Legal
Privacy Policy

How we handle your data

Impo is a personal memory OS. Trust is the entire product. This document explains, in plain language, what we collect, why, and the choices you always have.

The short version

  • Impo is a private, AI-powered memory vault. Your data is yours — we don't sell it, we don't train external models on it, and we don't share it with advertisers.
  • Passwords stored in your vault are encrypted server-side (Fernet). Only your account can decrypt them.
  • You can export or delete everything you've stored at any time from Profile → Data controls.
  • We use Claude (Anthropic) for AI features. Prompts are sent transiently, not retained by us for training, and never labelled with your identity.

Data we collect

We only collect what's needed to run the product for you:

  • Account: email or phone number, hashed password, subscription plan, timezone.
  • Content you save: notes, documents, photos, videos, passwords, journal entries, reminders, and any other item you choose to add. This is the app's core purpose.
  • Device metadata: installed passkey credentials (public key only), push-notification subscription tokens if you enable them.
  • Diagnostics: minimal server logs (IP, user-agent, error stack traces) for debugging and abuse prevention. Kept 30 days, then rotated.
  • Product analytics: we use PostHog to understand feature usage in aggregate. Events are keyed to a pseudonymous ID; we don't send raw content to PostHog.

What we DON'T do

  • We don't sell your data. Ever.
  • We don't use your content to train AI models.
  • We don't share your content with advertisers or data brokers.
  • We don't read your vault. Passwords remain encrypted at rest — support staff cannot see them.
  • We don't attach identifying info to AI prompts sent to third parties.

Who processes your data on our behalf

We use a small number of trusted subprocessors:

  • Anthropic (Claude): AI intent routing and vision categorization. Prompts sent transiently; not retained for training.
  • OpenAI (Whisper) — optional: only if you connect your own OpenAI API key for voice transcription. Audio never touches OpenAI unless you opt in.
  • Google (OAuth & Calendar sync) — optional: only if you connect a Google account. Impo requests the minimum scopes required.
  • Razorpay: payment processing for subscriptions. Card data never touches Impo servers.
  • MongoDB Atlas: managed database hosting.
  • PostHog: aggregate product analytics (see “Data we collect” above).

How we use your data

  • To operate the product: storing notes, documents, running search, delivering reminders, syncing Calendar, etc.
  • To power AI features: your prompts and — for images marked for classification — the image are sent to Anthropic transiently. No account identifier accompanies these requests.
  • To keep the service safe: throttling abuse, detecting fraud, and honoring lawful requests.
  • To improve the product: aggregate, non-identifying usage patterns (which features are used, error rates, etc.) via PostHog.

How long we keep data

  • Your content: retained as long as your account is active. When you delete an item it is soft-deleted immediately and hard-deleted from primary storage within 30 days. Backup snapshots roll over within 60 days.
  • Account deletion: when you delete your account (Profile → Data controls → Delete account) all associated content, files, and backups are removed within 60 days. Some records (payment invoices, security logs) may be retained longer where legally required.
  • Server logs: rotated after 30 days.

Your rights

Regardless of where you live, you can:

  • Access & export: download all your data as JSON from Profile → Backup & restore.
  • Correct: edit any item directly, or contact support for account fields.
  • Delete: individual items via the delete-with-undo flow, or the entire account via Profile → Data controls.
  • Object & restrict: disable optional integrations (Voice transcription, Google Calendar sync) at any time.
  • Portability: the JSON export is a portable, human-readable format.
  • Complain: if you're in the EU/UK you may lodge a complaint with your local data protection authority; in India you may contact the Data Protection Board.

Cookies & local storage

  • Authentication: we store a JWT token in localStorage to keep you signed in. Clearing your browser data logs you out.
  • Offline queue: we use IndexedDB to hold writes made while offline; they sync when you're back online, then are removed.
  • Preferences: your theme choice (light/dark) is stored locally.
  • Analytics: PostHog sets a pseudonymous ID cookie for aggregate metrics. It's not used for advertising.

International transfers

Our primary infrastructure is hosted in the region best suited for latency and legal compliance for our user base. AI features may transiently transfer prompt data to Anthropic infrastructure in the United States. When these transfers happen, we rely on Standard Contractual Clauses and/or vendor-specific data-processing agreements for lawful cross-border transfer.

Children's privacy

Impo is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us data, please contact us at hello@impoapp.com and we will delete it.

Contact us

Privacy questions, deletion requests, or feedback: hello@impoapp.com.

If you're a data-protection authority reaching out on behalf of a user, please include the affected account identifier in your request so we can respond within statutory deadlines.