DeDuplicate

Privacy Policy

Latest update: August 27, 2026

Applicability: This Privacy Policy applies to DeDuplicate version 3.0 and later. For versions prior to 3.0, please refer to the previous Privacy Policy.

Scope of this Privacy Policy

This Privacy Policy explains how DeDuplicate and the website deduplicate.app handle personal data. DeDuplicate is designed primarily as a locally installed application: cloud-storage files and metadata used for scanning, duplicate detection and file-management features are processed on the user's device rather than on DeDuplicate-operated servers.

This policy applies to the DeDuplicate application on its supported platforms, the deduplicate.app website, support communications, optional diagnostics, and the limited online services used to operate and license the application.

Owner and Data Controller

Paolo Pugliese

Partita IVA: 03818490363

Email: support@deduplicate.app

Summary of DeDuplicate's data-handling approach

  • Cloud-storage data is accessed only after the user explicitly connects a cloud account.
  • DeDuplicate does not use an application server to proxy, inspect, store or process the contents of connected cloud-storage accounts.
  • Cloud file data, metadata and data derived from them are processed locally on the user's device for the requested features.
  • Cloud account credentials and access tokens are not sent to DeDuplicate-operated analytics, diagnostics or application servers.
  • DeDuplicate does not sell cloud-storage data and does not use it for advertising, marketing, profiling, or training artificial-intelligence models.
  • Optional remote diagnostics are deliberately limited to technical application information and are designed not to contain cloud file content, cloud file metadata, cloud account credentials, provider payloads, or data derived from cloud files.

Data processed by the DeDuplicate application

Cloud account information

When the user connects a supported cloud-storage service, DeDuplicate may access basic account information made available by that provider, such as an account identifier, name, email address or profile image. This information is used only to identify the connected account inside the application and to provide the requested cloud-storage functionality.

Cloud files, folders and metadata

To identify duplicate files and provide file-management features, DeDuplicate may access data made available by the selected cloud provider, including file and folder identifiers, names, parent relationships and paths, file types, sizes, creation and modification dates, provider checksums, links and thumbnail information.

Where a user-facing feature requires access to file content, DeDuplicate may also read file data directly from the cloud provider on the user's device. For example, a feature may read part or all of a file locally in order to compare content or calculate a local fingerprint or checksum. Such content and derived values remain on the user's device unless the user explicitly chooses to export or share them outside the application.

Local storage

Data retrieved from connected cloud services is stored locally only to the extent necessary for DeDuplicate features, such as account information, scan snapshots, duplicate groups, deletion or restore history, and local application state.

Authentication credentials and OAuth tokens are stored using secure storage mechanisms provided by the operating system or platform where available. DeDuplicate also applies application-level security measures to its local data stores where supported.

Local application data remains under the user's control. It can be removed using the relevant application controls or by removing the application, subject to operating-system backup, restoration or synchronization mechanisms that are outside the Owner's control.

Connected cloud-storage services

DeDuplicate currently supports connections to the following services:

These integrations are not activated automatically. The user must explicitly connect an account and authorize DeDuplicate according to the authorization process provided by the relevant cloud service.

DeDuplicate communicates directly from the user's device with the APIs or download endpoints of the selected cloud provider. The Owner does not operate an intermediary cloud-processing server for these integrations.

Google Drive and Google user data

Why DeDuplicate requests Google Drive access

DeDuplicate needs access to the user's existing Google Drive files in order to scan the selected Drive content, identify duplicate files and, when requested by the user, perform file-management actions such as moving selected duplicate files to or from the trash. Access is requested only after an explicit user action.

Local-only processing of Google Drive data

Google Drive data is transferred directly between Google services and the DeDuplicate application running on the user's device. DeDuplicate does not send Google Drive user data through a DeDuplicate-operated server or any other third-party server for scanning, duplicate detection, matching, storage or file management.

In particular, Google Drive file content, file and folder identifiers, names, paths, metadata, checksums, thumbnails, links, locally calculated fingerprints or hashes, and other data obtained from or derived from Google Drive are not transmitted to Sentry, analytics services, DeDuplicate-operated application servers, advertising services, or other third parties.

Google OAuth credentials, access tokens and refresh tokens are likewise not transmitted to DeDuplicate-operated analytics or diagnostics services. They are used on the device solely to authenticate requests to Google and are stored using the secure storage mechanisms available on the platform.

Limited use of Google user data

DeDuplicate uses Google user data only to provide or improve user-facing functionality that the user has requested. Google user data is not used for advertising, marketing, user profiling, credit or eligibility decisions, or artificial-intelligence model training.

DeDuplicate handles information received from Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

Google account access and revocation

Users can remove a Google Drive account from DeDuplicate using the application's account controls. Users can also review or revoke DeDuplicate's Google authorization from their Google Account security and third-party access settings. Revoking access prevents DeDuplicate from making further authorized Google Drive API requests until the account is connected again.

Diagnostics and crash reporting

DeDuplicate may offer optional crash reporting and diagnostic reporting through Sentry. Automatic crash reporting is disabled unless the user enables it. A user may also explicitly choose to submit a diagnostic report when the application offers that option.

Remote diagnostic reports are intentionally restricted to application-controlled technical information that may include the application version, platform, stack information, a coarse error category, operation type, status code, or aggregate failure counts. The diagnostic system is designed so that cloud-provider data and credentials are not valid remote telemetry payloads.

DeDuplicate does not intentionally transmit cloud file content, filenames, paths, cloud file or folder identifiers, checksums, thumbnails, cloud-provider response payloads, OAuth credentials, or cloud-account tokens to Sentry. Network infrastructure used by Sentry may necessarily process ordinary connection metadata such as an IP address when a report is transmitted.

Provider: Sentry — Privacy Policy.

User-submitted support information

If a user contacts the Owner by email or another support channel, the Owner processes the information that the user chooses to provide, such as the email address, message content and attachments, for the purpose of responding to the request, diagnosing the reported problem and maintaining necessary support records.

DeDuplicate does not automatically attach cloud files or cloud-storage metadata to support communications. If a user intentionally includes such information in an email, screenshot or other attachment, that information is processed as part of the support request at the user's direction.

Application update and news checks

The application may contact deduplicate.app to retrieve application news or version information. The application sends only limited technical information required for this request, such as the application platform. The endpoint is not used to upload cloud-storage information.

As with ordinary web requests, the server or hosting infrastructure may process connection data such as IP address, request time, protocol information and other standard server-log data for security, troubleshooting and service operation.

Purchases, subscriptions and licensing

Purchases and subscriptions are handled by the relevant application store and, on supported platforms, by RevenueCat for purchase-entitlement and subscription-status management. Depending on the platform, this may involve Apple App Store, Google Play, Microsoft Store and RevenueCat.

The Owner does not receive users' complete payment-card details from these services. Purchase providers may process identifiers, transaction records, subscription status, product identifiers, device or platform information and related data according to their own policies. Cloud-storage files and metadata are not sent to RevenueCat for purchase processing.

Website data and cookies

Server logs

When a user visits deduplicate.app, the hosting and web-server infrastructure may process technical connection data necessary to deliver and secure the website, such as IP address, request date and time, requested URL, response status, browser or user-agent information and similar server-log data.

The website stores a cookie preference indicating whether the user has accepted or refused optional tracking. This preference is necessary to remember the user's choice.

Google Tag Manager and website analytics

The website may use Google Tag Manager to load analytics tags, including Google Analytics. These optional analytics tools are initialized only after the user gives consent through the website's cookie banner. If consent is refused, DeDuplicate does not intentionally initialize those optional Google tracking tags.

Analytics services may process information such as IP address, browser and device information, approximate location derived from IP address, page views, navigation events and cookie or similar identifiers according to Google's policies and the user's Google settings.

Users can withdraw consent for optional website analytics by clearing or changing the website's cookie preference where the relevant control is available, or by clearing site cookies and refusing optional tracking when prompted again.

The Owner processes personal data only where there is an appropriate legal basis. Depending on the context, these bases include:

  • Performance of a contract or steps requested by the user: providing the application, connected-account features, support, licensing and purchase-related functionality.
  • Consent: optional website analytics and optional remote crash reporting where consent or an affirmative user choice is required.
  • Legitimate interests: securing and maintaining the website and application infrastructure, preventing abuse, troubleshooting technical failures and keeping the service operational, provided those interests are not overridden by the user's rights and freedoms.
  • Legal obligations: retaining records or disclosing information where required by applicable tax, accounting, consumer-protection, judicial or regulatory obligations.

Most cloud-storage data used by DeDuplicate is processed locally on the user's device and is not received by the Owner. The descriptions above explain the local processing performed by the application even where the Owner does not receive a remote copy of that data.

Data sharing and disclosure

The Owner does not sell or rent personal data. Personal data may be disclosed only where necessary for the purposes described in this policy, including to service providers used for hosting, diagnostics, analytics after consent, purchase processing or support infrastructure, or where disclosure is required by law.

Cloud-storage content and metadata accessed by DeDuplicate are not disclosed to those service providers as part of DeDuplicate's normal cloud scanning and duplicate-detection operation.

International data transfers

Some service providers identified in this policy may process data outside the European Economic Area, including in the United States. Where the GDPR requires safeguards for an international transfer, the Owner relies on the transfer mechanisms and contractual safeguards made available by the relevant provider and applicable law.

Users can consult the privacy documentation of each provider linked in this policy for more information about processing locations and transfer mechanisms.

Data retention

  • Cloud-storage data processed by the app: retained locally only for as long as needed for the user's chosen application features or until removed through the application or device controls.
  • Cloud credentials: retained locally while the relevant account remains connected or as otherwise required to maintain the authorized session, and removed or rendered unusable when the account is disconnected or authorization is revoked according to the provider's mechanisms.
  • Diagnostic data: retained according to the configuration and retention periods of the diagnostic service, only when remote diagnostics are enabled or explicitly submitted.
  • Website/server logs: retained only as long as reasonably necessary for security, reliability, troubleshooting and legal obligations.
  • Support communications: retained for as long as reasonably necessary to handle the request, maintain support history, establish or defend legal claims, or comply with legal obligations.
  • Transaction and accounting records: retained for the periods required by applicable tax, accounting and commercial law.

Data handled independently by cloud providers, application stores, Sentry, RevenueCat, Google Analytics or other third-party services is subject to those providers' own retention policies.

Security measures

The Owner applies technical and organizational measures appropriate to the nature of the service and the data involved. These measures include data minimization, direct device-to-provider communication for cloud integrations, secure handling of authentication credentials, local storage protections, restricted remote diagnostic schemas and measures intended to prevent cloud-provider data from entering analytics or diagnostics systems.

No system can be guaranteed to be completely secure. Users are responsible for protecting access to their devices and cloud-service accounts and should use the security features offered by their operating system and cloud providers.

User rights under the GDPR

Where the GDPR applies and the Owner processes the user's personal data, the user may have the right to:

  • obtain confirmation as to whether personal data is being processed and request access to it;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data where the applicable legal conditions are met;
  • request restriction of processing where the applicable legal conditions are met;
  • object to processing based on legitimate interests;
  • withdraw consent at any time for processing based on consent, without affecting prior lawful processing;
  • receive data in a structured, commonly used and machine-readable format where the right to data portability applies;
  • lodge a complaint with a competent supervisory authority.

In Italy, the competent supervisory authority is the Garante per la protezione dei dati personali.

Requests concerning data processed by the Owner can be sent to support@deduplicate.app. The Owner may need to verify the identity of the requester before acting on a request.

Because cloud-storage data is generally stored only on the user's device and is not held by the Owner, the Owner may not possess a server-side copy that can be accessed, corrected or deleted. In those cases, the relevant application/device controls or the cloud provider's own controls should be used.

Automated processing

DeDuplicate automatically analyzes technical file information in order to identify possible duplicates. This automated processing is part of the service requested by the user and is not used to make decisions that produce legal or similarly significant effects about the user.

Children

DeDuplicate is a general-purpose file-management utility and is not specifically directed to children. The Owner does not knowingly use the application or website to solicit personal data from children for marketing or profiling purposes.

The Owner may process or disclose personal data where reasonably necessary to comply with a binding legal obligation, court order or lawful request from a competent authority, or to establish, exercise or defend legal claims and protect the security and rights of the Owner, users or third parties.

Changes to this Privacy Policy

This Privacy Policy may be updated when DeDuplicate's functionality, data practices, service providers or legal requirements change. The current version and its latest-update date will be published on this page.

If a change materially affects processing that relies on user consent, a new consent will be requested where required by applicable law.

Contact

Questions about this Privacy Policy or DeDuplicate's handling of personal data can be sent to: support@deduplicate.app.