Privacy Policy
Last updated: 2026-06-14
Nontonio
Effective Date: 14 June 2026
Last Updated: 14 June 2026
This Privacy Policy explains how Nontonio collects, uses, shares, and protects your personal data, and the rights and choices you have. Please read it together with any notices we provide when you use specific features.
About This Policy
Nontonio ("**Nontonio**", "**we**", "**us**", or "**our**") is a short-drama streaming service available through our website at nontonio.com, our Android mobile application, and our Telegram Mini App (together, the "**Service**"). Nontonio is operated by an individual based in Indonesia. For the purposes of data protection law, the operator of Nontonio is the "controller" responsible for your personal data.
By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
What This Policy Covers
About This Policy
Definitions / Key Terms
Who We Are and How to Contact Us
The Laws That Apply
Who Can Use Nontonio (Age)
Our Privacy Principles
Personal Data We Collect
Information Visible to Other Users
How We Use Your Data and Our Legal Bases
Personalization, Recommendations, and Profiling
Cookies, Identifiers, and Similar Technologies
How We Share Your Data
International Data Transfers
How Long We Keep Your Data
Aggregated and De-Identified Data
Your Privacy Rights and Choices
Data Security
Data Breach Notification
Children's Privacy
Mobile Application and Offline Downloads
Third-Party Links and Content
Additional Information for Users in the EEA and UK
Additional Information for California Residents
Additional Information for Users in Indonesia
Governing Law
Accessibility
Language
Changes to This Policy
Definitions / Key Terms
To keep things clear across the different laws that may apply to you, we use these terms:
Personal data / personal information — any information that relates to an identified or identifiable person. We use "personal data" and "personal information" to mean the same thing.
Processing — anything we do with personal data, such as collecting, storing, using, sharing, or deleting it.
Controller — the party that decides why and how personal data is processed. For the Service, that is the operator of Nontonio ("we").
Processor / service provider — a third party that processes personal data on our behalf and on our instructions.
Data subject / consumer — you, the individual the personal data is about.
Sensitive personal data / information — categories that receive special protection, such as account log-in credentials, precise location, or government identifiers.
Sale / sharing — as defined under California law, selling personal information for value, or sharing it for cross-context behavioral advertising. We do neither.
De-identified / aggregated data — data that can no longer reasonably be used to identify you.
Supervisory authority — a government data-protection regulator.
Who We Are and How to Contact Us
Controller: the individual operator of Nontonio, based in Indonesia.
Privacy and data-protection contact: [email protected] — use this address for any question, to exercise your rights, or to make a complaint.
Data-protection responsibility: as an individual operator, we currently perform the data-protection function directly. If the scale or nature of our processing later requires it under applicable law, we will appoint a dedicated Data Protection Officer and update this Policy.
Additional contact details for the operator are available on request.
The Laws That Apply
We aim to handle personal data in accordance with the data protection laws that may apply to you, including:
Indonesia — Law No. 27 of 2022 on Personal Data Protection ("**UU PDP**"), our primary governing framework.
European Economic Area ("EEA") and the United Kingdom — the General Data Protection Regulation and UK GDPR ("**GDPR**"), where applicable.
California, USA — the California Consumer Privacy Act as amended by the California Privacy Rights Act ("**CCPA/CPRA**"), where applicable.
Region-specific rights and disclosures appear in the "Additional Information" sections near the end of this Policy. Where a stricter requirement applies to you, we seek to honor it.
Who Can Use Nontonio (Age)
The Service is intended only for users aged 17 and older. See "Children's Privacy" below for how we handle age and children's data.
Our Privacy Principles
We collect only the personal data we need for the purposes described in this Policy, and we keep it only as long as necessary.
We take reasonable steps to keep your personal data accurate, complete, and up to date, and to correct or delete inaccurate data. Please help us by keeping your account details current.
We are accountable for processing your personal data lawfully, fairly, and transparently, and we apply the security measures described in this Policy.
For processing that may present higher privacy risks — such as large-scale analytics of usage behavior — we assess the risks and apply safeguards (including data minimization, coarse-only location, and pseudonymized identifiers).
Personal Data We Collect
Information You Provide to Us
Account and profile data: your email address, password (stored only in hashed form), and — if you choose to provide them — your phone number, display name, profile picture, language/locale, and time zone.
Authentication and security data: if you enable them, two-factor authentication settings, backup codes (stored hashed), and passkeys.
Payment and transaction data: the payer name and email associated with a payment, the amount, currency, and payment method, and — for manual bank-transfer payments — a proof-of-payment image you upload. We also store transaction records and the raw responses and webhook notifications we receive from our payment providers, which may contain additional details about the payment or payer provided by that provider. We do not collect or store your full card number or CVV — card details are entered directly on the secure pages of our payment providers.
Referral and payout data: if you take part in any referral feature, we record your referral code, the connection between you and the people you refer (or who referred you), and any rewards, credited amounts, and balances. If you receive a payout, we collect the bank or e-wallet account details you provide so we can pay you.
User-generated content: comments, reviews and ratings, content reports, content requests, watch-party chat messages, support tickets, support-chat messages, and any files you attach to support requests.
Form submissions and requests: if you submit a copyright/DMCA notice, an advertising inquiry, or a studio/partner application, we collect the information in that form — which may include your name, email address, postal address, telephone number, company name, and, for copyright notices, your physical or electronic signature.
Communications: messages you send us, including support inquiries and feedback.
Information We Collect Automatically
Viewing and usage data: your watch history (including playback/resume position, seconds watched, and completion status), titles you mark as favorite or save to "watch later," titles you download for offline viewing (including the associated download/licence records and their expiry), the searches you run on the Service including the search terms themselves, your playback and player preferences, and interactions such as the titles and genres you view.
Device and technical data: your IP address, browser type and user-agent string, device type, operating system, an optional device label, and your approximate, coarse location (see below). We retain your full IP address and user-agent string within your session records and our security, audit, and system logs (for example, when you sign in, reset a password, or change your email).
Account-security data: sign-in events such as your last login time, failed login attempts and any temporary lockouts, and your account status, used to protect your account and detect abuse.
Push-notification data: if you enable push notifications, the information needed to deliver them — on mobile, a device messaging token (Firebase Cloud Messaging) plus your platform, app version, and locale; on the web, your browser push subscription endpoint and the public encryption keys it provides.
Identifiers: cookies and similar identifiers, including persistent random identifiers we store on your device (in browser local storage on the web and separately within the Telegram Mini App) and a first-party identifier set by our analytics tool, which let us recognize your device across sessions for analytics and abuse-prevention (see "Cookies, Identifiers, and Similar Technologies").
Notification data: your notification preferences and a record of the in-app, email, push, and Telegram notifications we have sent you.
Trust-and-safety records: if we restrict, suspend, or ban an account, we record the moderation action, the reason for it (for example suspected fraud, chargeback abuse, or violation of our minimum-age requirement), and any related internal notes.
Approximate location: we derive an approximate, coarse location — your country, region, and city — from your IP address (via network/edge headers) and, in limited cases, a third-party IP-to-location lookup. We do not collect precise GPS or geolocation coordinates.
Information We Receive from Other Sources
Social and platform sign-in: if you sign in with Google or Facebook, we receive your provider account identifier, email address, name, and profile picture. If you access the Service through the Telegram Mini App and sign in via Telegram, Telegram provides us your Telegram user ID and basic profile information (such as your name, username, language, profile photo, and whether you have a Telegram Premium subscription). If you sign up only through Telegram and do not add an email address, we generate an internal placeholder email address for your account; this is not a working email and we cannot send you messages at it.
Payment providers and app stores: payment status and related transaction information from our payment providers and, for Android purchases, from Google Play.
Network and security providers: approximate-location and request metadata used to deliver and secure the Service.
Information Visible to Other Users
Some features let you share information with other users. Please be aware:
When you post a comment, review, or rating, your display name and profile picture are shown alongside it and are visible to other users of the Service.
When you join or host a Watch Party, the other participants in that room can see that you are present, your display name and profile picture, the title being watched together, who you watch with, and any chat messages you send in the room.
Content requests and content reports are sent to us and our moderators; they are not published.
Please do not include sensitive personal information in comments, reviews, watch-party chat, or other content you share with others. Content you post publicly may remain visible, or be retained in anonymized form, even after you delete your account (see "Deleting Your Account and What We Keep").
How We Use Your Data and Our Legal Bases
Under UU PDP, we process personal data on one or more of the lawful bases recognized in Article 20: your consent; the performance of a contract with you (or steps taken at your request before entering one); compliance with our legal obligations; protection of vital interests; performance of a task in the public interest; and our (or a third party's) legitimate interests, assessed against your interests, purposes, and reasonable expectations. For EEA/UK users, the corresponding GDPR basis is shown for each purpose below. For California residents, our processing corresponds to the business and commercial purposes described throughout this Policy.
To provide the Service — creating and managing your account; authenticating you; streaming content; saving your watch history, favorites, and preferences; processing subscriptions, payments, and payouts; enabling downloads; and providing customer support. Basis: performance of a contract.
To keep the Service secure and prevent abuse — detecting and preventing fraud, payment chargebacks, account abuse, and unauthorized access; enforcing our terms; maintaining security and audit logs; and managing your sessions and devices. Basis: legitimate interests.
To understand and improve the Service (analytics) — measuring usage, content performance, and engagement, including which titles, genres, and pages are viewed and which searches are run. Our analytics processing includes the search terms you enter and your IP address. Basis: legitimate interests (UU PDP Art. 20(2)(f)), balanced against your interests. You can object to this processing (see "Your Privacy Rights and Choices").
To personalize and recommend content — see "Personalization, Recommendations, and Profiling" below. Basis: legitimate interests / performance of a contract.
To communicate with you — sending service and transactional messages (such as account verification, password resets, and payment receipts); and, where you have enabled them, push notifications and optional updates. Basis: performance of a contract, legitimate interests, or consent. You can turn off push notifications and unsubscribe from promotional messages at any time.
To comply with law — keeping records required by law (for example, financial and tax records), responding to lawful requests from authorities, and establishing, exercising, or defending legal claims. Basis: legal obligation.
Providing certain data — such as your email address and password — is necessary to create an account and use core features; without it, you may not be able to use those parts of the Service.
Personalization, Recommendations, and Profiling
We use your viewing history, searches, and interactions to personalize content recommendations and rankings and to measure how the Service is used. This profiling is used only to operate and improve the Service. It does not produce legal effects concerning you or similarly significantly affect you, and we do not make decisions about you based solely on automated processing within the meaning of Article 22 of the GDPR or Article 10 of UU PDP. You may object to analytics-based and personalization processing by contacting [email protected].
Cookies, Identifiers, and Similar Technologies
We and our service providers use cookies, local storage, and similar technologies to operate and improve the Service:
Strictly necessary — required to sign you in and keep you signed in (for example, an authentication cookie holding your session token) and to keep the Service secure. These cannot be switched off.
Preferences — remember settings such as language and playback preferences.
Analytics — help us understand how the Service is used. We use a self-hosted analytics tool that sets a first-party identifier and a small playback-measurement identifier stored on your device. We also store persistent random identifiers in your browser's local storage (and separately within the Telegram Mini App) to recognize your device across sessions.
You can control cookies through your browser or device settings; blocking strictly-necessary cookies may prevent the Service from working. Where a cookie banner is shown, you can use it to manage non-essential cookies. Please note that, at present, our analytics run by default for all visitors; see "How We Use Your Data" and "Your Privacy Rights and Choices" for how you can object.
Do Not Track. Some browsers offer a "Do Not Track" (DNT) signal. There is no industry-standard response to DNT signals, and the Service does not currently respond to them. For California's Global Privacy Control signal, see "Additional Information for California Residents."
How We Share Your Data
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share personal data only as described below.
Service Providers and Partners
We use trusted third parties to operate the Service. By category, these include cloud hosting and storage providers, content-delivery and security providers, payment processors, analytics providers, email/communication providers, push-notification providers, and authentication (sign-in) providers. Some of them — in particular payment and sign-in providers — process certain data as independent controllers under their own privacy policies. Our key providers are:
Cloudflare — content delivery, security, and approximate-location detection; processes IP address and request metadata for all traffic. (cloudflare.com/privacypolicy)
OpenPanel (self-hosted analytics) — product analytics; processes usage events, pages viewed, the text of your searches, an analytics identifier, and your IP address.
Midtrans — payment processing (Indonesia/SEA); processes payer name, email, phone, and amount. Card details are entered on Midtrans' own pages. (midtrans.com/privacy-policy)
PayPal — payment processing (global); processes payment amount and order reference, and holds the payer's identity as an independent controller. (paypal.com/privacy)
Google — sign-in (Google OAuth), mobile push (Firebase Cloud Messaging), and Android in-app billing (Google Play); processes account identifier, email, name, avatar, device push token, and purchase tokens. (policies.google.com/privacy · play.google.com/about/play-terms)
Meta (Facebook) — sign-in (Facebook login); processes account identifier, email, name, and avatar. (facebook.com/privacy/policy)
Brevo — sending transactional and account emails; processes recipient email, name, and message content. (brevo.com/legal/privacypolicy)
Browser push services (e.g. Google, Mozilla, Apple) — delivering web push notifications; receive encrypted messages sent to your subscription endpoint.
Telegram — access and sign-in via the Telegram Mini App; processes your Telegram account identifier and basic profile data. (telegram.org/privacy)
IP-to-location provider — deriving approximate location from your IP address.
Cloud hosting provider (Singapore / Southeast Asia) — hosting our databases and file storage, including uploaded support attachments.
The specific providers used may change as the Service evolves; we will update this Policy accordingly.
Other Disclosures
Legal and safety: we may disclose personal data if required by law, or in good-faith belief that disclosure is necessary to comply with a legal obligation, enforce our terms, prevent fraud or harm, or protect the rights, safety, or property of Nontonio, our users, or the public.
Business transfers: if the Service or its assets are transferred to another operator (for example, through a sale or reorganization), personal data may be transferred as part of that transaction, subject to this Policy.
International Data Transfers
Nontonio is operated from Indonesia, and our hosting infrastructure is located in Singapore / Southeast Asia. Some of our service providers are located in other countries, including the United States (sign-in, payment, push-notification, and network providers) and the European Union (our email provider). This means your personal data may be transferred to, stored in, and processed in countries other than your own.
For users in Indonesia (UU PDP): where we transfer personal data outside Indonesia, we ensure that the receiving country or organization has a level of protection at least equivalent to UU PDP; where that is not established, we put in place adequate and binding safeguards (such as contractual data-protection commitments); and where neither applies, we rely on your consent.
For users in the EEA/UK (GDPR): where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers) and, for certified recipients in the United States, the EU-US / UK Extension of the Data Privacy Framework.
You may request more information about these safeguards, or a copy where available, by emailing [email protected].
How Long We Keep Your Data
We keep your personal data for as long as necessary to provide the Service and fulfill the purposes described in this Policy, and thereafter only as needed to comply with our legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements.
When we decide how long to keep personal data, we consider:
the amount, nature, and sensitivity of the data;
the potential risk of harm from unauthorized use or disclosure;
the purposes for which we process it, and whether we can achieve those purposes by other means;
the duration of our ongoing relationship with you and your account status; and
legal, accounting, tax, regulatory, or reporting obligations, and limitation periods for bringing or defending legal claims.
In general terms:
Account data is retained while your account is active and deleted or anonymized after you delete your account, except for information we must keep by law or for legitimate business purposes.
Financial and transaction records are retained for the period required by applicable tax and accounting laws, even after account deletion.
Security, audit, and system logs (which may contain your IP address and user-agent) are retained for limited operational periods — generally on the order of days to months — and then deleted.
- Analytics and play-event data is retained for a limited period and then deleted or aggregated.
When personal data is no longer needed, we delete it or irreversibly anonymize it.
Aggregated and De-Identified Data
We may create aggregated, de-identified, or anonymized data from personal data — for example, total views per title, popularity trends, and regional engagement and revenue statistics — that can no longer reasonably be used to identify you. Once data is aggregated or irreversibly de-identified, it is no longer personal data, and we may retain and use it indefinitely for any lawful purpose, including operating, analyzing, promoting, and improving the Service. We will not attempt to re-identify de-identified data except to test our de-identification.
Your Privacy Rights and Choices
Depending on where you live, you have some or all of the rights below. We honor these rights for all users to the extent applicable law requires.
Your Rights
Information — to be told about how and why we process your data, our identity, and our accountability.
Access — to request a copy of the personal data we hold about you.
Rectification / correction — to correct inaccurate or incomplete data.
Erasure / deletion and destruction — to request that we end processing and delete and/or destroy your personal data.
Restriction and objection — to restrict, delay, or object to certain processing, including processing based on our legitimate interests (such as analytics).
Objection to automated decisions — to object to decisions based solely on automated processing, including profiling, that significantly affect you.
Data portability — to receive certain data in a structured, commonly-used, machine-readable format, and to have it transmitted to another controller where technically feasible.
Withdraw consent — where we rely on consent, to withdraw it at any time.
Compensation — where provided by applicable law (including UU PDP), to seek compensation for harm caused by unlawful processing.
Lodge a complaint — with a data protection authority (see "Lodging a Complaint").
For users in Indonesia, these rights are recognized under UU PDP (Articles 5–13). For EEA/UK and California users, see the dedicated sections below.
Your Choices and Controls
You can manage much of your data directly in the Service:
Access / export — download a copy of your key account data from your account settings. To receive a complete copy of all personal data we hold (including session, device, and analytics records), email [email protected].
Correction — edit your profile (name, language, time zone, profile picture) and change your email through the verified email-change process.
Deletion — delete your account, and separately clear your watch history (all titles, a single title, or a single episode).
Sessions and devices — view and revoke active sessions, and unlink connected Google, Facebook, or Telegram sign-in.
Subscriptions — cancel your subscription. Subscriptions purchased through Google Play or PayPal may also be managed through those services.
Notifications — turn push and email notifications on or off. If you disable notifications in your device or browser settings, delivery stops and the associated push token or subscription becomes invalid; we remove or deactivate stored tokens that are no longer valid.
Analytics — object to analytics and personalization by emailing [email protected].
Cookies — manage cookies via your browser or device settings.
How to Make a Request
For any privacy request, contact us at [email protected]. The following applies:
We will acknowledge your request and may ask for information to verify your identity to a degree appropriate to the sensitivity of the data. If we cannot verify you, we may decline the request and will explain why. For security, we will not disclose certain elements (such as passwords or full payment credentials) in response to a request.
If you cannot use the in-app tools — for example, you have lost access to your account, or you signed up only through Telegram or a social login and do not have a usable email address — contact us and we will use alternative means to verify your identity (such as your Telegram username and user ID) before acting on your request.
Timeframes: under the GDPR, we respond within one month, extendable by up to two further months for complex or numerous requests (we will tell you within one month). Under the CCPA, we respond within 45 days, extendable by a further 45 days where reasonably necessary. UU PDP requests are handled within the timeframes required by Indonesian law.
We provide this information free of charge, except that we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, where permitted by law.
You will not be discriminated or retaliated against for exercising your rights.
Withdrawing Consent
Where we rely on your consent (for example, the device permission you grant for push notifications), we ask for it in clear terms at the point we need it, and withdrawing it is as easy as giving it: turn off push notifications in your device or browser settings, unsubscribe from marketing emails via the link in each message or in your settings, and object to analytics by emailing us. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide the specific feature that relied on it.
Deleting Your Account and What We Keep
When you delete your account, we anonymize your core profile and delete data we are not required to keep. However, to be transparent: some records linked to your prior account may persist in anonymized or retained form where retention is permitted or required, including:
transaction, payment, and payout records (for legal and tax compliance and anti-fraud);
security and audit logs;
push-notification device tokens, until they expire or are deactivated;
analytics and play-event records, until their retention period lapses; and
content you posted publicly (such as comments and reviews), which we anonymize or retain.
We sever the link to your identity where feasible and otherwise delete on our retention schedule. You can ask us to remove or anonymize specific public content by contacting [email protected].
Lodging a Complaint
We ask that you contact us first at [email protected] so we can try to resolve your concern. You also have the right to complain to a data protection authority:
In Indonesia — the personal data protection authority designated under UU PDP.
In the EEA — the supervisory authority in your country of habitual residence, place of work, or the place of the alleged infringement (a list is maintained by the European Data Protection Board at edpb.europa.eu).
In the UK — the Information Commissioner's Office (ico.org.uk).
Data Security
We take reasonable technical and organizational measures to protect your personal data, including: encryption of data in transit; hashing of passwords and sensitive tokens; encryption of sensitive secrets and media keys at rest; two-factor authentication and passkey support; access controls and audit logging; rate limiting and abuse protection; and redaction of sensitive fields in our logs.
No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Keeping your account secure. To help protect your account, we recommend you use a strong, unique password, enable two-factor authentication or a passkey, keep your device and the app up to date, sign out and revoke sessions on devices you no longer use, and be alert to phishing — we will never ask for your password by email or chat. If you believe your account has been compromised, contact us immediately at [email protected].
Data Breach Notification
If a personal-data breach occurs that affects you, we will assess the risk and, where required by applicable law, notify the competent supervisory authority and you. In line with UU PDP, we will provide written notification without undue delay and, where required, within 3×24 hours (72 hours) of becoming aware of the incident; under the GDPR, we will notify the relevant supervisory authority within 72 hours where required, and notify you directly where the breach is likely to result in a high risk to your rights and freedoms. Our notification will describe, to the extent known, the data affected, when and how the incident occurred, the likely consequences, and the steps we are taking to address it and limit harm. We maintain internal records of breaches as required by law.
Children's Privacy
The Service is intended only for users aged 17 and older. We rely on self-declaration of age at sign-up and do not currently operate an age-verification mechanism; we do not request your date of birth. We do not knowingly collect personal data from anyone under 17.
Where the personal data of a child is processed, UU PDP requires the consent of a parent or guardian and processing in the child's best interest; because our Service is not directed to children, we do not seek to collect such data. If we learn that we have collected personal data from a person under 17 without the required parental consent, we will delete it. Parents or guardians who believe their child has provided us with personal data may contact [email protected].
Mobile Application and Offline Downloads
When you use our Android app, we may collect your app version, device platform and language, and a Firebase Cloud Messaging registration token used to deliver push notifications. The app records app-open and app-install events for analytics. We do not use a mobile advertising identifier (such as the Android Advertising ID), and we do not track you across other apps or websites for advertising. The app requests only the permissions needed for its features (such as notifications and storage for offline downloads); you can manage these in your device settings. In-app purchases are processed by Google Play Billing under Google's terms.
If you download titles for offline viewing, we keep a record of which titles you downloaded and the expiry date of the offline licence. Our streaming and download technology uses content-protection measures (including encryption and access tokens) to enforce licensing limits; these generate technical records tied to your account and device.
Third-Party Links and Content
The Service may contain links to, or content from, third-party websites and services that we do not control, and may be accessed through third-party platforms. When you use the Service through the Telegram Mini App, your use of Telegram itself is also governed by Telegram's own terms and privacy policy, which we do not control. This Policy does not apply to third parties; we encourage you to review their privacy policies before providing them with personal data.
Additional Information for Users in the EEA and UK (GDPR)
If you are located in the EEA or the UK, the following applies in addition to the rest of this Policy:
Controller and contact: as described in "Who We Are and How to Contact Us."
Legal bases: we process your personal data on the legal bases set out in "How We Use Your Data and Our Legal Bases."
Your rights: you have the rights described in "Your Privacy Rights and Choices," including the right to object to processing based on legitimate interests and the right to lodge a complaint with your supervisory authority.
International transfers: your data may be transferred outside the EEA/UK, subject to appropriate safeguards, as described in "International Data Transfers."
Analytics: we currently rely on our legitimate interests to operate analytics that run by default. You have the right to object to this processing by contacting [email protected].
EU/UK representative: where we are required to designate a representative in the EU or UK under Article 27 of the GDPR, details will be provided here. [If you actively serve EEA/UK users, you may be required to appoint an EU/UK representative — confirm with legal counsel and fill in or remove this line.]
Additional Information for California Residents (CCPA/CPRA)
If you are a California resident, the following applies in addition to the rest of this Policy.
Categories of personal information collected, the purpose, and the categories of recipients. In the past 12 months we have collected and disclosed (to service providers, for business purposes only) the following categories. We have not sold any category, and have not shared any category for cross-context behavioral advertising.
Identifiers (name, email, IP address, account/device IDs) — purpose: account creation, authentication, security, communications — recipients: hosting, CDN/security, email, analytics, and sign-in providers.
Customer records (phone, payment payer details, payout/bank details) — purpose: process payments, subscriptions, and payouts — recipients: payment processors, hosting providers.
Commercial information (subscriptions, transactions) — purpose: provide and bill the Service, fraud prevention — recipients: payment processors, hosting providers.
Internet/network activity (watch history, searches, usage) — purpose: provide the Service, personalization, product analytics — recipients: analytics, hosting, CDN providers.
Approximate geolocation (city/region/country, not precise) — purpose: security, content delivery, analytics — recipients: CDN/security, IP-to-location, analytics, hosting providers.
Audio/visual information (profile picture, uploaded support attachments) — purpose: profile display, customer support — recipients: hosting/object-storage providers.
Sensitive personal information (account log-in credentials) — purpose: authentication and security only — recipients: hosting provider (no other recipients).
Inferences (content/genre preferences) — purpose: personalization and recommendations — recipients: hosting and analytics providers.
Categories of sources. We collect personal information directly from you (registration, profile, payments, user-generated content, support requests); automatically from your use of the Service (device, network, usage, and approximate-location data); and from third parties, including social and platform sign-in providers (Google, Facebook, Telegram), payment processors and app stores, and our content-delivery/security and IP-to-location providers.
Retention. We retain each category for the period described in "How Long We Keep Your Data," or for the criteria stated there. In summary: account identifiers and customer records are kept for the life of your account and then deleted or anonymized; financial/transaction records are kept for the minimum period required by tax and accounting law (which may be several years) even after deletion; internet/network activity and analytics/play events are kept for a limited period (generally up to around 90 days for raw events) and then deleted or aggregated; security, audit, and system logs are kept for short operational periods; and sensitive PI (log-in credentials) is kept only for the life of the account.
Your California rights. As a California resident you have the right to: know and access the categories and specific pieces of personal information we collect, use, and disclose; delete personal information we collected from you, subject to exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell or share); limit the use and disclosure of sensitive personal information (we use it only for permitted purposes); and not be discriminated or retaliated against for exercising these rights — we will not deny you the Service, charge a different price, or provide a different level of quality because you exercised your California privacy rights.
Right to opt out of sale or sharing; Global Privacy Control. We do not sell your personal information and do not share it for cross-context behavioral advertising, so there is nothing for you to opt out of, and we do not display a "Do Not Sell or Share My Personal Information" link. Some browsers send an opt-out preference signal such as the Global Privacy Control (GPC); because we do not sell or share, our processing already reflects an opted-out state. If our practices ever change, we will update this Policy, provide the required opt-out mechanism, and honor GPC signals as a valid opt-out for the browser or device from which they are sent.
Sensitive personal information and your right to limit. The only sensitive personal information we collect is your account log-in credentials. We use and disclose it solely to perform the Service, authenticate you, secure your account, and prevent fraud — purposes for which California law does not require us to offer a separate right to limit. We do not use it to infer characteristics about you or for advertising, and we do not collect precise geolocation, biometric, health, or similar sensitive categories. Accordingly, we do not display a separate "Limit the Use of My Sensitive Personal Information" link.
Financial incentives. We may operate a referral program that lets you earn account credit or a payout when people you refer sign up or subscribe. This is a referral reward tied to a qualifying sign-up or purchase; it is not a payment in exchange for, or conditioned on, your providing or allowing us to retain your personal information, and it does not change the price or quality of the Service based on your privacy choices. We therefore do not consider it a "financial incentive" requiring a separate notice. If we ever offer a program that pays you for your personal information, we will provide a Notice of Financial Incentive with the material terms and a good-faith estimate of the value of the data, and obtain your opt-in consent as required.
Authorized agents. You may use an authorized agent to submit a request on your behalf. The agent must provide proof that you gave them signed permission (or a valid power of attorney). Unless you have given a power of attorney, we may also ask you to verify your own identity directly and to confirm that you authorized the agent. Send agent requests to [email protected].
How to submit a request and verification. Because we operate exclusively online and interact with you directly through your account, our designated method for verifiable consumer requests is email to [email protected]. We will confirm receipt within 10 business days and respond within 45 days (extendable by a further 45 days where reasonably necessary), free of charge up to twice in any 12-month period. We will verify your identity to a degree of certainty appropriate to the sensitivity of the information requested before disclosing or deleting it.
Minors. The Service is intended for users 17 and older, and we do not sell or share personal information. We do not knowingly sell or share the personal information of consumers under 16, and would not do so without the opt-in consent required by California law (from the minor if 13–15, or from a parent/guardian if under 13).
Additional Information for Users in Indonesia (UU PDP)
Primary framework: UU PDP (Law No. 27 of 2022) is the primary framework governing our processing of your personal data.
Your rights are recognized under UU PDP Articles 5–13 and are described in "Your Privacy Rights and Choices," including the right to information, access, correction, ending processing and deletion/destruction, withdrawing consent, objecting to automated decisions, delaying or restricting processing, data portability, and bringing a claim and seeking compensation for a violation.
Analytics: our product analytics operate for all users on the basis of our legitimate interest in measuring and improving the Service (UU PDP Art. 20(2)(f)), which we have balanced against your interests. You may ask us to delay, restrict, or object to this processing by contacting [email protected].
Data-protection contact and grievances: contact [email protected]. We currently perform the data-protection function directly and will appoint a Data Protection Officer if and when required under UU PDP Article 53.
Governing Law
This Privacy Policy and any matter relating to our processing of your personal data are governed by the laws of the Republic of Indonesia, including UU PDP, without prejudice to mandatory data-protection rights you may have under the laws of your own country of residence (such as the GDPR or CCPA/CPRA). You retain your right under UU PDP to bring a claim and seek compensation for a violation of the processing of your personal data.
Accessibility
We aim to make this Privacy Policy accessible to people with disabilities and to follow recognized accessibility guidelines (such as WCAG) where reasonably practicable. If you use assistive technology and have difficulty accessing this Policy, or need it in an alternative format, contact us at [email protected] and we will provide it in a format you can access.
Language
This Privacy Policy is provided in English. [If you publish a Bahasa Indonesia version — recommended for Indonesian users under Indonesian law — add: "and in Bahasa Indonesia. The Indonesian-language version is available at [link]. If there is any inconsistency, the Bahasa Indonesia version prevails for users in Indonesia."]
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and, where appropriate, provide additional notice (such as through the Service or by email). Your continued use of the Service after the changes take effect constitutes your acknowledgment of the updated Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at [email protected]. We are based in Indonesia. Additional contact details for the operator are available on request.