Privacy Policy
Last updated 19 August 2026
Deduptio (“we”, “us”) is operated by VentuRise OÜ (registry code 17064180), Ruunaoja tn 3, Lasnamäe linnaosa, Tallinn, Harju maakond 11415, Estonia. This policy explains what we collect when you use deduptio.com, why, and how long we keep it.
What we collect
Account data. Your email address and a hashed password. We never store your password in readable form. We also record when you verified your email and when your account was created.
Security data. Hashed session tokens, and a log of login attempts including the email tried, the IP address, and whether it succeeded. We use this to rate-limit and detect abuse.
Your Attio connection. When you connect Attio, we store the OAuth access token that authorizes us to read and modify records on your behalf. Tokens are encrypted at rest.
Your CRM record data. To find duplicates we read records from the Attio objects you select and store their field values on our servers. Depending on your CRM, this can include personal data about your contacts — names, email addresses, phone numbers, company associations, and any other attributes on those records. We process this data solely to group duplicates, plan merges, and let you undo them.
Billing data. If you subscribe, we store your Stripe customer and subscription identifiers and your plan. We never see or store your card details — Stripe handles payment information directly.
How long we keep it
- Scan working data — the records pulled during a scan are scratch data, scoped to a single scan job and deleted when that job finishes.
- Duplicate groups — the field values of grouped records are kept so you can review the group, and are removed when the group is merged or skipped.
- Merge snapshots — the pre-merge copy of a record that powers undo is retained for 24 hours, then deleted automatically by a daily purge job.
- Merge audit log — a record of what was merged, by whom, and when, is retained for the life of your account so you have an accountable history.
- Account data — kept until you delete your account.
Who we share it with
We do not sell your data. We share it only with the providers that run the service:
- Attio — the source of your record data and the system we write merges back to.
- Neon — our database host (Postgres).
- Vercel — application hosting.
- Stripe — payment processing.
- Resend — transactional email (verification, password resets).
- Anthropic — processes conversations with the in-app assistant, described below.
- Google (Google Ads) — measurement and advertising on our public marketing pages. The Google Ads tag (gtag.js) records a pageview and, if you sign up, a conversion.
- Meta (Facebook) — the Meta Pixel, used the same way on our public marketing pages when it is enabled.
Advertising and measurement on our marketing pages
Our public marketing pages — the homepage, docs, guides and comparison pages — load third-party advertising tags so we can tell which campaigns bring people to Deduptio. These tags set cookies or similar identifiers in your browser and report a pageview, and a conversion event if you create an account. They run only on the public pages, never inside the signed-in application, and they never receive any of your Attio record data.
You can block them with any tracker-blocking extension or by declining cookies in your browser settings; nothing about Deduptio stops working if you do. If you are in the EU or UK and would like your data removed from these tools, email help@deduptio.com and we will action it.
Staff access
A small number of named operators can view operational metadata about your account — workspace name, plan, scan and merge statuses, and error messages — to provide support and keep the service reliable. The admin interface cannot display the field values of your CRM records: operator visibility is limited to counts, statuses, and errors. Every admin page view and action is logged, and that log is retained for 90 days. Admin access additionally requires the operator to re-confirm their password.
The one exception is the managed cleanup service: if you purchase it, you authorize our operators to view and merge the record data in your workspace for the duration of that engagement, so they can do the cleanup for you. That access ends when the engagement does.
The in-app assistant
The assistant available on signed-in pages sends your message, the rest of that conversation, and a summary of your Deduptio workspace state — your recent merges, scans and errors, as statuses and counts — to Anthropic to generate each reply. It never sends the field values on your Attio records: only Deduptio's own state about your workspace. Anthropic processes this as a subprocessor and does not train its models on it. Conversations are retained for 90 days and then deleted by an automated job, same as every other retained log described above. The assistant has read-only access to your workspace and cannot merge, retry, scan, roll back, reconnect Attio, or change your billing — see the assistant for what it can and cannot do.
Security
Attio access tokens are encrypted at rest. Passwords are hashed with Argon2. Traffic is served over TLS. Sessions expire on both an idle and an absolute timeout, and can be revoked. No system is perfectly secure, but we design merges to be reversible precisely because mistakes happen.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict its processing. You can disconnect Attio at any time, which stops us reading further records. Deleting your account removes your account data and the record data associated with it. For any of these requests, contact us at help@deduptio.com.
Where you use Deduptio to process personal data about your own contacts, you are the data controller and we act as your processor.
Changes
We'll update this page if this policy changes and revise the date above. Material changes will be emailed to account holders.
Contact
Questions about this policy: help@deduptio.com.