Legal

Privacy Policy

A plain-language summary of the data InvisiQ handles, where it sits, and what rights you have over it.

Last updated: 8 June 2026 · Version 1.2 (beta)

Before you start. During the beta, InvisiQ stores the text of the prompts you send, so we can understand what to build and improve the product. We store text only, never your screenshots or screen contents. API keys and obvious personal info are stripped before storage. Prompt data is deleted after 30 days, and you can wipe yours anytime in Settings → Privacy. This is the same notice you accept inside the app.

1. Who we are

This Privacy Policy applies to InvisiQ (the “Service”), a Windows desktop application operated by InvisiQ (“we”, “us”, “our”). We are based in New Delhi, Delhi, India. For privacy enquiries write to hello.invisiq@gmail.com.

2. The short version

The InvisiQ app runs on your machine, and your screen content never leaves your device. Screenshots are never stored or uploaded to us. We do operate a backend during the beta that handles Google sign-in, your 14-day trial, the text of the prompts you send (stored to improve the product, redacted and deleted after 30 days), and privacy-safe usage analytics. Your API keys, conversations, and memory index stay encrypted on your machine, and AI calls go directly to the provider whose key you configure. During the open beta we collect no payment details at all.

3. Information we collect

3.1 Account & trial data

  • Google sign-in identity. You sign in with Google; we receive your email address from Google to identify your account, send transactional emails, and respond to feedback.
  • Trial state (trial start date, days remaining), maintained on our server to run the 14-day free trial. The trial is enforced against our server clock, so changing your system clock, reinstalling, or making a new install does not reset it.
  • No payment details are collected during the open beta. If we introduce paid plans in future, any billing data will be handled by a PCI-DSS-compliant payment partner and this policy will be updated before that happens.

3.2 Prompt text (beta)

  • During the beta, the text of the prompts you send is stored on our backend so we can understand what to build and improve the product.
  • Before storage, we strip API keys and obvious personal information (such as emails, phone numbers, and card-like numbers).
  • We store text only, never your screenshots or screen contents. Whether a prompt included an image is recorded only as a yes/no flag; the image itself is not kept.
  • Stored prompt text is deleted after 30 days. You can wipe your data anytime in Settings → Privacy (“Delete my data”).

3.3 Product analytics

We collect privacy-safe product analytics to understand how the app is used, for example, app launched, signed in, message sent (with a length bucket, not the content), and trial expired. These events are not used to build advertising profiles.

3.4 Feedback you submit

  • If you submit a review or feedback, we store the name, email, rating, and message you provide, so we can act on it and reply to you.

3.5 Operational logs

Our trial-verification server logs the IP address, app version, and timestamp of each verification request. We retain these logs for a maximum of 30 days for fraud prevention and then permanently delete them.

3.6 Data we do not collect

  • Screenshots, region captures, or any pixel data from your screen
  • The contents of your conversations beyond the prompt text described in §3.2 (model responses and your local chat history stay on your device)
  • Keystrokes, mouse movement, or in-app interactions
  • Provider API keys (these are encrypted locally on your machine, see §5)
  • Cookies or web tracking identifiers on this marketing site

4. How prompts and screen content are handled

When you send a prompt or screen capture to an AI provider, that request goes directly from your device to the provider you configured (OpenAI, Anthropic, or Google), it does not pass through any InvisiQ server, and the screenshot itself is never sent to us. The data-handling terms of that AI provider apply to the content of the request. Separately, and as described in §3.2, the text of your prompt (redacted) is stored on InvisiQ’s backend during the beta and deleted after 30 days. Review each provider’s policy:

5. Local data storage

The following data is stored on your computer only:

  • API keys, encrypted with AES-256-GCM. The key is derived from your machine fingerprint using PBKDF2-SHA256 with 600,000 iterations.
  • Conversation history, encrypted at rest.
  • The local TF-IDF memory index, encrypted at rest.
  • Cached preferences, mode definitions, and rebinding state.

You can clear all local data, and request deletion of the prompt text stored on our backend, at any time via Settings → Privacy (“Delete my data”).

6. Legal bases for processing

Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and where applicable the EU GDPR, we process the limited personal data above on these bases:

  • Contract: account & trial data are required to provide the Service.
  • Consent: storage of your prompt text during the beta, which you accept in the “Before you start” notice before using the app.
  • Legitimate interest: short-lived trial-verification logs (fraud prevention) and privacy-safe product analytics (improving the Service).

7. Your rights

You may at any time:

  • Request a copy of the personal data we hold about you.
  • Ask for corrections to inaccurate data.
  • Request deletion of your account and associated data (subject to legal-retention duties on financial records).
  • Withdraw any consent you have given.
  • File a grievance with our Data Protection Officer at hello.invisiq@gmail.com.

Indian residents may also approach the Data Protection Board of India under the DPDP Act. EEA residents may lodge a complaint with their supervisory authority.

8. Children

The Service is not intended for users under the age of 18. We do not knowingly process the personal data of minors. If we learn we have done so, the account will be terminated and the data deleted.

9. International transfers

Account and billing data is hosted on infrastructure operated within India. Where data leaves India (for example, through your direct connections to non-Indian AI providers you configure), that transfer is initiated by you and governed by the recipient’s policy.

10. Retention

  • Prompt text (beta): 30 days, then permanently deleted.
  • Account data: retained while your account is active, plus 90 days after closure.
  • Feedback and reviews: retained for up to 24 months to inform the product roadmap.
  • Trial-verification logs: 30 days, then permanently deleted.
  • Product analytics: retained in aggregate to track product trends.

11. Security

We implement reasonable administrative, technical, and physical safeguards: encryption in transit (TLS 1.3) and at rest (AES-256-GCM), principle-of-least-privilege access controls, regular dependency audits, and a documented incident-response plan. No system is perfectly secure; if you discover a vulnerability, please report it to hello.invisiq@gmail.com.

12. Changes to this policy

We may update this policy. Material changes will be announced inside the app and on this page at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the current version.

13. Contact

Questions, concerns, or requests of any kind: