Start with the current KOKO program, not assumptions about data
Homebot One is developing KOKO and testing it in homes. The overview and Care pages cited here describe the program, but do not establish data fields, storage locations, retention periods, or deletion tools for a particular unit. Before a trial, request a dated data description for the configuration you would receive.
To decide whether the price is right for a trial, include the time and responsibility needed to manage its data. Get the collection, retention, and deletion commitments in writing before agreeing to a fee.
Build a data inventory around one real routine
Choose one routine and follow information from collection to disposal. Ask whether the build receives audio, images, video, spatial observations, device identifiers, account details, commands, support messages, diagnostics, or interaction logs. Do not infer that KOKO collects every item on this list. The purpose of the inventory is to turn a broad privacy question into a set of facts Homebot One can confirm, deny, or mark as not applicable.
For each confirmed data type, record who or what creates it, why it is needed, whether processing occurs on the robot or elsewhere, which organizations can receive it, and what output is produced. NIST's Privacy Framework treats processing as a lifecycle that can include collection, retention, use, sharing, transmission, and disposal. That lifecycle view helps a household distinguish a temporary sensor input from a saved recording, a derived memory, or an operational log.
- Data type and purpose for the named routine
- Collection trigger, such as continuous, event-based, or user-initiated
- Processing and storage location, including cloud or service providers
- People, systems, and organizations permitted to access it
- Retention event and verified method of disposal
Ask for retention rules that name both time and trigger
A useful retention answer says more than data is kept only as long as necessary. Ask for the period and the event that starts or ends it. A diagnostic log might be retained for a stated number of days after creation, while account records may follow a different schedule after a trial ends. Research data, support cases, backups, and records required for a dispute may each have separate rules. Keep those categories separate instead of accepting one vague answer for all information.
Also ask how derived information is handled. Deleting a recording may not automatically remove a transcript, annotation, embedding, profile, model input, summary, or copied support attachment. The applicable terms should explain which derivatives exist, whether they can be linked back to a person or home, and whether they follow the same deletion request. If a data type is retained for security, legal, or research reasons, request the reason, access limits, and final disposal event in writing.
- Active-trial data and routine history
- Account, billing, consent, and support records
- Security, diagnostic, and audit logs
- Research copies, annotations, and derived datasets
- Backups, disaster-recovery copies, and legal holds
Separate export, deletion, reset, and account closure
These actions answer different questions. Export asks what a user can retrieve and in which format. Deletion asks which active and derived records will be removed. A device reset addresses information on the physical unit and its configuration. Account closure ends access to an account but may not erase every retained record. Ask whether each action is self-service or requires support, how identity is verified, how long completion takes, and what confirmation the requester receives.
Backups and third-party processors need explicit treatment. If deletion from a backup cannot happen immediately, ask when the copy ages out, whether it remains isolated from ordinary use, and what happens if that backup is restored before expiration. Ask Homebot One to identify relevant service providers for the proposed program and explain how a deletion request reaches them. A clear answer should also cover shared-home data when one account holder requests deletion but information concerns other residents.
Turn the answers into a testable privacy schedule
Create a one-page schedule before the robot enters the home. List the approved routine, permitted data, retention rule, authorized viewers, export owner, deletion owner, and deadline for closing the account. Attach the current privacy notice and trial terms. If the program changes, compare the new terms with this baseline before enabling another feature or adding another household member.
At the end of the trial, run the promised process. Export a small non-sensitive sample if export is included, submit the deletion or reset request through the documented channel, save the confirmation, and verify that household and support accounts no longer have access. This exercise cannot prove that every backend copy is gone, but it can reveal whether the controls, responsibilities, and support path match the written commitment.
- Owner and deadline for every end-of-trial action
- Evidence expected after export, reset, deletion, and closure
- Escalation contact if a request is delayed or incomplete
- A review date for any data that is intentionally retained
Frequently asked questions
Has Homebot One published one retention period for all KOKO data?
The Homebot One overview and KOKO Care pages cited here did not include a retention schedule for the proposed trial when checked on October 2, 2026. Request the current schedule for the configuration and routine you are considering.
Does closing a KOKO account automatically delete all data?
Do not assume that account closure, device reset, and data deletion are the same action. Ask which records and derivatives each action covers, how backups age out, and what confirmation is provided.
What is the first data question to ask before a KOKO trial?
Name one proposed routine and ask which data types it requires, where each type is processed, who can access it, how long it is retained, and how it is deleted at the end.
What should a KOKO deletion confirmation cover?
Ask the confirmation to identify the request, covered account and device, completed actions, any retained categories and reasons, backup treatment, a responsible contact, and the date by which remaining copies are expected to age out.
Sources & further reading
- Homebot One: Official KOKO overview and in-home testing status (opens in a new tab)
- KOKO Care: Official consent, privacy, and development context (opens in a new tab)
- NIST: Getting Started with the Privacy Framework (opens in a new tab)
- FTC: Careful Connections—Keeping the Internet of Things Secure (opens in a new tab)
From Homebot One, the team building KOKO in Fremont, California.



