MarginKoala
Privacy
This operational draft explains the practical data flows currently implemented in MarginKoala.
What we collect
We collect the information needed to run your account and the features you choose to use. That can include your name, email address, sign-in identity, saved business profile, calculation history, team invitations, saved conversations and decisions, connected business data, and the content you submit to Koala-powered tools.
We also keep operational records such as subscription status, feature-usage counters, page-view activity, provider and model usage, estimated or reported service costs, timestamps and security/session data. The more detailed records are described below.
Sign-in and account providers
If you choose Google or Microsoft sign-in, the provider sends MarginKoala the account information needed to identify and sign you in. Email/password accounts are handled through the same account system.
Payments
MarginKoala billing uses Stripe for card and supported-wallet checkout, subscription management and refunds. MarginKoala stores Stripe customer, checkout, subscription and payment references, plan and subscription status, billing-event details and amounts so it can verify and manage paid access. Full card details stay with Stripe.
PayPal is not used to bill a MarginKoala subscription. If enabled, PayPal is an optional read-only business-data connector for payment, fee, refund and settlement evidence.
Koala and drafting tools
When a Koala-powered feature calls an AI model, MarginKoala sends the request and the context selected by the server as relevant to that request. This can include conversation messages, saved business facts, recent verified calculations, connected-data facts and processed attachment text or images. Connector credentials are not added to AI context.
Requests normally pass through Vercel AI Gateway, which can route them to the configured model provider. If the configured fallback is enabled, the same request can be sent directly to OpenAI when the gateway route fails. Gateway requests ask for zero data retention and disallow prompt training; direct OpenAI requests set storage to false. Those technical request settings operate alongside the applicable provider terms.
Separate AI telemetry records the task, provider and requested/resolved model, attempts, outcome, fallback, token counts, latency and reported or estimated cost. This telemetry does not store the raw prompt, answer, attachment or connector credential.
Live research
When Koala identifies that a question needs current external evidence, the server maps it to no more than two topics from a closed vocabulary of public subjects, such as an official tax rate or a provider's published pricing. It can append the business country or jurisdiction already held by MarginKoala. Only that reduced public-information query is sent to Tavily and, if needed and configured, Perplexity as a fallback. The original question, business figures, names, identifiers and attachments do not cross this search boundary. If the question does not map to an allowed public topic, no external research request is made.
Returned excerpts and source details are treated as untrusted evidence, passed to the model for that answer and can be saved with the conversation as source citations.
Research telemetry records the provider, search outcome, billable units, latency, cost and source/warning counts. It does not include the search query or returned evidence text. Live research runs only when the relevant provider credentials and feature controls are enabled.
Attachments
Koala attachments are signature-checked and stored with their filename, type, size, content hash, raw file bytes, extraction status and any candidate facts extracted from the document. Candidate facts remain user-document evidence that needs review; they do not silently overwrite stronger verified data.
Each stored attachment has a 30-day expiry. The retention job deletes the raw file record and its extracted candidate facts after that deadline. Deleting the file, its conversation or the account removes the associated attachment record earlier.
Connected services
If you choose a connection, MarginKoala can exchange authorisation and read business data through Rutter or Nango. Connector availability also depends on the relevant external provider account and approval.
Initial connectors are read-only. MarginKoala stores normalised source records, derived metrics and provenance so Koala can distinguish connected evidence from user-entered or model-generated information. It does not use a connector to move money, issue refunds, alter banking data or change a source system.
Connector secrets are encrypted at rest with AES-256-GCM and bound to the account or organisation and connector. Connection records hold a credential reference rather than plaintext secret material, and credential creation, access, rotation and revocation are audited. Only the required normalised business facts, not connector secrets or raw OAuth tokens, may be included in AI context.
Transactional messages such as password resets, team invitations and user-triggered follow-ups are delivered through our email provider. We keep anti-abuse counters so a compromised or abusive account cannot send unlimited mail through MarginKoala.
Cookies, page activity and optional marketing analytics
MarginKoala uses necessary session cookies and similar storage to keep you signed in, secure account access and remember the state of the product. Paid access is checked against server-side subscription records rather than relying on a long-lived browser flag.
First-party page-view records contain the page path without its query or fragment, a cleaned referrer host and campaign source when available, a one-way keyed hash derived from the network address, and the account ID when signed in. Admin and API paths are excluded from that page-view collection.
If the owner configures Google Analytics 4 or Meta Pixel, those third-party scripts load in the browser and receive page views and product-funnel events. Funnel fields can include the calculator or feature name, upgrade source, signed-in/subscribed state, and a confirmed purchase's value, currency, plan, interval and seat count. MarginKoala does not put calculator inputs or results, chat messages, attachments or connected-business records in those funnel events. Loading those scripts also lets Google or Meta receive the browser request under their own terms.
Operational logs and error monitoring
Structured operational logs can contain the route, stage, provider or connector, outcome, timing, request correlation ID, and keyed hashes of an account or organisation identifier. Sensitive-looking fields and values are redacted before structured logging.
If an error-monitoring webhook is configured, MarginKoala sends a limited error event to that destination. The event can include route, error class/code, correlation ID, stage, provider or source, outcome and opaque account/organisation hashes. It excludes raw prompts, request bodies, documents, OAuth tokens and unnecessary financial payloads.
Retention and deletion
MarginKoala applies different periods according to the purpose of the record. This is the current implemented schedule; a period described as "account life" means there is no shorter automatic time-based purge in the application today.
- Raw Koala attachments, extracted candidate facts and temporary workspace context: deleted after 30 days, or earlier through the supported file, conversation or account deletion path.
- Organisation membership audit events: deleted after 730 days by the authenticated retention job.
- Authentication sessions: valid for no more than seven days and revocable earlier; password reset and account closure revoke the applicable sessions.
- Team invitation access: expires after 14 days. Report-share access is selected between one and 30 days, with seven days as the default, and can be revoked sooner. The related audit record can remain for the account life.
- Profiles, calculations, favourites, conversations, decisions, tasks, reports, connected facts and support records: retained for the account or organisation life and removed by the applicable supported deletion or closure workflow.
- Insight engine task ledger: one row for each check the board has raised in a workspace, holding what it was worth, what you decided about it, when, and any reason you typed. Retained for the workspace life, included in the customer data export, and removed with the workspace by the supported deletion or closure workflow. Your typed reason is on the same footing as the rest of the row and is never sent outside your workspace.
- Insight engine cycle history: the engine evaluates your business on a schedule, and each cycle records which checks found something, whether it reached your plan and what you decided about it. It holds no written sentence about any customer, supplier or staff member — only the figure and the date the sentence is rebuilt from. Retained for the workspace life, included in the customer data export, and removed with the workspace by the supported deletion or closure workflow.
- Billing lifecycle and cash records needed for reconciliation can be de-identified on account deletion. Pseudonymous closure records can remain to prevent late provider events recreating access; there is currently no shorter automatic application expiry for those records.
- Privacy-safe operational and aggregate telemetry: retained until operator or provider deletion under the configured monitoring service; the application does not currently impose a shorter universal expiry.
- Recovery copies: deleted data can remain until the applicable managed-backup or encrypted off-site artifact expires. The production recovery runbook uses seven daily managed recovery points and, when the off-site job is enabled, seven-day encrypted artifact retention.
Before account deletion can complete, a Business organisation owned by that account must be transferred or closed, and connector credentials must be revoked. The deletion workflow then removes the account's authentication records, profile, calculations, conversations and attachments, Business Brain and decision/model data, connections and connected facts, subscription-access copy, user-linked email/AI usage records and team-seat links.
Provider-side records are governed by the relevant provider's deletion process. Aggregate or attempt-level operational telemetry without a direct account identifier may not be removed automatically with the account. The owner and legal counsel must decide which payment, security, consent and provider records require a separate retention or deletion process before this draft becomes the final policy.
Third-party services
MarginKoala relies on infrastructure and service providers including hosting/database infrastructure, Google and Microsoft for optional sign-in, Stripe for billing, an email delivery provider, Vercel AI Gateway and configured model providers, Tavily or Perplexity for live research, optional connector transports and source systems, an optional error-monitoring destination, and optional Google Analytics 4 or Meta Pixel. Their own terms apply when they process data for the service you choose to use.
Your choices and rights
You can choose not to connect a social sign-in provider, avoid submitting optional business data, cancel a subscription, or ask about access/correction/deletion rights available under applicable privacy law.