incove Privacy Policy
incove ("the Service") is an application for gathering and looking back on short everyday moments inside closed groups of family and people close to you. The operator treats your personal information seriously and complies with the Personal Information Protection Act and other applicable laws. This policy explains what information the Service processes and how, and in particular how end-to-end encryption (E2EE) protects your content.
1. End-to-end encryption (E2EE) — core principle
The contents of videos and the contents of sealed messages (Echoes) captured or uploaded in the Service are encrypted on your device, and the decryption key is stored wrapped to the public keys of the people meant to receive that content — so it can only be decrypted on their devices.
No third party, including the operator, can decrypt or view this content. It is transmitted to and stored on servers (database and storage) only in encrypted form, and the server does not hold the decryption key. This content is therefore not information that the operator can "collect" and read or analyze.
Profile (avatar) images and videos are not covered by the end-to-end encryption described above. Because an avatar has to be displayed to the other members of your group, it is stored unencrypted and can be viewed by the operator. They are protected by access control instead: the storage bucket is not public, and once the requester is confirmed to be a member of the same circle we issue only a signed URL for that person's current avatar, expiring after ten minutes. Avatar images chosen from the gallery are re-encoded before upload so that EXIF is removed entirely (see section 11).
The following, which the Service needs in order to run, is also unencrypted: account information (display name, email and so on), circle names and the member list with their labels, emoji reactions, timestamps such as when something was recorded or shared, mood values, and the sender's display name and event type carried in a push notification (a notification never carries the content itself). Reports, blocks and audit records are likewise unencrypted.
The unlock time of a sealed message (Echo) is chosen by the user (from 1 day up to 5 years, 6 months by default). For an Echo addressed to someone else, the server enforces the lock by refusing to deliver the ciphertext before that time. An Echo you leave for yourself is your own record, so the server has no reason to hide it from you — it simply is not shown in the app until the day you chose. Either way the server may know "when it is delivered," never "what it says."
2. Personal information we process
We process the following to provide the Service. The E2EE content in section 1 cannot be read by the operator and is listed separately below.
| Category | Items | Purpose |
|---|---|---|
| Account / auth | Email or social login identifier, display name, records of your consent choices and withdrawals (with timestamps) | Member identification, authentication, account management, proof of consent |
| Profile | Profile/avatar image or video, circle membership and role info | In-group display and features. Avatars are not E2EE and can be viewed by the operator; an access URL is issued only to requests verified as coming from a group member (see section 11) |
| Device / push | Device identifier, push token (FCM) | Notifications, security |
| Usage metadata | Upload frequency/time, group creation/invite patterns, non-identifying mood value | Operation, abuse detection, music matching (only the on-device mood result is sent) |
| Reports / safety | Report reason and details, submitted evidence (with reporter consent) | Handling illegal/harmful content (section 6) |
| App usage stats | App launches, screen views, menu taps and capture completions (app interactions), app instance identifier, device/OS/app version, approximate region derived from the IP address (down to city level) | Improving the Service by understanding usage flow. Screen-view and menu statistics are processed by Google LLC (Google Analytics for Firebase) as our processor; app-launch and capture-completion counts are stored on our own servers and not provided to third parties. Collected only if you turn on Settings > Privacy > Usage stats in the app (off by default); you can turn it off in the same place at any time (collection stops immediately and both identifiers are reset). Not linked to account identifiers |
| Website use | IP address, browser/device info, visit logs, cookies | Operating and securing the incove.app website, usage analytics (section 10) |
| E2EE content | Video and sealed-message contents (profile avatars not included) | Not readable by the operator. Relayed/stored as ciphertext only |
EXIF and other metadata (including capture location) are stripped from uploaded videos. Avatar images chosen from your gallery are also re-encoded before upload to strip GPS, orientation and other metadata, and avatar videos can only be recorded in the app. If you turn on app usage stats, Google Analytics derives an approximate region — down to city level — from your IP address and uses it for analysis. incove's servers do not store this value, and precise location is never collected. The Service has no advertising and does not collect advertising identifiers.
3. Purposes of use
Collected information is used only for member management and identity verification, providing group-based sharing and recap features, sending notifications, ensuring service stability and preventing fraudulent/illegal use, statistical analysis of usage to improve the Service, and fulfilling legal obligations. Usage analysis is performed in a form that does not identify individuals, and its results are not used for advertising. It is not used for other purposes; if purposes change, separate consent is obtained.
4. Retention and use period
As a rule, personal information is destroyed without delay, by irreversible means, upon account withdrawal. Exceptions:
- Where laws require retention, data is kept for that period and then destroyed.
- Material related to reports of child sexual abuse material (CSAE) or non-consensual intimate imagery may be kept separately to the extent necessary to cooperate with authorities and meet legal duties, then destroyed.
- Access and security logs are kept for up to one year for security and service stability, then destroyed.
- App usage stats (both the portion processed by Google Analytics for Firebase and our self-collected portion) are retained for up to 90 days from collection and then deleted; only non-identifiable aggregate statistics remain thereafter. Because these statistics are not linked to account identifiers, they are not subject to individual deletion on account withdrawal and are removed automatically once the retention period ends.
5. Account and data deletion
You may request deletion of your account and related data at any time.
- In-app: delete your account directly under Settings → Delete account.
- By email: if you cannot use the app, request deletion at hello@incove.app.
For the exact in-app location and details of what is deleted or briefly retained, see How to delete your account.
On request, the operator destroys the personal information linked to the account and the content you uploaded (including ciphertext), except material subject to the legal retention/preservation in section 4. If you own a group, group handling follows the in-app guidance.
Some things remain after deletion. For 90 days after withdrawal the same email address cannot be used to sign up again; to enforce this we keep only a one-way hash of the address, never the address itself. Your withdrawal reason and the record of messages you received before withdrawing are kept, detached from the account, for service improvement and dispute handling. Reports you filed and security-event records are not deleted — the user identifier is stripped from them and the records are retained for audit purposes.
6. Handling illegal/harmful content
Although the Service is closed, safety measures are taken only when a group member files a report. Content submitted with the reporter's consent (material the reporter can legitimately decrypt) is used only to process the report and meet legal obligations, and is stored in a separate secure area for that purpose. See the Terms of Service and the in-app community guidelines and child-safety policy for details.
7. Provision to third parties
The operator does not sell your personal information or provide it for marketing. It may be provided only in the following cases.
- When you have given explicit prior consent
- When required by law or lawfully requested by investigative authorities under due process
8. Entrustment of processing
We entrust the following processing tasks to run the Service. Entrustment contracts include the safeguards required by law, and processors act only within the entrusted scope under our supervision.
| Processor | Entrusted task | Information processed | Storage / processing location |
|---|---|---|---|
| Supabase, Inc. | Authentication and database operation | Email/social login identifier, display name, circle info, consent records | Seoul, Republic of Korea (AWS ap-northeast-2) |
| Cloudflare, Inc. | Content storage (R2) | E2EE-encrypted videos and messages (unreadable to the operator); profile avatar images and videos (not encrypted — viewable by the operator; non-public bucket, time-limited URL issued only after group-membership verification) | Globally distributed (automatic region) — not pinned to one country |
| Google LLC | Push notifications (Firebase Cloud Messaging), app usage stats (Google Analytics for Firebase), social sign-in | Device identifier, push token, app instance identifier, app interaction records | United States and global |
| Functional Software, Inc. (Sentry) | App error and performance diagnostics | Device, OS and app version at the time of an error; error stack information | United States |
| Cloudflare, Inc. | Website (incove.app) hosting and delivery, inquiry email routing | IP address, request logs, inquiry emails | Global (edge network) |
| Google LLC | Website analytics (Google Tag Manager / Google Analytics), inquiry email reception (Gmail) | Cookies, visit logs, approximate region, inquiry emails | United States and global |
9. International transfers
In providing the Service, some personal information is transferred and stored abroad as follows. E2EE content is transferred only as ciphertext, unreadable to anyone including the recipient. Video contents are ciphertext in whichever region they are stored, so where they sit does not change how well they are protected. Profile avatars are not E2EE, so they are transferred and stored unencrypted, protected by a non-public bucket and access controls.
| Recipient | Country | Items | When / how | Purpose and retention |
|---|---|---|---|---|
| Google LLC | United States and others | Device identifier, push token, app instance identifier, app interaction records, cookies/visit logs, inquiry emails | Continuous transmission over the network while using the Service/website | Notifications, app and website usage analytics, support / until entrustment ends or deletion (app analytics per the retention period in section 4) |
| Cloudflare, Inc. | United States and others (global edge) | E2EE ciphertext, profile avatar images and videos, IP address, request logs, inquiry emails | Continuous transmission over the network while using the Service/website | Content storage/delivery, website operation / until entrustment ends or deletion |
| Functional Software, Inc. (Sentry) | United States | Device, OS and app version; error stack information | When an error occurs in the app | Error diagnostics and stability / until entrustment ends or deletion |
You may object to international transfers at privacy@incove.app; where a transfer is essential to providing the Service, objecting may limit your use of the Service.
The Republic of Korea has held an EU adequacy decision since 2021, and transfers from the European Economic Area (EEA) to our servers in Korea rely on it. Transfers to Google LLC (United States) rely on safeguards recognized under applicable law, including Google's certification under the EU-U.S. Data Privacy Framework (DPF).
10. Cookies and similar technologies
The incove.app website uses cookies and similar technologies (such as Google Tag Manager) for core functionality and usage analytics. You can refuse or delete cookies in your browser settings, which may limit some website features. For visitors in the European Economic Area, the United Kingdom and Switzerland, we ask for consent through a banner before any analytics cookies are stored, and none are stored until you accept. The mobile app uses no cookies, but it does use an app instance identifier (a similar technology) for usage analytics. This identifier is used only if you turn on Settings > Privacy > Usage stats in the app; turning it off in the same place stops collection immediately and resets the existing identifier. The app serves no ads, collects no advertising identifier (AD_ID), and never uses analytics data for advertising purposes.
11. Security measures
We apply end-to-end encryption of content (industry-standard hybrid public-key and symmetric encryption), transport encryption (TLS/HTTPS), storage of private keys in the device secure storage, access controls, and audit logs. Profile avatars are not end-to-end encrypted, but the storage bucket is kept non-public and a dedicated serverless function issues a time-limited (presigned) access URL only after verifying that the requester belongs to the relevant group. Avatar images chosen from the gallery are re-encoded to strip GPS, orientation and other metadata, and avatar videos are accepted only when recorded in the app.
12. Rights of users and legal representatives
You may request access, correction, deletion, suspension of processing, or portability of your personal information, and may withdraw consent. You can exercise these rights at privacy@incove.app; we verify your identity and act within the statutory period. You can delete your account directly in the app (Settings → Delete account) and download a copy of your data with the in-app Export my data feature. An Echo you wrote yourself is included with its text and its scheduled opening date, even while it is still sealed. An Echo someone else addressed to you is not included until it opens. The minimum age to use the Service is 14. In some European Economic Area countries local law sets it at 15 or 16 instead, and which threshold applies is determined by your device's country setting. We do not collect personal information from children below the applicable minimum age, and we delete any such information without delay if we become aware of it.
Usage-stats collection is optional: it happens only if you turn on Settings > Privacy > Usage stats in the app, and you can turn it off in the same place at any time (collection stops immediately and the existing identifiers are reset). Your on/off choices are recorded and retained as proof of consent (deleted together with your account information when you withdraw from the Service).
13. Privacy officer and contact
Inquiries, complaints, and remedies regarding personal information can be submitted below.
Privacy officer and responsible team
- Officer / contact: incove team
- General inquiries: hello@incove.app
- Privacy inquiries: privacy@incove.app
- Safety & rights-violation reports: safety@incove.app
14. Additional information for EEA residents
If you use the Service from the European Economic Area (EEA), the following applies in addition under the EU General Data Protection Regulation (GDPR).
Legal bases for processing
- Performance of a contract: processing essential to providing the Service — account creation and sign-in, and the sharing, storage and delivery of group-based content
- Consent: app usage stats and website analytics cookies — all optional, and withdrawable at any time
- Legitimate interests: keeping the Service safe, preventing fraudulent use, and responding to illegal or harmful content
- Legal obligation: retention and reporting duties under applicable law
Your rights: you may request access, rectification, erasure, restriction of processing, objection, and data portability. See section 12 for how to exercise them and the in-app paths (Delete account, Export my data).
Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, where you work, or where the alleged infringement occurred.
International transfers: see section 9 for the transfer bases (Korea's EU adequacy decision; Google LLC's DPF certification).
15. Changes to this policy
This policy may be revised in line with changes in law or the Service; the effective date and changes will be announced upon revision.
Effective date: August 13, 2026
Revision history
- August 13, 2026 — Retired the feature that recorded a location (city name) when capturing in the app, and removed that collection item and its related notices from sections 1, 2, 4, 12 and 14 and from the account-deletion notice. The approximate region Google Analytics derives from your IP address when you opt in to app usage stats remains, and its scope is now stated precisely as "down to city level" (sections 2 and 8).
- August 10, 2026 — Stated in sections 1, 2, 8, 9 and 11 that profile (avatar) images and videos are not covered by end-to-end encryption and can be viewed by the operator, together with the safeguards that apply to them (non-public storage, a time-limited access URL issued only after group-membership verification, and metadata stripping for avatar images).
- August 3, 2026 — Updated sections 2, 3, 4, 8, 9, 10 and 12 to reflect the introduction of opt-in app usage stats (Google Analytics for Firebase plus self-collected counts). Also, for the global launch: aligned the minimum-age rules (section 12), added the website cookie-consent procedure (section 10), and added the EEA notice (section 14).
- July 19, 2026 — Initial version.