Kroolo AI Policy
Application and responsible use of Kroolo AI
Last updated: 01 September 2026
Kroolo builds AI into how teams plan, decide and act. This policy explains what Kroolo AI is, how it should be applied, the principles we follow in building and running it, and the rules that apply when you use it. It applies to everyone who uses Kroolo AI, including Customers, their Users, and visitors who use the free AI tools on our Sites.
This policy supplements our Terms of Service, Privacy Policy and Security Policy and, for Customers with a signed agreement, the AI terms in that agreement. If a signed agreement conflicts with this policy, the signed agreement controls. Capitalized terms not defined here have the meaning given in the Terms.
1. Scope and key terms
1.1 What Kroolo AI is. “Kroolo AI” means the AI Features of the Services, including the Kroo assistant, AI Agents, chat with files and projects, AI-assisted projects, tasks, documents, forms, dashboards and workflows, voice-to-workflow, and Kroolo Search. It also includes the free AI tools on our Sites, such as the Grammar Checker, Paraphraser, Summarizer, Translator and Chat with PDF. Appendix A describes each.
1.2 Key terms.
- “AI Agent” means a configurable AI Feature that performs tasks for a User or team, and that may take actions in the Services or in connected systems.
- “Knowledge Base” means content that a User or Admin gives an AI Agent as reference material.
- “Input” and “Output” have the meaning given in the Terms.
- “High-Impact Use” has the meaning given in Section 8.
1.3 Who must follow this policy. Customers are responsible for their Users’ compliance. Visitors who use free AI tools must follow Sections 4.7, 7 and 9.
2. Our principles
We design, build and run Kroolo AI around these principles.
2.1 Your control. You decide which AI Features are used, by whom, and on what data. Your content stays yours, and Kroolo AI does not gain access beyond what you allow.
2.2 Privacy and confidentiality by design. We send models only what a request needs, we do not train on your data, and we keep AI activity inside the security controls in our Security Policy.
2.3 Transparency. We tell you when a feature uses AI, which providers process your content, and what the known limits are.
2.4 Human oversight. AI supports people. It does not replace human judgment, especially where decisions affect people’s rights, money, jobs or safety.
2.5 Fairness. We work to reduce bias in how AI Features behave, and we prohibit uses that unlawfully discriminate.
2.6 Safety and security. We test AI Features before release, protect them against misuse and attack, and respond when problems are reported.
2.7 Accountability. Named owners at Kroolo are responsible for AI risk, and we hold our providers and ourselves to written commitments.
3. How Kroolo AI is applied
3.1 Intended uses. Kroolo AI is built for business productivity. Typical uses are drafting, summarizing and translating content; creating and organizing projects, tasks, documents and forms; asking questions about your workspace; searching across connected sources; producing insights from your own data; and automating routine workflows.
3.2 What it is not for. Kroolo AI is not a substitute for professional advice or judgment. It is not a medical device and must not be used to diagnose, treat or respond to emergencies. It is not designed to be the sole basis for decisions in the High-Impact Uses in Section 8.
3.3 How a request is handled. In general:
- you enter a prompt or start an AI Agent;
- Kroolo gathers only the context that you, or the permissions you hold, allow, such as a document you selected, project data, or search results;
- Kroolo sends the prompt and that context to the model provider that powers the feature;
- the provider returns Output, which Kroolo shows to you; and
- if an AI Agent is involved, it may take actions within the permissions it has been given.
3.4 Personalization and memory. Kroolo AI can use instructions, Knowledge Bases and history stored in your workspace to tailor responses for your account or team. This personalization is stored in your workspace under your controls and is not used to train models.
3.5 Web and external content. Where a feature reads web pages, emails, or documents from outside your organization, that content is untrusted. It may be wrong, and it may contain hidden instructions aimed at AI systems. Kroolo applies safeguards, but you should check important information against the original source.
3.6 Languages, formats and data types. Quality varies by language and file type. Take particular care with translations, numbers, tables and spreadsheets, scanned or handwritten documents, and long files.
4. Data use and protection
4.1 No training on your data. We do not use Customer Data, Input or Output to train or fine-tune Kroolo’s models or any third-party model, and we require our model providers to make the same commitment. A Customer may opt in in writing to a specific program that uses its data for improvement or evaluation. Usage Data and de-identified information may still be used as the Terms describe.
4.2 Data minimization and providers. We send a provider only the content a feature needs, and not unrelated account information.
4.3 Retention of prompts and Output. Prompts and Output that are saved in your workspace are Customer Data and are kept and deleted as Section 6.8 of the Terms describes. Providers may keep content only as needed to process a request.
4.4 Access by Kroolo personnel. Kroolo personnel access AI content only as Section 6.6 of the Terms describes. We log AI requests and metadata to detect abuse and security incidents, and we keep prompt content no longer than that purpose needs.
4.5 Sensitive and restricted data. Do not submit restricted data listed in Section 6.4 of the Terms unless we have agreed in writing. Submit personal data of other people only where you have a lawful basis. Take extra care with children’s data, health information and financial account numbers, and check your own legal and contractual limits before using them with AI.
4.6 Location and transfers. Where your hosting region is stated in an Order Form, AI processing follows the region and transfer terms of the DPA and Section 8 of the Privacy Policy.
4.7 Free tools. Content you submit to a free AI tool on our Sites is processed to return your result and handled as our Privacy Policy describes. Do not submit confidential, regulated or sensitive content to them.
5. Permissions and access controls
5.1 Permission-aware AI. Kroolo AI is designed so that it can reveal to a User only information that User could already access in the Services. It should not bypass roles, workspaces, private items or sharing settings.
5.2 Kroolo Search and connected sources. Kroolo Search is designed to respect the access permissions of each connected source, so a User sees results only from content that User can access there. Customers are responsible for the permissions in their source systems. Kroolo is not responsible for exposure that results from those settings.
5.3 Admin controls. Admins may be able to enable or limit AI Features, manage AI Agents and Connectors, and set usage limits, depending on plan.
5.4 Connectors. Connectors request only the scopes the enabled feature needs, and access can be revoked at any time by the User or Admin who granted it. Our use of Google user data follows the limits in Section 6.6 of the Privacy Policy.
5.5 Sharing AI Agents. Sharing an AI Agent shares its instructions and Knowledge Base with the people who can use it. Do not put content in a Knowledge Base that its users should not see. Agents run with the permissions, so grant no more access than the task needs.
6. Customer responsibilities
Security and responsible use are shared. Customers are responsible for how they configure and use Kroolo AI.
6.1 Governance. Customers should name a person responsible for AI use, decide which AI Features are enabled for which teams, keep internal guidelines for staff, and train Users on this policy.
6.2 Reviewing Output. Users must review Output before relying on it or sharing it, at the level Section 9.3 requires.
6.3 Lawful use. Customers must have the rights, notices, consents and lawful bases needed for the data they use with AI, and must tell people about AI use where the law requires.
6.4 Safe configuration. Grant AI Agents and Connectors the least access needed. Test new AI Agents on low-risk work before wider use. Keep Knowledge Bases accurate and current, and remove content that should not be exposed.
6.5 Reporting. Tell us promptly about harmful output, suspected misuse or security concerns (Section 16).
| Area | Kroolo | Customer |
|---|---|---|
| Platform and models | Secures the platform, chooses and contracts with providers, tests features | Decides which features to enable and for whom |
| Data | Does not train on Customer Data; protects it under the Security Policy | Decides what data to submit and has the right to use it |
| Permissions | Builds AI to respect permissions | Sets roles and source permissions correctly |
| Output | Describes limits and provides review guidance | Reviews Output and owns decisions based on it |
| AI Agents | Provides controls and limits | Configures, supervises and reviews agent actions |
| Compliance | Complies with laws that apply to Kroolo as a provider | Complies with laws that apply to its use, including sector rules |
7. Prohibited uses
You will not use Kroolo AI, and will not let anyone else use it, to:
- break the law, commit fraud, or infringe anyone’s rights;
- impersonate a person or organization, or create misleading synthetic media meant to deceive;
- harass or threaten people, or promote hatred, violence or self-harm;
- create sexual content involving minors, or exploit or endanger minors in any way;
- create or improve malware, exploit systems, or carry out security testing without authorization;
- develop, produce or deploy weapons;
- carry out unauthorized surveillance, covert monitoring of individuals, or social scoring;
- identify or categorize people from biometric data, or infer emotions of employees or students;
- manipulate or exploit vulnerable people, or use deceptive techniques to distort their decisions;
- make solely automated decisions with legal or similarly significant effects on individuals (Section 8);
- diagnose or treat medical conditions, or respond to emergencies;
- send spam, phishing or mass unsolicited messages;
- extract system prompts, model weights or training data, probe or bypass safeguards, or get around usage limits;
- use Output to train or improve a model or service that competes with Kroolo;
- present Output as verified professional advice without qualified review; or
- submit restricted data in breach of Section 6.4 of the Terms.
8. High-Impact Uses
8.1 What they are. A “High-Impact Use” is any use in which Output informs or triggers a decision that has legal or similarly significant effects on a person. This includes decisions about: employment, such as hiring, screening, promotion, discipline, termination, pay, and performance or retention analytics; credit, lending, insurance underwriting, pricing or claims; access to essential services or benefits; education admission or assessment; health care; legal advice or proceedings; law enforcement and immigration; critical infrastructure and safety; and significant decisions about minors.
8.2 Rules for High-Impact Uses. If a Customer uses Kroolo AI to support a High-Impact Use, it must:
- ensure that a qualified person makes and owns the decision, using Output as one input among others;
- not rely on Kroolo AI as the sole or main basis for the decision;
- carry out and record an assessment of risks, including bias and accuracy, before use, and test the use case on its own data;
- tell affected individuals about AI use where the law requires, and give them a way to ask for human review or contest the decision;
- keep records that let it explain and audit decisions; and
- comply with the laws and sector rules that apply, such as AI, anti-discrimination, consumer protection, employment and financial-services requirements.
8.3 Kroolo’s position. Kroolo AI is not designed to make automated decisions in these areas. Where a Customer uses Kroolo Search for finance, risk or compliance analysis, the results are meant to support analysts and are not automatic approvals or rejections. We may restrict or require an additional agreement for High-Impact Uses, and may suspend AI Features used in breach of this Section under Section 13.3 of the Terms.
9. Accuracy, limits and human oversight
9.1 Known limits. Kroolo AI can be wrong. It can produce content that is inaccurate, incomplete, out of date, biased, inconsistent between attempts, or invented. It can misread tables, numbers, scanned documents and complex spreadsheets, and it can misinterpret contract language. The same input can produce different Output, and Output may be similar to Output given to others.
9.2 Grounding and sources. Where a feature draws on your content, it shows source references so you can check them. A source reference shows where information came from. It does not prove the summary is correct.
9.3 Review standards. Review Output at a level that matches the risk.
| Level | Examples | Required review |
|---|---|---|
| Low | Brainstorming, internal notes, meeting summaries, first drafts | The User reads it and edits before use. |
| Medium | Emails and messages to others, customer-facing documents, plans, task assignments, translations | The sender checks names, dates, figures and commitments before sending. |
| High | Financial figures, contract or clause interpretation, regulatory or compliance conclusions, legal or HR content, anything given to regulators, auditors or clients | Verify against the source documents, have a second person review, and keep the source references. |
| High-Impact Use | Decisions described in Section 8 | Follow Section 8. |
9.4 Where AI should not be trusted alone. Do not rely on Kroolo AI alone for calculations that matter, legal or regulatory interpretation, medical or safety information, or facts about named people.
10. AI Agents and automation
10.1 Permissions. An AI Agent can act only within the permissions it has been given. It cannot exceed the access of the User or Admin who sets it up, and Customers are responsible for what they permit.
10.2 Accountability. Actions taken by an AI Agent are treated as actions of the Customer. Customers should supervise agents in proportion to the actions they can take.
10.3 Approval for external and sensitive actions. Actions with effects outside the workspace or that are hard to undo, such as sending messages to external people, deleting data, or changing financial or personnel records, should require human approval, or be limited to an Admin-approved list.
10.4 Testing and rollout. Test a new AI Agent on low-risk work, check its results, and widen its use gradually. Re-test after you change its instructions, Knowledge Base or connected tools.
10.5 Logs and stopping. Agent activity is logged so it can be reviewed, and Admins can pause or disable an AI Agent. Kroolo may limit or stop agent actions that it considers unsafe.
10.6 Untrusted content and prompt injection. Documents, web pages, emails and messages that an agent reads may contain instructions meant to redirect it. Do not give agents broad access to untrusted content together with the ability to take sensitive actions.
10.7 Labeling. Content or messages an AI Agent creates or sends should be identifiable as AI-generated where the product supports it, and where the law or good practice requires it.
11. Transparency and disclosure
11.1 In the product. We identify AI Features in the product or documentation, for example as “Uses AI”, and describe their limits.
11.2 Providers. We list our model providers in our sub-processor list and update it as changes are made.
11.3 Disclosure to others. Customers should tell people when they are interacting with an AI system, or when content is AI-generated or materially edited by AI, where the law requires it or where the context would otherwise mislead. This includes customer-facing chatbots, synthetic media and automated messages.
11.4 Documentation. On request and under NDA, we will give Customers with an enterprise agreement documentation on how AI Features work, their intended uses and limits, and the controls available.
12. Fairness, safety and quality
12.1 Our practices. Before release we test AI Features for foreseeable harms, including inaccurate, unsafe or biased output and misuse, and we apply safeguards such as filters and permission checks. We monitor for abuse and fix reported problems.
12.2 Limits of the models. The models behind Kroolo AI are built by others and learn from large sets of data that may contain bias. They may perform worse in some languages, dialects and subject areas. Kroolo AI is not designed to infer sensitive characteristics about individuals, and you must not use it for that purpose.
12.3 Non-discrimination. You must not use Kroolo AI to treat people unfairly or unlawfully because of characteristics such as race, color, ethnicity, religion, sex, gender identity, sexual orientation, age, disability, nationality or other protected status.
12.4 Feedback. Use the feedback controls in the product or the contact in Section 16 to tell us when Output is wrong, unsafe or biased.
13. Intellectual property
13.1 Ownership. As between you and Kroolo, you own your Input and, to the extent the law allows, your Output, as Section 7.2 of the Terms describes. Output may not be unique.
13.2 Third-party rights. Output can resemble existing material. Before you publish or commercialize Output, check that it does not use others’ protected content, and do not submit content you have no right to use.
13.3 Indemnity. Kroolo’s indemnity for infringement claims is as your agreement states. Unless it says otherwise, it does not extend to Output that you generate from your Input.
13.4 Confidential information. Do not enter another party’s confidential information into Kroolo AI unless you are allowed to share it with a service provider like Kroolo.
14. Third-party models and providers
14.1 Providers. Kroolo AI uses models from third-party providers under written terms that prohibit training on Customer Data and limit retention.
14.2 Model choice. Some features let Users or Admins choose between model. Different models can behave differently, so test your use case with the model you choose.
14.3 Changes. We may change, add or retire providers and models. We will keep the commitments in Section 4, update the sub-processor list, and give notice of material changes as the DPA requires. Customers who need to restrict providers or regions can ask us to record that in an Order Form.
14.4 Provider policies. Provider usage policies apply to your use of Kroolo AI, and we will give them to you on request.
15. Governance at Kroolo
15.1 Accountability. Responsibility for AI risk at Kroolo rests with Security Lead. Findings and significant incidents are reported to executive management.
15.2 Risk assessment. We assess risks before launching a new AI Feature, and again when a feature’s purpose, data or model changes materially.
15.3 Testing. Testing before release covers quality, safety, bias and security, including resistance to prompt injection and data leakage.
15.4 Provider due diligence. We review providers’ security, data-handling and training terms before we use them and at least annually.
15.5 Training. Kroolo staff who build or support AI Features receive training on responsible AI, privacy and security.
16. Reporting and enforcement
16.1 How to report. Report harmful, unsafe, biased or incorrect Output, suspected misuse, or an AI-related security concern to security@kroolo.com with a description, the feature involved, and steps to reproduce it. Report security vulnerabilities as the Security Policy describes.
16.2 Our response. We will acknowledge reports within 3 business days, to investigate, and tell you what we decide where we can. We may fix the problem, adjust safeguards, or restrict features.
16.3 Serious AI incidents. If we confirm a defect or misuse in an AI Feature that caused, or is likely to cause, material harm to a Customer, we will notify affected Customers without undue delay. Security incidents are handled as Section 8 of the Security Policy describes.
16.4 Enforcement. If this policy is breached, we may remove content, limit or suspend AI Features or an Account under Sections 13.3 and 13.4 of the Terms, or end the agreement, and we may cooperate with law enforcement and regulators.
17. Legal and regulatory compliance
17.1 Our obligations. We aim to comply with the AI, data protection and other laws that apply to Kroolo as a provider of AI Features.
17.2 Customer obligations. Customers are responsible for the laws that apply to how they deploy Kroolo AI. That includes rules on automated decision-making, transparency, employment, consumer protection and sector regulation, and, where Customers are deployers under laws such as the EU AI Act, the duties that follow. Customers must not use Kroolo AI for uses those laws classify as prohibited, and for High-Impact Uses must follow Section 8.
17.3 Regulated customers. Customers in financial services, insurance and other regulated sectors remain responsible for model risk management, outsourcing notifications, record-keeping and supervisory requirements. Kroolo will reasonably help with information requests under an enterprise agreement, including as Section 14 of the MSA describes.
17.4 Support for compliance. Where a law requires us to give a Customer information it reasonably needs to meet its own obligations about Kroolo AI, we will provide it.
18. Changes to this policy
We may update this policy as our features, providers and the law change. The “Last updated” date shows the current version. We will give at least 30 days’ notice of material changes by email or in the Service, and we will keep the commitments in Section 4 while a Customer’s Subscription Term continues.
19. Contact
- Privacy: privacy@kroolo.com
- Security: security@kroolo.com