Know What’s Due

Privacy

Last updated September 20, 2026

Dates, not documents

Know What’s Due is built to remember when something needs attention. It is not a place to keep the document itself.

There is no field anywhere in this product for a document scan, a passport or licence number, an account or policy number, a card number, a government identifier, or a medical record. Nothing uploads files. If you want to record something sensitive, this is not the right place for it.

What is stored

For each thing you track, the product stores:

  • the name you gave it — for example “Passport”
  • the date it is next due
  • how often it comes round, if you said it repeats
  • how many days ahead you want it to appear in What’s Due
  • the date you last marked it done, once you have
  • an optional short note
  • whether it is active, completed or archived, and when the record was created and last changed

There are no categories and nothing to classify. A thing is a name, a date, and optionally how often it comes round.

For your account, the product stores the email address and password credential held by our authentication provider, and your time zone — which is used to work out what “today” and “overdue” mean for you rather than for the server.

The name and note fields are free text, so it is possible to type something sensitive into them. Please don’t. They are capped at 120 and 500 characters and are meant for things like “Passport” and “renew online, takes 6 weeks”.

Who can see it

Your records are yours. Every query runs as your own account and the database refuses rows belonging to anyone else, enforced by row level security in Postgres rather than only by application code.

Nothing you track is shared with other users, sold, or used for advertising. There is no advertising in this product.

Connected apps

You can connect another application — an AI assistant, for example — so it can manage your list on your behalf. Connecting one uses OAuth: you are shown exactly what the app will be able to do, and nothing happens unless you approve it.

A connected app acts only as you, reaches only your own records, and is subject to the same database rules you are. It can add, change, complete and archive items. It cannot permanently delete anything — the connector interface archives instead, so the record survives.

Once you approve a connection, whatever that app does with the information it reads is governed by that app’s own privacy policy, not this one.

Service providers

Account authentication and data storage are provided by Supabase. Hosting is provided by Vercel. Both process data on our behalf in order to run the product.

Deleting your data

You can delete an individual item permanently from inside the app. Archiving keeps the record; deleting removes it. Delete is offered only on items you have already archived, so it takes two deliberate steps.

There is no self-service account deletion yet. To have your account and everything attached to it deleted, or to ask what is held about you, email hello@knowwhatsdue.com. There is no export button either — we will send you your data if you ask.

Anything else is on the support page.

Changes

If this policy changes in a way that affects what is stored or who can see it, the date at the top of this page will change with it.