Legal
Privacy Policy
Last updated: August 3, 2026
Scope and approach
This policy applies to duu.to public pages, campaigns, artist hubs, and the dashboard. We use a Mongolia-first, globally conservative privacy baseline: optional analytics and marketing integrations are off unless a visitor actively allows them. A browser's Global Privacy Control signal is treated as a refusal.
What we collect
- Account and workspace data — authentication email, profiles, campaigns, links, artwork, and settings needed to provide the service.
- Fan subscriptions — the email, optional name, consent text, source, and delivery/unsubscribe records submitted through an artist's form. Abuse-prevention systems may use a short-lived IP-derived key; raw IP addresses are not stored in analytics tables.
- Optional first-party analytics — only after analytics consent: event type, workspace/campaign/profile/block/ link identifiers, country derived from the request, coarse device and browser families, referrer hostname, path without query parameters, safe UTM source/medium/campaign values, and timestamp.
- Optional marketing events — only after marketing consent and only for an approved provider configured by a workspace owner. Queue records contain provider/event identifiers, a deduplication key, a consent receipt, a redacted URL path, and delivery status. Custom image beacons and arbitrary webhooks are not enabled.
How we use information
We use account and content data to operate duu.to, protect the service, deliver fan subscriptions, and show workspace analytics when allowed. Approved marketing providers may receive an event only when the visitor's current consent receipt permits it. Workspace owners cannot override this platform-wide rule.
Server and edge error reporting may be enabled for reliability. It is error-only: browser telemetry, replay, performance traces, and logs are disabled under this policy. Error events are scrubbed of request headers, cookies, query strings, user data, breadcrumbs, and extra payloads before delivery.
Cookies and choices
Essential authentication and security cookies support signed-in features. The optional preference cookie is versioned as duu_privacy_consent_v1 and lasts 180 days. On public pages, use the fixed Privacy choices control to accept, reject, change, or withdraw optional categories. The control has equal accept/reject access and withdrawal takes effect before a queued marketing event can be delivered.
See Cookies & privacy choices for the category-by-category inventory.
Retention
- First-party analytics events: up to 90 days.
- Legacy click events: up to 90 days.
- Marketing delivery logs: up to 30 days.
- Consent receipts: up to 395 days for audit and renewal.
- Account, content, and fan-subscription data: until account/list deletion or another documented service requirement.
- Contact-form name, email, optional subject, and message: stored until the workspace is deleted. A timed purge is not implemented.
Retention of analytics, click, delivery, and consent-receipt data is enforced by an authenticated, bounded purge job. Account deletion continues to cascade through workspace-owned records, including contact-form messages.
Service providers and transfers
duu.to uses self-hosted Supabase services for authentication, PostgreSQL, and object storage; Upstash for short-lived rate-limit keys; and Sentry for scrubbed server/edge errors when enabled. Approved marketing integrations (Meta, TikTok, Google Analytics, or Google Ads) receive data only after consent and have their own terms and privacy notices. Platform destinations such as Spotify or Apple Music process visits under their own policies.
Your requests
Account owners can delete their account from Dashboard Settings. Fan subscribers can use the unsubscribe link supplied by the list owner. For a privacy question or a deletion request, contact privacy@duu.to.
Contact
Privacy policy and provider-review questions: privacy@duu.to.