Privacy Policy

This Privacy Policy explains what account and usage data Startup Due Dil collects, and how private workspace content is processed to provide AI due diligence reports.

Last updated: June 25, 2026

Operator and contact

Startup Due Dil is operated as an independent sole entrepreneur project under the Startup Due Dil brand. Privacy contact: [email protected].

Account and access data

We collect account email, role, approved/blocked access status, monthly report limit, first and last seen timestamps, last IP address, browser/device request metadata, run counts, and a marketing opt-in flag.

Private workspace content

Client-provided diligence materials, comments or links, investor mandate context, generated reports, report artifacts, report chat, and related run inputs are private workspace content. The app stores and processes this content under the report owner's account only to run diligence, generate outputs, support report chat, and allow owner-controlled deletion. This content is not collected into the admin account/usage dashboard.

Usage metadata

We collect admin-visible usage metadata such as run ID, user email, run status, selected AI modules/agents, run duration, estimated token/cost totals, report read time, Ask DD question counts, and Ask DD routing agents.

Billing data

The app does not currently collect payment card details. If paid checkout is enabled, payment details are handled by Paddle or another payment provider, and Startup Due Dil may receive only the billing or plan metadata needed to manage access, invoices, support, refunds, and subscription status.

Why we process data

We process data to authenticate users, run due diligence workflows, generate reports, manage quotas, provide support, improve reliability, prevent abuse, maintain security, manage marketing preferences, and manage billing if payments are enabled.

AI providers

Due diligence runs may send relevant private workspace content and prompts to AI model providers such as OpenAI and Anthropic for temporary processing needed to generate outputs.

Infrastructure and processors

The service may use Cloudflare for access/security, DigitalOcean for hosting, GitHub for deployment, and Paddle for payments when monetization is enabled.

Admin-visible data

Admin views are designed to show account/access records and usage metadata only: email, role, approved/blocked status, monthly limit, run counts, first/last seen timestamps, last IP address in CSV exports, run ID/status, selected AI modules/agents, run duration, estimated tokens/cost, report read time, Ask DD question counts, and Ask DD routing agents. Admin dashboards do not link to or display private workspace content.

Report visibility

Private workspace content and reports are intended to be visible only to the account that created them. Owner checks block other client accounts and admins from opening, downloading, chatting with, or deleting a client report unless that admin account is also the report owner.

Retention and deletion

Users can delete due diligence runs from the app. Deletion removes the local run folder, generated report, run inputs, report artifacts, and related chat uploads from Startup Due Dil's application storage.

Security

Startup Due Dil uses private access controls, hidden session paths, owner-only report access, HTTPS through Cloudflare, and deletion controls. No online system can be guaranteed perfectly secure.

Your choices

You may request deletion or export of your personal data by contacting support.