Privacy Policy
Last updated: October 2026
Qoralo processes account email, a one-way password hash, content you publish, support or abuse messages you submit, and limited server-side page activity required to provide your analytics. We do not sell personal data.
Analytics minimization
Visitor IP addresses are used transiently for abuse prevention and are not stored in analytics. Referrers are reduced to their origin, user agents to a coarse device category, country to a short country code, and optional campaign fields to bounded first-party labels. Repeated events from one source are deduplicated in five-minute windows.
For details about visitor hashes, minimized referrers and optional pixels, read the privacy-first analytics guide.
Audience forms
When a page owner enables an audience form, Qoralo stores the submitted name, email address, exact consent statement and consent time for that owner. The form is optional, identifies its consent purpose, and does not send the contact to an external provider. Page owners can export or delete their contacts. Visitors can remove their own details from the confirmation link, which expires after 30 days.
Retention
Free analytics are retained for 30 days and Pro analytics for up to 365 days. Audience contacts follow the page owner's displayed 30–730 day retention setting. Expired analytics, audience contacts and authentication records are removed by scheduled retention. Account deletion removes account-owned product and audience data; legally necessary support or abuse records may be retained separately.