ActorOS

ActorOS · Privacy Policy

ActorOS Privacy Policy

Effective 5 October 2026 · Issued by Rudraayaan AI Technologies Private Limited (CIN U62011TS2026PTC216546), Krishna Nagar Colony, Ameenpur, Medak, Telangana 502032, India — operator of the ActorOS mobile application and of actoros.in.

This notice is issued under the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”). We process your personal data only as described here and in line with our obligations under that Act. In this policy, “we”, “us” and “ActorOS” mean Rudraayaan AI Technologies Private Limited; “you” means the person using the app.

Read section 3 before you publish a profile. ActorOS is a discovery platform: publishing a profile puts some of your information on a web page that anyone in the world can open. Section 3 lists exactly which fields those are, and which ones never leave the app.

1. Who this applies to

ActorOS is a talent-discovery platform connecting performers (“Talent”) with casting and hiring professionals (“Finders”). ActorOS is for adults aged 18 and over only. You may not create or use an account if you are under 18. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to a person under 18, we remove the account and delete the associated data. See our Child safety standards.

2. The personal data we process

We collect only what the service needs. We do not collect Aadhaar or any other government identity number.

CategoryExamplesOn your public page?
IdentityName, stage name, date of birth, gender, photographs.Age and gender: yes. Name, stage name and photographs: no.
HandleThe @handle you choose; it forms your public web address.Yes
Physical attributesHeight, weight, body type, complexion, eye and hair details (for casting relevance).No
ContactPhone, email, WhatsApp — stored separately from your profile and released only to a Finder whose request you approve.No
LocationThe city and state you enter.Yes
ProfessionalTalent type, skills, languages, credits, showreel and social links you add.Talent type, skills and languages: yes. Showreel, credits and social links: no.
UsageApp activity such as profile views and searches, used to run and improve the service.No
DiagnosticsIf the app crashes, a report containing the fault, your device model and operating system version. Personal data is stripped from the report text before it leaves your device, and the report is not tied to your account.No
Device identifiersA push notification token issued by Google or Apple to this installation, so we can notify you. It identifies the app on a device, not you, and is deleted when you sign out or delete your account.No

The current release does not process payment data — Pro is not sold inside the app. If paid features launch later, payments will be handled by the platform billing provider and this policy updated first.

3. What becomes public when you publish a profile

This is the section people are most often surprised by, so it is written plainly.

When your profile goes live, ActorOS creates a public web page for you at app.actoros.in/p/your-handle. Anyone in the world can open that page. It needs no ActorOS account, no login, and no app. Search engines are permitted to index it, and anyone who opens it can copy, save or republish what they see there.

Visible to everyone on that page:

  • your @handle;
  • your talent type, gender and age;
  • your city and state;
  • the languages you have listed;
  • your performance skills;
  • whether your profile carries a verified mark.

Never shown on that page, and never shown to a logged-out visitor:

  • your real name and your stage name;
  • your profile photograph, intro reel and portfolio images (see section 10 for an important qualification about the files themselves);
  • your bio;
  • your phone number, email address, WhatsApp number and social links.

Those withheld fields are shown inside the app, to signed-in users on a paid plan, and to you and our administrators. Your contact details are separate again: they are released only to a Finder whose specific request you have approved, one request at a time.

Your updates are published too. Whenever you edit a live profile, the public page changes with it — normally within five minutes. There is no separate publishing step, no draft stage and no review in between: on a live profile, an edit is a publication. If you would rather change something privately, unpublish your profile first, edit it, then publish again.

Your consent to this is specific and separate. Publishing your profile is its own consent under section 4 below. It is not bundled with signing in, it is never pre-ticked, and you give it knowing this page is public. You may withdraw it at any time from Settings → Your consents in the app; the page is unpublished immediately and the address then returns “not found”.

One limit you should know about, because no platform can promise otherwise: once information has been public, copies taken by search engines, caches, archives or other people are outside our control. We remove the page; we cannot recall what has already been copied from it.

4. How we use your data, and your consent

We process your data only for the specific purposes you agree to. Each purpose is separate — granting one does not grant another — and you can withdraw any of them at any time from Settings → Your consents in the app. No consent box is pre-ticked.

  • Create and run your account (required) — sign you in, keep your account secure, and provide the core service.
  • Publish your talent profile (required to go live) — creates the public web page described in section 3, readable by anyone on the internet, and makes your profile searchable by Finders inside the app. Withdrawing this unpublishes the page.
  • Share your contact with approved Finders — lets a Finder reach you only after you approve their specific request. Without this consent, no Finder can ever obtain your contact details.
  • Product updates (optional) — occasional news, tips and offers; opt out any time.
  • Usage analytics (optional) — anonymous usage patterns to improve the product.

Our legal basis for processing is your consent and, where applicable, the performance of the service you have requested. If we materially change how we use your data, we will ask for your consent again.

You are entitled to this notice in English and in any language listed in the Eighth Schedule to the Constitution of India. Write to support@actoros.in naming the language you want and we will provide it.

5. Use of artificial intelligence

We use artificial intelligence to improve search and discovery, so that a Finder searching for a skill or an attribute finds people who match it rather than only people whose name matches. To do this we send Google’s AI service a single line of text built from your profile — your name, stage name, handle, talent type, gender, city and state, physical attributes, languages, skills, hobbies and bio — and store the numeric representation it returns. We do not send your phone number, email, photographs or video. A Finder’s search text is sent the same way. Google is listed as a sub-processor in section 7. AI is never used to make an automated decision with legal effect about you without human review.

6. Content you upload

Any content you upload — including photographs, audio, video and PDF documents — remains yours, and you are solely responsible for it. By uploading, you confirm you own the content or hold the rights needed to share it. Copyright and other legal responsibility for uploaded content rests with the uploading user, not with the platform.

To report content as infringing or unlawful, email support@actoros.in with “Report” in the subject line, naming the @handle and what you saw. We review every such report and remove content that breaches our Terms of Service or the law. The uploading user remains legally responsible for what they uploaded.

7. Who we share data with (sub-processors)

We do not sell your personal data. Apart from what section 3 makes public by your own choice, we share personal data only with service providers who process it on our behalf under contract:

  • Supabase — hosting, database and file storage (data hosted in the India / Mumbai region).
  • Our SMS provider — to deliver the one-time passcode you sign in with.
  • Google — for optional “Sign in with Google”; for delivering push notifications to Android devices (Firebase Cloud Messaging, which receives a device token, not your identity); and for crash diagnostics (Firebase Crashlytics, see section 2). Where we use AI to rank search results, the text described in section 5 is sent to Google’s AI service for that purpose.
  • Apple — for delivering push notifications to iPhones and iPads, which receives a device token.
  • Resend — to send transactional email, such as a PRO code you asked for. It receives the email address the message is sent to.

Google, Apple and Resend process data outside India. Supabase hosts in the India / Mumbai region; the transfers named above are the exceptions to that, and each is limited to what the bullet describes.

We may also disclose data where the law requires it, or to protect the rights and safety of users.

8. How long we keep it

DataRetention
Active profile and mediaWhile your account is active.
After you withdraw consentPublic page unpublished immediately; data purged within 30 days unless a legal hold applies.
After you ask to delete your accountYour profile is unpublished immediately. The permanent purge runs 30 days later, and you can cancel during those 30 days. See Delete your account.
After the purge has runOnly a minimal, non-identifying deletion record, and anything the law requires us to keep.
Information under a preservation holdNot purged while the hold is in place. Retained for the period required or permitted by applicable law, or for as long as reasonably necessary for the matter concerned, then deleted. See section 12.
Crash diagnosticsUp to 90 days, then deleted by our provider.
Usage analyticsUp to 18 months, then aggregated.
Security log of our admin console365 days, then deleted automatically. It records which staff account made which change or export, on which account or record, and when, with the IP address and browser the action came from. Attempts to sign in to the console are logged the same way, with the IP address and browser but not the address that was typed.

9. Your rights, and how to delete your account

Under the DPDP Act you can:

  • access the personal data we hold about you;
  • correct or update inaccurate data (you can edit your profile at any time — remembering that on a live profile an edit is a publication);
  • withdraw any consent you have given;
  • request erasure of your data;
  • nominate another person to exercise your rights in the event of your death or incapacity;
  • raise a grievance with us (see section 14).

Deleting your account: open the app and go to Settings → Danger Zone → Delete account. This permanently removes your profile, uploaded media and contact details. You can also email support@actoros.in to request deletion. Delete your account sets out both routes in full, including what is kept afterwards and for how long.

10. How we protect your data

Access to data is controlled by default-deny row-level security. Contact details are held apart from the profile and released only on your approval. Profile fields are withheld server-side from anyone who has not been granted access — the public page in section 3 is built by a database function that never returns the withheld fields at all, rather than by hiding them in the browser. Data is encrypted in transit and at rest. Every change our staff make through the admin console, and every export of a person's data, is recorded in a security log that the console itself cannot edit or delete, so those actions can be checked afterwards (see section 8 for how long it is kept).

One qualification, stated plainly because it is true: profile photographs and intro reels are stored in buckets configured for public read. Neither the image nor its address appears on your public page — that page withholds them — but a person who already has the file’s address can open it without signing in. Portfolio images and consent records are in private storage and are reachable only through a short-lived signed link. If you would rather no photograph of you exist in public storage at all, remove it from your profile and it is deleted from the bucket.

11. Children

ActorOS is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal data from anyone under 18, and a declared date of birth indicating an age under 18 is refused by our systems rather than stored and hidden.

If you believe a person under 18 is using ActorOS, or that we hold data about a person under 18, tell us through the child safety report form or at support@actoros.in. We will restrict the account and remove the data, except to the extent we are required or permitted by law to preserve it — see section 12, which explains why that exception exists and what it covers. Our full standards are in the Child Safety and Child Sexual Exploitation Prevention Policy.

12. Child safety, legal compliance and preservation of information

Why this section exists. Everywhere else this policy tells you that we keep your data only as long as we need it and that you can have it erased. There is a narrow set of circumstances in which that is not the whole truth, and stating them plainly is better than leaving a reader to discover the exception later.

12.1 When information is preserved. Where a child-safety report, an investigation, a request from a court, police authority or other competent authority, or an actual or anticipated legal proceeding concerns an account, we may place that account and the related records under a preservation hold.

12.2 What a hold does. Records under a hold are excluded from our automated purges, including the purge that follows an account-deletion request. Your deletion request is still accepted and your profile still comes down immediately; only the irreversible purge is deferred. When the hold is released, the purge runs.

12.3 What may be preserved. The account record and registration details; the reported content and where it is stored; message records relating to the matter; access and activity logs; device and network information collected in the ordinary course; and the report itself together with our handling record.

12.4 How long. For the period required or permitted by applicable law, or for as long as reasonably necessary in connection with the matter or with the establishment, exercise or defence of a legal claim — whichever is longer. The records are then deleted.

12.5 Who can see it. Access is restricted to the smallest number of personnel necessary to handle the matter, and access is logged. Preserved information is not used for the product, for analytics or for marketing.

12.6 Disclosure. We disclose information to a court, police authority or other competent authority where we are legally required to do so, and we may do so where we are legally permitted to and consider it reasonably necessary to prevent or address harm to a child. Where we disclose, we do not notify the account holder if notification is prohibited, if we are directed not to, or if we reasonably believe notification would risk harm to a child, the destruction of evidence or the obstruction of an investigation.

How this fits with your rights. Your right to withdraw consent and to ask for erasure is unaffected in every ordinary case, and is the default. This section is the exception, it is limited to what is set out above, and it applies for only as long as the obligation does. It is stated identically on Delete your account (section 5) and in Child Safety Policy, section 11; if you ever find those three disagreeing, the discrepancy is a defect and we would like to be told about it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date above and, where required, ask for your consent again within the app.

14. Contact & grievance officer

For any privacy question, request, or grievance, contact our Grievance Officer:

Sandeep Naredla
Grievance Officer, Rudraayaan AI Technologies Private Limited
Krishna Nagar Colony, Ameenpur, Medak, Telangana 502032, India
support@actoros.in

The Grievance Officer is also the point of contact for requests from courts, police authorities and other competent authorities — see Child Safety Policy, section 17 — and for complaints about how we handled a report.

Our commitment on timing. We acknowledge a grievance within 24 hours of receiving it and aim to dispose of it within 15 days. Child-safety reports are placed ahead of every other queue and are handled under the Child Safety Policy; the fastest route for one is the child safety report form, which needs no account and returns a reference you can quote.

These are the timelines we hold ourselves to. Where a law or a rule made under it imposes a shorter or different period on us, that period applies instead of this one.