Privacy policy
What we collect, where it goes, and who else can see it.
Last updated 6 August 2026
Who runs this
Igor is operated by a single individual, reachable at igorkakaroff@gmail.com and +91 82528 56197. There is no other staff and no third party with routine access to your content.
What we hold
- Account details — the name and email address of each staff member with an account, and a hashed password. Passwords are stored hashed and cannot be read back by us.
- What you type — the questions asked and the answers returned, kept so conversations survive between sessions.
- Documents you upload — the case files sent to the reader, and the analyses produced from them.
- Usage records — for each request, the time, the model used, and the token counts. These exist to work out cost and to raise invoices. They do not contain the text of your questions.
There are no advertising trackers, no analytics scripts, and no third-party cookies. The only cookie set is the one that keeps you signed in.
Who else sees it
To answer a question or read a document, the relevant text has to be sent through the routes and processors below, in the order listed. This inventory is generated from one processor catalog that is itself derived from the configured model registry, the reader pins and the retrieval and search configuration. Disabled rows remain visible but do not receive data unless enabled.
| Processor / service | Purpose, route and what it receives | Where it runs | Status | Retention / training |
|---|---|---|---|---|
Joshi & Co. model gateway (llmux) — llmux.joshi-co.com llmux-gateway | First hop for chat, orchestration, every registry model and reader OCR in the default configuration; forwards each request to the selected upstream provider. Receives: Every model request the application makes, before it leaves for a provider. first-hop | Mumbai (AWS ap-south-1) — our own EC2 server | Enabled |
|
OpenAI — gpt-4o-mini registry:openai/gpt-4o-mini | Configured arbiter, worker model row (chat API, fast tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The provider's own infrastructure — may process outside India | Enabled |
|
OpenAI — gpt-5-mini registry:openai/gpt-5-mini | Configured worker, reader model row (responses API, standard tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The provider's own infrastructure — may process outside India | Enabled |
|
OpenAI — gpt-5.6-sol registry:openai/gpt-5.6-sol | Configured orchestrator, worker, trusted model row (responses API, frontier tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The provider's own infrastructure — may process outside India | Enabled |
|
Mistral AI — mistral-large-latest registry:mistral/mistral-large-latest | Configured worker, reader model row (chat API, standard tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The provider's own infrastructure — may process outside India | Configured, disabled |
|
Mistral AI — mistral-ocr-latest registry:mistral/mistral-ocr-latest | Configured ocr model row (ocr API, standard tier), reached through the gateway. Receives: Scanned document pages sent for text extraction. gateway | The provider's own infrastructure — may process outside India | Enabled |
|
Abliteration operator — abliterated-model registry:abliteration/abliterated-model | Configured trusted model row (chat API, standard tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The configured endpoint's operator — location per that operator; may be outside India | Enabled |
|
Anthropic — claude-opus-5 registry:anthropic/claude-opus-5 | Configured orchestrator, worker model row (chat API, frontier tier), reached through the gateway. Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn. gateway | The provider's own infrastructure — may process outside India | Configured, disabled |
|
Trusted-model role trusted-role | Confined (sensitive) work is routed by configured precedence: abliteration/abliterated-model → openai/gpt-5.6-sol. Disabled registry rows are never selected. Receives: The confined brief of a flagged turn — never the safe-path prompt. role | Whichever enabled registry row above currently holds the role. | Enabled |
|
Joshi & Co. corpus search (RAG serve) — rag.joshi-co.com rag-serve | Retrieves the corpus passages an answer is grounded in. Called on every grounded turn before any model runs. Receives: The question text on a safe turn; on a confined turn only the arbiter's sanitised query, and nothing at all on a #private turn. retrieval | Mumbai (AWS ap-south-1) — our own EC2 server | Enabled |
|
Mistral OCR (via the gateway) — mistral-ocr-latest reader-ocr | Extracts text from scanned reader documents through the model gateway. Receives: The pages of an uploaded document. gateway | The provider's own infrastructure — may process outside India | Enabled |
|
Google Gemini — gemini-2.5-pro (direct rollback) reader-google-rollback | Direct-transport reader rollback for document analysis (READER_TRANSPORT=direct only). Receives: The uploaded document and the reader brief, when the rollback transport is active. direct-rollback | The provider's own infrastructure — may process outside India | Configured, disabled |
|
Anthropic — claude-opus-5 (direct rollback) reader-anthropic-rollback | Fallback on the direct-transport reader rollback path (READER_TRANSPORT=direct only). Receives: The uploaded document and the reader brief, when the rollback transport is active. direct-rollback | The provider's own infrastructure — may process outside India | Configured, disabled |
|
Web-search proxy (cg-news editorial proxy) — search.joshi-co.com web-search-proxy | Fetches public web-search results when a turn is grounded in the live web; tries its upstreams in order and returns the first that answers. Receives: A server-authored search query (≤ 200 characters) on a safe turn, or the arbiter's sanitised query on a confined turn — never the raw message; nothing on a #private turn. proxy | Mumbai (AWS ap-south-1) — our own EC2 server | Enabled |
|
Google News RSS (search upstream) search-upstream:google-news | Keyless RSS feed; tried first. Reached only through the web-search proxy. Receives: The same search query the proxy received. search-upstream | The provider's own infrastructure — may process outside India | Enabled |
|
Tavily (search upstream) search-upstream:tavily | Search API; tried when the RSS leg returns nothing. Reached only through the web-search proxy. Receives: The same search query the proxy received. search-upstream | The provider's own infrastructure — may process outside India | Enabled |
|
SerpApi (search upstream) search-upstream:serpapi | Search API; the last leg in the proxy's chain. Reached only through the web-search proxy. Receives: The same search query the proxy received. search-upstream | The provider's own infrastructure — may process outside India | Enabled |
|
Google sign-in (OAuth) — accounts.google.com auth-google | Optional passwordless staff sign-in. Google confirms the staff member's identity; the application admits only addresses already provisioned in its own users table. Receives: The staff member's Google account email and basic profile at sign-in — never chat text or documents. A takeover of the Google account is a takeover of the staff account. auth | The provider's own infrastructure — may process outside India | Not configured |
|
Amazon SES (sign-in code email) email-ses | Delivers the one-time sign-in code when a staff member chooses "Email me a code". Receives: The staff member's email address and a one-time sign-in code. Never chat text or documents. auth | Amazon Web Services, ap-south-1 (Mumbai) | Not configured |
|
Where your text is processed.The model gateway, the corpus search service and the web-search proxy run on our own server in Mumbai (AWS ap-south-1). The model providers and search services in the table may process your text outside India — see each row's location. If that is a problem for the material you intend to put in, please raise it with us before uploading it rather than after.
Legal review pending — not verified by codeWe also use Amazon Web Services to store uploaded files and database records, in the Mumbai (ap-south-1) region; Vercel to serve the application; and Razorpay to take payment. Razorpay receives only billing details — never the contents of your conversations or documents.
We do not sell your data, and we do not share it with anyone beyond the providers listed above except where we are compelled to by law.
Who can see your work inside the office
Every record belongs to exactly one office, and that boundary is enforced by the database itself rather than by application checks alone. No office can see another's material.
Within an office, the supervising officer can see the work done under the office's account, including conversations started by staff. Staff members should treat their use of Igor as visible to their supervisor and not as private.
How long we keep it
Conversations, documents, and analyses are kept until the office asks us to delete them, or until 90 days after the last account in that office is closed, whichever comes first. Usage and invoice records are kept for eight years, as tax law requires. Backups are retained for 35 days, so deleted material can persist in backups for that period before it ages out.
Legal review pending — not verified by codeYour rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to igorkakaroff@gmail.com. We will respond within 30 days. If a request would delete records we are legally required to keep — invoices, principally — we will tell you which ones and why.
Security
Traffic is encrypted in transit. Files and database contents are encrypted at rest. Access to production systems is limited to the operator. If we ever discover a breach affecting your data, we will tell the affected office without delay and describe what happened, what was exposed, and what we have done about it.
Changes
If this policy changes in substance we will email every account holder before the change takes effect. The date at the top of this page shows when it was last revised.