Privacy Policy
Last updated: August 4, 2026
This policy explains how data is handled when you use the Dupe Zappa Windows app, website, browser tools, direct-purchase licensing, or support.
Controller
MerginIT e.U.
Jonas Fröller
Nußböckstraße 92
4060 Leonding, Austria
Email: jonas@merginit.com
MerginIT is the controller for personal data it receives and uses for product delivery, licensing, support, security, and its own legal duties. Checkout providers and app stores are separate controllers for their transaction services under their own privacy notices.
Local desktop processing
Dupe Zappa is designed to process your files locally on your Windows device. The app does not include advertising or third-party behavioral analytics, and MerginIT does not sell personal data.
When you select files or folders, the app accesses them to provide duplicate detection, search indexing, disk-usage analysis, junk-file detection, renaming, smart tagging, face grouping, automation, and AI-assisted suggestions. Depending on the enabled features, the app may store settings, selected paths, scan results, metadata, hashes, operation history, search indexes, extracted or OCR text, thumbnails, face embeddings, face groups, and smart tags locally on your device. Dupe Zappa does not send this local library data to MerginIT.
Optional network features
The built-in Ollama integration communicates with the Ollama endpoint you configure, normally on your own device or network. If you configure a custom AI API endpoint, Dupe Zappa sends the context needed for the requested suggestion to that endpoint. The endpoint provider's terms and privacy practices apply. Review the selected content and provider before enabling an external endpoint.
Model downloads, update checks, installer downloads, and optional-tool links may connect to providers such as Microsoft, GitHub, Cloudflare, Hugging Face, Ollama, or an optional tool's publisher. These providers receive ordinary request data such as IP address, URL, time, user agent, and download details under their own policies.
Website and browser tools
The website's hosting, content-delivery, and security providers process standard request data such as IP address, timestamp, requested URL, referrer, user agent, and error or security logs. The website may use Cloudflare hosting, caching, security, and cookie-free performance measurement. This website processing is separate from the desktop app.
The browser tools process selected files and folders in your browser. Depending on the tool, this may include file names, relative paths, contents used for hashing, image fingerprints, metadata, EXIF and GPS metadata, and generated exports. These selected files, names, contents, and results are not uploaded to MerginIT by the browser tools. They stay in your browser unless you choose to download or export them.
Direct purchases and Lemon Squeezy
Lemon Squeezy is the Merchant of Record and authorized reseller for direct Dupe Zappa purchases. It collects and uses customer, billing, payment, tax, device, and fraud-prevention information for checkout, payment, invoicing, tax, refunds, and transaction security as a separate controller. See Lemon Squeezy's Privacy Policy and Buyer Terms.
MerginIT receives the limited order and fulfilment data needed to supply and support the licence. This may include customer name and email, billing country, product and variant, order and customer identifiers, price, currency and tax status, licence or entitlement reference, purchase time, and refund or dispute status. MerginIT does not receive or store full payment-card details.
Microsoft Store purchases
Microsoft processes Microsoft Store purchases, delivery, Store entitlements, billing, refunds, and related security under the Microsoft Privacy Statement. Microsoft Store purchases do not create a separate MerginIT licence key. MerginIT may receive limited information if you provide it when requesting product support.
Licence activation
For direct licences, MerginIT processes the provider licence, order, product, variant, status and activation references; an HMAC-derived value of the licence key; the device public key and its thumbprint; whether the device key is TPM hardware-backed or Windows-protected; app version; activation and validation timestamps; and limited network or security log data such as IP address. The raw licence key is used transiently for provider validation and the encrypted dashboard session, but is not stored in the licensing database.
The device private key remains non-exportable on the PC. Signed offline entitlements identify the Dupe Zappa direct channel, licence and provider instance, device-key thumbprint, enabled features, revocation generation, and issue and expiry times. They expire after no more than seven days. The licence key, provider instance ID and cached entitlement are protected locally with Windows Data Protection API for the current user.
For the 25-group evaluation, MerginIT receives privacy-safe group tokens, reservation and completion state, a device-key thumbprint, and a keyed hash of stable Windows device signals so that reinstalling does not ordinarily reset the allowance. Paths, file names, file contents, file hashes, search indexes, face data, and local scan results are not sent for evaluation or licence enforcement.
Licence dashboard and transfer email
The dashboard accepts a licence key in a POST request and exchanges it for a short-lived, encrypted, secure browser session. It displays a masked purchase email and limited device activation information. To deactivate a PC, it creates a hashed six-digit challenge that expires after ten minutes and allows no more than five attempts. Request and network-source limits help prevent abuse.
MerginIT uses Resend to send transfer codes from license@merginit.com to the purchase email. The email address is encrypted in the licensing database. Resend receives the recipient, message content, sender and ordinary delivery metadata needed to deliver and secure the email.
Affiliate attribution
When the affiliate program is enabled and you arrive through an affiliate link, the site asks before retaining the referral identifier. If you accept, your choice and the identifier are stored in this browser and the identifier is added to a Lemon Squeezy checkout URL. Lemon Squeezy then processes attribution and ordinary checkout data under its privacy policy. If you decline, the identifier is not retained or sent to checkout. You can withdraw the choice by clearing this site's browser storage.
Support communications
When you contact support, MerginIT processes the contact details, message, order references, technical information, and attachments you provide to answer the request and maintain an appropriate support history. Do not send personal files, licence keys, or sensitive content unless support specifically requests an appropriate limited sample.
Purposes and legal bases
- Contract and pre-contract steps: delivery, activation, licence validation, updates, and support.
- Legal obligations: tax, accounting, consumer-rights, fraud-response, and regulatory records.
- Legitimate interests: website and licence security, abuse prevention, diagnostics, service improvement, and legal claims, balanced against your rights.
- Consent: only where a feature or applicable law requires consent; consent may be withdrawn prospectively.
Recipients and international transfers
Recipients are limited to providers needed for hosting, security, downloads, checkout, app-store delivery, licensing, email, support, professional advice, and user-configured services. Some providers may process data outside the European Economic Area. Where MerginIT is responsible for such a transfer, it relies on an adequacy decision, contractual safeguards, or another lawful transfer mechanism as applicable. Provider privacy notices contain further details about their locations and safeguards.
Retention
- Local app data remains until you delete or reset it.
- Entitlement records are kept while the perpetual licence remains valid and as needed to prove, restore, secure, or revoke it.
- Accounting and transaction records are generally retained for the applicable Austrian statutory period, normally seven years, and longer where a pending proceeding requires it.
- Activation, security, and support records are kept only as long as needed for their stated purpose, warranty or claims periods, and legal obligations.
Your rights
Depending on the applicable law, you may request access, correction, deletion, restriction, objection, or portability and may withdraw consent for future processing. These rights can be limited by legal retention or other statutory exceptions. Contact jonas@merginit.com or use the data-request form.
You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
Children and changes
Dupe Zappa is not directed to children. This policy may be updated when the product, providers, or legal requirements change. The current version and its update date will remain available on this page.