Public policy

Privacy Policy

This policy describes how Dueva handles account, organization, workspace, source-document, billing, and AI processing data for its web-based deal diligence workflows.

Last updated:

Privacy contacts

Requests can be sent to privacy@dueva.app, submitted through /privacy-request, or started from /account/delete for authenticated account deletion.

Who We Are

This Privacy Policy explains how Dueva LLC ("Dueva," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information when you use Dueva, a web application for AI-native M&A and deal diligence workflows.

By using Dueva, you acknowledge that we process personal information as described in this Privacy Policy. This policy does not override rights you may have under applicable law.

Legal company name
Dueva LLC
Business address
1616 E 56th St, 60637, Chicago, IL, USA
Privacy email
privacy@dueva.app
Privacy request URL
/privacy-request
Account deletion URL
/account/delete
Country/entity jurisdiction
United States / Illinois, USA
Product
Dueva
Platform
Web application

Personal Information Collected

Depending on how you use Dueva, we may collect the following categories of personal information.

  • Identifiers and account information, such as name, email address, authentication provider information, account settings, and profile details you or your identity provider supply.
  • Organization and workspace information, such as organization names, workspace membership, roles, invitations, billing status, workspace events, and user actions inside a workspace.
  • Communications, such as support requests, demo requests, feedback, invite messages, investor-update send requests, and other messages you send to us or through configured Dueva workflows.
  • Device and usage information, such as browser type, IP address, pages viewed, features used, timestamps, diagnostics, error data, and security logs needed to operate and protect the Services.
  • Information from third parties, such as Supabase Auth identity data, Google or Microsoft/Azure OAuth profile information, Stripe subscription events, and data from services you choose to connect or use with Dueva.

Uploaded Deal And Source Content

Dueva workspaces are designed for organization-scoped deal diligence. Users may upload, enter, generate, or save confidential workspace content, including deal records, source materials, parsed document text, extracted tables, analysis jobs, report-agent messages, diligence questions, summaries, red flags, citations, investor-ready output, team membership records, billing state, and workspace events.

Supported uploads include PDF, DOCX, TXT, CSV, and XLSX files. Original source documents can be stored in a private Supabase Storage bucket with organization-scoped object paths and short-lived signed URL access. Parsed content and related metadata may be stored with the relevant deal record or analysis job.

Demo or local-development mode may use browser localStorage or IndexedDB for non-production deal data, report-agent chat history, workspace events, and local original-file previews. Demo/local storage is not intended for real customer or live deal data.

Auth And Account Data

Dueva uses Supabase Auth as the user system of record. Users can create accounts and sign in with email/password, passwordless magic links, Google OAuth, and Microsoft/Azure OAuth when those providers are configured.

Authentication data may include email address, password credentials submitted to Supabase Auth, OAuth provider identifiers, session cookies, confirmation and magic-link state, organization membership, workspace role, and account status. Dueva stores workspace membership and tenant context so access remains scoped to the correct organization.

Billing Data

Dueva uses Stripe for subscription billing, Checkout, and the Customer Portal. Stripe may process payment method details, invoices, payment status, tax and billing details, fraud-prevention signals, and related transaction data under Stripe's own terms and privacy policy.

Dueva may store or receive subscription status, plan, trial dates, Stripe customer IDs, Stripe subscription IDs, Checkout state, portal state, and limited payment metadata needed to manage billing and entitlements. Dueva does not store full payment card numbers.

AI Processing

Dueva uses server-side model calls to provide deal analysis, workspace and report-agent responses, summaries, red flags, diligence questions, citations, source-backed explanations, and investor-ready output.

When you use AI-powered features, private workspace content may be processed by Dueva and configured server-side AI model providers to provide the requested feature, maintain safety, debug errors, improve service quality, prevent abuse, and comply with law.

Dueva outputs may be AI-generated and should be reviewed by a qualified professional. Dueva does not provide legal, tax, accounting, investment, or financial advice. Dueva analysis is based on uploaded materials and configured workspace context unless otherwise stated.

Private workspace content is not used to train Dueva models unless separately disclosed. The current codebase uses OpenAI through server-side API calls when an OpenAI API key is configured; any additional model provider, retention, logging, or training terms should be reflected here before that provider is enabled.

Cookies, Local Storage, And Analytics

Dueva may use cookies, browser storage, and similar technologies for authentication, session management, security, preferences, local demo mode, IndexedDB original-file previews, diagnostics, performance, and product operation.

The current MVP does not claim advertising, retargeting, cross-context behavioral advertising, session replay, or third-party analytics. If analytics, crash reporting, marketing pixels, or session replay are added later, this policy should be updated before those tools are enabled.

  • You can control cookies through browser settings, but disabling essential cookies may prevent login or workspace features from working.
  • Browser localStorage and IndexedDB are used only for demo/local or client-side app state where applicable, not as production storage for original source documents.
  • If analytics are added, Dueva should document the provider, purpose, retention, and opt-out controls before launch.

How Data Is Used

  • Provide, operate, authenticate, secure, and maintain Dueva.
  • Create and manage accounts, organizations, workspace membership, access controls, and tenant-scoped data.
  • Parse uploaded materials, generate source-backed analysis, answer workspace/report-agent prompts, create diligence outputs, and maintain citations.
  • Process subscriptions, manage Checkout and Customer Portal access, update billing status, and enforce billing-gated entitlements.
  • Send service messages, workspace invites, security notices, support responses, optional investor-update sends, and product communications where permitted.
  • Troubleshoot issues, debug parsing or model behavior, measure service performance, prevent fraud or abuse, and improve reliability.
  • Comply with legal obligations, enforce agreements, protect rights and safety, resolve disputes, and support business operations.

How Data Is Shared

We do not share personal information except as described in this Privacy Policy or as directed by you.

  • Within your organization or workspace, according to membership, role, and access controls.
  • With service providers that help us operate Dueva, subject to contractual, technical, and legal safeguards where applicable.
  • With Stripe for billing, Checkout, Customer Portal, subscription status, invoice handling, fraud prevention, and payment support.
  • With Supabase for authentication, database, tenant persistence, session handling, and private storage where configured.
  • With configured server-side AI model providers to provide requested AI features.
  • With email delivery providers or webhooks when you send invites or investor updates through configured workflows.
  • With third parties you direct us to use, such as integrations, exports, or recipients you choose.
  • For legal, safety, compliance, fraud-prevention, security, corporate transaction, audit, or dispute-resolution purposes.
  • As aggregated, de-identified, or anonymized information that cannot reasonably identify you.

Vendors And Service Providers

Dueva relies on vendors and service providers to deliver the Services. The final production vendor list should be confirmed before launch.

Authentication, database, and storage
Supabase Auth, Supabase database, and private Supabase Storage where configured.
AI model processing
OpenAI or other configured server-side AI model providers used for requested AI features.
Billing
Stripe Checkout, Stripe Customer Portal, Stripe webhooks, and subscription billing infrastructure.
Email delivery
Optional configured email providers or webhooks for invites and investor-update sends.
Hosting and infrastructure
Vercel or another configured production host, plus the infrastructure providers used by Supabase, Stripe, OpenAI, and any configured email delivery provider.
Analytics or diagnostics
No third-party analytics, crash reporting, advertising, attribution, or session replay SDK is present in the current package and app code reviewed for this policy.

Retention

We keep personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention depends on the type of information and why it was collected. When information is no longer needed, we delete, de-identify, anonymize, or securely retain it as required by law.

  • Account and membership information is generally retained while your account or workspace membership is active.
  • Deal records, source documents, parsed content, analysis jobs, citations, and report-agent messages are retained while needed to provide workspace features or until deleted, subject to backups and legal exceptions.
  • Billing and transaction records are retained as needed for tax, accounting, fraud-prevention, compliance, and dispute-resolution obligations.
  • Security logs, diagnostics, and support records are retained as needed to operate, secure, and improve the Services.
  • Browser localStorage and IndexedDB demo data remains on the user's device until the browser, app storage, or relevant local records are cleared.

Account And Data Deletion

You may request deletion of your account and associated personal information by contacting us at privacy@dueva.app or using /account/delete. Deleting a browser profile, local files, or cached app data does not automatically delete a production account or workspace data stored by Dueva.

When we process a deletion request, we will delete or de-identify personal information associated with the account or workspace where required, subject to legal, security, fraud-prevention, backup, tax, accounting, dispute-resolution, and legitimate business exceptions.

Account deletion URL
/account/delete
Privacy request URL
/privacy-request
Privacy email
privacy@dueva.app

Privacy Rights

Depending on your location and how you use Dueva, you may have the following privacy rights.

  • Access or know what personal information we hold about you.
  • Request correction of inaccurate personal information.
  • Request deletion of personal information.
  • Request a portable copy of certain personal information.
  • Opt out of marketing emails where marketing is sent.
  • Withdraw consent where processing is based on consent.
  • Object to or restrict certain processing where applicable.
  • Appeal a denied privacy request where required by law.
  • Opt out of sale, sharing, or targeted advertising if any such processing is added in the future.
Submit a request
/privacy-request
Contact
privacy@dueva.app

U.S. State Privacy Notice

This section applies to residents of U.S. states with applicable consumer privacy laws, including California where the California Consumer Privacy Act, as amended, applies.

In the past 12 months, depending on your use of Dueva, we may have collected the following categories of personal information.

  • Dueva does not sell personal information for money.
  • Dueva does not currently claim sharing personal information for cross-context behavioral advertising.
  • Dueva does not currently claim processing personal information for targeted advertising.
  • Dueva does not use sensitive personal information to infer characteristics unless separately disclosed and legally permitted.
  • Because the current MVP does not claim sale, sharing, or targeted advertising, it does not currently present a Do Not Sell or Share flow. If those practices are added, Dueva should add the required opt-out controls before launch.
Identifiers
Yes. Examples include name, email address, account IDs, OAuth identifiers, IP address, and device or browser identifiers.
Customer records
Yes. Examples include account details, organization membership, billing metadata, and subscription records.
Commercial information
Yes. Examples include subscription plan, purchase history, billing status, and product usage.
Internet or network activity
Yes. Examples include pages viewed, features used, logs, diagnostics, and interactions with workspace features.
Geolocation
Limited. Approximate location may be inferred from IP address for security, diagnostics, or compliance. Dueva does not request precise device location for current MVP features.
Audio, visual, or similar information
Possible. Users may upload source materials that contain images or other media inside supported file types, but Dueva does not claim routine camera, microphone, or media-library access.
Professional or employment information
Possible. Work email, title, company context, team role, and uploaded deal materials may contain professional information.
Inferences
Possible. Dueva may generate diligence summaries, red flags, fit notes, preferences, or workspace recommendations from user-directed deal content.
Sensitive personal information
Limited. Account login credentials are processed through Supabase Auth, and uploaded workspace content may contain sensitive information if users choose to include it.

EEA, UK, And Swiss Rights

If you are located in the European Economic Area, United Kingdom, Switzerland, or a similar jurisdiction, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, withdraw consent, object to direct marketing, and lodge a complaint with your local data protection authority.

Where GDPR, UK GDPR, or similar laws apply, our legal bases may include performance of a contract, legitimate interests, consent, legal obligation, or another lawful basis permitted by applicable law. Where we rely on legitimate interests, we balance those interests against your privacy rights and expectations. Where we rely on consent, you may withdraw consent at any time.

Controller
Dueva LLC
Country/entity jurisdiction
United States / Illinois, USA
Privacy contact
privacy@dueva.app

International Transfers

We are based in United States / Illinois, USA, and personal information may be processed in countries other than where you live. Those countries may have data protection laws different from those in your jurisdiction.

Where required, we use appropriate safeguards for international transfers, such as data processing agreements, standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.

Children's Privacy

Dueva is a professional deal diligence product and is not directed to children. We do not knowingly collect personal information from children under 13 or any higher age required by applicable law.

If you believe a child has provided us personal information, contact us at privacy@dueva.app. If we learn that we collected personal information from a child without required consent, we will delete it or take other appropriate steps required by law.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include authentication safeguards, tenant-scoped access controls, private storage paths, encryption in transit, server-side model calls, logging, monitoring, vendor review, secure development practices, and data minimization.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect personal information and improve safeguards over time.

Third-Party Services

Dueva may contain links to, receive data from, or send data to third-party websites, services, identity providers, billing providers, email providers, AI model providers, integrations, SDKs, or platforms. Their privacy practices are governed by their own policies.

You should review the privacy policies of third-party services you use with Dueva, including OAuth providers, Stripe, Supabase, and any integrations or recipients you direct Dueva to use.

Changes

We may update this Privacy Policy from time to time. The updated version will be posted with a new "Last updated" date. If we make material changes, we will provide additional notice where required by law, such as through the app, email, or website notice.

Your continued use of Dueva after an updated Privacy Policy becomes effective means you acknowledge the updated policy.

Contact

For privacy questions, requests, or complaints, contact:

Legal company name
Dueva LLC
Business address
1616 E 56th St, 60637, Chicago, IL, USA
Privacy email
privacy@dueva.app
Privacy request URL
/privacy-request
Account deletion URL
/account/delete
Country/entity jurisdiction
United States / Illinois, USA