DupliPage Privacy Policy

Last updated: 24 September 2026

1. About this policy

DupliPage lets you capture a copy of a webpage, edit and review its copy with other people, and run localization quality checks. It has two parts: the web service at duplipage.com and the DupliPage Chrome extension. This policy covers both, and describes how the software actually works today.

DupliPage is an independent service operated from Italy. The controller of the personal information described in this policy is the operator of the DupliPage service and can be contacted at privacy@duplipage.com.

DupliPage has no paid plans at the moment, so we handle no payment or billing information.

2. What DupliPage collects, and when

Before you invoke DupliPage on a page

The extension's page components are available on the websites you visit so DupliPage can respond when you use it. Before you invoke DupliPage on a page, neither that page's content nor its address is sent to DupliPage merely because you visited it. DupliPage does not collect your Chrome browsing history, and it never takes screenshots.

When you open the extension popup

Opening the popup checks with duplipage.com whether you are signed in and what you can do. If you are signed in, the extension receives your account name, email address and account identifier: your email is shown in the popup so you can see which account you are using, and your account identifier can be stored with a draft on your device so the draft stays attached to the right account.

If you are signed in, opening the popup also sends the address of the tab you opened it on, so DupliPage can show you the Duplis you have already created for that page. This happens when you open the popup, which may be before you capture anything. It is current-page context for a feature you invoked on that tab, not a record of your browsing.

When you start a session on a page

Starting a session does not upload the page. DupliPage receives the page's address, the account or task context that applies, and the site-specific editing information needed to make editing work on that site.

When you create a Dupli or upload a revision

This is the step where page content is sent to DupliPage, and only because you asked for it. We may receive:

  • the captured HTML of the page and its visible text, including the links and attributes present in that capture;
  • the page title and the address of the page;
  • your original and edited copy, and the information needed to locate each change on the page;
  • page-summary details (headings and meta description or keywords) where that feature is used;
  • localization issues you reported, and where they were found;
  • viewport and reconstruction details, so the copy can be displayed faithfully;
  • a Dupli password, if you choose to protect the Dupli with one.

Before a capture is sent, scripts and other executable behaviour are removed or neutralised so the copy is a static document. No screenshots are taken, and DupliPage has no feature that records what you type into a page's forms.

A captured page contains whatever that page was displaying at the moment you captured it, which can include confidential information or personal information about other people. Please capture only pages you are entitled to share for review.

Editing issue reports

If DupliPage cannot edit something on a page, you can send us a report. This is always explicit: you select the element and press Submit. A report contains a reduced form of the page address (site and path only), the page title, your note, the content you selected and the text around it, and the limited technical detail about that element and your browser that we need to diagnose the problem.

Drafts

While you edit, your work is saved as a draft in the extension on your device: the page address and title, your tracked changes and the markup fragments involved, viewport and synchronisation details, and your account identifier where needed. A draft never contains a full copy of the page. Drafts you discard are removed after 7 days. If you are signed in, a draft with unsaved work can be synchronised to your DupliPage account so you can pick it up elsewhere; that synchronised copy likewise contains no full copy of the page.

Your account and your team's work

The service stores your name, email address and account details, and a salted hash of your password; workspace, team and task membership, roles and invitations; your Duplis and their revisions, comments and activity history; reported localization issues; drafts synchronised to your account; feedback and waiting-list details you choose to submit; records of the service emails we send; and security and administrator-access records.

Passwords

The extension never receives your DupliPage account password. Account passwords are stored on our servers only as salted hashes. A Dupli password is a different thing: it protects the contents of one Dupli, and the extension does handle it. It can be generated for you or typed by you, held briefly while you finish creating the Dupli, sent to DupliPage, copied to your clipboard when you ask, and saved to your computer as a plain-text credentials file if you choose that option. On our servers, Dupli passwords are also stored only as salted hashes.

3. How we use information

We process information where it is necessary to provide the service you asked for: your account, your Duplis and revisions, collaboration in workspaces and tasks, drafts, and the notifications and emails that keep the people involved informed.

We rely on our legitimate interests to keep the service secure and prevent abuse, to diagnose faults, to improve DupliPage using the diagnostics and feedback you explicitly submit, and to allow the administrator access described below, which is recorded.

We process information where we need to in order to meet legal obligations, including handling privacy requests. Where we ask for your consent, for example for optional communications, you can withdraw it at any time by writing to privacy@duplipage.com.

DupliPage does not sell personal information. We do not use captured pages or Dupli content for advertising or to assess creditworthiness, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

4. Sharing and service providers

Information may be visible to:

  • people you share a Dupli with, including anyone holding a share link and, where you set one, the Dupli password;
  • collaborators in your workspace or team, according to the access controls in the product;
  • DupliPage administrators, where necessary to support, operate or secure the service - administrative access to a Dupli is recorded;
  • the service providers below, which process information to run DupliPage on our instructions;
  • authorities or others, where the law requires it.

Apart from these recipients, we do not share your information.

The providers we currently use are Vercel (application hosting and server-side functions), Supabase (database), Resend (transactional email) and Upstash (the short-lived counters used for rate limiting). The extension itself communicates only with duplipage.com; these providers are used by our backend.

Our application functions are currently configured for Frankfurt, and our production database is currently in our provider's Frankfurt (eu-central-1) region. Other providers and infrastructure may process information in other locations, including outside the European Economic Area. Where that happens, transfers are made on the basis of the safeguards available under applicable data-protection law. Write to privacy@duplipage.com if you would like information about the safeguards that apply to a particular transfer.

5. Storage, security and retention

What we do to protect information:

  • traffic to duplipage.com is encrypted with HTTPS, and the extension communicates only with duplipage.com;
  • account passwords and Dupli passwords are stored only as salted hashes;
  • permissions are checked on our servers for every request;
  • captured pages are displayed without running the captured page's scripts;
  • sensitive operations, such as entering a Dupli password or signing up, are rate-limited;
  • administrator access to a Dupli is recorded.

No service can promise perfect security. Keep your password private and share Duplis deliberately.

How long we keep things:

  • Account information: while your account is active, and afterwards only where we still need it to deal with a deletion request, a legal obligation or a security matter.
  • Duplis, revisions and comments: while you or your workspace keep them, because they are the record of what was reviewed and changed.
  • Deleting a Dupli removes it from normal use and stops its management link working. Underlying records may remain in our systems until they are erased - ask us if you need that done.
  • Drafts you discard in the extension: 7 days on your device. Uninstalling the extension removes local drafts immediately.
  • Invitation links: they expire after 7 days. The record that an invitation was sent may remain as part of the workspace or team history.
  • The cookie that remembers you unlocked a password-protected Dupli: 30 days.
  • Rate-limit counters: they expire at the end of their short window.
  • Editing issue reports, administrator-access records and other security records: kept for as long as they serve the operational or security purpose they were created for.

You can ask us to erase specific information at any time - see the next section.

6. Your choices and rights

In the product you can update your name, change your password, delete Duplis you own, discard and recover drafts, and uninstall the extension, which removes its local storage. There is currently no self-service account deletion and no self-service data export.

To delete your account, to have specific content erased, or to obtain access to, correction of, or a copy of your information, write to privacy@duplipage.com. We handle these requests by hand, in accordance with applicable data-protection law. We may need to verify that a request really comes from you, and some information may need to remain where it is required for legal, security or dispute-related reasons.

You also have the right to complain to a data protection supervisory authority. DupliPage is operated from Italy, so that is the Garante per la protezione dei dati personali; if you are in another EU or EEA country, you may complain to your own national authority instead.

7. The Chrome extension and Limited Use

The extension contains no advertising code, no analytics or behavioural telemetry, and no remotely loaded code. It does not read your Chrome browsing history, and it communicates directly only with duplipage.com.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain terms: information handled through the extension is used to provide and improve the DupliPage features you invoke, and is never sold, used for advertising, or used to assess creditworthiness.

If you enable DupliPage for Incognito, Chrome runs it separately from the regular extension context, according to Chrome's own Incognito permission model.

8. Children

DupliPage is a professional tool for people who work on websites, and it is not directed to children. If you believe a child has provided us with information, contact privacy@duplipage.com and we will delete it.

9. Changes and contact

We will update this policy as DupliPage and its data practices evolve, and we will change the date at the top when we do. Where a change is significant, we will highlight it in the service.

Questions, requests or complaints about this policy or your information: privacy@duplipage.com.

© 2026 DupliPage · Home