This policy covers the KDrama SL Android application, the installed iPhone web app (“PWA”), this website, and related support services (together, the “Services”). KDrama SL is the controller for the product processing described here. Contact the controller at contact@kdramasl.site.
1. Information we process
- Account and profile: Firebase user ID, verified phone number or email, sign-in provider, display name, profile image reference, session platform, and session timestamps when you choose Google or phone sign-in.
- Subscription and trial: eligibility, request status, plan, activation and expiry timestamps, and the identifiers needed to prevent repeated trials or apply an entitlement.
- Messaging: push token, device platform, app version, optional user ID, notification interactions, and local read/unread state. Notification read state is normally device-local.
- Use and telemetry: a pseudonymous installation or session identifier, app release/platform/OS, first and last seen times, install/open lifecycle, route/activity events, and catalog or per-title aggregate watch seconds when the relevant product control is enabled. Installed-PWA analytics is enabled as of this policy date; its current backend retains standalone installation-lifecycle records and may validate other submitted event categories without persisting them.
- Reports and support: video/subtitle reports, optional feedback, contact email, selected topic, message content, campaign interactions, and correspondence.
- Security and diagnostics: App Check or device-attestation results, IP and request metadata, authentication/security events, and native Firebase Crashlytics crash, ANR, device, app-version, and diagnostic information. Separate PWA crash reporting and performance monitoring are currently disabled; we will update this notice before enabling and retaining those categories.
- Manual Ad-Free/payment support: selected plan or trial, quoted price and currency, payment reference or proof, payer/contact details, activation status, and WhatsApp correspondence when you choose that manual flow. This website does not collect payment-card details.
2. Information kept on your device
Playback position/history, downloads, guest favourites/watchlist, notification-read state, caches, and some preferences are stored locally with Android storage or, for the PWA, localStorage, IndexedDB, Cache Storage, and service-worker caches. Eligible signed-in active Ad-Free users automatically synchronize eligible favourites/watchlist entries. Signed-in PWA accounts can also synchronize settings such as theme, data saver, and the Continue Watching preference. Local data can still be lost if you uninstall, clear app/browser storage, or the operating system evicts PWA data.
3. Why we use information
- Provide accounts, playback, downloads, progress, notifications, trials, and support.
- Protect the Services, enforce single-session/security controls, and prevent abuse.
- Measure reliability and aggregated use when the applicable feature is enabled.
- Serve and measure advertising or KDSL-managed custom campaigns where enabled.
- Handle copyright, privacy, payment, legal, and safety requests.
Depending on the activity and applicable law, we rely on providing the service you request, legitimate interests in security and improvement, consent where an optional feature actually asks for it, and compliance with legal obligations.
4. Advertising and promotions
Android currently uses Unity Ads. The PWA may use Monetag for sponsored gates or web ads, and this marketing website may automatically load Monetag on its home page when website advertising is enabled. Those providers can process IP address, advertising/browser identifiers, device and browser attributes, approximate location derived from IP, referrer/page information, frequency or fraud signals, and ad interactions. The marketing website does not provide a separate KDSL consent toggle for these tags. An active Ad-Free entitlement currently suppresses eligible Android Unity interstitial/rewarded ads and eligible PWA Monetag sponsor/direct-ad gates. KDSL-managed custom campaigns, promotional notifications, and Firebase in-app messages may remain.
When marketing-website advertising is enabled, the home page can automatically display a Monetag Vignette Banner. Selecting the Android download or iPhone web app can arm Monetag's OnClick format, so a sponsored tab may open after a later eligible page click. The official APK download and iPhone web app remain available if an ad is blocked or fails to load. The public website does not receive your signed-in app or PWA Ad-Free status, so these website ads run independently of that entitlement. Contact, legal, security, and Android release-detail pages do not intentionally load these ad tags. Links to the PWA, WhatsApp, and social networks open separate services governed by their policies.
5. Providers and recipients
- Google Firebase for authentication, Firestore, App Check, messaging, analytics/FIAM, and Crashlytics.
- Unity for Android advertising.
- Monetag for PWA and marketing-website advertising when enabled.
- Independent infrastructure providers including Vercel, Cloudflare (including Turnstile on the contact form), Backblaze B2, and related CDN/storage services for website operation, bot prevention, security, technical media delivery, and operational logs. Using those vendors does not mean KDSL owns the third-party entertainment material they transmit.
- Resend for website contact-email delivery.
- Google reCAPTCHA/phone-auth services and your mobile network operator for phone-number verification and SMS delivery.
- WhatsApp/Meta only after you choose to open and send a prefilled support or Ad-Free request; that message may include your user ID, registered contact, selected plan/trial status, and detected country where shown before sending.
- The bank, payment service, or named recipient shown to you before a manual Ad-Free payment, if you choose to proceed.
- Campaign sponsors and their disclosed asset or destination hosts when you view or open a sponsored campaign.
- Authorities, advisers, or rightsholders when required by law or reasonably necessary to address a valid legal/security claim.
6. Retention
We retain information only while it is reasonably needed for the purpose described, using the following criteria. Provider backup cycles and a lawful hold can delay final erasure.
- Account/profile and synced-setting records while the account is active and until a verified deletion request is completed, subject to backup and legal-hold constraints.
- Push tokens until replaced, invalidated, signed out, or removed during cleanup.
- Contact/support messages until the request and reasonable follow-up are complete; legal, security, fraud, or copyright material while a claim, dispute, or duty remains active.
- Pseudonymous analytics and operational/security logs while needed to measure the enabled service, investigate incidents, or maintain aggregate statistics.
- Trial, entitlement, payment, and transaction evidence while needed for service integrity, disputes, accounting, tax, or another legal obligation.
Device-local data remains until you delete it or the platform removes it.
7. International processing and security
Providers may process information outside Sri Lanka. We select established providers and use access controls, HTTPS, App Check/device attestation, restricted server credentials, and signed media access where deployed. No system is risk-free, so we do not guarantee absolute security. Report concerns through our Security page.
8. Your choices and rights
- Use guest mode for core browsing where available, or sign out to stop account sync.
- Control notifications through the app and operating-system settings.
- Use platform privacy/ad controls and any consent controls offered by an ad provider.
- Request access, correction, deletion, restriction, or objection where applicable.
- Clear local Android/PWA data separately; cloud deletion does not erase files already stored on your device.
See Data Deletion or contact us for a verified request. Where an optional feature asks for consent, you may withdraw that consent at any time, without affecting processing already carried out; another lawful basis may still apply to security, contracts, or legal duties. Account contact details and support reply details are required only when necessary to provide or verify the feature you request.
9. Children
The Services are not directed to children under 16. A person under 16 should not create an account or send personal information without a parent or guardian acting where legally permitted. Contact us if you believe a child provided information so we can review it.
10. Changes and complaints
We may update this policy when the Services or providers change and will publish the date above. Privacy complaints can be sent to our contact address. You may also have the right to complain to Sri Lanka’s Data Protection Authority or another competent regulator.