Compliance
We're honest about where we are. Aligned means implemented today; planned means on our roadmap and not yet certified.
Not applicable to Kool as a consumer social app: HIPAA, FedRAMP, DoD IL, PCI-DSS (we store no payment-card data). See our Security Overview and compliance roadmap.
Security
Security is built into how Kool is designed and run — not bolted on.
Passwordless auth
Sign-in is a one-time email code (hash-only storage) — no passwords to steal. Optional authenticator 2FA + device-session revocation.
Encryption everywhere
TLS in transit, encryption at rest on Cloudflare D1/R2, and encrypted WebRTC for calls & live.
Cloudflare edge
Runs entirely on Cloudflare with WAF, DDoS protection and rate limiting in front of all traffic.
Row-level tenancy
Every user record is isolated per owner; admin access is least-privilege and 2FA-gated.
No data sales, no trackers
We never sell your data, use no third-party analytics or ad SDKs, and show only contextual, non-tracking ads.
Responsible disclosure
Report vulnerabilities to security@k00l.app. We work with good-faith researchers.
Subprocessors
The third parties that process data on our behalf to run the service. Full list & transfer safeguards →
No third-party analytics, ad networks, or data brokers. No payment processor today (the app is free); future in-app purchases would run through Apple/Google.
FAQ
Do you sell our data?
No. We never sell or rent personal data, and we don't use it for cross-context behavioural advertising.
Do you use third-party analytics or ad trackers?
No. There are no third-party analytics SDKs or ad trackers. Any ads are contextual (at most coarse country/language) with no cross-app tracking and no ATT/IDFA prompt.
Where is our data stored?
On Cloudflare's global network (D1 database, R2 storage). Cross-border transfers are covered by the EU Standard Contractual Clauses and the UK Addendum. See the Privacy Policy.
Are you SOC 2 or ISO 27001 certified?
Not yet — both are on our roadmap. We operate documented security policies today and are working through readiness. Ask us for current status at security@k00l.app.
Can we sign a DPA or MSA?
Yes. Business customers can request our Data Processing Agreement (with SCC annexes), Master Service Agreement and SLA at legal@k00l.app. Summary: /dpa.
I found a security bug. How do I report it?
Email security@k00l.app. Please give us reasonable time to remediate before disclosure and only access the minimum needed to demonstrate the issue.
How do we delete our data?
Close your account in-app (Profile → Settings → Close account) or email privacy@k00l.app. For business customers, deletion on contract termination is covered by the DPA.
Resources
Our public legal & policy documents.
Updates
Trust Center & Legal Center published
Launched a full public legal package (Terms, Privacy, DPA, Cookie, Refund, Accessibility, Security) and this Trust Center.
Live status indicator
Added a real-time system-status signal, backed by our public status page at status.k00l.app.
Contextual, non-tracking ads
Confirmed our advertising is contextual only — no cross-app tracking, no third-party ad SDKs, no ATT prompt.