Kamalak

Privacy Policy

Last updated: May 11, 2026

1. Introduction

This Privacy Policy describes how Kamalak (“we”, “our”, “us”) collects, uses, stores, and shares information when you use our mobile application and related online services (together, the “Services”). The Services include short‑form video discovery, uploads, interactions (for example likes, comments, follows), messaging where available, notifications, and account features.

By creating an account, signing in (including via third‑party login), or otherwise using the Services, you agree to this Policy. If you do not agree, do not use the Services.

2. Information we collect

We collect information you give us, information generated when you use the app, and (with your consent where required) data from optional permissions.

Account & profile

Username, display name, profile photo / avatar where you provide one, email or phone number if used for signup or recovery, user ID inside our systems, and preferences you save in‑app.

Content you create

Videos, captions, thumbnails, hashtags, drafts (if synced), reactions, comments, follows, blocks, shares, abuse reports, and support messages—subject to functionality we enable over time.

Automatically collected (“usage & device”)

IP address, coarse or approximate location (where permitted), device model, OS version, app version, crashes or diagnostics logs, language, time zone, interaction events (playback, taps, impressions), timestamps, and identifiers we need to operate the Services (such as push notification tokens).

Where you grant optional permission (contacts, microphone, camera, gallery, notifications), we use access only as needed for the requested feature (for example filming or attaching media), consistent with OS permission prompts.

Cookies & similar technologies

On mobile, we rely on SDKs and local storage for session management, analytics, fraud prevention, and improvements. Embedded webviews or promotional links may place cookies governed by those sites’ policies.

3. Sign-in with Google, Telegram, and other providers

We may offer or add “Sign in with Google”, “Sign in with Telegram”, and similar third‑party sign‑in (“SSO” / federated authentication). Those providers authenticate you separately from us.

When you use SSO, we typically receive from the provider (depending on scope and consent):

We treat SSO data described above as described in Sections 4–7. SSO providers process your data under their own privacy notices, not this Policy. We encourage you to read:

You may disconnect or revoke some permissions in Google / Telegram settings; unlinking SSO in our app does not erase content you already uploaded unless deletion features are exercised as described below.

4. Video, interactions & public nature of the Services

Short‑video and social feeds are inherently public or semi‑public: uploaded content may be viewed, interacted with, and shared by others subject to visibility and safety rules we configure. Assume content you publish is visible to recipients you allow or to the public depending on settings.

We may moderate for safety (spam, harassment, unlawful content); where required we may disclose information to regulators or cooperate with lawful requests according to Section 7.

5. How we use information

Legal bases where applicable include: performance of a contract with you, legitimate interests (security & improvements), consent (optional features), and compliance with legal obligations.

6. Sharing & subprocessors

We may share limited information with vendors who help host, transcode/stream video, analyse errors, authenticate users, send transactional email or push, mitigate fraud and run SSO. Contractors are bound by confidentiality appropriate to their role and instructed not to reuse your data for unrelated marketing unless separately disclosed.

We may disclose information where required by law or to protect vital interests, or respond to valid legal process consistent with jurisdictional safeguards.

If we reorganize: your information might transfer under equivalent protections in a merger, acquisition or asset transfer; we will notify you where required before new terms take effect materially.

7. Retention, access & deletion

We keep data while your account stays active or as needed to honour legal or fraud‑prevention obligations. Deleted content may remain in encrypted backups briefly or in aggregate logs stripped of personal identifiers earlier than raw logs expire.

You may export, correct, restrict or erase certain Personal Data where feasible through in‑app settings or support. Some records must legally or operationally retained (audit logs minimal fields, invoicing artefacts if commercial features exist later).

For push notifications: stopping them in OS settings disables delivery from our systems even if a device token persists until routine cleanup.

8. Children

The Services are not directed at children under 13 (or older where local law requires a higher threshold). Users under the applicable threshold must obtain verifiable parental consent consistent with COPPA‑like regimes if we detect or knowingly collect minors’ data—or we will delete it after notice via support.

9. International users

Servers or subprocessors may be located globally. Where we transfer Personal Data internationally, we apply appropriate safeguards permitted by relevant law where required.

10. Security

We use commercially reasonable safeguards (encryption in transit where standard, restricted access, monitoring). No service is immune to breach; compromise response may include notifying you and regulators when legally required along with corrective steps we describe in‑app where practicable.

11. Changes to this Policy

We may revise this Policy. Updated date reflects the latest revision. Material changes might be highlighted in‑app before they take effect. Continued use after notice means acceptance of the update except where forbidden by law—in which case we offer alternatives or cessation.

12. Contact us

Privacy questions or rights requests:
Email: ilhomparisi@yandex.uz