Privacy

Last updated September 3, 2026

This is the English version of the Kulhad privacy policy, and it is the version that applies. Translations are for convenience.

1. About this policy

1.1 What it covers

This explains what Kulhad collects about you, why, who else sees it, how long we keep it, and what you can ask us to do about it. It covers kulhad.co, every creator page we serve including those on a creator's own domain, and the dashboard.

1.2 What it does not cover

It does not cover the payment itself. When you support a creator, the money goes from your bank to theirs over UPI and we are not a party to it. We never see your card number, your account number or your UPI credentials, because they are never sent to us. What your own bank and payment app record about that payment is governed by their policies, not by this one.

It also does not cover what a creator does with information you give them, or what a third party application does with data you allow it to read.

2. The short version

  • We collect what a creator types into their page, and what a supporter types into the pay card.
  • Supporting a creator needs no account, and leaving no name and no email is a complete option that changes nothing else.
  • A supporter's email address is never shown to the creator, never in their export, and we never send anything to it.
  • We do not sell personal data, we run no advertising, and we do not email a creator's supporters.
  • We run no analytics or tracking script of our own on any page.
  • You can take a copy of everything and delete your account yourself, from the dashboard.

3. What we collect

3.1 If you create a page

  • Your email address, from Google or from asking us to send you a sign in code.
  • What you put on your page: your name, your page name, your description, your profile photo and cover image, links to your other profiles, whether the page is for a person or an organisation, and the language it is written in.
  • The UPI IDs you publish, and a label for each so you can tell them apart.
  • Your goals, their targets, descriptions, cover images and the progress notes you write.
  • Your settings: suggested amounts and their labels, your thank you note, saved replies, the page theme, an announcement banner, and how you want supports handled.
  • Your custom domain, if you connect one.
  • Your own Google Analytics ID, if you choose to add one.
  • Subscription records, if you buy Premium: which plan, its status, when the period ends, and a record of each charge with a link to the provider's invoice.
  • A few timestamps of what we observed, such as when you first copied your page link or downloaded your QR code, which is what the setup checklist reads.

3.2 If you support a creator

  • The amount you entered.
  • The name you chose to leave, if you left one. Leaving it blank is a full option and the support shows as "Someone".
  • The message you wrote, if you wrote one.
  • A voice recording, if you made one.
  • The reference code we generated, and which of the creator's UPI IDs you were shown.
  • Your email address, only if you chose to give it. It exists so you can sign in later and see what you have sent. It is not shown to the creator, it is not in any export they can take, and we never send anything to it.
  • A salted, one way hash of your IP address, used to limit abuse. We do not keep the address itself.
  • Which link or surface you arrived from, such as the page itself, an embedded button, a QR code or a link a creator tagged for a particular channel.

3.3 If you sign in to see what you have sent

Signing in as a supporter creates the same kind of account a creator has, holding your email address and nothing else until you use it for something.

3.4 Collected automatically

  • Page view counts. We count views per page per day. There is no cookie, no identifier and no per visitor record behind that number: we cannot tell you who visited a page, and neither can the creator.
  • Rate limiting counters, briefly, so one person cannot flood a page or an inbox. For sign in codes this includes your email address and your IP address as the counter's key, for the length of the limiting window.
  • Server and edge logs. Our hosting and network providers record requests, including IP address, browser and page, under their own retention.

3.5 From other services

  • From Google, if you sign in with it: your email address and your name.
  • From a payment provider, if you buy Premium: the subscription status, whether a charge succeeded, and a link to the invoice. We also store the provider's own record of the event as it sent it to us.

4. Why we use it

  • To show a creator's page and to run the pay card, the QR code and the receipt.
  • To sign you in and keep you signed in.
  • To let a creator see and act on their supporters.
  • To count what a page has raised and how far a goal has come.
  • To email a creator when somebody marks a payment as sent, and about their account and billing. We never email supporters.
  • To take payment for Premium and keep a record of it.
  • To limit abuse, to keep automated submissions out, and to look into a report.
  • To answer you when you write to us.
  • To keep the records the law requires us to keep, and to respond to a valid legal request.

We do not use any of it to advertise to you, and we do not profile you.

5. What is public on a creator page

A creator page is a public web page. Anyone who visits it, and search engines, can see the creator's name, page name, description, photo, cover image, links, goals and progress notes.

Once a creator approves a support, the supporter's name, message and voice recording become public on that page too, along with the amount and the creator's reply. A support left without a name shows as "Someone". Until a creator approves it, a message is visible only to them, and a voice recording is served only to them.

A creator can choose whether the total raised and the number of supporters are shown.

6. Who we share it with

We do not sell personal data, and we do not share it for anybody else's marketing.

6.1 Service providers

These process data so that we can run the service, on our instructions:

  • Hosting and networking, which carries every request.
  • Object storage, which holds every image, audio and video file uploaded to Kulhad, including supporters' voice recordings.
  • Email delivery, which sends account and notification emails and therefore receives the recipient address and the contents of the message.
  • An anti abuse check on the pay card and the report form, which receives the visitor's IP address for that check.

6.2 Payment providers

If you buy Premium, we pass what the provider needs to bill you and receive back the subscription and payment status. Depending on which provider handles your subscription, this may include your email address and name. One of the providers we use is established outside India, so where it handles your subscription your billing information is processed outside India under that provider's own safeguards.

We never receive or store your full card, bank account or mandate details.

6.3 Analytics a creator adds themselves

We run no analytics or advertising script of our own on any page.

A creator on Premium may add their own Google Analytics ID. Where one has been added, that page loads Google's script, and Google receives the visitor's IP address, browser, the page visited and where they came from, and may set its own cookies. That happens under the creator's own arrangement with Google, and the creator is responsible for it. A page with no such ID loads no third party script at all.

6.4 Apps you connect

If you connect a third party application to your account, it can read and change what you approved on the consent screen, and that data then sits with them under their terms. We never give a connected app your supporters' email addresses or the hashes of their IP addresses.

You can see and disconnect anything you have connected, under Settings, in Connected apps. Disconnecting takes effect immediately: the application is refused on its very next request, rather than at the end of any window.

6.5 Legal requests

We may disclose information where the law requires it, where a valid order or request from a court or an authority compels it, or where it is necessary to establish or defend a legal claim or to protect somebody from harm.

7. What we never do

  • We never show a supporter's email address to a creator, and it is never in an export a creator can take.
  • We never email a creator's supporters.
  • We never sell personal data.
  • We never run advertising, and we do not track anybody across other websites.
  • We never see or store card, bank or UPI credentials.

8. Where your data is stored

Our database, our cache and our file storage are operated by providers we choose and are subject to their own security. Some of them, and some of the providers in section 6, operate outside India, so your information may be processed outside India. Where that happens we rely on our contracts with those providers and on the technical controls described in section 10.

9. How long we keep it

  • A support nobody acted on, still unpaid. 24 hours, then deleted.
  • A support marked as sent and not yet dealt with. 7 days, then deleted.
  • A support the creator rejected. 7 days, then deleted.
  • A support the creator approved. Until the creator deletes it, or deletes their account.
  • A creator's page and settings. While the account exists.
  • Sign in codes. 10 minutes.
  • Rate limiting counters. Minutes to an hour.
  • Page view counts, before they are totalled. 3 days.
  • Billing records and the payment provider's own event records. Kept as a financial record.
  • Reports about a page. Until the reported page is deleted.
  • A connected application's permission record. Until you disconnect it, or delete your account.
  • The token a connected application holds to stay signed in. 30 days from its last use, and immediately void once you disconnect.
  • The short-lived token it uses for each request. 1 hour, and refused from the moment you disconnect regardless of the hour.
  • Backups. About 7 days, then overwritten.

Deleting something removes it from the live service straight away. It can remain in a backup for up to about a week after that, until that backup ages out.

10. Security

We use access controls, encrypted connections, hashed and restricted secrets, and regular backups. Sign in codes are stored only as keyed hashes, are single use, and are destroyed after a few wrong attempts. A supporter's IP address is stored only as a salted hash. A voice recording is not publicly reachable until the creator approves it. Our database's public query interface is switched off.

No service on the internet is completely secure, and we do not claim otherwise. If a breach affecting your personal data occurs, we will act on it and notify whoever the law requires us to notify, in the time it requires.

11. Your choices and rights

11.1 Getting a copy

A creator can download everything on the account as a file from Settings, and the supporter list as a spreadsheet. Somebody who has signed in as a supporter can download what they have sent. If you want something these do not cover, write to hello@kulhad.co.

11.2 Correcting

A creator can change anything on their page from the dashboard. A supporter's message cannot be edited, by them or by the creator, because it is a record of what was said: a creator can hide it or reject it, and a supporter can have it removed under section 11.3.

11.3 Deleting your account

Both kinds of account can be deleted from Settings, and it is not reversible.

Deleting a creator account removes the page, the goals, the UPI IDs, the supports and their messages and recordings, the analytics and the billing records, and cancels any subscription with the payment provider.

Deleting a supporter account removes your email address, your name, your messages, your recordings and the hash of your IP address from every support you sent. The amount and the date stay, shown as "Someone", because they are part of a creator's own record of what they received and removing them would rewrite it.

11.4 What deletion cannot reach

Two honest limits.

If you sent support without leaving an email address, we have no way of knowing which support was yours, so we cannot find it to remove it on request. Nothing in it identifies you unless you typed something identifying into the name or the message.

Backups take about a week to age out, so a deleted record can persist in one for that long.

11.5 Withdrawing consent

Where we rely on your consent, you can withdraw it by removing the content, disconnecting the app, or deleting your account. Withdrawing does not undo anything lawfully done beforehand, and does not reach records we have to keep.

12. If something goes wrong

If you think your information has been mishandled, write to hello@kulhad.co and tell us what happened. We will look into it and reply.

13. Changes to this policy

We update this policy as the service and the law change. The date at the top of this page changes when we do, and where a change materially affects you we will make it visible in the product.

14. Contacting us and raising a grievance

Write to hello@kulhad.co for anything in this policy: a question, a request to see or remove your data, or a complaint about how we have handled it. Tell us enough to find the account or the support you mean. We may need to check that the request is really yours before we act on it.

If you are not satisfied with how we have dealt with a complaint, you may take it to the data protection authority in India.