Data Safety Summary
Last updated: 15 August 2026
A short, plain-language answer to “what does the Kissa app collect, and who sees it?” This mirrors our Google Play Data safety declaration. The full detail is in the Privacy Policy.
1. The short version
- We do not sell your data, and we do not share it with data brokers or advertisers.
- We show no ads, and there are no advertising or analytics SDKs in the app.
- Data is encrypted in transit using HTTPS/TLS, and at rest on our infrastructure.
- You can request deletion of your account and data at any time — see Delete Your Account & Data.
- Data is stored in Mumbai, India (AWS ap-south-1).
2. Data collected
“Collected” means the data leaves your device and reaches our servers. “Shared” means it is transferred to a third party — none of the below is shared for anyone else’s purposes.
| Data type | Collected | Why | Optional? |
|---|---|---|---|
| Name | Yes | Your account identity and creator display name | Required |
| Email address | Yes | Sign-in, account recovery, and service notifications | Required |
| User ID | Yes | Identifies your account, library, and content across the service | Required |
| Photos (profile picture) | Yes | Your avatar, if you upload one or sign in with Google | Optional |
| Audio files and images | Yes | The episodes creators publish. Only uploaded when you choose to publish | Creators only |
| App interactions | Yes | Plays, watch history, bookmarks, likes, follows, playlists — these power your library and the trending feed | Required |
| Crash logs and diagnostics | Yes | Keeping the app working, and investigating faults | Required |
| Approximate device and connection info (incl. IP address) | Yes | Security, abuse prevention, and choosing an audio quality that suits your connection | Required |
3. Data we do not collect
- Precise or approximate location — we never ask for location permission.
- Contacts, calendar, SMS, or call logs.
- Financial or payment information — Kissa is free and has no purchases. See Payments & Refunds.
- Health, fitness, or biometric data.
- Your microphone or camera — the app records nothing. Creators upload finished files.
- Advertising identifiers, and we run no cross-app tracking.
4. Who we share data with
Only with the infrastructure providers we need to run the service, and only so they can provide it to us. They act on our instructions and may not use your data for their own purposes.
| Provider | What they handle | Where |
|---|---|---|
| Amazon Web Services | Application hosting, database, and logs | Mumbai, India (ap-south-1) |
| Cloudflare | Media storage and content delivery | Global edge network |
| Optional Google Sign-In, and Play distribution | Per Google’s policies |
We also disclose data where the law requires it — a valid court order, or a lawful request from a government agency.
5. Security practices
- All traffic between the app and our servers is encrypted with HTTPS/TLS.
- Data is encrypted at rest on our database and object storage.
- Passwords are stored only as salted hashes. We never store, log, or transmit your password in a readable form.
- Sessions use short-lived access tokens with rotating refresh tokens, so a stolen token has a narrow window and reuse is detected.
- Access to production data is restricted to the people who need it to operate the service.
To report a vulnerability, see Security & Disclosure.
6. Children
Kissa is rated for adults and is not directed to children. You must be at least 18 to hold an account. We do not knowingly collect data from children. If you believe a child has an account, email privacy@kissa.texotic.in and we will remove it.
7. Full detail
This is a summary. The binding document is our Privacy Policy, and the cookies and on-device storage we use are itemised in the Cookie Policy.