Effective date: October 10, 2026
KORLIX AI (also called Korlix AI or KORLIX) is operated by Korlix INC. This policy explains the information processed through our app, website, AI tools, Social features and business workspaces, and the choices available to you. Features depend on your platform, app version, plan and enabled services; this policy covers the features you actually use.
For privacy requests, correction, access or deletion, contact support@korlixdeveloper.com. KORLIX is for users aged 16 and older. Users aged 16 or 17 need permission from a parent or legal guardian.
Business contact: Korlix INC, 7965 N High St, STE 350-41, Columbus, OH 43235, United States. For privacy requests, use support@korlixdeveloper.com and identify the account or feature concerned without sending passwords or sensitive identity documents.
Information and purposes
- Account and access: email address, account identifiers, authentication information including your latest successful sign-in time, profile settings, plan and entitlement status, and purchase or usage receipts. We use these to sign you in, manage access and allowances, prevent duplicate charges and respond to account requests. Social can display your last login to other members as described below.
- Content you choose: prompts, instructions, saved notes, documents, photos, audio, videos, generated outputs and feature-specific records described below. We process these to provide the feature, save requested work and produce exports.
- Support and safety: correspondence, reported content, report reasons, moderation decisions and relevant security records. We use these to investigate problems, enforce rules and address abuse.
- Technical information: IP addresses, device/app or browser information, request identifiers, diagnostic and usage events. Hosting, advertising and other providers also process technical information for delivery, reliability, security and their disclosed purposes.
Optional content and permissions are needed only for the features that use them. Do not include passwords, recovery codes, full card numbers or other people's confidential information in prompts, uploads or support messages. A business must have authority to provide its customers' and workers' information.
Third-Party AI Processing
When you choose an AI-powered feature and give permission in the app, Korlix may send the content you select to third-party AI providers that process it to produce the result you requested. Depending on the feature, those providers may include OpenAI, Kling AI, and MusicAPI.ai.
The content may include:
- typed text, questions, instructions, and prompts;
- images, photos, and camera content you select;
- files and documents you attach;
- voice, audio, speech, and transcripts used in LIVE CONVO; and
- agent training and long-term memories that you explicitly approve;
- selected business records, feature context and drafts authorized for the AI tool, such as inventory, bookkeeping, CRM, Workforce or FieldProof records; and
- selected live-chat questions or meeting content when you enable the corresponding AI feature.
Korlix asks for explicit permission in the app before sending these categories to a newly requested provider. You may decline, in which case the AI request is not sent. Non-AI portions of Korlix remain available. A new permission request is shown when the disclosure changes or when a new provider or data category is needed.
Saved permissions are scoped to your signed-in account on the current device or browser, including the approved provider and data categories. Open Korlix Account → Legal & Privacy → Reset AI-sharing choices on this device to remove those saved grants and be asked again. Resetting does not recall earlier requests, erase saved records, change another device, or stop active sessions or enabled server automations. Stop sessions and pause automations in their own controls.
Permission for an AI request is separate from publishing a Social post, enabling an email rule or sharing an export. Saved agent instructions and memories customize requests; the phrase “agent training” in KORLIX refers to these settings and saved knowledge, rather than a promise that KORLIX retrains a provider's underlying model. Provider processing and retention depend on the service and applicable terms, subject to the stricter Google API data restrictions below. Deleting a local item does not recall a request already sent to a provider.
Chat history, explicit memory and agents
Main-chat history is stored on your device. Explicit long-term memory notes are saved to your account so they can be used on another signed-in device when memory is enabled. Ordinary conversation does not automatically become long-term memory, and Social messages, attachments and agent memories are not automatically harvested into main-chat memory. You can review, edit, pause, delete or clear saved notes. Deleting a note stops future retrieval; it does not erase a past conversation or an AI request already in progress.
Agent tools store the instructions, selected knowledge, approved memories and workflow records you save. When used for an AI task, relevant approved content is included in the request. An agent’s forget or clear-memory control excludes that memory from future retrieval; the underlying stored record, including its text, may remain until separately deleted. This differs from deleting a main-chat memory note. Use an account or selected-data deletion request if you need retained agent records erased. Workflows and communication rules have separate controls: review their scope before enabling them. Local caches and downloaded files remain on your devices unless you remove them.
Brain Vault uses a separate password-based access control for saved private material. A vault icon, password or private-storage label is not a claim of end-to-end encryption or encryption controlled solely by your own key.
Social profiles, messages, groups and calls
Joining KORLIX Social is optional. Social stores your profile name, handle, biography, optional profession, profile photo, discovery/presence preferences, connections, invitations, blocks, forum content, messages and reports. Profile information and forum contributions are visible to other members according to the feature's access rules. Hiding your profile from People does not hide forum posts.
Online and last login: last login shows the latest successful sign-in to your KORLIX account recorded by our authentication service. Eligible signed-in Social members can see this timestamp where they may view your profile, subject to profile access, discovery and block controls. It is an account sign-in time, not a message-read receipt or the time you last opened Social. The separate online indicator reflects recent Social activity. In your Social profile settings, Show online status and last login controls both indicators. Turning it off hides them from other members; it does not delete authentication or security records. A screen that has not refreshed may show an earlier status.
Selected-connection online alerts: You can select accepted connections and choose a bell, short ring or silent alert. We store these choices and a cooldown timestamp to prevent repeated alerts, plus the latest short-lived online event for a selected connection. Events expire after 90 seconds and are removed during cleanup. Alerts respect the other person's online-visibility setting, blocks and active connection. Removing a connection or blocking removes the associated selections. Turning an alert off removes its active event; it cannot recall a notification already delivered. Browser background alerts require a separate opt-in for selected connections and browser notification permission. Lock-screen alerts do not include the connection's name. In-app sounds follow KORLIX sound settings; background sound and delivery follow browser and device settings. These alerts indicate recent activity, not a guarantee that someone is available.
Direct conversations require an accepted connection; groups require membership. Message content and any attachments offered by the app are available to authorized participants. Recipients can copy, download or share what they receive. Reports preserve the selected content snapshot for authorized moderation, even if the original is later removed. Social messages are not represented as end-to-end encrypted.
Auto Dump lets you choose whose conversation history changes. Only for me is the default: it hides a selected sent or received message from your own history across your signed-in devices, without removing it for other participants. For a message you sent, you can choose For everyone: it removes the message from both participants' conversation histories in a direct chat, or from all participants' histories in its group chat. You cannot use For everyone to remove another member's message. The selected scope applies after your chosen timer expires, even when your app is closed. An offline or already-open screen may retain a prior copy until it refreshes.
Auto Dump stops the affected participants from retrieving the message and new attachment links through the conversation; it does not physically erase the underlying stored message or attachment. It cannot recall screenshots, downloaded or exported files, copies shared elsewhere, or notifications already delivered. Previously issued temporary attachment links can remain usable until they expire. Report snapshots, necessary moderation/security records and backup copies are not automatically erased by a timer. Auto Dump is not secure destruction or a substitute for an account or selected-data deletion request; the retention rules below still apply.
Social albums store the photos, album titles and audience settings you save. Albums can be private, visible to accepted connections or visible to eligible signed-in Social members; check the audience before uploading. Album images are resized and re-encoded with embedded metadata removed. Temporary image links last up to five minutes. Removing access or an album cannot recall an already issued link, screenshot or downloaded copy.
Social audio/video calls use microphone and camera permissions and WebRTC connections. Call signaling and limited call metadata are processed to connect participants. Google's STUN service and, where configured, a Twilio TURN or other configured relay help establish connections; the other participant may learn your network/IP address. Social calling itself does not record or store the audio/video stream. A participant may independently record with another tool. Signal cleanup and stale-call cleanup occur during call termination or later activity, not on a guaranteed timer.
Free-play games with optional live camera or voice use the same Social call and permission controls. These games do not provide wagering or real-money payouts.
Use the in-app report and block controls for harmful content or unwanted contact. Blocking removes the connection; unblocking does not restore permission to contact. See the Community Guidelines and Child Safety Standards.
Recent Social call history is visible only to its participants for up to 30 days. It includes call direction, outcome and timing, but no stored call audio/video. Ended calls have their connection signals removed; stale calls are resolved during later activity or notification-worker cleanup. Supported clients can attempt connection recovery and let you minimize an active call within KORLIX. Browser and operating-system limits still control background media.
Browser call and message notifications are optional and require your device permission and a separate opt-in for that browser. We store the browser push endpoint, encryption keys, account binding and notification preferences to deliver alerts through its browser provider, such as Apple, Google, Mozilla or Microsoft. Alerts use generic text without a sender name or message contents. Subscriptions expire after 90 days without renewal and delivery metadata after seven days. Logout or turning notifications off clears that browser's binding; already delivered alerts or recipient copies cannot be recalled. Native operating-system incoming-call screens are not provided by the web release.
Social Discover news and videos
Discover stores the videos and captions you choose to upload, generated thumbnails, publication status, likes, saved items and reports. Uploads are private drafts until you publish them to eligible signed-in Social members. Unpublished drafts expire after 24 hours. Video processing removes embedded metadata and converts media for playback; this workflow does not send user videos to an AI provider. Publishing can expose people, voices, locations or other details visible or audible in the recording itself.
Blocking, suspension and removal restrict new feed and playback access. Media uses temporary links; already issued video links may work for up to 90 seconds, and buffered, downloaded or shared copies cannot be recalled. Removal hides videos immediately and queues storage deletion, with a minimum ten-minute delay and retries every thirty minutes. Account deletion also removes Discover metadata and queues video storage deletion. Reports preserve selected evidence for authorized moderation. Videos are not represented as reviewed before publication.
News editions use OpenAI web search to prepare short, original summaries of recent public reporting. News research does not receive your Social messages, videos, profile, likes or saved items. The feed shows source links, publication dates and checked times; opening a source takes you to its website and privacy practices. Cached editions are shared across members. Saved news remains available until unsaved or removed; unsaved cache items older than thirty days are eligible for deletion. The feed does not use a personalized political or behavioral profile.
THE RECEIPT WIZ
THE RECEIPT WIZ is a free, signed-in receipt scanner. Camera previews stay on your device until you choose to save a receipt. Saved photo or PDF originals, previews, merchant and purchase details, categories, descriptions and your corrections are stored privately in your account. Uploaded originals are retained as supplied and may contain embedded metadata; image previews are resized for viewing and analysis.
After your AI-processing permission, the selected receipt image preview or PDF is sent to OpenAI to suggest receipt details and a category. You can decline AI analysis and enter details yourself. We request no provider response storage; the provider's own data policies still apply. Automatic reading can be inaccurate, and you can review and correct its results.
The same private receipt record is available in the shared inboxes of your own Bookkeeping businesses and Tax Prep organizers. Edits remain synchronized; this does not share receipts with other users, post a bookkeeping entry or establish a tax deduction. Removing a receipt removes its original and details from these shared inboxes. Downloaded copies remain separate. Minimal daily scan counts are retained to enforce free-use allowances and prevent duplicate or abusive requests.
The Receipt Vault’s lock means these receipts require access to your KORLIX account; there is no separate Receipt Wiz vault password. A shared inbox is one record viewed in several tools, not additional backup copies. CSV exports contain extracted fields, not the original receipt images or PDFs. Download originals separately if you need an independent copy. No storage service or scanner guarantees that a receipt can never be lost.
These receipt details also apply when you launch Receipt Wiz from Bookkeeping or Tax Prep. Deleting the shared receipt removes it from all of those inboxes.
Where the independent receipt backup service is enabled, encrypted copies of saved receipt originals, previews, selected receipt details and recovery identifiers are stored privately with Backblaze B2 in the United States. These copies are used for operational recovery and verification. Backup snapshots are scheduled to expire approximately 30 days after capture, followed by the provider's deletion-processing interval. After a receipt is removed from active storage through the applicable deletion process, it is excluded from new snapshots; an older backup copy can remain until expiry. Restoring a backup must respect subsequent deletion requests and must not automatically reactivate deleted accounts or receipts. Backups are periodic and may be delayed or fail, so recent changes can be missing.
Bookkeeping and financial records
Bookkeeping stores the business details, income and expenses, journals, receipt files, bank-statement imports, reconciliation decisions and supporting notes you enter or upload. Receipt scanning sends selected receipt content to OpenAI only after AI-processing permission. Review suggested fields before saving. Statement imports and receipt links are records you supply; they do not grant automatic access to a bank account.
Financial documents can contain names, addresses, account details, purchase history and other financial information. Redact unnecessary identifiers before uploading. Posted financial history and corrections can be preserved as an audit trail; reversing an entry or removing an attachment link is not the same as erasing the original record. Ask support about deletion of associated files and account data. KORLIX does not provide banking, lending, investment execution or tax filing through these organizer tools.
When you choose Bookkeeping’s live voice assistance, selected business information, monthly totals, category or account names and requested draft information are sent to OpenAI after permission. The voice tool prepares material for your review; it does not retrieve original receipt files or independently post ledger changes. Review and save changes in Bookkeeping.
Contacts CRM, inventory and business communication
CRM stores contacts you enter or select for import, including names, phone numbers, email addresses, company details, notes, tags, follow-up dates and communication permissions. Supported imports include files you choose and, where supported, a contact picker. Import previews let you select records before saving; importing does not automatically authorize outreach or synchronize your email account.
CRM file imports do not connect to or read your Gmail or Outlook mailbox. A contact’s appearance in the Business Directory or another public source does not establish permission to send marketing.
Inventory and related business tools store product, supplier, customer, stock, order and transaction information, images and exports you choose to create. AI-assisted recognition and voice assistance send selected content and authorized inventory context to the disclosed AI provider after permission for the relevant categories. Business discovery and content tools can also process a business website, service area and search queries.
When you authorize email delivery or enable an email automation, approved recipient information, message content and delivery events are processed by our email service, Resend, and delivered to the selected recipients. Saved drafts and delivery/suppression records support the service and prevent unwanted outreach. CRM call briefs and call-permission records alone do not place a call. If you connect a separate publishing, advertising or communication service, selected content and authorization details are processed by that service for the action you enable.
KORLIX 2 MEET U and calendar connections
Scheduling stores the business’s appointment settings, availability, booking references, guest names and email addresses, appointment titles, times and any location or notes supplied for the booking. The business and authorized participants receive the details needed for the appointment. If you connect Google Calendar or Microsoft Outlook Calendar, account and calendar identifiers, calendar names, time zones, busy times and selected event details are processed to check availability and create or update appointments you authorize. Credentials are stored to maintain the connection; we do not request your Google or Microsoft password in KORLIX. Connecting a calendar does not provide KORLIX with access to your email inbox. Disconnect through the scheduling controls or revoke the provider’s authorization; events already created remain subject to that provider’s controls.
Funnels and advertising tools
Published funnels collect the fields a business chooses to request from visitors, such as contact details, an inquiry and communication preferences, and make submissions available to that business. The business is responsible for its form notice, purpose and any required marketing permission. Connecting Google Ads or Meta Ads allows the selected account and campaign operations you authorize; it is separate from Google Calendar or YouTube access.
When conversion measurement is enabled with the applicable permission, a funnel can send event identifiers and times, its public URL, browser information and advertising click identifiers to the selected advertising provider. The current Meta Lead integration sends event metadata and a Facebook click identifier when present; it does not send the submitted lead’s email or phone number. The Google integration uses available Google click identifiers. Browser, device and advertising-provider choices can affect measurement. Do not put private customer information into public page URLs.
Connected payroll
Where enabled for an eligible, approved US business, embedded payroll connects to Gusto. KORLIX processes company and administrator names, administrator email, provider company identifiers, connection and onboarding status, and the acceptance record, including account, email, time and IP information. Sensitive payroll, banking and tax-entry steps use the provider’s hosted forms. Gusto applies its own service and privacy terms and may retain required employment, payroll and tax records. Disconnecting or deleting a KORLIX account does not itself cancel payroll or erase provider-held statutory records. Availability depends on provider approval and configuration.
Workforce records and location
Workspace owners can approve recipients and enable Workforce email rules for recorded work summaries, missing updates and scheduled shift check-ins. New rules start paused. Draft review requires approval for each email; automatic mode sends within the owner-approved scope, weekdays, sending window and limits. Messages, approved recipient addresses and the owner’s verified reply address are processed by Resend. Messages include a link to stop future emails from that workspace. Provider acceptance does not guarantee delivery. Revoking a recipient or pausing a rule stops queued messages; it does not recall messages already handed to the provider. Message content is removed from Workforce automation history after 90 days; minimal event identifiers, consent and suppression records remain to avoid duplicate or unwanted messages.
Workforce also stores each company’s business profile, member types and job specialties, project/site assignments, task priorities, due dates and reported progress. Each company has its own workspace and role-based access.
Workforce tools store organization membership, worker identifiers, schedules, time entries, task updates, clock-in/out photos and precise location evidence requested or required by the workspace, and related approvals according to workspace settings. Authorized workspace managers can access records needed to manage that workspace. Submitted evidence is visible to authorized workspace managers. Photos are attendance evidence; this workflow does not perform facial identification or matching. Exceptions and disputed attendance require human review.
When you choose Talk to Rici in Workforce, voice audio/transcripts and authorized company, team, assignment, schedule and work-update context are sent to OpenAI after your AI-processing permission is checked. Ordinary members share only their own authorized records; owners and managers can share records from their workspace. Attendance photos, precise location stamps, member email addresses and invitation codes are excluded from these voice tools. Rici prepares unsaved drafts for on-screen review; it does not clock people in or out, approve time, change roles or send messages. The existing LIVE CONVO allowance applies.
Location is requested when you actively choose a location-based action, such as a clock-in check; Workforce does not continuously track workers in the background. Workforce location evidence may be sent to and stored by KORLIX and shown to authorized managers. Locator route planning can use location on your device; opening a route in Google Maps or Apple Maps sends the selected destination or route to that service. Location permissions can be changed in device settings. Workforce photo and location evidence expires after the workspace’s chosen period: 30 days by default, configurable from 7 to 90 days. Expired evidence is hidden from normal access and scheduled for hourly batch cleanup, which can be delayed by retries. Attendance and work-update records remain after the evidence expires. Recipient exports are separate copies.
Voice, meetings and recordings
Voice interactions, LIVE CONVO and enabled meeting assistance can process microphone audio, selected shared audio, transcripts, prompts, notes and generated responses. Content used for AI speech, transcription or assistance is sent to the disclosed provider after the applicable permission. If you start a recording in a feature that offers it, captured audio and generated voice included in that recording can be stored privately with recording metadata for later playback, export or removal.
Zoom Meeting Copilot uses connected meeting identifiers and selected meeting audio or captions to provide the assistance you enable. Before capture begins, it requests AI-sharing permission. Selected captions/transcripts and the selected agent’s approved training or memory context are sent to OpenAI for replies and generated voice. Connected raw meeting audio can reach KORLIX through the enabled meeting capture service. Browser or microphone permission and meeting participation alone do not replace this AI-sharing permission. Stop the assistant in its controls when you no longer want the session processed.
A meeting recording feature is separate from Social calls. Obtain every permission and participant consent required before recording or sharing a meeting. A recording may capture only the audio sources available to the selected mode, rather than every participant. Exports, transcripts and recipient copies must be managed separately.
The Pod and You
Podcast topics, preparation instructions, source references and recent discussion context are used to generate AI host speech. If you join with a chime-in, your selected microphone audio and transcript are sent to OpenAI after permission to respond in context. The hosts and voices are synthetic; source references do not guarantee that a statement is accurate or current. Playback, a smoke screensaver or leaving the app is not a guarantee that a recording has been saved or that a session has stopped. Use the podcast’s pause, stop and recording controls as applicable.
Connected telephone agents
When a configured telephone-agent service is used, providers such as Vapi and Twilio process the call connection and conversation. KORLIX processes call identifiers; selected conversation messages and the agent’s public knowledge can be passed to OpenAI to prepare replies. The current telephone bridge does not give callers access to your private Brain Vault or private account memory. Recording, transcripts and provider retention depend on the enabled service and its settings; do not assume that a call is unrecorded or immediately erased. The business operating the agent must give required caller notices and obtain required consent.
Cybersecurity Defender
Checks process the message or link text you submit to our backend. A deeper AI review sends that selected text to OpenAI after permission. Saved reports contain findings, extracted domain references, checklist progress and request fingerprints; findings can still reveal information about the submitted content. This tool does not automatically read your inbox, scan your device, inspect attachments or verify a website. Remove unnecessary personal details and secrets before submitting text.
Virtual Closet
Virtual Closet stores the person photos, clothing images, item names, categories, styling requests, and generated looks you choose to save in your account. These images are held in private cloud storage so you can reopen your closet on another signed-in device. Images are resized for this feature and location metadata is removed. Temporary image links expire after ten minutes.
When you request an AI try-on, your chosen person photo, clothing references, and instructions are sent to OpenAI. When you ask KORLIX for styling, wardrobe photos and item details are sent to OpenAI to suggest an outfit. The app checks your AI-processing permission before these requests. You can remove individual images and looks from Virtual Closet or request account deletion. Removing source clothing or a person photo does not automatically remove previously generated looks; those can be removed separately.
Contract Radar
Contract Radar saves your business profile, selected opportunities, pasted solicitation text, notes, pipeline stages, searches, and AI reviews privately in your account. When you ask KORLIX to discover opportunities, your services, service area, NAICS codes, and search focus are sent to OpenAI and may be used in web searches. Bid reviews send your business profile and the selected opportunity text to OpenAI. We request AI-processing permission before these actions.
You can remove saved opportunities and their associated reviews, or clear your Contract Radar data, including search history, from the Business tab. Removing a saved opportunity does not remove it from a prior search result; clear the radar to remove that history. Contract Radar does not automatically submit proposals or contact buyers. Original buyer notices and amendments should be checked before acting on a search result or draft.
PDF import processes the document temporarily to extract text without an AI request. The raw PDF is not retained by Contract Radar; extracted text is saved only when you apply and save it. Scanned documents require separately recognized text. Monitoring is off until you enable it. We save your chosen schedule, timezone, saved-search filters and in-app alerts. Deadline reminders use saved opportunities. When the direct SAM.gov connection is configured, selected search filters and notice identifiers are sent to SAM.gov for matching and updates; these checks do not use AI credits. Other regions use on-demand official-source search. You can disable monitoring, remove saved searches, clear alerts or clear all Radar data.
AI Visibility
AI Visibility stores your business name, website, service category, target market, optional business facts, discovery questions, reports, completed actions and any outcome notes privately in your account. After AI-processing permission, discovery questions are sent to OpenAI with web search. Your business details, public website and sampled answers are also sent to OpenAI to prepare website observations and content drafts.
Reports contain limited OpenAI API answer samples and source links; they do not measure every AI platform or guarantee rankings or bookings. Outcome counts are entered by you and are not automatically attributed. You can remove individual reports or clear your AI Visibility data in Business setup. Content drafts are prepared for your review and are not automatically published.
Study Studio lessons and progress
Study Studio stores your topic, learning settings, generated lesson, flashcards, quiz answers, reading progress and flashcard review dates privately under your signed-in account. After your AI-sharing permission, the topic and any pasted reference notes are sent to OpenAI to prepare the study pack. Ready-made starter lessons and practice do not make AI requests. KORLIX requests no provider response storage; OpenAI's own data policies still apply.
Pasted source notes are removed from the Study Studio job when preparation completes or fails. Interrupted jobs are marked failed and source notes removed on the next Study Studio access after the recovery window. The generated pack can still contain information derived from those notes. Deleting a pack removes its private content and progress; minimal usage and request receipts remain to prevent repeated charges or allowance resets. Deleting your account removes Study Studio data. Exports remain under your control. Review dates are in-app suggestions, not scheduled notifications. Study packs are learning aids, not verified course material or certification.
App Studio projects and previews
App Studio privately stores your app ideas, design settings, structured app definitions and the last 30 saved versions under your signed-in account. When you request an AI build or revision and allow AI sharing, your idea, instructions and current app definition are sent to OpenAI. Starter templates, manual styling, previews and exports do not require an AI request.
Interactive previews use fictional sample records. Entries you type into a preview stay temporarily inside that preview and are not saved to your KORLIX project or sent for AI processing. Downloaded apps can store their entries in the same browser when local storage is available; these files are local prototypes and do not provide secure accounts or a shared database. Keep sensitive production data out of prototypes. Deleting a project removes its saved ideas and versions while a minimal build/usage receipt remains to prevent duplicate charging. Account deletion removes project data and receipts; exported copies remain under your control.
App Studio customer portals
A separately published customer portal hosts shared requests, replies, status updates and private PDF/photo attachments using your saved project's branding. It does not publish arbitrary prototype code or sample records. Customers sign in with a verified KORLIX account and see their own requests; the portal owner and authorized staff can access the portal's requests. Invitations store the intended email, role and expiry, and must be accepted with that verified email. Creating an invitation does not send an email.
Portal launch links use temporary single-use codes tied to your KORLIX session. Portal sessions expire after one hour and are checked against current account, membership and publication status. Attachment images are resized and metadata removed; PDF content is retained as uploaded. Portal content is not sent to AI by this workflow. An optional external checkout link opens the owner's chosen payment provider, whose terms and privacy practices apply; KORLIX does not process or verify that payment.
Unpublishing stops member access while retaining portal records. Removing a request, file or project revokes its access and queues associated stored files for deletion; failed storage cleanup is retried. Deleting an owner's project or account removes that portal and its records. Deleting a customer's account removes their access, but requests, replies, email details and files shared with another portal owner may remain in that owner's business records. Contact the portal owner or KORLIX support about those records and recipient copies.
Live Studio shows and rehearsals
Live Studio privately stores saved show settings, generated captions, source references, run status and usage receipts. After your AI-processing permission and explicit rehearsal start, selected topics and text are sent to OpenAI for research, content review and AI-generated speech. Private rehearsal videos are stored in your account and opened through temporary playback links. Removing a saved show removes its current private rehearsal and show history; minimal start receipts remain to enforce usage limits.
YouTube connections and broadcast data
KORLIX Live Studio uses YouTube API Services. You authorize a channel you own or are permitted to manage and confirm its identity before use. We access and store its name and ID, broadcast and stream identifiers and status, selected live-chat questions, and related show history to display your connection, run shows you start or schedule, and respond to chat. Authorization credentials are encrypted; we do not collect your Google password. Google handles sign-in and its own data practices under the Google Privacy Policy.
A separate confirmation starts or schedules an unlisted show. Anyone with its YouTube link can watch. Generated voices, graphics and captions are transmitted to YouTube. After your AI-processing permission, selected live-chat questions are sent to OpenAI for moderation, research and a host response during the show; they are not used by KORLIX to train general-purpose AI models. Leaving the app does not stop the server-run show. Use End show to request a stop. YouTube broadcasts and copies remain on YouTube and are managed there.
Disconnect YouTube in Live Studio to withdraw KORLIX access, cancel queued YouTube shows and request running broadcasts to stop. We delete the locally stored authorization credentials and YouTube-derived channel data and history as soon as possible, within 7 calendar days of disconnection or a verified request to delete the associated YouTube API data, including an account-deletion request. This provider-specific deadline applies even if unrelated account records need separate handling. You can also revoke access in your Google account permissions; associated YouTube API data is deleted as soon as possible and within 30 calendar days of that revocation. Stored YouTube API data is refreshed or deleted within 30 days. These YouTube-specific limits take precedence over general retention and deletion instructions elsewhere in our policies. Independently entered show settings, private rehearsal videos and non-YouTube usage receipts are managed separately through the available KORLIX controls. For privacy questions or deletion requests, contact support@korlixdeveloper.com.
Limited use of Google API data
Google user data from Calendar, YouTube and other non-advertising integrations, including information derived from it, is used only to provide or improve prominent, user-facing features you choose. We do not sell that data, use or share it for advertising, or use it for lending or credit decisions. An advertiser’s separately authorized Google Ads account and campaign operations, and permitted funnel conversion events, are described in the advertising section; Calendar and YouTube data are not repurposed as advertising inputs. Transfers are limited to consented feature delivery or improvement, security, legal requirements, or an ownership transfer with your prior explicit consent. Human access requires your permission to review specific data, a necessary security investigation or a legal obligation. These restrictions apply to our staff, contractors and providers and override broader sharing or provider-use language elsewhere in this policy. Our use and transfer of Google API data is subject to the Google API Services User Data Policy, including its Limited Use requirements. For Google Workspace data, our use and transfer also adheres to the Google Workspace API User Data and Developer Policy. Google API data is not used to train general-purpose AI or machine-learning models.
Music Studio creations and drafts
Music Studio privately stores your saved draft, submitted ideas, lyrics, settings, favorites and generation status under your signed-in account. After your AI-sharing permission, generation ideas and lyrics are sent to MusicAPI.ai. KORLIX retains returned track metadata and provider-hosted audio links; it does not guarantee permanent storage of those audio files. Download audio you want to keep.
Generation requests reserve part of your monthly Music Production allowance and become used allowance when accepted by the provider. Interrupted submissions can remain reserved while their outcome is uncertain; retries recover the same request. Removing a finished creation clears its saved idea and track links in KORLIX while keeping a minimal request and usage receipt. It does not delete files retained by the music provider or copies you downloaded or shared. Account deletion removes the KORLIX draft and job records.
Tax preparation organizer
Tax Prep stores your selected tax year, expected filing status, state selections, checklist statuses, review notes and snapshots of the KORLIX Bookkeeping businesses you link. These records are private to your signed-in account. This version does not collect original tax forms or provide fields for Social Security numbers, tax identifiers or banking credentials. Keep those details out of free-text notes.
Linked books are copied when you create or explicitly refresh an organizer; changing source records requires a new review before export. Tax Prep’s organizer does not send organizer data for AI processing, calculate tax or file returns. If you separately launch Receipt Wiz from its shared inbox, the receipt-scanning and AI-permission rules above apply to that selected receipt. PDF and CSV packets are downloaded only when you request them, and any copies you share remain under your control. Removing an organizer deletes its saved checklist, notes, book snapshots and request receipts; it does not delete your Bookkeeping records. Saved organizers remain until you remove them or request account deletion.
BabyBlend creative portraits
BabyBlend privately stores the adult reference photos and fictional child portraits you choose to save, plus generation choices and request receipts. Reference photos are resized and location metadata is removed; original uploads are not retained. Temporary preview links expire after ten minutes. Only use photos of adults with their permission.
When you create a portrait, the two selected references and age/style choices are sent to OpenAI after your AI-processing permission is checked. KORLIX uses them for an imaginative portrait, not a genetic prediction, parentage test or medical assessment. Saved photos remain in your account until you remove them or request account deletion. Removing a reference does not remove existing portraits; those can be removed separately. Generation receipts are retained to prevent duplicate credit charges. Downloads and any copies you choose to share remain under your control.
FieldProof job records and evidence
FieldProof stores job details, customer/site information, technician notes, readings, priorities, due dates, work stages, punch-list items, checklists, reported customer approvals, original photo files, reduced-size previews and activity records privately for the signed-in account. Original files can include embedded metadata. Server upload times and SHA-256 hashes describe received files; they do not establish capture time, location, authenticity, safety or quality of work.
When you approve KORLIX photo review, job information and photo previews are sent to OpenAI to prepare documentation observations and working drafts. AI findings do not automatically change checklists or approve jobs. Approval records are technician declarations, not independently authenticated signatures. You can export reports and originals through device controls. Separately, enabled FieldProof email automations can send approved PDF reports, selected photo previews, completion follow-ups and supervisor summaries through Resend to authorized recipients. Review recipients, content and the rule’s sending scope before enabling it. Pause the rule to stop future queued actions; delivered messages and attachments cannot be recalled. Deleting a job removes its retained photos, reviews and activity; completed AI usage is not refunded.
When you choose Talk to Rici in FieldProof, voice audio and transcripts, requested job context, readings, checklist status, evidence metadata and unsaved drafts are sent to OpenAI after your AI-processing permission is checked. Rici uses those records to answer questions and prepare editable drafts. This voice workspace does not inspect the photo files or automatically save changes, approve work, resolve issues or send reports. Review and save drafts in FieldProof. The conversation uses your existing LIVE CONVO allowance.
Providers, advertising and sharing
The providers involved depend on the feature you actually enable. This list identifies the principal services and their roles; it does not mean every provider receives every user’s records.
| Provider | Purpose and information involved |
|---|---|
| Render and Supabase | Application hosting, authentication, databases, file storage and operational/security information needed to run KORLIX. |
| Backblaze B2 | Private, encrypted operational recovery copies where independent backups are enabled: receipts, account and application records, business records, saved content and files, and the metadata needed to restore access and respect deletion requests. Backup retention and deletion are described in the Receipt Wiz and Retention and deletion sections. |
| OpenAI | Selected prompts, images, documents, voice/transcripts and authorized feature context for AI responses, speech and analysis after permission. |
| Kling AI and MusicAPI.ai | Selected video references and generation instructions, or music ideas, lyrics and settings, for the requested media. |
| Resend | Authorized recipient/reply addresses, email content, selected attachments and delivery information. |
| Google, Microsoft and Zoom | Connected calendar, YouTube or meeting data for the specific service you authorize; Google’s separate data restrictions apply. |
| Vapi and Twilio | Configured telephone-agent services or Social call relay, including the connection information and conversation needed for that service. |
| Stripe and applicable app stores | Checkout, subscriptions and entitlement validation. KORLIX receives account, transaction and purchase-status references; its purchase forms do not collect full payment-card details. |
| Google AdMob, Google Ads and Meta Ads | Advertising and permitted measurement in the applicable Android experience or connected business campaign/funnel. |
| Gusto | Eligible connected payroll onboarding, company/administrator information and provider-hosted payroll operations. |
Ad-supported Android experiences use Google Mobile Ads (AdMob). The SDK can collect and share IP addresses (including inferred approximate location), advertising/app identifiers, ad and app interaction information, and diagnostics for advertising, analytics and fraud prevention. The data depends on SDK settings and your device/privacy choices. Where required, the app requests advertising consent through Google’s consent flow and offers its available privacy-options form. Advertising ID controls are available in Android settings. See Google's advertising information. AI prompts and business records are not supplied to AdMob as ad-targeting inputs by these KORLIX features.
The Google API data restrictions above take precedence for Google and YouTube data. For other data, we disclose information to providers needed to operate the selected service, to people you choose to contact or share with, and to authorized workspace members or Social participants as described above. We may also disclose relevant information to comply with a legal obligation, address security or abuse, protect rights, or manage a business transfer with appropriate safeguards. A provider's role and its own use of information depend on the applicable service terms; not every transfer has the same meaning as “sharing” in Google Play's Data safety form.
Provider systems and recipients may be in countries other than yours. Applicable safeguards and your rights depend on the relevant service and law. External links, recipient copies and independently used third-party accounts are subject to those services' own privacy practices.
Device storage and permissions
The app and website use browser or device storage for sign-in/session state, settings, saved AI-sharing choices, local chat or preview data and feature caches. Notifications require a separate device/browser permission; camera, microphone, photos and location permissions support the feature you choose. You can change permissions in device or browser settings. Clearing local storage may sign you out and remove local preferences or unsynchronized records; it does not delete cloud records or cancel subscriptions. Advertising and connected campaign measurement have the separate choices described above.
App feedback and store reviews
KORLIX uses a local counter to decide when to invite feedback or request an app-store review after three cumulative hours of signed-in active use. The counter and a flag recording the automatic invitation or request are stored separately for each account on that browser or device. They are not uploaded by this feature or synchronized across devices. Counting pauses while the app is hidden, in the background or locked, while its screensaver is active, and after two minutes without interaction. The counter does not record the contents of your typing. An invitation waits for a suitable pause rather than interrupting a tool, call or form. Clearing app or browser data can reset the counter and invitation flag.
Private app feedback is voluntary. If you send it, KORLIX support receives the message, your chosen topic, your account identity and the usual platform, device and request information used to investigate support reports. This form does not automatically attach your conversations or screenshots. Feedback is held in the restricted support queue under the support, security and retention rules in this policy; it is not posted as an app-store review. Do not include passwords, payment-card details or unnecessary sensitive information. You may contact support about access, correction or deletion.
Store reviews are separate and voluntary. On supported native builds, Apple or Google controls whether its review interface appears; a request does not guarantee a prompt. The review interface does not tell KORLIX whether you submitted a review or what rating you selected. Available store links on the web open the external store. A review you submit is handled under that store's own privacy, publication and account rules and may be public. Providing private feedback, declining a request or expressing dissatisfaction does not prevent you from leaving an honest store review.
Business workspaces and responsibilities
Workspace owners decide which authorized workers, customers or contacts to include, why their business uses the records, who receives them, and which rules or integrations to enable. Owners must provide appropriate notices and obtain the authority or consent required for employment, customer communications, recording and sensitive information. KORLIX provides the selected service and also processes account, billing, reliability and security information for its own operations. If your request concerns an employer’s or another business’s records, contact that business or KORLIX support so the request can be directed to the responsible party. Access to a workspace is not permission to use its data for unrelated purposes.
Retention and deletion
We keep account and saved feature data while it is needed to provide the service, until you use an available removal control or a verified account-deletion request is fulfilled, subject to the exceptions below. Temporary links expiring does not itself delete the underlying file. Individual feature deletion may leave minimal usage, billing, audit or safety records as described in this policy.
| Information | What happens |
|---|---|
| Saved receipts, files and projects | Remain until removed through the available feature controls or a verified deletion request is fulfilled, subject to applicable exceptions. |
| Workforce photos and GPS evidence | 30 days by default, adjustable from 7–90 days; access expires before scheduled storage cleanup finishes. Attendance records remain. |
| Social Auto Dump | After your chosen period, Only for me hides the message for you; For everyone hides your sent message for all participants in that conversation. The underlying message and attachment remain stored until separately removed under applicable deletion and retention rules. Reports, recipient copies and backups are not erased by the timer. |
| Social call history and browser push | Call history: up to 30 days. Push subscriptions: 90 days without renewal. Push delivery metadata: seven days. |
| Agent forget/clear memory | Stops future retrieval; retained underlying memory text needs separate deletion. Main-chat note deletion is a different control. |
| Workforce automation email content | Removed from automation history after 90 days; limited consent, suppression and deduplication records remain. |
| FieldProof email records | Message bodies and report attachments become eligible for cleanup after 30 days; related history is eligible 30 days after redaction. Delivery and suppression records can have different periods. Scheduled cleanup and retries may delay removal. |
| YouTube API data | The specific seven-day deletion and 30-day revocation/refresh rules in the YouTube section take precedence. |
- Account and saved content: delete individual items where supported, or request deletion of your account and associated data. This includes stored business documents, Social data, memories, studio projects and recordings within the request's applicable scope.
- Legal, financial and security records: retain only the information needed for an applicable legal obligation, unresolved payment/dispute, fraud prevention or safety investigation, for as long as that specific reason requires. Access is restricted and retained information is not kept merely to continue a closed account's ordinary service.
- Backups and provider copies: active-system deletion may precede expiry of backup copies or provider-side deletion. Backup copies remain subject to restricted use and the relevant expiry process; they are not a reason to reactivate a deleted account. Support can explain applicable retention exceptions and outstanding provider requests for your case.
- Other people's records and your exports: sent messages, legally required organization records and copies downloaded or shared by recipients may not be fully recallable. We remove or de-identify your account-associated data where applicable without erasing another person's independently held information.
Where wider independent backups are enabled, KORLIX stores encrypted database recovery copies and separate copies of uploaded files privately with Backblaze B2 in the United States. These can include account and authentication records, access plans and purchased balances, bookkeeping and inventory records, contacts and bookings, saved agent memories, Social content, Workforce and Fieldproof evidence, and recovery/deletion metadata. Access is restricted to authorized operational recovery and verification. Database captures are scheduled daily and after service restarts; file and deletion-control captures are scheduled approximately hourly. Successful backups can lag behind current activity when a service is unavailable or a run fails.
These independent application snapshots are scheduled to expire approximately 30 days after capture, followed by the provider's deletion-processing interval. Active-system deletion excludes removed data from subsequent captures; older encrypted copies may remain until expiry. Restores must reconcile later deletion requests, hidden-message controls, revoked access and completed transactions before restored data or automated actions become available. YouTube Live Studio connection and activity rows are excluded from this longer-retention application archive; the shorter YouTube-specific deletion commitments above still apply. A restored service can require provider reconnection. Backups do not guarantee zero data loss or uninterrupted service.
A database backup does not by itself include copies of original receipt images or other files held in separate object storage. Linked inboxes are not independent backups. Keep your own exports and original-file copies where you need them.
Use the Delete Account page for the in-app and email request routes, verification, retained-data information and subscription instructions. A request acknowledgment is not confirmation that deletion has finished. We explain material exceptions and the expected processing timeframe after verification rather than promise immediate erasure.
Security and your choices
We use authenticated access, scoped permissions, private storage where appropriate and encrypted web/API connections to protect data. No system can guarantee absolute security, and private storage does not prevent an authorized recipient from making a copy. Protect your account and devices and notify support about suspected unauthorized access.
You can decline an AI-processing request, manage saved memory, remove supported content, change device permissions, control Social discovery and online/last-login visibility, report or block members, and manage subscriptions through the billing provider. Depending on applicable law, you may also request access, correction, deletion, portability, restriction or objection, withdraw consent, exercise applicable advertising/sale/sharing opt-out rights, or complain to your local privacy authority. Contact support to make a request; available rights and verification depend on the law that applies to you. We may need to verify your identity and authority over an organization account.
Children and policy changes
KORLIX has a minimum age of 16 and is not directed to children under 16. Users aged 16 or 17 need permission from a parent or legal guardian. Do not create an account if you are under 16. At signup, we ask for an age range rather than a full date of birth or identity document. We store the eligible age range, your Terms agreement, Privacy Policy acknowledgment, any parent or guardian permission declaration, policy version and submission time with your account through Supabase. These are self-declarations, not independently verified age or guardian identity. An under-16 selection is refused by our signup flow without creating an account. Contact support if you believe someone under 16 has supplied personal information or any child is at risk through our service. Child sexual abuse and exploitation are prohibited, including synthetic material; see our Child Safety Standards.
We update this policy when practices change and show the effective date above. Where a change requires notice or renewed consent, we provide it through the appropriate app or account channel. Publication of a revised policy does not replace a feature's required permission.
Business Directory
Directory owners choose the business information, public contact details and company photos they submit for publication. Approved listings can be browsed without signing in. Do not publish a home address or personal contact information unless you intend it to be public; a service area can be used instead.
Owner/representative names, verification explanations and uploaded evidence are restricted to the owner and authorized reviewers. Payment processing for optional Verified Business memberships is handled by Stripe when enabled; KORLIX stores membership references and payment status, not full card details. The badge reflects completed ownership/contact checks and an active membership, not guaranteed service quality.
Directory activity counts record daily profile views and contact-button interactions with rate limiting; these are approximate counts, not confirmed customers. Favorites are stored in the visitor's browser. Owners can hide listings, manage uploaded files and cancel membership renewal in My Businesses. Contact support@korlixdeveloper.com for data-removal or verification-review requests.
Business Passport and AI Receptionist
A Business Passport is the shareable public profile inside the Business Directory. The owner chooses the approved headline, services, business photographs, public contact details and optional KORLIX 2MEETU booking link. Shared links, QR codes, printed pages and downloaded contact cards can be copied by recipients. Hiding a listing stops new public access through KORLIX; it does not recall copies already shared or downloaded.
Enterprise business owners can configure K-Nova as an AI receptionist using their published Passport and additional customer-facing answers. When enabled on a connected line, Vapi and the connected telephone provider, such as Twilio, process call audio and routing information. OpenAI processes speech, conversation text and the selected business information to transcribe, answer and speak. The caller hears an AI introduction. Text previews use OpenAI but create no customer messages or bookings. Call recording, provider transcript artifacts and provider-generated call analysis are disabled in this integration; KORLIX does not save full call transcripts or audio recordings.
The private business inbox stores call identifiers, caller ID when available, call times, duration, caller-requested contact details and messages, confirmed appointment details and handling status. Caller ID is not proof of identity. Call content is accessible to the business owner and authorized platform support where needed. Caller content is excluded from the inbox after 90 days and removed by scheduled cleanup, which may be delayed during interruptions. Minimal usage records can remain for allowance accounting. Appointments have the separate 2MEETU retention and management rules.
The owner chooses eligible appointment types, reviews approved answers, accepts processing, sets call limits and can pause the receptionist. Booking checks use real 2MEETU availability and any calendars the host enabled. The caller must confirm a readback before the appointment is reserved. Existing scheduling notifications operate according to the host’s settings. This receptionist does not place outbound calls, transfer calls or collect card details. Contact support@korlixdeveloper.com to request removal of retained call content or help with a phone connection. Providers apply their own service and retention terms.