Privacy Policy
This Privacy Policy explains what account and usage data Startup Due Dil collects, and how private workspace content is processed to provide AI due diligence reports.
Last updated: June 25, 2026
Operator and contact
Startup Due Dil is operated as an independent sole entrepreneur project under the Startup Due Dil brand. Privacy contact: [email protected].
Account and access data
We collect account email, role, approved/blocked access status, monthly report limit, first and last seen timestamps, last IP address, browser/device request metadata, run counts, and a marketing opt-in flag.
Private workspace content
Client-provided diligence materials, comments or links, investor mandate context, generated reports, report artifacts, report chat, and related run inputs are private workspace content. The app stores and processes this content under the report owner's account only to run diligence, generate outputs, support report chat, and allow owner-controlled deletion. This content is not collected into the admin account/usage dashboard.
Usage metadata
We collect admin-visible usage metadata such as run ID, user email, run status, selected AI modules/agents, run duration, estimated token/cost totals, report read time, Ask DD question counts, and Ask DD routing agents.
Billing data
The app does not currently collect payment card details. If paid checkout is enabled, payment details are handled by Paddle or another payment provider, and Startup Due Dil may receive only the billing or plan metadata needed to manage access, invoices, support, refunds, and subscription status.
Why we process data
We process data to authenticate users, run due diligence workflows, generate reports, manage quotas, provide support, improve reliability, prevent abuse, maintain security, manage marketing preferences, and manage billing if payments are enabled.
AI providers
Due diligence runs may send relevant private workspace content and prompts to AI model providers such as OpenAI and Anthropic for temporary processing needed to generate outputs.
Infrastructure and processors
The service may use Cloudflare for access/security, DigitalOcean for hosting, GitHub for deployment, and Paddle for payments when monetization is enabled.
Admin-visible data
Admin views are designed to show account/access records and usage metadata only: email, role, approved/blocked status, monthly limit, run counts, first/last seen timestamps, last IP address in CSV exports, run ID/status, selected AI modules/agents, run duration, estimated tokens/cost, report read time, Ask DD question counts, and Ask DD routing agents. Admin dashboards do not link to or display private workspace content.
Report visibility
Private workspace content and reports are intended to be visible only to the account that created them. Owner checks block other client accounts and admins from opening, downloading, chatting with, or deleting a client report unless that admin account is also the report owner.
Retention and deletion
Users can delete due diligence runs from the app. Deletion removes the local run folder, generated report, run inputs, report artifacts, and related chat uploads from Startup Due Dil's application storage.
Security
Startup Due Dil uses private access controls, hidden session paths, owner-only report access, HTTPS through Cloudflare, and deletion controls. No online system can be guaranteed perfectly secure.
Your choices
You may request deletion or export of your personal data by contacting support.