Privacy Policy
Effective Date: March 31, 2026
Kuroma ("we," "our," or "us") is operated by iKala. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our web application and services (the "Service").
1. Information We Collect
1.1 Information You Provide
- Account Information: When you sign in via Google OAuth, we receive your name, email address, and profile picture from your Google account.
- Brand Data: Domain names, brand names, industry categories, and competitor information you enter into the Service.
- Settings & Preferences: Notification preferences, theme settings, and alert configurations.
1.2 Information We Collect Automatically
- Usage Data: Pages visited, features used, timestamps, and interaction patterns within the Service.
- Device Information: Browser type, operating system, and screen resolution.
- Attribution Data: When you install our attribution pixel on your website, we collect anonymized visitor referral data to identify AI-referred traffic.
1.3 Information from Third-Party Services
- Google Analytics: If you connect your Google Analytics property, we access your website traffic data (sessions, pageviews, users, bounce rate) via the Google Analytics Data API to display alongside AI attribution data. We request the
analytics.readonlyscope for read-only access to your reports. - AI Platforms: We query public AI platforms (ChatGPT, Gemini, Claude, Perplexity, Grok, AI Overviews, AI Mode) to assess how they represent your brand. We do not share your personal data with these platforms.
- Google Search Console & Cloudflare: If you connect these integrations, we access bot visit data to analyze AI crawler activity on your website.
2. How We Use Your Information
- Provide, maintain, and improve the Service.
- Generate AI visibility scores, readiness assessments, competitive intelligence, and market insights for your brands.
- Send email notifications about scan results, alert triggers, weekly digests, and performance changes (configurable in Settings).
- Track AI-attributed website traffic and conversions via the attribution pixel.
- Display Google Analytics traffic data alongside AI attribution metrics when you connect GA4.
- Calculate industry benchmarks using aggregated, anonymized data across all users.
- Detect and prevent abuse, enforce rate limits, and maintain service security.
3. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Aggregated Benchmarks: Industry benchmark data is calculated from aggregated, anonymized brand data. Individual brand identities are hidden for free-tier users via anonymization.
- Service Providers: We use third-party services for infrastructure (Google Cloud Platform), email delivery (Resend), and caching (Redis). These providers process data on our behalf under data processing agreements.
- Legal Requirements: We may disclose information if required by law, regulation, or legal process.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
4. Google API Services — Limited Use Disclosure
Kuroma's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google Analytics data to display your website traffic alongside AI attribution metrics within the Kuroma dashboard.
- We do not use Google user data for advertising purposes.
- We do not share Google user data with third parties except as necessary to provide the Service.
- We do not allow humans to read your Google user data unless with your affirmative consent, for security purposes, to comply with applicable law, or for our internal operations where the data has been aggregated and anonymized.
5. Data Storage & Security
- Data is stored on Google Cloud Platform (Cloud Run, Cloud SQL for PostgreSQL, Memorystore for Redis) with encryption at rest and in transit.
- OAuth tokens for Google Analytics connections are stored encrypted in our database and are only used for authorized API calls.
- We implement rate limiting, distributed locks, and automated abuse detection to protect the Service.
- We conduct regular security reviews of our codebase and dependencies.
6. Data Retention
- Account Data: Retained for the duration of your account. When you delete your account, personal data is removed within 30 days.
- Brand Data: Brand scan results, AI visibility scores, and monitoring history are retained for 12 months to provide trend analysis.
- Attribution Data: Attribution events are retained for 12 months.
- GA4 Metrics: Daily traffic metrics synced from Google Analytics are retained for 12 months. You can disconnect GA at any time, which stops new data collection. Existing synced metrics remain unless you request deletion.
- Aggregated Data: Anonymized, aggregated benchmark data may be retained indefinitely.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your personal data and account.
- Export your data in a portable format (CSV export is available for attribution data).
- Withdraw consent for optional data processing (e.g., disconnect Google Analytics, disable email notifications).
- Revoke Google OAuth access at any time via your Google Account permissions.
8. Cookies
Kuroma uses minimal cookies:
- Authentication cookie: Maintains your logged-in session (essential, cannot be disabled).
- Theme preference: Stores your light/dark mode preference.
We do not use third-party tracking cookies or advertising cookies.
9. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Effective Date" above.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
- Email: contact@ikala.ai
- Website: https://kuroma.ai