Last updated 8 October 2026

Privacy policy

What we collect, why, who we share it with, how long we keep it, and your rights.

Who we are

Escanor is provided by Escanor Labs, ATF-39, Gaur World Smart Street, Sector-16B, Greater Noida West, Uttar Pradesh 201308, India ("Escanor", "we"). We decide why and how your personal data is processed for the service, and we are responsible for it under the Information Technology Act, 2000, the rules made under it, and the Digital Personal Data Protection Act, 2023.

Where your organisation adds you to its workspace, it decides what its workspace is used for; we process that workspace content on its behalf. Questions about it can go to your workspace administrator or to us.

What we collect and why

  • Account: name, email, profile picture, sign-in identifiers from Google or GitHub, and a hash of your password if you use email sign-in. Used to create your account, sign you in and keep it secure.
  • Sessions and security: sign-in times, IP address, browser or device type, and two-step verification settings. Used to keep your account secure, detect misuse and investigate incidents.
  • Connected services: the access tokens and keys you give us for services such as GitHub, AWS, Google Cloud, Kubernetes or Cloudflare (always stored encrypted), and the data we read from them to show dashboards and carry out the actions you ask for: repositories, deployments, resources, logs and metrics. We only read and act within the permissions you grant.
  • Your machines: if you pair a computer, the commands you run through Escanor, their output and basic system details. Used to run those commands and show you their results.
  • AI assistant: your messages, the files or code you choose to include, and the assistant's replies and actions. Used to answer you and carry out the tasks you give it.
  • Billing: your plan, billing cycle, payment status and Razorpay payment references. Card and UPI details are entered on Razorpay's page and never reach us.
  • Support, complaints and calls: what you write to us or enter when booking a call, and our replies. Used to help you and keep a record of the request.
  • Diagnostics: errors and performance timings from the web app, sent to your own workspace's monitoring so problems can be found and fixed.

Sensitive information

Passwords and the access keys you connect are sensitive personal data under the SPDI Rules, 2011. We collect them only with your consent, given when you connect a service or set a password, only for the purpose you connect them for, and store them encrypted. You can disconnect a service at any time, which deletes its stored keys.

The Escanor Android app

Each permission is requested only when you first use the feature that needs it. Refusing one switches off only that feature.

  • Microphone: what you say to the assistant is turned into text by Android's speech recognition and the text is sent to Escanor. "Hey Escanor" listens on the phone only after you switch it on, shows a notification while listening, and sends nothing until it hears those words.
  • Contacts and calls: contacts are read on the phone only when you ask to call someone by name; they are not uploaded. The Phone permission is used only to place the call you asked for.
  • Camera: used only to scan the pairing code shown by Escanor Desktop.
  • Notifications: a device token is stored to deliver the alerts you choose, and removed when you sign out.
  • Phone control (Accessibility): available only in the "with phone control" build, and only after you agree in the app and switch it on yourself in Android settings. It reads what is on screen at that moment to find a button or answer you; that text stays on the phone and is not stored or sent to us.

What we never do

  • We do not sell or rent your personal data.
  • We do not use your code, prompts or workspace content to train AI models.
  • We do not use advertising or cross-site tracking cookies.
  • We do not send you marketing email unless you opt in, and you can opt out at any time.

Who we share it with

We share personal data only with the service providers that run Escanor for us, under contracts that require them to protect it and use it only for us, and where the law requires it:

  • Hosting and storage: Amazon Web Services (application servers and database, Mumbai, India), Vercel (website), Cloudflare (network and secure tunnel), and Google Cloud (Mumbai, India) for Escanor's own AI models.
  • AI models: Google (Gemini) and Escanor's own models on Google Cloud. If you add your own key for another provider (for example Anthropic or OpenAI), your requests go to that provider under its terms.
  • Payments: Razorpay Software Private Limited, India.
  • Sign-in: Google and GitHub, when you choose to sign in with them.
  • Email and notifications: Zoho (email delivery, India) and Google Firebase Cloud Messaging for app notifications.
  • Services you connect: when you ask Escanor to act on GitHub, AWS or another connected service, we send that service what the action needs, under your own account with it.
  • Authorities: a government agency or court, when a valid legal order requires it. We check every request and disclose only what it requires.

Where it is processed

Your account and workspace data is stored in India (Mumbai). The website and network services deliver pages from locations worldwide, Gemini requests are processed by Google, and if you use your own key for an AI provider, your requests are processed wherever that provider operates. We transfer data outside India only to providers bound to protect it to the same standard, and never to a country the Government of India has restricted.

How long we keep it

  • Account and workspace data: while your account is open. When you delete your account, it is erased after a 7-day window in which you can change your mind.
  • After deletion: your name, email and sign-up date are kept for 180 days, as the IT (Intermediary) Rules, 2021 require, then erased.
  • Terminal sessions: 90 days after they close. Commands run on your machines: 180 days after they finish.
  • AI task runs and Autopilot runs: one year. AI conversations: until you delete them or your account.
  • Security and access logs: one year (at least 180 days, as CERT-In requires).
  • Payment records: as long as tax and accounting law requires (up to 8 years).
  • Complaints, privacy requests and consent records: kept as evidence of what was asked and done; contact details are removed when your account is deleted.
  • Call bookings: one year after the call.

How we protect it

Connected-service keys are encrypted at rest and decrypted only to carry out an action you asked for. All traffic is encrypted in transit. Access is limited to the people who need it, sign-ins and changes are logged, and you can turn on two-step verification. Deleting your account signs you out everywhere and revokes every key at once. If a breach affects your data, we will tell you without delay, along with what happened, what we are doing and what you can do, and report it to CERT-In and, from when that duty applies, the Data Protection Board of India.

Your rights

You can ask us for a summary of your data and how it is used, to correct or update it, to erase it, to withdraw a consent, or to nominate someone to act for you if you die or cannot act. You can also complain to us about how we handle your data. Withdrawing consent is as easy as giving it, and stops processing that relied on it from then on.

Make a request on Privacy requests, in Settings → Privacy & data when signed in, or by email to support@escanor.in from your account email. We acknowledge within 24 hours and respond within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India, or use any other remedy available to you. You may also give, manage or withdraw your consent through a Consent Manager registered with the Board, once registration opens.

The short consent notice lists, item by item, what we collect and why, in one place.

Children

Escanor is only for people aged 18 or over. We do not knowingly collect data about children. If you believe a child has an account, write to support@escanor.in and we will delete it.

Booking a call

When you book a call we collect your name, work email, company, role, team size and any notes, only to arrange and hold the call. We delete them one year after the call. Product updates are sent only if you tick that separate box.

Changes and contact

If we change this policy in a way that matters, we will tell you by email or in the app before the change applies, and ask for your agreement where the law requires it. Questions go to Lakshay Jain, Grievance Officer and data protection contact, at support@escanor.in.

Contact

Company
Escanor Labs
Address
ATF-39, Gaur World Smart Street, Sector-16B, Greater Noida West, Uttar Pradesh 201308, India
Grievance Officer
Lakshay Jain, Co-founder; Grievance Officer and data protection contact
Email (support, grievances, privacy and security)
support@escanor.in