LEGAL

App Privacy Policy

This policy covers the Kachak app — photos, spaces, guest lists, payments and accounts. The website policy is a separate, much smaller document: this site collects one email address and nothing else.

Who we are

Kachak is operated by KACHAK SPACE INNOVATION, SSM registration 202603188421 (KT0617814-H), a business registered in Malaysia, of Kuala Lumpur. For anything to do with your personal data, write to hello@kachak-app.com. A person reads it.

What we collect

  • Your name, and a profile photo if you add one.
  • The photos you take in a space, and which space they belong to.
  • A sign-in identifier — your Apple ID, Google account or phone number — if you make an account. You can use Kachak without one: joining a space needs no account at all.
  • A notification token for the device, so we can tell you a guest joined or a space is closing.
  • A contact phone number, if you enter one, or the number you verified at sign-in.

We do not collect your contacts, your precise location, or your browsing activity. We do not see or store card details — payments go to HitPay, and what comes back to us is whether a payment succeeded.

Usage analytics, and how to turn them off

We measure how the app is used — screens opened, how large the photos it uploads are, whether a roll finished — through Google Analytics for Firebase. That includes the country your connection appears to come from, which is why the line above says precise location. It is about the app, never about what is in your photos, and it is not used for advertising.

You can switch it off inside the app: Profile → Privacy & consent → Usage analytics. Nothing else changes when you do.

Crash reports

Separate from analytics, and always on. When the app fails, Firebase Crashlytics sends us what it was doing and what kind of device it was on, so the fault can be found and fixed. It carries no photograph and nothing you typed. The analytics switch does not turn this off — an app that cannot report its own crashes cannot be repaired.

Your photos are shared within a space, and nowhere else

Photos you take in a space are visible to the members of that space. Not to the public, not to other spaces, not to us for any purpose beyond storing and serving them. We do not use your photos for advertising and we do not use them to train models.

By joining a space and shooting, you agree that your photos are shared with that space's members. Please only photograph people who are happy to be in the shot.

How long we keep it

A space is open for five days. Its photos stay viewable for sixty days after it closes, and are then deleted along with the space itself — that expiry is the product, not a limitation. Your name and profile photo stay until you change or delete them. A guest account is discarded when you delete it, or superseded when you add an account to it — there is no logging out of one, because there is nothing to log back in to.

Deleting your account

You can delete your account from inside the app: Profile → Delete account. No email, no form, no waiting.

It deletes your account and everything personal about it — your profile, your rewards, your referral code, your notification tokens, your avatar — and takes your name off every space you joined, replacing it so the roster no longer identifies you.

Two things deliberately survive, and it is worth knowing before you tap it. Photos you took stay in the spaces they were shot for, because they belong to that event as much as to you and the other people in it did not choose for them to vanish. Spaces you hosted are not destroyed either, for the same reason — other people's photos are inside them. Both expire on their own schedule, within about two months. A roll cannot be curated — nobody deletes their own frames, which is what makes a Kachak gallery the evening as it happened rather than the version everyone was happy with. If a particular photo should not be there, report it from the photo, or ask that space's host, who can remove any frame in their own space. Do that before deleting your account: afterwards there is no account left to ask from.

If you signed in with Apple, deleting also revokes the Sign in with Apple token, so Kachak's access to your Apple ID ends with the account.

Your rights

Under Malaysia's Personal Data Protection Act 2010, and equivalent rules elsewhere, you can ask us to tell you what we hold and give you a copy, correct it, delete it, or stop using it. Most of that you can do yourself in the app; for anything else, email hello@kachak-app.com. There is no charge and no form. If you are unhappy with how we handle it, you can complain to the Personal Data Protection Commissioner in Malaysia.

Who processes it for us

  • Google Firebase — sign-in, database, photo storage and notifications. Data is stored in Singapore (asia-southeast1).
  • HitPay — payments. They receive what a payment needs; we never receive your card details.
  • Apple and Google — only if you choose to sign in with them, and only to confirm it is you.

We do not sell, rent or trade your data, and we never will.

Children

Kachak is for people aged 18 and over — hosting is a paid agreement, and we have no way to take a parent or guardian's consent. We do not knowingly collect data from anyone younger; if a minor has an account, write to us and we will delete it.

Notifications

We notify you about your spaces — a guest joining, a space closing soon, photos about to vanish. Turn them off any time in your device settings.

Changes

If this policy changes we will update this page and the date below, and say so in the app where the change is material.

Last updated 10 September 2026. KACHAK SPACE INNOVATION (SSM 202603188421), Kuala Lumpur, Malaysia.