Legal

Privacy Policy

Last updated 22 August 2026

Idiqo holds your notes so it can hand them back to you on another device. That is the whole reason we store anything. There is no advertising business here, no third-party analytics, and nothing about you is for sale.

1. What we collect

  • Your account. Email address, and the name and “where did you hear about us” answer you give during onboarding. If you sign in with Google, we receive the basic profile Google returns — email, name and picture — and nothing else from your Google account.
  • Your workspace. Pages, folders, drawings, tasks, tags, links between pages, and files you upload. We store these to sync them; we do not read them.
  • Your preferences. Theme, sync interval, graph settings, chosen Copilot model.
  • Session records. When you sign in we store a session row with your IP address and browser user agent, so “sign out every device” can mean something and so we can spot abuse.

We do not use advertising or third-party analytics, and we set no tracking cookies. The only cookie Idiqo sets is the session cookie that keeps you signed in — it is HttpOnly, so page scripts cannot read it.

2. Where it lives

Your workspace is written to your own browser first, in IndexedDB, which is why it opens instantly and works offline. A copy is synced to our servers so a second device can pick it up. The free notepad and whiteboard are browser-only: nothing from them is sent to us, and clearing your browser data clears them.

3. Who else touches it

We use a small number of providers, each for one job:

  • Google — only if you choose Google sign-in, and only for that sign-in.
  • OpenAI or Anthropic — only when you use the Copilot, and only the text that request needs. Nothing is sent to a model provider unless you ask the Copilot something.
  • Object storage — holds images and files you upload. Upload URLs are unguessable but they are not access-controlled, so anyone given a direct file link can open it. Do not upload anything you would not be comfortable sharing by link.

We do not sell your data, and we do not share it with anyone else except where the law requires it.

4. Published pages

A page you publish gets a public link that anyone holding it can read, without signing in and without appearing in your account. Unpublishing it takes the link out of service. Nothing is published unless you publish it.

5. How long we keep it

  • Pages you delete sit in the trash for 30 days and are then removed permanently.
  • Sessions expire after 30 days of inactivity, or immediately when you sign out.
  • Deleting your account removes your pages, drawings, tasks, uploaded files, search index and settings. Copies in a backup are removed as that backup rotates out.

6. What you can do

  • See it. Everything we hold about your workspace is on screen in the app.
  • Correct it. Your display name and preferences are in Settings.
  • Take it. Settings has an export, and an import to put it back.
  • Delete it. Settings → Account → Delete account, which takes the workspace with it.

Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a data protection authority. Write to hello@idiqo.app and we will help.

7. Children

Idiqo is not intended for children under 13. If we learn that an account belongs to one, we delete it. If you believe a child has created an account, tell us at hello@idiqo.app.

8. Changes and contact

If this policy changes, the date at the top changes with it, and we will tell you before a material change takes effect. Questions, requests or complaints: hello@idiqo.app.

See also the Terms of Service.