DoubleAgent

Data Handling

Last updated: August 19, 2026

This document describes how DoubleAgent collects, stores, protects, and deletes data. It supplements the Privacy Policy (what we collect and why) and the Terms of Use (the rules of the service).

What we collect, and what we never collect

  • Public sources only. Our collection service gathers posts that are publicly available: public forums, public groups, and public feeds. It does not log into private communities, bypass paywalls or access controls, or collect from sources that require a personal account relationship with the author.
  • No sensitive enrichment. We do not look up, purchase, or append sensitive personal data (such as credit, health, or precise location information) to any signal.
  • Signal contents.A stored signal consists of the public post text, its public author name, the venue, a link to the original, and the AI's assessment of it.

Where data lives

Production data is stored in a managed PostgreSQL database (Supabase, hosted on AWS in the United States) with encryption at rest. The application runs on Vercel. All traffic is encrypted in transit with TLS. Backups are managed by our database provider and encrypted at rest.

Access control

  • Every customer organization's data is isolated by database row-level security: queries are scoped to the requesting user's organization at the database layer, not just in application code.
  • Within an organization, a two-tier role model (admin and member) governs configuration changes, member management, and visibility of team-level views.
  • Platform-level administration is restricted to named DoubleAgent personnel and enforced by the same database-level policies.
  • Passwords are stored only as cryptographic hashes. Administrative provisioning uses scoped service credentials that are never exposed to browsers.

AI processing

Public post content is scored and summarized through Anthropic's commercial API. Under those commercial terms, submitted content is not used to train models. We do not train our own models on customer content. AI outputs are stored alongside the signal with the model and prompt version that produced them, so every automated judgment is auditable.

Subprocessors

We use the following subprocessors to operate the service:

  • Vercel: Application hosting and edge network (United States)
  • Supabase (on AWS): Database, authentication, and storage (United States)
  • Anthropic: AI scoring and summarization (commercial API) (United States)
  • Apify: Public-content collection infrastructure (EU / United States)
  • Resend: Transactional email delivery (United States)

Each subprocessor is bound by data protection terms and processes data only to provide its service to us. We will update this list when subprocessors change.

Retention and deletion

  • Customer account data: retained while the account is active; deleted or anonymized within 90 days of verified account closure or deletion request, except where law requires longer.
  • Customer-created content (contacts, notes, configuration): deleted with the account, or earlier on request by an organization admin.
  • Collected public posts: retained while relevant to the service; removed within 30 days of a verified request from the post's author.
  • Operational logs: retained for a limited period for security and debugging, then deleted.

Export

Customers can export their contacts from the product at any time (CSV). Additional exports of organization data are available on request to support@godoubleagent.ai.

Incident response

We monitor the pipeline and application for failures and anomalies with automated alerting. If we become aware of a security incident affecting personal data, we will investigate, contain, and notify affected customers and authorities as required by applicable law, without undue delay.

Your role as a customer

Data you put into DoubleAgent about your own prospects and contacts is yours, and you are its controller: collect and use it lawfully, honor removal requests you receive, and limit access within your organization using the roles the product provides.

Questions about this document: support@godoubleagent.ai