This is a plain-English summary of how DutyRadar handles personal data. We try to write only what's true and only what's worth knowing.
"DutyRadar," "we," and "us" refer to the operator of dutyradar.com. The site is run as a small operation; for any data-protection question, write to hi@dutyradar.com. For the purposes of EU GDPR we act as the controller of personal data described below.
dr_session. HttpOnly cookie holding your dashboard session ID. Lifetime: 30 days, refreshed on activity. Strictly necessary for login.dr_loggedin. Non-HttpOnly cookie holding only the value 1, used so the public site can swap "Log in" for "Dashboard" before paint. No identifier.dr.theme in localStorage. Your light/dark preference. Local-only.None of the above sets a tracking cookie under EU/UK ePrivacy law. We do not use Google Analytics, Facebook Pixel, LinkedIn Insight Tag, or any other tracker that would require a consent banner. If we ever add one, we'll add the banner first.
| What | Why | Legal basis |
|---|---|---|
| Account + key data | Provide the service you signed up for | Performance of a contract (GDPR art. 6(1)(b)) |
| Edge logs, rate limits, Turnstile | Detect abuse, secure the service | Legitimate interest (art. 6(1)(f)) |
| Usage rollups | Quota enforcement, your own analytics | Performance of a contract |
| Sign-in emails (magic link) | Authenticate you | Performance of a contract |
| Product update emails | Tell you about features and changes | Legitimate interest with opt-out (you can unsubscribe at any time, and every marketing email links to a one-click unsubscribe) |
We use these third parties to actually run the service. Each receives only what's necessary for their function.
| Service | What they get | Where |
|---|---|---|
| Cloudflare (Workers, KV, Web Analytics, Turnstile, edge) | Request metadata, session tokens, anti-bot challenge tokens, aggregated page-view stats | Global edge; primary US |
| Neon (Postgres database) | Account row, API-key hashes, daily usage rollups | AWS US-East-2 (Ohio) |
| Resend (transactional + product emails) | Your email address plus the contents of emails we send to you | AWS US-East-1 (N. Virginia) |
We do not sell personal data. We do not share it with advertisers or data brokers. The only outbound flow is the subprocessor list above plus what's required by law (e.g., a court order).
Cloudflare, Neon, and Resend are US-based. Where EU personal data is transferred there, we rely on the European Commission's adequacy framework (EU-US Data Privacy Framework) where applicable, plus Standard Contractual Clauses ("SCCs") signed with each subprocessor.
If you're in the EU, UK, or another jurisdiction with similar rules, you have the right to:
Email hi@dutyradar.com from your account address with the subject "GDPR request" and we'll respond within 30 days. No fee.
API keys are hashed with SHA-256 before storage; we never store plaintext. Sessions are token-based and HttpOnly. Email transit uses TLS, database transit uses TLS, edge transit uses TLS. We're a small operation. We don't have a SOC 2 report yet, but we follow the boring fundamentals.
The service isn't directed at children under 16. If you believe we've collected data on a minor, tell us and we'll delete it.
If we change anything material, we'll bump the "Last updated" date and email account holders. The current version is always at dutyradar.com/privacy.
Email hi@dutyradar.com for anything privacy-related. We read every message.