Privacy Policy
Effective September 24, 2026
This policy describes how dupy handles information on dupy.app, in the dupy workspace at studio.dupy.app and through dupy's MCP connection. dupy is currently in early access and is used only by people the workspace owner has invited.
Who handles your information
dupy is operated by 디스틸 (Distill), a business in South Korea (business registration 271-04-03553). The representative and privacy officer is 박성일 (Seongil Park). Contact details are at the end of this policy.
What we collect and how we use it
Sign-in and access
- Google sign-in. When you sign in, Google sends us a signed token. We check it and use only your verified email address to decide whether you have access. Google may show your name and profile photo on its sign-in screen, but dupy does not store them. dupy never receives your Google password.
- Session cookie. After sign-in we set one signed, HttpOnly cookie that contains your email address and expires after 24 hours or when you sign out.
- Team access list. When the workspace owner grants access, we store the invited email address, who added it and when.
- MCP connections. If you connect an AI client to dupy over MCP, we store the client's name and redirect addresses, and hashed authorization codes and tokens linked to your email address. Codes expire after 5 minutes, access tokens after 1 hour and refresh tokens after 30 days.
Content you create in the workspace
- Projects, topics, search keywords, themes, followed channels, review decisions and saved references.
- Studio workflows, productions, scripts, edits and the video, image, voice and music files generated for them.
- Personas and the media you attach to them, such as names, descriptions, face or style images and voice samples, and files you upload to the media library. Only upload images or voices of people who have agreed to that use.
We use this content to run the features you ask for: finding and analysing videos, and producing and rendering new ones.
Ask dupy conversations
Ask dupy saves your conversations in the workspace database, linked to your email address, so you can reopen them from any browser. A saved conversation includes your messages, the images you attach, the assistant's replies, the tools it ran with their results, and the project and topic you were viewing. Large images are reduced in size before they are sent and saved. Other members of the workspace cannot see your conversations in dupy.
When you send a message, the conversation so far and the relevant workspace context pass through our server to an AI model provider (via OpenRouter) to produce the reply. We use saved conversations to show you your history, and we look at them only when you ask for help, to investigate abuse or a security problem, or when the law requires it. You can delete a conversation from the chat list at any time, which removes it from the database.
Public short-form content we collect
To show what is performing in a topic, dupy collects publicly available information from TikTok, Instagram and YouTube through data providers (TikHub and the YouTube Data API). This includes video links, captions and hashtags, public view and engagement counts over time, creator handles and channel names, public channel statistics and music details. For videos selected for analysis we keep a private copy of the video, audio, captions and cover image, and produce a transcript and a structural analysis. This content can include creators' names, faces and voices. We process it to research formats and trends. We do not use it to identify or contact creators. Creators can ask us to remove their content from dupy using the contact details below.
Technical information
Our hosting and security providers process IP addresses, request times, requested addresses, browser information and response codes to deliver and protect the service.
Browser storage
Besides the session cookie, dupy stores a few settings in your browser: your interface language, the last topic you opened, a cached copy of the dashboard for faster loading and which Ask dupy conversation you had open. dupy does not use advertising or analytics cookies.
Support
If you email us, we receive your email address and the contents of your message.
How long we keep it
- Session cookies: 24 hours. MCP codes and tokens: until they expire as described above.
- Team access: until the workspace owner removes the email address.
- Ask dupy conversations: until you delete them, until you ask us to delete them, or until the service ends.
- Workspace content, collected content and generated files: until they are deleted in the workspace, until you ask us to delete them, or until the service ends.
- Support emails: as long as needed to resolve your request.
- Where Korean law requires us to keep a record for a set period, we keep it for that period only.
When information is no longer needed, we delete electronic files so they cannot be restored.
Who processes it for us
We do not sell personal information and do not share it with third parties for their own purposes. We use the service providers below to run dupy. They process information on our instructions.
| Provider | Location | What they do |
|---|---|---|
| Vercel Inc. | USA (service functions run in Seoul, South Korea) | Hosts dupy.app and studio.dupy.app, verifies sign-in and keeps request logs |
| Google LLC (Google Cloud) | South Korea (Seoul) for the API, background jobs and private media storage | Runs the dupy API, collection and Studio jobs; stores collected media, uploads and generated files; provides Google Sign-In |
| Google LLC (Vertex AI) | USA | Generates video, images and music for Studio from your prompts and, when you choose them, your persona images |
| ChiselStrike, Inc. (Turso) | Japan (Tokyo) | Hosts the workspace database: team access list, sign-in tokens for MCP clients, projects, collected video records, Studio records and Ask dupy conversations |
| OpenRouter, Inc. | USA; requests are routed to the selected model provider | Transcribes and analyses collected videos, writes Studio scripts and answers Ask dupy messages |
| Features & Labels, Inc. (fal) | USA | Generates persona voices and videos when a Studio step uses MiniMax models, using the persona images and voice samples you provide |
| Cloudflare, Inc. | USA | Provides DNS for dupy.app and forwards email sent to help@dupy.app |
Transfers outside South Korea
Using dupy transfers information to the providers above in the USA and Japan over encrypted network connections, at the time you use each feature. The items transferred are the ones described for each provider: your email address and sign-in tokens, workspace content, messages and uploads you send for processing, collected content and request logs. They are kept for the periods in this policy. You can avoid a transfer by not using the feature that requires it, for example Ask dupy or a Studio step. Because sign-in and hosting need these providers, you cannot use dupy without the transfer to Vercel and Google.
Your rights
You can ask to access, correct, delete or stop the processing of your personal information, and ask for a copy. Email us from the address you use with dupy and we will answer within 10 days. If we cannot fully meet a request, for example because the law requires us to keep a record, we will explain why. Team members can also ask the workspace owner to remove their access.
How we protect it
- All connections use HTTPS. Session cookies are signed, HttpOnly and limited to our own site.
- MCP authorization codes and tokens are stored only as hashes.
- Collected media and uploads are kept in a private storage bucket. Service accounts get only the access they need, and API keys are kept in a secrets manager.
- Access to the workspace requires a verified Google account on the access list.
Children
dupy is a tool for businesses and creators and is not intended for anyone under 14. We do not knowingly collect information from children.
Changes
We will update this policy when dupy changes how it handles information and will show the new effective date here. For material changes we will also tell users in the workspace before the change applies.
Contact and privacy officer
Privacy officer: 박성일 (Seongil Park).
- Email: help@dupy.app
- Business phone: +82 70 8065 1516 (South Korea)
- Written inquiries: 디스틸 (Distill), Unit 228, 2F, 19 Teheran-ro 20-gil, Gangnam-gu, Seoul, South Korea
If you are in South Korea and need further help, you can also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).