Welcome to Docko! This Privacy Policy explains what data Docko collects, who processes it, and the choices you have. Last updated: 5 October 2026.

1. Data We Collect

Docko works without an account. On first launch it creates an anonymous account with a random ID. This is what we handle:

  • Account: The anonymous account ID, your language and time zone, and your subscription status. We receive an email address only if you choose to link Apple sign-in (or Google sign-in, where offered) to use cloud backup; Apple may give us a private relay address instead of your real one.
  • Documents on your iPhone: Pages you scan are stored on your iPhone, and text recognition (OCR) runs on your device. Your documents are not uploaded unless you turn on cloud backup.
  • Search and automatic features: When you save a scan, the recognized text of its pages is sent to our servers and on to Amazon Web Services (Bedrock, EU) to create numeric search vectors and to suggest a folder and document type from the first page. If you turn on automatic summaries, the text is also sent to create the summary. Searching your library sends your search words the same way. We keep only the vectors, the document and page numbers and a short section label (up to 200 characters) taken from the page; the page text itself is not stored by us. Deleting a document removes its search vectors from our servers (if you are offline at that moment, the request is kept and retried later), and deleting your account removes all of them.
  • AI questions, summaries and translations: When you use Docko AI, your question and the relevant page text are sent to Amazon Bedrock (Anthropic Claude models, EU) and the answer is returned to your iPhone, where it is saved. We do not store this text. Amazon Bedrock does not use it to train models. We keep usage counters for your daily limits and technical logs (model, token counts, response time, cost) that contain no document text.
  • Cloud backup (Docko Pro, optional, off by default): If you turn it on, we upload your page images, document titles, folder names and page details, plus the name of your device. If you include AI data, we also upload the recognized text, extracted details and summaries. Original photos and saved signatures are uploaded only if you choose to include them. Backups are stored in Supabase (EU, Ireland), sent over TLS, and encrypted at rest by Supabase. Access is restricted to your account by row-level security. Backups are not end-to-end encrypted: Supabase's infrastructure and our administrators with database access could technically read them. We do not look at your documents.
  • Analytics (only with your consent): If you agree, Mixpanel (EU) receives product events such as screens opened, scans saved, exports, AI feature use, ad and purchase steps, and backup on/off, tagged with a random install identifier that is not your account ID. Microsoft Clarity records session replays and heatmaps; recording is paused on the scanner, document, text, chat, summary, signing, editor, search, export and tools screens. We never send document content, titles or file names to either. Both providers also receive technical data such as device model, OS version, app version and IP address, as any internet service does.
  • Crash reports: Crashes and errors are reported to Sentry (EU) from the app store version. This does not depend on the analytics setting. Reports contain technical details (device model, OS and app version, error trace) and no account ID, screenshots or session replay; file paths and document-related fields are removed before sending. Performance traces are sent only if you agreed to analytics.
  • Advertising: Docko shows Google AdMob rewarded ads only when you tap to watch one. AdMob receives your device's advertising identifier only if you allowed tracking through Apple's prompt and, where required, Google's consent form; otherwise only non-personalized ads are requested. To grant the reward, your account ID, the reward type and a random document identifier are passed to AdMob and returned to our server for verification.
  • Purchases: Subscriptions are processed by Apple and managed through Adapty. Your account ID is shared with Adapty so the subscription is tied to your account; Adapty also receives technical device data through its SDK. We store your subscription status and Adapty event records (event ID, type, outcome).
  • Reminders: Reminders are local notifications scheduled on your iPhone. We do not use push notifications or send reminder content to any server.

2. How We Use Your Data

We use your data to:

  • Provide Docko's scanning, search, AI and automatic filing features.
  • Back up and sync your documents, if you turn on cloud backup.
  • Apply daily limits and process your Docko Pro subscription.
  • Show rewarded ads when you tap to watch one, and grant the reward.
  • Understand how the app is used and fix crashes (analytics only with your consent).
  • Respond to support and privacy requests.

We do not sell your data and do not use your documents for advertising. Our legal bases are performing the service you asked for, your consent (analytics, tracking and personalized ads) and our legitimate interest in keeping the app stable and secure (crash reports).

3. Who Processes Your Data

We rely on the following service providers, who process data on our behalf:

  • Supabase (EU, Ireland): Database, sign-in, and file storage for the anonymous account, usage counters, search vectors and optional backups.
  • Amazon Web Services, Bedrock (EU): AI answers, summaries, classification and search vectors (Anthropic Claude and Cohere models). Text is processed to produce the result and is not stored by us.
  • Apple and Google sign-in: Only if you link an account for backup.
  • Adapty and the Apple App Store: Subscription purchases and status.
  • Mixpanel (EU): Product analytics, with your consent.
  • Microsoft Clarity: Screen-usage analytics, with your consent.
  • Sentry (EU): Crash and error reporting.
  • Google AdMob: Rewarded ad serving and reward verification.

Some of these providers may process technical data outside the EU under their own safeguards.

4. Tracking and Your Choices

During setup, Docko asks whether to share anonymous usage statistics and may show Apple's App Tracking Transparency prompt. If you choose "Ask App Not to Track", no advertising identifier is used and ads stay non-personalized. You can change this in iOS Settings → Privacy & Security → Tracking.

In the app, Settings → Privacy → Share usage analytics turns Mixpanel and Microsoft Clarity on or off at any time; turning it off also stops performance traces to Sentry. Crash reports are not covered by this switch. Rewarded ads show only when you tap the button, with or without analytics. Cloud backup is optional and can be turned off in Backup & sync, where you can also delete your cloud backup.

5. Data Retention and Deletion

We keep your account data, search vectors and backups until you delete them or your account. Server-side technical usage logs (model, token counts, cost) are kept without any link to you after account deletion.

Account Deletion: You can delete your account in the app (Settings › Backup & sync › Delete account) or by emailing privacy@inovy.dev. Deletion permanently removes your Docko data from our servers: backups and backup files, search vectors, usage counters, reward and subscription records, and your sign-in account (unless another Inovy app still uses the same sign-in, in which case only the Docko data is removed). It also erases your documents and settings stored in Docko on your iPhone, so export anything you want to keep first. Deleting your account does not cancel an App Store subscription.

Data already sent to Mixpanel, Microsoft Clarity, Sentry, Adapty and Google AdMob, and purchase records held by Apple, is kept by those providers under their own policies and retention periods and is not deleted by Docko's account deletion.

6. Your Rights

Depending on where you live, including under the GDPR, you can ask us for access to your data, correction, deletion, restriction, a portable copy, or object to processing, and you can withdraw consent at any time (for analytics, with the in-app switch) without affecting earlier processing. You also have the right to complain to your local data protection authority. Because the anonymous account has no name or email, we may ask you to prove it is yours from within the app.

7. Contact Us

If you have any questions or requests about your privacy, please contact us at: privacy@inovy.dev