Looply privacy policy

What the Android app and these website pages process, why, and how you can request deletion.

Effective: October 3, 2026 · support@kukkabu.com

1. Operator and contact

Looply is operated under the independent developer name Kukkabu Studios. For service, privacy or account requests, contact support@kukkabu.com.

2. Sign-in and account data

Google is the only sign-in method. Supabase Auth verifies Google identity tokens and manages sessions. Looply stores your Google account identifier, verified email, display name, profile-image URL, user ID and terms acceptance version. We do not receive your Google password. Android session and refresh tokens use secure local storage.

3. Device registration and integrity

Registration sends the app-scoped Android device identifier over HTTPS for server-side keyed hashing. The database stores its hash, device model, Android version and verification time, not the raw identifier. Google Play Integrity processes package, certificate, licensing, device, timestamp and request-binding signals. Tokens are not intentionally logged or retained after verification. Integrity is a risk signal, not an immutable phone identity or guarantee against fraud.

4. Testing and Android Usage Access

Looply stores listings, enrollments, daily check-ins, foreground seconds and credit transactions. Android Usage Access can expose broader usage events on your phone. Looply processes these locally to measure the assigned test package within its testing window, accounting for screen lock/device state. Only the enrollment, device reference, time window and foreground-second total are uploaded, not your complete usage-event stream or full app-use history. Usage Access is requested after an in-app explanation and can be revoked in Android settings. Without it, measured check-ins cannot succeed.

5. Information not requested

The current app does not request contacts, messages, call logs, phone numbers, location, microphone or camera access. It does not record screens, keystrokes or tested-app contents. There are no advertising or analytics SDKs in the current Android implementation. Processing a Google profile-image URL is not access to your photo library.

6. Why we process data

Data supports sign-in, testing coordination, device registration, measured check-ins, internal credits and refunds, security, abuse prevention, support and deletion. We process account and participation data to provide the requested service and security data to protect users and prevent repeated starter grants. Optional Play-account email sharing requires a separate affirmative choice for each listing. Contact support for questions about the legal basis or choices available where you live.

7. Visibility and providers

Listing names, descriptions, package names, Play links and Google Group membership links and addresses are visible to signed-in users who can see the listing. Owners can see participant names, readiness and testing progress. For an email-list test, a reserved tester may enter their Play-account email and explicitly consent to sharing it with that listing owner for test access. It may differ from the Google email used to sign in to Looply. Only that tester and that owner can read it through the participation API; other testers and unrelated owners cannot. Owners must use it only to manage the requested Play test, never for marketing, sale or unrelated contact. Google and developers separately process information when you join their Group or Play test. Supabase processes authentication, database and function data; the current database region is Singapore (ap-southeast-1). Google processes sign-in and Integrity requests. Cloudflare hosts this website, which loads Google Fonts. Zoho Mail handles support correspondence and Zoho Forms handles website contact submissions. Providers may process network/device metadata and information in other countries. We do not sell personal data.

8. Website storage, contact form and external links

The Kukkabu website stores theme, accent, calm-mode and display preferences locally in your browser. Its source does not add advertising trackers. Google Fonts receives font network requests. The homepage contact form sends the name, email, message and referring-page URL you supply to Zoho Forms when submitted so we can handle your inquiry; Zoho may also process network metadata. Zoho support emails and contact submissions stay in our account until we delete them manually; no automatic deletion period is configured. You can request their deletion by emailing support. The deletion page loads Google sign-in only when you choose to verify; Google may use its own cookies or storage. Infrastructure providers can process IP addresses and operational/security logs. Google Play, Groups and independent apps are separate services with their own notices.

9. Active-data retention and deletion

Active account and participation records remain while needed to provide the service, unless removed through supported actions. A submitted Play-account email can be corrected while your place is reserved; correction resets the owner confirmation. To withdraw sharing after readiness, leave the test or contact support. Looply clears the shared email and access confirmation when participation ends, including withdrawal, campaign closure or account deletion. An owner may already have added it to a Google Play list; leaving Looply does not remove that external copy. Owners must remove access-list copies when no longer needed, and you can ask that owner to remove yours. Verification challenges expire after five minutes; hourly maintenance removes expired challenges and rate-limit records. Account deletion ends listings and participation, reconciles unused credits and removes the Auth account, profile and linked active device, listing, enrollment, check-in and ledger records. Other participants keep independently earned credits and their own participation history, including a snapshot of a deleted owner's listing. Minimal accounting events containing record IDs, amounts and timestamps survive deletion to reconcile credits and prevent duplicate adjustments; they contain no names, emails, device data or usage proof and have no configured automatic expiry. Uninstalling or removing Google authorization alone does not delete your account.

10. Retained security hashes

The backend retains keyed Google-account and device hashes plus the starter-grant timestamp after deletion solely to prevent repeated starter grants. These hashes can still be personal data; they are not anonymous, not a profile copy, and not used to contact you. There is currently no automatic expiry. Contact support to request review or deletion of retained information; removing a grant record may affect whether a future account can receive starter credits.

11. Support, logs and backups

Zoho support correspondence and contact submissions remain in our account until manually deleted; there is no configured automatic deletion period. You may request deletion from support. Operational logs and backups can remain under Supabase, Cloudflare, Google and Zoho provider settings after active account data is deleted; they are not necessarily erased immediately. We do not promise a fixed backup or log purge period that we cannot verify. Restored data must remain subject to prior deletion requests.

12. Rights, age and changes

Looply is intended for adults aged 18 or older. Contact support if a child supplied account data. Depending on your location, you may have rights to access, correct, export, delete, restrict or object to processing, withdraw consent, or complain to a privacy authority. Requests may require proportionate identity verification, never your Google password. Material changes will be published here and, where needed, explained in the app with renewed acceptance or consent.

13. Safety reports, blocks and moderation

Looply stores abuse reports with the reporter, reported user, related listing, reason, optional details and review decision. Reports are available only to designated moderators, not other testers or the reported user. User-block relationships hide listings and prevent testing between the accounts. Blocking ends active participation between the pair; already-earned credits stay and unused funding is refunded. Unblocking does not restart tests. Moderation can remove a listing or suspend an account, with a recorded decision reason. Report records remain until a linked account/listing is deleted; linked blocks and moderator assignments are removed on account deletion. Deleting an independent reviewer account clears that reviewer reference. Do not include passwords, tokens or unrelated personal information in reports. Appeals go to support@kukkabu.com.

14. Activity, issues and notifications

Looply stores service notices, their read status, access problems, outage reports, appeals and moderation decisions. Your notices and issues are private to your account; designated moderators can review submitted issues. Avoid including passwords or unrelated personal information. Account deletion removes your linked notices and issues. Android notifications are optional local reminders controlled by the Profile switch and Android permission settings. Refusing notification permission does not prevent participation; you remain responsible for checking your test windows.

Related: Privacy · Terms · Support · Account deletion