RECO — Privacy Policy
Effective date: April 22, 2026
RECO ("the App") is a payment verification tool that captures screen recordings and screenshots of banking payment receipts as proof of payment. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
- User ID & Purchase ID — received from the referring platform via deep link. Used to associate recordings with the correct transaction.
- Screen recording (video) — captured during your banking session. Uploaded to secure cloud storage.
- Screenshot (image) — captured when you tap the overlay button. Uploaded to secure cloud storage.
- Device type — Android or iOS. Used for technical support and analytics.
2. Data We Do NOT Collect
- Location data
- Contacts or phone numbers
- Email addresses
- Photos from your camera or gallery
- Browsing history
- Advertising identifiers
3. How We Use Your Data
- Recordings and screenshots are uploaded to Digital Ocean Spaces (encrypted in transit via HTTPS).
- Metadata (user ID, purchase ID, device type) is stored in a secure database to track verification status.
- Staff receive time-limited signed links (7-day expiry) to review recordings.
- The referring exchange platform receives signed media URLs via API callback.
4. Data Storage & Security
- All data transmitted over HTTPS (TLS encryption).
- Media files stored in Digital Ocean Spaces with presigned URL access only — no public URLs.
- Local recordings and screenshots are deleted from your device immediately after successful upload.
- Authentication tokens are not persisted beyond the current session.
5. Data Sharing
- Recordings and metadata are shared with the referring exchange platform for payment verification.
- Staff reviewers access recordings via time-limited signed links.
- We do not sell your data to third parties.
- We do not use your data for advertising.
6. Data Retention
- Recordings are retained for the duration required for payment verification.
- You may request deletion of your data by contacting us.
7. Permissions Used
- Screen Recording (MediaProjection) — to capture your banking payment receipt as proof of payment. Requires your explicit consent each session.
- Display Over Other Apps (SYSTEM_ALERT_WINDOW) — to show a floating capture button over your banking app during recording.
- Internet — to upload recordings and communicate with our server.
8. Your Rights
- You can decline screen recording permission — the app will not function without it, but no data is collected.
- You can request deletion of your recordings by contacting the exchange platform or our support.
9. Children's Privacy
RECO is not intended for use by children under 13. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. Changes will be reflected on this page with an updated effective date.
11. Contact
For privacy questions or data deletion requests, contact the exchange platform through which you access RECO.