Looply privacy policy

What the current Android app and these website pages process, why, and how you can request deletion.

Draft updated: September 27, 2026 · support@kukkabu.com

Before public launch

Legal draft — pre-launch. These pages describe the current implementation, not an approved or publicly available Play release. Product policy fit, applicable legal requirements, provider settings and support/log/backup retention must be reviewed before launch.

1. Operator and contact

Looply is operated under the independent developer name Kukkabu Studios. For service, privacy or account requests, contact support@kukkabu.com.

2. Sign-in and account data

Google is the only sign-in method. Supabase Auth verifies Google identity tokens and manages sessions. Looply stores your Google account identifier, verified email, display name, profile-image URL, user ID and terms acceptance version. We do not receive your Google password. Android session and refresh tokens use secure local storage.

3. Device registration and integrity

Registration sends the app-scoped Android device identifier over HTTPS for server-side keyed hashing. The database stores its hash, device model, Android version and verification time, not the raw identifier. Google Play Integrity processes package, certificate, licensing, device, timestamp and request-binding signals. Tokens are not intentionally logged or retained after verification. Integrity is a risk signal, not an immutable phone identity or guarantee against fraud.

4. Testing and Android Usage Access

Looply stores listings, enrollments, daily check-ins, foreground seconds and credit transactions. Android Usage Access can expose broader usage events on your phone. Looply processes these locally to measure the assigned test package within its testing window, accounting for screen lock/device state. Only the enrollment, device reference, time window and foreground-second total are uploaded, not your complete usage-event stream or full app-use history. Usage Access is requested after an in-app explanation and can be revoked in Android settings. Without it, measured check-ins cannot succeed.

5. Information not requested

The current app does not request contacts, messages, call logs, phone numbers, location, microphone or camera access. It does not record screens, keystrokes or tested-app contents. There are no advertising or analytics SDKs in the current Android implementation. Processing a Google profile-image URL is not access to your photo library.

6. Purposes and legal bases

Data supports sign-in, testing coordination, phone registration, verified check-ins, credits/refunds, security, support and deletion. Where applicable, processing may rely on performance of the service agreement, proportionate legitimate security interests, consent for optional processing or legal obligations. Applicable legal bases and privacy safeguards must be reviewed for the locations where the service will be offered before public launch.

7. Visibility and providers

Listing names, descriptions and access links are visible to signed-in users. The current API does not expose tester email addresses to owners or other testers. Google and developers may receive account information separately when you join their Google Group or Play test. Supabase processes authentication, database and function data; the current database region is Singapore (ap-southeast-1). Google processes sign-in and Integrity requests. The website is configured for Cloudflare static hosting and Google Fonts. Our support-email provider processes correspondence. Providers may process network/device metadata and information across countries. The email provider, actual hosting settings and international-transfer safeguards need confirmation before launch. We do not sell personal data.

8. Website storage, contact form and external links

The Kukkabu website stores theme, accent, calm-mode and display preferences locally in your browser. Its source does not add advertising trackers. Google Fonts receives font network requests. The homepage contact form sends the name, email, message and referring-page URL you supply to Zoho Forms when submitted so we can handle your inquiry; Zoho may also process network metadata. Form-data retention/settings need confirmation. The deletion page loads Google sign-in only when you choose to verify; Google may use its own cookies or storage. Infrastructure providers can process IP addresses and operational/security logs. Google Play, Groups and independent apps are separate services with their own notices.

9. Active-data retention and deletion

Account and participation records remain while your account exists unless removed through supported actions. Verification challenges expire after five minutes; hourly maintenance removes expired challenges and rate-limit records. Account deletion ends listings/participation, reconciles unused funding and removes your Auth account, profile and linked active device/listing/enrollment/check-in/ledger records. Other users retain independently owned earned credits and records. Uninstalling or removing Google authorization alone does not delete your server account.

10. Retained security hashes

The backend retains keyed Google-account and device hashes plus the starter-grant timestamp after deletion solely to prevent repeated starter grants. These hashes can still be personal data; they are not anonymous, not a profile copy, and not used to contact you. There is currently no automatic expiry. A proportionate retention period, legal basis and rights-handling process require review before launch. Contact support to request review of retained information.

11. Support, logs and backups

Support correspondence and operational logs/backups may be retained by the actual email and infrastructure providers according to selected plans and settings. Account deletion removes active data, not necessarily every existing backup immediately. This draft does not invent retention durations: actual periods must be confirmed and published before launch. Any restoration process must respect previous deletion requests.

12. Rights, age and changes

Looply is intended for adults aged 18 or older. Contact support if a child supplied account data. Depending on your location, you may have rights to access, correct, export, delete, restrict or object to processing, withdraw consent, or complain to a privacy authority. Requests may require proportionate identity verification, never your Google password. Material changes will be published here and, where needed, explained in the app with renewed acceptance or consent.

Related: Privacy · Terms · Support · Account deletion