Privacy Policy

Updated: 6 October 2026

1. Introduction

duvet UK (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data when you use our energy performance and property valuation tools. The consumer estimate service is described below; council and installer features have separate scope where explicitly identified.

2. Data We Collect

  • Property Data: Postcode, property type, age, size, wall/roof type, heating systems.
  • Usage Data: How you interact with the wizard, pages visited, errors encountered.
  • Contact Info: Email address supplied to unlock demo results, or email and account identifier when you sign in. API enquiries also include your name, organisation, intended use and expected volume. Optional product-update consent is recorded separately and starts unchecked.

3. How We Use Your Data

  • To generate indicative energy performance estimates.
  • To provide property valuation estimates, associate your submissions with your contact details, and respond to API enquiries.
  • To secure the service and limit automated abuse. Short-lived rate-limit records contain hashed request identifiers.
  • To improve the accuracy and UX of our calculation engine.
  • We do not sell your specific property data to third-party installers without your explicit consent.

We use service-related contact details to provide the requested demo or respond to your enquiry, and rely on our legitimate interests in operating and securing the service. Optional product updates require your consent, which you can withdraw. Entering an email to unlock the demo does not verify ownership of that email or create an account.

Demo access cookies expire after 24 hours. Demo contacts and enquiries are retained for up to 12 months; account information is handled separately for your account. Home inputs and predictions are recorded for the service and model evaluation. These server records currently have no automatic expiry or fixed deletion period; they do not expire with the browser save or the demo access cookie. You can request erasure of your submissions. Contact details are not sent to the prediction models.

The combined tool keeps your home details, sample assumptions and estimates and a named comparison baseline in this browser tab’s session storage so you can return from supporting pages or reload. Saved assessments expire after 24 hours and are removed when the tab’s session ends. This browser save contains no email or access token; server access still requires the separate access cookie or account.

4. Third-Party Sharing

  • Vercel hosts the website and the authenticated prediction service. To resolve location, the service sends only the postcode to Postcodes.io; it does not send your email or other home details.
  • We may use the official EPC Register API to fetch data about your property.
  • We use Supabase for account authentication and database storage. Choosing Google sign-in also involves Google’s authentication service.
  • If you request quotes from our installer marketplace, we will ask for your explicit consent before sharing your details.

5. Your Rights

Under the UK GDPR, you have the right to access, rectify, or erase your personal data. Contact us to exercise these rights.

6. Local Authority Demo

Merewick is a demonstrator estate. Its homes, household flags, resident feedback and programme records are synthetic. Sign-in uses Supabase. Your account email, identifier and authentication cookies are real account data, separate from the demonstrator estate records.

Imported stock rows are held in memory and cleared on reload. Uploaded stock is separate from the demonstrator estate programme and funding model.

Home files are saved in this browser and remain after reload, including their versions and review details. They are not uploaded to council document storage. Groups, condition reports, request drafts, document comments and data history can be saved in this browser. They are not shared with colleagues.

Signing out does not remove browser-saved files or records. They are not separated by signed-in account; use only the supplied samples or demonstrator estate data.

Mapbox supplies the map and receives map requests. The postcode checker sends the postcode you enter to duvet's server. Uploaded stock rows and document bytes are processed locally.

Sign-in protects access to the enabled demo. It does not provide a council workspace, shared document storage or account separation for browser-saved records. Please use sample material only. A real-data pilot requires agreed access, hosting, retention and data-processing arrangements before council or resident information is accepted.