Privacy Policy
This English version is provided for convenience. The Simplified Chinese version is the binding text; if the two differ, the Chinese version prevails.
Scope: Malaysia · Singapore
Contact: tanqt18biz@gmail.com (also the contact for Malaysian PDPA matters and the Data Protection Officer contact under the Singapore PDPA; to be replaced by a domain mailbox once it is live)
1. Who we are and who this Policy applies to
Kira (operated by TECH CAT LABS (a business registered in Johor, Malaysia, registration no. 202403103398 / 003594732M), "we", "us") is an event and social platform for the cosplay and related creative community. This Policy explains what personal data we collect, why, how we use it, who we share it with, where it is stored, how long we keep it, and the rights you have.
- Kira is for users aged 18 or over; you declare that you are 18 or older when you register. We do not target minors and do not knowingly collect their data.
- During the closed beta Kira is open only to holders of an invite code. Beta accounts carry a publicly visible "Beta Tester" mark, and we keep a record of which batch of invite codes you joined with, for beta management.
- Ticking the consent box at registration means you consent to the processing described in this Policy. We record which version of the Policy you accepted and when.
2. Basic data we collect
- Account data: login e-mail, username, nickname, avatar/cover image, profile details you choose to provide (region, bio, role profiles, friend card, etc.), the time of your 18+ declaration, the Policy version you accepted, the invite-code batch used to join the beta.
- Content data: posts, Looks, comments/danmaku, chat messages, voice notes and media you upload.
- Transaction records: Starlet purchases (payment is handled by Apple or Google; we receive only receipt data for verification, never your card number), tips and support records, creator earnings and withdrawal records.
- Safety records: reports, blocks, sanctions and appeals, used for platform safety and dispute handling.
- Beta applications: the e-mail address, phone platform, region and the optional nickname and source you submit at kira.fans/beta, used only to review and send beta invitations and to manage the tester lists; deleted when the beta ends or 12 months after submission, whichever comes first, unless the address has registered an account.
- Device and technical data: device model, OS version, app version, language, push token, a per-install device identifier, IP address, crash and performance diagnostics.
- We do not collect your precise location, and we do not read your contacts, your photo library (other than files you choose to upload) or other apps.
3. Usage and engagement data
To operate the product and provide data features to you and to creators, we record how you use and interact within Kira, including:
- Profile visits: who visited your profile page and whose you visited (with time and entry source). Note: a future "invisible browsing" option would be a display-layer privilege — when enabled, you would not appear in the other person's list, but the visit record itself is still created and kept (for billing, safety and features). Invisible does not mean unrecorded.
- Content reach and engagement: how often and how widely your content is viewed or shown; the fact of your views, likes, comments, shares and other interactions. Posts show a public view count to all users.
- Notification data: acceptance, opening and tapping of system push notifications.
- Search and discovery: app opens, search terms, entry sources, follow sources. Search terms are kept only briefly (days); afterwards only the anonymous fact that a search occurred is retained.
- Retention: raw event records are kept for at most 90 days; statistics aggregated from them (such as visitor summaries and reach counts) are kept long-term as product data, always subject to the deletion right in section 7.
4. How we use this data
- to provide and improve product features (including data features such as "who viewed me" and creator dashboards, some of which may become paid or membership features);
- to perform our agreement with you: account management, beta management, Starlet and tip settlement, payment of creator earnings;
- for platform safety: anti-abuse, anti-fraud, handling reports and enforcing community rules, verifying age declarations;
- for product analytics and experience optimisation: we use third-party analytics and crash-reporting tools to process internal product telemetry; that telemetry is not used to show your behaviour to other users;
- to communicate with you: service notices, security alerts, policy changes;
- to comply with legal obligations and lawful requests from authorities.
5. Who we share data with
We do not sell or transfer your personal data to third parties. To run the Service we engage the following processors; they may process data only for the purposes we specify, may not use your data for their own purposes, and are bound by written data-processing agreements:
- Supabase: login and identity authentication (e-mail, secure storage of login credentials).
- Oracle Cloud (Singapore region): hosting of application servers and databases.
- OVH (European Union): storage of encrypted backups.
- Expo: delivery of push notifications.
- Sentry: crash reports and error diagnostics.
- PostHog: product usage analytics (internal telemetry).
- Apple App Store / Google Play: app distribution and payment processing for in-app purchases, each under its own privacy policy.
- Other users: your public profile, public content, the "Beta Tester" mark and the display data described in section 3 (such as visitor lists and view counts) are visible to other users as the features are designed. You can control some of these through your privacy settings.
- Legal requirements: we may disclose data where required by law, by a lawful request from a court or regulator, or where necessary to protect the rights and safety of us, our users or the public.
- Business changes: in a merger, acquisition or asset transfer your data may be transferred as part of it; we will notify you before the transfer.
6. What we do not do (firm commitments)
- We do not sell or transfer your personal data to third parties. "Data products" means only statistics and insight features provided to you or to creators within Kira, and never includes providing personally identifiable data to third parties outside the platform.
- We do not serve advertising based on third-party profiling (if advertising is ever introduced, this Policy will be revised and the change announced prominently).
- We do not process data of minors — Kira is not for anyone under 18.
- We do not collect precise location.
7. Your rights (PDPA)
- Access/export: you can request a copy of the personal data we hold about you (including the usage and engagement data in section 3) from Settings.
- Correction: you can correct your profile data at any time.
- Deletion: you can delete your account in the app (30-day cooling-off period, reversible) or, if you cannot log in, request deletion by e-mail from your registered address — see the Account Deletion page. Once deletion completes, your identity data is anonymised, your content and media are deleted, and your engagement records (including rows about you in visitor/reach aggregates) are deleted or de-linked.
- Withdrawing consent: withdrawal means stopping use of Kira and deleting your account; some records kept to meet legal obligations (such as safety-sanction audit trails and transaction records) are retained, anonymised, for the statutory period.
- Exercising rights or complaints: contact tanqt18biz@gmail.com. We answer requests from Malaysian users within 21 days and from Singapore users within 30 days; you also have the right to complain to the personal-data protection authority where you live.
8. Storage, cross-border transfer and security
- Your data is stored on cloud servers under our control located in Singapore; encrypted backups are stored in the European Union. By using Kira you consent to the transfer and storage of your data outside Malaysia and Singapore for these purposes. We choose only providers and regions that offer protection comparable to the PDPA.
- Backup retention: encrypted backups expire automatically after at most 30 days; after account deletion, copies in backups also expire within that period and are never restored into the Service.
- Encryption in transit (TLS); access to data is permission-controlled and audited; keys and credentials are kept separately from code. We take reasonable technical and organisational measures to protect data but do not promise absolute security.
- If a data breach affects your rights, we will notify you and the regulator as required by applicable law.
- Specific providers and regions may change with operational needs; where a change does not lower the level of protection, we update this Policy without seeking fresh consent.
9. Service status and responsibility (protective terms)
- Kira is provided "as is" and "as available"; we do not warrant uninterrupted, error-free operation or that data will never be lost.
- User content is the responsibility of the person who posts it; offline transactions, photo shoots, rentals and other dealings between users are at the users' own risk (in-app reminders apply), and Kira is not a party to any transaction between users.
- To the fullest extent permitted by applicable law, we are not liable for indirect, incidental or consequential loss. The remaining liability terms are in the Terms of Service.
10. Changes to this Policy
We may revise this Policy at any time. Material changes (such as new data types, new recipients or new purposes) are announced prominently in the app and require you to read and accept them again before continuing to use the Service; if you do not agree, you may stop using the Service and delete your account. Non-material changes are notified by updating the effective date, and your continued use is acceptance.