Looply data safety summary

Implementation summary, not a submitted or approved Play Console declaration.

Draft updated: September 27, 2026 · support@kukkabu.com

Account and device information

Google account ID, email, name, profile-image URL, user ID, keyed device hash, device model/version and Integrity verdicts support accounts, registration and security. Hashing does not make identifiers anonymous.

App activity

Listings, enrollments, check-ins, foreground seconds and ledger activity are stored. Usage events are processed locally; assigned-test totals are uploaded, not the full event stream. Support correspondence can contain voluntarily supplied information.

Providers and disclosures

Supabase, Google, the website host and support-email provider process service data. Google Groups/Play tests involve separate user-directed actions. Use Google’s actual collection/sharing definitions and the final provider settings for the Console form; do not automatically claim no data collected or shared.

Security, choices and retention

Transport uses HTTPS, Android sessions use secure storage, private routes verify sessions, and tables/RPC access are restricted. Users can revoke usage access and request deletion in-app, on the web or by email. Limited grant hashes remain. Provider and retention settings still require review.

Related: Privacy · Terms · Support · Account deletion