Short version.
Clips are encrypted on your device with AES-256-GCM under per-clip keys that are wrapped by a vault key. The vault key is generated on your first device and never sent to the server. It reaches another device only through an encrypted pairing relay that you verify with a 12-digit safety number, or through a recovery key that only you hold. Your password proves who you are; it never unlocks a clip. If every device and the recovery key are lost, nobody, including Big Helpers, can read the vault.
1. Three secrets, and only one of them is ours
- Your password proves your identity to the server. It is stored only as an Argon2id hash. It never encrypts a clip, so a server that knows your password hash still cannot read your vault.
- Your device lock, Face ID, Touch ID, fingerprint or an optional 6-digit PIN, is checked on the device and never leaves it.
- Your vault key is the only secret that opens clips. It exists on your devices and inside your recovery key. The server holds a fingerprint of it, so it can refuse a mismatched device, and nothing more.
2. How a clip is sealed
- Each clip gets its own random key and is encrypted with AES-256-GCM on the device that captured it.
- That per-clip key is wrapped under the vault key, a random 256-bit key created on your first device.
- Only the ciphertext, the wrapped key, a non-secret nonce and routing metadata are sent. Files, images and your profile photo travel the same way.
- One-time passwords are never synced at all. They stay on the device that saw them and expire after three minutes.
3. What the server can and cannot see
Can see: your account details, which devices you have and when they last synced, which devices hold the vault key, the size, type, timestamps and one-way integrity fingerprint of each clip, folder relationships, and billing references. The full list is in section 3 of the privacy notice.
Cannot see: the text, image or file inside any clip, your profile photo, your vault key, your recovery key, your device PIN or your backup passphrase. Because the integrity fingerprint of very common text could be guessed by comparison, keep anything that must never leave a device local with an exclusion rule.
4. Devices and sign-in
- Every install is a device with its own X25519 key pair. The private half never leaves the platform security store on that device.
- Access tokens are bound to one device, expire after 30 days without use and can be revoked from any other device. Sign-out revokes only the current token; "sign out everywhere" revokes all of them.
- Ten failed sign-ins in 15 minutes lock the identifier temporarily.
- Passkeys are supported for sign-in. Adding or removing a passkey requires you to re-authenticate.
- Email verification codes are six digits, valid for 15 minutes and allowed five attempts. Phone codes are generated and checked by the SMS provider; our server never sees the code.
- Apple and Google sign-in are not offered in this release.
5. Pairing a new device
Pairing is how the vault key gets from a device you already trust to a new one. It is same-account only: the new device signs in first, and only then can it be paired.
- The new device creates its device key pair and starts a pairing. It shows a QR code and a six-digit code that expire after two minutes.
- On a device that already holds the key, you scan the QR code or type the six digits. That device fetches the new device's public key from the relay.
- Both devices show the same 12-digit safety number as six pairs, for example
38 71 24 09 55 12. It is derived from the key agreement between the two devices, so if anyone is sitting between them the numbers differ. Compare them. If they differ, cancel and pair again. - When you approve, the existing device wraps the vault key for the new device's public key using X25519 key agreement, HKDF and AES-256-GCM, and sends the wrapped key through the relay.
- The new device unwraps the key, confirms its fingerprint matches the one the account already holds, and can now read and write clips.
The server relays ciphertext only. It stores the pairing for a short time, checks that both sides belong to the same account, and cannot open the wrapped key. Until a device holds the vault key it cannot read or write a single clip.
6. Recovery key and backups
When your vault is created on the first device, Copio shows a recovery key once and asks you to confirm you have stored it. That key is the only way back into the vault if every paired device is lost. We cannot reset it, because we never have it. Keep it in a password manager or on paper, away from your devices.
Export everything in Settings produces a .copio-backup file: your account data, settings, rules, devices, consents and every clip, decrypted on the device and re-encrypted with AES-256-GCM under a key derived from a passphrase you choose with Argon2id. The file is safe to keep anywhere and can be imported on any platform. The passphrase never leaves the device that made the file.
7. Revoking and erasing
Any device can be revoked from any other device, and the server refuses its token immediately. The revoked device still holds its local copy of the vault key and the encrypted clip cache until it next connects: the web app clears both the moment the server refuses its token, and the apps do the same on their next sync. A device that never connects again keeps what it already had, behind its own lock. Account erasure revokes every token, deletes your identity, devices, encrypted clips and blobs, and sends a confirmation email; an anonymised erasure record is hard-deleted after 30 days. Erasure does not destroy the encrypted vault already on your own device, which you remove separately. See Delete your Copio account.
8. Infrastructure and breaches
The Copio API and encrypted storage run on Big Helpers infrastructure in India. Every connection uses HTTPS with strict transport security, and the website carries a content security policy that allows only its own scripts. If a breach of our systems ever affects your personal data we contain it, report it to CERT-In within 6 hours, intimate the Data Protection Board of India within 72 hours and notify you without delay, as section 9 of the privacy notice sets out. A breach of the server exposes ciphertext and metadata, not the text of your clips.
9. What we ask of you
- Store your recovery key away from your devices, and keep a
.copio-backupfile somewhere safe. - Compare the safety number every time you pair. Never approve a pairing you did not start.
- Revoke a lost or sold device from another device, or from the web, as soon as you can.
- Use exclusion rules for anything that must stay on one device.
- Copio emails carry codes, never links that ask for your password. Nobody from Big Helpers will ever ask for your password, recovery key, PIN or a one-time password.
10. Reporting a security issue
If you believe you have found a vulnerability in Copio or this site, email admin@bighelpers.in with "Copio security" in the subject and enough detail for us to reproduce it. We acknowledge every report within 2 working days and tell you what we did about it. Please do not access, change or keep data that is not yours while testing. The Hindi version of this page is at copioapp.com/security-hi.html.