Last updated: August 24, 2026
Who this policy covers
Kroma provides software that helps businesses manage customer conversations across connected messaging channels. This policy applies to Kroma's website, dashboard, and connected-channel services.
A business using Kroma remains responsible for its relationship with its own customers. For customer messages processed for that business, Kroma acts on the business's instructions to provide the service.
Information we process
- Account and contact details provided by Kroma customers and their authorised team members.
- Messages, profile information, attachments, and conversation metadata received through channels a customer connects to Kroma, such as Instagram.
- Business information, knowledge-base content, orders, bookings, and settings a customer adds to the service.
- Technical, security, and usage information needed to operate, protect, and improve the reliability of the service.
How we use information
- Provide, secure, and support the Kroma service.
- Receive and send messages where a customer has connected and authorised a messaging channel.
- Generate customer-service responses using the configuration and information supplied by the business.
- Investigate faults, prevent abuse, meet legal obligations, and communicate important service updates.
Service providers and sharing
Kroma uses service providers to host the service, store data, provide artificial-intelligence capabilities, and connect messaging channels. Depending on the features a business enables, this can include Meta, OpenAI, Supabase, Railway, Google, Shopify, and payment providers.
We share information only as needed to provide the requested service, follow a customer's instructions, comply with law, or protect Kroma, our customers, and others from misuse or security threats.
Retention and security
We keep information for as long as needed to provide the service, resolve support or security issues, comply with legal obligations, and enforce agreements. Connected-channel credentials are stored with technical safeguards designed to limit access to authorised service operations.
No system is completely secure. Customers should protect their Kroma credentials and the administrator access to the social accounts they connect.
Your choices and requests
If you are a customer of a business using Kroma, contact that business first for questions about a conversation or its use of your data. Kroma customers can contact us for account and service requests.
For a data-deletion request, follow our Data Deletion Instructions.
Contact
For privacy questions, email hello@kroma.ai.
Questions about these terms or your data? Visit Contact Kroma.