Legal
Privacy Policy
Last updated 5 July 2026
This Privacy Policy explains how Kirisan ("we", "us") handles personal information when you visit kirisan.com, use the dashboard at dash.kirisan.com, call our API, or interact with our documentation and support channels (the "Service").
1. Information we collect
Account information
When you sign in with Google, we receive and store:
- Google account ID, email address, and whether your email is verified
- Display name and profile picture URL supplied by Google
- Session metadata such as sign-in time and IP address
Kirisan does not set or store a separate password for your workspace.
Workspace and usage data
To run the Service, we process information you provide or generate in the dashboard, including:
- Connected channel details (WhatsApp devices, WABA numbers, Telegram bots, email domains and senders)
- Message content, templates, schedules, campaigns, and delivery logs
- Contact names, phone numbers, email addresses, notes, and group memberships
- Autoreply rules, flow definitions, spreadsheet links, and submission answers
- Uploaded files, variables, webhook URLs, and API tokens you create
- Billing records, orders, invoices, and support messages you send us
Technical data
We automatically collect technical information such as browser type, device identifiers, request timestamps, and error logs. This helps us secure the Service, debug issues, and measure performance.
2. How we use information
We use personal information to:
- Provide, maintain, and improve the Service
- Authenticate you and manage your session
- Send and deliver messages through channels you connect
- Process billing, enforce quotas, and prevent abuse
- Respond to support requests and communicate about the Service
- Comply with legal obligations and protect our rights
We do not sell your personal information. We do not use your private message content for unrelated advertising.
3. How we share information
We share information only when needed to operate the Service:
- Channel providers — Meta/WhatsApp, Telegram, email delivery networks, and WhatsApp linked-device partners process message content and recipient identifiers on your behalf
- Google — for authentication and, if you connect one, to read Google Sheets you link for autoreply or contact import
- Infrastructure providers — hosting, storage, and monitoring vendors that process data under our instructions
- Your integrations — webhook endpoints and API clients you configure receive events and data you choose to forward
- Legal and safety — when required by law, court order, or to prevent fraud, abuse, or harm
If we are involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to continued protection consistent with this Policy.
4. Retention
We keep account and workspace data while your account is active and for a reasonable period afterward to comply with law, resolve disputes, and enforce agreements. Message logs, billing records, and support history may be retained for different periods depending on operational and legal needs. You may request deletion of your account by contacting support; some records may be kept where retention is required by law or legitimate business needs.
5. Security
We use administrative, technical, and organizational measures designed to protect personal information, including access controls and encryption in transit where supported. No method of transmission or storage is completely secure. You are responsible for safeguarding API tokens, device tokens, and webhook secrets in your environment.
6. Your choices and rights
Depending on where you live, you may have rights to:
- Access or receive a copy of personal information we hold about you
- Correct inaccurate information in your account settings
- Delete your account or certain data, subject to legal exceptions
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
To exercise these rights, open Account → Support in the dashboard. We may need to verify your identity before responding. You can also manage much of your data directly in the dashboard — for example by deleting contacts, devices, or templates.
7. Cookies and similar technologies
The marketing site and dashboard use cookies and local storage for essential functions such as keeping you signed in, remembering preferences, and protecting against abuse. We do not use third-party advertising cookies on the Service. You can control cookies through your browser settings; disabling essential cookies may prevent you from using the dashboard.
8. International transfers
Kirisan is operated from Indonesia. Your information may be processed in Indonesia and in other countries where our providers or channel partners operate. We take steps designed to ensure appropriate protections when data crosses borders.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated in the dashboard. Continued use after changes take effect means you accept the updated Policy.
11. Contact
Privacy questions or requests? Open Account → Support in the dashboard. For terms governing use of the Service, see our Terms of Service.