Why we do not sell your data

Vision

"We do not sell your data" is the cheapest sentence in technology. Everybody says it, several of the companies saying it are describing an arrangement that a normal person would call selling, and the phrase has been worn smooth to the point of carrying no information. So here is the version with the mechanism in it.

There are no third-party analytics SDKs in Kool. Not a reduced set, not ones configured carefully. None. That matters more than the policy statement it sits under, because an analytics SDK is not a passive measuring tool: it is somebody else's code, running inside your app, with the app's own permissions, deciding for itself what to collect and where to send it. The privacy promise of an app containing one is only as strong as another company's roadmap.

There are no advertising trackers and no cross-app tracking, which is why the app never shows an App Tracking Transparency prompt. That absence is a fact you can check from outside, unlike most privacy claims. There is nothing to ask you for.

Where ads appear, they are contextual. The most they use is a coarse country and language, because an ad in a language you do not read is not an ad, it is noise. They are not selected from a profile of you, and they do not follow you anywhere, because there is no identifier being carried between apps to follow you with.

The website matches the app. Only strictly necessary, first-party technologies to sign you in and keep the service secure. No advertising cookies, no cross-site trackers, no third-party analytics. One visible consequence: most visitors will never see a consent banner, because we set nothing that requires consent. If you have ever wondered why some sites need an elaborate dialogue to explain themselves and others do not, that is the difference, and the banner is the tell.

The reason to do it this way is not purity, it is structural. Every one of those absences removes an entire category of future decision. There is no data set that becomes tempting when a quarter goes badly, no partner integration to unwind under pressure, no default that could quietly change in a settings migration. The strongest privacy guarantee is not a promise not to do something. It is not having built the thing that would let you.

The most useful question to ask any company about privacy is not what they promise. It is what they would have to build in order to break the promise, and how much of it they have already built.

All posts