Kora

Use cases

  • Procurement exceptions
  • Maintenance escalation
  • Invoice processing
  • Request triage
  • Customer onboarding
  • Order exception handling

By outcome

  • Governed AI Workflows
  • Operational Excellence
SkillsPricingBlog
Sign InStart Free
Use casesProcurement exceptionsMaintenance escalationInvoice processingRequest triageCustomer onboardingOrder exception handling
By outcomeGoverned AI WorkflowsOperational Excellence
SkillsPricingBlog
Sign InStart Free
Privacy

Kora Privacy Notice

This notice explains how RAW Labs SA handles personal data and operational records through the Kora website, Kora SaaS, Kora Cloud, and requested managed services.

Last updated: September 2, 2026

1. Scope And Roles

This notice covers the public Kora website, Kora SaaS, Kora Cloud, and RAW Labs-operated managed services. RAW Labs SA is responsible for the account, billing, security, website, support, and service-operation processing it determines.

Kora SaaS is a hosted Kora Platform service. When an organization uses Kora SaaS to process personal data in its projects, workflows, chats, files, or connected systems, that organization determines what it submits and how its workflows use the data. RAW Labs processes that customer content to provide and secure the hosted service and follow the organization's configured instructions.

With self-managed Kora, customer workflows run in customer-controlled infrastructure. Runtime data normally stays in that environment except where an enabled managed service, a participating Kora Cloud plan, or a support interaction sends specific records to RAW Labs. Enterprise and offline self-managed deployments do not participate in Kora Cloud telemetry or data contribution.

2. Data We Collect

Kora services may collect and store these categories:

  • account and identity records, including names, emails, roles, memberships, invitations, and WorkOS user identifiers;
  • authentication sessions, security cookies, access events, and account-security records;
  • hosted organization, member-allocation, subscription, billing-status, AI-credit, and usage records;
  • projects, workflow definitions, prompts, chat messages, uploaded files, model settings, and release or deployment configuration submitted to Kora SaaS;
  • workflow inputs, outputs, tasks, reviews, and runtime artifacts created or stored while Kora SaaS executes workflows and agent tasks;
  • integration configuration, encrypted credentials, authorization records, and provider identifiers needed to operate selected connectors, models, and gateways;
  • public-website analytics data, including page URLs, page and section views, calls-to-action and form interactions, browser and device information, approximate location, and pseudonymous identifiers or session recordings produced by enabled analytics services;
  • marketing attribution records submitted with a contact request, when starting a Kora Cloud Evaluation, or previously through a Kora Cloud account signup, including campaign link parameters, the referring site, the landing page, and any "how did you hear about us" answer you provide;
  • Kora Cloud billing mirrors, deployment records, install-session records, activation records, signed licenses, check-ins, usage counts, and token metadata;
  • sanitized operational telemetry and designated data-contribution records from participating Kora Cloud deployments;
  • managed-service records, logs, audit events, support notes, security records, and collected-data retention state.

3. How We Use Data

RAW Labs uses Kora service data to:

  • create, authenticate, secure, and support users and organizations;
  • store and retrieve customer content and execute workflows and agent tasks requested by the organization;
  • provide chat, authoring, release, deployment, human-review, integration, and artifact features;
  • send the content needed for a requested model call, connector action, or other integration to the selected provider;
  • process plan selection, subscriptions, AI-credit purchases and consumption, billing status, invoices, and account access;
  • issue, refresh, revoke, and inspect Kora Cloud licenses and authenticate self-managed deployment check-ins;
  • operate, protect, debug, monitor, maintain, and improve Kora services and software;
  • prevent abuse, enforce terms and service limits, and meet support, security, legal, accounting, and compliance obligations;
  • use designated contributed data for the additional purposes described in the Telemetry And Data Contribution section.

Where applicable law requires a legal basis, processing may be necessary to provide the requested service or perform a contract, support RAW Labs' legitimate interests in operating and securing Kora, comply with legal obligations, or follow consent for optional activities such as analytics cookies. The applicable basis depends on the processing purpose and context.

4. Customer Content, AI, And Connectors

Kora SaaS may send relevant prompts, instructions, context, files, workflow inputs or outputs, and tool requests to an AI gateway, model providers selected through Kora, connector providers, or external systems selected or configured by the organization. Those providers process the information under their own service terms and the configuration used by the organization or RAW Labs.

Secret values and supported connection credentials are stored in encrypted form, but they may be decrypted inside trusted service processes when needed to perform an authorized model or connector request. Kora does not intentionally place reusable credentials in browser-visible responses, authored workflow files, model prompts, artifacts, or chat transcripts.

Ordinary Kora SaaS customer content is not data-contribution content merely because it is hosted, stored, or processed to provide the service. Data-contribution terms apply only to records designated for that program as described below.

5. Telemetry And Data Contribution

A Kora deployment configured and eligible for telemetry or data contribution may send sanitized telemetry and designated data-contribution records to RAW Labs. This can include a self-managed deployment or a participating hosted regional service. Enterprise and offline self-managed deployments do not participate. Designated records currently include project source snapshots, chat transcripts, and runtime traces after applicable redaction rules are applied.

Data-contribution payloads are redacted before storage for known secret-shaped keys and common credential patterns. Redaction reduces risk but does not guarantee that payloads contain no confidential or personal data.

RAW Labs may use contributed data to operate, secure, debug, improve, train, evaluate, benchmark, and develop Kora and related products, including commercial products, datasets, models, benchmarks, insights, and other outputs derived from contributed data.

6. Service Providers And Locations

Kora services use providers for hosting, database and object storage, authentication, billing, workflow orchestration, worker infrastructure, AI gateways and models, connectors, email or other communications, logging, analytics, and operations. Current service providers include Vercel, Neon Postgres, WorkOS, Stripe, Temporal Cloud, Hetzner, Amazon Web Services (AWS), including AWS S3, OpenRouter and its downstream model providers, and configured connector providers.

Kora also uses Notion for contact-lead intake and configured logging and email providers for operations and signup notifications. Google provides Google Analytics 4, and Microsoft provides Clarity, for public-website analytics.

Provider processing locations depend on the regional service, selected integration, and provider configuration. Personal data may be processed outside Switzerland or the country where the user is located. Where required, RAW Labs uses a legally recognized transfer mechanism or other appropriate safeguard.

7. Cookies

Kora services use necessary cookies for authentication, login state, account security, and session continuity. Kora SaaS and Kora Cloud are separate applications and maintain separate browser sessions, even when they use the same identity provider.

The public website may also set a first-party kora-attribution cookie recording how your browser reached the site: campaign link parameters, the referring site, and the landing page. Like other cookies scoped to this site, a matching same-origin request may transmit the cookie. Consented marketing-page browser code maintains this record. The contact conversion and Kora Cloud Evaluation-start paths currently read it server-side. The Evaluation path stores bounded attribution fields in account audit metadata and includes them in the existing operator account notification email. Retired Kora Cloud account-signup routes also read it, so historical account audit metadata and operator notification emails may retain the submitted attribution. The separate Kora SaaS signup service does not receive this cookie. Current contact attribution and any "how did you hear about us" answer may be processed in Notion for contact-lead intake and application logs.

Kora does not forward the serialized attribution record to analytics or advertising providers. The current public page URL, including its UTM parameters, may be visible to enabled analytics providers under their consent operating mode. Attribution is incomplete, affected by your choices, and observational. It does not prove that a campaign caused a conversion. Cookie touches older than 180 days are discarded: 180 days is the browser attribution horizon and does not set the retention period for server-side contact or Kora Cloud account records. New browser capture requires a current analytics-consent grant. When that grant expires, the next marketing-page visit blocks new capture and clears the attribution record. Before that visit, a previously captured fresh cookie may still accompany a direct conversion until its separate touch horizon. Rejecting or withdrawing consent clears the record immediately.

Kora uses Google Analytics 4 and Microsoft Clarity to understand public-website usage and improve the product. Clarity provides interaction analytics such as heatmaps and session recordings, subject to the visitor's consent and the resulting operating mode. Google Analytics 4 starts with analytics storage denied and can send limited cookieless signals until you accept. Kora also sends Microsoft Clarity an analytics-storage-denied signal before you make a choice. The Clarity project is configured to permit its default cookies where applicable. As a result, outside the EEA, United Kingdom, and Switzerland it may set first-party Clarity and Microsoft-domain third-party cookies before you make a choice. Clarity requires consent before setting cookies for visitors in those regions.

Clarity's _clck cookie keeps a pseudonymous visitor identifier for this site, while _clsk connects page views into one session. If you accept, Kora grants analytics storage to both tools and they may use analytics cookies to connect activity across pages and visits. If you reject, Kora sends a denied signal and clears first-party analytics cookies on the Kora domain; limited cookieless measurement may continue. Advertising storage remains denied, and Kora does not use these tools for advertising or retargeting. You can change or withdraw your decision at any time using the Cookie preferences link in the site footer, and we ask again periodically so your choice stays current. Google Analytics 4 and Microsoft Clarity are third-party services governed by their respective privacy policies.

8. Retention

Retention depends on the record, service lifecycle, account or organization status, customer instructions, security needs, and legal or accounting obligations. Active Kora SaaS service records are normally retained while needed to provide the organization's service. Temporary workspaces, provider logs, workflow histories, artifacts, deleted organizations, backups, and support records may have separate retention and deletion lifecycles.

Account, organization, or deployment termination removes or limits customer access but may not immediately delete every record. Security, billing, audit, backup, legal-hold, abuse-prevention, license-enforcement, and operational records may remain for the period reasonably required for their purpose. Kora Cloud tracks retention state, export requests, deletion requests, approvals, legal hold, and internal notes separately from account or deployment status.

9. Your Choices And Requests

Depending on applicable law, you may request access, correction, export, deletion, restriction, objection, or portability of personal data, withdraw consent for future processing, or complain to a competent supervisory authority. Some requests may be limited by the rights of others or by security, accounting, legal, abuse-prevention, license-enforcement, and legitimate operational requirements.

If your personal data was submitted to Kora by a customer organization, that organization may be responsible for handling your request. RAW Labs will support the applicable process as required.

10. Contact

Privacy questions and requests can be sent to RAW Labs SA at privacy@raw-labs.com.

Kora

Hand work to AI without losing control. Every run is recorded, with hashed facts in the event feed. Use Kora-hosted SaaS or self-host with Enterprise.

Product
  • Skills
  • Blog
Solutions
  • Governed AI Workflows
  • Operational Excellence
Get started
  • Pricing
  • Start free
  • Talk to sales
  • Sign in
Legal
  • Terms
  • Privacy
  • Software license
  • Credits
© 2026 RAW Labs SA. All rights reserved.