Kuji Cookie & SDK Notice
Applies to: the Kuji app (com.tacitlabs.kuji), outside the United Kingdom and outside the European Economic Area
Read alongside: the Kuji Privacy Policy, which this notice supplements.
1. What this notice covers
Kuji is an app, not a website, so it uses no browser cookies. What it does use are SDKs: small pieces of software made by another company and built into the app.
An SDK runs inside Kuji on your device. Some of them can send information out to the company that made them. They do the same kinds of job that cookies do on a website: measuring which features get used, reporting crashes, and handling purchases.
This notice covers every third-party component in Kuji that can process information beyond your device. Section 5 lists the ones that cannot.
It supplements the Kuji Privacy Policy. The privacy policy explains what we do with information overall. This notice explains, component by component, who else is involved.
2. How your choice is asked for and applied
Kuji uses a first-party consent control built into the app. There is no third-party consent platform, and no consent banner from another company.
Everything optional is off until you say yes. A small sharing panel appears shortly after Kuji first opens; picking is never delayed, blocked or interrupted to ask you, and closing the panel without choosing grants nothing. You can change any answer later: app menu → Sharing.
This is the same wherever you are. Kuji asks everyone, including in countries whose law does not require prior permission, and it does not work out what country you are in to decide. It makes no network request to find out where you are, and it reads no location signal from your device for this purpose.
There are three separate switches: Usage data, Crash reports and Advertising measurement. They carry the same three labels on the sharing panel and in the menu afterwards. All three start off, and each one stays off until you turn it on. They are genuinely independent: turning one on does not turn on any other, and none of them rides in on a consent you gave to something else.
A switch that is off means the component is not running at all. The analytics, crash-reporting and advertising-measurement components are not merely told to stay quiet; they are not started, so nothing can leak through a mistake in a setting. That is true whichever way the switch got there: off because you were asked and declined, or off because you turned it off yourself.
Nothing runs until you say yes.
One component runs regardless. The Play Billing component described in section 4 runs at every launch and every return to the app. It asks the store whether the paid unlock has been bought on your account. It is not behind a switch because it is necessary to perform our contract with you under the Terms of Use: it is how the unlock you paid for stays active, and on a new device it is how the unlock follows you.
On top of that, Kuji ties the advertising-related signals in the analytics SDK to Advertising measurement: they are granted while that setting is on, and denied while it is off.
That setting starts off, so those signals start denied.
Your choice is stored on your device, in Kuji's own private storage, and is read and applied every time the app launches. It is deliberately kept when you use "reset to defaults", so that resetting your settings can never quietly switch collection back on.
Your choice is version-stamped. If we ever widen what is collected, the stamp changes and you are asked again, rather than an old answer being carried forward onto something new you never agreed to.
One rule that does not vary: your choice is always yours. What is stored is what you actually chose. Kuji never records a choice on your behalf, and never treats "we did not ask" as "you agreed". Every switch sits in the same place, works the same way, and can be changed as often as you like.
Turning a switch off takes effect immediately. It stops future collection, and it clears what is still on your device: switching analytics off clears the analytics data cached there and replaces your analytics installation identifier with a new one, switching crash reports off deletes any report not yet sent, and switching advertising measurement off clears the data that component had stored on your device.
What the provider has already received is not deleted at that moment. Section 3 gives the period for each provider. That data is kept for that long, then deleted.
3. Components you can turn off
All three are off until you switch them on (see section 2), wherever you are, and each one stops the moment you switch it off.
3.1 Firebase Analytics: usage analytics
| Provider | Google Ireland Limited |
| Purpose | To understand which modes and features get used, so we know what to improve — in Kuji, and in other apps we make, including ones we have not released yet. Comparing the same feature across products is why this data is kept as long as it is; see the retention row |
| Runs only if | You turn Usage data on; see section 2. With the switch off it is not initialised at all |
| What it collects | A fixed set of ten events: a round started, a pick finished, a re-pick, a saved list was changed, a setting was moved, the record pane was opened, a privacy choice was saved, a free-tier limit was reached, the upgrade screen was shown, and the paid unlock was bought. Each carries a small number of plain labels and counts — which mode, how many took part, how many winners or teams, which setting moved and to what. Plus, automatically: app version, device model, operating system version, session and engagement data, an app-instance identifier, and an approximate location worked out from your network address — a city, that city's coordinates, and a postcode area (in the UK the outward code only, e.g. LU5). Plus two labels we attach ourselves: whether you have bought the paid unlock, and which build of the app you are running |
| What it deliberately does not collect | Any name you have typed, who or what won, or anything else you have typed. Kuji records how it is used, not what was picked or who was playing |
| Retention | Two periods, both set on our analytics account. Event records: 2 months. The app-instance identifier and what is tied to it: 14 months after your last use of Kuji, restarting each time you use it. Counts and totals that no longer identify an installation are not covered by either |
| The provider's role | Processor. It handles this data on our instructions and for our purposes only, not its own |
| Where it is processed | In the United States. Our agreement does not confine it to one country: it permits processing wherever the provider or its own suppliers operate facilities, rather than naming a list we could hold it to. The safeguard is the standard contractual clauses in the provider's own terms |
| Their privacy information | firebase.google.com/support/privacy |
On the location line. Kuji asks for no location permission and reads no location API. The value exists because the provider works it out from your network address, and it is not present at all if you have not turned analytics on.
How precise it is. A city, the coordinates of that city, and a postcode area — in the UK the outward code only, such as
LU5,SE8orEC4N, and in some other countries a full postal code.What that is not. It is not an address. An outward code reaches tens of thousands of homes and identifies none of them; no house and no street is involved. The coordinates are the city's and not yours. Nothing here comes from a satellite positioning system. And neither provider stores the network address the whole thing is worked out from.
3.2 PostHog: usage analytics
| Provider | PostHog, Inc., 2261 Market Street #4008, San Francisco, California, United States |
| Purpose | To understand which modes and features get used, so we know what to improve — in Kuji, and in other apps we make, including ones we have not released yet. Comparing the same feature across products is why this data is kept as long as it is; see the retention row |
| Runs only if | You turn Usage data on; see section 2. With the switch off it is not initialised at all: the component is never started, rather than started and told to stay quiet |
| What it collects | The same ten events and the same labels and counts as 3.1. Plus, automatically: an identifier for your installation, app version, device model, and operating system version, and the same two labels we attach ourselves: whether you have bought the paid unlock, and which build of the app you are running. Your network address is used to work out an approximate location and is then discarded rather than stored |
| What it deliberately does not collect | Any name you have typed, who or what won, or anything else you have typed. Screen views, launch-link contents and the device log are all switched off in the app rather than left to the provider's defaults, and no recording of your screen is made. Crash reporting is not part of this: it belongs to 3.3, behind a different switch |
| Retention | One period, set on our account with the provider: seven years. Counts and totals that no longer identify an installation are not covered by it |
| The provider's role | Processor. It handles this data on our instructions and for our purposes only, not its own |
| Where it is processed | Stored in the provider's European region, hosted in Germany. The provider is a United States company and our agreement with it allows for access and support from the US, under the standard contractual clauses built into that agreement |
| Their privacy information | posthog.com/privacy |
3.3 Firebase Crashlytics: crash reports
| Provider | Google Ireland Limited |
| Purpose | To find out when Kuji crashes, and why, so it can be fixed |
| Runs only if | You turn Crash reports on; see section 2. With the switch off it is not initialised at all |
| What it collects | The technical record of a crash (where in the code it happened, device model, operating system version, app version) and an installation identifier for the crash-reporting service |
| What it deliberately does not collect | No custom values are attached to reports, no user identifier is set, and no trail of your actions is recorded. Nothing you have typed can appear in a crash report |
| Retention | 90 days, on a rolling basis |
| The provider's role | Processor, on our instructions and for our purposes only |
| Where it is processed | As in 3.1 |
| Their privacy information | firebase.google.com/support/privacy |
3.4 Meta: advertising measurement
| Provider | Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California, United States. This is the Meta company responsible outside the European Economic Area, which is where this notice applies |
| Purpose | To measure which of our adverts brought people to Kuji, and whether they went on to buy the paid unlock |
| Runs only if | You turn Advertising measurement on; see section 2. With the switch off it is not initialised at all |
| What it collects | The advertising identifier your device provides; the fact that Kuji was installed and, if it happens, that the paid unlock was bought; information identifying the advert or campaign you interacted with; and your network address, used to match the install to the advert. Plus app version, device model, operating system, and the other standard technical details the provider's software attaches to what it sends. That last part is described as a category rather than a list, because the provider does not publish an exhaustive one |
| What it deliberately does not collect | Any name you have typed, who or what won, or anything else you have typed. The same exclusion rule applies here as everywhere else in Kuji |
| Retention | Up to two years. This is set by the provider under its own terms rather than by us: its Business Tools Terms permit it to keep this data for a maximum of two years |
| The provider's role | Independent controller. Meta uses what it receives for its own advertising purposes as well as ours. It does not simply act on our instructions, and we do not control what it does with it afterwards |
| Where it is processed | In the United States, where the provider is established. Where your own country's law treats that as a transfer needing a safeguard, the safeguard is a data-transfer agreement between us and the provider, designed to keep your information at an equivalent level of protection. Ask us for a copy using the contact details in section 7 |
| Their privacy information | www.facebook.com/privacy/policy |
3.5 Google: advertising measurement
This one is a route, not a component. There is no Google advertising SDK in Kuji. Nothing extra is installed and nothing extra is started. The analytics component in 3.1 is simply allowed to pass its advertising-related signals on. Separately, the Play Store tells Google which campaign led to the install. We list it here because the effect on you is the same.
| Provider | Google Ireland Limited |
| Purpose | To measure which of our adverts and store campaigns brought people to Kuji, and whether they went on to buy the paid unlock |
| When it happens | Only if you turn Advertising measurement on; see section 2. With that switch off, the advertising signals stay denied and none of this is sent |
| What is involved | The advertising-related signals attached to what 3.1 already sends, permitting Google to use it for our own campaign measurement. Alongside that, the Play Store passes Google the campaign that led to the install; that is the store's own record of its own advert, not something Kuji reads. Plus the fact that Kuji was installed and, if it happens, that the paid unlock was bought |
| What is not involved | Kuji does not send Google your advertising identifier here. The analytics component has that collection switched off in the app itself, and turning this switch on does not turn it back on |
| What it deliberately does not collect | Any name you have typed, who or what won, or anything else you have typed |
| Retention | Set by the provider under its own terms, not by us; see their privacy policy |
| The provider's role | Independent controller for advertising purposes. This is a different role from the one Google plays in 3.1 and 3.3, where it acts as our processor. The same company in two different capacities |
| Where it is processed | In the United States, and wherever else Google operates, under Google's own transfer arrangements rather than ours. This is the one entry on this page whose destination is not set by an agreement we hold |
| Their privacy information | policies.google.com/privacy |
3.6 Advertising inside the app
There is none. Kuji contains no advertising SDK that displays anything to you. There is no personalised advertising, no non-personalised advertising, and no fallback, because there are no adverts at all.
3.7 Selling and sharing your information
We do not sell your information. No data broker receives anything from Kuji.
We do share for cross-context behavioural advertising, unless you turn Advertising measurement off.
While that switch is on, Kuji sends Meta an advertising identifier, plus the fact that you installed Kuji and whether you bought the paid unlock (3.4). Google receives the advertising signals and the campaign information set out in 3.5, and not the advertising identifier. Both use what they receive for their own advertising.
That is sharing, even though Kuji shows you no adverts, because both use what they receive for their own purposes and not only ours.
The providers in 3.1, 3.2 and 3.3 are a different matter: they act on our instructions and for our purposes only, and nothing there is shared in that sense.
The switch is the control, and it starts off. Advertising measurement is off when you install Kuji, so no sharing happens until you turn it on, and none of it begins before you have chosen. To stop it again afterwards: app menu → Sharing, then turn Advertising measurement off. It needs no account. It takes effect immediately, and you can change it as often as you like.
We also honour any opt-out signal your platform sends us. Android sends no Global Privacy Control signal, which is a browser signal, but it does have a system advertising opt-out, and Kuji acts on that. Reset or limit your advertising ID in your device settings, or opt out of ads personalisation there, and we stop using the identifier and do not run the partner software that reads it, whatever the switch in the app says. The two are not equivalent: that covers everything built on the identifier, and 3.5 never uses it, so the switch in the app is what stops advertising measurement itself. The privacy policy sets out your choices over this in full.
4. Things that happen without asking you, and why
These are not covered by the switches in section 2, because they are not optional extras.
4.1 Google Play Billing: the Kuji Unsealed purchase
| Provider | Google Ireland Limited, as the store |
| When it becomes active | Only when you actively choose to buy Kuji Unsealed, or when the app checks whether you already own it |
| Why it isn't behind a switch | It is how the thing you asked for gets done, so it is necessary to perform our contract with you rather than something you opt into. You cannot buy something without the shop being involved, and there is no version of the purchase that works without it |
| What is sent | Your request to buy, the identifier of the product being bought (kuji_pro), and, once a purchase completes, the receipt token sent back to the store to confirm it. We never see your card, your payment details, or your billing address. The store handles the payment |
| What comes back | Confirmation that the purchase succeeded, and a receipt token |
| What is stored | A simple yes/no "the unlock is active" flag on your device. The receipt token is sent back to the store to confirm the purchase, which is what stops the store cancelling it. The token itself never reaches us. A copy of it is kept on your device only if Usage data is on, and once kept it stays until you clear the app's data or uninstall Kuji: turning Usage data off stops another copy being kept, but does not remove the one already there. Its only job there is to stop the same unlock being counted twice: with Usage data on, we are told that an unlock happened, once, and nothing about who or what was bought beyond the product. With Usage data off we are told nothing at all. The token is excluded from your device's backup, so it does not travel to a new device |
| The store's role | Independent controller. The store sells to you in its own right and keeps its own commerce records under its own terms, which we do not control |
| Their privacy information | support.google.com/googleplay/answer/2479637 |
4.2 Your device's own cloud backup
| Provider | Your device platform, under your account |
| When it becomes active | If backup is switched on in your device settings, a setting that belongs to you, not to Kuji |
| Why it isn't behind a switch | It is not our transfer. Your device backs up app settings to your account; Kuji is not the one sending it |
| What is included | Kuji's settings file, which contains your saved lists of names |
| What is excluded | Your pick history. It is kept in a separate file on your phone that the backup does not copy. And the purchase receipt token (4.1) |
| What we can do about it | Nothing. We cannot read it, retrieve it or delete it. You control it entirely through your device's backup settings |
This is the only route by which the names you type can leave the device, and the backup in the table above is the whole of it, and nothing in Kuji passes your names to another app. It is stated the same way in the privacy policy. If you would rather it did not happen, turn off backup for Kuji in your device settings.
5. Components that send nothing, listed for completeness
None of these transmits anything off your device. They are listed so the app's full component inventory can be reconciled against this notice. The list is read from the components resolved into the built release app, not from a source file.
| Component | What it does |
|---|---|
| Compose Runtime, Foundation, UI, Animation, Material 3 | Draw the interface and animate it |
| Compose Components, Resources | Loads images, fonts and text bundled inside the app |
| Compose Preview / UI Tooling Preview | Renders previews while we develop; no runtime effect for you |
| AndroidX Activity Compose | Connects the interface to the Android screen lifecycle |
| AndroidX Core SplashScreen | Draws the launch screen |
| AndroidX ProfileInstaller | Installs a performance profile so the app starts faster |
| AndroidX Fragment | A screen-support library other Google components rely on. Kuji uses none of it directly; a current version is included so the finished app does not carry an outdated copy |
| Google Advertising ID helper | Reads your device's own advertising opt-out setting so Kuji can honour it. It reads that setting and nothing else, and it is the reason the opt-out is respected rather than a way of tracking you |
Permissions, for the same reason. Kuji itself declares three: internet access, vibration for haptic feedback, and the advertising ID permission used by Advertising measurement. Five more are added to the finished app by the components in section 3, because Android merges a component's permissions into the app that includes it.
| Permission | Why it is there |
|---|---|
| Internet access | Declared by Kuji. Needed for everything in section 3 and for the store check in 4.1 |
| Vibration | Declared by Kuji. Haptic feedback |
| Advertising ID | Declared by Kuji. Used only by Advertising measurement |
| Network state | Added by the analytics component, to see whether the device is online before it tries to send |
| Wake lock | Added by the analytics component, to finish sending before the device sleeps |
| Billing | Added by the Play Billing component (4.1), so the app can talk to the store |
| Install referrer | Added by the analytics component, so the store can tell it which advert led to the install |
| A private receiver permission | Added by an Android support library. It can be held by nothing except Kuji itself, and grants no access to anything on your device |
None of these is a permission Android asks you to approve, and none reaches your personal files or sensors. Kuji has no access to your contacts, photos, files, microphone, camera, calendar or location.
The advertising ID permission is declared because advertising measurement needs it.
Your device settings let you reset or limit that identifier at any time. That applies to every app, not just Kuji.
Four advertising permissions are deliberately removed. The advertising components would otherwise add Android's Privacy Sandbox permissions for advertising ID, attribution, topics and custom audiences. Kuji strips all four, and they are absent from the built app.
6. Your choices, and how to act on them
| What you want to do | How |
|---|---|
| See or change what you have agreed to | Open the app menu → Sharing. The switches are there, and any of them can be turned off at any time |
| Stop usage analytics | Turn off Usage data; see section 2. Collection stops immediately for both providers in 3.1 and 3.2. On your device, cached data is cleared and your installation identifier is replaced for each of them — for 3.2 the component's own stored files and pending queue are deleted outright, because an identifier left behind would still tie this installation to everything it had sent. Data a provider already received is not deleted on the spot; it ages out over the periods in section 3 |
| Stop crash reports | Turn off Crash reports. Collection stops immediately, and reports not yet sent are deleted |
| Stop advertising measurement | Turn off Advertising measurement. Collection stops immediately, and this is how you stop the sharing described in 3.4 and 3.5. What our partners already received is held under their own terms; see 3.4 and 3.5. You can also reset or limit your advertising identifier in your device settings, which applies to every app, not just Kuji |
| Remove your saved lists or a person in one | App menu → Manage lists… → delete. That row is there whichever way Source is set. It goes immediately; deleting a whole list, or removing one person from it, each give you five seconds to undo |
| Clear your pick history | App menu → The record → CLEAR (a two-step confirm) |
| Keep your names out of your cloud backup | Turn off backup for Kuji in your device settings; we cannot do this for you (see section 4) |
| Remove everything on the device | Clear Kuji's data in your device settings, or uninstall the app |
| Ask about data a provider already holds | Email us; see section 7. We hold no copy, and nothing links you to an installation, so we cannot delete a provider's records for you. What we can do is tell you what applies and point you to each provider's own route (see 3.4 and 3.5) |
Resetting your settings does not switch collection back on.
7. Updates to this notice, and how to reach us
This notice is updated whenever an SDK is added, removed, or materially changed. It is also updated whenever a retention period changes, and whenever the consent arrangement itself changes: a new category, a changed default, or a changed way of withdrawing.
The Last updated date at the top of this notice changes whenever the notice does. Where a change means we are collecting something new, you are asked again rather than carried over (see section 2).
This notice, the Kuji Privacy Policy and our internal record of processing are updated together, in the same change, before the new version of the app is released.
Contact us:
Email: privacy@tacitlabs.co.uk
Post: Tacit Labs Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ
We aim to acknowledge within 5 working days, and to reply in full within one calendar month.