Privacy Policy

Last updated: 1 June 2026

This policy explains how Koalr Ltd (“we”, “us”, “our”) handles personal data when you visit koalr.ai and when you use the Koalr app to measure and improve how your brand shows up in AI search. We keep data collection to what we need to provide the service.

1. Who we are

Koalr Ltd operates the koalr.ai website and the Koalr application, and is the data controller for personal data collected through them. For any privacy question, reach us at privacy@koalr.ai or by post:

Koalr Ltd
PO Box 4321
London WC1N 3AX
United Kingdom

2. What we collect and why

On the website (koalr.ai)

  • The website address you enter — when you use the “scan my site” field, the domain you type is passed straight to the Koalr app to start your scan. The marketing site itself does not store it.
  • Anything you send us — if you email us or use a contact form, we receive the details you choose to share so we can reply.
  • Request logs — our hosting provider processes standard logs (including IP address and user agent) to serve the site and keep it secure.

The marketing site runs no analytics. We do not set advertising or tracking cookies and we do not use tracking pixels.

In the Koalr app

  • Account details — your name, email address, and sign-in credentials (or the identifier from a single sign-on provider, e.g. Google). Authentication and account records are handled by our authentication provider.
  • The brands and websites you analyse — the domains, brand names, competitors, prompts, and settings you add, so we can run scans and track results over time.
  • Scan and visibility data — content we retrieve from the public web about the sites you analyse, and the results of querying AI assistants and answer engines (such as ChatGPT, Google Gemini, Claude, Perplexity, Microsoft Copilot, and Google AI Overviews) to measure how your brand appears. We send prompts about your brand to those engines; we do not send them your account details.
  • Usage and diagnostic data — IP address, device and browser information, and error/diagnostic logs, used to operate, secure, and debug the service.

We do not sell your data, and we do not use it to train AI models.

3. Legal basis (UK GDPR)

  • Providing the app — performance of our contract with you (Article 6(1)(b)), including creating your account and running the scans you request.
  • Security, rate-limiting, and diagnostics — our legitimate interests (Article 6(1)(f)) in keeping the service available, preventing abuse, and fixing faults.
  • Marketing emails, where we send them — your consent (Article 6(1)(a)), which you can withdraw at any time.

4. Who we share data with

Your data is handled by a small number of processors who operate under written data processing terms. We use the following categories of processor:

  • Authentication provider — manages sign-in and your account credentials.
  • Database and hosting providers — store your account, the brands you track, and your scan results, and serve the website and app.
  • Background processing, queue, and rate-limiting provider — runs scan jobs and processes your IP address transiently to prevent abuse.
  • Web data and search providers — retrieve and structure publicly available information about the websites you ask us to analyse.
  • AI and answer-engine providers — receive the prompts we run to measure how your brand appears in AI search.
  • Error-monitoring provider — processes diagnostic data so we can detect and fix faults.

Our primary database is hosted in the European Union. Some processors may process data in the United States or other jurisdictions. UK-to-EU transfers rely on the UK-EU adequacy decision; transfers to the United States and other third countries rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or equivalent safeguards. We can provide the current list of named sub-processors on request to privacy@koalr.ai.

We will also disclose data if required by law, court order, or to protect the rights, property, or safety of Koalr or others.

5. How long we keep data

  • Account and scan data — for as long as your account is active. If you close your account or ask us to delete it, we remove your personal data within 90 days, except where we must keep it to meet a legal obligation.
  • Rate-limit counters — short-lived; rolling windows of minutes.
  • Server and diagnostic logs — retained by our hosting and error-monitoring providers for up to 90 days under their standard retention policies.

6. Your rights

Under UK GDPR you have the right to:

  • access a copy of your data;
  • correct data that is wrong;
  • have your data erased (“right to be forgotten”);
  • object to or restrict processing;
  • have your data provided in a portable format;
  • withdraw consent at any time (without affecting earlier processing).

To exercise any of these, email privacy@koalr.ai from the address on your account. We aim to respond within 30 days.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk.

7. Cookies

On the website, we use one strictly necessary cookie to remember your cookie preference. In the app, our authentication provider sets strictly necessary cookies to keep you signed in and secure your session. Under the Privacy and Electronic Communications Regulations (PECR), strictly necessary cookies do not require prior consent. We do not use any analytics or advertising cookies.

8. Security

Traffic to and from the website and app is encrypted with TLS. Your data is stored in managed databases accessed only with restricted service credentials, and sign-in is handled by a dedicated authentication provider. Standard security headers (including HSTS, Content Security Policy, X-Frame-Options, Referrer-Policy and Permissions-Policy) are applied across the service. No system is perfectly secure, but we take reasonable steps to protect your data and will notify you promptly if a breach affects you.

9. Children

Koalr is a business-to-business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes

We may update this policy as the product evolves. Material changes will be announced on this page with a new “last updated” date. If you have an account, we will email you before any change that materially affects how we use your data.

11. Contact

Questions, requests, or complaints: privacy@koalr.ai.

© 2026 Koalr Ltd. All rights reserved.