Kora
Platform

Industries

  • Manufacturing
  • Financial services
  • Life sciences and labs

By outcome

  • Governed AI Workflows
  • Workflow Compliance and Governance
  • Operational Excellence
SkillsPricingBlog
Sign InBook a DemoStart Free
Platform
IndustriesManufacturingFinancial servicesLife sciences and labs
By outcomeGoverned AI WorkflowsWorkflow Compliance and GovernanceOperational Excellence
SkillsPricingBlog
Sign InBook a DemoStart Free
Privacy

Kora Cloud Privacy Notice

This notice explains the personal data and operational records RAW Labs SA collects through Kora Cloud.

Last updated: July 21, 2026

1. Scope

This notice covers Kora Cloud, including the public website, account signup and login, billing redirects, installation sessions, deployment check-ins, license issuing and refresh, telemetry intake, data-contribution intake, and first-party managed services.

Local Kora deployments are customer-controlled. Customer workflow runtime data stays in the local deployment except where a Cloud-connected non-Enterprise plan, enabled managed service, or support interaction sends specific records to Kora Cloud. Enterprise and offline deployments do not participate in Kora Cloud telemetry or data contribution.

2. Data We Collect

Kora Cloud may collect and store these categories:

  • account and member records, including names, emails, roles, and WorkOS user ids;
  • authentication session records and security cookies used to sign in to Kora Cloud;
  • public-website analytics data, including page URLs, page and section views, calls-to-action and form interactions, browser and device information, approximate location, and pseudonymous identifiers or session recordings produced by enabled analytics services;
  • marketing attribution records submitted with a contact request or account signup, including campaign link parameters, the referring site, the landing page, and any "how did you hear about us" answer you provide;
  • billing mirror records needed to determine plan, subscription status, seats, and entitlement eligibility;
  • deployment records, install-session records, activation records, signed licenses, check-ins, usage counts, and token metadata;
  • sanitized operational telemetry from Cloud-connected non-Enterprise deployments;
  • data-contribution records from Cloud-connected non-Enterprise deployments, currently project source snapshots, chat transcripts, and runtime traces after redaction rules run;
  • managed-service and connector records, such as managed email requests and encrypted authorization records needed to operate Kora-provided connectors;
  • internal admin audit events, support notes, and collected-data retention state.

3. How We Use Data

RAW Labs uses Kora Cloud data to:

  • create and secure accounts;
  • process plan selection, checkout, billing status, and account access;
  • issue, refresh, revoke, and inspect signed Kora licenses;
  • approve installation sessions and authenticate deployment check-ins;
  • provide managed services requested by the deployment;
  • operate, protect, debug, and improve Kora Cloud and Kora software;
  • train, evaluate, benchmark, and develop Kora and related products using contributed data from Cloud-connected non-Enterprise deployments;
  • create commercial products, datasets, models, benchmarks, insights, and other outputs derived from contributed data;
  • enforce terms, license limits, and abuse-prevention controls;
  • handle support, security, legal, accounting, and compliance obligations.

4. Telemetry And Data Contribution

Cloud-connected non-Enterprise plans include telemetry and data contribution as part of Kora Cloud. Those deployments may send sanitized telemetry and data-contribution records to Kora Cloud. Enterprise and offline deployments do not participate in Kora Cloud telemetry or data contribution.

Data-contribution payloads are redacted before storage for known secret-shaped keys and common credential patterns. Redaction reduces risk but does not guarantee that payloads contain no confidential or personal data.

RAW Labs may use contributed data to operate, secure, debug, improve, train, evaluate, benchmark, and develop Kora and related products, including commercial products, datasets, models, benchmarks, insights, and other outputs derived from contributed data.

5. Service Providers

Kora Cloud uses service providers for hosting, database storage, authentication, billing, email or communications, logging, and operations. Current provider categories include Vercel for hosting, Neon Postgres for database storage, WorkOS for Kora Cloud authentication, and Stripe for checkout, billing, payment method, invoices, and customer portal flows. Kora also uses Notion for contact-lead intake and configured logging and email providers for operations and signup notifications. Google provides Google Analytics 4, and Microsoft provides Clarity, for public-website analytics.

6. Cookies

Kora Cloud currently uses necessary cookies for authentication, login state, account security, and session continuity. These include the Kora Cloud session cookie and short-lived login-state cookies used during the WorkOS sign-in flow.

The public website may also set a first-party kora-attributioncookie recording how your browser reached the site: campaign link parameters, the referring site, and the landing page. Like other cookies scoped to this site, a matching same-origin request may transmit the cookie. Consented marketing-page browser code maintains this record. Only contact and account-signup conversion paths read it server-side. The resulting attribution and any "how did you hear about us" answer may be processed in Notion for contact-lead intake, application logs, account audit metadata, and operator notification email.

Kora does not forward the serialized attribution record to analytics or advertising providers. The current public page URL, including its UTM parameters, may be visible to enabled analytics providers under their consent operating mode. Attribution is incomplete, affected by your choices, and observational. It does not prove that a campaign caused a conversion. Cookie touches older than 180 days are discarded: 180 days is the browser attribution horizon and does not set the retention period for server-side contact or signup records. New browser capture requires a current analytics-consent grant. When that grant expires, the next marketing-page visit blocks new capture and clears the attribution record. Before that visit, a previously captured fresh cookie may still accompany a direct conversion until its separate touch horizon. Rejecting or withdrawing consent clears the record immediately.

Kora Cloud uses Google Analytics 4 and Microsoft Clarity to understand public-website usage and improve the product. Clarity provides interaction analytics such as heatmaps and session recordings, subject to the visitor's consent and the resulting operating mode. Google Analytics 4 starts with analytics storage denied and can send limited cookieless signals until you accept. Kora also sends Microsoft Clarity an analytics-storage-denied signal before you make a choice. The Clarity project is configured to permit its default cookies where applicable. As a result, outside the EEA, United Kingdom, and Switzerland it may set first-party Clarity and Microsoft-domain third-party cookies before you make a choice. Clarity requires consent before setting cookies for visitors in those regions.

Clarity's _clck cookie keeps a pseudonymous visitor identifier for this site, while _clsk connects page views into one session. If you accept, Kora grants analytics storage to both tools and they may use analytics cookies to connect activity across pages and visits. If you reject, Kora sends a denied signal and clears first-party analytics cookies on the Kora domain; limited cookieless measurement may continue. Advertising storage remains denied, and Kora does not use these tools for advertising or retargeting. You can change or withdraw your decision at any time using the Cookie preferences link in the site footer, and we ask again periodically so your choice stays current. Google Analytics 4 and Microsoft Clarity are third-party services governed by their respective privacy policies.

7. Retention

Account or deployment termination removes customer access and active deployment control, but collected telemetry and data-contribution rows may remain as historical internal records. Kora Cloud tracks retention state, export requests, deletion requests, approvals, legal hold, and internal notes separately from account or deployment status.

8. Your Requests

You may contact RAW Labs to request access, correction, export, or deletion of personal data where applicable. Some records may need to be retained for security, accounting, legal, abuse-prevention, license-enforcement, or legitimate operational reasons.

9. Contact

Privacy questions and requests can be sent to privacy@raw-labs.com.

Kora

Self-improving agentic workflows with hash-chained evidence on every run. Sovereign, customer-controlled deployment by default.

Product
  • Platform
  • Reliability
  • Deployment
  • Where it runs
  • Blog
Solutions
  • Governed AI Workflows
  • Workflow Compliance and Governance
  • Operational Excellence
  • Manufacturing
  • Financial services
  • Life sciences and labs
Get started
  • Pricing
  • Start free
  • Talk to sales
  • Sign in
Legal
  • Terms
  • Privacy
  • Software license
  • Credits
© 2026 RAW Labs SA. All rights reserved.