KOLANSA PRIVACY POLICY
Privacy, explained plainly.
Last updated: 3 August 2026
This policy describes the KolAnsa product as currently implemented. It is not a promise that every operation stays on your device: some voice and AI functions use external cloud services, as described below.
1. Who this covers
This policy applies to visitors using the public demo and people using a KolAnsa account, dashboard, mobile experience, assistants and connected calling services. The legal entity operating KolAnsa and its registered address require owner/legal confirmation before publication.
2. Information we collect
- Account and authentication: email address, display name, password hash, login provider identifiers, profile image where supplied, session records and account permissions.
- Demo information: an optional business website URL, text extracted from reachable public pages, temporary business context, demo session state and abuse/cost-control events.
- Calls and voice: microphone audio needed to run a voice conversation, speech transcriptions, assistant replies and call outcome information. Depending on configuration, speech recognition and voice generation may run locally or through external providers.
- Business content: assistant instructions, knowledge files, business information, phrase banks, voices, schedules and integration settings you provide.
- Usage and technical data: metered model, voice and operation usage; credit entries; timestamps; service state; security and diagnostic events; and limited network/session information used for security and rate limiting.
3. How we use information
We use information to authenticate users, operate calls and assistants, personalise an optional website demo, provide requested actions, calculate and display usage, protect the demo from abuse, secure the service, troubleshoot faults and improve approved conversation behaviour. A website scan is treated as in progress until the service confirms a result.
4. Microphone, transcripts and voice processing
Your browser asks for microphone permission before capturing audio. You can refuse permission or turn the microphone off, but the spoken demo will not work without it. Audio and transcripts are processed to understand and answer you. The current system supports local speech processing as well as configured cloud speech-to-text, AI and text-to-speech services; the path used depends on deployment and selected features. KolAnsa does not claim that all raw audio is always processed locally.
5. External processors and international processing
KolAnsa may send the minimum information needed to configured categories of providers: AI/model services, speech recognition and voice generation, telephony and messaging, calendar or email integrations, authentication providers, payment services when activated, and infrastructure or security services. Those providers may process data outside New Zealand under their own service terms. This build does not activate a payment gateway and does not take a payment.
6. Privacy Firewall boundaries
The Privacy Firewall is designed to detect and replace supported categories of private values with opaque tokens before configured cloud AI requests. Workspace values in its local vault are encrypted, and supported private speech values can be assembled locally from saved audio pieces instead of being sent to a cloud voice provider. This is a technical safeguard, not a guarantee that every sensitive fact will always be detected. Business content, ordinary conversation text and information deliberately required by an external integration may still be processed by that provider. Strict modes can fail closed when required key protection is unavailable.
7. Cookies and session security
KolAnsa uses a secure-by-design, HTTP-only session cookie to keep you signed in. It is configured with SameSite protection; production deployments should enable transport-only secure cookies and HTTPS. The public demo uses short-lived protected session controls and enforces duration, cost and request limits.
8. Retention and deletion
Account, assistant, knowledge, usage and operational records are retained while needed to provide and secure the service and meet legitimate business or legal requirements. Demo business context is intended to be temporary and is constrained by the demo firewall, but operational security and metering events may be retained separately. Exact production retention periods and the verified process for account deletion require owner/legal confirmation. Contact KolAnsa to request access, correction or deletion; some records may need to be retained where legally required.
9. Security
Current safeguards include access controls, scoped guest permissions, password hashing, HTTP-only sessions, demo rate and cost controls, privacy tokenisation, authenticated encryption for supported vault data and fail-closed production key configuration. No internet service can promise absolute security.
10. Your choices
You may use the demo without providing a website, decline microphone access, stop a demo, sign out, choose whether to connect optional providers, and request access, correction or deletion. Browser settings let you clear the session cookie. Removing connected services may limit related features.
11. Children
KolAnsa is a business service and is not directed to children. Do not provide children’s personal information through the service unless you have authority and an appropriate lawful basis.
12. Changes and contact
We may update this policy as the product, providers or legal requirements change. We will update the date above when we do.
Privacy contact: OWNER/LEGAL TO CONFIRM EMAIL AND POSTAL ADDRESS BEFORE PUBLICATION.