← Back to Kuji

1. Background

Kuji is made by Tacit Labs Ltd. We are a company registered in England and Wales, number 17110976. Our office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.

In this policy, "we", "us" and "our" mean Tacit Labs Ltd. We are the business responsible for the personal information described here.

We care about your privacy. Kuji is built to need as little of your information as possible. This policy explains what personal information is involved when you use Kuji, what we do and do not receive, and what choices you have.

Some words we use: "Kuji" or "the app" means the Kuji application and everything shipped inside it. "Personal information" means information that identifies, relates to or could reasonably be linked with you. "Your device" means the phone or tablet you installed Kuji on. Where this policy says something happens "on your device", it means the information stays in Kuji's private storage on that device, and we cannot see it.

Our Cookie & SDK Notice goes with this policy. It describes the individual components inside the app one by one: what each sends, and what it never sends.

This version applies if you are outside the United Kingdom and outside the European Economic Area. If you are in either of those, the UK and EEA version of this policy applies to you instead.

2. The app we provide

Kuji is a fair picker. You put fingers on the screen, or type a list of names, and Kuji chooses a winner, splits teams, or settles an order at random.

There is no account and no sign-up. You do not give us your name, your email address or any other contact details to use Kuji.

Kuji has no server of its own. Everything you do in the app happens on your device.

Kuji is free to use. There is one optional purchase, Kuji Unsealed, which opens up extra options. Picking itself is never locked behind payment.

3. The categories of information Kuji handles

On your device only

What What it holds
The lists you save The list name and the names of the people in it, together with any weighting or "keep these two apart" settings. These names are personal information about the people you have named, who may be other people rather than you
Your recent results A short history of recent picks. Without the paid unlock the app shows you fewer of them; the rest stay on your device until newer picks push them out, and clearing the history removes them all. Where you picked from a list, the record includes the names of winners or teams, and the time of the pick
Your settings Appearance, sound and haptic settings, the picker options you last used, whether the calmer reduced-motion presentation is on, and whether you have bought the paid unlock
Your privacy choices How each of the three optional settings is set — Usage data, Crash reports and Advertising measurement — and which version of our privacy prompt you last saw

All of the above stays in Kuji's private storage on your device. We have no access to it. We cannot read it, copy it or recover it.

Information we receive from the app

Kuji can send us usage information, crash reports, and advertising measurement information. These are the three settings labelled "Usage data", "Crash reports" and "Advertising measurement", both where Kuji asks you before collecting anything and in the app menu afterwards, under Sharing.

This information carries no name and nothing you have typed, but it does include an identifier for your installation, so it identifies the installation rather than you.

All three are switched off when you install the app, and Kuji asks you shortly after it first opens. Nothing in this section is collected before you answer that question, and nothing is collected if you decline. This is the same wherever you are: Kuji does not work out what country you are in, and does not vary what it asks or what it collects by country.

Each is separate: turning one on does not turn on another. Section 4 explains what each contains.

Your device's own backup

Your device's operating system may include Kuji's on-device data in the backup it creates in your own cloud storage account. That covers your saved lists and your settings. Your recent results are not included: they are kept in a separate place on the phone that the backup does not copy. This is done by your device, not by Kuji.

That backup belongs to you, and is governed by your own platform account and its terms. We have no access to it, and we cannot delete it for you. You control it through your device's backup settings.

4. How we use information

The lists and personal names you put into Kuji stay on your device, and we do not receive them.

While any of the optional settings below is on, we do receive some information about how the app is used. That includes the shape of a pick and which settings you have changed. Each heading sets out what its setting covers.

Usage analytics

You choose whether this is on, and nothing is collected unless you turn it on.

While it is on, we receive a small, fixed set of labels and counts: which features get used, how many people took part in a pick, how many winners or teams it produced, and which settings you have moved away from their default. The Cookie & SDK Notice lists exactly what is sent.

We use it to decide what to build next — in Kuji, and in other apps we make, including ones we have not released yet. The approximate location described below serves a further purpose: understanding how Kuji is performing area by area. It is a count per area, never an examination of any individual; it does not change what any user is shown, and it is not used to target advertising or shared with any advertiser.

It does not include the names on your lists, who or what won, or anything you have typed.

The analytics services also collect some information of their own: an identifier for your installation, session and return-visit information, your app version, device model and operating system, and your device's internet (IP) address, which they use to work out an approximate location. That location is derived down to a city and a postcode area — a partial or full postal code depending on the country, and in the UK the outward code only, such as SE8 — along with the coordinates of that city's centre. Kuji asks for no location permission and reads no location API, and neither provider stores the address itself.

Two further labels are attached: whether you have bought the paid unlock, and which build of the app you are running. We use them to tell whether a problem or a pattern affects one group more than another.

Crash reports

You choose whether this is on, and nothing is collected unless you turn it on. While it is on, when Kuji crashes we receive the sequence of code that failed, your device model, operating-system version, app version, and an identifier for your installation. It contains nothing you typed.

Advertising measurement

You choose whether this is on, and nothing is collected unless you turn it on. While it is on, we can tell that you installed Kuji after seeing one of our adverts, and whether you later bought the paid unlock. An advertising partner tells us that much: for example, that an install came from a particular campaign.

This works using an advertising identifier your phone provides, plus information about the advert you tapped. The Cookie & SDK Notice lists exactly what each partner receives.

It does not include the names on your lists or what Kuji picked.

Our advertising partners use what they receive for their own purposes as well as ours, so their own privacy policies apply to it. The Cookie & SDK Notice names every partner we currently work with, and links to each one's policy.

Your phone's own settings let you reset or limit your advertising identifier, and Kuji treats that as an instruction in its own right: if your phone reports you have opted out of ads personalisation, we stop using the identifier and the partner software that reads it does not run, even if the switch above is still on. The other half of advertising measurement never uses that identifier, so a phone-level opt-out does not reach it — the switch above is what stops that.

This is sharing for cross-context behavioural advertising: our advertising partners, who are named in the Cookie & SDK Notice, use what they receive for their own advertising purposes, not only ours. Section 10 sets out how to stop it.

Purchases

If you buy Kuji Unsealed, the purchase is handled by the app store, not by us. We never see your payment card, bank details or billing address.

Kuji asks the store whether the unlock has been bought on your account. It asks each time it starts and each time you return, for everyone, including people who have never bought anything. Section 7 sets out what that check carries.

Kuji records on your device that the unlock is active. Your purchase also has a store reference, which Kuji sends back to confirm the purchase went through; that is what stops the store cancelling it, and the exchange is between your device and the store. While Usage data is on, Kuji keeps a copy of that reference. Once kept, the copy stays until you clear the app's data or uninstall Kuji. Turning Usage data off later stops another copy being kept but does not remove the one already there, and your device's backup does not copy it.

While Advertising measurement is on, our advertising partners are also told that a purchase happened (see that setting above). They are never told your payment details, because we never have them.

Advertising

Kuji contains no adverts. No advertising software displays anything to you inside Kuji. With Advertising measurement on, we measure which advert brought you to Kuji; we do not show you adverts inside it.

5. Why we are allowed to use your information

Kuji is used in many countries, and the law that applies to you is the law of the place you are in. This policy does not set out a separate answer for each one. The table below gives the basis for each thing we do, in the terms most data protection laws use; where your own law recognises these categories, these are the ones we rely on.

What we do Legal basis Why
Usage analytics Your consent It happens only because you turned Usage data on, and stops when you turn it off
Crash reports Your consent Same: Crash reports is off until you switch it on
Advertising measurement Your consent Same. This is also the switch that controls the sharing described in section 3.7 of the Cookie & SDK Notice
Checking whether you have bought the paid unlock Performance of our contract with you It is how we give you the version of the app you are entitled to. Not optional, and not covered by the settings above — see below and section 7
Keeping a record of the privacy choices you made Our legal obligation We have to be able to show you were asked and what you answered

The answer is your consent. Kuji asks before anything in section 3 is collected, and the three optional settings stay off until you say yes. We ask everyone, wherever they are, whether or not the law of their country requires it.

You can withdraw your consent at any time in the app menu, under Sharing. It takes effect immediately, and it is as easy to turn off as it was to turn on. When you withdraw it, collection stops, and what happens to information already on your device differs by setting:

What a provider has already received is not deleted on the spot. It is held for the period in section 9.

There is no other way we collect any of it. While a setting is off, the component behind it does not run at all.

Your purchase, and the app itself: performing our contract with you. Kuji asks the store whether the paid unlock has been bought on your account. It asks for everyone, every time it starts, including people who have never bought anything; that is how the unlock restores on a new phone without you proving anything. Installing Kuji means accepting our terms, and this check is how we give you the version of the app you are entitled to, whether that is the free one or the paid one. It is not one of the optional settings and it is not covered by them (see section 7).

We do not profile you, and we do not make automated decisions about you. Our advertising partners do build advertising profiles. While Advertising measurement is on, what they receive feeds those profiles, under their own policies (see sections 4 and 6).

6. Who else sees your information

Kuji has no sharing feature, no sync, no upload and no backend. We do not hold your lists or your results, so there is no way for another person or company to obtain them from us.

While usage analytics or crash reports are on, that information is processed on our behalf by our providers, which supply those services under contract and act on our instructions. The Cookie & SDK Notice names each of them.

Our advertising partners are in a different position. While Advertising measurement is on, what they receive is used for their own purposes as well as ours. Each is responsible for it in their own right, alongside us, rather than simply acting on our instructions. The Cookie & SDK Notice names every partner, sets out what each one receives and what it never receives, how long it keeps it, and links to each one's policy.

With one of those partners, Meta, the first step is shared. Collecting this information on your device and sending it to Meta is a step we and Meta decide on together, so for that step the two of us are jointly responsible, and you can raise a question or make a request about it with either of us. What Meta does with the information afterwards is Meta's own decision, taken for Meta's own purposes. We and Meta have an agreement that sets out which of us answers for what.

If you buy Kuji Unsealed, the transaction is handled by the app store operator, which acts in its own right as the seller of record.

We do not sell your information, and no data broker receives anything from Kuji. The advertising partners above are the only recipients who use anything for their own purposes, and only while that setting is on.

Your own cloud backup can carry the names you type off your device, and it is described in section 3.

We may disclose information where we are legally required to do so, or to establish or defend legal claims.

7. Sending information across borders

We work from the United Kingdom. If you use Kuji elsewhere, the limited information described in section 4 is handled in the UK and by our providers abroad. That only happens while the setting it belongs to is on.

Where it is stored and processed depends on the provider: one stores it in the European Union, the others in the United States. All of them are, or answer to, United States companies, so in each case the information crosses a border, and storing it in Europe does not stop a US company reaching it. The Cookie & SDK Notice records the position for each one.

Those are the places we know it goes, and not the limit of what our agreements allow. For at least one provider the agreement permits processing in any country where it or its own suppliers operate facilities, rather than naming a list we could hold it to.

Where information crosses a border, we rely on the safeguards the law requires for that destination. For most of our providers that is a set of standard contractual terms built into our contract with them. If you would like to see a copy of the safeguards that apply, contact us using the details in section 12.

If you leave the optional settings switched off, we receive no information about how you use Kuji, and nothing you have typed reaches us.

One exception is not covered by any switch. Kuji checks with the Google Play Store whether the paid unlock has been bought on your Google account. It does this when it starts, and when you return to it.

That check happens for everyone, including people who have never bought anything and never turned any setting on. It is how the app knows to restore your unlock on a new phone without asking you to prove a purchase.

It carries no names, no lists, no results and nothing you have typed. It asks the store what your account owns, nothing more. The exchange is between your device and Google Play under your own store account, and we do not receive it.

8. How we safeguard your information

Most of what Kuji holds never leaves your device. Your lists, the names in them and your results stay there, unless your own device backup includes them.

Information on your device is held in Kuji's private storage, which other apps cannot read.

Where you have turned an optional setting on, the information is encrypted while it travels to the provider.

The components behind those options are started only while the matching setting is on, and every setting is off until you turn it on (see section 3). The one thing that runs regardless is the store entitlement check in section 7, which never reaches us.

No system can be guaranteed completely secure. We aim to hold as little of your personal information as possible.

9. How long information is kept

What Kept for
Your saved lists Until you delete them, or clear the app's data. No time limit, and nothing is deleted automatically
Your recent results Until newer picks push them out of the history, or you clear the history in the app
Your settings and privacy choices Until you clear the app's data or uninstall Kuji
Usage analytics, if turned on A period set with each provider, recorded per provider in the Cookie & SDK Notice
Crash reports, if turned on As above, per provider, in the same notice
Advertising measurement, if turned on A period set by each partner under its own terms, not by us. The same notice records what each says
Your device's backup As long as your platform provider keeps it. We cannot delete it; you control it in your device's backup settings

Two notes on the table.

On lists. On the free tier you can keep up to three. With the paid unlock there is no limit on how many you keep. Kuji nudges you to keep each list to about ten names, but that is a nudge about how the app looks, not a limit on what your device keeps, and a list saved before that nudge existed keeps everyone already in it.

On your privacy choices. They are deliberately kept when you use "reset to defaults", so resetting never silently turns collection back on.

Removing Kuji, or clearing its data in your device's settings, removes everything Kuji has stored on that device.

10. Your choices

Because your lists, results and settings are held only on your device, the fastest route is inside the app:

Your phone's own settings also let you reset or limit your advertising identifier at any time, for every app at once, and Kuji honours that: once your phone reports you have opted out of ads personalisation, we stop using the identifier whatever the switch in the app says. Turning the switch off is what stops advertising measurement itself.

You can also ask us for a copy of any personal information we hold about you. You can ask us to correct it, delete it, or stop using it. Contact us using the details in section 12.

We aim to acknowledge within 5 working days, and we will reply within one calendar month. If your request is complex, or you have made several, we may need up to two further months. We will tell you inside the first month if we need longer, and why.

We cannot delete your device's own cloud backup. It sits in your platform account and we have no access to it. You remove that through your device's backup settings.

Kuji has no accounts, so we usually have no way to link a request to one person's information. If you write to us, we may need to ask what exactly you mean, so we can help.

If you are unhappy with how we have handled your personal information, we would appreciate the chance to put it right first. Depending on where you live, you may also have the right to complain to your local data protection authority. We are based in the United Kingdom, so you can complain to the Information Commissioner's Office as well, at ico.org.uk/make-a-complaint.

11. Children

Kuji is intended for people aged 13 and over, and is not directed at children. It is used in classrooms and families, and these protections apply to everyone using it:

Advertising measurement is never bundled with another choice, and it sends no name, no result and nothing anyone has typed. It is off until somebody turns it on, so turning it on is the deliberate act, and that is a decision for an adult to make. Section 6 sets out who receives it and what they do with it.

Kuji is not for children under 13, and we do not knowingly collect personal information from a child under 13. If you are a parent or guardian and believe a child under 13 has used Kuji in a way that sent us information, contact us. We will act to resolve what is reasonably possible. What is held on the device can be cleared there; what a provider already holds is deleted on the periods in section 9.

If you are under 18, please talk to a parent or guardian about the optional settings, including turning off any you would rather were not on. Kuji works fully without them.

We do not sell personal information, and we do not knowingly share the personal information of anyone under 16 for cross-context behavioural advertising.

A note for teachers and group organisers. If you type other people's names into a saved list, those names are personal information about them, not about you.

They stay on your device and we never see them. But they may be included in your device's own backup (see Your device's own backup in section 3).

12. Contact

If you have a question about this policy, or about how your personal information is handled, contact us:

Tacit Labs Ltd 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom privacy@tacitlabs.co.uk

13. Changes to this policy

We may update this policy when our practices change, when the technologies the app relies on change, or when the law that applies to us changes. The "last updated" date at the top always reflects the most recent version.

If we make a material change, for example if we begin collecting something new or use information for a new purpose, we will tell you in advance. That will be through a notice in the app, and where relevant through the app store listing, before the change takes effect.

A material change to what we collect, or to what we use it for, means we ask for your privacy choices again, rather than carrying an old answer forward onto something you did not agree to.

If you would rather not accept an updated policy, you can withdraw your consent at any time in the app's menu, or remove the app.