koza
ProductFor managersFor agenciesFor small bizPricingLog inStart your trial
Draft — not yet reviewed by a lawyer
This describes what the Koza software actually does, written from the codebase rather than from a template, so it is accurate about data flows. It has not been reviewed by a solicitor and does not yet cover the lawful bases, controller and processor roles, or international transfer mechanisms that UK and EU GDPR require. Do not rely on it as a legal instrument, and do not submit it for Meta App Review, until it has been reviewed.

Privacy Policy

Draft · 22 August 2026

Koza is a workspace for social media managers, agencies and small businesses. To do that it holds information about you, about your clients, and — if you connect them — about your social accounts. This page says exactly what, why, and how to get rid of it.

Who we areWhat we collectWhy we hold itConnected social accountsConnected Google accountOza and AI processingWho else sees itHow long we keep itYour rightsDeleting your dataHow it is protectedChanges

Who we are

Koza is operated by Nexity Agency. For the information you give us about your own account, we are the data controller. For the information you put into Koza about your clients, you are the controller and we are your processor — we hold it and act on your instructions, and it stays yours.

Questions, requests and complaints: hello@usekoza.com.

What we collect

CategorySpecificallyWhere it comes from
Your accountEmail address, full name, profile photo, job title, role in the workspaceYou, at sign-up — or from Google if you sign in with Google
Sign-inA password, stored only as a hash we cannot reverse; or a Google account identifierYou, or Google
Your clientsClient name, handle, industry, location, website, contact name and contact emailYou, as you set up each client
Your workPosts, captions, briefs, uploaded images and video, comments, projects, invoicesYou and your team, as you use Koza
Connected accountsAccess tokens, page and profile identifiers, usernames, granted permissionsMeta, when you connect Instagram or Facebook

We do not collect payment card details. We do not sell anything to advertisers, and we do not build advertising profiles.

Why we hold it

  • To give you an account and keep you signed in
  • To store the work you create and show it back to you and your team
  • To publish posts to the accounts you have connected, when you schedule them
  • To show you analytics for those accounts
  • To send you invites, magic links, confirmations and the mail you have asked for
  • To answer you when you get in touch

That is the whole list. If we ever want to use your information for something not on it, we will ask you first.

Connected social accounts

Connecting Instagram or Facebook is optional. Koza works without it. If you do connect an account, Meta gives us an access token and we request these permissions:

PermissionWhat we use it for
instagram_basicRead the profile so we can show you which account is connected
instagram_content_publishPublish the posts you have scheduled
instagram_manage_commentsShow comments on your posts inside Koza
instagram_manage_insightsShow reach, engagement and follower figures
pages_manage_postsPublish to a connected Facebook Page
pages_read_engagementRead engagement figures for that Page
pages_manage_metadataRead the Page details needed to publish
business_managementFind the Pages and Instagram accounts your business owns

We only read what those permissions cover, and only to show it to you inside your own workspace. We never post anything you have not scheduled, and we do not read your direct messages.

Disconnecting. You can disconnect an account at any time in Koza, which deletes the stored token. You can also revoke Koza from Meta directly, under Settings, then Business integrations. Revoking at Meta stops publishing immediately.

Connected Google account

Connecting Google is optional and Koza works without it. People connect it for two separate things, and Koza asks for them one at a time rather than in a single prompt, so granting one never requires the other.

Google Calendar

This is what scheduling runs on. When someone books a call through one of your booking links, Koza needs to know when the hosts are free and needs to put the meeting on their calendar.

PermissionWhat we use it for
calendar.readonlyRead your busy times so a booking page only offers slots when you are actually free, and show your events inside Koza
calendar.eventsCreate the event when someone books, and remove it if the booking is cancelled

For availability we ask Google only for free and busy periods, not the contents of those events. Koza does not read the titles, guests or notes of your other meetings to work out when you are free.

Google Drive

This is optional and separate. It exists so you can point Koza at a Drive folder you already have and work with the media in it without downloading and re-uploading everything.

PermissionWhat we use it for
driveList the contents of a folder you give us the link to, create folders, and rename or move files when you ask

Google classes this as broad access, and we would rather ask for less. The narrower permission only covers files an app created itself, which would defeat the point: the whole purpose is to open a folder that already exists. Koza only reads folders you have explicitly given it the link to. It does not browse, index or search the rest of your Drive.

Limited Use

Koza’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, and without exception:

  • We do not sell Google user data, and we never will
  • We do not use it for advertising, and we do not build profiles from it
  • We do not use it to train AI models. Calendar and Drive data is not sent to Oza or to any model provider
  • No human at Koza reads it, except where you have asked us for support, where the law requires it, or to investigate abuse or a security incident
  • We only use it to provide and improve the features you connected it for

Disconnecting. You can disconnect Google at any time in Koza, which deletes the stored refresh token. You can also revoke access directly at myaccount.google.com/permissions. Revoking at Google stops all access immediately, including the ability to add bookings to your calendar.

Oza and AI processing

Oza is the assistant inside Koza. When you ask Oza something, or use it to draft a caption or a digest, the text of that request — and the content it refers to — is sent to Anthropic, which runs the model, and the answer comes back to you.

  • This only happens when you use an Oza feature. Nothing is sent in the background
  • We do not send your password, your access tokens, or your billing details
  • Anthropic processes the request on our behalf as a sub-processor

If you would rather no content left Koza for this purpose, do not use Oza features; everything else works without them.

Who else sees it

We use a small number of companies to run Koza. Each only gets what it needs.

CompanyWhat they doWhat they hold
SupabaseDatabase and sign-inYour account, your clients, your work
VercelHostingRequests to the site, and server logs
AnthropicThe model behind OzaOnly what you send to Oza
MetaInstagram and FacebookOnly what you publish, and only if you connect an account
GoogleSign in with GoogleYour email address and name, if you use it

We do not sell your information. We do not share it with advertisers. If we are ever legally required to hand something over, we will tell you unless we are prohibited from doing so.

How long we keep it

  • Your account and your work: for as long as your workspace is open
  • Access tokens for connected accounts: until you disconnect, or revoke at Meta
  • Invoices and billing records: as long as tax law requires us to keep them
  • Server logs: a short operational period, then discarded

When a workspace is closed, we delete its contents. Backups roll off on their own schedule, so a copy can persist in a backup for a short window after deletion.

Your rights

If you are in the UK or the EU, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop using it in a particular way. Write to hello@usekoza.com and we will respond within one month.

If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first.

Deleting your data

Two ways, depending on what you want gone.

  • Just the social connection. Disconnect the account in Koza, or remove Koza at Meta under Settings, then Business integrations. The stored token is deleted
  • Everything. Email hello@usekoza.com from the address on the account and ask us to delete it. We will confirm, then remove your account, your clients and your work

How it is protected

  • Everything travels over HTTPS
  • Passwords are stored as hashes we cannot reverse
  • Access tokens for connected accounts are encrypted before they are stored
  • Access is scoped to your workspace, so other customers cannot see your data
  • Tokens are kept out of our logs

No system is perfect. If something happens that affects you, we will tell you what happened and what we did about it, rather than wait to be asked.

Changes

If we change how any of this works, we will update this page and change the date at the top. If a change materially affects you, we will email you about it rather than rely on you noticing.

Getting in touch. Privacy questions, access requests and deletion requests all go to hello@usekoza.com.
koza

The workspace for social media managers, agencies, and small businesses. Content, clients, invoicing, and AI — one tab.

Product
FeaturesPricingStart your trialLog in
Solutions
For agenciesFor small businesses
Compare
vs Rellavs HeyOrca
Company
AboutContactBrand system

Be the first to know about new features, tips, and updates from Koza.

© 2026 Koza Inc. All rights reserved.
Privacy PolicyTerms of Service