Privacy Policy
This policy explains what personal data Kool collects, why, and the rights you have. We collect the minimum needed to run a social app. We do not sell your data, run no third-party analytics or advertising trackers, and do not track you across other apps or websites.
What we collect
- Account. Your email address (used for passwordless sign-in), username, display name, and optional bio, link, gender and avatar. A phone number only if you add one.
- Sign-in & security data. We store only a short-lived hash of your one-time sign-in code (never the code), hashed session tokens with device info so you can revoke devices, and, if you enable it, a 2FA secret and hashed recovery codes. We log IP addresses and basic technical data to prevent abuse.
- Content you create. Messages, photos, videos, stories, posts, clips, live streams, comments, and meeting/call metadata (including any location you type into a meeting). Stories auto-delete after 24 hours.
- Connected email (optional). If you link a mailbox we store its provider and address. For Gmail we access your mail through Google's API only to show and send it inside Kool. Kool's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. We never sell it, use it for ads, or let humans read it.
- Music tags. Titles, artwork and 30-second previews come from Apple's public catalog; we store only the tag you attach.
Payments
Kool is currently free and we do not collect or store any payment-card data. If in-app purchases launch, Apple or Google will process them. We never see your card details.
Advertising
Any ads are contextual (based at most on a coarse country/language), never on a tracking profile. There is no cross-app tracking and no IDFA/ATT prompt.
AI
We use Cloudflare Workers AI, within our infrastructure, for content moderation and optional writing assistance. We don't sell your content to AI vendors or use your private content to train third-party models. Automated moderation decisions can be appealed in-app.
Where it lives & who we share with
Data is stored on Cloudflare (D1 database, R2 storage) and sent over TLS. We share data only with the providers needed to run Kool. See Subprocessors (Cloudflare, Resend for email, Google if you link Gmail, Apple), with other users as you direct, or where required by law. We never sell or rent it.
Your rights
Depending on where you live (GDPR/UK GDPR, CCPA/CPRA and others) you can access, correct, delete, port, or restrict your data, object to certain processing, and withdraw consent. We honour these rights for everyone. Use in-app controls or email privacy@k00l.app. EU/EEA/UK users may also complain to their local data-protection authority.
Retention & deletion
We keep data only as long as needed. Stories expire after ~24 hours; your account and content are deleted when you close your account (Profile → Settings → Close account) or email privacy@k00l.app, subject to short backup/log retention.
Children
Kool is for 16 and over, with one exception: a child account, which a parent or guardian creates inside a Kool family for someone aged 13 to 15. It exists only because that guardian gave permission, and we record who gave it, when, and how, as GDPR Article 8 requires. A guardian can withdraw that permission at any time in Profile → Family, which closes the child's account and deletes its data.
On a child account we collect the same data as any other account, plus the year of birth (not a full date — the only question it answers is whether they have turned 16) and a record of how long they spend in each area of Kool, which their guardian can see. Guardians can never read anyone's messages, including their child's; where our automated safety checks find sexual, violent, criminal or self-harm content involving a child account, the guardian is told the topic and the time and is never shown the content. Guardianship ends automatically the year they turn 16, when the account becomes theirs alone and nothing is deleted.
Kool is not directed to children under 13 and we do not knowingly collect their data. If you believe a child under 13 has an account, contact privacy@k00l.app and we will delete it.
International transfers
Kool runs on Cloudflare's global network; where data crosses borders we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and UK Addendum).
Contact
Privacy: privacy@k00l.app · Escalation: dpo@k00l.app