honey
due
Privacy & data
What Honey-Due stores, where it lives, and what leaves your device. Last updated 1 August 2026 · Operated by SGM Tactical LLC.
The short version
·
Your tasks live on your device first. The cloud is a backup, not the source of truth.
·
No analytics, no ad networks, no third-party trackers, no push notifications — none are in the app at all.
·
Nothing is ever sold or shared with advertisers or data brokers.
·
Your tank check-in and your quick notes never leave your device — they aren’t backed up and your partner can’t see them.
·
You can use Honey-Due without giving an email address.
·
Location is used only to fetch your local weather forecast.
What Honey-Due stores
Task data — titles, details, the original text you captured, status, size estimate, deadlines, shopping lists, completion notes, and flags like “outdoor.”
Plans — the time windows you declare, which tasks sit in them, and the plain-language reason for each placement.
Profile — your display name, your partner’s name as you type it, time zone, roughly when your day starts and winds down, and your vacation dates if you set any.
Your energy check-in — the daily “in the tank” reading. Stored only on your device: never uploaded, never in a digest, never visible through the partner link.
Your quick notes — jots from the Quick Notes drawer, and the category names and colors you create for them. Stored only on your device — not synced to the cloud backup.
A coarse sense of your usual area — a small on-device tally of which rough ~1.1 km areas the app usually wakes up in, so it can tell home from out-and-about and mention the shopping list when you’re already out. Never uploaded, never synced, never shared.
A weather cache — a recent forecast and a coarse place name, kept on your device.
Account identity — an anonymous ID by default. If you choose to save your account, an email and password handled by Supabase Auth (the app never stores your password itself).
Where your data lives
On your device — the iPhone app keeps everything in its own app storage. This is the source of truth, and the app works fully offline.
On Supabase — tasks, plans, your profile and your partner link token sync to a Postgres database hosted in the United States. Row-level security scopes every row to your account, so one account can’t read another’s.
Location and weather
Honey-Due asks for foreground location only — it never tracks you in the background.
Your coordinates go to Open-Meteo to fetch a local forecast, which is what lets the app steer outdoor jobs toward dry days.
Those coordinates are rounded before they leave. Your phone gives the app a precise position; before anything is sent it is rounded to about a 1.1 km square — tight enough that the forecast matches your actual sky, while still one rounding short of your exact address. What leaves your phone identifies your neighbourhood, not your house.
Those coordinates are not stored in our database and not attached to your account. Only a coarse place name and the forecast are cached on your device. Decline the permission and everything else still works — you just lose weather-aware planning and the out-and-about shopping reminder.
The out-and-about assist runs entirely on your phone: it compares the current rounded area against the on-device tally of your usual one, and if you’re clearly out and the shopping list has unbought items, it says so — inside the app only, never as a notification. Nothing about your movements is sent anywhere.
The partner link
If you share a partner link, whoever holds it can see your partner name, your task list, and a stripped-down slice of your plan (window labels and which task sits where). They can also send you a task request.
The link itself is the key — anyone with the URL can view that data, so treat it as private.
Revoke link — next to where you share it — kills the link outright: the old URL stops opening for everyone, including anyone it was forwarded to.
Re-sharing also generates a new link and revokes the old one.
Your location, your tank check-in and your quick notes are never included.
Payments
Supporting the app is voluntary — nothing is paywalled or gated.
If you tap a support amount you leave the app for a Stripe-hosted checkout page. Card details are entered on Stripe’s page and handled by Stripe. Honey-Due never sees, receives or stores your payment information.
What Honey-Due does not do
No analytics or usage tracking — there is no analytics SDK in the app.
No crash or performance reporting.
No advertising, ad identifiers or third-party trackers.
No push notifications and no device push tokens. Reminders appear inside the app only.
No selling or renting your data, to anyone, ever.
Automated processing (AI)
Honey-Due contains an optional feature that would use a large language model to interpret messily-typed captures. It is currently disabled in the shipped app.
Captures are parsed on your device by a simple built-in parser, and no task text is sent to any AI provider. If that ever changes, this policy will be updated before it ships and will name the provider.
Keeping and deleting your data
Deleting a task removes it from this device and from the cloud backup.
Signing out clears this device. Your account’s cloud data is kept on purpose, so signing out doesn’t lose everything.
Deleting your account erases everything — every task, plan and note, on the device and in the backup — and stops any partner link. You’ll find it under “Delete account” in Profile. It can’t be undone.
Your rights
Depending on where you live (for example under GDPR or CCPA/CPRA) you may have the right to access, correct, export or delete your personal data, and to object to certain processing.
Because Honey-Due is local-first, most of your data is already in your hands on your device. For anything else, contact us and we’ll action it. We don’t sell personal information, so there’s nothing to opt out of there.
Children
Honey-Due isn’t directed at children under 13, and we don’t knowingly collect personal information from them.
Changes to this policy
If the app’s data handling changes — AI parsing switched on, say, or analytics ever added — this policy is updated and the date at the top changes with it.
Contact
Questions, data access requests, or deletion requests:
nadirmims@sgmtllc.com