Privacy Policy
Effective: July 15, 2026 · Last updated: July 15, 2026
1. Who we are
incogno is an AI-assisted meeting and productivity application operated by Incogno ("incogno", "we", "us"). This Privacy Policy explains how we collect, use, store, and share personal data when you use the incogno desktop application, the website at incogno.ai, the customer and administrative portals, and our AI assistance, transcription, screen-context, billing, and support services.
For privacy questions or requests contact privacy@incogno.ai (privacy and data-protection requests) or support@incogno.ai (support); consumer complaints follow the separate track on our Grievance Redressal page. Our designated Privacy Officer / Data Protection Officer can be reached at privacy@incogno.ai. We aim to respond within 30 days.
2. What incogno does
incogno is an AI meeting copilot that provides real-time transcription, contextual assistance, summaries, notes, and answers based on information you supply. Depending on the features you enable, incogno may process meeting audio, transcripts and detected questions, text you type, visible screen text, screenshots you expressly submit, and AI-generated responses.
incogno's current Mac application captures system or meeting audio only, and only when you start Listen. It does not capture microphone audio: your own voice is picked up only if it is part of the system audio (for example, played back by the meeting app). If microphone capture is introduced in the future, incogno will request a separate operating-system permission and update this Policy before enabling it.
3. Personal data we collect
The table below itemises each category of personal data we process, what it includes, and the specific purpose it serves:
| Category | What it includes | Purpose |
|---|---|---|
| Account & authentication | Name, email, password (stored only as a hash), account ID, login sessions, refresh tokens, device names/identifiers, MFA settings, plan status | Creating and securing your account, sign-in, session and device management |
| System/meeting audio | Transient audio frames streamed while Listen is active (never your microphone) | Real-time transcription; processed transiently, never stored |
| Transcripts | Partial and final live transcripts, detected questions, the recent transcript excerpt sent with an assist request | Live captions, question detection, and context for the answer you asked for; stored only if you save a summary or run deep analysis |
| Typed prompts & AI outputs | Questions you type, generated answers, mode/answer-style/model preferences | Producing the assistance you requested; prompt and answer text is not stored — only usage metadata (model, token counts, latency) |
| Screen text | Text extracted via accessibility APIs or OCR, active application and window titles | Screen-aware answers when you enable them; processed ephemerally |
| Screenshots | A compressed screenshot of your screen — only when the screen-vision feature is used (Capture & Solve stays on-device: only the question text you confirm is sent) | Visual analysis you requested; not stored by incogno — AI providers may retain API inputs briefly under their own policies (see Subprocessors) |
| Knowledge base | Documents you upload and the embeddings generated from them | Retrieving your own material to improve answers; kept until you delete them |
| Saved summaries & deep analysis | Meeting summaries you save; deep-analysis transcripts with chapters, topics, text-based conversation-tone analysis, and speaker labels | Features you explicitly invoked; kept until you delete them or close your account |
| Network & device data | IP address, network-derived country signal, device and session identifiers, authentication tokens | Security, abuse prevention, rate limiting, regional plan enforcement, session management |
| Usage, quota & billing | Token counts, request metadata, plan and quota state, transaction and subscription identifiers, invoices, tax details, offers and refunds | Billing, quota enforcement, fraud prevention, accounting and tax compliance (we never receive your full card number — Razorpay processes payments) |
| Cookies & analytics | Essential session cookies; consent-gated analytics cookies and events on our public website (Google Analytics), including an analytics cookie identifier — never your account identifier, and never inside your signed-in account | Keeping you signed in; understanding how our public website and sign-up flow are used, only after you consent |
| Support communications | Your messages, contact details, and files you voluntarily provide | Resolving your requests (please never send passwords or payment credentials) |
| Consent records | Accepted policy version, timestamp, IP address, browser user-agent | Evidence that you accepted the Terms and this Policy |
What we do not collect: we do not create or store voiceprints or other biometric identifiers. Speaker labels in deep-analysis results are positional labels ("Speaker A", "Speaker B") derived from the conversation, not biometric templates.
4. How we use personal data
We use personal data to create and secure your account, authenticate you and manage sessions, provide transcription and AI assistance, understand typed questions and meeting context, provide screen-aware assistance when enabled, generate notes and summaries, operate subscriptions, trials, quotas, and billing, provide customer support, prevent fraud and abuse, diagnose technical problems, monitor availability and performance, comply with legal obligations, and improve the reliability and usability of the service.
We do not use meeting content to serve third-party advertising. We do not sell personal data. We do not use your private meeting, transcript, or screen content to train publicly available AI models. We use business/API offerings of our AI and speech providers and configure them, where supported, not to use submitted content to train general-purpose models — per-provider details and any exceptions are disclosed on our Subprocessors page.
Automated processing: to deliver the service, incogno automatically detects questions in the conversation, classifies requests, selects an AI provider or model for each request, enforces regional plans, applies fraud, quota, and security controls, and generates answers and summaries. We do not use these systems to make employment, credit, medical, legal, or similarly significant decisions about you.
We may create and use aggregated, de-identified statistics (for example, feature-usage counts and performance metrics) to operate and improve the service; we do not attempt to re-identify this data. We send transactional email (verification codes, receipts, security alerts) as part of the service; marketing email is sent only with your consent and always includes an unsubscribe option.
5. Audio, transcripts, and deep analysis
Raw meeting audio is processed transiently for live transcription and is never stored in your account. The optional deep analysis feature ("Understand") uploads the meeting audio once, after you stop listening, to produce chapters, topics, text-based conversation-tone analysis, entities, and a speaker breakdown; the uploaded audio is deleted right after analysis, and the resulting transcript and analysis are stored in your account until you delete them or close your account.
Meeting summaries you choose to save are stored until you delete them or close your account. Everything stored in your account is included in your data export and removed by account deletion (section 9).
6. AI providers and limited caching
incogno uses third-party AI and speech providers to deliver its features: currently speech-to-text by Deepgram and AssemblyAI, and AI responses by OpenAI, Anthropic, and Google. The current list, purposes, and processing locations are maintained at incogno.ai/subprocessors. Service providers may process data only for the services they provide to incogno, subject to contractual and security obligations.
To keep the service fast we cache a small class of AI responses server-side. Requests containing meeting-transcript or screen content are never cached — only standalone coding and definition answers with no transcript or screen context are eligible.
7. Data sharing and disclosure
We share personal data only with:
- service providers and subprocessors (hosting, AI, speech-to-text, email — see subprocessors), bound to process data only for the services they provide to us;
- payment and billing providers, to process your transactions;
- professional advisers (legal, accounting, audit) under confidentiality;
- a buyer, investor, or successor in connection with a merger, acquisition, reorganization, or sale of the service — your data remains subject to this Policy;
- government or law-enforcement authorities where legally required;
- other parties where you direct or authorize us to.
We never disclose meeting content to advertisers. We may disclose information where we reasonably believe it is necessary to protect users, incogno, or the public from fraud, abuse, security threats, or unlawful activity.
8. Data retention
We retain personal data only as long as needed for the purposes described here:
- Raw meeting audio: transient processing only — never stored (deleted immediately after transcription or deep analysis).
- Live assist prompts, transcript excerpts, screen text, and screenshots: processed ephemerally and not stored by incogno (usage metadata only). Our AI and speech providers may retain API inputs briefly under their own retention policies — see the Subprocessors page.
- Saved meeting summaries, deep-analysis transcripts, and knowledge-base documents and embeddings: until you delete them or close your account.
- Account, usage, consent, security, and audit records: for the life of your account, then removed with account deletion (except as noted below).
- Billing, invoice, and tax records: retained for the legally required accounting period even after account deletion; after deletion they are no longer linked to an identifiable account.
- Support communications: retained in our support mailbox while relevant to your requests.
- Consent-gated analytics events: up to 24 months, then deleted or aggregated.
When you delete content or your account, it is removed from our production systems immediately; encrypted backups expire on their backup cycle. We retain certain security, processing, and transaction records for periods required by applicable law and our verified retention schedule, and we are preparing our systems for the retention requirements that will apply under India's DPDP framework as its provisions take effect. We may retain limited information where necessary to prevent fraud, enforce our Terms, or comply with legal obligations.
9. Your rights
Depending on your location, you may have the right to access your personal data, obtain information about how it is processed, correct inaccurate information, request deletion, withdraw consent, object to or restrict certain processing, request portability, nominate another person to exercise your rights where applicable, and complain to a data-protection authority.
You can exercise the most important rights directly: Account → Export my data downloads everything stored in your account, and Account → Delete account permanently erases it. For anything else, email privacy@incogno.ai. We may need to verify your identity before completing a request. We aim to respond within 30 days (or sooner where the law requires).
India: privacy and data-rights requests go to privacy@incogno.ai (response target 30 days, identity verification where necessary); these rights and processes are ones incogno supports today and is preparing for full compliance with as India's DPDP framework takes effect. Consumer complaints (billing, service) follow a separate track — see our Grievance Redressal page (acknowledgement within 48 hours, resolution target one month). Once the relevant DPDP provisions are in force, you may also complain to the Data Protection Board of India in the manner prescribed under the DPDP Rules. EEA/UK: you may lodge a complaint with your local supervisory authority. California: we do not sell personal information and do not share it for cross-context behavioral advertising, so no "Do Not Sell or Share" opt-out is required; California residents otherwise have the rights to know, access, correct, and delete described above, with equal service when exercising them.
10. Meeting participants and third-party data
incogno may process personal data belonging to people participating in a meeting or visible on your screen. You are responsible for having authority to process that information: providing any legally required notice, obtaining any required consent, following workplace, interview, examination, and meeting policies, and complying with recording, interception, and privacy laws.
Our role varies by processing activity:
| Processing | incogno's role |
|---|---|
| Account, authentication, billing, fraud prevention, security, support | Data Fiduciary / controller |
| Website analytics and marketing | Data Fiduciary / controller |
| Content you submit for Assist, Listen, or deep analysis | incogno processes it to deliver the service you request, determining some of the technical means |
| Content processed for a business customer under a Data Processing Addendum | Processor / service provider |
| Other meeting participants’ data | Processed on your instruction, subject to incogno’s own legal obligations — you are responsible for notice and consent |
When an organization uses incogno for its own meetings, that organization may be the data controller (or Data Fiduciary) for participant data and incogno its processor or service provider; participants should direct requests about that data to the organization. Business and enterprise customers can request a Data Processing Addendum at legal@incogno.ai.
incogno's screen-share-exclusion ("stealth") functionality exists to keep your assistant private on your screen — it does not remove your obligation to disclose your use of the application where disclosure is legally, contractually, or ethically required.
11. Legal bases
Where a legal basis is required, we process personal data on the basis of contract (providing the service you requested), consent (optional features such as screen capture, deep analysis, non-essential analytics), legitimate interests (securing the service, preventing abuse, troubleshooting), and legal obligation (tax, accounting, fraud-prevention, and lawful-request requirements). You may withdraw consent for optional processing at any time through the application, the cookie controls, or by contacting us; withdrawal does not affect processing that occurred before it.
12. International data transfers
incogno and its service providers process data in countries other than your own — our application infrastructure runs in Singapore, and our AI, speech-to-text, and some other providers process data in the United States (see subprocessors for per-vendor locations). Where required, we use contractual, technical, and organizational safeguards for international transfers, subject to applicable Indian, European, UK, or other data-protection law.
13. Security
We use reasonable technical and organizational measures to protect personal data, including encrypted connections (TLS), password hashing, access controls, HttpOnly session cookies with refresh-token rotation, optional multi-factor authentication, restricted production access, logging and abuse detection, and secure cloud infrastructure. See our Security page for details. No method of transmission or storage is completely secure — you are responsible for protecting your device, credentials, and active sessions. If a personal-data breach creates a legal notification obligation, we will notify affected users and the relevant authorities as required by applicable law.
14. Children
incogno is not intended for anyone under 18. We do not knowingly permit children under 18 to create accounts or use the service — signup requires a declaration that you are at least 18. If you believe a child has provided personal data, contact privacy@incogno.ai and we will delete the account and its data.
15. Cookies
Our website uses essential cookies for authentication, security, and session management, and optional analytics cookies only where you consent. Our optional analytics are provided by Google Analytics (Google LLC) and load only after you accept them; we do not load them anywhere inside your signed-in account, and we disable Google Signals and ads personalisation, so they are not used for advertising. Information collected this way may be processed in or transferred to countries outside your country of residence, subject to the safeguards described in section 12. See the Cookie Policy and Subprocessors; you can change or withdraw your choice anytime via "Manage cookies" in the site footer, which stops further collection and clears the analytics cookies. Because there is no uniform standard for browser "Do Not Track" signals, we do not respond to them — our analytics are opt-in by consent instead.
16. Changes to this Policy
We may update this Policy when the product, legal requirements, or our processing practices change. Material changes will be communicated through the website, the application, or account email, and may require you to re-accept the updated documents. The effective date above shows when this Policy was most recently revised.
17. Contact and grievance handling
Privacy, data rights, and DPO: privacy@incogno.ai (response target 30 days) · Consumer grievances: grievance@incogno.ai (acknowledged within 48 hours, resolved within one month — see Grievance Redressal) · Support: support@incogno.ai · Legal/DPA: legal@incogno.ai
Entity: Incogno — full entity and officer details on our Contact page.