Cloud AI is disclosed
Kopti tells you when cloud AI is used for text, receipt, photo, or PDF understanding.
Privacy Policy
Kopti is built around private real-life maintenance details, receipts, warranties, and reminders. This policy explains what information is processed, why it is used, and how to contact us.
Effective July 29, 2026
Current app
Kopti tells you when cloud AI is used for text, receipt, photo, or PDF understanding.
AI can prepare a candidate. Only confirmed structured memory is added to items and history.
Original attachments are sent for parsing, then not kept on Kopti servers.
Kopti makes it straightforward to export structured data or delete your account and data.
Kopti is operated by the developer identified on the Kopti operator page. That developer is the controller for the personal data described here. For privacy requests, contact hello@kopti.app.
Kopti processes your name, email address, and account identifier supplied through Sign in with Apple; notes, transcripts, item and group names, internal record identifiers, metadata key names, dates, reminder settings, service history, receipt and warranty details; photos, PDFs, and other attachments you choose; App Store subscription transaction identifiers; feedback and support messages; and limited operational records such as quota use, export requests, deletion requests, request identifiers, status, and timing. Kopti does not use advertising identifiers or cross-app tracking.
With your explicit permission, Kopti sends the text or transcript you submit and any selected receipt, photo, or PDF to its configured cloud AI provider through Kopti's private LiteLLM gateway. To match the capture safely, the request may also include current saved item and group names, internal identifiers, group relationships, and metadata key names. This context lets the model match an event or reminder to an existing item even when your capture does not repeat the item's saved name. No existing notes, event history, reminder history, or metadata values are sent as matching context.
Technical metadata sent through the gateway includes a request-scoped identifier, capture-pass label, and content length. It does not include your stable Kopti user identifier or a plain content digest. The current cloud AI provider processes the request to prepare a draft and to operate and safeguard its service. Under its current API terms, content is not used to train its models by default; its abuse-monitoring logs may retain customer content for up to 30 days unless approved stricter controls apply. Kopti does not train its own models on your capture content.
Permission is stored per account and enforced by the backend before new text or attachments are sent, so withdrawing it applies across devices. Existing saved information remains available, but new AI drafts and attachment imports are disabled until permission is allowed again.
The iOS app records a voice note only after microphone and speech-recognition permission. Apple Speech converts the recording to English text, using on-device recognition when available. The temporary audio file is deleted after transcription or cancellation. Only the transcript is offered for cloud AI processing, subject to the separate cloud-AI permission.
Original attachments are sent for parsing, then not kept by the Kopti backend. If you keep proof, the iOS app stores the original locally with complete file protection and Kopti stores document metadata only. Those user-retained originals remain eligible for device backup under your Apple or Finder backup settings; whether a backup is available or encrypted depends on those settings. Kopti cache, pending shared imports, and temporary exports are excluded from device backup and follow their local cleanup lifecycle.
Providers receive the information needed for their role. Kopti does not sell personal information and does not use the app or website for advertising tracking.
Website fonts are served by Kopti, and the site uses no analytics, advertising tracker, or non-essential cookie. The minimized Nginx access event contains timestamp, HTTP method, normalized path without its query string, response status, response size, and request duration. It excludes IP addresses, forwarded IP addresses, referrers, and user agents. Nginx error records can still contain network information such as an IP address when needed to diagnose a malformed request or server failure.
Ordinary backend logs keep structural diagnostics such as request, user and entity identifiers, route template, status, timing, release, provider status, and database error code. Raw database messages, details, and hints are not copied into ordinary logs. Ordinary website and backend logs are restricted to the operator and authorized support administrators and kept in size-bounded rotating storage. Older entries are automatically removed as the configured storage limit is reached, so retention varies with log volume.
Full AI input/output logging is disabled during normal production operation. Authentication tokens, authorization material, and attachment bytes are not written to these logs.
Kopti's backend and private AI gateway run on Oracle infrastructure in Europe, and the Supabase project is hosted in the EU. The cloud AI provider, Apple, WishKit, and the support-mail path through Namecheap and the configured downstream mailbox provider may process information outside the European Economic Area depending on the service and its configuration. Kopti uses the transfer mechanism applicable to the provider and processing, such as an adequacy decision or standard contractual clauses where required. Kopti does not promise that cloud AI or WishKit processing remains only in the EU unless approved EU service controls are configured. Contact hello@kopti.app for information about the safeguards relevant to your data.
Structured items, events, reminders, document metadata, and capture history remain until you delete them or delete your account. Pending drafts expire after 14 days. Expired or failed extraction records are removed after 30 days, completed draft records after 90 days, and soft-deleted records and cleared chat after 30 days. Operational audit records are retained for up to one year and App Store subscription event history for up to two years. Routine resolved support correspondence is deleted within 12 months unless a legal obligation or active dispute requires it for longer. Original attachment bytes are not retained by the Kopti backend.
When an account-deletion receipt completes, active Kopti account and application data has been deleted. Restricted security logs, processor records, and encrypted backups may remain until their normal retention schedules expire; deleted account data is not restored into active use. WishKit controls its copy of feedback records under its retention policy. You can ask Kopti to access or delete identifiable WishKit feedback data by emailing the privacy contact below.
Apple processes payment details. Kopti receives verified transaction identifiers, subscription status, product, expiration, and account-binding information needed to grant Pro access. Deleting a Kopti account does not cancel an App Store subscription; subscriptions must be managed separately through Apple.
Subject to the conditions in applicable law, you can request access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, and portability of data you provided. You can also withdraw cloud-AI consent at any time.
The in-app export is a convenient portable copy of structured profile, group, item, maintenance, reminder, and document data, with chat optional. It is not necessarily a complete response to a GDPR access request. Email hello@kopti.app for a complete access request or to exercise any other right. Kopti may need to verify your identity before disclosing or changing account data.
You also have the right to complain to Latvia's Data State Inspectorate (Datu valsts inspekcija). Its personal-data complaint service explains how to submit a complaint.
We may update this policy as Kopti changes. If we make material changes, we will update the effective date on this page and seek renewed permission where a changed consent disclosure requires it.
iPhone app
Download Kopti on iPhone to keep item histories, proof, warranties, and reminders close to the things they belong to.
Designed for water filters, coffee machines, air purifiers, smoke detectors, bikes, warranties, receipts, repairs, and recurring care.