Koalafied privacy policy
Last updated: 2026-07-30
Koalafied is developed by Andrew Reid, trading as MUPPIT (registered Australian business name). On the App Store the seller appears as Andrew Robert Peter Reid. In this policy, “I”, “me”, and “my” mean that person trading as MUPPIT.
This privacy policy describes how the Koalafied™ app (“the App”) and the website at koalafied.app (“the Site”) handle information.
Summary
- Practice data you create in the App (paths, sessions, people, notes, and related files) stays on your devices and in your personal private CloudKit database. I do not operate a separate cloud copy of that data and cannot read it. See App data you create.
- Zoom is used only if you connect it. The App then retrieves limited Zoom information with your permission. Zoom sign-in tokens stay in your Apple Keychain. See Zoom data the App retrieves.
- Deauthorisation notices from Zoom may reach a small endpoint I operate on the Site. That endpoint is not a practice-data host. See Deauthorisation endpoint.
- The Site may use optional Cloudflare Web Analytics. See Website analytics.
- Support email you choose to send to me may include personal information. See Support email.
- App Store purchases are processed by Apple. See App Store purchases.
- Records about other people (clients, supervisees, peers) stay under your control on your devices and iCloud; see Information about other people.
Detail on what happens for each channel, how information is protected, who else is involved, overseas processing, your rights, and how to complain follows below.
What information is involved
App data you create
| What | Paths, milestones, templates; session and hour logs; names or labels you enter; app settings (for example Privacy Mode); and files you attach or import that the App stores with your records. |
| Why | So you can track credential and CPD hours on your devices. |
| Where | On your devices (local SwiftData) and, when iCloud Sync is on, in your personal private CloudKit database in the container iCloud.com.muppit.Koalafied. |
| How long | Until you delete the records, erase App data, delete the App (local copy), or remove data through your Apple ID / iCloud settings. |
| Who can see it | You, on devices signed into your Apple Account with access to that iCloud data. I cannot read your private CloudKit database. |
| How protected | Stored on your devices under device encryption and the App sandbox, and — when iCloud Sync is on — in your private CloudKit database. CloudKit encrypts that data in transit and at rest under Apple’s systems, and access is limited to the signed-in Apple Account. |
Privacy Mode masks identifying names in the interface when you turn it on. It is a display convenience; it does not create a separate anonymisation service run by me.
You may prepare a clean (redacted) copy of a session transcript on your device before sharing. That work stays on your devices. See the Guide page Reviewing transcripts.
Information about other people
The App is for a practitioner to keep records that may refer to clients, supervisees, peers, and others who are not parties to this policy.
Those records stay on your devices and in your personal iCloud (private CloudKit) under the same protections as other App data. Depending on your profession, what you enter may include sensitive information such as health details. You decide what to enter. You remain responsible for your own professional and confidentiality obligations; see the Terms of service. Tools such as Privacy Mode and on-device transcript redaction can help you handle screen sharing and sharing, but they do not transfer that responsibility to me.
I have no relationship with those people through the App and cannot answer privacy requests about records only you hold. Anyone seeking access to or deletion of information about them that exists only in your Koalafied records should approach you as the practitioner who keeps those records.
Zoom data the App retrieves
If you connect Zoom in Settings → Connections, the App asks Zoom for read-only access so it can:
- show which Zoom account is connected (profile, including account email);
- list your meetings;
- list your cloud recordings and their files.
The App does not ask for permission to change your Zoom account, administer an organisation, or read participant lists.
| What | Zoom profile identifiers needed to show the connected account (including email); meeting catalogue data; cloud recording catalogue data; and transcript, chat, or audio files you choose to bring into a session. |
| Why | So you can match Zoom meetings to sessions and keep recording-related files with those sessions on your devices. |
| Where | Sign-in tokens: your iCloud Keychain (synchronisable Zoom credentials item only), not your practice-record store and not any server I operate. Meeting and recording catalogues and imported files: on your devices with your App data (and CloudKit where that data syncs). |
| How long | Tokens until you Disconnect, delete the App, or Zoom revokes access (tokens then stop working). Imported files and linked meeting data remain in Koalafied until you delete them; Disconnect does not delete them. |
| Who can see it | You on your Apple devices. Zoom continues to hold the underlying account data under Zoom’s terms. I do not receive your Zoom meeting content, recordings, chat, or transcripts through any developer server. |
| How protected | Zoom OAuth access and refresh tokens are stored only in the system Keychain as a synchronisable iCloud Keychain item (AfterFirstUnlock accessibility) for multi-device use. Those tokens are not stored in the App’s local database, not in CloudKit, and not on any server I operate. Network calls use TLS (default App Transport Security). Imported files and catalogues use the same device encryption, App sandbox, and CloudKit protections as other App data. |
Disconnect in the App asks Zoom to revoke the token when possible and always removes Koalafied’s Zoom sign-in from Keychain on that device (and on your other devices when iCloud Keychain syncs).
If you remove Koalafied’s access in Zoom instead, see Deauthorisation endpoint. Zoom sign-in may remain in Keychain until you Disconnect in the App or the tokens stop working after Zoom revokes them.
Deauthorisation endpoint
Zoom Marketplace requires a Deauthorization Notification URL. When you remove Koalafied’s access in Zoom (or Zoom otherwise deauthorises the app), Zoom may send a notification to:
https://koalafied.app/api/zoom/deauth
| What | Zoom event metadata such as event type, Zoom user or account identifiers, client identifiers, and timestamps, as sent by Zoom. Not meeting content, recordings, chat, transcripts, session notes, paths, or other Koalafied practice records. |
| Why | To meet Zoom’s Marketplace requirement and acknowledge the notice. |
| Where | A Cloudflare Worker I operate for this URL. The Worker code stores nothing in application storage (no database and no logs of payload fields in that code). Cloudflare may retain ordinary edge or request metadata under Cloudflare’s own terms. |
| How long | My Worker keeps no application copy. Any Cloudflare edge metadata follows Cloudflare’s retention. |
| Who can see it | Zoom (as sender); Cloudflare (as host); and I only if I inspect operational tooling for that Worker. Practice data on your devices is not involved. |
| How protected | The endpoint is served over TLS and verifies Zoom webhook requests with HMAC; the Worker stores nothing from those notices in application storage. |
Website analytics
| What | Aggregate site usage signals from Cloudflare Web Analytics when an analytics token is configured (designed to be privacy-oriented; no cookies for the basic beacon). |
| Why | To understand Site traffic at a high level. |
| Where | Cloudflare’s systems for the Site. Not the App. |
| How long | Under Cloudflare’s terms for that product. |
| Who can see it | Cloudflare; and I via the Cloudflare dashboard for the Site. |
| How protected | Site traffic uses TLS. Analytics are handled under Cloudflare’s product and privacy terms. |
Apple crash and performance diagnostics
| What | Standard crash and performance diagnostics that Apple may make available to me in App Store Connect. |
| Why | So I can see aggregated stability information when Apple provides it. |
| Where | Apple’s systems; surfaced to me through App Store Connect when available. |
| How long | Under Apple’s App Store Connect retention for those reports. |
| Who can see it | Apple; and me via App Store Connect. |
| How protected | The App sends no analytics, advertising telemetry, or its own crash-reporting pipeline to me. If you have Apple’s “Share with App Developers” setting turned on, Apple may provide me with standard crash and performance diagnostics through App Store Connect. I do not control that setting or Apple’s aggregation of those reports. |
Support email
| What | Whatever you include when you email [email protected] (for example your address, name, and message content). |
| Why | To answer support and privacy questions. |
| Where | My email systems for that mailbox. |
| How long | As long as needed to respond and keep ordinary business records of the correspondence. |
| Who can see it | Me (and any email provider that hosts that mailbox under their terms). |
| How protected | Email in transit uses ordinary provider TLS where supported. I do not ask you to put passwords or Zoom tokens in email. |
App Store purchases
| What | Standard App Store Connect commerce information related to purchases (for example that a subscription was purchased or cancelled). Not your full payment card details. |
| Why | So I can operate App Store commerce for the App. |
| Where | Apple’s systems; limited commerce signals available to me in App Store Connect. |
| How long | Under Apple’s App Store records and any ordinary business records I keep of those signals. |
| Who can see it | Apple processes payment; I see standard developer commerce signals. |
| How protected | Payment handling is Apple’s. Access to App Store Connect is limited to my developer account. |
Availability of any in-app purchase or Koalafied Pro offering is controlled in App Store Connect and may change over time.
Collect, use, share, retain, and process
Collect
- From the App to me: I do not collect your practice data from the App onto servers I operate. Practice data stays on your devices and private CloudKit.
- Zoom connection: with your permission, the App retrieves Zoom profile, meeting, and recording information from Zoom to your devices as described above. That retrieval is between your device and Zoom.
- Deauthorisation endpoint: Zoom may send deauthorisation identifiers to the URL above. That is Zoom calling my endpoint, not the App uploading your practice data.
- Site: Cloudflare may collect Web Analytics signals for the Site when configured.
- Email: I receive what you choose to send to support@.
- Purchases: Apple provides standard commerce signals when you buy through the App Store.
- Diagnostics: if you enable Apple’s “Share with App Developers” setting, Apple may provide me with standard crash and performance diagnostics through App Store Connect.
Use
- Practice and Zoom-imported data on your devices: for the features you use in the App (tracking hours, matching meetings, reviewing transcripts, and related tools).
- Deauthorisation notices: to verify and acknowledge Zoom’s event.
- Site analytics: to understand Site traffic.
- Support email: to respond to you.
- Commerce signals: to operate App Store purchases.
- Apple diagnostics (when Apple provides them): to understand App stability.
I do not sell your data. I do not use your client and practice data for advertising. I do not provide your client and practice data to third parties for their marketing.
Share
I do not host or forward your practice records to other companies for their use.
Other parties are involved as platforms you or I use:
- Apple (device OS, Keychain, CloudKit, App Store);
- Cloudflare (Site and deauthorisation endpoint hosting);
- Zoom (your Zoom account, if you connect it).
See Who else is involved.
Retain
Retention is described per channel in What information is involved. In short: practice and imported files until you delete them; Zoom tokens until Disconnect, App deletion, or Zoom revocation; deauthorisation Worker application storage none; support email as needed to respond and for ordinary business records; Site analytics under Cloudflare; App Store commerce signals and any Apple diagnostics under Apple’s retention; ordinary commerce records I keep.
Process
Processing that reaches me is limited: acknowledging Zoom deauthorisation notices; reading Site analytics in Cloudflare; reading support email; seeing App Store commerce signals; and viewing Apple crash or performance diagnostics when Apple provides them. I do not process your private CloudKit practice database. On-device processing in the App (including redaction of transcripts on your device) happens on your devices under your control.
Who else is involved
| Party | Role | Their privacy information |
|---|---|---|
| Apple | Device platforms, Keychain, CloudKit sync, App Store payments | Apple Privacy Policy |
| Cloudflare | Hosts the Site and the deauthorisation Worker; optional Web Analytics; may retain edge request metadata under their terms | Cloudflare Privacy Policy |
| Zoom | Your Zoom account and OAuth access if you connect; may send deauthorisation notices to my endpoint | Zoom Privacy Statement |
I do not control how long Cloudflare retains edge metadata, or how Apple and Zoom operate their own services.
Overseas recipients
Apple, Cloudflare, and Zoom may hold or process information in the United States and other countries where they operate. That can include information associated with your Apple Account, Site or endpoint traffic, and your Zoom account. See their policies linked above. Ordinary internet transit may also cross borders; that is not the same as me disclosing your practice records to a separate host I operate.
Your rights
For practice data and Zoom-imported files on your devices and in your iCloud account, you control them through the App, device settings, and Apple ID / iCloud tools, and through Zoom’s own account settings for Zoom access.
For information I hold (mainly support email and App Store commerce signals), you can ask me to:
- tell you what I hold about you in that correspondence or those signals;
- correct it;
- delete it (where I can control it);
- give you a copy of what I hold in that correspondence.
Email [email protected]. Include enough detail for me to find the relevant messages or records. I will respond as quickly as I can and will tell you if it will take longer.
Access and correction
To ask for access to, or correction of, personal information I hold, email [email protected]. That is the contact channel for these requests (email only).
Complaints
If you have a privacy complaint about how I handle information, please write first to [email protected]. I will acknowledge your complaint and answer in writing.
If you have not heard back in about a month, you can take the matter to a privacy regulator. In Australia that may include the Office of the Australian Information Commissioner (OAIC). In the United Kingdom that may include the Information Commissioner’s Office (ICO).
Retention
See the “How long” rows under What information is involved.
Children
The App is not directed at children. The App is intended for users 16 years of age or older. If you are a parent or guardian and believe a child has provided information through the Site contact channel, contact me and I will delete what I can control (for example, email correspondence).
International users
If you use the App outside Australia, practice data still follows your Apple Account and devices (SwiftData / CloudKit). For information that actually reaches me (for example support email), the rights and complaint paths above are how to contact me and escalate if needed.
Apple App Store guidelines
This policy is written with Apple App Store Review Guidelines on privacy and data use in mind, including Guidelines 5.1.1 (Privacy: Data Collection and Storage) and 5.1.2 (Privacy: Data Use and Sharing).
Changes
I may update this policy as the App or Site changes. Material changes will be reflected on this page with an updated review date above.
Contact
Privacy questions: [email protected]