Privacy policy

What we collect, where it goes, and who else can see it.

Last updated 6 August 2026

Who runs this

Igor is operated by a single individual, reachable at igorkakaroff@gmail.com and +91 82528 56197. There is no other staff and no third party with routine access to your content.

What we hold

  • Account details — the name and email address of each staff member with an account, and a hashed password. Passwords are stored hashed and cannot be read back by us.
  • What you type — the questions asked and the answers returned, kept so conversations survive between sessions.
  • Documents you upload — the case files sent to the reader, and the analyses produced from them.
  • Usage records — for each request, the time, the model used, and the token counts. These exist to work out cost and to raise invoices. They do not contain the text of your questions.

There are no advertising trackers, no analytics scripts, and no third-party cookies. The only cookie set is the one that keeps you signed in.

Who else sees it

To answer a question or read a document, the relevant text has to be sent through the routes and processors below, in the order listed. This inventory is generated from one processor catalog that is itself derived from the configured model registry, the reader pins and the retrieval and search configuration. Disabled rows remain visible but do not receive data unless enabled.

Processor / servicePurpose, route and what it receivesWhere it runsStatusRetention / training
Joshi & Co. model gateway (llmux) — llmux.joshi-co.com
llmux-gateway

First hop for chat, orchestration, every registry model and reader OCR in the default configuration; forwards each request to the selected upstream provider.

Receives: Every model request the application makes, before it leaves for a provider.

first-hop

Mumbai (AWS ap-south-1) — our own EC2 serverEnabled
  • Requests are forwarded to the selected upstream model provider.
  • Gateway retention and logging terms require legal confirmation.
Legal review pending — not verified by code
OpenAI — gpt-4o-mini
registry:openai/gpt-4o-mini

Configured arbiter, worker model row (chat API, fast tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The provider's own infrastructure — may process outside IndiaEnabled
  • API inputs and outputs are not used to train provider models by default.
  • Provider abuse-monitoring logs may be retained for a limited period.
Legal review pending — not verified by code
OpenAI — gpt-5-mini
registry:openai/gpt-5-mini

Configured worker, reader model row (responses API, standard tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The provider's own infrastructure — may process outside IndiaEnabled
  • API inputs and outputs are not used to train provider models by default.
  • Provider abuse-monitoring logs may be retained for a limited period.
Legal review pending — not verified by code
OpenAI — gpt-5.6-sol
registry:openai/gpt-5.6-sol

Configured orchestrator, worker, trusted model row (responses API, frontier tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The provider's own infrastructure — may process outside IndiaEnabled
  • API inputs and outputs are not used to train provider models by default.
  • Provider abuse-monitoring logs may be retained for a limited period.
Legal review pending — not verified by code
Mistral AI — mistral-large-latest
registry:mistral/mistral-large-latest

Configured worker, reader model row (chat API, standard tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The provider's own infrastructure — may process outside IndiaConfigured, disabled
  • API inputs and outputs are processed under the provider's API data terms.
  • Retention and training treatment must be confirmed for the contracted service tier.
Legal review pending — not verified by code
Mistral AI — mistral-ocr-latest
registry:mistral/mistral-ocr-latest

Configured ocr model row (ocr API, standard tier), reached through the gateway.

Receives: Scanned document pages sent for text extraction.

gateway

The provider's own infrastructure — may process outside IndiaEnabled
  • API inputs and outputs are processed under the provider's API data terms.
  • Retention and training treatment must be confirmed for the contracted service tier.
Legal review pending — not verified by code
Abliteration operator — abliterated-model
registry:abliteration/abliterated-model

Configured trusted model row (chat API, standard tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The configured endpoint's operator — location per that operator; may be outside IndiaEnabled
  • Retention and training treatment depend on the operator serving this configured endpoint.
Legal review pending — not verified by code
Anthropic — claude-opus-5
registry:anthropic/claude-opus-5

Configured orchestrator, worker model row (chat API, frontier tier), reached through the gateway.

Receives: The prompt the route builds for this row — the question and retrieved context on a safe turn; only a confined brief on a flagged turn.

gateway

The provider's own infrastructure — may process outside IndiaConfigured, disabled
  • Content sent through the API is not used to train their models.
  • Provider safety systems may retain prompts and outputs for up to 30 days.
Legal review pending — not verified by code
Trusted-model role
trusted-role

Confined (sensitive) work is routed by configured precedence: abliteration/abliterated-model → openai/gpt-5.6-sol. Disabled registry rows are never selected.

Receives: The confined brief of a flagged turn — never the safe-path prompt.

role

Whichever enabled registry row above currently holds the role.Enabled
  • The role resolves only to an enabled configured registry row.
  • The selected upstream provider's retention and training terms apply.
Legal review pending — not verified by code
Joshi & Co. corpus search (RAG serve) — rag.joshi-co.com
rag-serve

Retrieves the corpus passages an answer is grounded in. Called on every grounded turn before any model runs.

Receives: The question text on a safe turn; on a confined turn only the arbiter's sanitised query, and nothing at all on a #private turn.

retrieval

Mumbai (AWS ap-south-1) — our own EC2 serverEnabled
  • Queries are used to rank corpus passages and are not used to train any model.
  • Serve-side query logging and retention require legal confirmation.
Legal review pending — not verified by code
Mistral OCR (via the gateway) — mistral-ocr-latest
reader-ocr

Extracts text from scanned reader documents through the model gateway.

Receives: The pages of an uploaded document.

gateway

The provider's own infrastructure — may process outside IndiaEnabled
  • API inputs and outputs are processed under the provider's API data terms.
  • Retention and training treatment must be confirmed for the contracted service tier.
Legal review pending — not verified by code
Google Gemini — gemini-2.5-pro (direct rollback)
reader-google-rollback

Direct-transport reader rollback for document analysis (READER_TRANSPORT=direct only).

Receives: The uploaded document and the reader brief, when the rollback transport is active.

direct-rollback

The provider's own infrastructure — may process outside IndiaConfigured, disabled
  • Content sent through the paid API is not used to train their models.
  • Paid Gemini API prompts and responses may be logged for a limited abuse-monitoring period.
Legal review pending — not verified by code
Anthropic — claude-opus-5 (direct rollback)
reader-anthropic-rollback

Fallback on the direct-transport reader rollback path (READER_TRANSPORT=direct only).

Receives: The uploaded document and the reader brief, when the rollback transport is active.

direct-rollback

The provider's own infrastructure — may process outside IndiaConfigured, disabled
  • Content sent through the API is not used to train their models.
  • Provider safety systems may retain prompts and outputs for up to 30 days.
Legal review pending — not verified by code
Web-search proxy (cg-news editorial proxy) — search.joshi-co.com
web-search-proxy

Fetches public web-search results when a turn is grounded in the live web; tries its upstreams in order and returns the first that answers.

Receives: A server-authored search query (≤ 200 characters) on a safe turn, or the arbiter's sanitised query on a confined turn — never the raw message; nothing on a #private turn.

proxy

Mumbai (AWS ap-south-1) — our own EC2 serverEnabled
  • The proxy forwards the query to one upstream search service and returns titles, links and snippets.
  • Proxy-side logging and retention require legal confirmation.
Legal review pending — not verified by code
Google News RSS (search upstream)
search-upstream:google-news

Keyless RSS feed; tried first. Reached only through the web-search proxy.

Receives: The same search query the proxy received.

search-upstream

The provider's own infrastructure — may process outside IndiaEnabled
  • The search service's own retention and training terms apply to the query.
Legal review pending — not verified by code
Tavily (search upstream)
search-upstream:tavily

Search API; tried when the RSS leg returns nothing. Reached only through the web-search proxy.

Receives: The same search query the proxy received.

search-upstream

The provider's own infrastructure — may process outside IndiaEnabled
  • The search service's own retention and training terms apply to the query.
Legal review pending — not verified by code
SerpApi (search upstream)
search-upstream:serpapi

Search API; the last leg in the proxy's chain. Reached only through the web-search proxy.

Receives: The same search query the proxy received.

search-upstream

The provider's own infrastructure — may process outside IndiaEnabled
  • The search service's own retention and training terms apply to the query.
Legal review pending — not verified by code
Google sign-in (OAuth) — accounts.google.com
auth-google

Optional passwordless staff sign-in. Google confirms the staff member's identity; the application admits only addresses already provisioned in its own users table.

Receives: The staff member's Google account email and basic profile at sign-in — never chat text or documents. A takeover of the Google account is a takeover of the staff account.

auth

The provider's own infrastructure — may process outside IndiaNot configured
  • Google's account terms and privacy policy apply to the sign-in itself.
  • Sign-in profile data is used only to match an existing staff record.
Legal review pending — not verified by code
Amazon SES (sign-in code email)
email-ses

Delivers the one-time sign-in code when a staff member chooses "Email me a code".

Receives: The staff member's email address and a one-time sign-in code. Never chat text or documents.

auth

Amazon Web Services, ap-south-1 (Mumbai)Not configured
  • AWS does not use customer content to train models.
  • SES delivery logs and retention require legal confirmation.
Legal review pending — not verified by code

Where your text is processed.The model gateway, the corpus search service and the web-search proxy run on our own server in Mumbai (AWS ap-south-1). The model providers and search services in the table may process your text outside India — see each row's location. If that is a problem for the material you intend to put in, please raise it with us before uploading it rather than after.

Legal review pending — not verified by code

We also use Amazon Web Services to store uploaded files and database records, in the Mumbai (ap-south-1) region; Vercel to serve the application; and Razorpay to take payment. Razorpay receives only billing details — never the contents of your conversations or documents.

We do not sell your data, and we do not share it with anyone beyond the providers listed above except where we are compelled to by law.

Who can see your work inside the office

Every record belongs to exactly one office, and that boundary is enforced by the database itself rather than by application checks alone. No office can see another's material.

Within an office, the supervising officer can see the work done under the office's account, including conversations started by staff. Staff members should treat their use of Igor as visible to their supervisor and not as private.

How long we keep it

Conversations, documents, and analyses are kept until the office asks us to delete them, or until 90 days after the last account in that office is closed, whichever comes first. Usage and invoice records are kept for eight years, as tax law requires. Backups are retained for 35 days, so deleted material can persist in backups for that period before it ages out.

Legal review pending — not verified by code

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to igorkakaroff@gmail.com. We will respond within 30 days. If a request would delete records we are legally required to keep — invoices, principally — we will tell you which ones and why.

Security

Traffic is encrypted in transit. Files and database contents are encrypted at rest. Access to production systems is limited to the operator. If we ever discover a breach affecting your data, we will tell the affected office without delay and describe what happened, what was exposed, and what we have done about it.

Changes

If this policy changes in substance we will email every account holder before the change takes effect. The date at the top of this page shows when it was last revised.