Kacto Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how Kacto LTD ("Kacto", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Kacto mobile apps, the Kacto website and web app at kac.to and app.kac.to, creator pages hosted on our subdomains (for example username.kac.to) and on connected custom domains, and any related services (together, the "Service").
Kacto is an AI-powered platform that helps artists, producers, DJs, and creators publish music links ("drops"), build a fan audience, message fans, sell paid content, view insights, and use an AI assistant.
Please read this together with our Terms of Service.
Who this policy is for
Kacto is used by two kinds of people, and our role differs for each:
- Creators — people who sign up for a Kacto account to build pages, publish drops, and grow an audience. For Creator personal data, Kacto is the data controller.
- Fans / visitors — people who visit a Creator's page, get notified, pre-save music, or buy a drop. For the fan lists and audience data a Creator collects through Kacto, the Creator is the controller and Kacto acts as a processor / service provider on the Creator's behalf. Kacto is a controller only for the limited purposes of operating, securing, and improving the Service and complying with law.
If you are a fan and want your data removed from a specific Creator's audience, contact that Creator, or contact us at hello@kac.to and we will assist and route the request.
2. Information we collect
2.1 Information you provide
Account & profile (Creators)
- Username, email address, and display name.
- Optional profile details: bio, profile photo, and a linked Spotify artist profile.
- Authentication: we use Firebase Authentication. You sign in with Google (OAuth) or with a one-time email code (OTP). We do not store your Google password.
Content you create
- Drops and their metadata: titles, music/streaming links, cover art, release dates, visibility (public / private / paid).
- Audio you upload to your Audio Vault.
- Custom domains or subdomains you connect.
- Messages, email templates, and broadcast campaigns you compose for your fans.
- Prompts and messages you send to the AI assistant, and images the AI generates for you.
Payment information
- Subscriptions are purchased through Apple or Google in-app purchase and managed via RevenueCat; we receive subscription status, not your full card number.
- Payouts and paid-drop sales are processed through Stripe Connect. Stripe collects the identity, bank, and tax information required to pay you out (KYC). We receive account status and transaction metadata, not your full banking credentials.
Support
- If you contact support through the in-app chat (Crisp) or by email, we receive your messages and contact details.
2.2 Information collected from fans/visitors (on a Creator's behalf)
When a fan interacts with a Creator's page, we may collect:
- Display name and email address (for "Get Notified" sign-ups).
- Pre-save authorizations and related tokens when a fan connects Spotify or Apple Music to pre-save a release. These tokens are stored server-side in restricted storage and are used to add the release to the fan's library.
- Engagement signals (e.g., whether the fan opted in to notifications, pre-saved, or connected a streaming service).
- Purchase records for paid drops.
Raw fan email addresses and streaming tokens are kept in a server-only, access-restricted store (fanSecrets) that is not exposed to client apps; the Creator sees a masked/limited view.
2.3 Information collected automatically
- Usage & analytics (via PostHog): screen/page views, feature interactions, and events tagged with a surface (app or fan link) and platform (iOS/Android/web). We collect approximate location: country/region derived either from your device's regional setting (country_code) or from IP-based GeoIP at the server. We do not collect precise GPS location.
- Device & technical data: app version, device/OS type, host/domain, language, and similar diagnostic data.
- Page-view counters ("Insights"): aggregate view and click counts per drop and profile, shown to the relevant Creator.
- Cookies / similar technologies: on the web, we and our providers use cookies and local storage for authentication, preferences, and analytics. See Section 9.
2.4 Device permissions
The apps may request access to your photo library (to set cover/profile art), media library (to save share images), microphone (to add audio to your Audio Vault), and notifications. You can grant or revoke these in your device settings.
How we use information
We use personal information to:
- Provide, operate, and maintain the Service (create accounts, publish drops, route custom domains, deliver messages, process pre-saves and purchases).
- Power the AI assistant: your prompts, plus context about your account (display name, username, bio, your drops and their stats, and linked Spotify catalog) are sent to our AI provider (Google Gemini) to generate replies and cover-art images. The assistant may use Google Search grounding to answer questions.
- Process payments, subscriptions, and payouts, and calculate our platform fee on paid drops.
- Send transactional email (sign-in codes, welcome emails) and, at a Creator's direction, deliver the Creator's broadcast emails to their fans.
- Measure and improve the product (analytics, insights, troubleshooting).
- Provide customer support.
- Protect the Service: detect, prevent, and respond to fraud, abuse, spam, and security incidents.
- Comply with legal obligations and enforce our Terms.
Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (securing and improving the Service, analytics, preventing abuse), consent (certain cookies/analytics, and marketing where required), and legal obligation (tax, accounting, responding to lawful requests). For fan audience data, the Creator determines the legal basis; Kacto processes it under our agreement with the Creator.
How we share information
We do not sell personal information for money. We share information only as described here:
4.1 Service providers / sub-processors
We share data with vendors that process it on our behalf under contract:
- Provider ; Purpose ; Data involved
- Google Firebase / Google Cloud ; Auth, database, file storage, serverless functions, hosting ; Account, content, fan data, logs
- Google (Gemini API) ; AI assistant chat & image generation ; Prompts + account context you provide to the assistant
- PostHog ; Product analytics ; Usage events, approximate (country-level) location, device data
- RevenueCat ; Subscription management ; Firebase user ID, subscription status
- Stripe ; Payments, payouts, paid-drop checkout, KYC ; Identity, bank/tax (for Creators), transaction data
- Zoho ZeptoMail ; Transactional & broadcast email ; Sender/recipient email, message content
- Crisp ; In-app support chat ; Support messages, contact details
- Spotify ; Fan pre-save & creator artist linking ; OAuth authorization, streaming identifiers
- Apple Music (MusicKit) ; Fan pre-save ; Music authorization tokens
- Cloudflare ; Custom-domain routing, TLS, CDN ; Network/request data
- Odesli / Kacto music lookup ; Resolve music links across platforms ; Public music URLs
- Apple App Store / Google Play ; App distribution & in-app purchases ; Purchase data controlled by the store
A current list of sub-processors is available on request at hello@kac.to.
4.2 Between Creators and fans
When a fan interacts with a Creator's page, the Creator receives the fan data described in Section 2.2 for the purpose of managing their own audience. Creators must handle that data lawfully and in line with their own privacy notice.
4.3 Legal, safety, and business transfers
We may disclose information to comply with law or valid legal process, to protect the rights, safety, and property of Kacto, our users, or the public, and in connection with a merger, acquisition, financing, or sale of assets (subject to this policy).
AI features
The AI assistant is optional and used at your initiative. When you use it:
- Your message and account context are transmitted to Google's Gemini API to generate a response or image.
- Generated images are stored in our Cloud Storage and shown to you; you may add them to your drops.
- Do not enter sensitive personal data you do not want processed by a third-party AI provider.
- We instruct the model not to reproduce third-party copyrighted logos or copy existing commercial album covers that are not yours; however, you are responsible for how you use AI outputs (see the Terms).
International transfers
We are based in the United Kingdom and our providers may process data in the United States, the European Union, and other countries. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) / Addendum and the EU Standard Contractual Clauses, or an equivalent mechanism. Contact us for details.
Data retention
- Creator accounts and content: retained while your account is active.
- Fan audience data: retained while the Creator's account is active and the fan remains on the roster, or until deletion is requested.
- Analytics: retained per our provider's default retention.
- Payment/tax records: retained as required by law (typically several years).
When you delete your account (see Section 8), we run an automated erasure that removes your drops, links, creator hub, insights, fan personas owned by your account, connected hosts, uploaded files, and your authentication record. Some data may persist temporarily in backups and logs, and certain records (e.g., transaction/tax records) may be retained where legally required. Data held by independent providers (e.g., Stripe, Apple/Google for purchases) is subject to their retention policies.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent.
- Delete your account: available in-app under Account Settings, which triggers full data erasure as described above.
- Access/other requests: email hello@kac.to. We will verify your identity before acting.
- Fans: to be removed from a specific Creator's audience, contact the Creator or us; we will help route the request to the controlling Creator.
- Marketing/broadcast emails: every Creator broadcast includes an unsubscribe mechanism; transactional emails (e.g., sign-in codes) are not marketing and cannot be opted out of while you use the Service.
California (CCPA/CPRA): You have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information, and not to be discriminated against for exercising these rights. We do not sell personal information. We may "share" limited identifiers with analytics providers for cross-context behavioral analytics; you can opt out by contacting hello@kac.to or using available in-app/browser controls.
EEA/UK: You may lodge a complaint with your local supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) (ico.org.uk). For all privacy and data-protection enquiries (including from the EEA), contact hello@kac.to.
We respond to rights requests within the timeframes required by applicable law.
Cookies and tracking
On the web, we use strictly necessary cookies/local storage for authentication and preferences, and analytics cookies/identifiers (PostHog) to understand usage. You can control cookies through your browser settings; blocking some cookies may break parts of the Service. Where required by law, we request consent before setting non-essential cookies.
We do not currently respond to browser "Do Not Track" signals in a standardized way, but we honor Global Privacy Control (GPC) where legally required.
Security
The Service is not directed to children under 13 (or 16 in the EEA where local law requires a higher age), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact hello@kac.to and we will delete it. Creators are responsible for ensuring their own audience collection complies with laws protecting minors.
Children's privacy
The Service is not directed to children under 13 (or 16 in the EEA where local law requires a higher age), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact hello@kac.to and we will delete it. Creators are responsible for ensuring their own audience collection complies with laws protecting minors.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you through the Service or by email and update the "Last updated" date. Continued use after changes take effect means you accept the revised policy.
Contact us
Kacto LTD (company number 17315151)
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: hello@kac.to