Privacy Policy
What Co-Help collects, where it is processed, who receives it, how long it is kept, and the choices and rights you have.
1. Who we are
Co-Help is a desktop application for Windows and macOS, a backend service that powers its AI features, and the website at co-help.com (together, the “Service”). The Service is operated by Techtonic Innovations LLC, a Virginia limited liability company based in Reston, Virginia, USA (“Techtonic”, “we”, “us” or “our”).
Techtonic Innovations LLC is the controller (the business responsible) for the personal information described in this policy. You can reach us about anything in this policy at Help@TechtonicInnovations.com.
This policy should be read together with our Terms of Service.
2. Summary
- Your interview profile, conversations, transcripts and knowledge base stay on your machine. They are saved in the app’s data folder on your own computer, not on our servers.
- On our servers we keep a small account record: your name, email address, a hashed password (never the password itself), and your plan and billing status, plus the Stripe identifiers needed to link your purchase to your account.
- AI requests pass through our backend, are answered and discarded. To give you an answer, the app sends the relevant text (and any screenshot you take) to our backend, which forwards it to the AI providers listed in section 5 and returns the result. Our backend does not save that content and our logs are configured not to record it. We log only request metadata, such as the time, which AI model provider answered, how long it took and (for audio) the upload size, never the content.
- Payments are handled by Stripe. We never see or store your full card number.
- We do not sell your personal information and we do not “share” it for cross-context behavioral advertising.
- The website uses Google Analytics (with Google Consent Mode) and Cloudflare Web Analytics. You can accept or decline analytics cookies at any time; see section 15.
3. Information we collect
3.1 Account information
When you create an account in the app we collect your name, email address and password. Your password is sent only over an encrypted connection and is stored, on your device and on our servers, only as a one-way scrypt hash, never as the password itself. We also record your account role and status, your plan, how the account was created, and when it was created and last signed in.
3.2 Purchase and billing information
Purchases are made through Stripe (Stripe Payment Links, Stripe Checkout and the Stripe customer portal). Stripe collects your payment card details, billing details and email address directly and processes them under the Stripe Privacy Policy. From Stripe we receive your email address, your Stripe customer ID, your Stripe subscription ID (for subscriptions), the Stripe checkout session ID, the plan you bought and its payment status, and later changes to that status (for example renewals, cancellations, refunds or failed payments). We never receive your full card number.
3.3 Content you process with the app
This is the information that makes Co-Help useful during a call. It is kept on your device, and it passes through our backend only for as long as it takes to answer a request:
- Call audio. When you start listening, the app captures your computer’s system audio (the other side of your call) using your operating system’s screen/audio capture permission, and can fall back to your microphone. Short audio segments are sent over an encrypted connection to our backend, which forwards each one to Groq for speech-to-text and returns the text. Audio is held in memory only for the duration of the request and each upload is capped at 10 MB.
- Transcripts, questions and answers. The transcribed text, questions you type, and the answers you receive.
- Your profile and knowledge base. Information you enter during setup, such as your name, job title, background, resume, projects, stories, notes, the role or job description, company information, documents you upload (PDF, DOCX, text) and web pages you add by link. Files are parsed on your device, and linked web pages are fetched directly from your device.
- Screenshots. When you use screenshot Q&A, the app captures an image of your screen on your device and sends it through our backend to a vision-capable AI provider. Anything visible on your screen at that moment is included, so close anything you do not want processed.
- GitHub content (optional). If you connect GitHub (see 3.8), relevant excerpts of code from your repositories.
To generate an answer, the app includes the relevant parts of this content in the request it sends to our backend. Please do not include information you are not permitted to share (for example, another person’s confidential information or an employer’s trade secrets), and avoid including sensitive personal information such as health, financial account or government ID details in your profile or knowledge base.
3.4 Device and app information
When the app contacts our backend, our hosting provider receives your IP address and standard request details. The app checks for updates by requesting a version file from our website and downloading new versions from GitHub Releases; installers downloaded from this website are served from Google Cloud Storage. Those requests reveal your IP address, and the app version, to the service that answers them. The app does not include any third-party analytics, advertising or crash-reporting software.
3.5 Usage metadata and service logs
Our backend writes operational logs. They include a request identifier, timestamps, the type of event (for example “answer returned” or “token issued”), which AI provider answered and how long it took, which providers failed and an error code, the size in bytes of an audio segment, your plan, your Stripe customer ID and checkout session ID for purchase events, and, for account events (such as account creation, account synchronization and changes made by our administrators), your email address. Our hosting platform (Google Cloud Run) also records standard web request logs, including your IP address, user agent, the requested path, response status, latency and response size. Logs are configured to never record the content of your requests or answers (transcripts, prompts, audio, screenshots), request bodies, passwords, password hashes or your license token.
3.6 Website information
- Google Analytics 4 collects information about your visit, such as pages viewed, referring site, approximate location derived from your IP address, and device and browser information. Whether it may set cookies depends on your choice and your region; see section 15.
- Cloudflare Web Analytics runs on our homepage. It is a cookieless page-performance and visit counter that does not use cookies or local storage to identify you.
- Downloads after checkout. After you pay, the download page sends the Stripe checkout session ID from the page address to our backend, which confirms the payment with Stripe and records a pending purchase (see section 4) so your purchase is recognized when you sign up in the app.
- Third-party content. Our pages load fonts from Google Fonts and scripts from cdnjs (Cloudflare) and jsDelivr. These services receive your IP address and browser information when your browser requests those files.
3.7 Support emails and demo requests
If you email us, we receive your email address and whatever you include in your message. If you request a demo on our homepage, the name, email address, company, message and preferred date and time you enter are delivered to our inbox by EmailJS (EmailJS Privacy Policy). If EmailJS is unavailable, the form instead opens a pre-filled email in your own mail program, and nothing is sent until you send that email yourself.
3.8 GitHub connection (optional)
You can connect GitHub in the app’s setup screen, either by signing in with GitHub or by pasting a personal access token. The app uses that authorization, directly from your device, to read your GitHub profile, repository information and file contents from GitHub’s API, and includes relevant code excerpts in AI requests as described in 3.3. Your GitHub token is stored on your device, encrypted (using your operating system’s credential protection where it is available). It is not sent to our backend. You can remove it with Disconnect in the GitHub Connection section of setup, and you can revoke Co-Help’s access at any time in your GitHub account settings. GitHub processes your information under the GitHub General Privacy Statement.
3.9 Internal notifications
When a new account is created, our systems may send an internal notification containing the new account’s name and email address to a messaging tool used only by our team, so we can welcome and support new users.
3.10 Emails we send
We do not send marketing emails. Stripe sends payment receipts and billing emails on our behalf. We email you ourselves only to answer your messages or about your account, purchases, security or changes to our terms or this policy.
4. What stays on your device and what reaches our servers
| Information | Where it is kept | Details |
|---|---|---|
| Interview profile, knowledge base, session context, conversation history, transcripts, session reports, settings | Your device only | Saved in the app’s data folder on your computer. It is protected by your computer’s account security and any disk encryption you use; Co-Help does not separately encrypt this folder. Deleting the app’s data folder removes it. We cannot access or recover it. |
| Local copy of your sign-in | Your device only | Your name, email, a scrypt password hash and your local plan status, so you can sign in on that device. |
| Co-Help license token and GitHub token | Your device only | Encrypted with your operating system’s credential protection (DPAPI on Windows, Keychain on macOS). If that protection is unavailable, the app does not save your license token at all, and it encrypts your GitHub token with a key stored on the device instead. |
| Account record | Our servers (Google Cloud Firestore, United States) | Email, name, scrypt password hash, role, status, plan, how the account was created, creation, update and last sign-in times, and (if we grant complimentary access) the granted plan and its expiry. Stored under a keyed hash of your email address. |
| License token record | Our servers (Google Cloud Firestore, United States) | A keyed hash of your license token (never the token itself) and a short prefix of that hash for support look-ups, your email and display name, Stripe customer ID, Stripe subscription ID (if any), plan, status, and created, last-used, expiry and revocation times. |
| Pending purchase record | Our servers (Google Cloud Firestore, United States) | Created when you return to our download page after paying: your email, the Stripe checkout session ID, Stripe customer ID, plan and payment time. It links a website purchase to the account you create in the app, is deleted when you claim it, and stops working after 30 days. |
| AI request content (audio, transcript text, profile excerpts, screenshots, code excerpts) | Passes through our backend in memory only | Forwarded to AI providers and discarded after the answer is returned. Not saved to our database and not written to our logs. |
| Service logs | Our servers (Google Cloud Logging) | The metadata described in 3.5, kept for 30 days. |
5. AI providers (sub-processors)
Co-Help does not run its own AI models. Our backend sends each answer request to several AI providers at the same time and returns the first good answer. By default a request goes to the flagship pool (OpenAI, Anthropic and Google). If that whole pool is unavailable, the app retries with a broader pool (OpenAI, Anthropic, Google, DeepSeek and Mistral AI) and then a fast pool (Groq, OpenAI, Google and Anthropic). Screenshot requests go only to providers that accept images (OpenAI, Anthropic and Google). All speech-to-text goes to Groq.
As of the date of this policy, these are the only AI providers that receive request content:
| Provider | Company based in | What it receives | Its policies |
|---|---|---|---|
| OpenAI | United States | Text answer requests (all pools) and screenshot requests | Privacy policy |
| Anthropic | United States | Text answer requests (all pools) and screenshot requests | Privacy policy |
| Google (Gemini API) | United States | Text answer requests (all pools) and screenshot requests | Gemini API terms, privacy policy |
| Groq | United States | All call audio for speech-to-text; text answer requests in the fast pool | Privacy policy |
| Mistral AI | France (EU) | Text answer requests in the broader fallback pool | Terms and privacy policy |
| DeepSeek | People’s Republic of China | Text answer requests in the broader fallback pool (never audio or screenshots) | Privacy policy |
DeepSeek processes data in China. When the flagship pool is unavailable, text answer requests can be sent to DeepSeek, which processes and stores data in the People’s Republic of China, where the law may allow government authorities to access it. Screenshots and audio are never sent to DeepSeek.
We use these providers’ developer APIs, not their consumer chat apps. Each provider processes request content under its own API terms, subject to each provider’s API data policies, which may allow it to keep content for a limited period (for example, for abuse and misuse monitoring). Google applies different data-use terms to paid and unpaid Gemini API services; please review the linked policies. We will update this section before any additional AI provider begins receiving request content.
6. How we use information and our legal bases
We use personal information only for the purposes below. If you are in the European Economic Area (EEA), the United Kingdom or Switzerland, the right-hand column shows the legal basis we rely on under Article 6 of the GDPR (and the UK GDPR and Swiss law).
| Purpose | Information used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the Service: transcription, AI answers, screenshot Q&A, GitHub grounding | Content you process with the app; device information | Performance of our contract with you (6(1)(b)) |
| Create and run your account; sign-in across devices; password changes | Account information | Performance of contract (6(1)(b)) |
| Take payment, verify purchases, activate and renew plans, handle cancellations, refunds and disputes | Purchase and billing information; account information | Performance of contract (6(1)(b)); legal obligation for tax and accounting records (6(1)(c)) |
| Security, fraud and abuse prevention, rate limiting, debugging and keeping the Service reliable | Service logs; device information; license token records | Our legitimate interests in operating a secure and reliable service (6(1)(f)) |
| Respond to support emails and demo requests | Support and demo information | Steps you ask us to take before a contract, or performance of contract (6(1)(b)); our legitimate interest in answering enquiries (6(1)(f)) |
| Internal new-account notifications | Name and email | Our legitimate interest in supporting new users (6(1)(f)) |
| Website analytics with cookies (Google Analytics) | Website information | Your consent (6(1)(a)) in the EEA, UK and Switzerland; our legitimate interest in understanding site use (6(1)(f)) elsewhere, subject to your opt-out |
| Cookieless site measurement (Cloudflare Web Analytics) | Website information | Our legitimate interest in measuring site performance (6(1)(f)) |
| Comply with law, enforce our Terms, and establish, exercise or defend legal claims | Any of the above, as needed | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) |
We do not use your interview content to train AI models, we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, and we do not build advertising profiles. Where we rely on legitimate interests, you can object (see section 12). Where we rely on consent, you can withdraw it at any time without affecting processing that happened before.
8. How long we keep information
| Information | How long |
|---|---|
| Account record | For as long as your account exists. We delete it within 30 days of a verified deletion request. |
| License token records | For as long as your account exists (records of expired or revoked tokens are kept to prevent misuse and reconcile billing). We delete them within 30 days of a verified deletion request. |
| Pending purchase record | Deleted when you claim your purchase in the app. An unclaimed record stops working after 30 days; we keep it as a record of your purchase and delete it within 30 days of a verified deletion request. |
| AI request content | Not stored by us. Discarded once the answer is returned. Providers keep content only as their API data policies allow (see section 5). |
| Service logs | 30 days, then automatically deleted. |
| Support emails and demo requests | As long as needed to handle your request and keep a record of our correspondence. We delete them within 30 days of a verified deletion request unless we must keep them for a legal reason. |
| Payment and transaction records held by Stripe | As Stripe and applicable tax, accounting and anti-fraud laws require. |
| Google Analytics data | Kept by Google according to our Google Analytics property’s data-retention setting; for standard Google Analytics properties the maximum for user-level data is 14 months. |
| Information on your device | Until you delete it or remove the app’s data folder. |
We may keep information longer where the law requires it, or where it is needed to resolve a dispute, prevent fraud or abuse, or enforce our agreements, and only for as long as that need lasts.
9. Security
We use administrative, technical and organizational measures designed to protect personal information, including: encryption in transit (HTTPS/TLS) between the app, the website and our backend; AI provider keys and our signing secrets held in Google Secret Manager and never shipped in the app; passwords stored only as scrypt hashes; license tokens stored only as keyed hashes; database records keyed by keyed hashes of email addresses; encryption at rest provided by Google Cloud; rate limiting and input validation on our backend; and access to production systems limited to authorized personnel. On your device, your license token and GitHub token are encrypted using your operating system’s credential store where it is available.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account or license token has been compromised, tell us at Help@TechtonicInnovations.com so we can revoke it. If a data breach affects your personal information, we will notify you and the relevant authorities as the law requires.
10. International data transfers
We are based in the United States and our backend and database run in the United States. If you use the Service from outside the United States, your information is collected and processed in the United States, whose data-protection laws may differ from those where you live. Our service providers may process information in the United States and other countries; as described in section 5, Mistral AI is based in France and DeepSeek processes data in the People’s Republic of China.
Where personal information of people in the EEA, the UK or Switzerland is transferred to a country that has not been found to provide adequate protection, we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum and Swiss amendments where relevant) as incorporated in our providers’ data processing terms, or, where no such mechanism is available, on the transfer being necessary to perform our contract with you at your request (GDPR Art. 49(1)(b)). You can ask us for more information about these safeguards using the contact details in section 19.
11. Your privacy rights
Depending on where you live, you may have some or all of the rights below. We extend the core rights of access, correction and deletion to all users, wherever they live.
- Access / know: confirm whether we process your personal information and get a copy of it.
- Correction: fix inaccurate information.
- Deletion: ask us to delete your information.
- Portability: receive your information in a portable, machine-readable format.
- Objection and restriction: object to, or ask us to limit, certain processing.
- Withdraw consent: where we rely on consent, withdraw it at any time.
- Opt out: of sale, of sharing for targeted advertising, and of profiling (we do none of these).
How to exercise your rights
Email Help@TechtonicInnovations.com from the email address on your account, with the subject line “Privacy Request” and the right you want to exercise. Information stored only on your device is under your control: you can view it in the app, and delete it by removing the app’s data folder.
- Verification. To protect you, we verify requests by confirming that they come from the email address on the account, and we may ask for information that matches our records (for example details of your purchase). We will not ask for more information than we need.
- Authorized agents. You may use an authorized agent. We will ask the agent for proof of your signed permission, and may ask you to verify your identity with us directly, unless the agent holds a valid power of attorney.
- Timing. We respond within the time the law that applies to you requires (for example, one month under the GDPR and 45 days under US state laws), and we will tell you if we need an extension that the law allows.
- Deletion. When we delete your account, we delete your account record and revoke your license tokens so AI access stops. Deleting your account does not cancel a Stripe subscription by itself; cancel it first (see our Terms) so you are not billed again. We may keep limited information where the law requires or allows it (for example, transaction records needed for tax purposes).
- No discrimination. We will not deny you the Service, charge you a different price or provide a different quality of service because you exercised a privacy right.
12. EEA, UK and Swiss residents
If the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies to you, you have the rights to access, rectification, erasure, restriction of processing, data portability and to object to processing based on our legitimate interests, and the right to withdraw consent at any time. The legal bases we rely on are listed in section 6. Providing account and payment information is necessary to enter into a contract with us; without it we cannot provide the paid Service.
You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the country where you live or work or where you believe an infringement occurred. In the UK this is the Information Commissioner’s Office, and in Switzerland the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first, so please contact us.
13. California residents (CCPA/CPRA)
This section is our notice at collection and privacy policy disclosure under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). In the last 12 months we collected the categories of personal information below. We collect them from you, from your device, and from Stripe, for the business purposes described in section 6, and keep them for the periods in section 8.
| Category | Examples | Disclosed for a business purpose to | Sold or shared? |
|---|---|---|---|
| Identifiers | Name, email address, IP address, Stripe customer ID, license token hash | Google Cloud; Stripe; email and team-messaging providers; Google Analytics and Cloudflare (IP address only) | No |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address; payment details are collected by Stripe | Google Cloud; Stripe | No |
| Commercial information | Plan purchased, payment and subscription status | Google Cloud; Stripe | No |
| Internet or other electronic network activity | Website pages viewed, referrer, service request metadata and logs | Google Cloud; Google Analytics; Cloudflare | No |
| Approximate geolocation | Region derived from IP address (never precise location) | Google Analytics; Cloudflare | No |
| Audio, electronic, visual or similar information | Call audio and screenshots, processed transiently to answer your request | Google Cloud; AI providers in section 5 | No |
| Professional or employment-related information | Resume, job title, background, projects and job descriptions you choose to include in AI requests | Google Cloud; AI providers in section 5 | No |
| Sensitive personal information | Account log-in (email address with password), stored only as a scrypt hash | Google Cloud | No |
We do not collect inferences to profile you, and we use sensitive personal information only to provide the Service and keep it secure, as the CCPA permits, so the right to limit its use does not apply. We do not knowingly sell or share the personal information of consumers under 16.
Your California rights. You have the right to know what personal information we collect, use and disclose (including specific pieces); to delete it; to correct inaccurate information; to opt out of the sale or sharing of personal information (we do neither); to limit the use of sensitive personal information (which we do not use for any purpose that triggers this right); and not to be discriminated against for exercising these rights. To exercise them, follow section 11. We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by another 45 days with notice. We honor Global Privacy Control signals as described in section 16.
Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes.
14. Virginia and other US states
Residents of Virginia (Virginia Consumer Data Protection Act) and of other US states with comprehensive privacy laws, such as Colorado, Connecticut, Utah, Texas and Oregon, may have the rights to confirm whether we process their personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions with legal or similarly significant effects. We do not sell personal data, use it for targeted advertising, or profile you in that way. We process sensitive data (such as account log-in credentials) only as needed to provide the Service. To exercise your rights, follow section 11. We respond within 45 days, extendable once by another 45 days where reasonably necessary, with notice.
Appeals. If we decline to act on your request, you may appeal by emailing Help@TechtonicInnovations.com with the subject line “Privacy Appeal” within a reasonable time after our decision. We will respond in writing within 60 days, explaining what we did and why. If your appeal is denied, you may contact your state Attorney General; Virginia residents can contact the Office of the Attorney General of Virginia at www.oag.state.va.us.
16. Do Not Track and Global Privacy Control
We honor Global Privacy Control (GPC) and Do Not Track (DNT) browser signals on co-help.com. If your browser sends either signal, we keep Google Analytics cookies off for that browser, we do not show the cookie banner, and we treat the signal as a valid request to opt out of the sale or sharing of your personal information (which we do not do in any case).
17. Children
The Service is intended only for adults. You must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us personal information, contact us and we will delete it.
18. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the “Last updated” date above. If we make material changes, we will give you notice in advance, for example in the app, by email to the address on your account, or on this website, and where the law requires your consent to a change, we will ask for it.
19. Contact us
Techtonic Innovations LLC
Reston, Virginia, USA
Email: Help@TechtonicInnovations.com
For privacy requests, please use the subject line “Privacy Request” (or “Privacy Appeal” for appeals).