Privacy Policy
Last updated: August 27, 2026
This policy explains what information KRBR ("we", "us") collects, why we collect it, and the choices you have. It covers karbar.app and the KRBR application.
The two kinds of data in KRBR
KRBR is a workspace where service businesses manage their own clients. That means there are two distinct categories of personal data, and our role is different for each:
- Your account data. Information about you and your business — your name, email, company details, subscription and settings. For this data, we are the data controller.
- Your workspace content. Information you store about your clients — their names, contact details, projects, documents, invoices, messages and form responses. This data belongs to you. We process it only to provide the service, on your instructions, and we do not use it for our own purposes, sell it, or use it for advertising. You are responsible for having the right to store and use your clients' information.
What we collect
- Account information: name, email address, password (stored as a salted hash), business name, address and branding you provide during signup and onboarding.
- Public resource information: when you choose to start the free invoice generator or copy or print a contract template, we collect the contact and business details shown in that resource's access form, the resource used, campaign attribution and repeat-use count. Client names, invoice line items and edits you make to public templates remain in your browser and are not submitted through that form.
- Workspace content: the leads, clients, contacts, projects, tasks, contracts, proposals, invoices, expenses, files, messages and scheduling data you and your team create or upload.
- Billing information: your KRBR subscription is billed through Stripe. Your card number goes directly to Stripe and never touches our servers; we store only the subscription status, plan and Stripe identifiers.
- Integration data and tokens: if you connect Gmail, Google Calendar, Google Drive, Outlook, OneDrive, Dropbox, Zoom, Zapier, Stripe, PayPal or Square, we receive the account identity, data you choose to sync or import, and authorization tokens needed to perform the actions you request. Integration tokens are encrypted and scoped to the connected user or workspace.
- Usage and log data: standard server logs (IP address, browser type, pages requested, timestamps) used for security and troubleshooting.
- Cookies and analytics: we use essential cookies to keep you signed in and protect your session. When configured, Google Analytics measures visits and interactions on public marketing pages using device, browser, referral and approximate-location information. We do not use this information for personalized advertising, and authenticated workspace and client-portal pages are excluded from analytics.
Google API Services and OAuth
Google connections are optional. KRBR requests a permission only after you choose the corresponding Google feature, and uses the resulting Google user data only to provide that feature:
| Feature | Google data accessed | How KRBR uses it |
|---|---|---|
| Sign in with Google | Your Google account identifier, name, email address and email-verification status. | To create or link your KRBR account, authenticate you and display your account identity. KRBR does not receive your Google password. |
| Gmail | Your Google account identity and permission to send email from your Gmail account. | To send only the client and workspace messages you direct KRBR to send. KRBR does not request permission to read your Gmail inbox. |
| Google Calendar | Event titles, descriptions, dates and times, attendees, locations, meeting links and event identifiers from your primary calendar. | To import and synchronize calendar events and to create, update or delete events when you perform the matching action in KRBR. |
| Google Drive | Your account identity, Drive storage usage, files you explicitly select with Google Picker, and files KRBR creates in your Drive. This can include selected file names, identifiers, metadata and contents. | To preview, import or link only the files you select, and to create, upload, download or delete KRBR-accessible files when you explicitly request those operations. KRBR does not request access to browse every file in your Drive. |
Storage and retention. For connected Google integrations, KRBR stores the connected account identity, granted scopes, token expiry and encrypted access or refresh tokens. Calendar events you sync and Drive files you copy into KRBR become workspace content and remain until you delete them or close the account. Linked Drive items retain the identifiers and metadata required to display the link. Disconnecting a Google integration removes its stored tokens and stops future API access; previously imported workspace content is not automatically deleted.
Sharing and human access. We do not sell Google user data, use it for advertising, transfer it to data brokers, or allow humans to read it except when you give explicit permission for support, when necessary to investigate abuse or a security incident, when required by law, or for internal operations where the data has been aggregated or de-identified. Google-sourced content is shared only with infrastructure providers needed to deliver KRBR, or when you direct a feature to send, export or process it. If you deliberately invoke an AI feature on Google-sourced workspace content, the relevant content may be processed by Microsoft Azure OpenAI solely to provide that requested feature and is not used to train a foundation model.
Google Limited Use disclosure. KRBR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google services in Settings → Integrations, revoke KRBR directly from your Google Account connections, or request deletion at support@karbar.app.
How we use data
- To provide, operate and secure the service you signed up for.
- To send transactional email — invoices you issue, booking confirmations, payment reminders, account notices. We send marketing email only with your consent, and every marketing message includes an unsubscribe link.
- To respond to support requests.
- To provide and measure public tools and templates, attribute the resource to the person who requested it, and follow up about that request. Promotional email is sent only when the separate marketing checkbox is selected.
- To meet legal obligations and enforce our Terms of Service.
AI features
KRBR includes AI features (drafting, search, briefings and document Q&A). When you use them, the relevant workspace content is processed by Microsoft Azure OpenAI Service under our agreement with Microsoft. Your content is not used to train third-party foundation models. AI features run only when you invoke them or enable them for your workspace.
Payments you receive from your clients
Client payments run through your own connected Stripe, PayPal or Square account. Your clients' payment card details are collected and processed by those providers under their privacy policies — KRBR never receives, stores or holds card numbers or funds. We store transaction metadata (amount, status, invoice reference) so your records stay in sync.
Who we share data with
We do not sell personal data. We share data only with the service providers required to run KRBR, each bound to process it solely for that purpose:
- Microsoft Azure — hosting and database (United States, East US region), and Azure OpenAI for AI features.
- Stripe — KRBR subscription billing; plus your own connected payment providers (Stripe, PayPal, Square).
- Email delivery providers — to send and receive the transactional email described above.
- Integration partners you connect — Google, Microsoft, Zoom, Zapier — under their own terms, only for the connection you authorized.
We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to previously collected data and we will notify you of any successor).
Data retention and deletion
Your workspace content is retained while your account is active. If you cancel, you may export your data first; we delete workspace content within 90 days of account closure, except records we must keep for legal, tax or security purposes. Public resource contact records are retained while they remain relevant to the request or our business relationship. You can request deletion at any time by contacting us.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted, integration tokens are stored encrypted and scoped per workspace, and passwords are stored as salted hashes. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you without undue delay.
Your rights
Depending on where you live (including under GDPR and the CCPA), you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. To exercise any of these rights, email us at support@karbar.app. We will respond within 30 days. We do not discriminate against you for exercising your rights.
If your information appears in another business's KRBR workspace (you are someone's client), contact that business first — they control that data, and we will support them in fulfilling your request.
Children
KRBR is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
If we make material changes, we will notify account holders by email or in-app notice before the changes take effect. The "Last updated" date above always reflects the current version.
Contact
Questions about privacy: support@karbar.app.