Koza is a workspace for social media managers, agencies and small businesses. To do that it holds information about you, about your clients, and — if you connect them — about your social accounts. This page says exactly what, why, and how to get rid of it.
Koza is operated by Nexity Agency. For the information you give us about your own account, we are the data controller. For the information you put into Koza about your clients, you are the controller and we are your processor — we hold it and act on your instructions, and it stays yours.
Questions, requests and complaints: hello@usekoza.com.
| Category | Specifically | Where it comes from |
|---|---|---|
| Your account | Email address, full name, profile photo, job title, role in the workspace | You, at sign-up — or from Google if you sign in with Google |
| Sign-in | A password, stored only as a hash we cannot reverse; or a Google account identifier | You, or Google |
| Your clients | Client name, handle, industry, location, website, contact name and contact email | You, as you set up each client |
| Your work | Posts, captions, briefs, uploaded images and video, comments, projects, invoices | You and your team, as you use Koza |
| Connected accounts | Access tokens, page and profile identifiers, usernames, granted permissions | Meta, when you connect Instagram or Facebook |
We do not collect payment card details. We do not sell anything to advertisers, and we do not build advertising profiles.
That is the whole list. If we ever want to use your information for something not on it, we will ask you first.
Connecting Google is optional and Koza works without it. People connect it for two separate things, and Koza asks for them one at a time rather than in a single prompt, so granting one never requires the other.
This is what scheduling runs on. When someone books a call through one of your booking links, Koza needs to know when the hosts are free and needs to put the meeting on their calendar.
| Permission | What we use it for |
|---|---|
| calendar.readonly | Read your busy times so a booking page only offers slots when you are actually free, and show your events inside Koza |
| calendar.events | Create the event when someone books, and remove it if the booking is cancelled |
For availability we ask Google only for free and busy periods, not the contents of those events. Koza does not read the titles, guests or notes of your other meetings to work out when you are free.
This is optional and separate. It exists so you can point Koza at a Drive folder you already have and work with the media in it without downloading and re-uploading everything.
| Permission | What we use it for |
|---|---|
| drive | List the contents of a folder you give us the link to, create folders, and rename or move files when you ask |
Google classes this as broad access, and we would rather ask for less. The narrower permission only covers files an app created itself, which would defeat the point: the whole purpose is to open a folder that already exists. Koza only reads folders you have explicitly given it the link to. It does not browse, index or search the rest of your Drive.
Koza’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, and without exception:
Disconnecting. You can disconnect Google at any time in Koza, which deletes the stored refresh token. You can also revoke access directly at myaccount.google.com/permissions. Revoking at Google stops all access immediately, including the ability to add bookings to your calendar.
Oza is the assistant inside Koza. When you ask Oza something, or use it to draft a caption or a digest, the text of that request — and the content it refers to — is sent to Anthropic, which runs the model, and the answer comes back to you.
If you would rather no content left Koza for this purpose, do not use Oza features; everything else works without them.
When a workspace is closed, we delete its contents. Backups roll off on their own schedule, so a copy can persist in a backup for a short window after deletion.
If you are in the UK or the EU, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop using it in a particular way. Write to hello@usekoza.com and we will respond within one month.
If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first.
Two ways, depending on what you want gone.
No system is perfect. If something happens that affects you, we will tell you what happened and what we did about it, rather than wait to be asked.
If we change how any of this works, we will update this page and change the date at the top. If a change materially affects you, we will email you about it rather than rely on you noticing.
Connected social accounts
Connecting Instagram or Facebook is optional. Koza works without it. If you do connect an account, Meta gives us an access token and we request these permissions:
We only read what those permissions cover, and only to show it to you inside your own workspace. We never post anything you have not scheduled, and we do not read your direct messages.
Disconnecting. You can disconnect an account at any time in Koza, which deletes the stored token. You can also revoke Koza from Meta directly, under Settings, then Business integrations. Revoking at Meta stops publishing immediately.