Privacy Policy
Last updated: 15 August 2026
What personal data Kissa collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
Kissa (“Kissa”, “we”, “us”) is a creator-first storytelling platform — audio films and written short fiction — operated by Texotic Software Solutions from India. This policy explains how we handle personal data when you use our website, progressive web app, and mobile app (together, the “Service”).
Texotic Software Solutions is the data fiduciary for your personal data under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). If you are in a jurisdiction with equivalent law, we apply comparable protections.
1. The short version
- We collect what we need to run your account, your library, and creator publishing.
- We do not sell your personal data, and we share it with no one for their own purposes.
- We show no ads and embed no third-party advertising or analytics trackers.
- Your data is stored in Mumbai, India (AWS ap-south-1).
- You can delete your account and data at any time — here is how.
A condensed version for app-store purposes is on the Data Safety Summary page.
2. Data we collect
Data you give us
- Account data: your name, email address, username, and a hash of your password. If you sign in with Google, we receive your name, email address, and profile picture from Google — never your Google password.
- Profile data: display name, bio, and avatar, if you add them.
- Creator data: for creators, the intent and genres you submit when activating, plus the series, episodes, audio files, images, titles, and descriptions you upload.
- Support data: reports, appeals, feedback, and support messages you send us, and our replies.
Data generated as you use the Service
- Activity data: watch history, playback positions, bookmarks, likes, follows, playlists, wishlist, and downloads — this is what your library is made of.
- Preferences: autoplay, reduced motion, audio quality, volume, and notification settings.
- Technical data: IP address, device and browser type, operating system, approximate connection quality, and timestamps of requests.
- Diagnostic data: error and crash logs.
Data we do not collect
We do not collect your location, contacts, calendar, SMS, call logs, microphone or camera input, health or biometric data, advertising identifiers, or payment and financial information. Kissa is free — see Payments & Refunds.
3. Why we use it, and on what basis
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Create and operate your account | Account data, profile data | Performance of our contract with you (our Terms) |
| Keep you signed in and your account secure | Account data, technical data | Contract; legitimate use for security |
| Power your library, history, and resume-where-you-left-off | Activity data, preferences | Contract |
| Publish and moderate creator content | Creator data, activity data | Contract; legal obligation as an intermediary |
| Notify you about new episodes and account activity | Account data, follows, preferences | Consent, withdrawable in settings |
| Trending and recommendations | Aggregate activity data | Contract; legitimate use |
| Prevent abuse, spam, and fraud | Technical data, activity data | Legitimate use |
| Investigate faults and improve the Service | Diagnostic data, aggregate usage | Legitimate use |
| Comply with law and respond to lawful requests | Any relevant data | Legal obligation |
We do not use your personal data for automated decision-making that produces legal effects for you. Moderation decisions that restrict an account are reviewed by a person, and you can appeal — see Community Guidelines.
4. Who we share data with
We share personal data only with providers who process it on our instructions to deliver the Service, under contract, and only for that purpose.
| Provider | What they handle | Where |
|---|---|---|
| Amazon Web Services | Application hosting, database, secrets, and logs | Mumbai, India (ap-south-1) |
| Cloudflare | Media object storage and content delivery | Global edge network |
| Optional Google Sign-In, and app distribution via Play | Per Google’s policies |
We also disclose data where the law requires: a valid court order, or a lawful request from a government agency or law-enforcement body. Where we are permitted to tell you about such a request, we will.
If Kissa is ever acquired or merged, your data may transfer to the acquirer, who would remain bound by this policy. We would tell you before that happened.
What is public. Your username, display name, avatar, bio, and anything you publish as a creator are visible to everyone, including people without an account. Your watch history, bookmarks, likes, playlists, and email address are never public.
5. Cookies and on-device storage
We use strictly necessary cookies to keep you signed in, and browser storage for playback preferences and offline downloads. We set no advertising or cross-site tracking cookies. Every cookie and storage key is itemised in the Cookie Policy.
6. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, and activity data | While your account is active |
| Everything above, after you delete your account | Erased within 30 days; purged from backups within 90 days |
| Refresh tokens | 30 days, or immediately on logout or password change |
| Server and security logs (including IP addresses) | Up to 180 days |
| Moderation records, reports, and suspensions | Up to 3 years, to enforce against repeat abuse |
| Anonymised, aggregate statistics | Indefinitely — these no longer identify you |
| Data under a legal hold or statutory retention duty | As long as the law requires |
7. Where your data is processed
Your data is primarily stored and processed in Mumbai, India (AWS ap-south-1). Media served through our CDN is cached on edge servers worldwide so playback is fast wherever you are; those caches hold published media, not your account or activity data. Google processes sign-in data under its own policies if you use Google Sign-In. We do not transfer personal data to any country that the Indian government has restricted under section 16 of the DPDP Act.
8. Security
We encrypt data in transit with HTTPS/TLS and at rest, store passwords only as salted hashes, rotate session tokens with theft detection, and restrict production access to those who need it. Full detail, and how to report a vulnerability, is on Security & Disclosure.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as the DPDP Act requires, and report to CERT-In within the timelines its directions specify.
9. Your rights
Under the DPDP Act you have the right to:
- Access — get a summary of the personal data we hold about you and how we process it.
- Correction and completion — fix data that is wrong, incomplete, or out of date. Most of this you can do yourself in your profile.
- Erasure — have your data deleted. See Delete Your Account & Data.
- Withdraw consent — turn off notification emails in settings at any time. Withdrawing consent does not affect processing already carried out.
- Nominate — name someone to exercise your rights if you die or become incapacitated. Email us to register a nominee.
- Grievance redressal — complain about how we handled your data, and escalate if unsatisfied. See Grievance Redressal.
To exercise any of these, email privacy@kissa.texotic.in from your registered address. We respond within 30 days. We may ask you to verify your identity first — we will not hand your data to someone impersonating you.
Your duties. The DPDP Act asks you not to impersonate anyone when giving us data, not to suppress material information, and not to file false or frivolous grievances.
10. Children
Kissa is an adults-only service. You must be at least 18 to hold an account, and we do not knowingly collect personal data from children. If we learn that an account belongs to someone under 18, we delete it. If you believe a child has an account, tell us at privacy@kissa.texotic.in. We do not carry out tracking, behavioural monitoring, or targeted advertising directed at children — we do none of those for anyone.
11. Changes to this policy
We update this policy as the Service changes. The date at the top is the current version. For material changes we give notice in the app or by email before they take effect, and where the change requires your consent, we ask for it.
12. Contact us
| Reason | Contact |
|---|---|
| Privacy questions, and access, correction, or erasure requests | privacy@kissa.texotic.in |
| Formal grievance under the DPDP Act or the IT Rules, 2021 | Grievance Officer |
| Anything else | hello@kissa.texotic.in |
Data fiduciary: Texotic Software Solutions.
Action required before launch: A privacy policy must name the data fiduciary and give a postal address. Fill in registeredAddress in apps/web/src/lib/legal.ts — it will appear here automatically and this warning will disappear.