Kopigo

Privacy policy

This policy explains how Kajodex handles personal data when you use Kopigo, its account service, and its subscription features. It applies to the Kopigo application and backend; the Kajodex website has a separate website privacy notice.

Controller: Kajodex, Helsinki, Finland. Privacy and support contact: support@kajodex.com.

The short version

  • Clipboard content is end-to-end encrypted on your devices. The Kopigo backend cannot read it and clears delivered ciphertext; undelivered ciphertext expires after 30 minutes.
  • OCR images, recognized text, QR captures and values, and clipboard history stay on your device.
  • We process account, device-routing, delivery, notification, and subscription data needed to operate and protect Kopigo.
  • We do not sell personal data, use it for advertising, or include third-party analytics trackers in Kopigo.

Account and authentication data

Firebase Authentication, provided by Google, handles Kopigo sign-in. Depending on the method you choose, Google or Apple may also process the sign-in request under its own privacy terms.

  • Firebase processes your email address, authentication credentials or provider identity, Firebase user identifier, and authentication security metadata.
  • The Kopigo backend stores your Firebase user identifier, an optional keyed one-way hash of your email address rather than the address itself, account timestamps, and a session-revocation watermark.
  • We never send your password or provider access token to the Kopigo backend.

Purpose and legal basis: creating and securing your account and performing our contract with you. Security and abuse prevention are also our legitimate interests.

Encrypted content in transit

When you send text, your device encrypts it separately for each destination device before upload. The backend receives only ciphertext, a nonce, a one-time sender public key, and the routing fields needed to deliver that encrypted envelope. It does not hold the private keys required to decrypt your content.

The backend clears stored ciphertext when the receiving device confirms delivery. If delivery never completes, the encrypted envelope expires and is erased after 30 minutes.

Device data and encrypted device metadata

  • For each registered device, the backend stores a random device identifier, platform type, X25519 public key, registration and last-seen timestamps, revocation state, and current connection state.
  • Device display names and system hostnames are encrypted on your devices before storage. The backend stores only recipient-specific opaque envelopes and cannot read those names.
  • Device private keys stay in platform secure storage and never leave the device.

Purpose and legal basis: routing encrypted transfers between devices attached to your account and performing our contract with you.

Routing and acknowledgement metadata

To route transfers and synchronize status, the backend stores limited metadata: random item and delivery identifiers, which of your devices sent an item to which of your devices, creation and expiry times, delivery and first-copy acknowledgement times, and non-content item preferences such as expiry behavior. This metadata does not contain readable clipboard text and is normally retained for no more than 7 days.

Android push notifications

On Android, Kopigo registers a Firebase Installation ID so Firebase Cloud Messaging can alert a background or locked device. The identifier is encrypted at rest on the Kopigo backend. A push contains only a generic clipboard-arrival event and a random, short-lived delivery identifier. It never contains clipboard content, ciphertext, account identifiers, device identifiers, device names, or hostnames. The registration is removed when you sign out, revoke the device, or delete the account.

Data that stays on your device

  • Readable clipboard text and the content currently being composed.
  • OCR source images, recognized text, QR captures, and decoded QR values. Recognition and decoding run locally.
  • Your 50 newest sent and 50 newest received history entries, encrypted locally with an account-scoped key held in platform secure storage.
  • Device private keys and locally decrypted device names and hostnames.

Subscriptions and purchase data

Kopigo uses RevenueCat to validate and synchronize Premium subscriptions across supported platforms. Apple App Store or Google Play processes the purchase and payment. Kajodex does not receive your full payment-card details.

  • RevenueCat receives your opaque Firebase user identifier as the Kopigo App User ID, together with platform and store transaction information needed to validate the purchase, such as an Apple receipt or Google purchase token, product, entitlement, subscription status, renewal state, and period dates.
  • RevenueCat may process limited technical information required to operate its SDK and subscription service, such as platform, operating-system information, locale, currency, and last-use time. Kopigo does not send RevenueCat your email address, clipboard content, device names, advertising identifiers, or custom analytics attributes, and disables RevenueCat diagnostics collection.
  • The Kopigo backend stores the subscription provider, status, entitlement, product, store, environment, renewal state, period end, and update time so it can enforce plan limits. It stores no payment-card data.

Purpose and legal basis: performing the Premium subscription contract, preventing purchase fraud, restoring entitlements across your devices, and meeting legal obligations related to paid services.

Service providers and recipients

  • Google provides Firebase Authentication and Android Firebase Cloud Messaging. Apple and Google may also provide federated sign-in when you select their sign-in method.
  • RevenueCat validates and synchronizes subscription entitlements. Apple App Store and Google Play process purchases, receipts, refunds, and subscription management under their own terms and privacy notices.
  • Hetzner hosts the Kopigo backend in the European Union and necessarily processes network-level technical data, such as IP addresses, to carry requests and protect its infrastructure.
  • Email and support providers process information you choose to send when contacting support. Personal data may also be disclosed where law requires it or where necessary to establish, exercise, or defend legal claims.

Legal bases

  • Contract: account authentication, device registration, encrypted transfer routing, history-related acknowledgements, plan enforcement, and subscription delivery.
  • Legitimate interests: securing accounts and infrastructure, preventing abuse and fraud, diagnosing service-level failures without logging clipboard content, and maintaining service availability.
  • Legal obligation: tax, accounting, consumer-protection, lawful-request, and data-protection duties where they apply.
  • Consent: only where a platform permission or applicable law specifically requires consent. You may withdraw consent through the relevant platform setting, without affecting earlier lawful processing.

International data transfers

The Kopigo backend is hosted in the European Union. Google, Apple, and RevenueCat are international providers and may process data outside the European Economic Area. Where required, transfers rely on the safeguards available under the relevant provider agreement, such as an adequacy decision or approved standard contractual clauses. Provider privacy notices describe their locations and safeguards in more detail.

Retention

  • Encrypted transfer envelopes: until delivery, and no longer than 30 minutes if undelivered.
  • Routing and acknowledgement metadata: normally up to 7 days.
  • Account, device, encrypted device-metadata, and backend subscription records: while your Kopigo account exists, unless a shorter operational period applies.
  • Deleted-account security tombstone: the opaque Firebase user identifier and deletion/session times for approximately 24 hours, preventing an already-issued token from recreating the account.
  • Android push registration: until sign-out, device revocation, or account deletion.
  • Support correspondence and legally required transaction records: only as long as reasonably necessary for the request or the applicable legal retention period. Store and processor copies follow their own documented retention rules.

Security

Kopigo uses per-device X25519 keys, fresh ephemeral keys for transfers, and ChaCha20-Poly1305 authenticated encryption. Local history and readable device metadata are encrypted with account-scoped keys held in platform secure storage. Access to backend records is authenticated and restricted to the owning account.

No system is perfectly secure. Keep your device, operating system, store account, and Kopigo credentials protected, and contact support@kajodex.com if you suspect unauthorized access.

Your data-protection rights

Under the EU General Data Protection Regulation, where applicable, you may request access to and correction or erasure of your personal data, restriction of processing, objection to processing based on legitimate interests, and portability of data you provided. You may also withdraw consent where processing relies on consent.

Email support@kajodex.com from the address associated with your Kopigo account. We may need to verify account ownership before acting. You also have the right to complain to a supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Account deletion and local copies

Deleting your Kopigo account removes its server-side subscription record, devices, encrypted metadata, push registrations, clipboard-item metadata, and pending deliveries, subject to the short security tombstone and any legal retention duty described above. Account deletion does not cancel an Apple App Store or Google Play subscription; cancel it separately in the store.

The device performing deletion removes its account-scoped keys, preferences, and encrypted history. Kopigo cannot remotely erase encrypted history already stored on another offline device. Remove Kopigo or clear its local data on devices you no longer control.

Children

Kopigo is a general productivity tool and is not directed specifically at children. A minor should use Kopigo only with the involvement of a parent or legal guardian where required by local law, especially before starting a paid subscription.

Changes to this policy

We update this policy when Kopigo’s data handling, providers, or legal obligations change. Material changes will be communicated in the application, by email, or through another appropriate notice. The date below identifies the current version.

Last updated: July 30, 2026