On this page
Privacy Policy
| 1. Scope and applicability | |
|---|---|
| Legal entity | Trishara Ventures LLP (Trishara Ventures LLP) operates Koovira as a multi-module digital platform, and also operates The Gym by Koovira (thegym.koovira.com), Tosset (tosset.com, talent and casting) and Tosset TV (tv.tosset.com, OTT streaming) under the same legal entity. This privacy policy covers the Koovira-family account (Koovira, Tvatto, Koovira partner apps, MY-KSociety, The Gym by Koovira) and, where a reader lands here from Tosset or Tosset TV app listings, documents how Trishara Ventures LLP handles personal data across its services. Tosset and Tosset TV each run their own account system; the data-protection principles and operating entity stated below apply uniformly. |
| Effective date | 05/06/2026. Last reviewed: 05/06/2026. |
| Users covered | Visitors, registered users, merchants, service providers, partners, admins and any person using Koovira services. |
| Policy acceptance | Use of the platform, clicking accept, submitting content, creating listings, onboarding as merchant/partner, or completing payment confirms acceptance of applicable policies. |
| 2. User obligations and prohibited conduct | |
|---|---|
| Accuracy | Users must provide accurate identity, contact, listing, payment, KYC and transaction information. |
| Prohibited content | Users must not upload or share unlawful, harmful, obscene, sexually explicit, paedophilic, invasive of privacy, hateful, defamatory, fraudulent, misleading, infringing, spam, malware or otherwise illegal content. |
| No misuse | Users must not impersonate others, manipulate reviews, scrape data, bypass security, harvest personal data, abuse messaging, evade moderation or use Koovira for fraud. |
| Lawful use | Users are responsible for complying with applicable Indian laws, sector rules, tax, consumer, labour, real estate, transport, payment, advertising and safety obligations. |
| Personal data | Koovira may process identity, contact, profile, location, device, KYC, wallet/payment, content, communication, listing, transaction, support and security data. |
| Sensitive data | KYC documents, financial identifiers, bank details, precise location, dating/matrimonial data and identity proofs require stricter access and purpose controls. |
| Consent | Where consent is the lawful basis, consent must be clear, specific, informed, recorded and withdrawable for optional processing. |
| 2b. Location data (Google Play disclosure) | |
|---|---|
| What we collect | With your permission, Koovira collects approximate (coarse) and, where you grant it, precise (fine) location only while the app is in use. We do not collect background location. |
| Why | To show you nearby businesses, listings, delivery and courier matches, services, trainers, nearby people/professionals you have opted into, map pins, local search results, and to pre-fill shipping/pickup addresses. For partner apps (Driver / Courier / Local / Truck) location is used to match jobs to on-duty operators and to show route progress to the customer during an active job. |
| Who it is shared with | Within Koovira, with the business, driver, delivery partner, service provider or counterparty the current action requires. We do not use location for advertising. We do not sell location data. We do not share location with third parties for marketing. |
| Retention | Raw per-session location points are kept only for the duration of the session that produced them and the completion of the related task. Aggregated, non-identifying location analytics may be retained for product improvement. |
| Control | You can revoke the location permission at any time from your device: Settings → Apps → Koovira → Permissions → Location. Features that need location fall back to your saved city or to the manual search bar. |
| Account deletion | Location data linked to your account is deleted when you delete your account via Account & Data Deletion, except for records retained under limited exceptions (tax, payment, KYC, fraud, dispute and legal-hold). |
| 3. Platform controls and compliance handling | |
|---|---|
| Moderation | Koovira may review, restrict, label, suspend, remove or preserve content/accounts when policy, safety, fraud, legal or technical risks are detected. |
| Security | Koovira uses access controls, audit logs, CSRF/session controls, rate limits, device/session monitoring and other reasonable security practices. |
| Records | Koovira may preserve logs, removed content, acceptance history, reports, transaction records and security events where required for investigations, disputes, fraud prevention or legal compliance. |
| Policy updates | Koovira may update policies with a new version and may require fresh acceptance for material changes. |
| Data minimisation | Koovira should collect only data required for the stated purpose and avoid storing unnecessary payloads, secrets or CSRF tokens in business metadata. |
| Retention | Data is retained only as required for service delivery, legal compliance, security, disputes, tax, fraud prevention or lawful hold. |
| 4. Data, records, complaints and legal requests | |
|---|---|
| Grievance officer | Complaints may be raised through the public Grievance Officer page or in-app report flows. Officer details are managed by Koovira admin settings. |
| Timelines | Koovira aims to acknowledge grievances within the configured SLA and resolve them within the applicable legal/platform timeline, subject to complexity and lawful process. |
| Legal requests | Koovira may act on valid court, government, law-enforcement, CERT-In or authorised agency requests in accordance with applicable law. |
| Privacy requests | Users may request access, correction, deletion, grievance redressal or withdrawal of optional consent, subject to identity verification and lawful retention requirements. |
| User rights | Users may request correction, deletion, access/export, grievance redressal or consent withdrawal, subject to lawful verification and retention. |
Google User Data & Limited Use
When you connect your Google account to Koovira (an optional feature), we access only the data you explicitly authorise on Google's official consent screen:
- Basic profile & email (
openid,email,profile) — to sign you in and identify your Koovira account. - Google Contacts, read-only (
contacts.readonly) — to help you find and invite people you already know who are on Koovira. We never message your contacts automatically; sending an invite is always an explicit action you take. - Google Calendar events (
calendar.events) — to add schedules, bookings, interviews and appointments you create in Koovira to your Google Calendar, and to update or cancel them when you change them in Koovira.
Koovira's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising or to train generalised AI/ML models, and do not transfer it to third parties except as necessary to provide a feature you requested, to comply with applicable law, or with your explicit consent. Human access to Google user data is prohibited except with your consent, for security/abuse handling, or where required by law.
Disconnecting & Deleting Your Data
You are in full control of connected accounts and imported data:
- Disconnect any time from Settings → Connected Apps & Permissions. Disconnecting immediately deletes the stored access and refresh tokens and stops all syncing.
- Revoke from Google at any time via your Google Account permissions page.
- Delete imported contacts from within Koovira.
- Delete your Koovira account and all associated data from Settings → Security → Delete My Profile, or by writing to us at support@koovira.com.
Updated 2026-06-27 to reflect new platform features.
Connected accounts & external integrations
If you choose to connect an external account (for example Google or Instagram) for sign-in, contact import, calendar sync or content import, we request only the permissions needed for the feature you enabled, and we store the access tokens in encrypted form. You can disconnect any integration at any time; disconnecting stops further data exchange.
Content you import
When you import your own content from a connected social account, we process only the content from accounts you personally authorise, solely to re-create it in your chosen Koovira format. We do not access other people's accounts.
Automated processing & AI
We use automated systems, including a local-first AI assistant, for safety moderation, search, recommendations and support. Your personal data is not sold and is not sent to third-party model vendors for training. See our AI Transparency Policy for details.
Your three profiles (Social, Professional and Dating)
Your Koovira account can hold three separate profiles — Social, Professional and Dating — each stored as its own record with its own display name, audience and privacy controls. Activity on one profile is not publicly linked to another. Your Dating profile is kept isolated: it is never shown in public discovery, never featured or promoted, never exposed through our developer APIs, and never indexed by search engines. It is protected by an additional PIN.
Confessions
Confessions lets you post and comment anonymously to the community. By default your name is not shown to any other member on your confession or its comments. For safety and to meet legal obligations, we record which account posted each confession and comment, but we never reveal that identity to other members in any part of the product. We ask you not to name real people, phone numbers or handles; such content is automatically screened and may be blocked, and our moderators can remove content that breaks our rules. Confessions is for members aged 18 and over and is separate from the Dating product. If you report a confession, we use your report and the stored author information only to review and act on the content.
Promoting your profile or listings
If you choose to boost your profile or a listing, we use the public information on that profile or listing to show it to more members as promoted content, and we measure impressions and clicks so we can report the promotion's performance to you. Promotions are paid from your Koovira Credits, and the amount is always shown before you confirm. You can promote your Social or Professional profile; Dating profiles are never promoted. We do not use promotion to reveal any information that is not already visible on the promoted profile or listing.
Developer APIs and third-party access
Developers who build on Koovira can access our APIs under scoped, revocable credentials. Our developer APIs expose only public, non-personal information — for example public business reputation and public community listings. Members' personal profiles, personal social activity and personal reputation are not available through the developer APIs. Each API scope is limited to a specific purpose, and access is logged.
Grievance & DPDP
In line with India's Digital Personal Data Protection Act, 2023, you may exercise access, correction, and erasure rights, and contact our Grievance Officer using the details at the end of this policy.
Active Third-Party Processors
This summary reflects the active third-party processor register maintained in PAdmin.
| Vendor | Purpose | Data Shared | Country | Privacy |
|---|---|---|---|---|
| Google LLC (Firebase Cloud Messaging) | Delivery of push notifications to the Koovira mobile apps | Device push token and notification payload. No profile, contact or payment data. | United States | View |
| Google LLC (Google Analytics / Tag Manager) | Website usage analytics — loaded only after you grant the Analytics cookie category | Pseudonymous usage events, approximate location, device and browser data. Blocked entirely until analytics consent is given. | United States | View |
| Meta Platforms, Inc. | Marketing measurement (Meta Pixel) — loaded only after you grant the Marketing cookie category | Pseudonymous campaign and page-view events. Blocked entirely until marketing consent is given. | United States | View |
| OpenStreetMap Foundation (Nominatim) | Address lookup and geocoding for listings, delivery and location search | The address or coordinates being looked up. No account identifiers. | United Kingdom | View |
| Razorpay Software Private Limited | Payment processing for orders, wallet top-ups and subscriptions | Name, email, mobile, order/transaction amount and reference. Card details are entered on Razorpay and never stored by Koovira. | India | View |
Retention Windows We Enforce
These are the retention rules our systems actually apply. Records we are legally required to keep longer (tax, accounting, fraud and safety) are retained for that statutory period.
| Area | Record type | Kept for | Then |
|---|---|---|---|
| Auth | Login Logs | 180 days | Deleted |
| Auth | Old Sessions | 180 days | Deleted |
| Auth | Otp Logs | 180 days | Deleted |
| Chat | Chat Attachments | 180 days | Deleted |
| Chat Snaps | Snap View Logs | 30 days | Deleted |
| Chat Snaps | Today Snap Media | 1 day | Deleted |
| Chat Stickers | Sticker Usage History | 180 days | Deleted |
| Growth | Signup Interest | 730 days | Anonymised (kept without identifying you) |
| My Eyes Only | Private Vault Media | Until you remove it | Kept until you delete it yourself |
| Payments | Failed Payment Logs | 180 days | Archived (kept only where law requires) |
| Privacy | Export Files | 30 days | Deleted |
| Profiles | Deleted Profiles | 365 days | Anonymised (kept without identifying you) |
| Security | Ip Intel Cache | 30 days | Deleted |
| Security | Ip Intel Events | 180 days | Deleted |
| Support | Support Attachments | 365 days | Deleted |
You can request a copy of your data, a correction, or deletion at any time from your Privacy Center.
