MarginKoala

Privacy

This operational draft explains the practical data flows currently implemented in MarginKoala.

What we collect

We collect the information needed to run your account and the features you choose to use. That can include your name, email address, sign-in identity, saved business profile, calculation history, team invitations, saved conversations and decisions, connected business data, and the content you submit to Koala-powered tools.

We also keep operational records such as subscription status, feature-usage counters, page-view activity, provider and model usage, estimated or reported service costs, timestamps and security/session data. The more detailed records are described below.

Sign-in and account providers

If you choose Google or Microsoft sign-in, the provider sends MarginKoala the account information needed to identify and sign you in. Email/password accounts are handled through the same account system.

Payments

MarginKoala billing uses Stripe for card and supported-wallet checkout, subscription management and refunds. MarginKoala stores Stripe customer, checkout, subscription and payment references, plan and subscription status, billing-event details and amounts so it can verify and manage paid access. Full card details stay with Stripe.

PayPal is not used to bill a MarginKoala subscription. If enabled, PayPal is an optional read-only business-data connector for payment, fee, refund and settlement evidence.

Koala and drafting tools

When a Koala-powered feature calls an AI model, MarginKoala sends the request and the context selected by the server as relevant to that request. This can include conversation messages, saved business facts, recent verified calculations, connected-data facts and processed attachment text or images. Connector credentials are not added to AI context.

Requests normally pass through Vercel AI Gateway, which can route them to the configured model provider. If the configured fallback is enabled, the same request can be sent directly to OpenAI when the gateway route fails. Gateway requests ask for zero data retention and disallow prompt training; direct OpenAI requests set storage to false. Those technical request settings operate alongside the applicable provider terms.

Separate AI telemetry records the task, provider and requested/resolved model, attempts, outcome, fallback, token counts, latency and reported or estimated cost. This telemetry does not store the raw prompt, answer, attachment or connector credential.

Live research

When Koala identifies that a question needs current external evidence, the latest user question can be sent as a search query to Tavily and, if needed and configured, to Perplexity as a fallback. Returned excerpts and source details are treated as untrusted evidence, passed to the model for that answer and can be saved with the conversation as source citations.

Research telemetry records the provider, search outcome, billable units, latency, cost and source/warning counts. It does not include the search query or returned evidence text. Live research runs only when the relevant provider credentials and feature controls are enabled.

Attachments

Koala attachments are signature-checked and stored with their filename, type, size, content hash, raw file bytes, extraction status and any candidate facts extracted from the document. Candidate facts remain user-document evidence that needs review; they do not silently overwrite stronger verified data.

Each stored attachment has a 30-day expiry. The retention job deletes the raw file record and its extracted candidate facts after that deadline. Deleting the file, its conversation or the account removes the associated attachment record earlier.

Connected services

If you choose a connection, MarginKoala can exchange authorisation and read business data through Rutter or Nango, or through Basiq for the Australian CDR/Open Banking connection. CDR/Open Banking is available only when the production provider, consent scope and institutions are activated. Connector availability also depends on the relevant external provider account and approval.

Initial connectors are read-only. MarginKoala stores normalised source records, derived metrics and provenance so Koala can distinguish connected evidence from user-entered or model-generated information. It does not use a connector to move money, issue refunds, alter banking data or change a source system.

Connector secrets are encrypted at rest with AES-256-GCM and bound to the account or organisation and connector. Connection records hold a credential reference rather than plaintext secret material, and credential creation, access, rotation and revocation are audited. Only the required normalised business facts, not connector secrets or raw OAuth tokens, may be included in AI context.

Email

Transactional messages such as password resets, team invitations and user-triggered follow-ups are delivered through our email provider. We keep anti-abuse counters so a compromised or abusive account cannot send unlimited mail through MarginKoala.

Cookies, page activity and optional marketing analytics

MarginKoala uses necessary session cookies and similar storage to keep you signed in, secure account access and remember the state of the product. Paid access is checked against server-side subscription records rather than relying on a long-lived browser flag.

First-party page-view records contain the page path without its query or fragment, a cleaned referrer host and campaign source when available, a one-way keyed hash derived from the network address, and the account ID when signed in. Admin and API paths are excluded from that page-view collection.

If the owner configures Google Analytics 4 or Meta Pixel, those third-party scripts load in the browser and receive page views and product-funnel events. Funnel fields can include the calculator or feature name, upgrade source, signed-in/subscribed state, and a confirmed purchase's value, currency, plan, interval and seat count. MarginKoala does not put calculator inputs or results, chat messages, attachments or connected-business records in those funnel events. Loading those scripts also lets Google or Meta receive the browser request under their own terms.

Operational logs and error monitoring

Structured operational logs can contain the route, stage, provider or connector, outcome, timing, request correlation ID, and keyed hashes of an account or organisation identifier. Sensitive-looking fields and values are redacted before structured logging.

If an error-monitoring webhook is configured, MarginKoala sends a limited error event to that destination. The event can include route, error class/code, correlation ID, stage, provider or source, outcome and opaque account/organisation hashes. It excludes raw prompts, request bodies, documents, OAuth tokens and unnecessary financial payloads.

Retention and deletion

Apart from the 30-day attachment period described above, the current product does not apply one universal retention period to every record. Account and business records remain while the account uses the service unless they are deleted through a specific product control or an approved account-deletion request. A final legal retention schedule still requires owner and legal review.

Before account deletion can complete, a Business organisation owned by that account must be transferred or closed, and connector credentials must be revoked. The deletion workflow then removes the account's authentication records, profile, calculations, conversations and attachments, Business Brain and decision/model data, connections and connected facts, subscription-access copy, user-linked email/AI usage records and team-seat links.

Provider-side records are governed by the relevant provider's deletion process. Aggregate or attempt-level operational telemetry without a direct account identifier may not be removed automatically with the account. The owner and legal counsel must decide which payment, security, consent and provider records require a separate retention or deletion process before this draft becomes the final policy.

Third-party services

MarginKoala relies on infrastructure and service providers including hosting/database infrastructure, Google and Microsoft for optional sign-in, Stripe for billing, an email delivery provider, Vercel AI Gateway and configured model providers, Tavily or Perplexity for live research, optional connector transports and source systems, an optional error-monitoring destination, and optional Google Analytics 4 or Meta Pixel. Their own terms apply when they process data for the service you choose to use.

Your choices and rights

You can choose not to connect a social sign-in provider, avoid submitting optional business data, cancel a subscription, or ask about access/correction/deletion rights available under applicable privacy law.