Dueply

Privacy notice

Last updated 3 October 2026

This notice explains what personal data Dueply processes, why, for how long, and how you can intervene. It is written from what the software actually does, not from a template.

What Dueply does

Dueply examines the flight you give it to work out whether you may be owed compensation or a refund for a delay or cancellation, under Regulation (EC) 261/2004 or, for flights to and from the United Kingdom, its UK version (UK261) or, for flights from Turkey and on Turkish carriers into it, the Turkish SHY-YOLCU regulation. It shows you what it found and what is missing.

Dueply does not file claims for you, does not contact airlines on your behalf, and does not give legal advice.

What we process

Account. Email address, password (kept only as an scrypt hash, never in the clear) and, if you give one, a name.

Sessions. A session identifier kept as a hash, with its expiry and the app version it was last used from.

Flights. Flight number, date, and the normalised flight record we obtain from the provider.

Assessments and claims. The outcome of a check and the answers you give to the questions needed to complete it; if the airline refuses, the reason you give.

Service usage. The distinct flights checked during the month and active monitors, to apply the limits shown in the app.

Purchases. For each pack bought on Google Play: a fingerprint (hash) of the purchase token, the product, the credits granted, the price and currency Google Play showed and the date, plus the balance of credits not yet used. No payment details.

Notifications. If you enable push, the device token, encrypted.

Device verification. When you use a free check from the Android app, Google Play Integrity confirms to us that the request comes from the genuine app, installed from Google Play, on a genuine device; the app also sends Google's App Set ID. We do not keep the identifier, only a keyed fingerprint (HMAC) of it together with the flights checked for free from that device, for the current and the previous month. The fingerprint is not linked to your account and remains if you delete it.

Free checks per email address. So that free checks do not start over by deleting the account or by using variants of the same address (for example name+something@), we keep a keyed fingerprint (HMAC) of your address, reduced to its base form, together with the flights checked for free, for the current and the previous month. We do not keep the address itself; the fingerprint is not linked to your account and remains if you delete it. The same fingerprint also counts searches for flights that were not found, which we pay the data provider for: we keep only their date and time, for one day.

Internal usage statistics. Events such as "check started" or "notification opened", tied to a random code associated with your account, with no email address or content. They tell us where the service works and where it does not.

Record of operator access. When someone at Dueply looks at your data in the operations console, we record who, when and what.

Operational records. Technical and security events needed to run and protect the service.

Payments

You can buy packs of checks and watched flights in the Android app. Payment happens entirely on Google Play, which acts as an independent controller for payment data: Dueply never sees or stores card numbers or other payment details.

From Google Play we receive only what we need to verify the purchase and credit it to your account: the purchase token, the product bought and its state. We keep a fingerprint of the token, the product, the credits granted and the date for as long as your account exists, to answer support or refund requests and to make sure one purchase is never credited twice. If Google Play tells us a purchase was refunded, we remove that pack's unused credits from your balance.

Why we process it

  • Account, sessions, flight checks, claims, watched flights: performing the service you asked for (Art. 6(1)(b) GDPR).
  • Push notifications: performing the service (Art. 6(1)(b) GDPR), only if you turn them on; you can turn them off at any time in the phone or app settings.
  • Purchases and credits: performing the contract (Art. 6(1)(b) GDPR).
  • Device verification and the email fingerprint for free checks: our legitimate interest (Art. 6(1)(f) GDPR) in stopping free checks, which cost us, from being obtained without limit by creating new accounts. The App Set ID is read only when you ask for a free check, because that check cannot be provided without it (Art. 122 Italian Privacy Code). The same fingerprints link the accounts used from the same mailbox or the same phone, which share the free places for watching flights; the link is deleted with the account.
  • Security records and the record of operator access: our legitimate interest (Art. 6(1)(f) GDPR) in protecting the service and being able to show who looked at data, and the security obligation (Art. 32 GDPR).
  • Internal usage statistics: our legitimate interest (Art. 6(1)(f) GDPR) in improving the service.
  • Backups: our legitimate interest (Art. 6(1)(f) GDPR) and the security obligation (Art. 32 GDPR) in being able to restore data.

On request to [email protected] we send you the assessment in which we balanced these interests against yours.

An email address and a password are needed to use Dueply: without them we cannot create the account. A name and push notifications are optional. Device verification is needed only for free checks: if it is not possible, you can still use bought checks.

Automated decisions

The outcome of a flight check is computed automatically, by applying the rules of Regulation (EC) 261/2004, UK261 or SHY-YOLCU to the flight data and your answers. It is an indication: it does not decide your right, which remains the airline's or a court's to decide, and we do not make claims for you.

Access to free checks also depends on an automated device check: if it fails, you can use bought checks.

Neither is a decision with legal or similarly significant effects within the meaning of Art. 22 GDPR. If you want a person to review an outcome, write to [email protected].

Deleting your account

You can delete your Dueply account at any time, directly from the Android app:

1. Open Dueply and sign in.

2. Tap the profile icon (Profile and settings).

3. Open Privacy and your data.

4. Tap Delete account, enter your password, then tap Permanently delete.

If you can no longer use the app, email [email protected] from your account's address: we delete the account within 30 days and confirm it to you.

Deleted immediately: the account (email, password, name), sessions, flights checked, assessments, claims and answers, watched flights, notifications and preferences, devices registered for notifications, purchases and unused credits.

What remains, and for how long:

  • Encrypted database backups, for up to 30 days, after which they are deleted.
  • The record of operator access to data, for 12 months, with your identifier replaced by a pseudonym that does not identify you.
  • Usage statistics events, for 12 months: the link to your account is removed, but they stay grouped under the random code.
  • The device fingerprint used for free checks, until the end of the following month.
  • The email address fingerprint used for free checks, until the end of the following month.
  • The email address fingerprint with searches for flights not found: one day.
  • Google Play purchase notifications, which contain only a fingerprint of the purchase token, for 12 months.

Deleting the account loses its unused credits. If you delete it within 14 days of a purchase none of whose credits you have used, write to [email protected] first and we will refund that pack.

For how long

  • Sessions: 30 days at most, then they expire; expired or closed sessions are deleted 30 days later.
  • Email verification codes: 15 minutes; expired ones are deleted after 7 days.
  • Password reset codes: 30 minutes.
  • Device fingerprint, email address fingerprint and the flights checked for free with them: the current and the previous month, then deleted; they are not linked to your account and are not deleted with it.
  • Notifications already read in the app: 90 days. Push delivery attempts: 30 days. Devices retired from notifications: 30 days.
  • Backups: 30 days, then deleted.
  • Record of operator access, usage statistics events and Google Play purchase notifications: 12 months.
  • Everything else: for as long as your account exists. When you delete it, the linked data is deleted, except as set out in "Deleting your account".

Who else processes your data

We rely on providers acting as processors. Each receives only what it needs:

  • OVH (France, EU) — hosts the server and the database. Receives everything the service stores.
  • Resend — sends verification, password-reset and purchase confirmation email. Receives your address and the content of those messages.
  • Cloudflare — protects and delivers the site. Processes IP addresses and request metadata.
  • Google Firebase Cloud Messaging — delivers push notifications, if you turned them on. It receives the device token and a message carrying only the kind of update and an identifier: the content stays in the app.
  • Google Cloud Pub/Sub — delivers Google Play's notifications about purchases and refunds to us. They carry the purchase token, not your name or address.
  • Google Drive — holds the database backups, encrypted before they leave: Google cannot read their contents.
  • Google Play Integrity — assesses whether the app and the device are genuine when you use a free check from the Android app. It receives from the app the device signals the assessment needs and a fingerprint of the request, not the content of the check. If Google enables "device recall" for Dueply, it keeps three yes/no values for the device recording how many free checks were used in the month, with no identifier, for up to 3 years after last use.
  • AeroDataBox (Canada) — provides the flight data, through the API.market marketplace that forwards our requests. They receive only a flight number and a date, which do not identify you on their own.
  • Authorised Dueply staff — access data only through the operations console, with two-factor authentication, and every access is recorded.

Google and Cloudflare also process data in the United States under the EU-US Data Privacy Framework (Commission adequacy decision (EU) 2023/1795); Resend under the standard contractual clauses (decision (EU) 2021/914). You can ask us for a copy of the safeguards at [email protected].

Website statistics (Google Analytics)

On dueply.app we use Google Analytics 4 only if you accept it in the banner. If you refuse, or until you choose, nothing is loaded from Google.

If you accept, Google Analytics sets cookies (`_ga` and similar) and collects, in aggregate, the pages visited, how long a visit lasts, the type of device and browser and the approximate country. Google Analytics 4 does not store IP addresses. We do not use this for advertising, and Google Signals and ad personalisation are switched off.

The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code). Google Ireland Limited acts as our processor; data may be transferred to the United States under the EU-US Data Privacy Framework. Google keeps the data for 14 months.

You can change your mind at any time with the Cookie preferences link at the bottom of the page: withdrawing consent deletes the Google Analytics cookies. The Android app does not use Google Analytics.

Your rights

Right to object. You can object at any time, on grounds relating to your particular situation, to the processing based on our legitimate interest (Art. 21 GDPR), by writing to [email protected]. If you object to device verification you will not be able to use free checks, but you can use bought ones.

You may also exercise the other rights in Articles 15-22 GDPR at any time: access, rectification, erasure, restriction and portability.

You can exercise two of these rights directly from Privacy and your data in the app settings:

  • A copy of your data. A file with the data linked to your account, which also states explicitly what it leaves out and why. For usage statistics and the record of operator access, write to us.
  • Account deletion. Your data is erased, except as set out in "Deleting your account".

For the others, or if something is wrong: [email protected]. We reply within one month.

If you believe the processing breaches the GDPR you can complain to the Italian supervisory authority (garanteprivacy.it) or to the authority where you live.

If you live outside the European Union

Dueply can be used from any country. Wherever you live, we process your data as described here and give you the same rights as the GDPR does.

The server and the database are in the European Union (OVH, France): if you use Dueply from another country, your data is transferred to and stored there. The other providers process it as described in “Who else processes your data”.

You exercise your rights the same way, in the app or by writing to us ([email protected]). Any further rights the law of your country gives you still apply, and you can also contact the data protection authority of your country.

Security

Passwords are stored as scrypt hashes. Device tokens and operator second factors are encrypted with AES-256-GCM, each under a separate key: compromising one does not expose the others.

Traffic is encrypted in transit. The database is not reachable from the internet. Backups are encrypted before they leave the server, under a key that does not exist on it.

Logs never contain message content, addresses, tokens or passwords: they are filtered by field name, not by good intentions.

Children

Dueply is not intended for anyone under 18 and does not knowingly collect their data.

Changes

If this notice changes materially we will tell you before the change takes effect. The date at the top is the last revision.

Data controller

Federico Fazzi, Via Grazia Deledda 14, 07100 Sassari, Italia.

For anything concerning personal data: [email protected]. We have not appointed a data protection officer (DPO), because our processing does not require one.