Privacy Policy

Effective June 15, 2026

Who we are

Korrali Revenue Recovery ("Korrali", "we", "our") is operated by Korrali LLC This policy explains what data we collect when you use revenue.korrali.com and the Korrali Revenue Stripe App.

Data we collect

  • Account data: Name and email address when you sign up via Google OAuth or email magic link.
  • Stripe data (read and write): When you connect your Stripe account, we read charge, customer, subscription, and invoice records to detect revenue anomalies, and — when you enable recovery — we retry, pay, and update failed invoices on your behalf to recover revenue. We never store raw card numbers, bank details, or PII beyond what Stripe already exposes in its API response.
  • Anomaly records: Detected anomalies (type, financial impact, status, timestamps) are stored so you can track and resolve them.
  • Usage data: Standard web server logs (IP address, browser, pages visited) retained for 30 days for security and debugging.

How we use your data

  • Run anomaly detectors against your Stripe account and surface findings in your dashboard.
  • When you enable recovery, retry and pay failed invoices and update invoice records to recover revenue on your behalf.
  • Send email notifications about new anomalies (you can turn these off in Settings).
  • Process subscription payments via Stripe (we never see your card number).
  • Improve detection accuracy and fix bugs.

We do not sell your data, share it with advertisers, or use it to train AI models.

AI processing

When AI-personalised dunning is enabled, we send the details needed to write a recovery email — such as the customer name, invoice amount, currency and failure reason — to a third-party AI provider to generate that email's copy. We use Groq as the primary provider and OpenAI as a fallback. This data leaves our infrastructure to reach them.

If the generated copy fails our safety and validity checks, we fall back to a fixed deterministic template and no AI output is sent to anyone. We never send raw card numbers or bank details, because Stripe never exposes them to us in the first place.

We do not use your data to train AI models — ours or anyone else's.

Stripe permissions

When you connect Stripe, Korrali Revenue requests read and write access to your Stripe account, used in two ways:

  • Read — charges, customers, subscriptions, and invoices, to detect payment-failure spikes, duplicate charges, silent churn, and past-due invoices.
  • Write — to run the recovery you enable: retrying and paying failed invoices and updating invoice records as part of dunning.

Beyond the invoice-recovery actions you enable, we do not move your payouts, issue refunds, or change your bank or account settings. You can revoke access at any time from Settings, or from your Stripe dashboard.

Data retention

Anomaly records are retained for 2 years so you can track resolution trends. Account data is deleted within 30 days of account closure on request. You can export or delete your data at any time from Settings → Account.

Security

All data is transmitted over TLS. Stripe tokens are stored encrypted at rest. We follow SOC 2 Type II security practices. Your Stripe access token is stored in our database and is never exposed to the frontend or logged.

Your rights

You can access, export, correct, or delete your personal data by emailing privacy@korrali.com. EU/UK users may also lodge a complaint with their local data protection authority.

Changes to this policy

We will notify you by email and update the effective date above if we make material changes. Continued use of the service after changes constitutes acceptance.

Contact

Questions? Email privacy@korrali.com or write to: Korrali LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA.