Skip to main content
Koalr is built and run by Koalr Limited in the United Kingdom. This page is the practical summary; the privacy policy and terms are the full versions.

Hosting and encryption

  • Your data is held in a managed database hosted in the European Union, reached only with restricted service credentials.
  • All traffic to the website and the app is encrypted in transit, and data is encrypted at rest.
  • Standard security headers are applied across the app, including HSTS, a Content Security Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy.
  • The tokens that link your Google and Bing accounts are encrypted with AES-256-GCM before they are stored, and the connections use read-only scopes. Koalr cannot write to those accounts, and you can revoke access from your Google or Microsoft account at any time.

Access to your account

  • Sign-in supports email and Google accounts.
  • Organisation roles (Owner, Member) and per-site levels (Viewer, Editor, Manager) control what each person can see and change. See Members and roles.
  • The MCP server authenticates with your own Koalr login over OAuth, shows a consent screen, is read-only, and its sign-ins expire within 24 hours. See Limits and security.
  • Connector keys for Looker Studio are organisation-scoped, owner-created, shown once, stored only as a one-way hash, and revocable with immediate effect.

What Koalr stores

  • The AI answers it captures for your prompts, in full, and the metrics derived from them.
  • Your site configuration, prompts, competitors, actions, drafts and reports.
  • Aggregated traffic and search data from the Google and Bing properties you connect.
  • Your organisation’s members, roles and preferences, and the record of your acceptance of the terms.
  • Server and diagnostic logs, kept for up to 90 days.

What Koalr never does

  • Sell your data.
  • Train AI models on it. Neither your Koalr data nor any Google user data, raw, aggregated or anonymised, is used to develop, improve or train any AI or machine-learning model.
  • Store card details. Payment is handled by Stripe. Koalr holds a reference to your subscription, never the card.
  • Store Google or Bing credentials. Only encrypted, read-only tokens.
  • Keep plain-text keys. Connector keys are shown once and hashed.

Third parties

Koalr uses a small number of processors to run the service: an authentication provider, database and hosting providers, a background-processing provider, web data and search providers, AI and answer-engine providers, an error-monitoring provider, an email delivery provider, a payment processor (Stripe), a product analytics provider hosted in the EU, and an internal messaging provider. Transfers outside the UK and EU rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or equivalent safeguards. The current list of named sub-processors is available on request to privacy@koalr.ai.

Retention and deletion

  • Account and site data is kept for as long as your organisation exists, and for at least 30 days after a subscription ends.
  • Deleting a site removes everything it holds. Deleting your organisation, requested by an owner, cancels the subscription and removes every site; the data is deleted within 90 days of the request. Google and Bing connections and everything derived from them go with it.
  • Billing records are kept for six years after the financial year they relate to, as the law requires.
  • An organisation left dormant for a long time may be deleted after 30 days’ notice by email.

Your rights

Email privacy@koalr.ai to access a copy of your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, or withdraw consent. We aim to respond within 30 days. The UK regulator is the Information Commissioner’s Office.

If something goes wrong

No system is perfectly secure. Koalr takes reasonable steps to protect your data, patches promptly, and will notify you promptly if a breach affects you.

Questions

privacy@koalr.ai for privacy, legal@koalr.ai for contracts, support@koalr.ai for everything else.