Privacy Policy
Last updated 3 September 2026
Kopya takes pictures of your screen. That deserves a plain explanation of where those pictures go, so this policy starts there.
Your screenshots
When you press the hotkey, the app captures your primary display, downscales it, and sends it over TLS to our server, which forwards it to our model provider for inference. Then:
- Kopya does not intentionally retain it after processing. Our application processes the image in memory for the request and does not add it to our database or application storage.
- Provider application storage is disabled. We send each request with the Responses API's storage setting disabled. OpenAI states that API inputs and outputs are not used to train its models by default unless the account owner explicitly opts in.
- Limited provider retention can still apply. OpenAI says request content may be retained in abuse-monitoring logs for up to 30 days by default and may be accessed by authorised personnel or contractors for abuse investigation, support, or legal compliance. Images flagged by safety classifiers may be retained for manual review.
- Kopya does not intentionally retain the answer either. It is returned to your app and is not added to our database or application storage.
The practical consequence: capture only what you are entitled to capture. If your screen shows someone else's confidential information, sending it to us — or any AI tool — may be something your employer or the law has an opinion about.
What we do store
Account
- Your email address, display name and avatar URL, from the provider you sign in with.
- How you signed in — Google, or an emailed sign-in link — and the account identifier that came with it.
- Your plan, subscription status and renewal date.
- Your language preference, so the app can open in the language you chose.
Devices
- A name for each desktop install (your computer's hostname), its platform and app version, and when it was last active.
- A cryptographic hash of its session token — never the token itself, so a breach of our database does not yield working credentials.
Usage
- For each request: timestamp, token counts, computed cost, and whether it succeeded. This is what enforces the limits in the Fair Use Policy and what you see on your dashboard.
- Kopya does not add the screenshot, question, or answer to its usage database.
Who else touches your data
- OpenAI — receives the screenshot and question to generate the answer, with application storage disabled. Its API data controls still allow abuse-monitoring logs for up to 30 days by default, while API inputs and outputs are not used for training by default. See OpenAI's API data controls.
- Polar — our payment provider, authorised reseller and merchant of record. Polar handles checkout and holds your billing details; we never see your card number. Your IP address is forwarded to Polar when checkout begins so it can select the payment currency, prefill the billing country and calculate applicable tax.
- Google — if you sign in that way, receives a standard OAuth request and returns your basic profile.
- Resend — our email provider, delivers your sign-in link. It sees your email address and nothing else.
- NOWPayments — if you pay in crypto, processes that payment. We never see your wallet beyond the confirmation that payment arrived.
- Neon and Vercel — our database and hosting providers.
- Meta and Reddit — only if you accept advertising cookies. See the next section for exactly what they receive.
Cookies and advertising measurement
Kopya sets a small number of essential cookies for sign-in, security and your language choice. These are needed for the service to work and do not require consent.
We also run ads on Meta (Facebook and Instagram) and Reddit, and we would like to know which of them bring people who actually use Kopya. That measurement is optional and happens only after you accept it in the cookie banner. You can use the whole site, download and use the app, sign up and pay without accepting it, and you can change your mind at any time via Cookie preferences in the footer. Browsers that send a Global Privacy Control or Do-Not-Track signal are treated as a refusal.
If you accept, the following happens:
- The Meta Pixel and the Reddit Pixel load on kopya.ai and set their first-party cookies (
_fbp,_fbc,_rdt_uuid,_rdt_cid). Their scripts report page views and the events below to Meta and Reddit. - Our servers report the same events to Meta's and Reddit's Conversions APIs: a download click, account creation, the first time the app answers a question for your account, and a completed purchase (with the order value and currency). Each event carries an identifier so both copies of an event are counted once.
- To match those events to an ad, we send the pixel cookie values, the click identifier from the ad link, your IP address and browser type as seen on kopya.ai, and, for account-level events, a SHA-256 hash of your email address and of your account id. We never send your screenshots, questions, answers, name, card details or raw email address.
- We keep our own record of how you found us (campaign parameters such as
utm_source, the page you landed on, the referring site and the click identifiers) together with your consent, for up to 90 days, and a record of the events above linked to your account so we can tell which campaigns work. Data needed to send an event to Meta or Reddit is deleted as soon as it has been delivered, or after 7 days at the latest.
Withdrawing consent stops the pixels, removes their cookies from your browser, deletes our stored attribution and cancels any event that has not yet been sent. Events already delivered are held by Meta and Reddit under their own policies: Meta privacy policy and Reddit privacy policy. Meta and Reddit act as independent controllers for what they do with that data, including combining it with their own account data.
Your rights
You can see everything we hold about you on your dashboard. You can disconnect any device there, which invalidates its session immediately.
To export or delete your account and all associated data, email hello@kopya.ai. Deletion removes your account, devices and usage records; it does not remove invoices we are required to keep for tax purposes.
Depending on where you live you may have additional rights under the GDPR, UK GDPR, CCPA or Turkish KVKK, including access, rectification, portability and objection. The same email address handles all of them.
Retention
- Account and device records: until you delete your account.
- Usage records: 90 days, then aggregated and the per-request rows deleted.
- Advertising consent and attribution: 90 days after your last consent refresh, or immediately on withdrawal.
- Invoices: as long as tax law requires.
Contact
Questions about this policy go to hello@kopya.ai.
