Welcome to the Kool Trust Center

Kool is a mobile social & messaging app built privacy-first. Here's a transparent, plain-language view of how we handle security, privacy, compliance and reliability.

Checking system status…

Compliance

We're honest about where we are. Aligned means implemented today; planned means on our roadmap and not yet certified.

GDPR / UK GDPRPrivacy Policy, DPA, SCCs, data-subject rights, 72h breach process
Aligned
CCPA / CPRANo sale or sharing; rights honoured for all users
Aligned
ePrivacy / PECR (cookies)Strictly-necessary first-party cookies only; no ad trackers
Compliant
SOC 2 Type IISecurity, Availability, Confidentiality. Readiness in progress
Planned
ISO/IEC 27001ISMS scope & controls being formalized
Planned
WCAG 2.2 AA (accessibility)Self-assessed today; formal third-party audit planned
In progress

Not applicable to Kool as a consumer social app: HIPAA, FedRAMP, DoD IL, PCI-DSS (we store no payment-card data). See our Security Overview and compliance roadmap.

Security

Security is built into how Kool is designed and run, not bolted on.

No password to steal

You sign in with a one-time code sent to your email, and we never keep the code itself. Add a second step if you want one, and cut off any device you no longer trust.

Scrambled the whole way

Everything you send is scrambled on its journey and stays scrambled while it sits with us. messages, files, calls and live video alike.

Guarded at the door

Kool runs on Cloudflare, so attacks meant to knock the service over or break into it are absorbed before they ever reach your data.

Your things are yours alone

Every record belongs to one account and is walled off from every other. The handful of people here who can reach anything at all can reach only what their job needs, behind a second lock.

Nothing about you is for sale

We do not sell or rent your information, there is no outside company watching what you tap, and any advertising is chosen by the page you are on rather than by anything we know about you.

Found a hole? Tell us

Report vulnerabilities to security@k00l.app. We work with good-faith researchers.

Subprocessors

The third parties that process data on our behalf to run the service. Full list & transfer safeguards →

CloudflareRuns the app, keeps your data, carries your calls, and turns attacks away at the door
Global edge
ResendSends the few emails Kool has to send you, like your sign-in code
US / EU
GoogleOnly if you choose to bring your Gmail in, and only to show and send that mail
Optional
AppleHands out the app, and looks up the songs you share
Global

No third-party analytics, ad networks, or data brokers. No payment processor today (the app is free); future in-app purchases would run through Apple/Google.

FAQ

Do you sell our data?

No, not to anyone, not ever, and not in the quiet ways either. We do not sell or rent your personal information, and we do not let it be used to follow you around other apps and websites building a profile for advertisers. Kool does not make money that way, so there is nothing here to be tempted by.

Do you use third-party analytics or ad trackers?

No. There is no analytics company watching what you tap and no advertising code riding along inside the app. Any advertising we show is chosen by the page you are on rather than by anything we know about you. at most a rough sense of country and language. That is also why iPhone never asks you whether Kool may track you. It has nothing to ask about.

Where is our data stored?

On Cloudflare's network, which keeps data close to the people using it rather than in one distant building. When information does cross a border, it travels under the standard legal agreements European and UK law provide for exactly that, so the protection follows the data. The details are in our Privacy Policy.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we would rather say so plainly than imply otherwise. Both are security audits done by an outside firm, and both are on our list. In the meantime we run to written security practices already and are working through what the audits ask for. If you need to know exactly where we have got to, ask us at security@k00l.app and we will tell you honestly.

Can we sign a DPA or MSA?

Yes. If your organisation needs the formal paperwork: the data-processing agreement, the service agreement, the uptime commitments. Write write to legal@k00l.app and we will send it over. There is a plain-language summary at /dpa if you would like to read what it says before involving lawyers.

I found a security bug. How do I report it?

Please tell us at security@k00l.app, genuinely, thank you. All we ask in return is a fair chance to fix it before it goes public, and that while you are proving the problem you go no further into anyone's data than you need to. We will not come after you for looking in good faith.

How do we delete our data?

Close your account in the app, under Profile, then Settings, then Close account, or write to privacy@k00l.app and we will handle it. For organisations, deletion when a contract ends is written into the agreement rather than left to trust.

Resources

Our public legal & policy documents.

Updates

July 2026

Trust Center & Legal Center published

Launched a full public legal package (Terms, Privacy, DPA, Cookie, Refund, Accessibility, Security) and this Trust Center.

July 2026

Live status indicator

Added a real-time system-status signal, backed by our public status page at status.k00l.app.

July 2026

Contextual, non-tracking ads

Checked and confirmed: any advertising is chosen by the page you are on, nothing follows you between apps, and no outside advertising company has code inside Kool. That is also why your iPhone never asks whether Kool may track you.