Security, privacy and legal — in the open
Dual Login is built for legitimate business and privacy work. Here is how we protect your data and the policies that govern the service.
Trust and compliance highlights
Encrypted by default
TLS in transit, encryption at rest for sensitive data and synced profiles, and salted-hash passwords.
Stripe payments (PCI-DSS)
Card data is handled by Stripe, a PCI-DSS Level 1 provider. We never store full card numbers.
GDPR & CCPA aware
Data-subject rights, Standard Contractual Clauses for transfers, and a DPA for business customers.
Anti-abuse enforcement
We prohibit fraud, phishing and cybercrime, screen payments, and act on credible abuse reports.
Policies & legal
Everything in one place. Each document is written in plain English.
Privacy Policy
How Dual Login collects, uses, protects and shares your information — cookies, payment data, analytics, retention, GDPR and CCPA rights, and how to contact us.
Terms of Service
The agreement between you and Dual Login — eligibility, accounts, subscriptions, billing, license, acceptable use, prohibited activities.
Refund Policy
Dual Login's refund and cancellation policy — subscription refunds, the cooling-off period, non-refundable items, chargebacks and how to request a refund.
Cookie Policy
How Dual Login uses cookies and similar technologies — strictly necessary, functional, analytics and marketing cookies, and how to manage them.
Acceptable Use Policy
What you can and cannot do with Dual Login — allowed business and privacy use cases, prohibited activities, abuse prevention and enforcement.
Security Policy
How Dual Login protects your data — encryption, authentication, infrastructure security, and how to responsibly disclose a vulnerability.
Disclaimer
Legal disclaimer for Dual Login — no warranties, no guarantee of results, your responsibility for lawful use, and third-party services.
End User License Agreement (EULA)
The license terms for the Dual Login desktop software — grant of license, restrictions, updates, ownership and termination.
Data Processing Addendum (DPA)
Dual Login's Data Processing Addendum for business customers — roles, processing scope, subprocessors, security.
Anti-Abuse Policy
How Dual Login prevents and responds to abuse and fraud — our commitments, what we monitor, enforcement actions, and how to report abuse.
DMCA & Copyright Policy
How to report copyright infringement to Dual Login and our counter-notice process under the DMCA and similar laws.
Compliance
Dual Login's approach to compliance — data protection (GDPR/CCPA), PCI-DSS payments via Stripe, sanctions and export controls, and lawful-use requirements.
Which document answers your question?
Twelve policies is a lot to face when you arrived with one question, so here is the short map. If you want to know what we collect and what we do with it, read the Privacy Policy — it is the one that describes the relationship between you and us, whoever you are. If you are a business putting other people’s personal data through the platform and your own compliance obligations require terms with vendors, you additionally want the Data Processing Addendum, and you can have it signed by asking.
If your question is money — when you are billed, what cancelling does, when a charge can come back — that is the Refund Policy, and it is deliberately short. If your question is what am I allowed to do with this, the Acceptable Use Policy draws the line and the Anti-Abuse Policy explains how we act on it, including what protects you from a report that turns out to be wrong. If you are evaluating us for an employer, the Compliance page is the one written to be forwarded: it covers data protection, how card payments are handled, and sanctions and export controls in the order a reviewer usually asks about them.
The positions behind the paperwork
A trust page is easy to fill with reassuring adjectives, so it is worth stating the handful of choices these documents actually reflect. We collect as little as the service can run on. That is partly principle and partly self-interest: data you never collected cannot leak, cannot be subpoenaed, and does not have to be defended when somebody asks what you hold. It is why full card numbers never reach our servers — they go to a PCI-DSS provider, so that a breach of us is not a breach of your card.
Your browser profiles live on your machine. Cookies, local storage and cache sit in per-profile data directories on your own disk. What synchronises to your account is what you choose to sync, so that a login survives a lost laptop or a move to a second PC. We are not reading through those profiles, and the product would be self-defeating if we were: a company selling isolation that quietly watched the people who bought it would be selling nothing at all.
We say what the tool cannot do. Dual Login isolates browser identities, and it does that well. It cannot promise a platform will let you keep a particular account, because that decision rests on payment details, phone numbers, content, IP reputation and platform policy as much as on device identity. Anyone in this market guaranteeing the whole picture is selling something they are not able to deliver, and the Disclaimer exists to make our position on that unambiguous rather than merely unstated.
Enforcement is graduated, and you are told the finding. A tool that makes accounts harder to link is genuinely more attractive to somebody committing fraud, and pretending otherwise would be dishonest. So the rules name real victims — fraud, stolen credentials, phishing, malware — rather than listing sites you may not visit, and acting on them starts with a look rather than a verdict. An account that is actioned is told what for, because a finding you cannot see is one you cannot answer.
Reporting something
Three addresses, three different jobs. Send a security vulnerability to security@duallogin.com before disclosing it anywhere else: include enough to reproduce it, give us a reasonable window, and do not go through other people’s data to prove the point. We do not threaten researchers who work that way. Send abuse to abuse@duallogin.com with whatever lets us verify it — a report we can check gets acted on, and one we cannot starts a look rather than finishes one. Send legal and compliance questions, including requests for a signed DPA, to legal@duallogin.com; naming a signing entity is a routine request that needs no call and no plan upgrade.
Every policy below carries a plain-English summary at the top: the same document answered as the questions people actually arrive with, with each answer pointing at the numbered section it came from, so you can check it rather than take our word for it. Where the two could be read differently, the formal text governs — which is the honest way round, and the reason the summary sits above it rather than instead of it.
Security or compliance question?
Reach our team at legal@duallogin.com or report a vulnerability to security@duallogin.com.