, we delete it.
16. Changes to this policy
We will post updates here with a new effective date. For material changes we will notify you (email or in-app) before they take effect and, where required, ask for renewed acceptance or consent. Prior versions are available on request.
17. Security
Measures include: server-side-only OAuth tokens encrypted with Google Cloud KMS; database rules denying client access to token and internal collections; TLS in transit; least-privilege access (a single-operator team); and incident logging. No internet service can promise perfect security; Section 11 explains how to reach us, and we maintain an incident-response procedure including notification of authorities and affected users where required by law.
Justduedate7