⬡ Legal
Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how I-CO ("I-Co," "we," "us," or "our") collects, uses, and protects information when you use our website, desktop application, and related services (collectively, the "Service"). By using the Service, you agree to the practices described here.
1. Information We Collect
We collect the following categories of information:
- Account information. Name, email address, username, and a securely hashed password, collected when you create an account. Authentication is handled by Firebase Authentication; we never see or store your raw password.
- Payment information. When you purchase lifetime access, your payment is processed by Razorpay (for payments in India) or PayPal (for international payments). We receive confirmation that a payment was made, a transaction/order ID, and the amount charged. We do not collect or store your card number, CVV, UPI PIN, or other raw payment credentials — those are handled entirely by our PCI-DSS compliant payment processors.
- Usage and device data. Basic technical information such as device/platform type, app version, and login timestamps, used to enforce account and licensing rules (for example, single-device login for the desktop app) and to diagnose issues.
- Support communications. Information you provide when you contact us for support, such as your name, email, and the content of your message.
- API keys you provide (Bring Your Own AI). If you connect your own API key (e.g., Groq or Gemini) or point I-Co at a local Ollama instance, that key is stored locally and encrypted on your device. We do not transmit your API keys to our servers or have access to them.
2. How We Use Information
- To create and maintain your account and authenticate you.
- To process payments and grant lifetime access to paid features.
- To provide customer support and respond to inquiries.
- To enforce our Terms of Service, including single-device login limits.
- To maintain the security and integrity of the Service.
- To comply with legal obligations.
We do not sell your personal information to third parties.
3. Payment Data & Third-Party Processors
All payment transactions are processed by Razorpay and/or PayPal, both of which are PCI-DSS compliant payment processors. Card numbers, CVVs, and other sensitive payment credentials are entered directly into these processors' secure interfaces and are never transmitted to or stored on our servers. Our systems only retain the minimum information necessary to confirm your payment and grant access — such as a transaction ID, amount, currency, and payment status.
4. Screen & Audio Capture
I-Co's screen and audio capture features operate only when you explicitly enable them within the desktop application. Captured audio/screen content used to generate a response is sent to the AI provider you have configured (your own Groq or Gemini key, or a local Ollama model running on your own machine) for processing. When using a local model via Ollama, no capture content leaves your device. We do not store, view, or retain your screen or audio capture content on our servers.
5. Data Storage & Security
Account and application data are stored using Google Firebase (Authentication and Firestore). We apply reasonable administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, or disclosure. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your account information for as long as your account is active. If you request deletion of your account, we delete your Firestore user record, associated username/email reservations, and your Firebase Authentication account, subject to any retention required for legal, tax, or fraud-prevention purposes.
We retain different categories of information for different periods, as set out below:
- Account data (name, email, username, hashed password). Retained for as long as your account remains active, and deleted within a reasonable period — typically 30 days — after a verified deletion request, except where retention is required under Section 9 (Legal Compliance) below.
- Payment and transaction records (transaction ID, amount, currency, payment status). Retained for as long as required by applicable tax, accounting, and audit laws — in India, this is currently up to eight (8) years from the date of the transaction — even if you delete your account in the meantime. Razorpay and PayPal separately retain their own transaction records under their respective retention policies, which we do not control.
- Support communications. Retained for up to twenty-four (24) months from your last message, to allow us to review prior issues, honor warranty/refund claims, and improve support quality.
- Usage, device, and login data. Retained for up to twelve (12) months, for security monitoring, license enforcement, and fraud investigation.
- Backups. Deleting data from our live systems does not necessarily delete it instantly from routine security backups. Backup copies are retained for a limited period — up to ninety (90) days — after which they are automatically overwritten or purged in the ordinary course of our backup cycle.
- Legal holds. Notwithstanding the periods above, we may retain specific information for longer where necessary to resolve a dispute, respond to a legal, regulatory, or law-enforcement request, enforce our agreements, or investigate suspected fraud or abuse, for as long as that purpose reasonably requires.
Once a retention period expires and no legal hold applies, we delete or irreversibly anonymize the corresponding data in the ordinary course of business.
7. Consent
By creating an account, you affirmatively agree to this Privacy Policy, our Terms of Service, and our Refund & Cancellation Policy. We record the date and policy version you agreed to at signup on your account, so that we have a durable record of your consent if it is ever disputed.
Our processing of your information relies on one or more of the following legal bases, as applicable:
- Consent — for example, when you create an account or enable optional features.
- Performance of a contract — to provide the Service you purchased, including processing your payment and granting access.
- Legitimate interests — such as securing the Service, preventing fraud, and enforcing single-device login limits, balanced against your rights.
- Legal obligation — where we must retain or disclose information to comply with applicable law (see Section 9 below).
Where our processing relies on your consent, you may withdraw that consent at any time by discontinuing use of the Service and requesting deletion of your account as described in Section 8. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and may mean we can no longer provide you with paid or free features of the Service that depend on that data.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and associated data.
- Object to or restrict certain processing of your information.
- Withdraw previously given consent, as described in Section 7.
- Lodge a complaint with your local data protection authority, if applicable in your jurisdiction.
To exercise any of these rights, contact us at support.icoapp@gmail.com. We aim to respond to verified requests within thirty (30) days, or sooner where required by applicable law. We may need to verify your identity before acting on a request, and may decline a request where an exception under applicable law applies (for example, where we are required to retain data under Section 6 or Section 9).
9. Legal Compliance
We aim to handle personal information in line with applicable data protection law, including India's Digital Personal Data Protection Act, 2023, and, where relevant to a given user, other data protection laws such as the EU/UK GDPR or U.S. state privacy laws.
We may access, preserve, or disclose your information where we have a good-faith belief that doing so is necessary to:
- Comply with a valid legal process, subpoena, court order, or government or regulatory request;
- Enforce our Terms of Service or investigate a potential violation of them;
- Detect, prevent, or address fraud, security, or technical issues, including payment fraud or chargebacks;
- Protect the rights, property, or safety of I-Co, our users, or the public, as required or permitted by law.
If we become aware of a data breach that is likely to result in a risk to your rights or freedoms, we will notify affected users and, where legally required, the relevant supervisory or regulatory authority, without undue delay and in line with applicable breach-notification timelines.
If you have an unresolved privacy concern or grievance that our regular support channel has not addressed to your satisfaction, you may escalate it to our designated grievance contact at support.icoapp@gmail.com, marked "Privacy Grievance". We aim to acknowledge grievances within a reasonable time and resolve them as required under applicable law.
10. Children's Privacy
The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children.
11. International Data Transfers
We serve users globally and process payments in multiple currencies (INR via Razorpay, USD via PayPal). By using the Service, you consent to your information being processed in the countries where we and our service providers operate.
Because of how the Service is built, your information may be transferred to, stored in, and processed in countries other than the one in which you reside, including the United States and other countries where our service providers maintain infrastructure:
- Google Firebase (Authentication & Firestore) — operated by Google, with infrastructure that may be located in the United States or other countries where Google operates data centers.
- Razorpay — processes and stores payment data primarily within India.
- PayPal — processes payment data globally, including in the United States, under its own privacy and security practices.
Where we transfer personal information across borders, we rely on the receiving provider's own recognized safeguards and compliance certifications (such as standard contractual clauses, PCI-DSS certification, or equivalent frameworks maintained by Google, Razorpay, and PayPal) to protect that information to a standard consistent with this Policy. We do not independently audit these providers' infrastructure, and rely on their public compliance representations.
If you access the Service from outside India, you understand and agree that your information will be transferred to, and processed in, India and the other countries referenced above, which may have data protection laws different from those of your home country.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
Questions about this Privacy Policy or how we handle your data can be sent to support.icoapp@gmail.com. See our Contact page for additional ways to reach us.