Kolio legal

Privacy Policy

Last updated: 2026-08-10

This is a plain-language policy provided by an independent operator and has not yet been reviewed by counsel. It describes what actually happens today rather than every legal formality. Questions: [email protected].

Kolio’s policies are published in English. If a translated summary is ever provided, the English version governs.

1. Who is responsible

Kolio is operated by an independent developer; there is no registered legal entity yet. For anything privacy-related — access, correction, deletion, export, or complaints — email [email protected].

2. What we collect from account holders

  • Your account email address (used for sign-in and service email), the identity provider you choose, its account identifier, and basic profile details it makes available, such as a display name or profile image.
  • If you set a password, Supabase stores the protected password verifier needed to authenticate you. Kolio’s application servers do not receive or store your plain-text password.
  • Profile details you choose to add — creator directory profiles, media-kit contents, and offer details you publish.
  • Content you create or upload: scripts, prompts, media, rendered videos, and scheduled posts.
  • Usage events — telemetry about which features run (for example a render finishing or a post publishing), used to operate the product, meter credits, and improve reliability.
  • Billing status from Stripe (plan, credit balance, payment events). Card numbers are handled by Stripe and never touch Kolio’s servers.

3. Click and scan analytics

When someone opens a tracked link or scans a QR code, we record the event type and timestamp, the referring page, the browser’s user-agent string, a bot-likeness flag, and a one-way hashed form of the network address used for rate-limiting and bot filtering. The raw IP address is not stored with the event. These counts power the campaign reports creators share.

4. Data your audience submits through creator pages

Creators use Kolio to host capture pages, surveys and polls, and a directory with intro requests. Through those pages, people who are not Kolio users submit data: lead names and email addresses, survey and poll responses, and intro-request contact details.

  • Kolio processes this data on the creator’s behalf, to deliver it to that creator. The creator decides why it is collected and how it is used.
  • Kolio never sells this data — the promise printed on every capture page — and does not use it for advertising or to build profiles across creators.
  • It is retained until the creator deletes it or the creator’s account closes.
  • If you submitted data through a creator’s page and want it removed, contact that creator, or email [email protected] and we will handle it with them.

5. Connected social, marketplace, and advertising data

If you connect social accounts or use creator-campaign and paid-ad tools, Kolio processes the records needed to provide those functions and keep an auditable history. Depending on what you use, these records can include:

  • Connected-account and provider identifiers, published-post identifiers and URLs, direct-message conversations and message content, attachments and lifecycle status, comments, reviews, reviewer, participant or author identifiers supplied by the platform, provider payloads, auto-reply decisions, and account and post metrics.
  • Campaign briefs, invitations, offers, fees, deadlines, deliverables, disclosure requirements, acceptance and cancellation history, proof links, reports, disputes, counterparty details, and payment-workflow status.
  • Ad-account identifiers, creative and destination details, targeting choices and audience notes, beneficiary and payor information, budgets, schedules, provider status, and spend or performance results returned by the ad platform.

When you open the Social Operations Inbox, Kolio requests the selected connected account's conversations from PostProxy and displays them to you. Kolio does not copy direct-message bodies or attachments into its own database. It records content-free operational events for actions such as sending, marking read, or archiving. PostProxy and the social platform may retain the conversation under their own terms and retention rules.

When you choose Sponsor Scout or another enabled public-source research action, Kolio sends the bounded public handles, URLs, topics, and research purpose you provide to SocialCrawl or Social Fetch. We store the query, provider and source route, freshness, cache and fallback status, and the public profile, post, or engagement evidence returned. Encrypted raw provider responses are retained for up to 14 days; normalized evidence and reusable public-data cache entries are retained for up to 90 days unless they expire or are removed sooner. Deleting a saved request immediately removes its user-linked normalized evidence and erases its encrypted raw payload content. A content-free audit row and credit ledger may remain, and a shared public-data cache entry may remain until its own 90-day expiry.

We use these records to perform the action you request, prevent duplicate provider actions, reconcile status, measure results, resolve disputes, and create evidence for the people involved. They are retained while the connected account, campaign, ad, or related account remains active and afterward for as long as reasonably needed for security, accounting, dispute, and legal obligations. Disconnecting an account stops new routine collection but does not erase existing campaign, publication, payment, or audit records.

6. How we use data

To provide and operate the service, meter credit usage, prevent abuse (rate-limiting and bot filtering), fix bugs, and send service email such as sign-in links, confirmation and password-reset instructions, security notices, and billing notices. Kolio does not sell personal data and does not run third-party advertising or cross-site tracking.

7. AI likeness and voice cloning

Some Kolio features can reproduce a person’s appearance or voice. You are responsible for having the rights to the photos and audio you submit, and these are prohibited uses: creating a likeness or voice of a real person without their consent, of a minor, or any sexual, harassing, defamatory, or impersonating content. Accounts that break these rules can be suspended and their trained models and voices deleted. We run automated safety checks on AI generation — a content filter on generated images and a prohibited-content blocklist on video-generation prompts — and block flagged requests, but we do not pre-screen every upload, so the responsibility to have consent is yours.

  • Brand Characters (AI likeness). When you train on photos of a real, identifiable person you must tick a box affirming you have that person’s consent; that self-declaration is stored with the character. Your original training photos are stored temporarily by Kolio and sent to the AI provider to build a private model. They are scheduled for automated cleanup within 24 hours of upload and are removed when the storage-cleanup job next runs. The derived training archive Kolio builds is deleted when the provider request finishes. We then keep only a reference to the trained model, usable only by your account.
  • Voice cloning. Cloning requires you to affirm the sample is your own voice or that you have the speaker’s permission; that affirmation is recorded. The audio sample is sent to the voice provider to create a private voice and then deleted from Kolio’s storage right after; only your account can synthesize with the clone.
  • To delete a trained character or cloned voice, email [email protected] — we delete our stored reference so it can no longer be used in Kolio, and we ask the provider that hosts the trained model or voice to delete their copy. (Original Brand Character photos are scheduled for automated cleanup within 24 hours of upload; voice samples are deleted from Kolio’s storage after processing.)

8. Processors we rely on

Data is processed by the third-party services that run Kolio: Supabase (authentication and database), and, only when an option is enabled and you choose it, a supported identity provider such as Google or Apple (additional providers may be added later); Stripe (payments), OpenAI and Anthropic (text generation), ElevenLabs and MiniMax (voice synthesis and voice cloning), fal.ai and Runware (video, image, audio generation, and media enhancement), PostProxy (social connections, publishing, and supported engagement operations), SocialCrawl and Social Fetch (opt-in public-source research), Cloudflare R2 (media storage), and AWS (video rendering and delivery). Content you generate is sent to the AI providers needed for the feature you use; audience-submitted data stays in the database and is not sent to AI providers.

9. Cookies and local storage

Kolio’s own pages set no advertising or analytics cookies. Kolio sign-in sessions and preferences (such as display language) are kept in your browser’s local storage rather than advertising cookies. Third-party pages you are handed off to — for example an enabled third-party sign-in provider, Stripe checkout, and the billing portal — may set their own necessary cookies under their own policies.

10. Retention, deletion, and export

Account data is kept while your account is active. Signed-in members can export their account data and request permanent account deletion through Account data controls on the Member page. To request correction or deletion of specific data, or if the self-service controls are unavailable, email [email protected] from your account email. Deletion is subject to an in-product preflight for unresolved billing, publishing, campaign, or refund obligations. Eligible deletion requests are honored within 30 days, except records we must retain for security, accounting, disputes, or law (such as payment records held by Stripe).

11. International transfers

The processors above run in multiple regions, primarily the United States, so your data may be stored and processed outside the country you live in. Where a processor offers contractual safeguards for international transfers (such as standard contractual clauses), we rely on those safeguards.

12. Your rights and changes to this policy

Depending on where you live, applicable privacy and data protection laws may give you rights to access, correct, delete, or export your personal data, and to complain to a local regulator. Nothing in this policy takes away rights that cannot be waived under the laws that apply to you. Exercise any of them via [email protected]. When this policy changes materially, we will update the “Last updated” date and notify account holders by email where the change affects them. See also the Terms of Service and Refund Policy.