Privacy notice
Effective and last updated: 24 August 2026
1. Who operates Copio
Copio is operated by Big Helpers in India. For privacy requests and grievances, contact the Big Helpers privacy team at bossess.com@gmail.com. Do not send your password, recovery phrase, recovery package, access token or clipboard content by email.
2. Data we handle
- Account data: name, email address, optional phone number, locale and timezone.
- Device and security data: platform, public encryption key, device identifier, public-key fingerprint, last-seen time, optional push token, token/device revocation state, login and consent records, IP address and user agent where needed for security and consent evidence.
- Synced vault data: ciphertext, encrypted per-clip keys, non-secret nonces, content type, byte size, a one-way content integrity fingerprint, client and server identifiers, folder relationship, pinned state, timestamps, expiry and deletion state. The server does not receive the vault master key or plaintext clip body.
- Account-rights data: grievances, corrections, nominee details and account-erasure records that you choose to submit.
- Billing data: no payment details are collected in the current mobile beta. If paid service is later enabled, the payment or app-store provider supplies limited order, payment and entitlement identifiers; Copio does not store full card or bank credentials.
- Operational data: bounded server logs, error information and security events needed to operate and protect the service. Clipboard plaintext and recovery secrets are not intentionally logged.
The integrity fingerprint is server-visible metadata. It is not a decryption key, but a fingerprint of very common text may be guessable. Avoid syncing secrets that your own exclusion rules should keep local.
3. Clipboard and device permissions
Local capture behavior differs by operating system. iOS saves content through the app, share extension or Copio Keyboard; the keyboard does not request Full Access. Android background clipboard access is restricted, so capture uses an explicit foreground flow, the optional Copio Keyboard and an optional accessibility-assisted quick-paste control. macOS can monitor the pasteboard and can request Accessibility only for direct paste. Browser access occurs through explicit extension actions. These permissions are used for Copio features, not advertising or profiling.
4. Why we process data
We use the data above to create and secure your account, register and revoke devices, provide optional encrypted sync and pairing, apply retention and quota rules, answer support or grievance requests, provide export/correction/erasure/nominee controls, prevent abuse, diagnose failures and meet legal obligations. Optional sync starts only after an affirmative consent choice and can be withdrawn in the app.
5. Sharing and location
The Copio API and encrypted storage are hosted on Big Helpers infrastructure in India. We may use infrastructure, security, email or payment processors only as needed to provide the service. Apple and Google process store distribution, crash or device information under their own notices. We do not sell personal data, share it for behavioural advertising or use clipboard content to train AI models.
6. Security and recovery
Clip bodies are encrypted on the device with AES-256-GCM. Device pairing uses X25519 and safety-number confirmation. Tokens and vault keys are protected using platform security stores. No system is risk-free. Keep your 12-word recovery phrase and encrypted recovery package separately; both are required. Big Helpers cannot decrypt your vault or replace a lost recovery secret.
7. Retention and deletion
Account and encrypted sync data remain while the account is active or until an expiry/deletion rule applies. Soft-deleted clip tombstones may remain so deletion can propagate to paired devices. When authenticated account erasure is accepted, access tokens are revoked and server-side identity, device records, encrypted clips, encrypted blobs, configuration, billing records, nominee and grievance data are deleted; a minimal anonymised erasure record may remain. Security or transaction records may be retained only where law requires it.
Account erasure does not silently destroy the independent encrypted vault already stored on your device. Remove the app and its local data separately if you also want that device copy deleted. See Delete your Copio account.
8. Your choices and rights
Subject to applicable law, you can withdraw sync consent, export the account data held by the service, correct account information, erase the account, revoke devices, nominate another individual and lodge a grievance. Use the controls in the app or contact us. We may ask for proportionate verification and will never ask for your password or recovery phrase by email.
9. Children
The current internal beta is intended for people aged 18 or older. Do not create a beta account for a child. A future child-access flow will require the legally required verifiable parental consent before being offered.
10. Changes
We will update the date above and give an appropriate in-app or email notice before a material change. You can read this notice in Hindi.