Privacy Policy
Last updated: 11 September 2026
This policy explains how Koalr Limited, company number 17333455 (“we”, “us”, “our”) handles personal data when you visit koalr.ai and when you use the Koalr app to measure and improve how your brand shows up in AI search. We keep data collection to what we need to provide the service.
1. Who we are
Koalr Limited operates the koalr.ai website and the Koalr application, and is the data controller for personal data collected through them. For any privacy question, reach us at privacy@koalr.ai or by post:
Koalr Limitedc/o HJS, Tagus House, 9 Ocean Way
Southampton, Hampshire, SO14 3TJ
England
Where we process personal data on behalf of a business customer (for example data from accounts you connect, or logins an agency creates for its clients), we do so as that customer’s processor under the Data Processing Addendum in our Terms of Service.
2. What we collect and why
On the website (koalr.ai)
- The website address you enter — when you use the “scan my site” field, the domain you type is passed straight to the Koalr app to start your scan. The marketing site itself does not store it.
- Anything you send us — if you email us or use a contact form, we receive the details you choose to share so we can reply.
- Request logs — our hosting provider processes standard logs (including IP address and user agent) to serve the site and keep it secure.
The marketing site uses two analytics tools, Google Analytics and PostHog (hosted in the EU), and only if you opt in via the cookie banner. They tell us which pages people visit and how they found us. Until you opt in they record nothing and store nothing on your device. We do not set advertising cookies and we do not use tracking pixels.
In the Koalr app
- Account details — your name, email address, and sign-in credentials (or the identifier from a single sign-on provider, e.g. Google). Authentication and account records are handled by our authentication provider.
- The brands and websites you analyse — the domains, brand names, competitors, prompts, and settings you add, so we can run scans and track results over time.
- Scan and visibility data — content we retrieve from the public web about the sites you analyse, and the results of querying AI assistants and answer engines (such as ChatGPT, Google Gemini, Claude, Perplexity, Microsoft Copilot, and Google AI Overviews) to measure how your brand appears. We send prompts about your brand to those engines; we do not send them your account details.
- Usage and diagnostic data — IP address, device and browser information, and error/diagnostic logs, used to operate, secure, and debug the service.
- Connected Google Analytics and Search Console data — only if you choose to connect a Google account. Section 3 sets this out in full.
- Connected Bing Webmaster Tools data — only if you choose to connect a Microsoft account. Section 3A sets this out.
- Billing details — your billing name, address and, where you give one, VAT number, plus a reference to your subscription. Card details go directly to our payment processor, Stripe, and never reach Koalr.
- Product analytics — which pages and features you use in the app, recorded by PostHog (hosted in the EU) and linked to your account so we can see how the product is used and fix what is not working. In the app this runs without cookies or any other storage on your device.
- MCP server and connector access — if you connect an AI client through our MCP server, or a Looker Studio connector with a connector key, we log the tool calls made and the key used, tied to your account, to enforce rate limits and investigate problems.
- Terms acceptance — the version of the Terms of Service you accepted, when, and on which screen, kept on your account record.
We do not sell your data, and we do not use it to train AI models.
3. Google user data (Analytics and Search Console)
Connecting a Google account is entirely optional and no part of Koalr requires it. If you do connect one, this section sets out exactly what Google user data Koalr accesses, how it is used, who it is shared with, how it is protected, and how long it is kept.
Koalr’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.1 What data we access
Access happens only after you grant it on Google’s own consent screen, and only through these read-only scopes:
.../auth/analytics.readonly: read-only access to Google Analytics. We list the GA4 properties your account can see, so you can choose which one to link to a site in Koalr. For that linked property only, we then read aggregated daily reports: sessions, total users, active users, engaged sessions, key events, page views, engagement duration, and (where the property records it) revenue, broken down by date, session source, default channel group, landing page, page path, and hostname. These are report totals. We do not access user-level records, user IDs, client IDs, advertising identifiers, or any report dimension that identifies an individual visitor..../auth/webmasters.readonly: read-only access to Google Search Console. We list the properties your account can see, so you can choose which one to link. For that linked property only, we then read aggregated Search Analytics performance: clicks, impressions, click-through rate, and average position, by date, search query, and page.openidandemail: the email address of the Google account you connected. It is used only to label the connection in Koalr, so you can see which account is linked and disconnect the right one. It is not used to sign you in to Koalr, and we do not read your Google profile, contacts, or any other account data.
Both API scopes are read-only. Koalr has no ability to create, change, or delete anything in your Google Analytics or Search Console account.
3.2 How we use it
Google user data is used solely to provide the features you connected it for, and is shown only to your own Koalr organisation:
- the AI Traffic page: visits referred to your site from AI assistants such as ChatGPT, Perplexity, Gemini, Claude and Copilot, with trend, platform breakdown, landing pages, and visitor quality;
- the Google Search view: your official Search Console clicks, impressions, queries and pages, used alongside Koalr’s own AI Overview tracking so you can compare the two;
- joins between the two: which pages AI engines cite versus which pages AI traffic actually lands on, so you can see where visibility is and is not converting into visits;
- summaries and recommendations generated inside the product, including answers from the in-app assistant and, if you enable it, the figures returned through your own Koalr MCP connection.
We do not use Google user data for advertising or ad targeting, for credit, lending or eligibility decisions, for market research or benchmarking across customers, or for any purpose other than providing and improving these user-facing features for you.
3.3 Who we share it with
We do not sell Google user data, and we do not transfer it to data brokers, advertisers, ad networks, or information resellers. It is shared only with:
- our database and hosting providers, which store and serve it as part of running Koalr;
- our error-monitoring provider, which may incidentally receive limited technical detail (such as a property identifier in an error message) when a sync fails;
- our AI provider (Anthropic), when you ask the in-app assistant a question or request a summary that draws on these figures. The relevant numbers are sent so the model can answer you, and are used for nothing else. Anthropic does not use data submitted through its API to train its models.
- other members of your own Koalr organisation, and, where an agency manages your account, the agency users assigned to your site. It is never visible to another customer.
We will also disclose data if required by law, court order, or to protect the rights, property, or safety of Koalr or others.
3.4 AI and machine learning
We do not use Google user data, whether raw, aggregated, or anonymised, to develop, improve, or train any artificial intelligence or machine learning model, and we do not transfer it to any third-party service that would use it to train theirs. Where these figures are passed to an AI provider, it is only to generate an answer or summary you asked for inside Koalr.
3.5 How we protect it
- The Google refresh token is encrypted with AES-256-GCM before it is stored. The encryption key is held as a server-side secret, is never sent to the browser, and the token itself is never exposed to any client.
- All traffic to Google’s APIs and to Koalr is encrypted in transit with TLS.
- Data is stored in a managed database reachable only with restricted service credentials, and every read is scoped to the organisation that owns the connection.
- The OAuth exchange is protected by a signed, short-lived state parameter, and access to production credentials is limited to named Koalr staff.
3.6 How long we keep it, and how to delete it
- Disconnecting: you can disconnect at any time from Account → Integrations in the Koalr app. Koalr revokes its token with Google immediately, deletes the stored credential, and stops all further access. You can also revoke Koalr from your Google Account permissions page.
- Figures already imported: reports imported before you disconnected stay in your own dashboards so your history is not lost. Ask us at privacy@koalr.ai and we will delete them within 30 days. Deleting the site they belong to removes them too.
- Closing your account: all Google connections and all data derived from them are deleted within 90 days, along with the rest of your account data.
3A. Bing Webmaster Tools data
Connecting a Microsoft account is optional. If you do, we ask for read-only access to Bing Webmaster Tools, list the properties your account can see so you can choose which one to link to a site in Koalr, and then read aggregated search performance for that property only: clicks, impressions, queries and pages by date. We use it in the same views as the Google Search Console data described in section 3, store and protect it in the same way, and delete it on the same terms. Koalr cannot change anything in your Bing account. Disconnect at any time from Account → Integrations or from your Microsoft account’s app permissions.
4. Legal basis (UK GDPR)
- Providing the app — performance of our contract with you (Article 6(1)(b)), including creating your account and running the scans you request.
- Security, rate-limiting, and diagnostics — our legitimate interests (Article 6(1)(f)) in keeping the service available, preventing abuse, and fixing faults.
- Marketing emails, where we send them — your consent (Article 6(1)(a)), which you can withdraw at any time.
- Connecting your Google account — your consent (Article 6(1)(a)), given on Google’s consent screen and withdrawable at any time by disconnecting in the app or revoking access in your Google Account.
- Connecting your Microsoft account — your consent (Article 6(1)(a)), given on Microsoft’s consent screen and withdrawable at any time.
- Billing and invoicing — performance of our contract (Article 6(1)(b)) and our legal obligations (Article 6(1)(c)) to keep tax and accounting records.
- Service emails about your sites (digests, alerts, setup nudges and product updates) — our legitimate interests (Article 6(1)(f)) in keeping customers informed about the service they pay for. You can switch each of them off, per site or altogether, from Account → Notifications or the link in any such email. Account and billing emails cannot be switched off.
- Product analytics in the app — our legitimate interests (Article 6(1)(f)) in understanding how the product is used and fixing faults, run without cookies or device storage.
5. Who we share data with
Your data is handled by a small number of processors who operate under written data processing terms. We use the following categories of processor:
- Authentication provider — manages sign-in and your account credentials.
- Database and hosting providers — store your account, the brands you track, and your scan results, and serve the website and app.
- Background processing, queue, and rate-limiting provider — runs scan jobs and processes your IP address transiently to prevent abuse.
- Web data and search providers — retrieve and structure publicly available information about the websites you ask us to analyse.
- AI and answer-engine providers — receive the prompts we run to measure how your brand appears in AI search.
- Error-monitoring provider — processes diagnostic data so we can detect and fix faults.
- Payment processor (Stripe) — takes your card details and billing address directly, charges your subscription and issues invoices. Koalr never sees your full card number.
- Email delivery provider — sends account, billing and notification emails on our behalf.
- Product analytics provider (PostHog, EU-hosted) — processes app usage tied to your account, and website usage if you opt in via the cookie banner.
- Website analytics provider (Google Analytics) — if you opt in via the cookie banner, processes usage data (pages visited, referral source, IP address) to show us how the website is used.
- Internal messaging provider — receives your name and email address when you sign up or subscribe, so the founders are notified and can welcome you.
Our primary database is hosted in the European Union. Some processors may process data in the United States or other jurisdictions. UK-to-EU transfers rely on the UK-EU adequacy decision; transfers to the United States and other third countries rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or equivalent safeguards. We can provide the current list of named sub-processors on request to privacy@koalr.ai.
We will also disclose data if required by law, court order, or to protect the rights, property, or safety of Koalr or others.
6. How long we keep data
- Account and scan data — for as long as your organisation exists. When a subscription ends we keep your organisation’s data so that your history is intact if you return. We may delete organisations that never subscribed, or that have been locked for more than 12 months, after giving 30 days’ notice. If the owner asks us to delete the organisation, we remove personal data within 90 days, except what we must keep to meet a legal obligation.
- Billing records — six years after the end of the financial year they relate to, as UK tax law requires.
- Captured AI answers and public web content — the answers we retrieve from AI engines and the public pages we crawl are our own records of what those engines say and are kept for as long as they are useful for trend analysis. They are about brands and websites, not about you.
- Rate-limit counters — short-lived; rolling windows of minutes.
- Server and diagnostic logs — retained by our hosting and error-monitoring providers for up to 90 days under their standard retention policies.
7. Your rights
Under UK GDPR you have the right to:
- access a copy of your data;
- correct data that is wrong;
- have your data erased (“right to be forgotten”);
- object to or restrict processing;
- have your data provided in a portable format;
- withdraw consent at any time (without affecting earlier processing).
To exercise any of these, email privacy@koalr.ai from the address on your account. We aim to respond within 30 days.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk.
8. Cookies
On the website, we use one strictly necessary cookie to remember your cookie preference. If you opt in via the cookie banner, we also set Google Analytics cookies (names beginning _ga) and PostHog cookies (names beginning ph_) to understand which pages people visit; you can withdraw consent at any time from the cookie preferences and those cookies are deleted. In the app, our authentication provider sets strictly necessary cookies to keep you signed in and secure your session, and product analytics runs without any cookies or device storage. Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies do not require prior consent; analytics cookies are set only with yours. We do not use any advertising cookies.
9. Security
Traffic to and from the website and app is encrypted with TLS. Your data is stored in managed databases accessed only with restricted service credentials, and sign-in is handled by a dedicated authentication provider. Standard security headers (including HSTS, Content Security Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy) are applied across the service. No system is perfectly secure, but we take reasonable steps to protect your data and will notify you promptly if a breach affects you.
10. Children
Koalr is a business-to-business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes
We may update this policy as the product evolves. Material changes will be announced on this page with a new “last updated” date. If you have an account, we will email you before any change that materially affects how we use your data.
12. Contact
Questions, requests, or complaints: privacy@koalr.ai.
