kool.

Welcome to the Kool Trust Center

Kool is a mobile social & messaging app built privacy-first. Here's a transparent, plain-language view of how we handle security, privacy, compliance and reliability.

Checking system status…

Compliance

We're honest about where we are. Aligned means implemented today; planned means on our roadmap and not yet certified.

GDPR / UK GDPRPrivacy Policy, DPA, SCCs, data-subject rights, 72h breach process
Aligned
CCPA / CPRANo sale or sharing; rights honoured for all users
Aligned
ePrivacy / PECR (cookies)Strictly-necessary first-party cookies only; no ad trackers
Compliant
SOC 2 Type IISecurity, Availability, Confidentiality — readiness in progress
Planned
ISO/IEC 27001ISMS scope & controls being formalized
Planned
WCAG 2.2 AA (accessibility)Self-assessed today; formal third-party audit planned
In progress

Not applicable to Kool as a consumer social app: HIPAA, FedRAMP, DoD IL, PCI-DSS (we store no payment-card data). See our Security Overview and compliance roadmap.

Security

Security is built into how Kool is designed and run — not bolted on.

Passwordless auth

Sign-in is a one-time email code (hash-only storage) — no passwords to steal. Optional authenticator 2FA + device-session revocation.

Encryption everywhere

TLS in transit, encryption at rest on Cloudflare D1/R2, and encrypted WebRTC for calls & live.

Cloudflare edge

Runs entirely on Cloudflare with WAF, DDoS protection and rate limiting in front of all traffic.

Row-level tenancy

Every user record is isolated per owner; admin access is least-privilege and 2FA-gated.

No data sales, no trackers

We never sell your data, use no third-party analytics or ad SDKs, and show only contextual, non-tracking ads.

Responsible disclosure

Report vulnerabilities to security@k00l.app. We work with good-faith researchers.

Subprocessors

The third parties that process data on our behalf to run the service. Full list & transfer safeguards →

CloudflareCompute, database (D1), storage (R2), real-time, AI, CDN/WAF
Global edge
ResendTransactional email (sign-in codes, security notices)
US / EU
GoogleOnly if you link a Gmail mailbox — Gmail API (Limited Use)
Optional
AppleApp Store distribution & public music catalog
Global

No third-party analytics, ad networks, or data brokers. No payment processor today (the app is free); future in-app purchases would run through Apple/Google.

FAQ

Do you sell our data?

No. We never sell or rent personal data, and we don't use it for cross-context behavioural advertising.

Do you use third-party analytics or ad trackers?

No. There are no third-party analytics SDKs or ad trackers. Any ads are contextual (at most coarse country/language) with no cross-app tracking and no ATT/IDFA prompt.

Where is our data stored?

On Cloudflare's global network (D1 database, R2 storage). Cross-border transfers are covered by the EU Standard Contractual Clauses and the UK Addendum. See the Privacy Policy.

Are you SOC 2 or ISO 27001 certified?

Not yet — both are on our roadmap. We operate documented security policies today and are working through readiness. Ask us for current status at security@k00l.app.

Can we sign a DPA or MSA?

Yes. Business customers can request our Data Processing Agreement (with SCC annexes), Master Service Agreement and SLA at legal@k00l.app. Summary: /dpa.

I found a security bug. How do I report it?

Email security@k00l.app. Please give us reasonable time to remediate before disclosure and only access the minimum needed to demonstrate the issue.

How do we delete our data?

Close your account in-app (Profile → Settings → Close account) or email privacy@k00l.app. For business customers, deletion on contract termination is covered by the DPA.

Resources

Our public legal & policy documents.

Updates

July 2026

Trust Center & Legal Center published

Launched a full public legal package (Terms, Privacy, DPA, Cookie, Refund, Accessibility, Security) and this Trust Center.

July 2026

Live status indicator

Added a real-time system-status signal, backed by our public status page at status.k00l.app.

July 2026

Contextual, non-tracking ads

Confirmed our advertising is contextual only — no cross-app tracking, no third-party ad SDKs, no ATT prompt.