KLKToki Privacy Policy

Privacy Policy · Version 2.0 · Effective date: 13 September 2026

Data Controller: Lumeorix (operating the KLKToki service) — [email protected]

This Privacy Policy describes how Lumeorix (“we”, “us”, “our”), as operator of the KLKToki mobile and web application (the “Service”), collects, uses, discloses, transfers, retains, and protects personal data when you create an account, use the feed, messaging, audio/video calling, live features, communities, payments, or related backend services. By using the Service, you acknowledge this Policy. Where required by law, we will obtain your consent for specific processing activities.

1. Scope and definitions

“Personal Data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion. This Policy applies to all users of KLKToki worldwide. Additional rights for residents of the European Economic Area (EEA), the United Kingdom, and California are described below. This Policy covers the KLKToki apps for Android and iOS and the website at klktoki.com, including APIs that power those clients.

2. Personal data we collect

We collect Personal Data that you provide, that is generated through your use of the Service, and that we obtain automatically from your device and network. We do not require special-category data (such as health, religion, political opinions, or sexual orientation) as a condition of using KLKToki. If you voluntarily include such information in user-generated content, it is processed as content you chose to share.

2.1 Data you provide

Account data: full name or display name, username, email address, password (stored only as a modern cryptographic hash such as Argon2id; never in plaintext), and date of birth or age confirmation for minimum-age verification. Profile data: avatar, biography, language and preference settings. Optional phone number where SMS or verification features are enabled. User-generated content: posts, photos, videos, comments, reactions, music uploads, and community contributions. Communications: direct messages and related metadata (timestamps, delivery/read status). Support correspondence you send to our team. Payment-related details needed to complete a transaction (processed by our payment provider; we do not store full card numbers).

2.2 Data collected automatically

Device and technical identifiers: device type/model, OS version, app version, approximate device identifiers used for session security, and push-notification tokens (for example via Firebase Cloud Messaging). Network data: IP address, connection type, and approximate location derived from IP. Precise GPS location only when you grant permission for a specific feature (for example nearby communities or optional geotagging). Usage and diagnostics: feature interactions, session duration, performance metrics, and crash logs (including via error-monitoring tools). Security signals: login history, trusted devices, multi-factor authentication state, and fraud/abuse risk indicators. Real-time audio and video streams during calls or live sessions are processed to deliver the feature and are not retained as recordings unless you (or a host, where disclosed) explicitly enable recording.

3. Legal bases for processing

Where GDPR/UK GDPR applies, we process Personal Data on one or more of these bases: (a) performance of a contract — to provide the Service under our Terms; (b) consent — for optional features such as push notifications, precise location, or marketing communications; (c) legitimate interests — security, fraud prevention, service improvement, and aggregate analytics, balanced against your rights; (d) legal obligation — where we must retain or disclose information under applicable law.

4. How we use personal data

We use Personal Data to: create and administer accounts; authenticate users and protect accounts (including MFA and device trust); operate the feed, messaging, calls, live rooms, communities, and related features; personalize recommendations within the Service; process payments and donations through our payment processor; send operational messages (verification, security alerts, service notices); detect and prevent fraud, abuse, spam, and unauthorized access; diagnose performance issues; comply with law and respond to valid legal process; and enforce our Terms and community standards.

5. Sharing and disclosure

We do not sell Personal Data and we do not rent it for third-party advertising networks. We may disclose Personal Data: (1) to other users according to your privacy settings and the nature of the content you post or share; (2) to service providers acting as processors under contractual confidentiality and data-processing terms (hosting, media transport, payments, push delivery, crash monitoring, storage); (3) in connection with a corporate transaction (merger, acquisition, or asset sale), with notice where legally required; (4) when required by law or to protect the rights, safety, and security of KLKToki, our users, or the public.

6. Categories of service providers

Infrastructure and hosting providers process server-stored data needed to run the Service. Real-time communications infrastructure processes audio/video streams during calls and live sessions. Payment processors (PCI-DSS certified) handle payment credentials; we do not store full primary account numbers. Push-notification platforms deliver device messages. Error and stability monitoring tools receive technical logs and crash diagnostics. Object storage providers store media you upload. These providers are authorized to process data only on our documented instructions and for Service operation.

7. International transfers

Personal Data may be processed in countries other than your country of residence, including jurisdictions where our infrastructure or processors operate. Where we transfer Personal Data from the EEA, UK, or other regions that require safeguards, we use appropriate mechanisms such as Standard Contractual Clauses or other lawful transfer tools, together with technical and organizational measures.

8. Cookies and similar technologies

On the web we use session cookies and similar technologies necessary for authentication, security, and preferences (including language). In the mobile app we use local storage and SDKs required for stability, push delivery, and security. You can control certain permissions (including location and advertising identifiers where applicable) in your device settings. We do not use third-party advertising tracking cookies as a core part of KLKToki; first-party sponsored placements may appear in the feed under our own advertising products.

9. Security measures

We implement technical and organizational measures designed to protect Personal Data, including TLS encryption in transit, hashed passwords, signed session tokens, secure session storage, optional multi-factor authentication, role-based internal access controls, rate limiting and abuse detection, and monitoring. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work continuously to reduce risk.

10. Retention

We retain Personal Data while your account remains active and for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and prevent fraud or abuse. After account deletion, we delete or anonymize Personal Data within a reasonable period, generally within 90 days, except where longer retention is required by law (for example certain payment or security records). See also our Account & Data Deletion page for operational details.

11. Your privacy rights

Depending on your jurisdiction, you may have the right to access, correct, delete, port, restrict, or object to certain processing of your Personal Data, and to withdraw consent where processing is consent-based, without affecting the lawfulness of prior processing. You may exercise many rights from account settings or by contacting [email protected]. You may also lodge a complaint with your local data-protection authority.

12. California residents (CCPA/CPRA)

If you are a California resident, you have the right to know the categories of personal information we collect and the purposes of collection; to request deletion; to opt out of the “sale” or “sharing” of personal information (we do not sell personal information); and to non-discrimination for exercising these rights. Submit requests to [email protected].

13. EEA and UK residents (GDPR)

If you are in the EEA or UK, Lumeorix acts as controller of your Personal Data for the Service under the GDPR or UK GDPR as applicable. You may contact us to exercise your rights and may lodge a complaint with your supervisory authority.

14. Children’s privacy

The Service is not directed to children under 13 years of age (or the higher digital consent age required in your country). We do not knowingly collect Personal Data from children below that age without verifiable parental consent where required. If we learn that we have collected such data, we will take steps to delete it promptly.

15. Security incident notification

If a security incident affecting Personal Data creates a risk to your rights and freedoms, we will notify you and competent authorities within the timeframes required by applicable law.

16. Changes to this Policy

We may update this Policy to reflect changes in our practices or legal requirements. Material changes will be communicated through the Service, email, or a prominent notice before they take effect. The version and effective date at the top of this page identify the current Policy.

17. Contact

For privacy questions, rights requests, or complaints related to this Policy, contact Lumeorix / KLKToki at [email protected]. We will respond within the timeframes required by applicable law.

Language note: This document is published in all languages supported by KLKToki. If there is any inconsistency between translations, the English and Spanish versions prevail for interpretation.