CoCap
CoCap
We collect what’s needed to help you practise — and nothing to sell. Here’s exactly what we hold, who touches it, and how to take it back.
Last updated: 23 September 2026
CoCap is operated by Kapil Bansal (sole proprietor, GSTIN 23GALPB3479M1ZB), 140, Nihalpur Mundi, Indore, Madhya Pradesh 453331, India — the data fiduciary responsible for your personal data under India's Digital Personal Data Protection Act, 2023.
For any question, request or complaint about your data, write to our grievance contact at hello@cocap.in. We respond within 30 days.
Account: your phone number and/or email address (whichever you sign in with), and what you choose to add — your name, photo, city, a line about you, your learning goal, and the level you picked when you joined.
Practice: your answers in Learn and Words, the words you save, your level-check answers, the evidence behind your English level, your conversations with Kyra, and your CapCoins and XP.
Your speech, in three different ways:
Sessions: your bookings, times and topics, any note you add for the other member, feedback and problem reports you send, people you block, your age confirmation (Sessions are 18+) and, if you apply to host, your application. If a verified host connects Zoom, we also keep the Zoom user/account identifiers, granted scopes and encrypted OAuth authorization needed to create and run that host's Sessions while the connection remains active. See Sessions below.
Feedback and support messages: what you write, an optional screenshot, and — stated on the form — the app version, the screen you came from and your device type. If you are not signed in and leave an email for a reply, that email.
App and device: counts of which screens and actions are used, and the technical detail of an error when one happens. We do not collect your contacts, your precise location, your device advertising ID, or anything from other apps.
A notification token, in the Android app. If you allow notifications, Android gives the app an anonymous device token through Google's Firebase Cloud Messaging, and we store it so we can send you a reminder. It carries no name, number or address, it is reset if you reinstall CoCap, and refusing the permission stops it being created. It is deleted with your account.
WhatsApp, when you choose it. If you turn on WhatsApp updates or message Kyra there, Kapso and WhatsApp (Meta) route your WhatsApp number and the message needed for that conversation. When you message CoCap on WhatsApp, CoCap keeps the canonical WhatsApp delivery address observed on that signed inbound message so later updates go back to the same account instead of guessing a country code from a local-format profile phone. CoCap also keeps your WhatsApp consent and reminder preferences, plus delivery metadata such as sent, delivered, read or failed. For a scheduled template, CoCap may temporarily keep the template parameters needed to send it (for example your first name or Session time); those parameters are erased as soon as the job is sent, skipped, failed or expires. Terminal workflow metadata is retained for up to 30 days for operational debugging. The delivery log does not store a second copy of the message body or your phone number.
How you found us. When you first arrive we note the website that sent you, any campaign tag in the link, and which CoCap page you landed on — once, with your account. It is not shared and is deleted with your account.
Payments. CoCap is free in this release and takes no new payments. The Android app has no in-app purchases or subscriptions. Until July 2026 the website briefly sold plans through Razorpay; we keep the order records of those payments for as long as the law requires.
When you ask Kyra something, she is given: your first name; a short summary of your English level, goal and the mistakes you repeat; how much of your own language to use; up to 5 of the notes she keeps about you; and whatever is on your screen at that moment. That is sent to our AI provider (OpenAI, United States) to write her answer.
Her notes. Kyra keeps a few short notes between conversations — an exam date, a job you are preparing for, how you like to be corrected — each with the reason it is kept and whether you told her or she worked it out. She refuses to keep phone numbers, emails, codes or ID numbers.
Your control. Me → Kyra’s memory shows every note and everything she reads from your progress. You can correct, pin, add or forget a note, forget all of them, or clear what she worked out about you. Forgetting is permanent: the note is deleted, not hidden.
Memory and progress are different. Deleting a Kyra note stops that note being used in later conversations, but it does not erase the practice evidence behind My English, such as completed exercises or level evidence. Those records are part of your learning progress and can be removed through the relevant in-app controls or by deleting your account.
Kyra is never given your phone number or your email. Raw saved recordings are not turned into Kyra memory notes. When you explicitly request speaking feedback, the transcript and validated feedback may contribute a structured learning signal such as a recurring grammar or phrasing mistake; Kyra may later receive that short learning summary as part of your progress context, not the recording itself or the full transcript. Nothing she is given is used for advertising or to train AI models.
To run CoCap: coach you, work out and show your English level, run Sessions, keep your CapCoins and XP, send the reminders you asked for, answer your messages, and keep CoCap safe and working.
We do not sell your personal data. Ever.
We do not use your conversations or recordings to train AI models. Groq's current business-service terms prohibit using customer inputs or outputs for model training unless the customer explicitly authorises it; CoCap does not give that authorisation.
These providers process data for us, each bound by contract and given only what its job needs:
Website measurement loads only if you agree to it, and never receives your practice, recordings or conversations. CoCap shows no ads and ships no advertising SDK.
Your account, your practice history and your saved recordings are stored in India (Mumbai).
Some processing happens outside India, under contractual safeguards and limited to what the task needs: what Kyra is given (OpenAI, United States); short audio clips for transcription and speaking feedback (Groq, United States); Sessions video calls (Zoom); crash diagnostics; some email delivery; and the servers that run the app, which sit on a global network. None of it is used for advertising or model training.
Sessions are 20-minute English conversations with another member, on Zoom. They are for people aged 18 and over; you confirm your age the first time you book or apply to host.
What the other member sees: your first name, the topic you picked and any note you add for them. A host also sees the times you have booked with them. Your phone number and email are never shown.
The call itself runs on Zoom, on the host's own Zoom account, and Zoom's privacy policy applies to it. CoCap does not record Sessions, and members must not record them either.
If you connect Zoom as a host: you authorize CoCap on Zoom's own consent screen. We store the minimum Zoom connection data needed to create and manage your Sessions — your Zoom user/account identifiers, the scopes you granted, and OAuth access/refresh tokens encrypted at rest. CoCap never sees your Zoom password.
When you disconnect or remove CoCap from Zoom: we revoke access when possible, erase the stored Zoom authorization and Zoom profile identifiers from the connection, and cancel future Sessions that depended on that connection so another member is not left waiting. You can reconnect later through Zoom's authorization screen.
Reports and blocks are seen only by the CoCap team, who use them to keep Sessions safe. If you apply to host, CoCap reviews your application by hand.
Much of it you can do yourself, inside the app:
You may also ask us to correct your data, tell you what we hold, remove something the app has no button for, or act for someone you nominate. Write to hello@cocap.in — we act within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
Data is stored with row-level security and reached only through our servers, over encrypted connections. Saved recordings and feedback screenshots sit in private storage, reachable only through short-lived signed links. Login codes expire in 5 minutes and are stored hashed.
We keep your practice history while your account is active, because your level and progress are built from it. A note you tell Kyra to forget is deleted straight away. Zoom connection credentials and identifiers are removed when a host disconnects Zoom or removes CoCap from their Zoom account.
When you delete your account it is deactivated at once and permanently erased after 30 days — including your recordings, your Kyra notes and your uploads. Messages you sent us and reports you made in Sessions are kept, detached from your account, so we can act on them; ask and we will delete those too. Beyond that we keep only what the law requires, such as the records of earlier payments.
CoCap is for people 13 and older; Sessions are for 18 and older.
Under India's DPDP Act anyone under 18 is a child. If you are under 18, please use CoCap with a parent or guardian's knowledge and consent. We show no advertising, we do not track anyone across other apps or websites, and we do not use anyone's conversations for AI training.
If you believe a child under 13 is using CoCap, or you are a parent who wants an account removed, contact us and we will delete it.
When how we handle data changes, we update this page and its date. For a change that materially affects you, we tell you in the app or by email before it takes effect.