Data Safety Form

Updated July 26, 2026 · Based on a code audit of the app

For full details on uses, providers and your rights, see the Privacy Policy.

Data the app collects

Personal info

  • Email address: Account management: sign-in, account recovery and ban enforcement. If the account is permanently banned, the email is kept to prevent re-registration. Optional. Shared with Google (OAuth identity provider) and Supabase (auth processor, AWS USA). You can delete it.
  • Name (Google display name) and Google profile-picture URL: Account management. Stored from your Google account at sign-in; the picture is stored but not currently displayed in the app. Optional. Shared with Google (source via OAuth) and Supabase (processor). You can delete it.
  • User ID (UUID, assigned to everyone including guests) and random public username: App functionality: keys your server-side records (skills, social, telemetry, store, PvP, moderation, notifications). The username is your public handle shown to other players and is editable. Required. Shared with Supabase (processor). You can delete it.

Messages

  • Comments and replies on exercises (500 characters max): Social feed functionality. Screened by an automatic moderation filter (profanity, contact info, links); violating comments are hidden. Copies of the text may be kept in reports and notifications even after you delete the comment. Optional. Not shared with third parties. You can delete it.

App activity

  • Likes and saves on exercises, comment likes: App functionality and a feed-personalization signal. You can toggle each reaction off at any time. Optional. Not shared with third parties. You can delete it.
  • Behavioral telemetry: impressions, dwell time, solves, wrong attempts, skips, scroll-backs, feed switches and app foreground/background, with per-session skill-vector snapshots: Improving the exercise sequence and understanding which content works. Only collected if you accept telemetry; you can withdraw it in You → Privacy. Kept for 24 months and fully erased when you delete your account. Optional. Not shared with third parties. You can delete it.
  • Math skill-mastery vector, seeded from your onboarding grade and ability tier: Personalization: drives which exercises are recommended to you. Your other onboarding answers (goal, pace, per-topic comfort) stay on-device only. Required. Not shared with third parties. You can delete it.
  • PvP duel win/loss tally: Functionality: the lobby comparison card shows your cumulative wins and losses to other players. Live duels are relayed in memory and never stored. Optional. Not shared with third parties. You can delete it.
  • Owned and equipped avatar cosmetics (item IDs only): Functionality and personalization: your avatar outfit, visible to other lobby players. Optional. Not shared with third parties. You can delete it.
  • User reports (reason code + optional detail up to 500 characters + reported-comment snapshot), blocks, and moderation sanctions (mutes and bans): Safety and moderation: reports go to a human review queue; blocks hide both sides; permanent bans register the banned email. Reports are kept even if the comment is deleted. Optional. Not shared with third parties. Deletion via email request.
  • Notification log (replies, comment likes, system announcements) with comment-body snapshots: Functionality: the You-tab notifications list. The log keeps text snapshots even if the original comment is deleted. Optional. Not shared with third parties. You can delete it.
  • Ephemeral multiplayer presence: position, pose, emotes (fixed list, no free text), outfit and username, plus presence heartbeats with a random per-app-session client ID: Functionality: the real-time 3D plaza and "players online" counters. NOT persisted: it lives only in memory and vanishes within seconds or on service restart. Optional. Not shared with third parties. You can delete it.
  • On-device-only data: XP, streaks, missions, attempt history, saved items, feed-model state, onboarding answers (goal/pace/comfort), session tokens and language preference: App functionality. Never leaves the device except via the flows described above; stored in unencrypted local storage and cleared by uninstalling the app or clearing its data. Required. Not shared with third parties. You can delete it.

Device or other IDs

  • Device model, OS platform and app version attached to each telemetry session (not a unique hardware ID): Analytics: segmenting behavior by platform and device class. Optional. Not shared with third parties. You can delete it.
  • PostHog anonymous ID (SDK-generated, persisted on device) + standard device context (model, OS, app version, screen size) + transient client IP for coarse geolocation: Product analytics, only with your consent: the app starts with analytics off. We send a short list of named events (completing a challenge, viewing the subscription screen, starting or completing a purchase, running out of hearts); we do not send screen views or taps. Never linked to your Kimcura account. Optional. Shared with PostHog Inc. (US Cloud). Deletion via email request.

In-app purchases

  • Kimcura Plus subscription state (active or not) and an identifier for your account: Knowing whether you have access to paid features. Payment is processed by the app store: we never receive or store your card details. Optional. Shared with RevenueCat Inc. (USA) and the app store (Google Play or the App Store). You can delete it.

What Kimcura does NOT collect

  • Precise or approximate location (no permissions or geolocation code; only PostHog's server-side coarse IP geolocation)
  • Contacts
  • User photos or videos
  • Microphone or audio recordings
  • Advertising ID and ads (no ad SDKs)
  • Financial or payment information (the app store processes payment; we never see or store your card details)
  • Push notification tokens (notifications are in-app only)
  • Health and fitness data
  • SMS or call logs
  • Calendar
  • Files and documents
  • Web browsing history
  • Persistent hardware device identifiers