Privacy Policy
The short version
- Files you upload are processed in memory and never written to disk. Full reports are deleted after 24 hours.
- We keep a short summary of each audit and a snapshot of each project so we can show what changed and alert you later. They are deleted when you delete your account.
- For Code Review and Design Audit, excerpts of your code or screenshots of your app are sent to Anthropic’s AI to be reviewed.
- If you use API Health, the AppKavo SDK in your app sends us details of failed API calls from your app (method, host, the path with IDs removed, error type, app and OS version, and a random install ID). We keep them for 30 days and never receive request or response contents.
- We don’t sell your data, show ads, or use analytics or tracking cookies.
1. Who we are
AppKavo is operated by Hicaso LLP, a limited liability partnership in India (“we”, “us”). We decide how and why the personal data described here is processed, which makes us the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023. The one exception is App Shield data about your app’s users, covered in section 7.
Questions? Write to Hello@hicaso.com.
2. What we collect
Account information
- Your name, email address and a scrypt hash of your password (never the password itself).
- If you sign in with Google: your Google account ID, name and email.
- Your plan, billing status and renewal date, and your email preferences (for example, whether you want the weekly digest).
What you give us to audit
- App builds (
.apk,.aab,.ipa), source code archives, and repositories you choose through GitHub. - URLs of websites, APIs and store listings you ask us to scan.
- Screenshots captured from a device you connect for a Design Audit.
- Dependency manifests and lockfiles sent by the
@appkavo/watchCLI or GitHub Action. - Push credential details you add for expiry alerts (such as the expiry date of an APNs certificate or FCM key).
These files can contain personal data or secrets, such as API keys embedded in an app. We process them only to produce your audit.
GitHub
If you connect GitHub, we receive an access token and your GitHub username so we can list and read the repositories you choose. The sign-in token is held only in your server session. If you install the AppKavo GitHub App, we store the installation and the repositories it covers, plus push notifications GitHub sends us, so we can review new commits.
Payments
Payments are handled by Razorpay. We receive and store your subscription ID, plan and renewal date. We never see or store your card, UPI or bank details.
Technical data
- For Live URL Scans run without an account, we record your IP address as a daily counter to enforce the free limit. These counters are erased after one year.
- Our servers briefly use IP addresses in memory for rate limiting and abuse prevention.
3. How we use it
- To run the service: producing audits, reports, score badges and comparisons between audits.
- To keep watching: nightly vulnerability and store-policy checks, credential expiry reminders, and alert emails for projects you watch.
- To run your account: sign-in, email verification, password resets, billing and plan limits.
- To email you: service emails and the weekly digest. You can turn the digest off in your dashboard.
- To keep AppKavo safe: rate limits, abuse prevention and fixing problems.
We process this data because you asked us to provide the service, or because you consented, for example by signing up or connecting GitHub. We do not sell personal data. We don’t use your uploads to train AI models, and we don’t share them for advertising.
4. AI processing
Some features use Claude, an AI model made by Anthropic, through Anthropic’s commercial API:
- Code Review: excerpts from your largest developer-written source files, plus the static-analysis findings.
- Commit reviews: the changes in a commit pushed to a repository connected through the GitHub App.
- Design Audit: screenshots of your app and the measurements we take from them.
- Rejection explainer: the rejection message you paste and, if you link an app, that app’s Store Readiness findings.
Binary audits (APK, AAB, IPA), Live URL Scans, API audits, Store Readiness and the privacy generator don’t send your files to an AI model. (If you link an app in the Rejection explainer, its Store Readiness findings — not your file — are sent with your message.)
5. Who we share it with
We share data only with service providers who help us run AppKavo, and only what each one needs:
| Provider | What they receive | Why |
|---|---|---|
| Anthropic | Code excerpts, commit changes, app screenshots, rejection messages | AI review and Rejection explainer (see section 4) |
| Razorpay | Your billing details, entered on Razorpay’s own form | Payments |
| GitHub | Requests made with your token | Reading the repositories you choose |
| Sign-in requests; your IP address when our pages load Google Fonts | Google sign-in; fonts | |
| OSV.dev and package registries (npm, PyPI, pub.dev, Packagist and others) | Package names and versions only | Vulnerability lookups and checking that packages exist |
| Our email delivery provider | Your email address and the message | Sending service emails |
| Our hosting provider | Everything we store | Running our servers and database |
Some of these providers may process data outside India. We may also disclose data when Indian law requires it, or to protect our users or AppKavo from fraud or abuse. If Hicaso LLP is merged or sold, your data would move to the new owner under this policy.
6. How long we keep it
- Uploaded files: processed in memory and discarded when the audit finishes. They are never written to disk.
- Full reports: deleted automatically after 24 hours.
- Audit summaries: scores, finding counts and similar details for your last 500 audits, kept until you delete your account.
- Project snapshots: the dependency list, Android permissions and components, store-related app metadata (which can include parts of your app’s Info.plist) and privacy mappings. Kept while your account exists so we can show what changed and send alerts.
- GitHub push records: deleted after 30 days, or 90 days if processing failed.
- Anonymous scan counters: daily IP counters used only for rate limiting, erased after one year.
- Records the law requires: where Indian law requires us to keep logs or records, for example under CERT-In’s log-retention directions, the DPDP Rules or tax law, we keep only what is required, for as long as required, and use it only for that purpose. Some processing logs can therefore outlast a deleted report or account.
- Account data: kept until you delete your account. Deleting it from your dashboard removes your account, audit history, snapshots, API tokens, alerts, GitHub App records and App Shield data. We may keep billing records where tax law requires.
7. App Shield SDK
If you add the App Shield SDK to your app, it sends us data from your users’ devices: a random ID generated on each install (not a hardware or advertising ID), your app and SDK version, the environment, security detections (such as a rooted device, emulator, debugger or hooking tool), the decision taken, and timestamps.
For this data, you are the Data Fiduciary and we process it on your behalf. You are responsible for telling your users about it in your own privacy policy and having a valid basis for collecting it. We use it only to provide App Shield to you, and it is deleted when you delete your project or your account.
8. Cookies
We use one essential cookie to keep you signed in, and your browser’s session storage to remember your profile while a tab is open. We don’t use analytics, advertising or tracking cookies.
9. Security
We use HTTPS, hash passwords with scrypt, hash API and SDK tokens before storing them, and keep uploads off disk. Our scanners refuse to reach private network addresses. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as Indian law requires.
10. Your rights
Under India’s Digital Personal Data Protection Act, 2023, you can:
- ask what personal data we hold about you and how we use it;
- ask us to correct, complete or update it;
- ask us to erase it, or delete your account yourself from the dashboard;
- withdraw consent at any time, which won’t affect processing already done;
- nominate someone to exercise these rights if you die or become unable to;
- raise a grievance with us, and then with the Data Protection Board of India.
To use any of these rights, email Hello@hicaso.com. We may need to confirm your identity first.
11. Children
AppKavo is a tool for developers and is not meant for anyone under 18. We don’t knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes
If we change this policy, we will update the date at the top. For significant changes, we will also email account holders before the change takes effect.
13. Contact & grievances
Grievance Officer, Hicaso LLP
Email: Hello@hicaso.com
We will acknowledge your message and aim to resolve it within 15 days.