← Kukkabu Studios
Studio Policy

Kukkabu Studios Privacy Policy

Effective date: January 1, 2026•Contact: support@kukkabu.com

This Privacy Policy explains how Kukkabu Studios collects, uses, and discloses information when you visit our website (kukkabu.com) or use our mobile applications. For privacy policies specific to our games and apps, please select their respective tabs above.

1. Website Visitors & Cookies

When you visit our website, we may collect basic log information automatically, including your browser type, device information, operating system, and IP address. We use this data to analyze trends, administer the site, and improve user experience. Our website uses minimal operational cookies. You can manage or disable cookies in your browser settings, though some website features may require them to function.

2. Mobile Applications & Services

Kukkabu Studios publishes various mobile games and productivity apps (such as Wall Jumper, Numlink Flow, Receipt Minder, Cash Stride, and Mind Opener). Each app has different data collection practices tailored to its functionality: • Receipt Minder collects account sync details and receipt records via Supabase cloud storage. • Cash Stride collects account sync details and transaction records via Supabase cloud storage. • Wall Jumper is an offline game that integrates third-party AdMob SDKs for optional rewarded ads. • Numlink Flow is an offline logic puzzle game that integrates third-party AdMob SDKs for optional rewarded hint ads. • Mind Opener is a local-only focus aid that collects zero personal data and operates fully offline. Please toggle the tabs above to review the detailed privacy guidelines for each specific app.

3. Data Security & Storage

We use industry-standard security measures to protect the integrity and confidentiality of any information you share with us. For cloud-synced apps, details are encrypted in transit and at rest. However, no internet transmission or electronic storage method is 100% secure.

4. Children's Privacy

Our general services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at support@kukkabu.com so we can investigate and purge the records.

5. GDPR & International Rights

If you reside in the European Economic Area (EEA) or other regions with statutory privacy regulations, you have rights to access, correct, delete, or restrict processing of your personal information. You can manage ad personalized settings and UMP consent options in-app, delete your sync account instantly, or reach out to us by email for data inquiries.

6. Contact Us

If you have any questions, feedback, or concerns regarding our privacy practices, please contact us at support@kukkabu.com.

Receipt Minder Overview →

Receipt Minder Privacy PolicyReceipt Minder Logo

Effective date: January 1, 2026•Contact: support@kukkabu.com

Receipt Minder helps users save receipts, review extracted receipt details, track warranties and return windows, and export reports. This policy explains what data Receipt Minder collects, how it is used, and how users can request deletion.

Data we collect

Account data

Email address, user ID, display name, and authentication provider (email/password or Google sign-in).

Receipt data

Store name, purchase date, totals, taxes, discounts, tips, currency, payment method, categories, tags, and notes, and receipt item names, quantities, prices, barcodes, and product models.

Receipt images and OCR data

Local receipt image files, recognized OCR text, and extraction confidence and extraction status.

Warranty and return data

Product name, warranty duration and expiry date, manufacturer details, claim instructions, and return deadline and return status.

Report and export data

Selected date ranges, report formats, and generated local export files.

Settings and preferences

App display preferences, notification preferences, app lock settings, and connected Google Drive state.

Diagnostics

Crash/error metadata, and sanitized technical context.

Advertising data

Advertising identifiers, ad interaction events, consent choices, and device and app information used by Google Mobile Ads — for Free users.

How we use data

  • Save and display receipt records.
  • Extract receipt details from images and text.
  • Sync user data when a user signs in.
  • Track warranties and return windows.
  • Generate PDF and CSV reports.
  • Back up receipt images to cloud storage.
  • Restore receipt images for Pro users.
  • Process subscriptions through Google Play Billing.
  • Show rewarded ads to Free users.
  • Diagnose crashes and app errors.
  • Respond to support and deletion requests.

Third-party services

  • Supabase — authentication, profile sync, database sync, Edge Functions, and storage where configured.
  • Google Play Billing — subscriptions, purchase validation, refunds and cancellation handled by Google Play.
  • Google AdMob / Google Mobile Ads — rewarded ads for Free users, advertising ID and consent-based ad serving.
  • Google Drive — optional image backup for users who connect Drive.
  • Google sign-in — sign in to or create a Receipt Minder account with Google.
  • Sentry — optional crash/error diagnostics.
  • Google Gemini or configured AI provider — AI receipt extraction for both free and paid users (subject to limits and rewarded ads on the free tier).

Advertising

Free users may see Google AdMob rewarded ads when they choose to unlock limited extra AI receipt scans, receipt saves, warranty slots, or watermarked PDF exports. These rewards are subject to daily and monthly caps. Premium and Minder Pro users do not see ads. Google Mobile Ads may use advertising identifiers, device information, and consent choices to serve personalized, non-personalized, limited, or technical ads. For users in the European Economic Area (EEA), ad consent preferences can be managed, customized, or withdrawn at any time through the in-app settings via the Google User Messaging Platform (UMP) consent options form.

Data sharing

  • Receipt Minder does not sell user receipt data.
  • Data may be shared with the third-party services listed above only to operate the app features.
  • Users control whether to connect Google Drive.
  • Users control whether to create/sign in to an account.

Data retention

  • Local data stays on the device until deleted by the user or app data is cleared.
  • Synced account data remains until the user deletes it or requests deletion. When data is deleted or soft-deleted by the user, it is permanently purged from our backend database and storage systems within a 30-day retention window.
  • Google Play billing records may be retained by Google according to Google policies.
  • Diagnostics may be retained for a limited operational period.

Account and data deletion

  • Signed-in users can delete their account from Settings → Privacy & Security → Delete Account.
  • Users can also clear only the data stored on their current device.
  • Users can request deletion by email.
  • Deletion requests should include the email used for the Receipt Minder account.
  • For full instructions, see the Delete Account page.

Security

  • Receipt Minder uses platform and provider security features.
  • Sensitive receipt text and image URIs should not be included in diagnostics.
  • App lock is available on device.
  • No method of storage or transmission is perfectly secure.

Children

Receipt Minder is not designed for children under 13 and is intended for general users who manage personal or business receipts.

Changes

This policy may change and the effective date will be updated.

Contact

support@kukkabu.com

Cash Stride Overview →

Cash Stride Privacy PolicyCash Stride Logo

Effective date: August 11, 2026•Contact: support@kukkabu.com

Cash Stride is a sleek, cross-platform personal finance manager designed to give you complete clarity over your financial life. We value your privacy and isolate your records database-side.

1. Introduction

We value your privacy. This Privacy Policy explains how Cash Stride collects, uses, and protects your information when you use our services.

2. Data We Collect

We collect your profile details (name, email), financial records you log (expenses, income, budgets, categories), and any bug report descriptions and screenshot attachments you upload.

3. How We Use Data

Your financial data is used solely to provide in-app analytics, budget tracking, and reports. Screenshots and bug reports are used to diagnose and resolve issues.

4. Data Security & Storage

Your data is stored securely using Supabase and is protected by Row Level Security (RLS) policies, ensuring only you can access your personal information.

5. Your Rights

You have the right to access, edit, or delete your data at any time. You can permanently delete your account and all associated data directly from the Settings screen.

6. Contact Us

If you have any questions or concerns about our privacy practices, please contact us at support@kukkabu.com.

Looply Overview →

Looply privacy policyLooply Logo

Effective: October 3, 2026•Contact: support@kukkabu.com

What the Android app and these website pages process, why, and how you can request deletion.

1. Operator and contact

Looply is operated under the independent developer name Kukkabu Studios. For service, privacy or account requests, contact support@kukkabu.com.

2. Sign-in and account data

Google is the only sign-in method. Supabase Auth verifies Google identity tokens and manages sessions. Looply stores your Google account identifier, verified email, display name, profile-image URL, user ID and terms acceptance version. We do not receive your Google password. Android session and refresh tokens use secure local storage.

3. Device registration and integrity

Registration sends the app-scoped Android device identifier over HTTPS for server-side keyed hashing. The database stores its hash, device model, Android version and verification time, not the raw identifier. Google Play Integrity processes package, certificate, licensing, device, timestamp and request-binding signals. Tokens are not intentionally logged or retained after verification. Integrity is a risk signal, not an immutable phone identity or guarantee against fraud.

4. Testing and Android Usage Access

Looply stores listings, enrollments, daily check-ins, foreground seconds and credit transactions. Android Usage Access can expose broader usage events on your phone. Looply processes these locally to measure the assigned test package within its testing window, accounting for screen lock/device state. Only the enrollment, device reference, time window and foreground-second total are uploaded, not your complete usage-event stream or full app-use history. Usage Access is requested after an in-app explanation and can be revoked in Android settings. Without it, measured check-ins cannot succeed.

5. Information not requested

The current app does not request contacts, messages, call logs, phone numbers, location, microphone or camera access. It does not record screens, keystrokes or tested-app contents. There are no advertising or analytics SDKs in the current Android implementation. Processing a Google profile-image URL is not access to your photo library.

6. Why we process data

Data supports sign-in, testing coordination, device registration, measured check-ins, internal credits and refunds, security, abuse prevention, support and deletion. We process account and participation data to provide the requested service and security data to protect users and prevent repeated starter grants. Optional Play-account email sharing requires a separate affirmative choice for each listing. Contact support for questions about the legal basis or choices available where you live.

7. Visibility and providers

Listing names, descriptions, package names, Play links and Google Group membership links and addresses are visible to signed-in users who can see the listing. Owners can see participant names, readiness and testing progress. For an email-list test, a reserved tester may enter their Play-account email and explicitly consent to sharing it with that listing owner for test access. It may differ from the Google email used to sign in to Looply. Only that tester and that owner can read it through the participation API; other testers and unrelated owners cannot. Owners must use it only to manage the requested Play test, never for marketing, sale or unrelated contact. Google and developers separately process information when you join their Group or Play test. Supabase processes authentication, database and function data; the current database region is Singapore (ap-southeast-1). Google processes sign-in and Integrity requests. Cloudflare hosts this website, which loads Google Fonts. Zoho Mail handles support correspondence and Zoho Forms handles website contact submissions. Providers may process network/device metadata and information in other countries. We do not sell personal data.

8. Website storage, contact form and external links

The Kukkabu website stores theme, accent, calm-mode and display preferences locally in your browser. Its source does not add advertising trackers. Google Fonts receives font network requests. The homepage contact form sends the name, email, message and referring-page URL you supply to Zoho Forms when submitted so we can handle your inquiry; Zoho may also process network metadata. Zoho support emails and contact submissions stay in our account until we delete them manually; no automatic deletion period is configured. You can request their deletion by emailing support. The deletion page loads Google sign-in only when you choose to verify; Google may use its own cookies or storage. Infrastructure providers can process IP addresses and operational/security logs. Google Play, Groups and independent apps are separate services with their own notices.

9. Active-data retention and deletion

Active account and participation records remain while needed to provide the service, unless removed through supported actions. A submitted Play-account email can be corrected while your place is reserved; correction resets the owner confirmation. To withdraw sharing after readiness, leave the test or contact support. Looply clears the shared email and access confirmation when participation ends, including withdrawal, campaign closure or account deletion. An owner may already have added it to a Google Play list; leaving Looply does not remove that external copy. Owners must remove access-list copies when no longer needed, and you can ask that owner to remove yours. Verification challenges expire after five minutes; hourly maintenance removes expired challenges and rate-limit records. Account deletion ends listings and participation, reconciles unused credits and removes the Auth account, profile and linked active device, listing, enrollment, check-in and ledger records. Other participants keep independently earned credits and their own participation history, including a snapshot of a deleted owner's listing. Minimal accounting events containing record IDs, amounts and timestamps survive deletion to reconcile credits and prevent duplicate adjustments; they contain no names, emails, device data or usage proof and have no configured automatic expiry. Uninstalling or removing Google authorization alone does not delete your account.

10. Retained security hashes

The backend retains keyed Google-account and device hashes plus the starter-grant timestamp after deletion solely to prevent repeated starter grants. These hashes can still be personal data; they are not anonymous, not a profile copy, and not used to contact you. There is currently no automatic expiry. Contact support to request review or deletion of retained information; removing a grant record may affect whether a future account can receive starter credits.

11. Support, logs and backups

Zoho support correspondence and contact submissions remain in our account until manually deleted; there is no configured automatic deletion period. You may request deletion from support. Operational logs and backups can remain under Supabase, Cloudflare, Google and Zoho provider settings after active account data is deleted; they are not necessarily erased immediately. We do not promise a fixed backup or log purge period that we cannot verify. Restored data must remain subject to prior deletion requests.

12. Rights, age and changes

Looply is intended for adults aged 18 or older. Contact support if a child supplied account data. Depending on your location, you may have rights to access, correct, export, delete, restrict or object to processing, withdraw consent, or complain to a privacy authority. Requests may require proportionate identity verification, never your Google password. Material changes will be published here and, where needed, explained in the app with renewed acceptance or consent.

13. Safety reports, blocks and moderation

Looply stores abuse reports with the reporter, reported user, related listing, reason, optional details and review decision. Reports are available only to designated moderators, not other testers or the reported user. User-block relationships hide listings and prevent testing between the accounts. Blocking ends active participation between the pair; already-earned credits stay and unused funding is refunded. Unblocking does not restart tests. Moderation can remove a listing or suspend an account, with a recorded decision reason. Report records remain until a linked account/listing is deleted; linked blocks and moderator assignments are removed on account deletion. Deleting an independent reviewer account clears that reviewer reference. Do not include passwords, tokens or unrelated personal information in reports. Appeals go to support@kukkabu.com.

14. Activity, issues and notifications

Looply stores service notices, their read status, access problems, outage reports, appeals and moderation decisions. Your notices and issues are private to your account; designated moderators can review submitted issues. Avoid including passwords or unrelated personal information. Account deletion removes your linked notices and issues. Android notifications are optional local reminders controlled by the Profile switch and Android permission settings. Refusing notification permission does not prevent participation; you remain responsible for checking your test windows.

Mind Opener Overview →

Mind Opener Privacy PolicyMind Opener Logo

Effective date: January 1, 2026•Contact: support@kukkabu.com

Overview

Mind Opener is a visual focus session tool for Android. It provides configurable moving bar sessions and stores settings and session totals locally on the user's device.

Data collection

Mind Opener does not collect personal information in the current Android release.

Local storage

Mind Opener stores app settings and session totals locally on the device. This may include:

  • Selected session duration
  • Bar direction
  • Travel time and pause settings
  • Bar thickness
  • Focus colors and half-time color settings
  • Break reminder preferences
  • Total sessions
  • Total focus time
  • Completed cycle count
  • Last session timestamp

No account

Mind Opener does not require an account, login, or user profile.

No ads or analytics

Mind Opener does not include advertising SDKs, analytics SDKs, or crash reporting SDKs in the current Android release.

Data sharing

Mind Opener does not sell or share personal data.

Internet and permissions

The current Android release is designed as a local-only app. It does not request Android platform permissions such as storage, camera, microphone, location, contacts, or notifications.

Data retention and deletion

Local settings and stats stay on the device until the user resets them in the app, clears app data, or uninstalls the app.

Age restrictions

Mind Opener is intended for individuals aged 18 and older. It is not directed to children.

Changes

This policy may be updated if the app's features or data practices change.

Contact

support@kukkabu.com

Wall Jumper Overview →

Wall Jumper Privacy PolicyWall Jumper Logo

Effective date: July 23, 2026•Contact: support@kukkabu.com

1. Information We Collect Automatically

Wall Jumper is built as a free-to-play, ad-supported game. We do not require users to create accounts, and we do not collect personal information such as names, addresses, or phone numbers directly. However, the Game integrates third-party software development kits (SDKs) that automatically collect certain information from your device. Specifically, we use Google AdMob to serve advertising. The Google AdMob SDK may collect: Device Identifiers (Advertising ID), Device Metadata (model, OS, screen size, IP address, network provider), and Usage Statistics (ad clicks/views and performance logs).

2. Third-Party Service Providers

Third-party service providers collect and process data in accordance with their own privacy policies. You can read the privacy policy of our service provider here: Google Play Services & Google AdMob Privacy Policy (https://policies.google.com/privacy). Google's use of data is further described at https://policies.google.com/technologies/ads.

3. How We Use the Collected Information

  • Ad Delivery: To display ads (personalized or non-personalized based on your consent and device settings).
  • Ad Performance & Bug Fixing: To monitor ad performance, diagnose crashes, and optimize game flow using logs provided by the Google AdMob SDK.
  • Fraud Prevention: To prevent invalid ad impressions and click spam.

4. Consent (EEA, UK, and Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we will show a consent form (via Google's User Messaging Platform) before serving personalized ads. You may choose to receive non-personalized ads instead. You can change your consent choice at any time from within the game under Settings → Ad Consent.

5. Children's Privacy (COPPA & GDPR Compliance)

Wall Jumper is not designed or intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information to third-party services within the game, please contact us at support@kukkabu.com so we can request removal from our partners' servers.

6. Data Retention & Deletion

Because the Game runs locally on your device and does not store user accounts or personal profiles on external servers, the Developer does not hold any user data that can be deleted. Device identifiers collected by Google AdMob are managed directly by Google and can be reset or disabled in your device's operating system settings under "Ads".

7. Your Choices & Control

You can opt out of personalized ads or reset your advertising identifier directly on your device:

  • On Android: Open Settings → Google → Ads → Opt out of Ads Personalization, or Reset advertising ID.
  • On iOS: Open Settings → Privacy & Security → Tracking → turn off "Allow Apps to Request to Track."

EEA/UK/Switzerland users can also reopen the consent form at any time from the game's Settings → Ad Consent screen.

8. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective date" above.

9. Contact Us

If you have any questions or suggestions regarding this Privacy Policy, please contact us at support@kukkabu.com.

Numlink Flow Overview →

Numlink Flow Privacy PolicyNumlink Flow Logo

Effective date: August 30, 2026•Contact: support@kukkabu.com

1. Information We Collect Automatically

Numlink Flow is built as a free-to-play, offline-first logic puzzle game. We do not require users to create accounts, and we do not collect personal information such as names, addresses, or phone numbers directly. All puzzle progress, star counts, daily streaks, and game settings are stored locally on your device. However, the game integrates third-party software development kits (SDKs) to serve optional rewarded ads for hints. Specifically, we use Google AdMob, which may automatically collect: Device Identifiers (Advertising ID), Device Metadata (model, OS, screen size, IP address, network carrier), and Usage Statistics (ad clicks, views, and crash performance logs).

2. Third-Party Service Providers

Third-party service providers collect and process data in accordance with their own privacy policies. You can read the privacy policy of our service provider here: Google Play Services & Google AdMob Privacy Policy (https://policies.google.com/privacy). Google's use of data is further described at https://policies.google.com/technologies/ads.

3. How We Use the Collected Information

  • Ad Delivery: To display optional rewarded hint ads (personalized or non-personalized based on your consent and device settings).
  • Ad Performance & Diagnostics: To monitor ad delivery, diagnose runtime crashes, and optimize game flow using telemetry provided by the Google AdMob SDK.
  • Fraud Prevention: To prevent invalid ad impressions and automated spam.

4. Consent (EEA, UK, and Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we present a consent form (via Google's User Messaging Platform) before serving personalized ads. You may choose to receive non-personalized ads instead. You can modify your consent choice at any time from within the game under Settings → Ad Consent.

5. Children's Privacy (COPPA & GDPR Compliance)

Numlink Flow is not designed or intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided personal information to third-party services within the game, please contact us at support@kukkabu.com so we can request removal from our partners' servers.

6. Data Retention & Deletion

Because the game runs locally on your device and does not store user accounts or personal profiles on external servers, the Developer does not hold any user data that can be deleted. Device identifiers collected by Google AdMob are managed directly by Google and can be reset or deleted in your device's operating system settings under 'Ads'.

7. Your Choices & Control

You can opt out of personalized ads or reset your advertising identifier directly on your device:

  • On Android: Open Settings → Google → Ads → Opt out of Ads Personalization, or Reset advertising ID.
  • On iOS: Open Settings → Privacy & Security → Tracking → turn off 'Allow Apps to Request to Track.'

EEA/UK/Switzerland users can also reopen the consent form at any time from the game's Settings → Ad Consent screen.

8. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the 'Effective date' above.

9. Contact Us

If you have any questions or suggestions regarding this Privacy Policy, please contact us at support@kukkabu.com.