Legal

Privacy Policy

Effective August 7, 2026 · Version 2026-08-07

Also see Terms of Service

1. Introduction

This Privacy Policy explains how Mukha Chitram ("Mukha Chitram", "we", "us", "our") collects, uses, discloses, stores, and protects personal information when you use the Mukha Chitram mobile application, website at mukhachitram.com, and related services (collectively, the "Service").

This policy applies to artists, producers, guests who browse without an account, website visitors, and anyone who interacts with the Service. It should be read together with our Terms of Service (also called Terms of Use / Terms & Conditions) at mukhachitram.com/terms.

Mukha Chitram is an admin-mediated marketplace for the film and performing-arts industry in India. Artists and producers do not contact each other directly inside the app. Staff of Mukha Chitram sit in the middle of every conversation (the "relay"). That design shapes what we collect and who can see it.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

Data Fiduciary. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), Mukha Chitram is the Data Fiduciary for personal data processed through the Service, except where a third-party processor (for example Razorpay, Apple, or Google) acts as an independent controller of payment credentials under its own policy.

2. Key definitions

In this Privacy Policy:

  • Personal information or personal data means information that identifies you or can reasonably be linked to you (a "Data Principal" under the DPDP Act).
  • User content means profile information, portfolio media, relay messages, reports, and other material you submit to the Service.
  • Artist means a user who creates a talent profile that may become discoverable after staff approval and payment.
  • Producer means a user who browses LIVE artist profiles and may send interest through the staff-mediated relay. Producers are never listed or shown to artists.
  • Staff means managers and admins who review profiles, moderate relay messages, and operate the Service. Staff authenticate only through a separate admin web app.
  • Processing means any operation on personal information, including collection, storage, use, disclosure, and deletion.
  • Service providers or processors means third parties that process personal information on our behalf to help operate the Service.

3. Information we collect

We collect information in three main ways: information you provide, information generated through your use of the Service, and limited technical information from your device.

Information you provide

  • Mobile phone number for OTP sign-in (required for accounts; this is the only consumer sign-in method)
  • Display name and role (artist or producer), chosen once at signup
  • Optional email address on artist profiles for receipts and notices only — never used as a login credential and never shown to producers
  • Artist profile details such as stage/display name, headline, bio, primary role, skills, languages, city, state, gender, years of experience, availability, credits, and related structured fields
  • Date of birth for artists — stored as a private field, used to compute an age band for filtering and shown only to staff; never returned to another consumer account
  • Photos, videos, audio samples, captions, and other portfolio media
  • External links you add (for example Instagram, YouTube, IMDb), subject to moderation
  • Messages you send into the staff-mediated relay (pending staff release, edit, or block)
  • Reports, support emails, and other communications you send us
  • For under-18 artist submissions where permitted: guardian consent documentation as required by our review process

Information generated through use

  • Profile listing status and review history (for example DRAFT, PENDING_REVIEW, APPROVED_UNPAID, LIVE, LAPSED, REJECTED, SUSPENDED, DEACTIVATED)
  • Relay thread and message states (PENDING, RELEASED, EDITED, BLOCKED), including staff actions and audit records
  • Private likes and saves (bookmarks). Artists may see anonymous interest notices or aggregate counts — never the identity of who liked or saved them
  • Verification / moderation notes and enforcement actions tied to your account
  • Payment status, plan tier, purchase history, Razorpay or store transaction references, and payment-window timestamps

Technical and device information

  • A random device identifier stored locally for guest browsing, rate limiting, and session continuity before or alongside sign-in
  • User ID and authentication tokens managed through our auth provider
  • Push notification token if you enable alerts
  • Device model, operating system version, app version, and language settings
  • Crash logs, error reports, and performance diagnostics when crash reporting is enabled
  • Optional usage events (for example onboarding steps) only if you leave analytics enabled in Settings → Privacy

Guest browsing. Anyone may browse discovery and public LIVE profiles without an account. Guests do not see private fields and are not counted as identified users in interest signals. Signing in is required to like, save, message, or create a profile.

4. How we collect information

We collect personal information:

  • Directly from you when you register, create a profile, upload media, send relay messages, make purchases, contact support, or change settings
  • Automatically when you use the app or website, including through logs, cookies or similar technologies on the web, and diagnostic tools
  • From service providers such as Apple, Google, Razorpay, and Supabase when needed to authenticate users, deliver notifications, process payments, or maintain infrastructure
  • From staff review when managers or admins process your profile, revisions, reports, or relay messages
  • From other users only in limited ways — for example when a producer likes or saves your LIVE profile (you are not told who), or when someone files a report

We do not buy personal information from data brokers for advertising purposes.

5. Device permissions

The app requests device permissions only when a feature requires them.

We may request access to:

  • Camera — to capture photos or videos for your portfolio
  • Photo library — to upload existing media to your portfolio
  • Microphone — to record voice samples where supported
  • Notifications — to alert you about profile status, payment window reminders, relay messages from the Mukha Chitram Team, or other account activity

We do not request access to your contacts, calendar, reminders, files outside the media you choose, or precise device location for core Service functionality.

6. App Store and Google Play summary

This section summarizes the data categories we disclose in App Privacy and Data safety forms.

Contact information — Phone number and optional email are linked to your account and used for authentication, account management, receipts, and support.

User content — Profile text, photos, videos, audio, and relay messages are linked to you and used to provide core Service functionality and moderation.

Identifiers — User ID, device ID, and push token are linked to you and used for sign-in, account integrity, rate limiting, and notifications.

Purchases — Plan tier, payment status, and transaction identifiers are linked to you and used to unlock listing / portfolio features after approval.

Diagnostics — Crash and error data may be linked to you and are used to improve stability and fix bugs.

Usage data — Optional product analytics may be collected only when enabled. You can opt out in Settings → Privacy.

Tracking — We do not sell personal information. We do not use personal information for cross-app advertising tracking.

Sensitive / private fields — Date of birth, phone number, and email of any user are never returned by our APIs to another consumer account.

7. How we use information

We use personal information to operate, secure, and improve the Service. Depending on the activity, we rely on one or more of the following bases under applicable law (including the DPDP Act where applicable): your consent; performance of our contract with you; compliance with law; and legitimate uses necessary for providing the Service you requested.

We use information to:

  • Create, authenticate, and maintain your account (phone OTP for consumers; separate credentials for staff)
  • Display LIVE artist profiles in discovery and search to artists, producers, and guests
  • Operate the staff-mediated relay: queue, review, release, edit, or block messages and attachments
  • Review artist profiles and revisions for quality, fraud prevention, duplicate detection, and policy enforcement
  • Compute age bands from date of birth for filtering without exposing date of birth to other users
  • Process one-time payments after profile approval, unlock listing entitlements, issue receipts, and handle admin-initiated refunds
  • Send service-related push notifications, SMS OTP messages, payment-window reminders, and support responses
  • Show artists anonymous interest notices or aggregate save/like counts — never another user's identity
  • Monitor, investigate, and respond to reports, abuse, and security incidents
  • Maintain staff audit logs for mutations and for staff reads of private fields (including date of birth and phone)
  • Analyze reliability through crash reporting and optional product analytics
  • Comply with legal obligations and respond to lawful requests from authorities

We do not use private relay message content for advertising profiling.

8. What other users can see (visibility rules)

Visibility on Mukha Chitram is intentionally asymmetric. These rules are product invariants, not optional preferences.

Artist profiles (LIVE only) — After staff approval and a server-verified payment, a profile with listing status LIVE may appear in discovery and public profile views. Other users may see public profile fields and portfolio media you chose to publish (for example display name, headline, bio, roles, city/state, skills, languages, credits, gallery). Date of birth, phone, and email are not shown to other consumer accounts.

Non-LIVE profiles — Profiles that are DRAFT, PENDING_REVIEW, APPROVED_UNPAID, REJECTED, LAPSED, SUSPENDED, or DEACTIVATED are not discoverable by other consumer accounts.

Producers — Producers are never listed, searchable, or shown to artists. An artist sees relay conversations only as messages from "Mukha Chitram Team". Producer name, company, project, or budget is shared with an artist only if staff deliberately include it in a released message.

Likes and saves — These are private bookmarks. Artists may receive anonymous notices ("Someone liked your profile") or aggregate counts. Artists never learn who liked or saved them.

Relay messages — A message written by a producer or artist stays PENDING until staff RELEASE, EDIT, or BLOCK it. The other leg never sees PENDING or BLOCKED messages. Edited messages show only the staff-approved text to the other leg; both versions may be retained for audit.

Guests — May view public LIVE profiles only; never private fields.

Removing content from your profile does not automatically delete copies already downloaded or screenshotted by others outside our systems.

9. How we share information

We do not sell your personal information. We share information only as described below.

With other users — Only according to the visibility rules in Section 8. We do not disclose producer identity to artists through the product. We do not disclose artist phone, email, or date of birth to other consumer accounts.

With our staff — Managers and admins access profiles, private fields, media, and relay content as needed to review submissions, operate the relay, resolve reports, and enforce policy. Staff reads of private fields and staff mutations are audit-logged.

With service providers — We use trusted providers to help run the Service, including:

  • Supabase — database, authentication, and file storage
  • Razorpay — payment processing in India (where offered)
  • Apple App Store and Google Play — in-app purchases where required by store rules
  • Sentry — crash and error reporting
  • Expo, Apple, and Google — push notification delivery
  • SMS / OTP providers configured through our auth stack — to deliver one-time passwords

These providers process information on our instructions and for the purposes described in this policy. They may also process information under their own terms and privacy policies.

For legal and safety reasons — We may disclose information if we believe in good faith that disclosure is necessary to comply with law, respond to valid legal process, protect the rights, safety, and security of users or Mukha Chitram, investigate fraud or abuse, or enforce our Terms.

Business transfers — If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction with notice where required by law.

10. Payment information

Artist listing / portfolio plans are typically charged only after staff approval, as a one-time fee, within a limited payment window shown in the app. Payment success is confirmed by our servers (for example a signature-verified Razorpay webhook or store receipt validation) — not by the client alone.

When you make a purchase:

  • Razorpay (where offered, including on Android / web checkout) processes payments under its own privacy policy. We may receive order amount, payment status, payment IDs, order IDs, and limited billing metadata. We do not store full card numbers, CVV, or complete UPI credentials on our servers.
  • Apple or Google (where In-App Purchase is used) processes App Store and Google Play payments under their own privacy policies. We receive purchase confirmation, product identifiers, and transaction references needed to unlock features.

Refunds, where granted, are admin-initiated and manual, audited, and not automatic. Keep payment credentials secure on your device and with your app store or payment provider.

11. Cookies and similar technologies

On our website, we may use cookies, local storage, and similar technologies to:

  • Keep you signed in where applicable
  • Remember preferences
  • Measure site performance and diagnose errors
  • Protect against abuse

You can control cookies through your browser settings. Disabling cookies may affect some website functionality.

12. How long we keep information

We retain personal information for as long as reasonably necessary to provide the Service, comply with law, resolve disputes, enforce agreements, and maintain security — consistent with purpose limitation under the DPDP Act.

In general:

  • Account and profile data is kept while your account is active
  • Relay messages, edits, blocks, and moderation / audit records may be retained while relevant to safety, disputes, staff operations, or legal obligations
  • Payment and transaction records may be retained as required by tax, accounting, or payment regulations
  • Crash logs and diagnostics are retained for a limited period needed for debugging and trend analysis
  • Guardian consent documents for under-18 submissions are retained as needed for compliance and review

When you delete your account from Settings → Delete account, we begin deleting or anonymizing profile fields, sign-in credentials, and personal identifiers associated with your account, subject to backup cycles and legal retention requirements. Relay history visible to the other party may be anonymized rather than erased where needed to preserve the other user's thread integrity. Staff audit logs required for security and compliance may be retained in minimized form.

13. Your choices and privacy controls

You can control your information through the Service and your device:

  • Access and update — Edit your profile and account details in the app. Certain artist fields (Tier A) require staff re-approval before the live copy changes; structural fields (Tier B) may update immediately
  • Deactivate listing — Artists may deactivate a LIVE profile (hidden from discovery; restorable by the artist where the product allows)
  • Delete account — Permanently delete your account from Settings → Delete account while signed in
  • Notifications — Disable push alerts in Settings → Notifications or through your device OS
  • Analytics — Opt out of optional usage analytics in Settings → Privacy
  • Permissions — Revoke camera, photo, microphone, or notification permissions in your device settings
  • Marketing — We do not send promotional SMS without consent. OTP and transactional messages are service messages

Deleting your account may not remove information already viewed by others prior to deletion, information retained in backups for a limited time, payment records we must keep by law, or staff audit records.

15. Security

We use administrative, technical, and organizational measures designed to protect personal information, including:

  • Encryption in transit using TLS
  • Access controls and authenticated infrastructure
  • Server-side authorization and database permission policies where applicable
  • Separation of staff admin access from the consumer mobile app
  • Staff audit logging for sensitive reads and mutations
  • Contact-detail scanning and human review of relay messages before release
  • Rate limiting on relay initiation and related abuse controls
  • Monitoring for abuse, fraud, and suspicious activity

No method of transmission or electronic storage is completely secure. You are responsible for keeping your phone, OTP messages, and device passcode secure.

16. International data transfers

We are based in Hyderabad, Telangana, India. Our service providers may process personal information in India, the United States, the European Union, or other countries where they or their subprocessors operate.

Where required by applicable law (including the DPDP Act), we take reasonable steps to ensure that cross-border transfers are permitted and appropriately safeguarded.

17. Children and under-18 artists

The Service is intended for adults. The default eligibility to create an account and use producer or adult artist features is 18 years of age (or the age of majority in your jurisdiction if higher).

Where we permit artist profile submissions for individuals under 18, those submissions are routed to a separate review queue and require guardian consent documentation. Under-18 profiles are subject to heightened review. We do not knowingly allow under-18 users to act as producers.

We do not knowingly collect personal information from children in a manner that violates applicable law. If you believe a child has provided personal information to us without required consent, contact support@mukhachitram.com and we will take appropriate steps.

18. No sale and no cross-app tracking

We do not sell or rent your personal information to third parties for their independent marketing purposes.

We do not use your personal information for cross-app advertising tracking. Third-party payment, analytics, and infrastructure providers may process limited data under their own policies when you interact with their services through Mukha Chitram.

19. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, or our data practices. When we do, we will post the updated version at mukhachitram.com/privacy and update the effective date / version.

If changes are material, we may also provide notice through the app, website, or other reasonable means. Your continued use of the Service after the updated policy becomes effective means you accept the revised policy, except where applicable law requires a different form of consent.

20. Grievance Officer and contact

If you have questions, concerns, or complaints about this Privacy Policy, our data practices, or content on the Service, contact us:

Mukha Chitram

Registered office: Kondapur, Hyderabad, Telangana, India

Support email: support@mukhachitram.com

Grievance / privacy email: grievance@mukhachitram.com

Website: https://mukhachitram.com/privacy

Grievance Officer (India). For grievances under the Information Technology Act, 2000 and applicable rules (including Intermediary Guidelines), and for privacy grievances under the DPDP Act where applicable, you may write to:

Name: Rama Krishna

Designation: Grievance Officer, Mukha Chitram

Email: grievance@mukhachitram.com

Address: Kondapur, Hyderabad, Telangana, India

We aim to acknowledge grievances within the timelines required by applicable law and to resolve them diligently. If you are not satisfied with our response, you may have the right to approach the Data Protection Board of India or other competent authority where applicable law provides that right.

Grievance Officer: Rama Krishna · Kondapur, Hyderabad, Telangana, India

See also Terms of Service