DutyRadar docs · get a key

Privacy policy

Last updated: 2026-05-07

This is a plain-English summary of how DutyRadar handles personal data. We try to write only what's true and only what's worth knowing.

Who we are

"DutyRadar," "we," and "us" refer to the operator of dutyradar.com. The site is run as a small operation; for any data-protection question, write to hi@dutyradar.com. For the purposes of EU GDPR we act as the controller of personal data described below.

What we collect

Account data (when you sign up)

Usage data (when you call the API)

Automatic / cookies

None of the above sets a tracking cookie under EU/UK ePrivacy law. We do not use Google Analytics, Facebook Pixel, LinkedIn Insight Tag, or any other tracker that would require a consent banner. If we ever add one, we'll add the banner first.

Why we process this data (legal basis)

WhatWhyLegal basis
Account + key dataProvide the service you signed up forPerformance of a contract (GDPR art. 6(1)(b))
Edge logs, rate limits, TurnstileDetect abuse, secure the serviceLegitimate interest (art. 6(1)(f))
Usage rollupsQuota enforcement, your own analyticsPerformance of a contract
Sign-in emails (magic link)Authenticate youPerformance of a contract
Product update emailsTell you about features and changesLegitimate interest with opt-out (you can unsubscribe at any time, and every marketing email links to a one-click unsubscribe)

Who we share data with (subprocessors)

We use these third parties to actually run the service. Each receives only what's necessary for their function.

ServiceWhat they getWhere
Cloudflare (Workers, KV, Web Analytics, Turnstile, edge)Request metadata, session tokens, anti-bot challenge tokens, aggregated page-view statsGlobal edge; primary US
Neon (Postgres database)Account row, API-key hashes, daily usage rollupsAWS US-East-2 (Ohio)
Resend (transactional + product emails)Your email address plus the contents of emails we send to youAWS US-East-1 (N. Virginia)

We do not sell personal data. We do not share it with advertisers or data brokers. The only outbound flow is the subprocessor list above plus what's required by law (e.g., a court order).

International transfers

Cloudflare, Neon, and Resend are US-based. Where EU personal data is transferred there, we rely on the European Commission's adequacy framework (EU-US Data Privacy Framework) where applicable, plus Standard Contractual Clauses ("SCCs") signed with each subprocessor.

How long we keep it

Your rights

If you're in the EU, UK, or another jurisdiction with similar rules, you have the right to:

Email hi@dutyradar.com from your account address with the subject "GDPR request" and we'll respond within 30 days. No fee.

Security

API keys are hashed with SHA-256 before storage; we never store plaintext. Sessions are token-based and HttpOnly. Email transit uses TLS, database transit uses TLS, edge transit uses TLS. We're a small operation. We don't have a SOC 2 report yet, but we follow the boring fundamentals.

Children

The service isn't directed at children under 16. If you believe we've collected data on a minor, tell us and we'll delete it.

Changes to this policy

If we change anything material, we'll bump the "Last updated" date and email account holders. The current version is always at dutyradar.com/privacy.

Contact

Email hi@dutyradar.com for anything privacy-related. We read every message.