AppKavo
Legal

Privacy Policy

Effective 4 October 2026 · Hicaso LLP, India

The short version

1. Who we are

AppKavo is operated by Hicaso LLP, a limited liability partnership in India (“we”, “us”). We decide how and why the personal data described here is processed, which makes us the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023. The one exception is App Shield data about your app’s users, covered in section 7.

Questions? Write to Hello@hicaso.com.

2. What we collect

Account information

What you give us to audit

These files can contain personal data or secrets, such as API keys embedded in an app. We process them only to produce your audit.

GitHub

If you connect GitHub, we receive an access token and your GitHub username so we can list and read the repositories you choose. The sign-in token is held only in your server session. If you install the AppKavo GitHub App, we store the installation and the repositories it covers, plus push notifications GitHub sends us, so we can review new commits.

Payments

Payments are handled by Razorpay. We receive and store your subscription ID, plan and renewal date. We never see or store your card, UPI or bank details.

Technical data

3. How we use it

We process this data because you asked us to provide the service, or because you consented, for example by signing up or connecting GitHub. We do not sell personal data. We don’t use your uploads to train AI models, and we don’t share them for advertising.

4. AI processing

Some features use Claude, an AI model made by Anthropic, through Anthropic’s commercial API:

Binary audits (APK, AAB, IPA), Live URL Scans, API audits, Store Readiness and the privacy generator don’t send your files to an AI model. (If you link an app in the Rejection explainer, its Store Readiness findings — not your file — are sent with your message.)

5. Who we share it with

We share data only with service providers who help us run AppKavo, and only what each one needs:

ProviderWhat they receiveWhy
AnthropicCode excerpts, commit changes, app screenshots, rejection messagesAI review and Rejection explainer (see section 4)
RazorpayYour billing details, entered on Razorpay’s own formPayments
GitHubRequests made with your tokenReading the repositories you choose
GoogleSign-in requests; your IP address when our pages load Google FontsGoogle sign-in; fonts
OSV.dev and package registries (npm, PyPI, pub.dev, Packagist and others)Package names and versions onlyVulnerability lookups and checking that packages exist
Our email delivery providerYour email address and the messageSending service emails
Our hosting providerEverything we storeRunning our servers and database

Some of these providers may process data outside India. We may also disclose data when Indian law requires it, or to protect our users or AppKavo from fraud or abuse. If Hicaso LLP is merged or sold, your data would move to the new owner under this policy.

6. How long we keep it

7. App Shield SDK

If you add the App Shield SDK to your app, it sends us data from your users’ devices: a random ID generated on each install (not a hardware or advertising ID), your app and SDK version, the environment, security detections (such as a rooted device, emulator, debugger or hooking tool), the decision taken, and timestamps.

For this data, you are the Data Fiduciary and we process it on your behalf. You are responsible for telling your users about it in your own privacy policy and having a valid basis for collecting it. We use it only to provide App Shield to you, and it is deleted when you delete your project or your account.

8. Cookies

We use one essential cookie to keep you signed in, and your browser’s session storage to remember your profile while a tab is open. We don’t use analytics, advertising or tracking cookies.

9. Security

We use HTTPS, hash passwords with scrypt, hash API and SDK tokens before storing them, and keep uploads off disk. Our scanners refuse to reach private network addresses. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as Indian law requires.

10. Your rights

Under India’s Digital Personal Data Protection Act, 2023, you can:

To use any of these rights, email Hello@hicaso.com. We may need to confirm your identity first.

11. Children

AppKavo is a tool for developers and is not meant for anyone under 18. We don’t knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes

If we change this policy, we will update the date at the top. For significant changes, we will also email account holders before the change takes effect.

13. Contact & grievances

Grievance Officer, Hicaso LLP
Email: Hello@hicaso.com

We will acknowledge your message and aim to resolve it within 15 days.