Privacy Policy

Effective Date: January 30, 2026

askitmore co., ltd ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Kuku and our related services.

1. Information We Collect

1.1 Information You Provide

Account Information

  • — Email address
  • — Name (optional)
  • — Password (hashed, never stored in plain text)

Payment Information

  • — Payment details are collected and processed by Polar.sh ("Polar"), our Merchant of Record
  • — We do not directly collect or store your credit card numbers or banking information
  • — We receive transaction records (purchase date, amount, subscription status) from Polar

Support Communications

  • — Messages you send to our support team
  • — Feedback and survey responses

1.2 Information Collected Automatically

Usage Data

  • — Feature usage statistics (anonymized)
  • — Error logs and crash reports
  • — App version and operating system

Device Information

  • — Device type and model
  • — macOS version
  • — Unique device identifiers (for licensing purposes only)

1.3 Information We Do NOT Collect

Your Documents

  • — We do NOT collect, access, or store your local markdown files
  • — Your documents remain entirely on your device
  • — We cannot read or recover your local files

2. How We Use Your Information

We use collected information to:

PurposeData Used
Provide and maintain the ServiceAccount info, usage data
Process payments and subscriptionsTransaction records from Polar
Send service-related communicationsEmail address
Improve the ServiceAnonymized usage statistics
Respond to support requestsContact info, communications
Detect and prevent fraudAccount info, device info
Comply with legal obligationsAs required by law

3. Third-Party Services

3.1 Payment Processing (Polar)

We use Polar.sh as our Merchant of Record for payment processing.

What Polar Collects:

  • — Payment method details (credit card, etc.)
  • — Billing address
  • — Transaction history

Important:

  • — When you make a purchase, you are transacting with Polar, not directly with us
  • — Polar is responsible for PCI compliance and payment security
  • — Polar handles all sales tax, VAT, and invoicing
  • — Your payment data is governed by Polar's Privacy Policy
  • — We only receive transaction summaries, not your full payment details

3.2 AI Services (Google Gemini)

When you use AI features:

  • — Your prompts and selected document content are sent to Google's Gemini API
  • — This data is processed according to Google's Privacy Policy
  • — Google's API terms state that API data is not used for model training
  • — We do not control how Google processes this data

What is sent to AI:

  • — Your chat messages
  • — Document content you explicitly include in context
  • — File names of referenced documents

What is NOT sent:

  • — Your entire vault
  • — Documents you haven't referenced
  • — Your local file system information

3.3 Analytics (Website Only)

We use Mixpanel to collect anonymized analytics data on our website (kuku.mom) to understand usage patterns and improve our services.

What We Collect:

  • — Page views and navigation patterns
  • — Button clicks and feature usage
  • — Browser type and device information (anonymized)

Important:

  • — Analytics data is anonymized and aggregated
  • — We do NOT collect personal identifiers through analytics
  • The Kuku desktop application does NOT collect any analytics data
  • — Your editing activity and document content are never tracked

3.4 Speech-to-Text (Whisper)

Voice transcription is processed entirely locally on your device using Whisper. Audio data is never sent to external servers.

4. Data Storage and Security

4.1 Local Data

Your markdown files and vault data are stored locally on your device. We recommend:

  • — Regular backups of your vault folder
  • — Using encrypted storage if handling sensitive information
  • — Securing your device with a password

4.2 Cloud Data

Account information and usage data are stored on secure servers with:

  • — Encryption at rest and in transit (TLS 1.3)
  • — Regular security audits
  • — Access controls and monitoring

4.3 Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Payment/transaction records7 years (legal requirement)
Usage statistics2 years (anonymized)
Support communications3 years
Error logs90 days

5. Data Sharing

We do not sell your personal information. We may share information only in these circumstances:

RecipientPurposeData Shared
PolarPayment processingTransaction data
Google (Gemini)AI featuresContent you send to AI
Service providersInfrastructureAnonymized usage data
Legal authoritiesLegal complianceAs required by law

6. Your Rights and Choices

6.1 Access and Portability

You have the right to:

  • — Access your account information
  • — Download your data in a portable format
  • — Request a copy of data we hold about you

6.2 Correction

You can update or correct your account information at any time through the dashboard.

6.3 Deletion

You can request deletion of your account and associated data. Upon request:

  • — Account data will be deleted within 30 days
  • — Some data may be retained for legal compliance
  • — Local files on your device are not affected
  • — Payment records held by Polar are subject to their retention policies

6.4 Opt-Out Options

You can opt out of:

  • — Marketing communications (unsubscribe link in emails)
  • — Analytics collection (in app settings)
  • — AI features (don't provide API key)

6.5 Do Not Track

We respect Do Not Track browser signals where applicable.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including:

  • — United States (Polar, Google Gemini, infrastructure providers)

We ensure appropriate safeguards are in place, including:

  • — Standard contractual clauses
  • — Compliance with applicable data protection laws

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we discover such collection, we will delete the information promptly.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • — Know what personal information we collect
  • — Request deletion of your personal information
  • — Opt out of the sale of personal information (we do not sell your data)
  • — Non-discrimination for exercising your rights

To exercise these rights, contact us at privacy@kuku.mom.

10. European Privacy Rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • — Access your personal data
  • — Rectify inaccurate data
  • — Erase your data ("right to be forgotten")
  • — Restrict processing
  • — Data portability
  • — Object to processing
  • — Withdraw consent
  • — Lodge a complaint with a supervisory authority

Legal Basis for Processing:

  • — Contract performance (providing the Service)
  • — Legitimate interests (improving the Service, security)
  • — Consent (marketing communications)
  • — Legal obligations (tax and accounting)

Data Controller: askitmore co., ltd

Payment Data Controller: Polar.sh (as Merchant of Record)

11. Korean Privacy Rights (PIPA)

If you are in the Republic of Korea, you have rights under the Personal Information Protection Act (PIPA), including:

  • — Access to your personal information
  • — Correction of inaccurate information
  • — Deletion of your information
  • — Suspension of processing

Personal Information Protection Officer:

Email: privacy@kuku.mom

12. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • — Notify affected users within 72 hours
  • — Notify relevant supervisory authorities as required
  • — Take immediate steps to mitigate the breach

13. Third-Party Links

The Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Material changes will be notified via email or in-app notification.

15. Contact Us

For privacy-related questions, concerns, or requests:

General Inquiries: privacy@kuku.mom

Support: support@kuku.mom

Company:

askitmore co., ltd

Seoul, Republic of Korea

Payment-Related Privacy Inquiries:

For questions about payment data, you may also contact Polar directly at support@polar.sh or visit Polar's Privacy Policy.

16. Summary

What We CollectWhat We Don't Collect
Account info (email, name)Your local documents
Transaction records (from Polar)Full payment card details
Usage statistics (anonymized)Browsing history
Crash reportsLocation data
Support messagesContacts

Key Points:

  • — Your files stay on your device
  • — AI features send only what you explicitly share
  • — Voice transcription is 100% local
  • — Payments are handled by Polar (Merchant of Record)
  • — We don't sell your data
  • — You can delete your account anytime

17. Security Vulnerability Reporting

If you discover a security vulnerability that may affect user data or privacy, we encourage responsible disclosure. Please report security issues to security@kuku.mom.

For our complete security policy, including what to report and our responsible disclosure guidelines, please visit our Security Policy page.

Last updated: January 30, 2026