Skip to main content
KoalaData
Discover Leaderboards
Log in Register

Privacy Policy

How KoalaData processes account, security, and report data

Last updated: 22 July 2026

1. Operator and hosting

The operator named in the Legal Notice is responsible for this service. KoalaData is hosted on infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The regular hosting location is within the EU/EEA.

2. Connection and security data

The web server keeps access logs for seven days. These logs may contain the IP address, request date and time, requested method and path, response status, referrer, and browser user agent. They are used to operate and troubleshoot the service and to detect and block bad actors, spam, denial-of-service attacks, and other abuse. Access logs are not used for advertising, profiling, or audience analytics and are deleted automatically after seven days.

KoalaData also uses the current network address temporarily in memory for rate limiting and abuse prevention. When a network address is stored with a session or security audit event, IPv4 addresses are reduced to their /24 network and IPv6 addresses to at most the first three groups. A shortened browser user agent may also be stored for session security.

Legal basis: Art. 6(1)(f) GDPR, legitimate interest in reliable service delivery, technical troubleshooting, secure operation, and abuse prevention.

3. Accounts and sessions

Account and session records are personal data when they relate to an identifiable user. For registered publishers, KoalaData stores a public username, account status, role, account timestamps, and an Argon2id password hash. It does not require an email address and never stores the password itself. Account data is retained until deletion is requested or it is required for account administration.

Login uses one essential HTTP-only session cookie. Only a SHA-256 hash of its random token is stored on the server. Sessions expire after the configured lifetime, 30 days by default, are invalidated on logout, and are removed after expiry. This cookie is required for the requested login, so no consent banner is shown for it.

Legal basis: Art. 6(1)(b) GDPR, providing the requested account, and Art. 6(1)(f) GDPR, account security.

4. CSV imports and project data

Uploaded CSV files, draft previews, project metadata, and derived observations are processed to provide project dashboards. Draft files expire automatically. Confirmed source files remain private to authorized project members and support import rollback. Public dashboards expose only approved project information and aggregate metrics, never the original CSV files.

Project links and logos are not sent to a third-party favicon service.

Legal basis: Art. 6(1)(b) GDPR, providing the requested dashboard and import features.

5. No advertising or client tracking

KoalaData does not use third-party analytics, tracking cookies, advertising networks, social embeds, or profiling. It does not use automated decision-making within the meaning of Art. 22 GDPR.

6. External links

GitHub, store, and publisher links are ordinary external links, not embedded trackers. Opening one sends the usual connection data to that provider under its own privacy policy.

7. Your rights

Under the GDPR, you may have rights to access, rectification, erasure, restriction of processing, data portability, objection, and lodging a complaint with a supervisory authority. Use the contact details in the Legal Notice for privacy requests.

© 2026 KoalaData. Open-source Chrome Web Store analytics.

Imprint • Terms • Privacy • GitHub (v1.5.17) • ♥ Support KoalaData