Kopya

Privacy Policy

Last updated 6 August 2026

Kopya takes pictures of your screen. That deserves a plain explanation of where those pictures go, so this policy starts there.

Your screenshots

When you press the hotkey, the app captures your primary display, downscales it, and sends it over TLS to our server, which forwards it to our model provider for inference. Then:

  • We do not store it. The image exists in memory for the length of the request and is discarded when the answer returns. It is never written to disk on our servers.
  • We do not train on it. Requests are sent with storage disabled at the provider, so it is not retained for model training.
  • No human reviews it. There is no internal tool that can show us your screenshots, because there is nothing to show.
  • The answer is not kept either. It is returned to your app and forgotten.

The practical consequence: capture only what you are entitled to capture. If your screen shows someone else's confidential information, sending it to us — or any AI tool — may be something your employer or the law has an opinion about.

What we do store

Account

  • Your email address, display name and avatar URL, from the provider you sign in with.
  • How you signed in — Google, or an emailed sign-in link — and the account identifier that came with it.
  • Your plan, subscription status and renewal date.
  • Your language preference, so the app can open in the language you chose.

Devices

  • A name for each desktop install (your computer's hostname), its platform and app version, and when it was last active.
  • A cryptographic hash of its session token — never the token itself, so a breach of our database does not yield working credentials.

Usage

  • For each request: timestamp, token counts, computed cost, and whether it succeeded. This is what enforces the limits in the Fair Use Policy and what you see on your dashboard.
  • Not the screenshot, the question, or the answer.

Who else touches your data

  • OpenAI — receives the screenshot and question to generate the answer, with storage disabled.
  • Paddle — our payment provider and merchant of record. They handle checkout and hold your billing details; we never see your card number.
  • Google — if you sign in that way, receives a standard OAuth request and returns your basic profile.
  • Resend — our email provider, delivers your sign-in link. It sees your email address and nothing else.
  • NOWPayments — if you pay in crypto, processes that payment. We never see your wallet beyond the confirmation that payment arrived.
  • Neon and Vercel — our database and hosting providers.

We do not sell your data, and we do not run advertising or third-party trackers.

Your rights

You can see everything we hold about you on your dashboard. You can disconnect any device there, which invalidates its session immediately.

To export or delete your account and all associated data, email oxygrows@gmail.com. Deletion removes your account, devices and usage records; it does not remove invoices we are required to keep for tax purposes.

Depending on where you live you may have additional rights under the GDPR, UK GDPR, CCPA or Turkish KVKK, including access, rectification, portability and objection. The same email address handles all of them.

Retention

  • Account and device records: until you delete your account.
  • Usage records: 90 days, then aggregated and the per-request rows deleted.
  • Invoices: as long as tax law requires.

Contact

Questions about this policy go to oxygrows@gmail.com.