Privacy Policy
Last updated: July 20, 2026
This policy explains how data is handled when you use the Dupe Zappa Windows app, website, browser tools, direct-purchase licensing, or support.
Controller
MerginIT e.U.
Jonas Fröller
Nußböckstraße 92
4060 Leonding, Austria
Email: jonas@merginit.com
MerginIT is the controller for personal data it receives and uses for product delivery, licensing, support, security, and its own legal duties. Checkout providers and app stores are separate controllers for their transaction services under their own privacy notices.
Local desktop processing
Dupe Zappa is designed to process your files locally on your Windows device. The app does not include advertising or third-party behavioral analytics, and MerginIT does not sell personal data.
When you select files or folders, the app accesses them to provide duplicate detection, search indexing, disk-usage analysis, junk-file detection, renaming, smart tagging, face grouping, automation, and AI-assisted suggestions. Depending on the enabled features, the app may store settings, selected paths, scan results, metadata, hashes, operation history, search indexes, extracted or OCR text, thumbnails, face embeddings, face groups, and smart tags locally on your device. Dupe Zappa does not send this local library data to MerginIT.
Optional network features
The built-in Ollama integration communicates with the Ollama endpoint you configure, normally on your own device or network. If you configure a custom AI API endpoint, Dupe Zappa sends the context needed for the requested suggestion to that endpoint. The endpoint provider's terms and privacy practices apply. Review the selected content and provider before enabling an external endpoint.
Model downloads, update checks, installer downloads, and optional-tool links may connect to providers such as Microsoft, GitHub, Cloudflare, Hugging Face, Ollama, or an optional tool's publisher. These providers receive ordinary request data such as IP address, URL, time, user agent, and download details under their own policies.
Website and browser tools
The website's hosting, content-delivery, and security providers process standard request data such as IP address, timestamp, requested URL, referrer, user agent, and error or security logs. The website may use Cloudflare hosting, caching, security, and cookie-free performance measurement. This website processing is separate from the desktop app.
The browser tools process selected files and folders in your browser. Depending on the tool, this may include file names, relative paths, contents used for hashing, image fingerprints, metadata, EXIF and GPS metadata, and generated exports. These selected files, names, contents, and results are not uploaded to MerginIT by the browser tools. They stay in your browser unless you choose to download or export them.
Direct purchases and Lemon Squeezy
Lemon Squeezy is the Merchant of Record and authorized reseller for direct Dupe Zappa purchases. It collects and uses customer, billing, payment, tax, device, and fraud-prevention information for checkout, payment, invoicing, tax, refunds, and transaction security as a separate controller. See Lemon Squeezy's Privacy Policy and Buyer Terms.
MerginIT receives the limited order and fulfilment data needed to supply and support the licence. This may include customer name and email, billing country, product and variant, order and customer identifiers, price, currency and tax status, licence or entitlement reference, purchase time, and refund or dispute status. MerginIT does not receive or store full payment-card details.
Microsoft Store purchases
Microsoft processes Microsoft Store purchases, delivery, Store entitlements, billing, refunds, and related security under the Microsoft Privacy Statement. Microsoft Store purchases do not create a separate MerginIT licence key. MerginIT may receive limited information if you provide it when requesting product support.
Licence activation
For direct licences, MerginIT processes the licence or entitlement reference, activation status, a device identifier created for licensing, app version, activation and validation timestamps, and limited network or security log data such as IP address. This is used to activate one device per licence, permit legitimate device moves, prevent abuse, troubleshoot activation, and keep entitlements synchronized after refunds or disputes. File names, file contents, search indexes, face data, and local scan results are not part of licence activation.
Support communications
When you contact support, MerginIT processes the contact details, message, order references, technical information, and attachments you provide to answer the request and maintain an appropriate support history. Do not send personal files, licence keys, or sensitive content unless support specifically requests an appropriate limited sample.
Purposes and legal bases
- Contract and pre-contract steps: delivery, activation, licence validation, updates, and support.
- Legal obligations: tax, accounting, consumer-rights, fraud-response, and regulatory records.
- Legitimate interests: website and licence security, abuse prevention, diagnostics, service improvement, and legal claims, balanced against your rights.
- Consent: only where a feature or applicable law requires consent; consent may be withdrawn prospectively.
Recipients and international transfers
Recipients are limited to providers needed for hosting, security, downloads, checkout, app-store delivery, licensing, email, support, professional advice, and user-configured services. Some providers may process data outside the European Economic Area. Where MerginIT is responsible for such a transfer, it relies on an adequacy decision, contractual safeguards, or another lawful transfer mechanism as applicable. Provider privacy notices contain further details about their locations and safeguards.
Retention
- Local app data remains until you delete or reset it.
- Entitlement records are kept while the perpetual licence remains valid and as needed to prove, restore, secure, or revoke it.
- Accounting and transaction records are generally retained for the applicable Austrian statutory period, normally seven years, and longer where a pending proceeding requires it.
- Activation, security, and support records are kept only as long as needed for their stated purpose, warranty or claims periods, and legal obligations.
Your rights
Depending on the applicable law, you may request access, correction, deletion, restriction, objection, or portability and may withdraw consent for future processing. These rights can be limited by legal retention or other statutory exceptions. Contact jonas@merginit.com or use the data-request form.
You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
Children and changes
Dupe Zappa is not directed to children. This policy may be updated when the product, providers, or legal requirements change. The current version and its update date will remain available on this page.