Privacy Policy for Kolbo.AI
Last Updated: August 31, 2026 · Version 2026-08-31-il-amendment-13
@kolbo-cli/kolbo command-line coding agent), the Kolbo WhatsApp and Telegram bots, and related services (collectively, the "Platform").Collection Notice for Israeli Users · הודעה לפי סעיף 11 לחוק הגנת הפרטיות
בעלת השליטה במידע: Zohar Vanunu Productions, LLC, המפעילה את Kolbo.AI. ליצירת קשר ולמימוש זכויות: support@kolbo.ai.
מסירת המידע היא מרצונך ואינה חובה חוקית, אלא אם נציין אחרת. בלי פרטי חשבון הכרחיים לא נוכל לפתוח חשבון; בלי תוכן או מדיה שבחרת למסור לא נוכל לבצע את פעולת ה AI שביקשת; ובלי מידע הנדרש לתשלום לא נוכל להשלים רכישה.
נשתמש במידע להפעלת החשבון, אספקת שירותי AI, חיוב, אבטחה, תמיכה, מניעת הונאה, עמידה בדין ושיפור השירות. מידע הנחוץ לביצוע בקשה יימסר לספקי תשתית, תשלום, דואר ולספקי מודלי AI הרלוונטיים, וכן לרשויות כאשר הדין מחייב זאת. מידע לספקי אנליטיקה, דיוור שיווקי ועוגיות לא הכרחיות יופעלו רק לפי הבחירה שלך.
עומדות לך זכויות עיון במידע לפי סעיף 13 ובקשת תיקון או מחיקה של מידע שאינו נכון, שלם, ברור או מעודכן לפי סעיף 14, בכפוף לחריגים שבדין. דרך המימוש מפורטת בסעיף 7 להלן.
Controller and contact: Zohar Vanunu Productions, LLC, operating Kolbo.AI. Providing information is voluntary and is not legally required unless we say otherwise. Without essential account data we cannot create an account; without the prompt or media you choose to provide we cannot perform the requested AI operation; and without required payment data we cannot complete a purchase. We use the data for account operation, requested AI services, billing, security, support, fraud prevention, legal compliance, and service improvement. Necessary data is disclosed to relevant infrastructure, payment, email and AI providers, and to authorities where legally required. Analytics providers receive information only under your optional choice. Israeli users have statutory access and correction rights described in Section 7.
- You own all content you generate through our AI tools
- We don't sell personal information for money. Optional advertising and affiliate measurement may be treated as “sharing” under some privacy laws and is disabled unless your choice permits it
- Your prompts are sent to AI providers to generate your content
- We don't train on your outputs for other users
- The Kolbo CLI runs locally on your machine and asks for permission before executing commands or editing files outside your project
- The Kolbo WhatsApp and Telegram bots route your messages through Meta and Telegram, who have their own privacy policies that also apply
- In group chats, every group member can use the linked Kolbo account's credits: only add the bot to groups you trust
- You can delete your account at any time. We use a 30-day soft-delete window so you can recover from a mis-click; after that, account content is permanently removed, subject to limited financial, legal and backup retention described in Section 6a.
- Your data is processed in the United States and the European Union
- Israeli privacy rights include access and correction under Sections 13 and 14 of the Privacy Protection Law
1. Information We Collect
Information You Provide:
- Name, email address, company name (if applicable)
- Profile preferences and settings
- Billing and payment information (processed by Stripe)
- Content you upload: text, images, videos, audio files (including voice recordings), Training Lab data (see Section 10 for sensitive data)
Information Collected Automatically:
- IP address, browser type, user agent, operating system
- Pages viewed, referring URLs, UTM parameters
- Feature usage, AI models selected, session duration
- Device information and unique identifiers
Desktop App, CLI, and Plugin Data:
If you use Kolbo Studio (desktop) or our Adobe plugin, we may also collect system information, app version, and auto-update requests.
If you use the Kolbo CLI (the @kolbo-cli/kolbo command-line coding agent), the following information is sent to Kolbo's backend so we can route your requests to AI providers and bill against your credit balance: the prompts you submit, the file paths and file contents the agent reads as context for the response, the names and arguments of tools the agent runs (including shell commands and file edits) once you approve them, the outputs of those tools, and basic telemetry (CLI version, operating system, model selected). The CLI runs as a local process on your computer. We do not crawl, index, or upload files from your machine on our own initiative: only the file content that is included as context for the request you initiated is transmitted, and only for the duration needed to generate a response.
Your CLI authentication token is generated when you log in via our device-code flow and is stored in your local user data directory with owner-only file permissions where the operating system supports them. The token is sent back to our backend only as the Authorization header on requests you initiate.
WhatsApp and Telegram Bot Data:
The Kolbo WhatsApp bot and the Kolbo Telegram bot are alternative front-ends to the same Kolbo.AI account, credit system, and generation services available on the Kolbo website. When you interact with either bot we collect and process:
- From Telegram: your Telegram user ID, your Telegram username (if set on your profile), the chat ID (when the bot is used in a group), and the content of messages you send to the bot (text, images, audio, video).
- From WhatsApp: your phone number (which is also your WhatsApp ID), your WhatsApp display name (if Meta provides it), and the content of messages you send to the bot.
- From you during account linking: your email address. To use any generative feature, you must link your messaging identity to a Kolbo.AI account by entering a 6-digit one-time password (OTP) sent to your email. If the email does not belong to an existing Kolbo account, we create one automatically and credit it with a promotional starter balance.
- Generated during use: the prompts you submit, the media you attach, the AI-generated outputs (images, videos, music, audio, text), conversation history persisted so the AI can reference earlier messages, and credit transactions tagged with the originating bot for billing audit purposes.
All bot messages are transmitted through Meta's WhatsApp Business Cloud API or Telegram's Bot API before they reach our backend. Meta and Telegram are independent third parties with their own privacy policies, which apply to your messages while in transit through their infrastructure. We strongly recommend reviewing them: WhatsApp Privacy Policy and Telegram Privacy Policy.
Group chats: when the bot is added to a WhatsApp or Telegram group, every member of that group can send prompts to the bot, every member can see the bot's replies, and every prompt consumes credits from the single Kolbo account that linked the bot to the group. The person who linked the account is responsible for any credit usage by other group members. Only add the bot to groups you trust.
2. How We Use Your Information
- Provide, maintain, and improve our services
- Process your inputs through AI models and deliver outputs
- Process payments and send transaction confirmations
- Communicate with you (support, updates, security alerts)
- Send marketing and promotional communications only where you opted in or another lawful basis applies
- Analyze usage patterns to improve the Platform
- Maintain the security of the Platform
- Comply with legal obligations
- Train custom models in Training Lab: solely for your use, never shared with other users
3. Sharing Your Information
We do not sell personal information for money. Optional advertising disclosures may qualify as “sharing” under some privacy laws. We disclose information only in these situations:
- AI providers: Your prompts are sent to the AI provider you select (e.g., OpenAI, Google, Anthropic, and others) to generate outputs. Their own privacy policies also apply
- Service providers: Payment processing, cloud hosting, analytics, and email communications
- Legal requirements: When required by law or to protect our rights, users, or public safety
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you
- With your consent: For example, when you collaborate with other users on projects
We may share non-personally-identifiable, aggregated data for research and analysis.
Our key service providers include cloud hosting (AWS and DigitalOcean Spaces for object storage), payment processing (Stripe), optional analytics and advertising measurement (PostHog, Google Analytics, Google Ads, Tag Manager and Meta), optional affiliate attribution (PromoteKit), transactional email (Resend, used among other things to deliver the OTP codes that link the WhatsApp and Telegram bots to your Kolbo account), messaging-bot transport (Meta Platforms, Inc. for the WhatsApp Business Cloud API and Telegram Messenger Inc. for the Telegram Bot API), and various AI model providers. For a current list of sub-processors or more details, contact support@kolbo.ai.
4. Cookies and Analytics
We use cookies and similar technologies to personalize your experience and understand usage patterns:
- Essential cookies: Required for platform functionality
- Analytics cookies: Usage analysis via PostHog and Google Analytics
- Advertising and attribution cookies: Campaign and affiliate measurement via Google Ads, Meta and PromoteKit
- Preference cookies: Remember your language and settings
Non-essential analytics and advertising storage is disabled until you make a choice in our cookie controls. Your choice is shared across our kolbo.ai web properties where technically available. We treat an enabled Global Privacy Control signal as a request to disable advertising and affiliate measurement. You can also block or delete cookies in your browser. Declining non-essential cookies does not affect core functionality. Native applications use equivalent local settings rather than browser cookies.
5. Security
We implement technical and organizational measures designed to protect your personal data against unauthorized access, loss, or misuse. No system is perfectly secure, and we cannot guarantee absolute security. In the event of a data breach, we will notify affected users as required by applicable law.
What we do
- All communication between our web app, desktop app, Kolbo CLI, and our backend uses TLS (HTTPS).
- Payment information is processed by Stripe and is not stored on our servers.
- The Kolbo CLI stores its authentication token in your local user data directory with owner-only file permissions where the operating system supports them (POSIX
0600; on Windows, file permissions follow the user account ACL). - The Kolbo CLI redacts common secret patterns (API keys, JWTs, PEM private keys,
Authorizationheaders, AWS / Google / GitHub / Slack / Anthropic / OpenAI / Stripe tokens) from its persisted log files and session metadata before they are written to disk. - The Kolbo CLI defends against server-side request forgery (SSRF) on its outbound HTTP tools by blocking private, loopback, link-local, and cloud-metadata addresses (including IPv4-mapped IPv6 forms), and by re-validating after every redirect.
- The Kolbo CLI follows symlinks before checking project boundaries on file read / write / edit operations, and prompts before any action that would touch a file outside the current project.
- The Kolbo CLI scrubs dynamic-loader environment variables (
LD_PRELOAD,DYLD_INSERT_LIBRARIES,NODE_OPTIONS, etc.) from the inherited environment before launching MCP server subprocesses, so a poisoned shell environment cannot inject code into them. - Backend overrides for the Kolbo CLI are restricted to HTTPS, with HTTP only allowed for localhost during development.
- The CLI's local HTTP server refuses to bind to non-loopback network interfaces unless an authentication password has been explicitly configured.
- One-time passwords (OTPs) used to link the WhatsApp and Telegram bots to your Kolbo account are hashed with bcrypt before storage, expire after 10 minutes, allow a maximum of 3 verification attempts per code, and are rate-limited to 3 requests per hour per email address.
- Webhook callbacks from Meta's WhatsApp Business Cloud API are cryptographically verified using the signature header Meta provides. Telegram bot callbacks are protected by a shared secret. All bot traffic between Kolbo and Meta or Telegram uses HTTPS end-to-end.
- To report a security vulnerability, email support@kolbo.ai with "security report" in the subject line. We will respond as quickly as we are able.
What we have not done
In the interest of being honest about our current security posture, Kolbo.AI has not undergone a third-party penetration test, does not currently publish a SOC 2 or ISO 27001 report, and does not yet store Kolbo CLI authentication tokens in operating-system keystores (Apple Keychain, Windows Credential Manager, libsecret): they are stored as a file with restrictive permissions instead. Migrating to OS keystores, adding PKCE to the CLI's OAuth device flow, and publishing signed installer scripts are items on our security roadmap. Enterprise customers with specific security requirements should contact us before deploying at scale.
Your role in the security model
The Kolbo CLI is an AI coding agent. By design it can execute shell commands and read or modify files on the machine where it runs. Every such action is gated by an interactive permission prompt: you, the human approving each action, are the security boundary. Please review what the agent is about to do before approving it, and never approve actions you do not understand.
6. Data Retention
- Account data: Retained while your account is active.
- Soft-deleted user content (generations, sessions, chat history, custom voices, etc.): Retained for up to 30 days from the moment you (or our system) flag it as deleted, then permanently removed by an automated daily sweeper. This 30-day window exists so you can recover content you removed by mistake.
- Generation Inputs (reference photos, voice samples, and other media you upload to produce a generation): Retained while the generation, and any Visual DNA, voice clone or custom model built from them, remains in your library. When you delete them they follow the same 30-day soft-delete window above. We use them only to provide the feature you requested: see Section 3 of our Terms of Service for the limited license that applies.
- Bot account links: The record connecting your WhatsApp number or Telegram user ID to your Kolbo account is retained for the life of your Kolbo account or until you send
/logoutto the bot, whichever comes first. - Bot one-time passwords (OTPs): Hashed bcrypt records auto-expire 10 minutes after generation.
- Bot messages, prompts, and generated media: Retained under the same retention rules as content created on the Kolbo website (your media library).
- Financial records (credit transactions, invoices, payment records): Retained for up to 7 years where needed for applicable tax, VAT, accounting, fraud-prevention, dispute, and reconciliation duties. After account deletion, the live account link and unnecessary personal fields are removed or restricted. Provider transaction, customer, invoice, product, amount, and timestamp identifiers may remain where needed to reconcile records and answer lawful claims.
- Stripe payment records: Held by our payment processor (Stripe) per their retention policies, independent of our own systems.
- Backups: A deleted account may persist in an access-restricted backup until that backup expires under the applicable rotation schedule. If a backup is restored for disaster recovery, completed deletion requests must be reapplied.
6a. Account Deletion: How It Works
When you delete your account (via the in-app setting or by contacting us), we follow a two-phase process to balance your right to erasure with protection against accidental loss:
- Phase 1: Soft delete (immediate): Your account is flagged as deleted and you are signed out of all sessions. You can no longer log in. We send you an email with a one-click restore link that is valid for 30 days. During this window the account is unavailable through the Platform and access is limited to authorized personnel and systems that need it for security, recovery, legal, or support purposes.
- Phase 2: Permanent deletion (after 30 days): A scheduled job hard-deletes the account. This includes: your user record, all generations (images, videos, audio), all sessions, chat history, media library, uploaded files, custom voices, projects, memories, visual DNAs, moodboards, custom agents, preferences, API keys, and connected integrations. We also delete the corresponding files from our cloud object storage (DigitalOcean Spaces).
- Limited records that may remain: Financial and provider transaction records described in Section 6, plus access-restricted backups until their scheduled expiry.
- Restoring within the window: Open the email we sent you and click "Restore my account". You can also email support@kolbo.ai from the address on file.
- Accounts we terminate: If we terminate your account rather than you deleting it, the same 30-day preservation window applies, but no automatic restore link is sent. You may email support@kolbo.ai from the address on file during that window to request a copy of your content. We may skip the window and delete immediately where the termination relates to child sexual abuse material, fraud, or a security threat. See Section 13 of our Terms of Service.
- Skipping the window: If you want immediate, irreversible deletion with no recovery option, email support@kolbo.ai and request "immediate hard deletion". We will confirm in writing and execute within a reasonable time (typically 7 business days).
This two-phase model satisfies the GDPR right to erasure (Article 17): the 30-day grace window is well within the "without undue delay" standard, and you may always request the immediate-deletion path described above.
7. Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Restrict or object to certain processing
- Request data portability (download your outputs through the Platform)
- Withdraw consent for non-essential processing
- Lodge a complaint with your local data protection authority (e.g., GDPR Art. 77)
Rights under Israel's Privacy Protection Law:
- Access: ask to inspect personal information about you held in a database, including information presented in a human-readable form, under Section 13.
- Correction or deletion: ask the controller to correct or delete information that is incorrect, incomplete, unclear, or outdated, under Section 14.
- Direct mailing: ask to be removed from a direct-mailing database and require each qualifying direct-mail message to identify the sender and the source of the information.
- Complaint: contact the Israeli Privacy Protection Authority if you believe your rights were not respected.
Send an email from the address associated with your account to support@kolbo.ai with “Privacy Request” in the subject. State whether you seek access, correction, deletion, portability, objection, or another right. We will verify identity proportionately and respond within the period required by applicable law. Our operational target is 30 days. We may retain information where a legal obligation or another lawful exception applies, and we will explain that decision.
To unlink the WhatsApp or Telegram bot from your Kolbo account at any time, send /logout to the bot. The link record is removed immediately. Deleting your Kolbo account also removes any active bot links automatically.
8. Consent and Withdrawal
Consent is used only where it is the appropriate legal basis. Processing that is necessary to create an account, complete a payment, secure the Platform, or perform an AI request you initiate is service processing, not optional consent. You may withdraw consent for future optional processing at any time. This does not affect earlier lawful processing or processing based on another legal ground.
- Marketing: No more promotional emails (service emails continue)
- Analytics and advertising: Change your cookie choice or browser settings; core functionality remains available
- Voice cloning, face editing, image training: Stop using the relevant feature and request deletion of the related asset or account. Existing legal or financial records may remain where required by law
9. Children's Privacy
Our Services are intended for users who are at least 18 years old. We do not knowingly collect information from anyone under 18.
If we discover we have collected data from someone under 18, we will delete it promptly. Anyone who believes a minor has provided us with personal information should contact support@kolbo.ai.
10. AI Content, Voice Data, and Training
Ownership:
You own the outputs you generate through our AI tools. We do not claim ownership of your content and do not use your outputs for any purpose other than delivering them to you.
Training Data:
- Your outputs are not used to train models for other users
- Training Lab data is used only for your custom models
- We use usage statistics for platform improvement
- Third-party AI providers may have their own data policies: we recommend reviewing them
Features involving voice, face, likeness, or custom training:
These features process the media you deliberately submit to perform the operation you request. Before using them, you must have authority from every identifiable person depicted or heard and complete any feature-specific confirmation presented in the product:
- Voice cloning and text-to-speech: Voice recordings are sent to our audio AI providers to create voice models. You must confirm you have the right to use any voice samples you upload
- Image-based training: When you train custom models using images of people (Training Lab, visual DNA), you must confirm you have the rights to those images
- Face and likeness editing: Features like face swap, character replace, and lipsync process facial data from images or videos you provide
Voice recordings and facial data may be specially protected under applicable law. Under Israeli law, they are a “biometric identifier” when used or intended for unique identification or authentication. Other content may still reveal specially sensitive information. We process this media only to provide the feature requested, do not use it to identify users unless a feature expressly says so, and do not sell it or allow providers to use it for their own advertising.
AI Model Sub-processors:
To deliver the feature requested, we transmit prompts, reference media and, where applicable, voice or facial media to the selected AI model provider. Representative providers include OpenAI, Google, Anthropic, fal.ai, Replicate, Kuaishou, ByteDance, MiniMax, xAI, ElevenLabs, DeepDub, Suno and other providers shown in the product. Availability and routing change frequently. Contact us for the current sub-processor register before submitting regulated or enterprise data.
We do not train our own foundation models on your prompts, uploaded media or generated outputs. Where a provider offers a no-training or zero-retention API mode, we use it when commercially available; otherwise the provider's standard API terms apply.
Synthetic-Media Marking (EU AI Act Article 50):
Some outputs carry machine-readable provenance markers applied by the upstream model provider that generated them, such as C2PA / Content Credentials or an invisible watermark, and these pass through to the file you receive. Kolbo.AI does not currently add its own marking layer on top, so coverage depends on which model you used and is not complete. We are working toward applying our own marking across all outputs and will update this section when that is in place. In the meantime, every output of the Services is AI-generated whether or not it carries a marker: when you publish or share one you must disclose that to your audience, and you must not remove a marker that is present. See Section 20 of our Terms of Service for the full obligation.
11. International Data Transfers
Your data is processed in the United States and the European Union, and may be processed in other locations where our service providers and AI providers operate.
For transfers of personal data from the EEA, UK, and similar jurisdictions to the United States and other countries that have not received an adequacy decision, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards as implemented by our service providers.
For transfers from databases subject to Israeli law, we apply the Privacy Protection Regulations (Transfer of Data to Databases Outside the State Borders), 2001. Depending on the destination and recipient, the transfer is based on an applicable regulatory route and contractual commitments requiring the recipient to protect privacy, use the information only for the permitted purpose, and not transfer it onward without lawful safeguards. Data received from the European Economic Area is also handled under Israel's 2023 EEA-transfer regulations, including accuracy, notice, deletion, and data-minimization duties.
Business and Enterprise customers may request a Data Processing Agreement (DPA) by contacting support@kolbo.ai.
12. Legal Basis for Processing (GDPR)
For users in the EEA, UK, and similar jurisdictions:
| Activity | Legal Basis |
|---|---|
| Account, payments, AI services, Training Lab | Contract performance |
| Security and fraud prevention | Legitimate interest and legal obligation |
| Optional analytics | Consent |
| Marketing, non-essential cookies | Consent |
| Voice cloning, face/likeness editing, image-based training | Contract performance for the requested feature; explicit consent where the data qualifies and applicable law requires it |
| Tax records, legal compliance | Legal obligation |
You may contact us to learn more about how we apply these legal bases.
13. Automated Decision-Making
Our "Smart Agent" feature automatically selects the best AI model for your task by analyzing your prompt. This does not produce legal effects: it only determines which model processes your request, and you can always override it manually. We do not use automated decision-making for decisions that significantly affect you.
14. California Privacy Rights (CCPA/CPRA)
California residents have additional rights, including rights to know, correct and delete personal information and to opt out of its sale or sharing. We do not sell personal information for money. Optional Meta, Google Ads and affiliate measurement may qualify as sharing for cross-context behavioral advertising; you can opt out through our privacy controls, an enabled Global Privacy Control signal, or by contacting us. We will not discriminate against you for exercising these rights. Contact support@kolbo.ai to exercise your California privacy rights.
15. Links to Other Sites
Our Platform may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites.
16. Email Communications
We send marketing and promotional emails only when you affirmatively opt in or where another lawful basis expressly permits the message. Every marketing email provides an unsubscribe method. You may also email us with “Unsubscribe” in the subject. Transactional and security messages that are necessary to operate your account are not marketing and may continue.
17. Changes to This Policy
We may update this policy from time to time. For material changes, we will give you at least 15 days' notice via email or a notice on the Platform before the change takes effect. Continued use after a change takes effect constitutes acknowledgment of the updated policy.
18. Contact
Zohar Vanunu Productions, LLC131 Continental Drive, Suite 305
Newark, Delaware 19713, United States
Website: www.kolbo.ai
Privacy requests: support@kolbo.ai. Please use “Privacy Request” in the subject.