Privacy Policy
Last updated: 01 September 2026
Your privacy matters to us. This policy explains how Kroolo collects, uses, shares and protects personal information when you visit our websites, use Kroolo Work, Kroolo Search, Kroolo AI and our apps, or otherwise deal with us. If you do not agree with this policy, please do not use our Sites or Services.
1. Who we are and what this policy covers
1.1 Who is responsible. Kroolo Labs, Inc. and its affiliates (“Kroolo”, “we”, “us” and “our”) are responsible for your personal information as a controller for the purposes in this policy. Our affiliates may provide, support or bill the Services for us.
1.2 Our two roles. We act as a controller for information about visitors to our Sites, people who register for Accounts, billing contacts, people who contact support or sales, subscribers to our communications, and business contacts we reach out to. We act as a processor or service provider for Customer Data, which is the content that Customers and their Users put into the Services, such as tasks, documents, chats, files and content from connected sources. For Customer Data, the Customer decides why and how it is used, and our Data Processing Addendum governs our handling. This policy does not describe that processing. If your information is in a workspace run by your employer or another organization, contact that organization about it.
1.3 Related documents. The Terms of Service, the Cookie Policy, our Security page, the DPA and our sub-processor also apply. Capitalized terms not defined here have the meaning given in the Terms.
1.4 Meaning of personal information. “Personal information”, also called personal data, means information about an identified or identifiable individual.
2. Privacy at a glance
- We collect information you give us, information from your use of the Services, and information from other sources such as your organization’s administrators, connected apps and partners.
- We use it to provide, secure and improve the Services, to bill and support you, and, where the law requires your consent, to market to you.
- We do not sell personal information.
- We do not use Customer Data, prompts or AI output to train AI models (Section 5).
- We share information with service providers, partners, affiliates, other users in your workspace, and authorities where required (Section 6).
- We keep information only as long as we need it (Section 10).
- Depending on where you live, you may have rights to access, correct, delete and more (Sections 11 and 12). Write to privacy@kroolo.com.
3. Information we collect
3.1 Information you provide.
- Account and profile: name, email address, credentials, profile photo, job title, company, language and preferences. If you sign in with Google, Microsoft, Apple or Slack, we receive your name, email address and identifier, as your settings on that service permit.
- Billing: billing contact, address, tax identifiers and purchase history. Card details go directly to our payment processor.
- Content you submit to the Services (Customer Data): tasks, documents, comments, chat messages, files, forms and prompts. We handle this as a processor (Section 1.2).
- Communications and support: emails, form entries, support tickets, attachments, and notes from demos and calls.
- Site activity you initiate: newsletter sign-ups, event registrations, surveys, comments and reviews.
3.2 Information we collect automatically.
- Use of the Services: features used, actions taken, timestamps, identifiers, file types and sizes, search terms, and use of AI Features.
- Device and connection: IP address, device type, operating system, browser, language, device identifiers, and crash and diagnostic data. We use your IP address to estimate your approximate location.
- Cookies and similar technologies: see Section 7.
- Email interactions: whether an email was opened and which links were clicked.
3.3 Information from other sources.
- Other users and administrators: for example, an invitation that includes your email address, an @mention, or contact details an administrator gives us when naming you as an Admin.
- Connected services: when you or your Admin enables a Connector or integration (such as Google Workspace, Microsoft, Slack, calendars or cloud storage), we receive information according to the scope granted and that service’s own settings.
- Partners: resellers, distributors and referral partners may give us billing and contact details, the plan purchased and your region.
- Business contacts and prospects: we may collect business contact details, such as name, work email, job title and employer, from public professional profiles and directories, events, referrals and business partners, to contact people about Kroolo for business purposes. You can object at any time (Section 11).
- Service providers and public sources: for example, analytics, fraud prevention and security information.
3.4 Sensitive information. We do not intentionally collect sensitive personal information, such as health data, government identifiers or financial account numbers. Please do not submit it through the Sites or free tools. Customers should follow Section 6.4 of the Terms before putting such data in the Services.
3.5 If you do not provide information. You do not have to give us information, but some is needed to create an Account, provide the Services or answer your request.
4. How we use information
4.1 Purposes and legal bases. The table shows what we use personal information for as a controller and, for people in the EEA, the UK and Switzerland, the legal basis.
| Purpose | Examples | Legal basis (GDPR and UK GDPR) |
|---|---|---|
| Provide the Sites and Services | Create and manage Accounts, authenticate you, operate features, process payments, provide support. | Contract (Art. 6(1)(b)) |
| Keep the Services safe and secure | Detect fraud and abuse, verify accounts, prevent security incidents, enforce our Terms. | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where required |
| Improve and develop the Services | Analyze Usage Data, fix bugs, test features, understand what people find useful. | Legitimate interests (Art. 6(1)(f)); consent for non-essential cookies (Art. 6(1)(a)) |
| Communicate with you | Transactional emails, security alerts, billing notices, service changes, responses to your questions. | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Marketing and promotion | Newsletters, product news, event invitations, outreach to business contacts. | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests (Art. 6(1)(f)) for business-to-business contact |
| AI Features | Process your prompts and related content to return the result you asked for. | Contract (Art. 6(1)(b)) |
| Comply with law and protect rights | Respond to lawful requests, keep records, establish or defend legal claims. | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Publicity you agree to | Customer stories and testimonials. | Consent (Art. 6(1)(a)) |
| Business transactions | Due diligence, merger, financing or sale of our business. | Legitimate interests (Art. 6(1)(f)) |
4.2 Marketing and communications. We send messages needed to run the Services, such as security alerts, billing notices and service changes. You cannot opt out of these while your Account is active. We send marketing emails and text messages only where you have opted in or the law otherwise allows, and every marketing email has an unsubscribe link. We do not share your information with other companies for their own marketing.
4.3 De-identified and aggregated information. We may de-identify or aggregate information so it no longer identifies you, and use it to operate, improve and promote the Services. We do not try to re-identify it. It never includes the content of Customer Data.
5. AI features
5.1 What they are. AI Features include Kroolo AI, AI Agents, Kroolo Search and the writing and document tools on our Sites, such as the Grammar Checker, Paraphraser, Summarizer, Translator and Chat with PDF.
5.2 What is sent to models. When you use an AI Feature, your prompt and the context needed to answer it, such as a document you selected or the search results relevant to your question, are sent to the model provider that powers the feature. These providers act as our subprocessors under written terms and are listed in Appendix A. We send only what the feature needs, and we do not send unrelated account information.
5.3 No training on your data. We do not use Customer Data, prompts or AI output to train or fine-tune AI models, and we require our model providers not to do so. A Customer may opt in in writing to a specific program that uses its data for improvement or evaluation.
5.4 Kroolo Search and connected sources. Kroolo Search builds an index of content from the sources a Customer connects, so it can return results. It is designed to respect the access permissions of each source, so a User sees only content that User can already access there. Access is limited to what the connecting User or Admin authorized. Section 6.6 describes extra limits for Google data.
5.5 Outputs and automated decisions. AI output is generated automatically and can be wrong, so please check it before relying on it. We do not make decisions that have legal or similarly significant effects on individuals based solely on automated processing. Customers who set up AI Agents or automations are responsible for how they are configured and supervised.
5.6 Free tools on our Sites. Content you submit to a free tool is processed to return your result and handled as Section 10 describes. Please do not submit confidential or personal information to them.
5.7 Your choices. Admins may be able to limit or turn off certain AI Features in workspace settings.
6. How we disclose information
6.1 We do not sell personal information. We do not share it with others for their own marketing.
6.2 Service providers. We use providers for hosting, authentication, payments, customer support, email, analytics and AI model services. They may access personal information only to perform services for us, under written terms that require confidentiality and security and limit their use of the data. Appendix A lists current providers by category.
6.3 Partners. Resellers, distributors and referral partners who sell or support Kroolo receive the contact, order and support information they need for that purpose. If you buy through a partner, we share the account and usage information needed for billing and support entitlement.
6.4 Other users and administrators. If you register with an email address on a domain your employer or organization owns, its administrators may see your name, profile, content and activity, and may manage, claim, transfer or delete your Account. People in a workspace can see what you share with them.
6.5 Services you connect. When you or your Admin connects a third-party service, information moves between us and that service according to the scope granted. Its own privacy policy governs what it does with the information, and you should check its settings.
6.6 Google user data. Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google data only to provide or improve the features you use. We do not transfer it to others except as needed to provide those features, to comply with law, or in a merger, acquisition or sale of assets. We never use it to serve advertising, including retargeting or interest-based ads. We do not allow people to read it unless you give explicit permission for specific items, it is needed to investigate a security issue, the law requires it, or it has been aggregated and anonymized for internal operations. We do not use Google user data to train generalized AI or machine-learning models.
6.7 Legal and safety. We may disclose information where we believe it is reasonably necessary to comply with law, legal process or an enforceable government request, to enforce our Terms, to protect the security of the Services, to protect the rights, property or safety of Kroolo, our customers or the public, or to respond to an emergency involving danger to a person. Where lawful, we will tell the affected Customer first.
6.8 Affiliates and business transfers. We share information with Kroolo affiliates to operate the Services. If Kroolo is involved in a merger, acquisition, financing, reorganization or sale of assets, information may be transferred as part of it, and we will tell you if the transfer would change how your information is handled.
6.9 With your consent. We share information for other purposes when you ask us to or agree, for example to publish a testimonial.
6.10 Public areas. Anything you post in public areas of our Sites, such as blog comments or forums, can be read, collected and used by anyone. Please take care what you share.
7. Cookies and similar technologies
We and our partners use cookies, pixels, device identifiers and similar technologies to keep you signed in, remember preferences, understand how our Sites and Services are used, and measure our marketing. Our Cookie Policy lists the cookies we use and how to manage them. You can change your choices through our cookie settings and your browser. Blocking some cookies may stop parts of the Services from working.
We honor the Global Privacy Control signal where the law requires. There is no common standard for “Do Not Track” browser signals, so we do not respond to them. Our emails may contain pixels that show whether a message was opened; you can prevent this by turning off images in your email client.
8. International transfers
We operate globally. Kroolo and our providers work in many countries, and we host the Services on Amazon Web Services. Your information may therefore be processed outside the country where you live, including in countries whose data protection laws differ from yours.
When we transfer personal information across borders, we use the safeguards each law requires. For transfers from the EEA and Switzerland, these are the European Commission’s standard contractual clauses or an adequacy decision. For transfers from the UK, we use the UK International Data Transfer Agreement or the UK Addendum to those clauses. For transfers from Singapore, we put in place legally enforceable obligations that give the information a standard of protection comparable to the PDPA. For transfers from the DIFC and the UAE, we use the mechanisms permitted under those laws. You can ask us for a copy of the safeguards that apply to you by writing to privacy@kroolo.com.
9. Security
We use administrative, technical and physical safeguards designed to protect personal information, including encryption of data in transit and at rest access controls limited to staff who need access, confidentiality obligations for staff, and security review of our providers. Our Security page gives more detail. No system is completely secure, so we cannot guarantee that information will never be accessed without permission. Please protect your credentials and use single sign-on and multi-factor authentication where offered. If a breach affects your personal information, we will notify you and regulators as the law requires.
10. How long we keep information
| Information | How long we keep it | Notes |
|---|---|---|
| Account and profile information | While your Account is active, then up to 90 days after closure. | Longer only where the law requires or a dispute is open. |
| Customer Data | Available to export read-only for at least 30 days after the Subscription Term ends, then deleted from active systems within 90 days. | Matches Terms 6.8. Backups are overwritten on our normal cycle. |
| Billing and transaction records | As tax and accounting law requires, usually 5 to 7 years. | Kept even after an Account closes. |
| Support tickets and communications | 24 months after the ticket closes. | |
| Marketing preferences | Until you unsubscribe, then a minimal suppression record so we do not contact you again. | |
| Prospect and business contact data | Until you object, or 24 months after our last interaction. | |
| Security and access logs | 12 months. | |
| Cookie and analytics data | As stated in the Cookie Policy. | |
| Content submitted to free AI tools | Deleted after the result is returned / within 30 days. |
When a retention period ends, we delete or de-identify the information. If that is not possible, for example because it sits in a backup, we store it securely and keep it away from any further use until we can delete it.
11. Your rights and choices
11.1 What you can do yourself. You can view and update profile details in your Account settings, close your Account, opt out of marketing using the unsubscribe link or your preferences, change cookie settings, export Customer Data using in-product tools, and disconnect a Connector or revoke Kroolo’s access in the settings of the connected service, such as your Google Account.
11.2 Your rights. Depending on where you live, you may have the right to: be informed about how we use your information; access it and get a copy; correct it; delete it; restrict or object to its use, including for direct marketing; move it to another provider; withdraw consent at any time; not be subject to solely automated decisions with significant effects; not be discriminated against for exercising your rights; appeal our decision on a request; and complain to a regulator. Sections 11.4 and 12 give details.
11.3 How to make a request. Email privacy@kroolo.com. We may ask for information to confirm it is you. If your information is Customer Data in a workspace run by an organization, we will refer you to that organization and help it respond where required. We respond within 30 days, or the shorter or longer period applicable law sets, and we will tell you if we need more time. There is no charge unless a request is manifestly excessive. We may decline a request where the law allows, for example if it would reveal someone else’s information, if we must keep the information by law, or if it is not technically possible. You may use an authorized agent if you give them written permission. If we decline your request, you can appeal by replying to our response within 60 days, and we will answer within 45 days.
11.4 Complaints. Please contact us first so we can try to resolve your concern. You may also complain to a regulator: in the EEA, your local data protection authority; in the UK, the Information Commissioner’s Office; in Singapore, the Personal Data Protection Commission; in the DIFC, the Commissioner of Data Protection; in India, the Data Protection Board of India, after you have used our grievance process; and in the United States, your state attorney general.
12. Regional disclosures
12.1 European Economic Area, United Kingdom and Switzerland. The controller is Kroolo, as Section 1.1 describes. Section 4.1 sets out our legal bases. You have the rights in Section 11.2 under the GDPR and UK GDPR, and where we rely on legitimate interests you may object. Transfers are covered in Section 8.
12.2 Singapore. We collect, use and disclose personal data in line with the Personal Data Protection Act 2012 (PDPA), with your consent or as the PDPA otherwise permits. You may withdraw consent, and we will explain the consequences of doing so.
12.3 United Arab Emirates and DIFC. Where the DIFC Data Protection Law (Law No. 5 of 2020) or the UAE Federal Decree-Law No. 45 of 2021 on personal data protection applies, you have the rights in Section 11.2, including the right to object to solely automated decisions.
12.4 India. Where India’s Digital Personal Data Protection Act, 2023 applies, we process personal data with your consent or for other lawful purposes the Act allows. You may withdraw consent, and you may access, correct and erase your personal data, use our grievance process, and nominate another person to exercise your rights if you die or cannot act.
12.5 United States. This section supplements the policy for residents of states with privacy laws, including California. The table describes what we collected in the past 12 months and why.
We do not sell personal information. We do not knowingly sell or share the personal information of anyone under 16. We use sensitive personal information only for purposes the law permits. You have the rights in Section 11.2, including the right to opt out of sale, sharing and targeted advertising, and we honor the Global Privacy Control signal where required. Section 11.3 explains how to make a request, use an authorized agent, or appeal.
13. Children
Our Sites and Services are not intended for anyone under 16. If we learn we have collected personal information from a child under 16 without the required parental consent, we will delete it. A school or other organization may allow minors to use the Services under its own responsibility and after obtaining any consents the law requires. In that case the school or organization is responsible for those Users, as the Terms describe. Parents and guardians can contact us at privacy@kroolo.com.
14. Third-party sites and services
Our Sites and Services may link to websites and services we do not control, and they may include social media buttons. We are not responsible for their privacy practices, and their policies govern the information they collect. We encourage you to read them before you share personal information.
15. Changes to this policy
We may update this policy. The “Last updated” date above shows the current version. We will give at least 30 days’ notice of material changes by email or in the Service before they take effect, and we will ask for your consent again where the law requires it. Prior versions are available on request. If you do not agree with a change, you can close your Account before it takes effect.
16. Contact us
- Privacy questions and requests: privacy@kroolo.com
- General support: help@kroolo.com and kroolo.com/contact-support