doubleWaitlist

Legal

Privacy Policy

Last updated August 9, 2026 · Effective August 9, 2026

This Privacy Policy explains how Integer Software LLC (doing business as "Integer") ("Integer," "we," "us," or "our"), a Delaware limited liability company qualified to do business in New York, collects, uses, discloses, and protects personal information in connection with our software platform currently made available under the "Double" name, including our web application, browser extensions, APIs, and related services for automated monitoring, analysis, and reporting with respect to publicly available websites and related information (collectively, the "Service").

About our role. Integer offers the Service to business and professional customers ("Customers"). When a Customer submits data to the Service for processing on its behalf, Integer acts as a service provider under the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA") and as a processor under the EU General Data Protection Regulation ("GDPR") and UK GDPR, and the Customer is the "business" / "controller" responsible for the lawfulness of that processing. When you visit our marketing site, sign up for an account, or contact us directly — and when we collect and analyze publicly available information as described in Section 3 — Integer acts as a controller of that personal information and this Policy applies in full. Where a Customer deploys Integer-provided software components on the Customer's own websites or applications, data those components collect from the Customer's end users is processed on the Customer's behalf under our DPA and the Customer's own privacy notice.


1. Scope

This Policy applies to personal information processed by Integer in connection with:

  • The Double dashboard and marketing site at https://withdouble.ai;
  • The Double browser extensions;
  • The Double APIs and related tools;
  • Publicly available information we collect and analyze in operating the Service; and
  • Sales, support, marketing, and security operations.

This Policy does not apply to: (a) third-party websites or services, including websites that the Service analyzes (which are governed by their own privacy notices); (b) the websites or applications of our Customers; or (c) any data processed solely on behalf of a Customer under a Data Processing Addendum ("DPA"), which is governed by that DPA and the Customer's own privacy notice.

2. Personal information we collect

a. Account and identity information. Name, work email, employer/organization name, role, password (hashed), and authentication identifiers.

b. Billing information. Billing contact, tax ID, billing address, and payment method metadata. Card numbers are processed by our payment processor and are not stored by Integer.

c. Customer Content. Information Customers (or their authorized users) upload, generate, or transmit through the Service, including files, prompts, instructions, configurations, monitoring targets and preferences, captures of publicly available web content created with our browser extension, and API usage logs tied to a Customer's tenancy.

Browser extension. Our browser extension collects data only during recording or capture sessions that the signed-in user explicitly initiates. During a session it captures the content and technical behavior (e.g., network activity) of the pages the user visits, and uploads those captures to the user's account. The extension does not monitor or collect the user's general browsing activity outside an active session.

d. Publicly available information. See Section 3.

e. Usage and device information. Log data, IP address, device identifiers, browser type, operating system, referring URLs, pages or screens viewed, feature usage, crash data, and approximate location derived from IP.

f. Cookies and similar technologies. See our Cookie Notice for the categories, purposes, and your choices.

g. Communications. Messages you send to support, sales, or security; survey responses; and call recordings where lawfully disclosed.

h. Information from third parties. Identity providers (e.g., SSO), enrichment vendors, and fraud-prevention partners.

We do not intentionally collect special categories of personal data (e.g., health, biometric, precise geolocation) and ask Customers not to upload such data to the Service.

Categories collected, purposes, and recipients (CCPA/CPRA summary)

Category of Personal Information (Cal. Civ. Code §1798.140)Examples Integer collectsBusiness or commercial purposeCategories of recipients
IdentifiersName, work email, IP address, account IDProvide Service, authenticate, securitySubprocessors, Customer admins, authorities as required
Customer records (§1798.80(e))Name, billing contact, payment metadataBilling, account managementPayment processor, accounting/tax advisors
Commercial informationSubscription, plan, usageBilling, analyticsSubprocessors
Internet/network activityLog data, device data, feature usageOperate Service, security, analyticsSubprocessors
Geolocation (approximate, IP-derived)Coarse city/regionSecurity, analyticsSubprocessors
InferencesUsage patterns, preference settingsImprove ServiceInternal
Professional/employmentEmployer, roleProvide Service, account contextInternal
Publicly available informationInformation appearing on public websites (see Section 3)Provide monitoring, analysis, and reporting services; improve ServiceCustomers, Subprocessors

Much of the information described in Section 3 is "publicly available information" excluded from the definition of "personal information" under CCPA/CPRA §1798.140(v)(2); we describe it here for transparency regardless. Integer does not intentionally collect Sensitive Personal Information as defined by §1798.140(ae). Integer has not Sold or Shared Personal Information in the preceding 12 months as those terms are defined under CCPA/CPRA.

3. Publicly available information we analyze

The Service collects, preserves, and analyzes information that is publicly available on the internet — for example, the content, source code, configuration, and observable technical behavior of publicly accessible websites, and related public business information. This information may incidentally include personal information that appears on those websites, such as names, business contact details, or professional information of the people associated with them.

  • How we collect it. Using automated tools that access publicly available web pages in a manner similar to an ordinary visitor. Our systems are designed to access only publicly available resources and do not bypass authentication requirements, log-in walls, or paywalls.
  • Why we collect it. To provide monitoring, analysis, evidence-preservation, and reporting services to our Customers, and to operate, secure, and improve the Service.
  • Legal basis (EEA/UK, where applicable). Our legitimate interests in providing analysis and reporting services concerning publicly available information (Art. 6(1)(f)), balanced against the rights and interests of the individuals concerned.
  • Who receives it. Our Customers (in analyses and reports), and the Subprocessors that host and support the Service.
  • Retention. For as long as reasonably necessary for the purposes above, including maintaining the integrity of point-in-time records.

If your personal information appears in publicly available material we have collected and you wish to inquire about it or exercise applicable rights, contact [email protected]. Note that we may retain information as needed to preserve the integrity of records, comply with law, or support the establishment, exercise, or defense of legal claims.

4. Sources of personal information

We collect personal information directly from you, automatically through your use of the Service, from our Customers, from publicly available sources as described in Section 3, and from third parties such as identity providers, integration partners, and fraud-prevention partners.

5. How we use personal information

We use personal information for the following purposes:

  • Provide and operate the Service, including authenticating users, performing monitoring and analysis, and generating reports and other outputs for Customers.
  • Bill and account-manage, including invoicing, tax reporting, and dunning.
  • Support and communicate, including responding to inquiries and sending administrative messages.
  • Improve the Service, including diagnosing errors, measuring performance, and developing new features. Integer does not use Customer Content to train our own foundation models or to train any third-party model in a way that benefits other Customers. Aggregated and de-identified data may be used for analytics and product improvement.
  • Secure the Service, including fraud prevention, abuse monitoring, and incident response.
  • Marketing, including newsletters and product updates, subject to your preferences and applicable law.
  • Legal and compliance, including responding to lawful requests, enforcing our Terms, and meeting our obligations under GDPR, CCPA/CPRA, and other applicable privacy and data protection laws.

Where GDPR or UK GDPR applies, we rely on the following legal bases: (i) performance of a contract (Art. 6(1)(b)) for account, billing, and core Service delivery; (ii) legitimate interests (Art. 6(1)(f)) for security, abuse prevention, analytics, improving the Service, and the analysis of publicly available information described in Section 3, balanced against your rights; (iii) consent (Art. 6(1)(a)) for optional cookies and certain marketing; and (iv) legal obligation (Art. 6(1)(c)) for tax, accounting, and lawful-request compliance.

6. AI processing and disclosures

Integer uses large language models and other machine-learning systems to generate analyses, summaries, reports, and similar outputs ("Output").

  • Output is automated, probabilistic, and may be inaccurate or incomplete. Output is provided for informational purposes only and is not legal advice or a substitute for the judgment of a qualified professional; Customers are responsible for independent professional review before relying or acting on Output.
  • We may engage third-party model providers (Anthropic, OpenAI, and Google) and, where we do, only under terms that prohibit those providers from training on Customer Content submitted through Integer.
  • Integer does not sell or share personal information for cross-context behavioral advertising, and does not use sensitive personal information for purposes other than those permitted under CPRA §7027(m).
  • Integer does not engage in automated decision-making that produces legal or similarly significant effects on individuals as defined under GDPR Art. 22. Outputs of the Service are preliminary observations for human professional review; they are not automated determinations about individuals.
  • Not a "high-risk AI system." Integer does not market the Service for use in consequential decisions affecting employment, education, lending, housing, insurance, healthcare, government benefits, or similar categories regulated as "high-risk AI" under the Colorado AI Act (SB 24-205), the EU AI Act, or analogous laws. Customers who repurpose the Service for such decisions are solely responsible for compliance.

7. How we disclose personal information

We disclose personal information to:

  • Subprocessors and service providers under written contracts that restrict use to providing services to Integer. As of the effective date, our principal Subprocessors processing personal information in production are: Clerk (authentication and identity), Railway (application hosting and runtime), Cloudflare (DNS, CDN, edge security, and R2 object storage), Temporal Cloud (workflow orchestration), and PostHog (product analytics, feature flags, error tracking, and session replay). We separately engage Google (Google OAuth via Clerk and Google Fonts) and Apple (Sign in with Apple) as platform providers. AI model providers (Anthropic, OpenAI, and Google) will be added to the Subprocessor list when used to process Customer Content in production. Billing data is handled by our payment processor, which is engaged as a service provider outside the Customer-data Subprocessor list. Our current Subprocessor list is available at /subprocessors and is updated when changes occur.
  • Customers, when you are an authorized user of a Customer's tenancy (e.g., your administrator can see your account and activity), and when your personal information appears in publicly available material included in analyses or reports provided to Customers (see Section 3).
  • Professional advisors, including auditors, lawyers, and accountants.
  • Authorities, where required by law, subpoena, court order, or to protect rights, safety, or property.
  • Corporate transactions, in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to confidentiality.

In the preceding 12 months we have not "sold" personal information and have not "shared" personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA. We do not knowingly collect or sell the personal information of consumers under 16.

8. International data transfers

Integer is based in the United States and processes personal information in the United States and in regions where our cloud providers operate. Where we transfer personal information from the EEA, UK, or Switzerland to a country not deemed adequate, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum or UK IDTA, as applicable), supplementary measures including encryption in transit and at rest, and our DPA. A copy of our SCCs and DPA is available on request at [email protected].

9. Retention

We retain personal information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention windows:

  • Account records: for the life of the account, plus up to 90 days after termination, then deleted or de-identified.
  • Customer Content: per the Customer's instructions and DPA; deleted following the 30-day post-termination export/return window described in the Terms of Service and DPA, unless legal hold applies.
  • Publicly available information and derived analyses: for as long as reasonably necessary for the purposes in Section 3, including preserving the integrity of point-in-time records.
  • Billing records: seven (7) years for tax/accounting.
  • Security logs: up to 13 months.
  • Backups: purged on a rolling cycle not to exceed 35 days after primary deletion.

10. Your privacy rights

a. All users

You may contact us at [email protected] to ask about your personal information, update your account, or unsubscribe from marketing.

b. California residents (CCPA/CPRA)

You have the right to: (i) know what personal information we have collected, used, disclosed, or sold/shared; (ii) delete personal information, subject to exceptions; (iii) correct inaccurate personal information; (iv) opt out of sale/sharing of personal information (we do not sell or share, but the link below is provided in any case); (v) limit use of sensitive personal information; and (vi) be free from retaliation for exercising these rights.

Submit a request to [email protected]. We will verify your identity using account credentials or, for non-account holders, by matching identifying details against our records. You may use an authorized agent with written permission. We respond within 45 days (extendable by 45 days where permitted). Do Not Sell or Share My Personal Information.

California "Shine the Light" (Cal. Civ. Code §1798.83). California residents may request information about Personal Information Integer has disclosed to third parties for those third parties' direct-marketing purposes during the preceding calendar year. Integer does not currently disclose Personal Information to third parties for those third parties' direct marketing. To submit a Shine the Light request, email [email protected] with the subject line "California Shine the Light Request."

c. EEA / UK / Swiss residents (GDPR / UK GDPR)

You have the right to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. Where Integer acts as a processor, please direct rights requests to the Customer who controls your data; we will assist that Customer in responding. You may lodge a complaint with your supervisory authority. Integer has not yet appointed an Art. 27 EU representative or UK representative; one will be designated prior to engaging in regular processing in scope of the EU or UK GDPR.

d. Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, delete, correct, and opt out of targeted advertising, sale, and certain profiling. We honor these rights through the same channels described above.

11. Account deletion

You may export and delete your Double account and associated personal information at any time:

  • Export your data first (recommended): open Settings → Account → Export in the dashboard, or email [email protected].
  • Delete in the dashboard: sign in and open Settings → Account → Delete Account.
  • Delete by email: [email protected].

Deletion requests are processed within 30 days. Some information may be retained as described in Section 9 (e.g., billing records, legal holds, backup cycles).

Account deletion will: (a) terminate access to the Service for that account; (b) delete authentication credentials, profile data, and content associated with that user; and (c) initiate deletion of associated Customer Content unless retention is required by law or the Customer's separate agreement. If you are a member of a Customer's tenancy, your administrator may continue to retain content you contributed to that tenancy in accordance with the Customer's own policies.

12. Security

Integer maintains administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, least-privilege provisioning, MFA for production access, vulnerability management, code review, secure SDLC, vendor risk review, logging and monitoring, and incident response. No system is perfectly secure, and we cannot guarantee absolute security.

Responsible disclosure. Security researchers may report suspected vulnerabilities to [email protected]. Integer will not pursue legal action against researchers acting in good faith under Integer's published vulnerability disclosure policy.

13. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.

14. Cookies and tracking

We and our service providers use strictly necessary, functional, analytics, and (where consented) marketing cookies. EEA, UK, Swiss, and California visitors are presented with a cookie consent banner offering granular choices, and analytics and session-replay technologies are not loaded for those visitors before consent. We honor Global Privacy Control ("GPC") signals as opt-outs for residents of states that recognize them.

15. Changes to this Policy

We may update this Policy from time to time. We will post the new effective date at the top and, for material changes, provide additional notice (e.g., email or in-app banner). Continued use of the Service after the effective date constitutes acceptance.

16. Contact us

  • Email: [email protected]
  • Mail: Integer Software LLC, Attn: Privacy, 169 Madison Ave, STE 64131, New York, NY 10016, United States
  • EU representative (Art. 27 GDPR): Not currently appointed. Will be designated prior to processing personal data of EU data subjects in scope of GDPR.
  • UK representative: Not currently appointed. Will be designated prior to processing personal data of UK data subjects in scope of UK GDPR.