Privacy Policy
EclipseCopilot is built privacy-first. We collect only what the app needs to work for you, read your documents on your device where we can, and never use your household data to train AI. This policy explains what we collect, how we use it, and the control you have.
1. Who we are
EclipseCopilot is operated by KDEP Enterprise (“we”, “us”), the controller of your personal data. Contact us at [email protected].
2. What we collect
- Account details — your name and email from your sign-in provider (Apple or Google), and your account’s region and age band.
- Home data you add — bills, assets, warranties, documents, reminders, and household members you invite.
- Optional profile details — a phone number, date of birth, and a short bio, if you choose to add them. None of these are required to use the app, and you can remove them at any time.
- Amounts you record — purchase prices and dates for things you own, budget entries, and repair or project costs. These are figures you type in yourself. We never connect to a bank, and we never see a card or any other payment instrument.
- Device push token — if you enable notifications, so we can send reminders.
- Minimal diagnostics — basic, non-advertising usage signals to keep the app reliable. These are counted on our own servers to spot faults; there are no third-party analytics or advertising trackers in EclipseCopilot, and nothing is stored on your device for tracking.
3. How your documents are processed
When you scan a document on a phone, the text is recognizedon your device — the image stays on your phone, and only the extracted text is sent to us. On the web, where on-device scanning isn’t available, the document is read on our server. We use classical, on-device and server-side techniques — we do not use your data to train any AI model, and the app makes no paid, third-party AI calls.
4. How we use your data
- to provide the Service — store and show your home data back to you and members you authorize;
- to send reminders and safety-recall alerts you’ve opted into;
- to keep the Service secure and working;
- to comply with legal obligations.
We do not sell your personal data or use it for third-party advertising.
Our legal basis (UK/EU users)
Where the GDPR applies, we rely on these bases:
- Performance of a contract — storing and showing your home data, and running the reminders that are the point of the Service.
- Consent — push notifications, which you turn on yourself and can turn off at any time in Settings, without affecting what we did before you withdrew it. We do not currently run optional or third-party analytics, so there is nothing else here to consent to; if that ever changes, we will ask first rather than assume.
- Legitimate interests — keeping the Service secure, preventing abuse, and fixing faults. We balance these against your rights and use the least data that works.
- Legal obligation — where the law requires us to keep or disclose something.
5. Sharing & service providers
We share data only with members you invite to your home, and with a small set of service providers (processors) that operate the Service on our behalf:
- Amazon Web Services — hosting and storage of the Service and its database.
- Resend — transactional email (reminders, invitations, account notices).
- Expo push notification service — delivering notifications to your device.
- Apple and Google — sign-in only; they confirm who you are, and we never send them your home data.
- Cloudflare — DNS and protection for our web traffic.
Each is bound by a data-processing agreement and may use your data only on our instructions.
Free public sources we look things up in
Some features answer a question by asking a free public service. In every case we send the smallest thing that will get an answer, and never your documents, images, name, or address:
- Safety recalls & product details — we send a model number or VIN to the U.S. National Highway Traffic Safety Administration (NHTSA), the Consumer Product Safety Commission (CPSC), and Wikipedia.
- Weather for your home— we send your home’spostal code only to Zippopotam.us (to turn it into an approximate location) and Open-Meteo (to fetch the forecast). Your street address is never sent, and the forecast follows the home, not you.
These are lookups, not accounts: we don’t create a profile with them and they don’t receive anything that identifies you.
6. Where your data lives
Your account is assigned aresidency region when it’s created, and your personal data is stored in that region. Residency is fixed for the life of the account, so your data doesn’t move between regions unexpectedly.
7. Retention & deletion
- Delete a home— hidden immediately, recoverable for5 days, then permanently erased.
- Delete your account— blocked immediately, recoverable for30 days, then permanently erased.
- Inactivity — after long inactivity we warn you and, if the account stays abandoned, delete it to avoid keeping data no one uses.
- Activity history— the timeline of changes in each home is kept for2 years; older entries are automatically removed.
- Shared homes — if you leave a home others still own, your personal identifiers are removed while the shared household’s records remain for the co-owners.
- Account recovery records — if you use a recovery email to regain access after losing your Apple or Google account, we keep a record of each attempt (when it was started, the IP it came from, whether it completed or was cancelled) for 12 months. We keep it because a failed or cancelled attempt is often the only warning that someone tried to take your account, and that record is what lets us — and you — see it. It is then automatically removed.
After a deletion completes, data is purged from our systems and drops out of backups on their normal rotation.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to or restrict certain processing. You can delete your data yourself from Settings → Account, or contact us at [email protected] to exercise any of these rights.
Access and portability are self-service: Settings → Account → Download my data gives you a ZIP containing your personal data as spreadsheet-ready CSV files, the documents you uploaded, and a manifest explaining why each item is held and how long it is kept. You can download once a week. We ask you to sign in again first, because the file contains everything you have ever uploaded. Details belonging to other people in your household are left out.
We answer within one month. Exercising a right never costs you anything and never degrades the Service. If you think we’ve got it wrong, you have the right to lodge a complaint with your data-protection supervisory authority — in the EU, your national authority; in the UK, the Information Commissioner’s Office (ICO). We’d appreciate the chance to put it right first.
9. Security
Data is encrypted in transit and at rest. Each household’s data is isolated, and access is enforced by role at our servers — not merely hidden in the app. You can protect your own sign-in with multi-factor authentication — an authenticator app or a passkey.
10. Children
EclipseCopilot is for adults (18+). Children may appear only as adult-managed, non-login profiles and cannot sign in or hold an account.
11. International transfers
When you invite someone whose data will be processed in your account’s region, both of you confirm consent to that processing before access is granted, providing the basis for any cross-border transfer.
12. Automated processing
When you scan a document, we use deterministic pattern-matching to guess fields like the vendor, amount, and due date, and to suggest a category. It is a starting point, not a decision: nothing is saved until you confirm it, and you can edit every field. We make no decisions about you that produce legal or similarly significant effects, and there is no profiling of you as a person — only reading of the documents you choose to scan.
13. California privacy rights
If you live in California, you have the right to know what personal information we collect and why, to request a copy or its deletion, to correct it, and not to be discriminated against for asking. The categories we collect are listed in section 2, and we use them only for the purposes in section 4.
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not knowingly collect the personal information of anyone under 18 (see section 10). To exercise any of these rights, email [email protected].
14. Changes to this policy
We may update this policy; we’ll revise the “Last updated” date and, for material changes, notify you in the app.
15. Contact
Questions or requests? Email[email protected].