The short version: your designs are yours, we don't train models on your content, and we don't sell your data. The long version is below.
"Your designs are yours. We don't train models on user content, never sell or share your data, and never use your designs in marketing without permission."
KoalaFul ("we", "us", "our") is the operator of the design platform at koalaful.io and dash.koalaful.io. This policy describes what data we collect, why we collect it, how we use it, and the rights you have over it.
For any privacy question, write to legal@koalaful.io.
Email address, display name, password (hashed), and authentication tokens when you sign up. If you sign in via a third-party provider (Google, GitHub, etc.), we receive your email and profile information from that provider.
Designs you create, files you upload, brand kit settings, and folder organisation. These are stored encrypted at rest and only visible to you and anyone you explicitly share with.
Standard product analytics: pages visited, features used, error logs, browser type, IP address (for rate limiting and abuse prevention), and approximate location derived from IP. We use privacy-respecting analytics and aggregate where possible.
If you subscribe to the Pro API plan, our payment processor (Stripe) collects and stores your payment details. We never see or store full card numbers.
To provide the product: hosting your designs, rendering exports, running the editor, processing payments, sending account emails. To improve the product: anonymous usage analytics to understand which features matter. To prevent abuse: rate limiting, fraud detection, and protecting other users from spam or attack.
When you use the ChatGPT app or Claude Connector, your prompts and the resulting designs are processed by OpenAI or Anthropic respectively, governed by their privacy policies. KoalaFul does not store those prompts beyond what's required to render and save the resulting design.
Under GDPR (if you're in the EU/UK) and CCPA/CPRA (if you're in California), you have the right to:
To exercise any of these rights, email legal@koalaful.io. We'll respond within 30 days.
We keep your designs and account data for as long as your account is active. If you delete your account, all designs, uploads, and personal data are permanently removed within 30 days, except where retention is required by law (for example, billing records for tax purposes).
Encryption in transit (TLS 1.3) and at rest (AES-256). Regular security reviews, principle of least privilege internally, and prompt notification if a breach affecting your data ever occurs.
KoalaFul is not intended for users under 13. If you're a parent or guardian using KoalaFul for homeschooling or educational purposes with a younger child, the account should be in your name and you take responsibility for any content created.
If we materially update this policy, we'll notify you by email at least 30 days before changes take effect. Minor edits (typos, clarifications) may be made without notice but never to expand what we collect or how we use it.
Privacy questions, data requests, complaints: legal@koalaful.io. Our Data Protection Officer reads every email.
If you're in the EU, you also have the right to lodge a complaint with your local data protection authority.