← deduplex

Privacy Policy

Last updated: September 16, 2026

Before publishing: replace [Contact Email] below, and confirm this accurately describes your actual data flows before relying on it — particularly if you'll have users in the EU/UK (GDPR) or California (CCPA), where specific disclosures and rights are legally required beyond what's drafted here.

This Privacy Policy describes how Zach Audan, doing business as Deduplex ("we," "us," or "our") collects, uses, and shares information in connection with Deduplex (the "Service"). We are based in Quebec, Canada.

1. Information We Collect

2. How We Use Information

We use the information above to: operate and maintain the Service; process billing via Stripe; detect and prevent abuse; and respond to support requests. We do not sell your data.

3. Idempotency Keys and Audit Log Content

The idempotency keys and event data you send to the API are only as sensitive as what you choose to put in them — avoid including raw payment card numbers, passwords, or other highly sensitive values directly in a key. This data is stored to power the Service's core duplicate-detection and audit guarantees, and is retained for as long as your account is active plus a reasonable period afterward for dispute resolution, unless you request earlier deletion.

4. Third-Party Processors

We use the following categories of subprocessors to operate the Service:

Each processes data on our behalf under their own privacy and security commitments.

5. Data Retention

We retain account and audit-log data for as long as your account is active. You may request deletion of your account and associated data by contacting us at [Contact Email], subject to any data we're required to retain for legal, tax, or billing-dispute purposes.

6. Your Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. To exercise any of these rights, contact us at [Contact Email].

7. Security

We use industry-standard measures — including rate limiting, per-tenant data isolation, and hash-chained tamper-evident logging — to protect data submitted to the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

The Service is not directed to individuals under 16, and we do not knowingly collect personal information from them.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

10. Contact

Questions about this Privacy Policy can be sent to [Contact Email].