Legal

Privacy Policy

Last updated: August 26, 2026

1. Introduction

Duplyfi ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our desktop application, website, and services.

This policy is designed to comply with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

Account Information

  • Email address (for account creation and communication)
  • Password (stored as a salted hash, never in plain text)
  • Display name (optional)

Device Information

  • Hardware identifier (HWID) for license binding and device management
  • IP address (logged temporarily for security purposes)

Telemetry Data

Telemetry is on by default in the desktop application and can be turned off at any time in Settings. While it is on, we collect:

  • Crash reports and error logs
  • Feature usage statistics (which effects are used, etc.)
  • Performance metrics (processing times, thread usage)
  • App and system details (app version, operating system, and processor architecture)

Telemetry is not anonymous. While you are signed in, each event is recorded against your account and stored with the IP address it was sent from. It never includes your files or their contents.

When something fails, the error report carries the error message, the stack trace, which part of the app failed, and technical detail about the operation that failed. That detail can include file paths from your machine, such as the output folder you were writing to or the preset that was loaded.

3. How We Use Your Information

  • Authenticate your account and manage license activation
  • Process subscription payments via our merchant of record
  • Send transactional emails (account verification, password resets)
  • Improve the product based on aggregated telemetry, unless you have turned it off
  • Detect and prevent fraud or abuse, including repeated free-trial abuse on the same device
  • Comply with legal obligations

We do not sell your personal information. We do not use your data for advertising.

4. Payment Processing

All payments are processed by our payment processor, which acts as our merchant of record. We do not store, process, or have access to your credit card details, bank account information, or other payment credentials. Our payment processor handles all payment data in accordance with PCI DSS standards.

For billing inquiries, you can access the customer portal through your Duplyfi account settings.

5. Email Communications

Transactional emails (account verification, password resets, subscription confirmations) are sent via Resend. We do not send marketing emails unless you explicitly opt in. You can unsubscribe from optional emails at any time.

6. Data Storage and Security

Your account data is stored in a PostgreSQL database hosted on DigitalOcean infrastructure. We implement industry-standard security measures including:

  • Encrypted connections (TLS/SSL) for all data in transit
  • Salted password hashing (bcrypt)
  • JWT RS256 authentication tokens
  • Rate limiting on all API endpoints
  • Regular security audits

Your media files are processed entirely on your local device and are never uploaded to our servers.

7. Data Retention

  • Active accounts: Data is retained for the duration of your account.
  • Deleted accounts: Account data is permanently deleted within 30 days of account deletion, with one exception (see below).
  • Device fraud-prevention records: A one-way hash of your device's hardware identifier is retained after account deletion to prevent repeated free-trial abuse on the same device. This hash cannot be linked back to your account or any personal information once your account is deleted, and it is kept under our legitimate interest in preventing fraud.
  • Telemetry data: Telemetry events are retained for up to 180 days, then automatically purged.
  • Server logs: IP addresses in server logs are retained for up to 90 days for security purposes.

8. Your Rights

Under GDPR and CCPA, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Delete your account and associated data
  • Export your data in a portable format
  • Opt out of telemetry data collection at any time via Settings
  • Object to processing of your data

To exercise any of these rights, contact us at privacy@duplyfi.com. We will respond within 30 days.

9. Cookies

Signing in does not set a cookie. Your session token is held in your browser's local storage on the device you signed in from, and it is cleared when you log out.

We set two first-party cookies, and only when you arrive through a link that carries the matching parameter:

  • duplyfi_ref, set when you follow an affiliate link. It stores that affiliate's referral code so the affiliate is credited if you subscribe. Expires after 30 days.
  • duplyfi_utm, set when you follow a campaign link. It stores the source, medium and campaign names from that link so we can tell which campaigns bring people to the site. Expires after 30 days.

Both are set by this site, are readable only by duplyfi.com, and contain no name, email address, or account identifier. We use no advertising cookies and no third-party analytics cookies; our site analytics run on our own server and set no cookie. You can delete either cookie at any time in your browser settings.

10. Third-Party Services

We share limited data with the following third parties:

ServicePurposeData Shared
Payment ProcessorPayment processing (merchant of record)Email, billing info
ResendTransactional emailEmail address
DigitalOceanInfrastructure hostingEncrypted account data
CryptomusCryptocurrency payment processingEmail, payment amount

11. Children's Privacy

Duplyfi is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at privacy@duplyfi.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before the changes take effect. Continued use of the Service after changes constitutes acceptance.

13. Contact

For privacy-related questions or to exercise your data rights, contact us at privacy@duplyfi.com.

For general support, contact support@duplyfi.com.