Privacy Policy
Effective [Effective date] · Version 2026-10-01
This policy explains what Katha collects, why, who processes it, how long it's kept and the rights you have. In short: your uploads are private to you, originals are deleted after processing, everything else is deleted automatically after 30 days without activity, and we never sell your data or use it for advertising.
1. Who is responsible
[Your legal entity name] ([Registered address]) is the data controller. Contact: [privacy@your-domain.com]. Grievance Officer: [Name], [grievance@your-domain.com].
2. What we collect
- Account data: your email address, account creation and sign-in times, and which version of these terms you accepted.
- Content you upload: comic page images (CBZ, CBR, PDF or image files).
- Data generated from your content: panel images, transcripts of the dialogue, character names and descriptions (including an inferred gender and the reason for it), the voices chosen, generated audio, and processing logs.
- Technical data: IP address, browser and device information in our hosting providers' server logs, and an authentication cookie that keeps you signed in.
- Abuse protection: short-lived counters used for rate limiting (for example, sign-in attempts). They are keyed by a one-way salted hash of your email, IP address or device id, never the raw value, and are deleted within two days.
- Activity and security logs: a record of actions in your account (for example sign-ins, uploads, review edits, deletions, data exports and public links), with the time, a salted hash of the IP address, approximate location (country, region, city, from our hosting provider) and browser/OS. We use them to keep the service secure, investigate abuse and support you. Only the operator can see them.
- Public link viewers: when someone opens a public share link, we record the time, an anonymous device id (hashed), a hashed network address, approximate location, browser/OS and the referring site, to count views and unique viewers and to prevent abuse. Viewers are never identified by name or account.
We don't collect payment details, and we don't use analytics, advertising or tracking cookies.
3. Why we use it (and the legal basis)
- To provide Katha: storing your uploads, transcribing them, generating voices and letting you read them (performance of our contract with you, GDPR Art. 6(1)(b)).
- To sign you in: sending one-time sign-in emails. We don't send marketing (contract, Art. 6(1)(b)).
- To keep the service secure, prevent abuse and handle copyright complaints (legitimate interests, Art. 6(1)(f), and legal obligations, Art. 6(1)(c)).
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. We don't use your content to train our own AI models.
4. AI processing
To create transcripts and voices, page and panel images and dialogue text are sent to the AI providers below. They process it to return results to us.
- Google (Gemini API): reads panels and generates expressive voices. When we use Google's free (unpaid) tier, Google's terms allow it to use submitted content to improve its products, and trained reviewers may read it. On a paid tier, Google's terms say it doesn't use submitted content that way. Don't upload content you wouldn't want processed on these terms.
- Groq: text reasoning (merging the cast, choosing voices) and fallback panel reading, processed under Groq's terms.
- Kokoro-82M (fallback voice engine) runs on our own servers; nothing is sent to a third party for it.
5. Who processes your data
We share data only with the providers that run Katha for us, and only what each needs:
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Accounts, database and file storage (hosting of your uploads, transcripts and audio) | Email, uploads, derived data |
| Vercel | Application hosting | Request metadata (IP address, user agent) in server logs |
| Google (Gemini API) | Reading panels (transcription, character detection) and expressive voice generation | Panel images and dialogue text |
| Groq | Text reasoning (merging the cast, choosing voices) and fallback panel reading | Dialogue text, character descriptions; panel images only as a fallback |
| Google (Gmail SMTP) | Sending sign-in emails | Email address and a one-time sign-in code |
We don't sell or rent personal data, or share it for advertising. We may disclose data if required by law or a valid legal order, or as part of a merger or acquisition (with notice to you).
6. International transfers
Our providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. How long we keep data
| Original page uploads | Deleted as soon as the chapter finishes processing |
| Panels, transcripts, character data, audio, processing logs | Deleted automatically 30 days after the chapter's last activity (reading, editing or processing resets the timer), or immediately when you delete them |
| Series and cast | Deleted with the series, or automatically once the series has had no chapters for 30 days |
| Account profile | Until you delete your account |
| Activity and security logs, public link view records | 180 days, then deleted automatically. When you delete your account, your log entries are anonymised (unlinked from you) |
| Hosting and email provider logs | Kept by those providers for their standard periods (typically up to 30 days) |
| Provider backups | Deleted data may remain in encrypted backups for a short period before being overwritten |
8. Your rights
Depending on where you live (including under the GDPR, UK GDPR, India's DPDP Act and US state laws), you can:
- Access and take your data with you: use Download my data on the Account page.
- Correct it: edit transcripts, names and voices in the app, or contact us.
- Delete it: delete chapters, series or your whole account from the app at any time.
- Object to or restrict processing, and withdraw consent where processing relies on it.
- Complain to your data protection authority, or to our Grievance Officer.
Contact [privacy@your-domain.com] to exercise any right we don't cover in the app. We respond within 30 days. We don't sell or "share" personal information as defined by the CCPA/CPRA.
9. Cookies and local storage
We use only strictly necessary cookies: an authentication cookie that keeps you signed in and, on public share links only, a random device id used solely to rate-limit viewing (it identifies no one and is never linked to an account). The installable app (PWA) stores the app's own files on your device so it loads quickly; your private pages, chapters and audio are never cached this way. There are no analytics or advertising cookies, so no consent banner is needed.
10. Security
Data is encrypted in transit (HTTPS) and at rest by our storage provider. Files are kept in private storage, and database access rules ensure each account can only reach its own data, including administrators, who cannot open other users' uploads. The operator's console shows account metadata only (email, series and chapter titles, processing status, counts, storage used, public-link statistics and logs), never your pages, transcripts or audio; and every operator look at an account is itself logged. A chapter is only ever visible to others if its uploader (an administrator) creates a revocable share link for it. No system is perfectly secure; if a breach affects your data, we'll notify you and the authorities as the law requires.
11. Children
Katha isn't intended for children under 13 (or under 16 in the EEA/UK without parental consent). If you believe a child has given us personal data, contact us and we'll delete it.
12. Changes
We'll update this policy when our practices change. For material changes we'll update the version number and ask you to review and accept it the next time you use Katha.