Legal

Privacy Policy

Last updated August 12, 2026

This policy explains what Jodi Anoorabh LLP (the data fiduciary behind Kriloop) collects when you use Kriloop, why, who we share it with, and the choices you have. Kriloopis operated from India and built around India’s Digital Personal Data Protection Act, 2023 (DPDP). Kriloop is open to people everywhere, and we extend these same core protections to all of our users wherever they live.

1. What we collect

You give us

  • Account & profile: name, email, password (stored hashed — we never see it), profile photo, bio, handle and interests.
  • Content: the Tracks you run, join and follow; your posts (“artifacts”), comments, reactions and direct messages; uploaded images, audio and video.
  • Host & payout details (hosts only): legal name and, where required for tax, PAN. If you have earnings to be paid, we also ask for your bank account details — we only ask once there is money waiting for you, we store the account number encrypted, and it is never shown again in the app (you see the last 4 digits).
  • Support & grievances: anything you send us when you contact support or raise a complaint.

We collect automatically

We collect information about your activity on Kriloop, which we use to do things like show you the Tracks you follow and work out which parts of the app to fix next. This may include:

  • Tracks, posts and profiles you view
  • What you click, and how long you spend on a page
  • Live sessions you join
  • Things you buy on Kriloop
  • Your app version, device type and IP address — which tells us roughly which region you are in
  • A device push token, if you turn on notifications

We also use cookies and similar technologies — see the Cookie Policy. We do not use your activity to build an advertising profile, and we do not share it with advertisers.

From others

  • Payment metadata from our payment processor (payment and order identifiers, status) — we never receive or store your full card details.

2. Why we use it & our legal basis

  • To run the service — accounts, feeds, Tracks, bookings, memberships, messaging and payouts (performance of our contract with you / your consent).
  • To process payments and meet tax and accounting obligations such as GST and TDS (legal obligation).
  • To keep the community safe — moderation, anti-abuse, fraud and security (our legitimate interests / legal obligation).
  • To send service messages and the notifications you have enabled (consent, which you can withdraw).
  • To understand how Kriloop is used so we can improve it — which features people use, and where they get stuck (legitimate interests).
We do not sell your personal data, and we do not use it for third-party advertising or behavioural ad targeting.

3. Who we share it with

We use vetted service providers (processors), each receiving only what it needs to do its job. We describe them by category rather than by name, because a provider within a category may change; what does not change without an update to this notice is the kind of data each category receives.

  • Infrastructure & hosting — cloud database, authentication, storage, content delivery and media streaming.
  • Payments — our payment processor, for checkout and for paying hosts. We never receive or store your full card details. A host’s bank account number is stored by us, encrypted, and used only to make their payout.
  • Communications — transactional email and, for live sessions, video-classroom infrastructure.
  • Analytics — a product-analytics service, hosted in the EU, that records which features are used so we can decide what to build. We send it a defined list of events made up of identifiers, counts and amounts. We do not send it the content of your posts or messages, your name, your email, or your payment details.
  • How you use the website — on kriloop.com we look at which pages you open, what you click, and where you get stuck, so we can fix the parts that don’t work. Technically this is captured as a replay of the page, so we are specific about the limits: everything you type is masked and recorded as asterisks, never as its contents; and recording is switched off entirely on your messages, your account and payment settings, and the host verification screens. The Kriloop mobile apps do not do this at all.
  • AI — an AI gateway we operate ourselves. It is used two ways: to generate some of Kriloop’s own content (such as house Tracks), and to check posts and messages for unsafe content before they are sent. That check runs on our infrastructure provider’s AI service, happens before anything is stored or delivered to anyone, and produces only a safe/unsafe verdict. Your content is not used to train AI models, or to profile or target you.

We also share information when the law requires it (valid legal process), to protect rights and safety, or as part of a business transfer (we would tell you first). When you post publicly or to a Track, that content is visible to others according to the Track’s visibility settings — that is the point of a social network, not a disclosure governed by this policy.

4. Your rights

You can, at any time:

  • access and edit your profile and most of your data in-app;
  • request a copy of your personal data, or its correction or erasure;
  • withdraw consent (e.g. turn off notifications) as easily as you gave it;
  • nominate someone to exercise your rights if you are incapacitated or deceased (DPDP);
  • depending on where you live, you may have further rights — such as objecting to or restricting certain processing, or asking for a portable copy — and we’ll honour reasonable requests like these.

Delete your account from Settings → Account (see Account & Data Deletion) — this removes your personal data, cancels active Memberships and refunds eligible enrolments, keeping only what tax and accounting law requires. To make any other request, write to privacy@kriloop.com. We respond within the timelines the law sets, and otherwise as quickly as we reasonably can.

5. Children

Kriloop is for adults — you must be 18 or older to use it. We do not knowingly collect data from anyone under 18, and we do not profile children or show them targeted content. If you believe a minor has given us personal data, contact privacy@kriloop.com and we will delete it.

6. Retention & security

We keep your data while your account is active, plus the period that tax and accounting law requires for payment records, and only as long as needed for the purposes above. Data is encrypted in transit, access is role-restricted on a need-to-know basis, and sessions stored on your device are encrypted. No system is perfectly secure, but we work to protect your information and to detect and respond to incidents.

7. International transfers

Kriloop is operated from India and uses global infrastructure, so your data may be processed in countries other than your own. When we move data across borders we use reputable service providers and appropriate contractual safeguards (such as standard contractual clauses) to keep it protected.

8. Data breaches

If a personal-data breach affects your information, we will tell you without undue delay — in plain language: what happened, the likely impact on you, what we are doing about it, steps you can take to protect yourself, and who to contact. We will also report the breach to the Data Protection Board of India, and to any other authority, within the time and in the manner the law requires.

9. Grievances & how to complain

For privacy questions, data requests or complaints, contact our Data-protection / Grievance Officer at privacy@kriloop.com — full details on the Grievance Redressal page. If you are not satisfied, you may complain to the Data Protection Board of India, or, depending on where you live, to your local data-protection authority.

10. Changes

We may update this policy; we will post the new version here with a fresh date and flag material changes in-product.

Jodi Anoorabh LLPA6-19138 Sobha Dreams Acres Tropical Greens, Balagere Village, Varthur Hobli, Varthur, Bengaluru, Karnataka 560087, India. Privacy contact: privacy@kriloop.com.