Skip to main content
Privacy Policy

Privacy Policy

Last updated: 2026-08-25 — reflects Duetide V1 implementation.

REQUIRES PROFESSIONAL LEGAL REVIEW BEFORE PUBLIC ADOPTION

This Privacy Policy is a V1-accurate description of what Duetide’s implementation actually does. It is not legal advice. The items flagged [REQUIRES LEGAL REVIEW] below, plus the entire jurisdiction, corporate identity, contact address, and retention-window language, must be reviewed by qualified counsel before this page is treated as a binding public commitment.

1. Account & user information

When you create a Duetide account, the platform stores your email address, display name, and session metadata using better-auth. Authentication sessions are short-lived and renewed on sign-in. Profiles collect a per-user [REQUIRES LEGAL REVIEW] name and email; nothing else is required to use the service.

2. Organization data

If you create or join an organization, Duetide records your membership and the organization’s display name, default time zone, and (optionally) its primary office location. Members, owners, and invitations are stored inside the organization you belong to and are scoped so other organizations cannot see them.

3. Tracked-item data

Each tracked item — license, certification, contract, permit, insurance policy, vehicle document, inspection, or warranty — is stored with the fields you enter or that are extracted from your uploaded documents: renewal date, notice window, vendor, responsible person, statuses, and free-form notes. Owner-side fields (vendor name, counterparty) are surfaced inside your organization only.

4. Responsible-person & location data

Records can be assigned to a responsible person within your organization. Location metadata (one-line site/office name) is used for filtering and filtering-only searching. [REQUIRES LEGAL REVIEW]

5. Reminder email processing

Duetide sends renewal reminders through the platform’s email proxy to the recipient configured per record — the item’s owner or an explicit reminderEmail. Reminder content includes the record’s display name, renewal date, notice window, and any custom body you supply. Delivery is best-effort; you remain responsible for the underlying obligation regardless of whether a reminder arrives.

[REQUIRES LEGAL REVIEW] — Reminder email content, sender identification, unsubscribe path, and transactional vs. marketing classification must be reviewed by counsel.

6. Uploaded documents & metadata

Files you upload (PDFs, images, DOCX, spreadsheets) are stored through the platform’s storage proxy. The provider encrypts content at rest. Metadata — file name, size, upload timestamp, MIME type, and the record it attaches to — is stored alongside the file. Duetide does not read your files for any purpose other than extraction on your behalf.

7. Billing, subscription, & payment processing

Subscription state (plan, trial window, period end, cancellation status) is stored in your organization. Payment processing is handled through the Stripe Connect platform via the platform’s billing integration; the platform never receives your card number. [REQUIRES LEGAL REVIEW]

8. Support requests

Messages submitted via the public Contact form are stored against a persistent message ID. The team can pull the thread back up via that ID when they reply. The message body and your name + email (if you supplied them) are visible to support staff.

9. Platform-admin / support access

A small group of platform administrators can read messages, audit logs, and — for support purposes — billing metadata. All administrator reads are audit-logged: who accessed what, when, and from which operator are recorded, and the audit log is retained for [REQUIRES LEGAL REVIEW] the period defined by your organization’s policy.

10. Operational & security logging

Duetide records operational security metadata: request headers (including CSP nonce and report-only violations), routing paths, status codes, and rate-limit decisions. Logs are retained for [REQUIRES LEGAL REVIEW] the operational window configured in the deployment.

11. Retention & deletion behavior actually implemented

Audit log entries are retained indefinitely while your organization is active. Tracked items you archive via archivedAt are retained but hidden from the default workspace view; permanent deletion requires a support request. [REQUIRES LEGAL REVIEW] Billing subscriptions retain their state for the customer-portal record so cancellation and refund paths remain auditable.

12. Subprocessors & platforms

  • Polsia — application hosting, runtime, and platform primitives.
  • Stripe (Connect) — payment processing.
  • Platform email proxy — reminder + transactional email.
  • Platform storage proxy — uploaded documents (encrypted at rest by the provider).

13. Contact & jurisdiction

Duetide’s V1 contact address, corporate legal name, and governing jurisdiction are [REQUIRES LEGAL REVIEW]. Until those values are confirmed and inserted by counsel, please send privacy questions to privacy@duetideapp.com.

Questions about this policy? Use the Contact page or email privacy@duetideapp.com.