Privacy
What we collect, and what we don't
Last updated September 2026. DulyCheck is an early-stage analytical tool, and this notice describes how the current product works today.
Account and property-workspace information
You sign in to a DulyCheck account to save your own properties and use account-based allowances. Authentication is handled by DulyCheck's canonical Supabase project. We store the account identifier needed to keep your saved properties, revisions, plan usage, and billing state tied to the correct account.
You may provide deal figures and assumptions such as price, rent, expenses, financing terms, target return, property type, occupancy, rental strategy, year built, HOA status, rehab plans, inspection status, and optional labels, addresses, and evidence notes. When you save a property, DulyCheck stores the validated inputs, evidence information, validated diligence profile, revision lineage, random report token, and related account and plan-usage information needed to operate the workspace.
Financial calculations and verdicts are rebuilt from validated source inputs rather than trusted simply because a browser submitted them. This reduces the amount of browser-supplied derived data that DulyCheck treats as authoritative.
Uploaded screenshots and PDFs
Authenticated users can submit supported PNG, JPEG, WEBP, and PDF underwriting files for structured transcription, subject to file-size and plan usage limits. The file is sent through a DulyCheck-controlled Supabase Edge Function and then to OpenAI's API so explicitly stated underwriting fields can be transcribed into a structured response for your review.
The current extraction request sets OpenAI's Responses API storage option to false. The current DulyCheck extraction function does not write the uploaded file itself to DulyCheck database tables or file storage. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. OpenAI may still retain customer content in abuse-monitoring logs for a limited period under its then-current API policies unless different approved retention controls apply.
Extraction results can include transcribed values, confidence labels, and short source context. If you accept values and save the property, accepted inputs and evidence context can become part of the saved workspace. Document reading is a transcription aid, not independent verification, and you remain responsible for reviewing the extracted information.
Usage allowances
DulyCheck records account-level usage needed to enforce new-property and AI document-read allowances. Those records can include the account identifier, plan period, usage count, allowance, and timestamps. Usage records are not copies of the property documents or underwriting files themselves.
Saved deals and private links
Your saved properties appear in My Deals. Each saved workspace uses a long random token in its report URL rather than a sequential public ID. Access can depend on account ownership and the workspace's access state. Treat private report links as sensitive and share them only with people you want involved in the diligence process.
Subscriptions and payments
Stripe processes paid Investor and Pro subscriptions and provides the hosted billing tools used for payment-method changes, invoices, eligible plan changes, and cancellation. DulyCheck stores subscription and payment-provider references, plan status, billing-period information, and related entitlement data needed to apply the correct product allowances. Full card numbers and card security codes do not reach or get stored by DulyCheck.
Local Help and third-party links
DulyCheck can generate location-aware search links or later surface third-party providers relevant to diligence, such as inspectors, insurers, lenders, contractors, property managers, attorneys, accountants, agents, or engineers. Following a third-party link can send you to that provider's or directory's service, where its own privacy practices apply.
DulyCheck does not currently transmit your full saved deal to a Local Help provider merely because a search link is shown. If a future referral or integrated-provider workflow sends information to a third party, the product should disclose that transfer at the point it becomes relevant. We do not sell your personal information.
Product metrics and analytics
DulyCheck keeps simple daily aggregate counts of a small fixed set of product actions, such as starting a deal check, reaching key intake steps, saving a property, opening What If, reading a document, or answering a feedback prompt. The aggregate product-metrics table stores the event name, date, and count rather than the underlying deal inputs.
DulyCheck may also use Google Analytics 4 to understand traffic and product usage. The current analytics implementation is designed to send only an allowlisted route path for page-view measurement. It does not intentionally send deal inputs, property addresses, report tokens, URL query strings, card information, uploaded documents, or account email addresses as analytics event parameters. Private report-token and admin routes are excluded from DulyCheck's manual page-view allowlist.
The Google Analytics configuration disables Google Signals and advertising-personalization signals by default. Google Analytics can use cookies or similar browser storage and may process ordinary technical information such as device/browser information, approximate location derived from network information, referrer, and interaction timestamps under Google's then-current analytics terms and policies. DulyCheck does not use this analytics configuration to sell personal information or to build advertising audiences.
Lovable's publishing layer may inject its own browser analytics script into hosted pages. Because DulyCheck private-report URLs contain opaque access tokens, DulyCheck installs an early browser guard that blocks requests to Lovable's reserved analytics endpoint on this site. The guard is narrowly scoped to that endpoint and does not block DulyCheck's Supabase operations or the sanitized Google Analytics configuration described above.
Standard server and platform logs may separately record ordinary request information for reliability, security, debugging, and abuse prevention.
Service providers
Lovable hosts the public application. DulyCheck's canonical Supabase project provides authentication, saved-property data, Edge Functions, entitlement and usage controls, and aggregate product metrics. OpenAI processes supported user-submitted documents for structured transcription. Stripe provides subscription and billing processing. Google Analytics may provide website and product-usage analytics. Google Maps or ordinary web search links may be used when you choose Local Help discovery.
DulyCheck may add additional property-data, public-record, insurance, market, mapping, or professional-service providers as the diligence product expands. Where those providers process user or property information, this notice and the product experience should be updated to reflect the material change.
Security
We use reasonable safeguards, including encrypted transport, authenticated account flows, server-controlled access to saved-property records, and restricted direct browser access to internal database tables. We do not claim a security certification or guarantee that any internet service is perfectly secure. Do not upload information you are not authorized to provide or are not comfortable sending through the current processing providers.
Retention, deletion, and questions
Saved property workspaces and account records can remain stored so the product can preserve your history and revisions. Cancelling a paid subscription does not automatically delete existing saved deals. Self-service account or property deletion is not yet available in the current MVP. If you need account or saved-property data removed, contact DulyCheck support with enough information for us to identify the account or record safely.