Who we are
Cobar is made and operated by Wallaroo Media, 78 W Center St, Provo, UT 84601. When this policy says "we", it means Wallaroo Media acting as the operator of Cobar. Questions go to [email protected].
What we collect
Account information: your name, email and role, provided by you or by the organization that invited you. Sign-in is handled by Clerk.
Workspace content: the requests you make, the brand, strategy and memory you record, the documents Cobar produces and the reviews and approvals recorded in your workspace.
Correspondence: information you send when requesting a walkthrough, support or help with a privacy request.
Connected-service data: the data each connection permits, read with that account's key or consent. Which services and what they permit is listed in the next section.
Meeting notes: when you connect Fathom or a Drive folder as a meeting source, Cobar can import and store transcript or notes text, meeting metadata and source version history. This content is available for review in Cobar.
Usage and diagnostics: sign-in events, pages visited and errors, used to run and improve the service.
Connected services
Connections can include Klaviyo, Shopify, Google Analytics 4, Search Console, Google Tag Manager, Google Ads, Google Business Profile, Gmail, Google Calendar, Meta, Google Docs and Drive, WordPress, HubSpot, Bing Webmaster, Microsoft Clarity, Fathom and Slack. The available data and permissions depend on the services you or an authorized workspace administrator connect.
Cobar reads from these services to produce the work you ask for and writes to them only when a person approves the action: a Klaviyo draft, a WordPress draft, a paused ad, a document in your Drive.
Google user data
Cobar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account and approve access, Cobar asks Google only for the permissions below and uses each one only as described. Cobar also receives the Google account's email address, to identify which account is connected and which account owns the documents Cobar creates.
Google Analytics 4 (read-only): Cobar reads report data and the list of properties the account can see, to write performance reports, audits and recommendations for the property you choose.
Search Console (read-only): Cobar reads search performance data and the list of sites the account can see, for search reports and audits.
Tag Manager (read-only): Cobar reads containers, tags and triggers, to check how a site's measurement is set up.
Google Ads: Cobar lists the Google Ads accounts the Google account can reach, including those under a manager account, so you can pick one, then reads campaign performance for the account you select, for ads reports. Google's Ads permission also allows changes; Cobar does not use it to change campaigns, budgets or bids.
Google Business Profile: Cobar lists the business accounts and locations the Google account manages, so you can pick the location that belongs to your account. Google offers one Business Profile permission, and it allows changes; Cobar does not currently make any change to your profile.
Google Docs in your Drive: Cobar creates Google Docs for finished work in the connected account's own Drive and writes the work into them. This permission reaches only files Cobar created; through it, Cobar cannot see or open other files in your Drive.
Other Google connections: separately, a workspace can connect Gmail and Google Calendar through their own sign-in, import meeting notes from selected Drive folders, or create Google Docs through its organization's own Google Workspace. These ask for their own permissions, which can allow changes as well as reading, and the limits on use and sharing in this section apply to them too.
How Google data is used: only to provide the features you use inside Cobar, such as the reports, audits, drafts and documents you ask for. Cobar does not sell Google data and does not itself use it for advertising or model training. Human access is limited by the Google policy, including its requirements for consent and its security and legal exceptions.
Who it is shared with: apart from the places you direct finished work to, such as a Klaviyo draft or a report you send, Google data is shared only with the service providers listed under Service providers, to process the work you asked for, for example the AI provider that drafts a report from your analytics. Google data is never sent to fal.ai or Higgsfield; images made from it are created only by Google's Gemini API and OpenAI's API, which do not use it to train models.
How it is stored: Cobar keeps the tokens Google issues for the connections above encrypted in its database, and uses them only to make the requests described here. Reports, documents and the evidence behind them stay in your workspace as described under Retention.
Disconnecting: disconnecting a Google service from an account stops Cobar using it for that account. The Google sign-in itself can stay connected while other services or accounts use it. When Google Analytics is disconnected and no other connection uses that sign-in, Cobar deletes the stored tokens and asks Google to revoke them. To end Cobar's access to a Google account completely, remove Cobar at myaccount.google.com/connections, or ask for deletion as described under How to delete your data.
Shopify
When a store is connected, Cobar reads products, collections, orders and inventory through the Shopify Admin API. Order data is minimized before use: names, emails, phone numbers and billing and shipping addresses are removed, and each customer becomes a pseudonymous salted reference. Removing an integration does not itself delete the work already stored in Cobar. Contact us using the deletion instructions below to request removal of stored data.
How we use it
To produce the work you ask for, grounded in your own data. To route that work to the right person for review and keep a record of who approved what. To deliver approved work to the destination you chose. To keep the service running, secure and improving.
Cobar does not currently sell personal data or use workspace content to advertise Cobar. We do not currently publish customer work or results as promotional examples. We will ask for separate permission before using specific customer material in a case study or other promotion.
Website measurement and communications
This website uses Google Analytics to count visits and see which pages are read. For visitors outside the European Economic Area, the United Kingdom and Switzerland it sets analytics cookies; for visitors in those regions it sets none and sends measurement pings without cookies or an identifier, which carry details such as the page address, the referring page, the browser type and the IP address, from which Google derives an approximate location. If your browser sends a Global Privacy Control signal, the site sets no analytics cookies wherever you are. You can also block Google Analytics with Google's browser add-on at tools.google.com/dlpage/gaoptout. Google Analytics keeps visit-level data for 14 months. Its advertising features and Google signals are turned off, and the site has no advertising pixels or session replay. Hosting infrastructure may process request information to deliver and protect the site. If you contact us, we use your message to respond to your inquiry.
The signed-in application is a separate service. Some of its pages use Google Analytics to understand how the app is used; when you are signed in, those visits carry a pseudonymous account identifier, never your name or email address. Errors are reported to Sentry with credentials and private links removed, together with a small sample of performance traces and profiles.
The app does not yet apply these regional defaults. Before we offer the app in the European Economic Area, the United Kingdom or Switzerland, we will ask users there for consent before Google Analytics loads in the app.
Before introducing new tracking or marketing uses, we will update this policy and provide the choices or consent mechanisms required for those uses. This policy does not give blanket permission for future tracking.
Service providers
Cobar uses DigitalOcean for hosting, Clerk for sign-in, Sentry for error reporting, Resend for transactional email, DataForSEO for search data and Firecrawl to fetch the web pages Cobar reads, such as your own website. Its AI integrations include Anthropic, OpenAI, Google, fal.ai and Higgsfield; which provider processes a task depends on configuration, connected accounts and fallback handling. Prompts, supplied context or images may be sent to the provider processing that task. Cobar's hosting and database are in New York, United States. Our service providers process data in the United States and other countries where they operate.
Cobar uses Google's Gemini API on the paid tier, under which Google does not use prompts or responses to improve its products. Images made with data from your connected accounts are created only by Google's Gemini API and OpenAI's API. fal.ai and Higgsfield are used only for creative work that carries no data from your connected accounts, such as images made from your logo, brand colors, the request you type and images you attach. Higgsfield is currently connected through a standard API account, not a confirmed enterprise no-training agreement. Its standard terms permit use of the content it receives for that work, and of its outputs, for model training. Provider retention and data use depend on the applicable account and agreement.
Retention
Workspace content is retained while your account is active, to provide your account and its work history. Stored content can include imported meeting transcripts and notes, source version history, and documents and evidence produced from connected-service data.
When an account is closed, or after we verify a deletion request, we delete its workspace content and the personal information we hold about you within 30 days, unless the law requires us to keep something longer.
Routine diagnostic and error logs are kept for no more than 30 days. Sign-in, access and security logs are kept for no more than 90 days. Records of who changed a workspace's settings or content are part of that workspace's history and are kept with it. Database backups expire within 30 days; deleted data can remain in a backup until it expires, and we do not restore it for ordinary use.
How to delete your data
Disconnect a service from its account page. A shared sign-in may remain available to other accounts. Use the provider's own permissions settings to revoke Cobar's access at the provider. To request deletion of a workspace, your own account or personal data Cobar holds about you, write to [email protected] from the address on the account. Justin Doyle handles privacy requests.
We may need to verify your identity and authority over a shared workspace. We will explain the outcome of your request, any applicable retention exceptions and next steps within the deadlines required by applicable law. Disconnecting an integration or receiving a platform acknowledgement is not confirmation that stored data has been erased.
Your rights
Wherever you live, you may ask what personal information we hold about you, and ask us to correct it, give you a copy you can take elsewhere, or delete it. Write to [email protected] from the address on your account. We will confirm your request, may need to verify your identity, and will respond within one month, or within 45 days where US state law sets that period. If a request is complex we may extend that time as the law allows and tell you why.
Who answers a request. When a business uses Cobar, it decides which accounts and data to connect and why. For that business's own customer and marketing data we act on its behalf, and requests about that data should go to the business; we will help it respond. For your Cobar account and our own operations, Wallaroo Media is responsible.
European Economic Area, United Kingdom and Switzerland. Under the GDPR and UK GDPR you also have the right to restrict or object to our processing, and to withdraw consent at any time where we rely on it. We process personal information to provide the service you or your organization signed up for (contract), to keep Cobar secure and improve it (legitimate interests), where you have agreed (consent), and to meet legal obligations. You can complain to your local data protection authority; in the UK this is the Information Commissioner's Office. Cobar is operated and hosted in the United States; before we offer Cobar in these regions we will put appropriate safeguards for international transfers in place.
California and other US states. Residents of California and of other states with comprehensive privacy laws have the right to know the categories and specific pieces of personal information we collect, the sources, our purposes and the categories of recipients; to correct and delete it; and to opt out of its sale or sharing for targeted advertising. The categories we collect are identifiers and account details, the content you provide, internet and usage activity in the app, and professional information about your role. We collect them from you, from your organization and from the services you connect, for the purposes in this policy, and disclose them only to the service providers listed here. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics about you. Because we do not sell or share personal information, there is nothing to opt out of today; if that changes, we will honor opt-out requests, including Global Privacy Control browser signals. Someone you authorize in writing may make a request on your behalf. We will not treat you differently for exercising these rights. If we decline a request, you may appeal by replying to our decision; if we deny the appeal, you may contact your state attorney general.
Product eligibility
Cobar product accounts are for adults aged 18 or older and are available only in supported regions. If you believe a child has provided personal information through a product account, contact [email protected] so we can investigate and address it.
Security
Workspace roles govern access to work and connected accounts. Current Wallaroo Media staff who work on a client's account can access that account's information in Cobar for service operations, support or security. This is distinct from ordinary workspace access. Access is limited to current Wallaroo Media staff and is reviewed once a quarter.
Changes to this policy
We will post changes here and update the date above. Material changes are announced to account owners by email.
Contact
Wallaroo Media · 78 W Center St, Provo, UT 84601 · [email protected]