Privacy Policy

Last updated: 15 August 2026

What personal data Kissa collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Kissa (“Kissa”, “we”, “us”) is a creator-first storytelling platform — audio films and written short fiction — operated by Texotic Software Solutions from India. This policy explains how we handle personal data when you use our website, progressive web app, and mobile app (together, the “Service”).

Texotic Software Solutions is the data fiduciary for your personal data under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). If you are in a jurisdiction with equivalent law, we apply comparable protections.

1. The short version

  • We collect what we need to run your account, your library, and creator publishing.
  • We do not sell your personal data, and we share it with no one for their own purposes.
  • We show no ads and embed no third-party advertising or analytics trackers.
  • Your data is stored in Mumbai, India (AWS ap-south-1).
  • You can delete your account and data at any time — here is how.

A condensed version for app-store purposes is on the Data Safety Summary page.

2. Data we collect

Data you give us

  • Account data: your name, email address, username, and a hash of your password. If you sign in with Google, we receive your name, email address, and profile picture from Google — never your Google password.
  • Profile data: display name, bio, and avatar, if you add them.
  • Creator data: for creators, the intent and genres you submit when activating, plus the series, episodes, audio files, images, titles, and descriptions you upload.
  • Support data: reports, appeals, feedback, and support messages you send us, and our replies.

Data generated as you use the Service

  • Activity data: watch history, playback positions, bookmarks, likes, follows, playlists, wishlist, and downloads — this is what your library is made of.
  • Preferences: autoplay, reduced motion, audio quality, volume, and notification settings.
  • Technical data: IP address, device and browser type, operating system, approximate connection quality, and timestamps of requests.
  • Diagnostic data: error and crash logs.

Data we do not collect

We do not collect your location, contacts, calendar, SMS, call logs, microphone or camera input, health or biometric data, advertising identifiers, or payment and financial information. Kissa is free — see Payments & Refunds.

3. Why we use it, and on what basis

PurposeData usedBasis under the DPDP Act
Create and operate your accountAccount data, profile dataPerformance of our contract with you (our Terms)
Keep you signed in and your account secureAccount data, technical dataContract; legitimate use for security
Power your library, history, and resume-where-you-left-offActivity data, preferencesContract
Publish and moderate creator contentCreator data, activity dataContract; legal obligation as an intermediary
Notify you about new episodes and account activityAccount data, follows, preferencesConsent, withdrawable in settings
Trending and recommendationsAggregate activity dataContract; legitimate use
Prevent abuse, spam, and fraudTechnical data, activity dataLegitimate use
Investigate faults and improve the ServiceDiagnostic data, aggregate usageLegitimate use
Comply with law and respond to lawful requestsAny relevant dataLegal obligation

We do not use your personal data for automated decision-making that produces legal effects for you. Moderation decisions that restrict an account are reviewed by a person, and you can appeal — see Community Guidelines.

4. Who we share data with

We share personal data only with providers who process it on our instructions to deliver the Service, under contract, and only for that purpose.

ProviderWhat they handleWhere
Amazon Web ServicesApplication hosting, database, secrets, and logsMumbai, India (ap-south-1)
CloudflareMedia object storage and content deliveryGlobal edge network
GoogleOptional Google Sign-In, and app distribution via PlayPer Google’s policies

We also disclose data where the law requires: a valid court order, or a lawful request from a government agency or law-enforcement body. Where we are permitted to tell you about such a request, we will.

If Kissa is ever acquired or merged, your data may transfer to the acquirer, who would remain bound by this policy. We would tell you before that happened.

What is public. Your username, display name, avatar, bio, and anything you publish as a creator are visible to everyone, including people without an account. Your watch history, bookmarks, likes, playlists, and email address are never public.

5. Cookies and on-device storage

We use strictly necessary cookies to keep you signed in, and browser storage for playback preferences and offline downloads. We set no advertising or cross-site tracking cookies. Every cookie and storage key is itemised in the Cookie Policy.

6. How long we keep data

DataRetention
Account, profile, and activity dataWhile your account is active
Everything above, after you delete your accountErased within 30 days; purged from backups within 90 days
Refresh tokens30 days, or immediately on logout or password change
Server and security logs (including IP addresses)Up to 180 days
Moderation records, reports, and suspensionsUp to 3 years, to enforce against repeat abuse
Anonymised, aggregate statisticsIndefinitely — these no longer identify you
Data under a legal hold or statutory retention dutyAs long as the law requires

7. Where your data is processed

Your data is primarily stored and processed in Mumbai, India (AWS ap-south-1). Media served through our CDN is cached on edge servers worldwide so playback is fast wherever you are; those caches hold published media, not your account or activity data. Google processes sign-in data under its own policies if you use Google Sign-In. We do not transfer personal data to any country that the Indian government has restricted under section 16 of the DPDP Act.

8. Security

We encrypt data in transit with HTTPS/TLS and at rest, store passwords only as salted hashes, rotate session tokens with theft detection, and restrict production access to those who need it. Full detail, and how to report a vulnerability, is on Security & Disclosure.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as the DPDP Act requires, and report to CERT-In within the timelines its directions specify.

9. Your rights

Under the DPDP Act you have the right to:

  • Access — get a summary of the personal data we hold about you and how we process it.
  • Correction and completion — fix data that is wrong, incomplete, or out of date. Most of this you can do yourself in your profile.
  • Erasure — have your data deleted. See Delete Your Account & Data.
  • Withdraw consent — turn off notification emails in settings at any time. Withdrawing consent does not affect processing already carried out.
  • Nominate — name someone to exercise your rights if you die or become incapacitated. Email us to register a nominee.
  • Grievance redressal — complain about how we handled your data, and escalate if unsatisfied. See Grievance Redressal.

To exercise any of these, email privacy@kissa.texotic.in from your registered address. We respond within 30 days. We may ask you to verify your identity first — we will not hand your data to someone impersonating you.

Your duties. The DPDP Act asks you not to impersonate anyone when giving us data, not to suppress material information, and not to file false or frivolous grievances.

10. Children

Kissa is an adults-only service. You must be at least 18 to hold an account, and we do not knowingly collect personal data from children. If we learn that an account belongs to someone under 18, we delete it. If you believe a child has an account, tell us at privacy@kissa.texotic.in. We do not carry out tracking, behavioural monitoring, or targeted advertising directed at children — we do none of those for anyone.

11. Changes to this policy

We update this policy as the Service changes. The date at the top is the current version. For material changes we give notice in the app or by email before they take effect, and where the change requires your consent, we ask for it.

12. Contact us

ReasonContact
Privacy questions, and access, correction, or erasure requestsprivacy@kissa.texotic.in
Formal grievance under the DPDP Act or the IT Rules, 2021Grievance Officer
Anything elsehello@kissa.texotic.in

Data fiduciary: Texotic Software Solutions.

Action required before launch: A privacy policy must name the data fiduciary and give a postal address. Fill in registeredAddress in apps/web/src/lib/legal.ts — it will appear here automatically and this warning will disappear.