Privacy Policy
Last updated: May 18, 2026
DualTake ("we", "us") provides a dual-camera recording app for iOS and the web. This Privacy Policy explains what we collect, why we collect it, and the choices you have. Contact us anytime at hello@getdualtake.app.
1. What we collect
Account data
- Email address if you sign in with email, Google, Apple, or GitHub.
- Display name and avatar URL if your sign-in provider returns them.
- Hashed password if you use email sign-in (PBKDF2-SHA256; we never see your plain-text password).
Subscription data
- Pro entitlement status, product ID, expiration date, and renewal state — synced from Apple App Store via StoreKit, or Stripe for web payments, through RevenueCat.
- We do not see or store your credit card number, Apple ID password, or full billing address.
Recordings
- On iOS: recordings stay on your device. We never upload them.
- On the web: recordings save directly to your computer's Downloads folder. We never upload them to any server.
Technical data
- IP address and User-Agent (used briefly to rate-limit auth requests and for security logging; not retained beyond 30 days).
2. What we do not collect
- Your videos, audio, photos, or any content you record.
- Your location, contacts, calendar, or other device data.
- Behavioural tracking cookies or third-party advertising identifiers.
3. Third parties we share data with
- Apple — for Sign in with Apple and App Store purchase validation.
- Google — if you use Sign in with Google. Your email and Google profile ID are exchanged.
- GitHub — if you use Sign in with GitHub. Your email and GitHub username are exchanged.
- RevenueCat — manages our subscription state across iOS and web.
- Stripe — processes web payments. Stripe sees your card details; we do not.
- Cloudflare — hosts our website and API; routes your traffic.
- MailChannels — delivers email verification and password reset emails.
4. Where data lives
Account records live in a Cloudflare D1 database (EU-region). iOS-specific account records live in a PostgreSQL database hosted on Railway (EU-region). Recordings never leave your device.
5. Your rights (GDPR / CCPA)
You have the right to access, correct, export, or delete your data at any time. The DualTake app has a "Delete account" button in Settings that performs an immediate hard delete of your account and subscription record. To request export of your data, email hello@getdualtake.app.
6. Data retention
- Account record: until you delete your account.
- Subscription record: until your subscription expires or you delete your account.
- Rate-limit logs: 30 days.
7. Children
DualTake is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
8. Changes to this policy
If we make material changes, we will update this page and, where required, notify you via email. Continued use after changes constitutes acceptance.
9. Contact
Data controller and contact: hello@getdualtake.app.