Koa ✦ Privacy Policy
Last updated: May 2026
Koa is a personal AI assistant that lives in iMessage. This policy explains
what data we collect, how we use it, who we share it with, and how you can
remove it.
What we collect
- Phone number — used as your account identifier and to send you messages
- Messages you send Koa — stored so Koa can remember context across conversations
- Photos, videos, voice notes, files — analyzed to generate responses; descriptions are stored, raw bytes are not retained beyond the request
- Account data from connectors you authorize (Google Calendar, Gmail, Drive, etc.) — used only to fulfill your requests, never sold or shared
- Stripe billing details — processed by Stripe; we store only your customer ID and subscription status
How we use it
- To respond to your messages
- To fire scheduled reminders, subscriptions, and check-ins you've requested
- To improve Koa's responses through correction memory and routine learning
- To provide customer support if you reach out with an issue
Who we share it with
We share data only with the third-party services required to operate Koa:
- OpenAI — for AI inference (your messages and media are sent for processing; OpenAI's API is configured not to retain data for training)
- SendBlue — to deliver your iMessages
- Stripe — to process Pro upgrade payments
- Pinecone — for long-range memory storage (encrypted at rest)
- Google / Notion / Outlook / etc. — only for providers you've explicitly connected
We do not sell your data. We do not use your data for advertising.
How long we keep it
By default, your data is retained as long as your account is active. You can
delete everything at any time from your dashboard at app.koa.app — the
"Delete all my data" button wipes your subscriptions, corrections,
routines, connections, and reminders within seconds.
OAuth tokens
When you connect a service like Gmail or Google Calendar, we store the OAuth
access and refresh tokens encrypted in our database. You can revoke any
connection from the dashboard, which immediately deletes the tokens and
prevents Koa from making further requests against that account.
Children's privacy
Koa is not intended for users under 13. If you believe a child has provided
us with personal information, contact us and we will delete it.
Changes
If we make material changes to this policy, we'll notify you via iMessage
before the changes take effect.
Contact
Questions or data requests: hello@koa.app
← back