> ## Documentation Index
> Fetch the complete documentation index at: https://docs.koalr.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and data

> Where your data lives, how it is protected, who can reach it, what Koalr never does with it, and how to get it removed.

Koalr is built and run by Koalr Limited in the United Kingdom. This page is the practical summary; the [privacy policy](https://koalr.ai/privacy) and [terms](https://koalr.ai/terms) are the full versions.

## Hosting and encryption

* Your data is held in a managed database hosted in the European Union, reached only with restricted service credentials.
* All traffic to the website and the app is encrypted in transit, and data is encrypted at rest.
* The production database is backed up every night.
* Standard security headers are applied across the app, including HSTS, a Content Security Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy.
* The tokens that link your Google and Bing accounts are encrypted with AES-256-GCM before they are stored, and the connections use read-only scopes. Koalr cannot write to those accounts, and you can revoke access from your Google or Microsoft account at any time.

## Access to your account

* Sign-in supports email and Google accounts. Two-step verification is not available yet.
* Your own account, its sign-in methods and active devices are managed under your avatar, **Account**, where you can also delete the account.
* Organisation roles (Owner, Member) and per-site levels (Viewer, Editor, Manager) control what each person can see and change. See [Members and roles](/account/members-and-roles).
* The MCP server authenticates with your own Koalr login over OAuth, shows a consent screen, is read-only, and its sign-ins expire within 24 hours. See [Limits and security](/api/mcp/limits-and-security).
* Connector keys for Looker Studio are organisation-scoped, owner-created, shown once, stored only as a one-way hash, and revocable with immediate effect.

## Access by Koalr staff

Koalr staff have no standing access to your workspace. When we need to see what you see to investigate something you have reported, we use the sign-in provider's impersonation feature, which records every such session as an impersonation rather than as you.

## What Koalr stores

* The AI answers it captures for your prompts, in full, and the metrics derived from them.
* Your site configuration, prompts, competitors, actions, drafts and reports.
* Aggregated traffic and search data from the Google and Bing properties you connect.
* Your organisation's members, roles and preferences, and the record of your acceptance of the terms.
* Server and diagnostic logs, kept for up to 90 days.

## What Koalr never does

* **Sell your data.**
* **Train AI models on it.** Neither your Koalr data nor any Google user data, raw, aggregated or anonymised, is used to develop, improve or train any AI or machine-learning model.
* **Store card details.** Payment is handled by Stripe. Koalr holds a reference to your subscription, never the card.
* **Store Google or Bing credentials.** Only encrypted, read-only tokens.
* **Keep plain-text keys.** Connector keys are shown once and hashed.

## Third parties

Koalr uses a small number of processors to run the service: an authentication provider, database and hosting providers, a background-processing provider, web data and search providers, AI and answer-engine providers, an error-monitoring provider, an email delivery provider, a payment processor (Stripe), a product analytics provider hosted in the EU, and an internal messaging provider. Transfers outside the UK and EU rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or equivalent safeguards. The current list of named sub-processors is available on request to [privacy@koalr.ai](mailto:privacy@koalr.ai).

## Retention and deletion

* Account and site data is kept for as long as your organisation exists, and for at least 30 days after a subscription ends.
* Deleting a site removes everything it holds. Deleting your organisation, requested by an owner, cancels the subscription and removes every site; the data is deleted within 90 days of the request. Google and Bing connections and everything derived from them go with it.
* Billing records are kept for six years after the financial year they relate to, as the law requires.
* An organisation left dormant for a long time may be deleted after 30 days' notice by email.

## Your rights

Email [privacy@koalr.ai](mailto:privacy@koalr.ai) to access a copy of your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, or withdraw consent. We aim to respond within 30 days. The UK regulator is the Information Commissioner's Office.

## If something goes wrong

No system is perfectly secure. Koalr takes reasonable steps to protect your data and will notify you promptly if a breach affects you. If you find a vulnerability, email [support@koalr.ai](mailto:support@koalr.ai) and do not test against other customers' data.

## Questions

[privacy@koalr.ai](mailto:privacy@koalr.ai) for privacy, [legal@koalr.ai](mailto:legal@koalr.ai) for contracts, [support@koalr.ai](mailto:support@koalr.ai) for everything else.
