Short version.
Copio keeps clipboard content encrypted on your device. Cross-device sync is optional and starts only after you consent. When it is on, the service receives encrypted clip envelopes and limited metadata, never the vault key, your device PIN, a backup passphrase or the plaintext of a clip. OTP clips and content excluded by your rules do not sync. We do not sell personal data, run advertising or train AI models on your content. Big Helpers is the Data Fiduciary and has a named Grievance Officer you can write to.
1. Who is responsible
Copio is operated by Big Helpers, India, which is the Data Fiduciary for the personal data described in this notice. Big Helpers decides why and how that data is processed.
Data Fiduciary: Big Helpers.
Grievance Officer: Big Helpers, shrawan@bighelpers.in.
Write to the Grievance Officer for any privacy request, question or complaint. Never send your password, recovery key, backup passphrase, device PIN, access token or clipboard content by email. We will never ask for them.
2. This notice and the DPDP Act
The Digital Personal Data Protection Act, 2023 (the DPDP Act) requires a Data Fiduciary to give you a notice before or at the time it asks for consent (section 5). The notice must describe the personal data, the purpose, how you exercise your rights and how you complain to the Data Protection Board of India. This page is that notice. Section 5(3) allows the notice to be read in English or any language in the Eighth Schedule to the Constitution, so it is also published in Hindi.
Inside the app, the same information is shown on the consent screen headed "Your data, plainly stated" before sync is switched on. That screen, this page and the consent notice together form the notice under section 5.
3. Data we handle
- Account data: name, email address, optional username, optional mobile number, locale and timezone, whether the email or phone has been verified, and the date the account was created.
- Profile photo: if you add one, the image is encrypted on your device under the vault key before upload. The server stores only ciphertext and a blob identifier. It cannot display or inspect your photo.
- Device and security data: platform, device name, the device's public encryption key and its fingerprint, last-seen time, optional push token, device-bound access tokens and their revocation state, passkey metadata (credential identifier, nickname, last-used time), sign-in attempts, account-lock counters, consent records, and the IP address and browser or app identifier recorded with those events as security and consent evidence.
- Synced vault data: encrypted clip bodies (ciphertext), encrypted per-clip keys, non-secret nonces, content type, byte size, a one-way integrity fingerprint, client and server identifiers, folder relationship, pinned state, timestamps, expiry and deletion state, and the SHA-256 fingerprint of your vault key (not the key). Encrypted files and images travel the same way as blobs.
- Verification and pairing data: hashed one-time codes for email verification and password reset, the provider request reference for phone verification (the SMS provider generates and checks the code; our server never sees it), and short-lived pairing records that relay a wrapped vault key between two of your own devices.
- Rights and grievance data: grievances, corrections, nominee details and account erasure requests you submit.
- Billing data: where a paid plan is bought, the order, payment and entitlement identifiers supplied by Razorpay (UPI on Mac and web), Apple or Google, the plan and its dates. Copio never stores card, bank or UPI credentials. The current mobile beta collects no payment details.
- Operational data: bounded server logs, error reports and security events needed to run and protect the service. Clipboard plaintext, keys and recovery secrets are never intentionally logged.
The integrity fingerprint is server-visible metadata. It is not a decryption key, but the fingerprint of very common text could in principle be guessed. Use exclusion rules for anything that must stay on one device.
4. Why we process it, and the lawful basis
Section 4 of the DPDP Act permits processing only for a lawful purpose, either with your consent (section 6) or for a legitimate use listed in section 7. Copio relies on:
- Consent (section 6) for optional cross-device sync and for phone verification. Each is a separate, unticked choice. Withdrawing consent is as easy as giving it (section 6(4)): in Copio on iPhone, iPad, Mac and Android, switch sync off under Settings, then Privacy; on the web app, which has no sync switch yet, remove the browser or any other device under Settings, then Devices, erase the account, or raise a grievance from Settings, then Privacy and legal, with the subject "Withdraw sync consent", which we action within 2 working days; remove your number in Profile to withdraw phone verification. Withdrawal stops future processing; it does not make earlier lawful processing unlawful (section 6(5)).
- Data you volunteer for a stated purpose (section 7(a)) for creating and securing your account, verifying your email, registering and revoking devices, pairing, answering support and grievance requests, running export, correction, erasure and nomination, and billing a plan you buy.
- Compliance with a court order or a legal obligation (section 7(d)) where Indian law requires us to keep or hand over a record.
We also use the data to prevent abuse, diagnose failures, enforce quotas and expiry rules and keep the service secure, all of which are part of providing the service you asked for. We do not profile you, sell personal data or use it for advertising.
5. Clipboard and device permissions
Capture works differently on each operating system. iOS saves content through the app, the share extension or Copio Keyboard; the keyboard does not request Full Access. Android background clipboard access is restricted, so capture uses an explicit foreground flow, the optional Copio Keyboard and an optional accessibility-assisted quick-paste control. macOS can monitor the pasteboard and requests Accessibility only for direct paste. The browser extension acts only on an explicit action. These permissions are used for Copio features, not for advertising or profiling.
6. What the server can and cannot see
Copio is zero-knowledge by construction. Your vault key is generated on your first device and travels to another device only inside an encrypted pairing relay (X25519 key agreement, HKDF and AES-256-GCM) or inside a recovery kit you hold. The server stores a fingerprint of the key so it can refuse a mismatched device, but never the key. Your account password proves who you are; it is never used to encrypt clips. Your device PIN and biometric lock are checked on the device only. A backup passphrase for a .copio-backup file never leaves the device that made the file.
What the server can see: the metadata listed in section 3, when your devices sync, and which devices hold the key. What it cannot see: the text, image or file inside any clip, your profile photo, your PIN, your passphrase or your vault key. If every device and your recovery key are lost, nobody, including Big Helpers, can decrypt the vault.
7. Sharing, processors and location
The Copio API and encrypted storage run on Big Helpers infrastructure in India. We use a small number of processors only to the extent needed to provide the service:
- Email delivery for verification codes, password reset, account and grievance mail, sent from
noreply@copioapp.com. - SMS verification through MSG91, which receives your mobile number to deliver and check a one-time code when you choose to add a phone number.
- Payments through Razorpay for UPI and card payments on Mac and web, and through Apple or Google for store purchases, each under its own privacy notice.
- App distribution through Apple and Google, which process crash and device information under their own notices.
Processors act on our instructions and cannot read clip content, because they never receive it. We do not sell personal data, share it for behavioural advertising or use clipboard content to train AI models. We disclose personal data to a public authority only when Indian law requires it.
8. Security safeguards
Section 8(5) of the DPDP Act requires reasonable security safeguards. Clip bodies are encrypted on the device with AES-256-GCM under per-clip keys wrapped by the vault key. Device pairing uses X25519 and a 12-digit safety number that you compare on both screens. Passkeys are supported for sign-in. Access tokens are bound to one device, expire after 30 idle days and can be revoked from any other device. Ten failed sign-ins in 15 minutes lock the identifier temporarily. Keys and tokens live in the platform security store. No system is free of risk, so keep your recovery key safe and separate from your devices.
9. Personal data breach
Section 8(6) of the DPDP Act requires a Data Fiduciary to intimate the Data Protection Board of India and each affected Data Principal when a personal data breach occurs. If we become aware of a breach affecting your personal data we will:
- contain the incident and record what happened, when and what data was involved;
- report it to CERT-In within 6 hours of noticing it, as the CERT-In directions of 28 April 2022 require;
- intimate the Data Protection Board of India within 72 hours;
- notify you without delay by email and in the app, describing the nature of the breach, the likely consequences, what we have done and what you can do, including revoking devices or rotating your recovery key.
Because clip content is encrypted with keys the server never holds, a breach of the server exposes ciphertext and metadata, not the text of your clips.
10. How long we keep data
Section 8(7) of the DPDP Act requires us to erase personal data once the purpose is served or consent is withdrawn, unless a law requires retention. The table below gives the actual periods. "Erasure" means the account erasure you trigger in the app or by verified request.
| Data | Kept for | Then |
|---|---|---|
| Account (name, email, username, phone, locale, timezone) | Life of the account | Deleted on erasure |
| Device records and public keys | Until you revoke the device or erase the account | Deleted on erasure; revoked access tokens are purged 90 days after revocation |
| Access tokens | Until sign-out, revocation, or 30 days without use | Revoked tokens purged after 90 days |
| Clip ciphertext and per-clip keys | Until you delete the clip, it expires (OTP clips after 3 minutes, or your own rule), or it falls outside the free tier's 500 live clips | Ciphertext removed; a content-free deletion marker stays until erasure so deletion reaches every paired device |
| Encrypted files, images and profile photo (blobs) | Same as the clip or profile that references them | Deleted from disk when the clip is deleted and on erasure |
| Verification codes and pairing records | Email codes 15 minutes, phone codes 5 minutes, pairing relay 2 minutes | Pairing rows removed after 24 hours; used or expired codes cannot be reused |
| Consent records (what you agreed to, when, from which device) | Life of the account | Deleted on erasure |
| Billing records (order, payment and entitlement identifiers, plan dates) | Life of the account, plus the period Indian tax and accounting law requires after each transaction (currently up to 8 financial years) | Deleted when that period ends |
| Grievance and rights requests | Until resolved, then 3 years | Deleted |
| Erasure record (anonymised confirmation that an account was erased) | 30 days after erasure | Hard-deleted by a daily job |
| Server, security and error logs | Up to 90 days | Rotated out and deleted |
Account erasure revokes every token, deletes the server-side identity, devices, encrypted clips and blobs, configuration, billing references, nominee and grievance data, and sends you a confirmation email. It does not destroy the independent encrypted vault already stored on your own device. Remove the app and its local data separately if you also want that copy gone. See Delete your Copio account.
11. Your rights as a Data Principal
The DPDP Act gives you these rights. Each is a control in the app, and each can also be raised with the Grievance Officer.
- Access (section 11): a summary of the personal data we hold about you, what we do with it and who it has been shared with. Use Export in Settings, or ask the Grievance Officer.
- Correction and erasure (section 12): fix account information in Settings, delete individual clips at any time, and erase the whole account from Settings. We may keep only what a law requires, for as long as it requires.
- Grievance redressal (section 13): see section 12 below.
- Nomination (section 14): name a person who may exercise these rights if you die or become incapacitated. Add or change your nominee in Settings.
- Withdraw consent (section 6(4)): switch off sync in the apps, or on the web remove your devices, erase the account or raise a grievance with the subject "Withdraw sync consent"; remove your phone number at any time. Section 4 gives the steps.
- Revoke a device: cut off any paired device immediately from any other device.
Section 15 of the DPDP Act also places duties on you: give accurate information, do not impersonate another person, and do not file a false or frivolous grievance. We may ask for proportionate verification before acting on a request, and we will never ask for your password or recovery key.
12. Grievance redressal
Section 13 of the DPDP Act gives you the right to a readily available means of grievance redressal. Use Settings, then Privacy and legal, then Raise a grievance, or write to the Grievance Officer:
Grievance Officer, Big Helpers
shrawan@bighelpers.in
We acknowledge every grievance within 2 working days and resolve it within 30 days. If you are not satisfied with the response, or do not receive one in that time, you may approach the Data Protection Board of India under section 13(3) of the Act.
13. Children
Section 9 of the DPDP Act requires verifiable parental consent before processing a child's personal data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Copio is intended for people aged 18 or older. Do not create an account for a child. If we learn that an account belongs to a child without verifiable parental consent, we will erase it. We do not track or profile any user, child or adult.
14. Changes to this notice
We will update the date at the top and give an appropriate in-app or email notice before a material change. Where a change needs fresh consent, we will ask for it in the app rather than assume it. The Hindi version of this notice is at copioapp.com/privacy-hi.html. If the two versions differ, the English version governs.