Privacy Policy
Dupely · Effective 31 August 2026
Dupely is a mobile app that identifies a product from a photo or a typed name and suggests cheaper alternatives. This page describes everything the app and its server collect, why, and how to get rid of it. It is written to be read, not to be survived.
There is no account
Dupely has no sign-up, no login and no password. It never asks for your name, email address, phone number, date of birth or address, and there is no way to give them to it.
When you first open the app it generates a random identifier — a UUID — and stores it in the device’s secure storage. That identifier is what keeps your scan history yours and what counts your free scans. It is not derived from anything about you or your device: it is a random number. If you delete the app, it is gone, and reinstalling produces a new one with no way to connect the two.
What we collect
| Data | Why | How long |
|---|---|---|
| The photo you scan | It is sent to an analysis provider so the product in it can be identified. | Kept at most 7 days, then deleted automatically. |
| The text you type into the search field or the Ask box | Same: it is the question being answered. | Stored with the scan until you delete it. |
| The result — product name, attributes, suggested alternatives | So your history and your saved dupes are there when you come back. | Stored with your device identifier until you delete it. |
| Your anonymous device identifier | To keep your history yours, count free scans, apply rate limits and check your subscription. | Until you delete your data or the app. |
| Your chosen language and coarse technical facts about the request | To answer in your language and to keep aggregate counts of how the app is used. | Stored with the scan. |
| Subscription status | To know whether this device has Dupely Pro. | For as long as the subscription and its record exist. |
We do not collect contacts, location, health data, browsing history or advertising identifiers. Dupely contains no advertising and no third-party analytics or attribution SDK, and it does not track you across other companies’ apps or websites.
Photos
Before anything is uploaded, the phone downsizes your photo to at most 1024 pixels on its longest side and re-encodes it as a JPEG. That re-encode discards the EXIF metadata the camera wrote, including GPS coordinates.
The reduced image is then uploaded to our server and passed to the analysis provider that identifies it. Depending on how the service is configured, the file is held either by our image storage provider or by the analysis provider, in both cases with an expiry of no more than 7 days, after which it is deleted. Deleting your data in the app deletes the stored photo straight away rather than waiting for the expiry.
Photos are used to answer your scan and to serve a cached answer if the same photo is scanned again. They are not used to train models, and they are not shown to anyone else.
Who processes your data
These are the companies involved, and what each one sees:
- OpenRouter, Inc. and/or EachLabs — the analysis providers. They receive the photo or the typed query and the language you want the answer in. Which one is used depends on how the service is configured at the time; both may be involved as one falls back to the other.
- MongoDB, Inc. (MongoDB Atlas, European Union region) — the database that holds your scans, results and device identifier.
- RevenueCat, Inc. — subscription infrastructure, from the point purchases go live. It receives your anonymous device identifier and the purchase receipt so entitlement can be verified. It never receives your photos.
- Cloudinary Ltd. — image storage, when the service is configured to use it rather than the analysis provider’s own storage. It receives the photo and nothing else.
- Apple (and Google, on Android) — the app stores. They handle the payment itself; we never see your card details.
Currency conversion uses the European Central Bank’s published daily reference rates, fetched by our server. No data about you is sent in that request.
Data may be processed in countries outside your own, including the United States, because that is where some of these providers operate.
Deleting your data
Open Settings → Delete my data in the app and confirm. That removes every scan made from this device, the results, and the stored photos — from our database and from the image storage — and it cannot be undone. You do not need to contact us and there is nothing to prove: the device identifier is the only key.
Deleting the app without doing this leaves the records behind, keyed to an identifier that no longer exists anywhere; they are of no use to anybody, but if you want them gone, delete your data first. You can also write to support@mirai.app and ask.
Your rights
Depending on where you live you may have the right to access, correct, export or erase your data, and to object to its processing. Because there is no account, the practical route for all of these is the delete button above, or an email to support@mirai.app. Be aware that without your device identifier we have no way to find your records, so include what you can.
Subscriptions
Dupely Pro is an auto-renewing subscription sold through Apple. It renews automatically unless you turn off auto-renewal at least 24 hours before the period ends, in the iOS Settings app → your name → Subscriptions. The Terms of Use cover this in full.
Children
Dupely is not directed at children and we do not knowingly collect data from anyone under 13.
Security
Traffic between the app and our server is encrypted in transit. Data at rest is held by the providers listed above under their own security arrangements. No system is perfect, and we would rather say so than promise otherwise.
Changes
If this policy changes materially, the effective date at the top changes and the new version is published here before it takes effect.
Contact
Dupely is not affiliated with, endorsed by, or sponsored by any brand it identifies or suggests.