← Back to Koby

Privacy Policy

Your privacy and trust matter to us

Looking for our usage terms? See the Terms of Service.

Quick Navigation

  • Overview
  • Data We Collect
  • How We Use Your Data
  • Data Sharing
  • Your Rights
  • Contact Us

Privacy Policy

🔒 Privacy-First Philosophy

Koby is built with privacy as a core value. We offer an offline mode where your data never leaves your device, and we give you granular control over what you share when using cloud features.

Effective Date: November 15, 2025

Last Updated: July 24, 2026

This Privacy Policy explains how Koby, a product of Luarai SAS (NIT 901.953.562, Cra 13 # 21-48, Chía, Colombia) ("we," "us," or "our"), collects, uses, and protects your personal information when you use our service. We are committed to transparency and compliance with GDPR, CCPA, and other privacy regulations.

1. Data We Collect

1.1 Data You Provide

  • Account Information: Email address and display name (plus profile picture when you sign in with Google). You can sign in with Google or with an email address and password; password credentials are stored and secured by Firebase Authentication, never by us directly.
  • Reading Data: Books you've read, highlights, annotations, vocabulary words (from your Kobo database)
  • Saved Web Content: Articles you explicitly save with the Koby browser extension or import features (their text, images, and source URL), stored in your private library so you can listen on any of your devices
  • Privacy Settings: Your visibility preferences and privacy controls
  • Social Interactions: Follows, likes, comments (if you use social features)
  • Subscription & Billing: If you subscribe to Koby Pro, your payment is processed by Stripe. We do not receive or store your full card number; Stripe handles that. We retain a Stripe customer/subscription identifier, your plan, and its status so we can grant and manage your Pro access.

1.2 Automatically Collected Data

  • Usage Data: Pages visited, features used, time spent (enabled by default; you can turn this off at any time in Privacy Settings, and it is always off on school accounts)
  • Device Information: Browser type, operating system, IP address (for security only)
  • Performance Data: Error logs, crash reports (for debugging)

1.3 Data We Don't Collect

When you use Koby without an account and with the on-device voice:

  • ❌ We do NOT upload your Kobo database to our servers
  • ❌ We do NOT track your reading activity
  • ❌ We do NOT share your data with anyone
  • ✅ Processing happens locally in your browser

The exception is the cloud features described in §1.4 (cloud voices, AI descriptions, translation, Study Mode): those work by sending content to servers when you choose to use them, whether or not you have an account where sign-in is required for them.

1.4 Cloud Audio & AI Features

Some features, such as the Listen audiobook player's cloud voices and AI descriptions of images, charts, and comic pages, work by sending content to our servers and trusted AI providers for processing. When you use these features:

  • Passages of your book's text are sent to our cloud rendering service (Google Cloud Run) to generate narration audio.
  • Images from your book may be sent to Google's Gemini AI to generate a spoken description.
  • This content is processed to produce your audio/descriptions and is not used to train third-party models or sold to anyone.

If you prefer to keep everything on your device, use the on-device voice, which performs all narration locally without sending your book to our servers.

1.5 Browser Extension

The Koby browser extension is a save button, not a tracker:

  • It only reads a page when you explicitly save it (toolbar button, keyboard shortcut, or right-click menu).
  • It does not collect your browsing history, track the sites you visit, or run any analytics.
  • What you save goes to your private library on your Koby account. Saved articles are private by default and never appear on your public profile unless you change their visibility yourself.
  • The extension stays signed in through your Koby account; it stores only its own session credentials and a local list of pages you've saved (used to show the "already saved" checkmark).

2. How We Use Your Data

2.1 Primary Uses

  • Provide Services: Display your highlights, enable exports, generate analytics
  • Improve Features: Understand usage patterns to build better features
  • Security: Detect and prevent abuse, fraud, or security threats
  • Communication: Send important updates (you can opt-out of non-essential emails)

2.2 Analytics

Unless you turn it off, we collect anonymous usage data using:

  • Google Analytics 4 (anonymized IP addresses)
  • Firebase Analytics (app performance monitoring)

We never include the text you read, highlight, type, or search for in analytics events. You can disable analytics at any time in Privacy Settings, and the choice takes effect immediately. Analytics is always disabled on school and institution accounts.

2.3 Community & Social Features (Opt-In)

Koby is private by default. Your profile, highlights, books, and reading activity are visible to no one unless you explicitly join the Community in Privacy Settings. Only after opting in do your per-item visibility settings apply:

  • Public: Anyone can see your content
  • Friends Only: Only users you follow who follow you back
  • Private: Only you can see your content

Leaving the Community (turning the setting off) immediately makes everything private again. School and institution accounts cannot join the Community at all.

3. Data Sharing & Third Parties

3.1 We Do NOT Sell Your Data

We will never sell, rent, or trade your personal data to third parties for marketing purposes. Period.

3.2 Third-Party Services We Use

  • Firebase (Google Cloud): Cloud infrastructure, authentication, database hosting
    • Privacy Policy: firebase.google.com/support/privacy
    • Location: United States (GDPR-compliant)
  • Stripe: Payment processing for Koby Pro subscriptions (United States). Stripe handles your card details directly under its own privacy policy.
    • Privacy Policy: stripe.com/privacy
  • Google Gemini & Google Cloud: AI image descriptions and cloud narration for the Listen feature (see §1.4), processed in the United States. Content is sent only to generate your audio/descriptions and is processed under the paid API tier, which Google states is not used to train its models.
    • Privacy Policy: policies.google.com/privacy
  • Free Dictionary API: Word definitions for flashcard exports (no personal data sent)

3.3 When We May Share Data

We may share your data only in these limited circumstances:

  • Legal Requirements: If required by law, court order, or government request
  • Safety: To protect the rights, property, or safety of Koby, our users, or the public
  • Business Transfer: If Koby is acquired or merged, your data may transfer to the new entity (you'll be notified)

3.4 Data Breach Notification

If a data breach affects your personal data, we will notify affected users, and any affected institution, within 72 hours of confirming the breach, with what happened, what data was involved, and what we are doing about it.

⚠️ Public Highlights Warning

If you choose to make highlights public or share them via links, anyone with the link can view them. Be mindful of what you share publicly.

Students, Schools & Children

Zero Student PII by Design

When Koby is used by a school or institution, we work on a simple principle: we never hold a student identity.

  • We receive no data from the school: no rosters, no student records, and no integration with student information systems.
  • School trials and deployments use accounts held by staff, shared for student use. We never receive a student's name, email address, or any other student identifier.
  • The basic listening features work without any account at all, processing files locally in the browser.
  • School and institution accounts have analytics disabled, cannot enable Community/social features, and use stricter content filtering on all AI features.

AI Features and Student-Typed Text

When Study Mode is used, the reader's typed answer is sent to Google's AI service to generate feedback. It is processed only for that purpose, is not stored by us, is not used to train models, and carries no account identifier in the request. On school accounts this processing uses the strictest available content-safety settings.

Children

Koby's consumer service is intended for users aged 13 and over (under-18s need parental consent; see our Terms). Younger students may use Koby only through a school's staff-managed deployment as described above, in which case we collect no personal information from the child at all: the account, and any data in it, belongs to the school staff member.

For Schools: FERPA and State Privacy Laws

Because we receive no student education records and no student PII, Koby's school model is designed not to trigger the vendor obligations of FERPA and state student-privacy laws (such as New York Education Law 2-d). Where an institution nonetheless requires a data privacy agreement before use, we will complete the institution's process. Contact us at luaraiteam@gmail.com. A plain-language summary for schools is available at koby.luarai.com/schools.html.

4. Your Rights (GDPR & CCPA)

You have the following rights regarding your personal data:

4.1 Access & Portability

  • Download Your Data: Export all your data as JSON/CSV from Privacy Settings
  • View What We Have: Request a full report of data we hold about you

4.2 Correction & Deletion

  • Update Information: Edit your profile, highlights, or settings anytime
  • Delete Specific Data: Remove individual highlights, books, or vocabulary words
  • Delete All Data: Use "Delete All Highlights" in Privacy Settings (irreversible)
  • Delete Account: Permanently delete your account and all data (irreversible)

4.3 Control & Consent

  • Granular Privacy Controls: Set visibility for profile, highlights, books, and stats individually
  • Opt-Out of Analytics: Disable usage tracking anytime
  • Withdraw Consent: Change any privacy setting or delete your account anytime

4.4 Data Retention

  • Active accounts: Data retained as long as your account is active
  • Deleted accounts: Data permanently deleted within 30 days
  • Backups: Backup data purged within 90 days of deletion
  • Optional auto-deletion: Set automatic deletion in Privacy Settings (1, 2, or 5 years)

Exercise Your Rights

To exercise any of these rights, visit Privacy Settings or contact us at:

Email: luaraiteam@gmail.com

Response Time: Within 30 days (GDPR requirement)

5. Contact Us

For questions, concerns, or data requests:

Koby Team · Luarai SAS

NIT: 901.953.562 · Address: Cra 13 # 21-48, Chía, Colombia

Privacy & Support: luaraiteam@gmail.com

Website: luarai.com

Response Time: Within 48 hours for general inquiries, 30 days for GDPR requests

Last Updated: July 24, 2026

Privacy Policy Version 1.3