This Privacy Policy describes how Kamalak (“we”, “our”, “us”) collects,
uses, stores, and shares information when you use our mobile application and related online
services (together, the “Services”). The Services include short‑form video
discovery, uploads, interactions (for example likes, comments, follows), messaging where
available, notifications, and account features.
By creating an account, signing in (including via third‑party login), or otherwise using the
Services, you agree to this Policy. If you do not agree, do not use the Services.
2. Information we collect
We collect information you give us, information generated when you use the app, and (with your consent where required) data from optional permissions.
Account & profile
Username, display name, profile photo / avatar where you provide one, email or phone number
if used for signup or recovery, user ID inside our systems, and preferences you save in‑app.
Content you create
Videos, captions, thumbnails, hashtags, drafts (if synced), reactions, comments, follows,
blocks, shares, abuse reports, and support messages—subject to functionality we enable over time.
Automatically collected (“usage & device”)
IP address, coarse or approximate location (where permitted), device model, OS version,
app version, crashes or diagnostics logs, language, time zone, interaction events (playback,
taps, impressions), timestamps, and identifiers we need to operate the Services (such as push
notification tokens).
Where you grant optional permission (contacts, microphone, camera, gallery, notifications), we
use access only as needed for the requested feature (for example filming or attaching media),
consistent with OS permission prompts.
Cookies & similar technologies
On mobile, we rely on SDKs and local storage for session management, analytics, fraud
prevention, and improvements. Embedded webviews or promotional links may place cookies
governed by those sites’ policies.
3. Sign-in with Google, Telegram, and other providers
We may offer or add “Sign in with Google”,
“Sign in with Telegram”, and similar third‑party sign‑in (“SSO” /
federated authentication). Those providers authenticate you separately from us.
When you use SSO, we typically receive from the provider (depending on scope and consent):
A stable subject identifier tied to your account with that provider (not your password).
Your chosen name and profile image as shown by that provider.
Your email address, if required for linking or communicated by the provider and you authorize it.
Telegram‑specific identifiers or basic profile metadata if our integration uses Telegram Login or Telegram Bot API flows you approve.
We treat SSO data described above as described in Sections 4–7. SSO providers process your
data under their own privacy notices, not this Policy. We encourage you to read:
You may disconnect or revoke some permissions in Google / Telegram settings; unlinking SSO in
our app does not erase content you already uploaded unless deletion features are exercised as
described below.
4. Video, interactions & public nature of the Services
Short‑video and social feeds are inherently public or semi‑public:
uploaded content may be viewed, interacted with, and shared by others subject to visibility
and safety rules we configure. Assume content you publish is visible to recipients you allow or
to the public depending on settings.
We may moderate for safety (spam, harassment, unlawful content); where required we may disclose
information to regulators or cooperate with lawful requests according to Section 7.
5. How we use information
Operate, secure, personalize, debug, and improve the Services;
Show relevant recommendations and maintain fairness of ranking;
Comply with law, enforce our terms, settle disputes;
Use aggregated or de‑identified analytics that do not identify you.
Legal bases where applicable include: performance of a contract with you, legitimate interests
(security & improvements), consent (optional features), and compliance with legal obligations.
6. Sharing & subprocessors
We may share limited information with vendors who help host, transcode/stream video, analyse
errors, authenticate users, send transactional email or push, mitigate fraud and run SSO.
Contractors are bound by confidentiality appropriate to their role and instructed not to reuse
your data for unrelated marketing unless separately disclosed.
We may disclose information where required by law or to protect vital interests, or respond to
valid legal process consistent with jurisdictional safeguards.
If we reorganize: your information might transfer under equivalent protections
in a merger, acquisition or asset transfer; we will notify you where required before new terms
take effect materially.
7. Retention, access & deletion
We keep data while your account stays active or as needed to honour legal or fraud‑prevention
obligations. Deleted content may remain in encrypted backups briefly or in aggregate logs stripped
of personal identifiers earlier than raw logs expire.
You may export, correct, restrict or erase certain Personal Data where feasible through in‑app
settings or support. Some records must legally or operationally retained (audit logs minimal
fields, invoicing artefacts if commercial features exist later).
For push notifications: stopping them in OS settings disables delivery from our systems even if a
device token persists until routine cleanup.
8. Children
The Services are not directed at children under 13 (or older where local law
requires a higher threshold). Users under the applicable threshold must obtain verifiable parental
consent consistent with COPPA‑like regimes if we detect or knowingly collect minors’ data—or we
will delete it after notice via support.
9. International users
Servers or subprocessors may be located globally. Where we transfer Personal Data internationally,
we apply appropriate safeguards permitted by relevant law where required.
10. Security
We use commercially reasonable safeguards (encryption in transit where standard, restricted
access, monitoring). No service is immune to breach; compromise response may include notifying you
and regulators when legally required along with corrective steps we describe in‑app where
practicable.
11. Changes to this Policy
We may revise this Policy. Updated date reflects the latest revision. Material changes might be
highlighted in‑app before they take effect. Continued use after notice means acceptance of the
update except where forbidden by law—in which case we offer alternatives or cessation.