Privacy notice
Last updated September 25, 2026. Questions or requests: okankaradmn@gmail.com.
What we use
When you create an account, we store your email address, a password hash if you use a password, verification status, and session records. If you use Google sign-in, we verify the Google identity token and store your Google account identifier with your Copycat Checks account. If you add a passkey, we store its public key and credential identifier; your private key stays with your passkey provider. We store your Stripe customer and subscription identifiers and the original app links you first use for paid evidence exports so we can enforce your plan limit.
Reviews, monitoring, and images
Saved leads and complaint drafts stay in your browser’s local storage. When you compare screenshots or export an evidence packet, the server processes the submitted images and draft to produce a response. Those requests are not saved as case records by Copycat Checks. For apps you choose to monitor, we store the App Store link and listing details, search terms, screenshot URLs, derived image features, similarity scores, match history, scan times, and alert status. We also retain App Store catalog search responses so the monitor can reuse them across checks. App Store searches and listing lookups are sent to Apple; App Store screenshots may be fetched from Apple’s image hosts. We do not store the screenshot image files in the monitoring database.
Payments, email, and analytics
Stripe handles checkout, subscription changes, and payment details. We use Cloudflare to host the service and send account and possible-match emails, and Neon to store account, plan, and monitoring data. We use Google Analytics to understand website visits. These services may process technical information such as IP address, browser details, and request data under their own policies.
Choices and retention
You can sign out, clear locally saved drafts in your browser, and manage or cancel your subscription through Stripe. Account, passkey, protected-app, and monitoring records remain while your account exists unless you request deletion. Operational logs and service-provider records may follow the providers’ retention schedules. Email okankaradmn@gmail.com to request access, correction, or deletion of account data.