1. Who We Are
Chiku Live is a live video and social entertainment platform for adults aged 18 and over.
- Operator: Chiku Live LLP, a limited liability partnership registered in India
- Governing law / jurisdiction: India
- Website: https://chikulive.com
- General contact: contact@chikulive.com
- Grievance Officer (India — DPDP Act / IT Act): Grievance Officer, Chiku Live LLP — contact@chikulive.com
2. Scope of This Policy
This policy describes the personal data Chiku Live collects when you use our app and website, how we use it, who we share it with, where we store it, how long we keep it, and the rights you have over it.
3. Who Can Use the App
You must be 18 or older to create an account. We ask for your date of birth at sign-up and use it to verify this. See Section 11 for our children's policy.
4. What We Collect
4.1 Account and Contact Information
When you create an account we collect:
- Email address — used as your login credential or as a linked address.
- Phone number — collected if you use phone-number login.
- Recovery email address — optional; you provide it yourself and verify it with a one-time code.
- Google account email, display name, and profile photo URL — collected only if you choose to sign in or link via Google.
Your email address, phone number, and recovery email are stored in a private part of your account that is readable only by you and our authorised staff. They are not stored on your public profile.
4.2 Profile Information (Visible to Other Users)
The following fields on your public profile are readable by any signed-in user:
- Display name and display ID (a four-digit sequential number) — shown on your profile and in live rooms.
- Gender — used to determine which features you can access; female users may go live at any level; male users must reach level 10 first.
- Birth year — your approximate age (current year minus birth year) is shown on your profile. Your full date of birth is kept private (see 4.3).
- Profile photo and photo wall (up to five photos).
- Profile video (Video Avtaar) — a short clip shown on your profile.
- Cover photo — shown to viewers in the Explore feed before they enter your live stream.
- Bio (text).
- Vibes / interests — tags you select; shown as chips on your profile and used to match you with relevant live streams.
- Country flag — derived from your IP address (see 4.9) and stored as a country code.
- Online / offline / live / on-call status and last-seen time.
- Level, follower count, following count.
4.3 Date of Birth
Your full date of birth is collected at sign-up to confirm you are 18 or older. It is stored in a private part of your account and is not visible to other users. Other users see only your birth year.
4.4 Face Verification Data
To unlock live streaming, 1-on-1 calls, PK battles, party rooms, and points withdrawal, we ask you to complete a face liveness verification. During this process:
- A reference frame (face image) from the liveness session is sent to Amazon Web Services Rekognition (region ap-south-1, Mumbai, India) via the AWS Face Liveness SDK, which uses Amazon Web Services Cognito to obtain temporary credentials for the session.
- A face biometric vector is extracted by Rekognition and stored with Amazon Web Services Rekognition, linked to your user ID.
- An enrollment selfie (the reference image returned by AWS after the liveness challenge) is stored in a private location accessible only to our authorised staff. It is not accessible to you or to other users.
Your cover photo is checked against your enrolled face each time you upload one (Rekognition 1:1 face match).
If someone else attempts to enroll using a face that matches yours, both the blocked attempt image and a copy of your enrollment image are stored in a private part of your account where only you and our authorised staff can see them.
None of your biometric data is visible to other users. See Section 8 for deletion details.
4.5 Content You Post or Stream
- Posts (photos and videos), their captions, and likes and comments — visible to all signed-in users.
- Gift Moment clips — short video clips captured from your live stream feed and published as posts; visible to all signed-in users.
- Voice notes — audio clips you send to a host during a live room or party; stored in our file storage and readable only by that host.
- Profile visit log — we record which profiles you visit and which users have visited yours; visible only to the profile owner (not to other general users).
Photos and videos you post are scanned for prohibited content using Google Cloud Vision SafeSearch (for images) and Google Cloud Video Intelligence (for videos) before they are published.
4.6 Direct Messages
Text you send in private 1-on-1 conversations and any image attachments are stored in our database and file storage. Image attachments are scanned for prohibited content via Google Cloud Vision SafeSearch before being delivered. Access to a conversation is limited to the two participants.
A short preview of your message (up to approximately 120 characters of text) and your display name are included in push notification payloads routed through Firebase Cloud Messaging. We do not offer end-to-end encryption for messages.
4.7 Gifts, Coins, Points, and Withdrawal Information
- Coin purchase records — when you buy coins via Apple App Store or Google Play in-app purchase, the purchase is recorded. Apple and Google handle payment processing; we do not receive your card details.
- Gift transaction ledger — every gift sent creates a permanent record containing sender ID, recipient ID, stream or call reference, gift type, coin cost, points credited, and timestamp.
- Fan club and VIP transaction records — permanent financial records. Fan club memberships and VIP plans are purchased with coins, not through the App Store or Google Play.
- Points ledger (XP and honor) — a per-event log of points earned and spent.
- Payout / withdrawal details — when you request a points withdrawal you provide payout details (bank account number and IFSC, UPI ID, or USDT TRC-20 wallet address, plus your name). These are stored in a private part of your account visible only to you and our finance staff. You must also enter a 6-digit security code to confirm each withdrawal request. Withdrawals have a minimum of USD $10 and must be in steps of $10 (or the full withdrawable balance). 10,000 points equal USD $1. Fees are: USDT withdrawals 1.5%, bank transfer 3%, EPAY a flat 10,000 points (USD $1). Points earned from gifts and calls funded by in-app coin purchases are held for 72 hours before they can be withdrawn. When your account is deleted, the payout details are redacted from withdrawal records (replaced with a marker noting only the payment type); withdrawal amounts, dates, and status are kept for financial audit purposes.
4.8 Device and Log Data
The following are stored in a private part of your account and are not visible to other users:
- Device name (e.g. "iPhone 16" or "Samsung Galaxy S24") — recorded when you log in from a new device to generate a security notification.
- Login timestamp and last-active timestamp — used to detect new-device logins and suppress duplicate alerts within 12 hours.
- Active session ID — a random identifier used to enforce single-device login (a new login from another device signs out the previous session).
Push notification tokens (FCM) are stored on your public profile and are readable by any signed-in user. They cannot be used to send notifications to your devices without our server credentials. The tokens are used to deliver incoming call alerts, security notifications, and other push notifications to your devices. They are removed when you sign out and are deleted when your account is purged.
A one-way hash of your most recent password is stored in a server-only private location. It is not readable by you, other users, or staff through the app; it is used only to prevent password reuse when you change your password.
4.9 Approximate Location / Country from IP Address
When you set up your profile and each time you join a live room, your device sends an HTTP request to ipapi.co, a third-party geolocation service. Your device's IP address is transmitted as part of that request. The app uses only the country code returned (for example, "IN" for India) and does not store your IP address. The country code is stored on your profile and shown to other users as a country flag.
4.10 In-App Notification and Privacy Preferences
Your notification preferences and privacy settings (alert toggles, message allowance setting, and similar) are stored in a private part of your account and are not visible to other users.
4.11 Call and Live Stream Activity
- Call document — when a 1-on-1 call is created, a record is made containing the caller's and host's IDs, names, and photos, the price per minute, total duration, coins spent, points credited, and start/end times. This is a permanent financial record.
- In-call chat messages — text exchanged during a call is stored under the call record.
- Post-call ratings — a caller's star rating and tag feedback are stored after a call; the aggregate score is shown on the host's profile.
- Stream viewer presence — while you are in a live room, your display name, photo, country, and level appear in the viewer list visible to all viewers in that room.
- Join/entry announcements — when you enter a live room or party, your display name, photo, and level are broadcast as an entry announcement visible to all current viewers in that room.
- Gift events — when you send a gift during a live stream, your display name, photo, the gift details, and coin amount are shown to all current viewers in the room.
4.12 Leaderboard Entries
Your user ID and country code appear in public leaderboard rankings for coins spent, gifts received, invite referrals, and similar tracks. Rankings accumulate across periods and are visible to all signed-in users.
4.13 Invite Feed
When you earn an invite reward, your display name and the reward amount appear in a public social-proof feed visible to all signed-in users on the invite page.
4.14 Support Tickets and Reports
- Support tickets you submit — including the text of your messages, your user details, and any images you attach — are visible to our support and moderation staff.
- Reports you file against other users — including your identity, the reported user's identity, the reason, and any free-text details — are visible to our moderation staff only.
4.15 iOS Clipboard (Referral Code Detection)
On first launch on iOS, the app reads the device clipboard once to detect whether a referral code (in the format chikuinvite:<code>) is present. The clipboard content is used only to attribute the install to an inviter; no other clipboard data is read or stored. If a valid referral code is found, it is saved to record the invite relationship. iOS 14 and later shows a system notification when an app reads the clipboard.
4.16 Optional AI Features (Not Currently Active)
The app contains code for two AI features that are not currently switched on (their API keys are placeholders and the functions are not deployed):
- AI Bio — when this feature is available and you choose to use it, your display name and up to four interest/vibe tags would be sent to Groq (a language model API) to generate a suggested bio. No photo is sent. The generated text is shown to you before you can publish it.
- AI Glow-Up — when this feature is available and you choose to use it, a selfie you upload would be sent to Replicate (using the zsxkib/instant-id model) to generate an AI-styled portrait. The generated image would then be scanned by Google Cloud Vision SafeSearch before being stored privately in your account.
We will update this policy and notify you before enabling either feature.
5. Why We Use Your Data
| Purpose | Data used |
|---|---|
| Create and manage your account | Contact details, profile, auth credentials |
| Verify your age (18+ requirement) | Date of birth |
| Verify your identity and prevent fraud and multi-account abuse | Face biometric data |
| Deliver live streams, 1-on-1 calls, and messaging features | Profile, presence, messages, voice notes, live stream data |
| Moderate content to keep the app safe | Photos, videos, images in messages (via Google Cloud Vision / Video Intelligence) |
| Process coin purchases and points withdrawals | In-app purchase records, withdrawal/payout details |
| Detect new-device logins and send security alerts | Device name, login timestamps |
| Enforce single-device sign-in | Active session ID |
| Deliver push notifications | FCM tokens, message previews |
| Show country-relevant content and matches | Country code |
| Maintain financial and audit records | Gift, call, and coin ledgers; withdrawal records |
| Investigate reports and support tickets | Report contents, account data |
| Show public leaderboards and social-proof invite feed | Display name, user ID, country code, points earned |
6. Who We Share Your Data With
We do not sell your personal data. We share it only as follows:
| Recipient | Data shared | Purpose |
|---|---|---|
| Google / Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, FCM) | All data stored on Firebase; push tokens | Core infrastructure |
| Google Cloud Vision SafeSearch | Image bytes of profile photos, post photos, DM image attachments, AI-generated images | Content moderation |
| Google Cloud Video Intelligence | Video file references for post videos and profile videos | Content moderation |
| Amazon Web Services — Rekognition (ap-south-1, Mumbai) | Face image bytes; stores your face biometric vector | Identity verification and anti-fraud |
| Amazon Web Services — Cognito (ap-south-1, Mumbai) | Used by the Face Liveness SDK to obtain temporary session credentials | Face liveness session |
| ipapi.co | Your device's IP address (implicit in the HTTP request) | Country detection |
| Self-hosted LiveKit server (media.chikulive.com) | Your Firebase UID, display name, and live audio/video streams | Real-time live streaming and calls |
| Firebase Cloud Messaging (Google) | FCM tokens; message preview text (up to ~120 chars); caller name and photo in call notification payloads | Push notifications |
| Apple App Store / Google Play | In-app purchase transactions | Payment processing |
| Other signed-in users | Public profile fields (Section 4.2), live-room activity, gift events, entry announcements, leaderboard entries, invite feed entries, FCM tokens (stored on your public profile; cannot be used to send notifications without our server credentials) | Core social features |
| Our moderation and support staff | Reports, support tickets, and private account data when investigating a reported account | Safety and support |
| Our finance staff | Withdrawal requests and payout details | Withdrawal processing |
7. Where Your Data Is Stored
| System | Location |
|---|---|
| Firebase (Firestore, Storage, Cloud Functions) | asia-south1 — Mumbai, India |
| AWS Rekognition and Cognito | ap-south-1 — Mumbai, India |
| LiveKit media server (self-hosted) | media.chikulive.com — Bengaluru, India (DigitalOcean) |
| ipapi.co | Operated by a third party; see https://ipapi.co/privacy/ |
8. How Long We Keep Your Data
8.1 Active Accounts
We keep your data for as long as your account is active.
8.2 Account Deletion and the 30-Day Grace Period
You can request account deletion in the app (Settings → Delete account). After you confirm the request, a 30-day grace period begins. During this period you can cancel the request and restore your account. After 30 days a scheduled automated process performs the following steps on a best-effort basis:
Permanently deleted:
- Your login credential record.
- Your AWS Rekognition face biometric vector.
- All data in our database associated with your account, including your private account information, enrollment selfie, notification preferences, follow relationships, and all other account data.
- All files in our file storage associated with your account, including your profile media, stream covers, posts, gift moments, and outbox files.
- Voice notes sent by others to you during your own live streams — audio clips viewers recorded and sent to you as the host.
- Your posts (database records and stored files).
- Your invite links.
- Your ranking entries across all leaderboard periods.
- Your username slot (released for reuse).
Redacted (not fully deleted):
- Withdrawal requests — your bank account number, UPI ID, USDT wallet address, and name are replaced with a marker noting only the payment type. The withdrawal amounts, dates, and status are retained for financial audit purposes.
Kept (not removed on account deletion):
- Messages you sent to others — message text and any attached images remain in the other participant's conversation history; your display name and photo may remain associated with those messages.
- Voice notes you sent to other hosts — audio clips you recorded and sent to a host during their live stream or party are stored in that host's file storage. These files are not deleted when your account is purged.
- Invite feed entries — when you earn an invite reward, a record containing your display name and the reward amount is published to a public social-proof feed. These entries are not removed when your account is deleted. To request removal contact us at contact@chikulive.com.
- Financial ledger records — gift transactions, fan club transactions, VIP purchase records, and call billing records (these reference your user ID but do not contain payout details).
- Reports you filed or that were filed against you — retained for safety and moderation purposes.
- Support tickets — retained for support purposes.
- Gift events, stream entries, and similar records that reference your user ID in shared records.
8.3 Other Retention Periods
- LiveKit server logs (your user ID and display name in session data): kept on our media server in India for troubleshooting and security.
9. Security
We take the following measures to protect your data:
- All data in transit between the app and our servers is encrypted with TLS.
- Access rules restrict who can read our database and file storage: your public profile fields are readable only by signed-in users; your private account data is readable only by you and our authorised staff.
- Your enrollment selfie and face biometric vector are stored in locations that are not accessible to clients or other users.
- Your password is never stored in plaintext; only a one-way hash in a protected server-only location is kept, and it is never logged.
- Single-device sign-in enforcement limits concurrent access to your account.
No security measure is perfect. If you believe your account has been compromised, contact us immediately at contact@chikulive.com.
Note: the app does not block screen recording on either Android or iOS (the screen-lock feature is currently disabled in code). Viewers may be able to record live streams.
10. Your Choices and Rights
Depending on the law that applies to you, you may have the right to:
- Access a copy of your personal data.
- Correct inaccurate data — you can edit most profile fields in the app.
- Delete your account and the associated personal data (Settings → Delete account; see Section 8.2 for what is and is not deleted).
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
To exercise any right other than in-app profile editing or account deletion, please contact us at contact@chikulive.com. We will respond within the timeframe required by applicable law.
We do not currently provide an automated personal-data export tool. To request a copy of your data, please write to us at the contact address above.
11. Children
Chiku Live is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has created an account, please contact us at contact@chikulive.com. We will investigate and delete the account.
12. Changes to This Policy
We may update this policy from time to time. When we make material changes we will post the updated policy at https://chikulive.com and, where appropriate, send you a notification in the app. The "Last updated" date at the top shows when it was last revised.
13. Contact and Grievance Officer
General enquiries and data rights requests:
Chiku Live LLP
Email: contact@chikulive.com
Grievance Officer (India — DPDP Act 2023 / IT Act 2000):
Grievance Officer, Chiku Live LLP
Email: contact@chikulive.com