Privacy Policy
Last Updated: March 16, 2026
KohiCorp is an API monitoring and error tracking service with AI-assisted analytics. This policy describes what data we process, why, and what controls are available to you.
1. Who We Are
KohiCorp ("we", "us", "our") is an API monitoring and error tracking service registered in the Netherlands (KVK: 42006840). When your organization sends data through our SDKs, your organization is the data controller and KohiCorp acts as data processor. For account data we collect directly (email, billing), KohiCorp is the controller. Data processing terms are set out in Section 4 of our Terms of Service.
2. What We Collect
We collect information you provide and information generated through your use of the Services.
- Account data: name, email address, account role (owner, admin, member), login credentials, and Stripe customer identifier (payment details are handled entirely by Stripe).
- Monitoring telemetry: endpoint paths, HTTP methods, status codes, timing metrics, client IP addresses, and HTTP request/response headers and bodies. Sensitive fields (passwords, tokens, API keys, email addresses) are redacted by the SDK before transmission.
- Error tracking data: error type, error message, stack traces, request context (URL, method, headers, body), and client IP address.
- AI assistant data: prompts, chart requests, and generated answers.
- Alert configuration: notification preferences, webhook URLs (Discord, Slack), and sensitivity settings.
- Device and usage data: IP address, browser information, pages visited.
3. How We Use It
We use data to provide monitoring, error tracking, dashboards, alerts, and AI insights; to authenticate users and prevent abuse; to process payments; to improve the Services; and to comply with legal obligations.
4. Legal Bases (GDPR)
Where GDPR applies, we rely on: performance of a contract, legitimate interests (security, fraud prevention, improvement), legal obligation, and consent where required.
5. AI Processing
KohiCorp uses AI to summarize monitoring data, explain anomalies, and assist with troubleshooting. We do not use Customer Data from any workspace to train general-purpose models. Any future data-sharing controls will be opt-in.
6. Sharing
We share data only when needed to operate the Services. Our sub-processors include: Hetzner (infrastructure hosting, Germany), Stripe (payment processing, USA/Ireland), Cloudflare (security and CAPTCHA, USA), Google (OAuth authentication, USA), and Amazon SES (email delivery, EU). All sub-processors are bound by contractual confidentiality and data protection obligations. We may disclose data when required by law or to protect rights and safety.
7. Retention
Monitoring telemetry: Free plan 14 days, Pro plan 90 days, then automatically deleted. Error tracking data: Free plan 7 days, Pro plan 90 days. AI assistant conversations: retained until account deletion. Alert history: 90 days. Dashboard configurations: retained until account deletion. Sessions: 30 days. Account and billing records: retained as required by Dutch tax law (up to 7 years). You may request deletion of personal data at any time, subject to legal retention obligations.
8. Security
We protect data with encryption in transit, access controls, and security monitoring. No system is perfectly secure, but we work to reduce risk and respond quickly to incidents. In the event of a qualifying data breach, we will notify the relevant authorities and affected individuals as required by applicable law.
9. Your Rights
Under GDPR (EEA/UK), you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. You may lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local supervisory authority.
Under CCPA/CPRA (California), you have rights to know, delete, correct, and opt out. We do not sell personal information.
To exercise any rights, email [email protected].
10. Cookies
We use strictly necessary cookies to operate the Services. No analytics or tracking cookies are used.
- __Secure-session: authentication session token. HttpOnly, Secure, SameSite=Lax. Duration: 30 days.
- kohi_project: remembers your last selected project in the dashboard. Duration: 1 year.
- oauth_state: temporary CSRF protection token during Google OAuth sign-in. Duration: 5 minutes.
11. International Transfers
Data may be processed outside your country. Where required, we use contractual safeguards for lawful transfers. DPA terms including transfer mechanisms are available on request.
12. Changes and Contact
We may update this policy from time to time. Material changes will be communicated by notice or email. The Services are not directed to children under 13.
For privacy questions or to exercise your rights: [email protected]. For general support: [email protected].