incove Privacy Policy

incove ("the Service") is an application for gathering and looking back on short everyday moments inside closed groups of family and people close to you. The operator treats your personal information seriously and complies with the Personal Information Protection Act and other applicable laws. This policy explains what information the Service processes and how, and in particular how end-to-end encryption (E2EE) protects your content.

1. End-to-end encryption (E2EE) — core principle

The contents of videos and the contents of sealed messages (Echoes) captured or uploaded in the Service are encrypted on your device, and the decryption key is stored wrapped to the public keys of the people meant to receive that content — so it can only be decrypted on their devices.

No third party, including the operator, can decrypt or view this content. It is transmitted to and stored on servers (database and storage) only in encrypted form, and the server does not hold the decryption key. This content is therefore not information that the operator can "collect" and read or analyze.

Profile (avatar) images and videos are not covered by the end-to-end encryption described above. Because an avatar has to be displayed to the other members of your group, it is stored unencrypted and can be viewed by the operator. They are protected by access control instead: the storage bucket is not public, and once the requester is confirmed to be a member of the same circle we issue only a signed URL for that person's current avatar, expiring after ten minutes. Avatar images chosen from the gallery are re-encoded before upload so that EXIF is removed entirely (see section 11).

The following, which the Service needs in order to run, is also unencrypted: account information (display name, email and so on), circle names and the member list with their labels, emoji reactions, timestamps such as when something was recorded or shared, mood values, and the sender's display name and event type carried in a push notification (a notification never carries the content itself). Reports, blocks and audit records are likewise unencrypted.

The unlock time of a sealed message (Echo) is chosen by the user (from 1 day up to 5 years, 6 months by default). For an Echo addressed to someone else, the server enforces the lock by refusing to deliver the ciphertext before that time. An Echo you leave for yourself is your own record, so the server has no reason to hide it from you — it simply is not shown in the app until the day you chose. Either way the server may know "when it is delivered," never "what it says."

2. Personal information we process

We process the following to provide the Service. The E2EE content in section 1 cannot be read by the operator and is listed separately below.

CategoryItemsPurpose
Account / authEmail or social login identifier, display name, records of your consent choices and withdrawals (with timestamps)Member identification, authentication, account management, proof of consent
ProfileProfile/avatar image or video, circle membership and role infoIn-group display and features. Avatars are not E2EE and can be viewed by the operator; an access URL is issued only to requests verified as coming from a group member (see section 11)
Device / pushDevice identifier, push token (FCM)Notifications, security
Usage metadataUpload frequency/time, group creation/invite patterns, non-identifying mood valueOperation, abuse detection, music matching (only the on-device mood result is sent)
Reports / safetyReport reason and details, submitted evidence (with reporter consent)Handling illegal/harmful content (section 6)
App usage statsApp launches, screen views, menu taps and capture completions (app interactions), app instance identifier, device/OS/app version, approximate region derived from the IP address (down to city level)Improving the Service by understanding usage flow. Screen-view and menu statistics are processed by Google LLC (Google Analytics for Firebase) as our processor; app-launch and capture-completion counts are stored on our own servers and not provided to third parties. Collected only if you turn on Settings > Privacy > Usage stats in the app (off by default); you can turn it off in the same place at any time (collection stops immediately and both identifiers are reset). Not linked to account identifiers
Website useIP address, browser/device info, visit logs, cookiesOperating and securing the incove.app website, usage analytics (section 10)
E2EE contentVideo and sealed-message contents (profile avatars not included)Not readable by the operator. Relayed/stored as ciphertext only

EXIF and other metadata (including capture location) are stripped from uploaded videos. Avatar images chosen from your gallery are also re-encoded before upload to strip GPS, orientation and other metadata, and avatar videos can only be recorded in the app. If you turn on app usage stats, Google Analytics derives an approximate region — down to city level — from your IP address and uses it for analysis. incove's servers do not store this value, and precise location is never collected. The Service has no advertising and does not collect advertising identifiers.

3. Purposes of use

Collected information is used only for member management and identity verification, providing group-based sharing and recap features, sending notifications, ensuring service stability and preventing fraudulent/illegal use, statistical analysis of usage to improve the Service, and fulfilling legal obligations. Usage analysis is performed in a form that does not identify individuals, and its results are not used for advertising. It is not used for other purposes; if purposes change, separate consent is obtained.

4. Retention and use period

As a rule, personal information is destroyed without delay, by irreversible means, upon account withdrawal. Exceptions:

5. Account and data deletion

You may request deletion of your account and related data at any time.

For the exact in-app location and details of what is deleted or briefly retained, see How to delete your account.

On request, the operator destroys the personal information linked to the account and the content you uploaded (including ciphertext), except material subject to the legal retention/preservation in section 4. If you own a group, group handling follows the in-app guidance.

Some things remain after deletion. For 90 days after withdrawal the same email address cannot be used to sign up again; to enforce this we keep only a one-way hash of the address, never the address itself. Your withdrawal reason and the record of messages you received before withdrawing are kept, detached from the account, for service improvement and dispute handling. Reports you filed and security-event records are not deleted — the user identifier is stripped from them and the records are retained for audit purposes.

6. Handling illegal/harmful content

Although the Service is closed, safety measures are taken only when a group member files a report. Content submitted with the reporter's consent (material the reporter can legitimately decrypt) is used only to process the report and meet legal obligations, and is stored in a separate secure area for that purpose. See the Terms of Service and the in-app community guidelines and child-safety policy for details.

7. Provision to third parties

The operator does not sell your personal information or provide it for marketing. It may be provided only in the following cases.

8. Entrustment of processing

We entrust the following processing tasks to run the Service. Entrustment contracts include the safeguards required by law, and processors act only within the entrusted scope under our supervision.

ProcessorEntrusted taskInformation processedStorage / processing location
Supabase, Inc.Authentication and database operationEmail/social login identifier, display name, circle info, consent recordsSeoul, Republic of Korea (AWS ap-northeast-2)
Cloudflare, Inc.Content storage (R2)E2EE-encrypted videos and messages (unreadable to the operator); profile avatar images and videos (not encrypted — viewable by the operator; non-public bucket, time-limited URL issued only after group-membership verification)Globally distributed (automatic region) — not pinned to one country
Google LLCPush notifications (Firebase Cloud Messaging), app usage stats (Google Analytics for Firebase), social sign-inDevice identifier, push token, app instance identifier, app interaction recordsUnited States and global
Functional Software, Inc. (Sentry)App error and performance diagnosticsDevice, OS and app version at the time of an error; error stack informationUnited States
Cloudflare, Inc.Website (incove.app) hosting and delivery, inquiry email routingIP address, request logs, inquiry emailsGlobal (edge network)
Google LLCWebsite analytics (Google Tag Manager / Google Analytics), inquiry email reception (Gmail)Cookies, visit logs, approximate region, inquiry emailsUnited States and global

9. International transfers

In providing the Service, some personal information is transferred and stored abroad as follows. E2EE content is transferred only as ciphertext, unreadable to anyone including the recipient. Video contents are ciphertext in whichever region they are stored, so where they sit does not change how well they are protected. Profile avatars are not E2EE, so they are transferred and stored unencrypted, protected by a non-public bucket and access controls.

RecipientCountryItemsWhen / howPurpose and retention
Google LLCUnited States and othersDevice identifier, push token, app instance identifier, app interaction records, cookies/visit logs, inquiry emailsContinuous transmission over the network while using the Service/websiteNotifications, app and website usage analytics, support / until entrustment ends or deletion (app analytics per the retention period in section 4)
Cloudflare, Inc.United States and others (global edge)E2EE ciphertext, profile avatar images and videos, IP address, request logs, inquiry emailsContinuous transmission over the network while using the Service/websiteContent storage/delivery, website operation / until entrustment ends or deletion
Functional Software, Inc. (Sentry)United StatesDevice, OS and app version; error stack informationWhen an error occurs in the appError diagnostics and stability / until entrustment ends or deletion

You may object to international transfers at privacy@incove.app; where a transfer is essential to providing the Service, objecting may limit your use of the Service.

The Republic of Korea has held an EU adequacy decision since 2021, and transfers from the European Economic Area (EEA) to our servers in Korea rely on it. Transfers to Google LLC (United States) rely on safeguards recognized under applicable law, including Google's certification under the EU-U.S. Data Privacy Framework (DPF).

10. Cookies and similar technologies

The incove.app website uses cookies and similar technologies (such as Google Tag Manager) for core functionality and usage analytics. You can refuse or delete cookies in your browser settings, which may limit some website features. For visitors in the European Economic Area, the United Kingdom and Switzerland, we ask for consent through a banner before any analytics cookies are stored, and none are stored until you accept. The mobile app uses no cookies, but it does use an app instance identifier (a similar technology) for usage analytics. This identifier is used only if you turn on Settings > Privacy > Usage stats in the app; turning it off in the same place stops collection immediately and resets the existing identifier. The app serves no ads, collects no advertising identifier (AD_ID), and never uses analytics data for advertising purposes.

11. Security measures

We apply end-to-end encryption of content (industry-standard hybrid public-key and symmetric encryption), transport encryption (TLS/HTTPS), storage of private keys in the device secure storage, access controls, and audit logs. Profile avatars are not end-to-end encrypted, but the storage bucket is kept non-public and a dedicated serverless function issues a time-limited (presigned) access URL only after verifying that the requester belongs to the relevant group. Avatar images chosen from the gallery are re-encoded to strip GPS, orientation and other metadata, and avatar videos are accepted only when recorded in the app.

12. Rights of users and legal representatives

You may request access, correction, deletion, suspension of processing, or portability of your personal information, and may withdraw consent. You can exercise these rights at privacy@incove.app; we verify your identity and act within the statutory period. You can delete your account directly in the app (Settings → Delete account) and download a copy of your data with the in-app Export my data feature. An Echo you wrote yourself is included with its text and its scheduled opening date, even while it is still sealed. An Echo someone else addressed to you is not included until it opens. The minimum age to use the Service is 14. In some European Economic Area countries local law sets it at 15 or 16 instead, and which threshold applies is determined by your device's country setting. We do not collect personal information from children below the applicable minimum age, and we delete any such information without delay if we become aware of it.

Usage-stats collection is optional: it happens only if you turn on Settings > Privacy > Usage stats in the app, and you can turn it off in the same place at any time (collection stops immediately and the existing identifiers are reset). Your on/off choices are recorded and retained as proof of consent (deleted together with your account information when you withdraw from the Service).

13. Privacy officer and contact

Inquiries, complaints, and remedies regarding personal information can be submitted below.

Privacy officer and responsible team

* The incove team operates these channels to protect users' personal information and handle related complaints. Please direct any privacy-related inquiries that arise while using the Service to the emails above.

14. Additional information for EEA residents

If you use the Service from the European Economic Area (EEA), the following applies in addition under the EU General Data Protection Regulation (GDPR).

Legal bases for processing

Your rights: you may request access, rectification, erasure, restriction of processing, objection, and data portability. See section 12 for how to exercise them and the in-app paths (Delete account, Export my data).

Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, where you work, or where the alleged infringement occurred.

International transfers: see section 9 for the transfer bases (Korea's EU adequacy decision; Google LLC's DPF certification).

15. Changes to this policy

This policy may be revised in line with changes in law or the Service; the effective date and changes will be announced upon revision.

Effective date: August 13, 2026

Revision history