Privacy Policy
Last updated: July 2026
1. What we collect
We collect only what's needed to run Legiqo:
- Account data — your email address and authentication details.
- Financial data you add — invoices, vendor and client records, documents, notes, and related details you enter or upload.
- Team & client data — information about team members you invite to your organization and the clients whose invoices you process.
- Usage data — basic activity logs (e.g. sign-ins, feature usage) used for security, audit trails, and improving the product.
2. How we use it
We use your data to run the app: extracting and validating fields from invoices you upload, running compliance checks, generating AI-assisted answers, and powering the team access you set up for your organization. We do not sell your data or share it with advertisers.
3. AI providers
Some features (document extraction, chat, generated summaries and checklists) send relevant data to third-party AI providers to produce a response. Only the data needed for that specific request is sent. Providers do not use this data to train their models, and it is not retained by them beyond processing your request.
- Groq — provides AI inference for features like AI Chat and exception resolution. Your financial data is sent to Groq's API for processing but not stored by them.
- Google Gemini — provides AI document extraction. Uploaded invoices are sent to Gemini's API for field extraction but not stored by Google.
- DeepSeek — provides a secondary verification check on invoice data already extracted by Gemini (e.g. vendor name, GSTIN, amounts). It receives only this already-extracted structured data, not the original uploaded file.
4. Payment providers
To process subscription payments, we work with the following providers, who receive the billing details necessary to complete your transaction:
- Razorpay — processes payments for users in India.
- Stripe — processes payments for users outside India.
5. Where data is stored
Your data is stored with Supabase, our database and file storage provider. Documents are kept in a private storage bucket that only your organization (and, where you've explicitly granted access, your invited team members) can reach. All data in transit is encrypted (HTTPS/TLS).
6. Who can see your data
By default, only members of your organization can see your data.
- Team access — team members you invite can see and act on what your organization grants them access to.
We never access your data ourselves except to provide support you request or as required by law.
7. Data breach notification
If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under Section 8(6) of the DPDP Act, 2023. Our notification will describe the nature of the breach, the data involved, and the steps we're taking in response, and we aim to notify affected users as soon as possible after confirming a breach.
8. Children's data
Legiqo is not directed at, and is not intended for use by, anyone under 18. Creating an account requires confirming you're 18 or older, in line with Section 9 of the DPDP Act, 2023, which requires verifiable parental consent to process a child's personal data. We do not knowingly collect personal data from children. If we learn that someone under 18 has created an account, we will delete the account and associated data. If you believe a child has provided us with personal data, contact our Grievance Officer at privacy@legiqo.co.
9. Your rights (DPDP Act, 2023)
Under India's Digital Personal Data Protection Act, 2023, you have the right to access, correct, and erase your personal data, and to withdraw consent at any time. You can export your data, withdraw AI consent, or permanently delete your account from Settings; deletion removes your personal data from our active systems.
Grievance Officer: for any complaint or grievance regarding the processing of your personal data, contact our Grievance Officer at privacy@legiqo.co. We aim to acknowledge grievances within 7 days and resolve them within 30 days. A named Grievance Officer has not yet been designated for this purpose [TO BE DETERMINED — SEE OPEN ITEMS]; complaints sent to the address above are reviewed by the team.
10. Do Not Sell My Personal Information
We do not sell, share, or trade your personal information to third parties for advertising or marketing purposes.
11. European Users
If you are in the European Economic Area, you have additional rights under the GDPR, including data portability, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact privacy@legiqo.co.
12. California Users
If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to opt out of any sale of personal information. Legiqo does not sell personal information. To exercise these rights, contact privacy@legiqo.co.
13. Data retention
We keep your data for as long as your account is active. There is currently no automated retention schedule that purges data after a fixed period; the specific retention period for each category of data is [TO BE DETERMINED — SEE OPEN ITEMS]. If you delete your account, this triggers an immediate, on-demand deletion of your personal data from our active systems. Some information may briefly persist in backups or security/audit logs before those backups themselves age out.
14. Cookies
Legiqo uses only essential cookies needed to keep you signed in and to secure your session. We do not use tracking or advertising cookies. See our Cookie Policy for details.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page.
16. Contact us
Questions about this policy or your data can be sent to privacy@legiqo.co.