Privacy Policy
Effective Date: January 30, 2026
askitmore co., ltd ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Kuku and our related services.
1. Information We Collect
1.1 Information You Provide
Account Information
- — Email address
- — Name (optional)
- — Password (hashed, never stored in plain text)
Payment Information
- — Payment details are collected and processed by Polar.sh ("Polar"), our Merchant of Record
- — We do not directly collect or store your credit card numbers or banking information
- — We receive transaction records (purchase date, amount, subscription status) from Polar
Support Communications
- — Messages you send to our support team
- — Feedback and survey responses
1.2 Information Collected Automatically
Usage Data
- — Feature usage statistics (anonymized)
- — Error logs and crash reports
- — App version and operating system
Device Information
- — Device type and model
- — macOS version
- — Unique device identifiers (for licensing purposes only)
1.3 Information We Do NOT Collect
Your Documents
- — We do NOT collect, access, or store your local markdown files
- — Your documents remain entirely on your device
- — We cannot read or recover your local files
2. How We Use Your Information
We use collected information to:
| Purpose | Data Used |
|---|---|
| Provide and maintain the Service | Account info, usage data |
| Process payments and subscriptions | Transaction records from Polar |
| Send service-related communications | Email address |
| Improve the Service | Anonymized usage statistics |
| Respond to support requests | Contact info, communications |
| Detect and prevent fraud | Account info, device info |
| Comply with legal obligations | As required by law |
3. Third-Party Services
3.1 Payment Processing (Polar)
We use Polar.sh as our Merchant of Record for payment processing.
What Polar Collects:
- — Payment method details (credit card, etc.)
- — Billing address
- — Transaction history
Important:
- — When you make a purchase, you are transacting with Polar, not directly with us
- — Polar is responsible for PCI compliance and payment security
- — Polar handles all sales tax, VAT, and invoicing
- — Your payment data is governed by Polar's Privacy Policy
- — We only receive transaction summaries, not your full payment details
3.2 AI Services (Google Gemini)
When you use AI features:
- — Your prompts and selected document content are sent to Google's Gemini API
- — This data is processed according to Google's Privacy Policy
- — Google's API terms state that API data is not used for model training
- — We do not control how Google processes this data
What is sent to AI:
- — Your chat messages
- — Document content you explicitly include in context
- — File names of referenced documents
What is NOT sent:
- — Your entire vault
- — Documents you haven't referenced
- — Your local file system information
3.3 Analytics (Website Only)
We use Mixpanel to collect anonymized analytics data on our website (kuku.mom) to understand usage patterns and improve our services.
What We Collect:
- — Page views and navigation patterns
- — Button clicks and feature usage
- — Browser type and device information (anonymized)
Important:
- — Analytics data is anonymized and aggregated
- — We do NOT collect personal identifiers through analytics
- — The Kuku desktop application does NOT collect any analytics data
- — Your editing activity and document content are never tracked
3.4 Speech-to-Text (Whisper)
Voice transcription is processed entirely locally on your device using Whisper. Audio data is never sent to external servers.
4. Data Storage and Security
4.1 Local Data
Your markdown files and vault data are stored locally on your device. We recommend:
- — Regular backups of your vault folder
- — Using encrypted storage if handling sensitive information
- — Securing your device with a password
4.2 Cloud Data
Account information and usage data are stored on secure servers with:
- — Encryption at rest and in transit (TLS 1.3)
- — Regular security audits
- — Access controls and monitoring
4.3 Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Payment/transaction records | 7 years (legal requirement) |
| Usage statistics | 2 years (anonymized) |
| Support communications | 3 years |
| Error logs | 90 days |
5. Data Sharing
We do not sell your personal information. We may share information only in these circumstances:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Polar | Payment processing | Transaction data |
| Google (Gemini) | AI features | Content you send to AI |
| Service providers | Infrastructure | Anonymized usage data |
| Legal authorities | Legal compliance | As required by law |
6. Your Rights and Choices
6.1 Access and Portability
You have the right to:
- — Access your account information
- — Download your data in a portable format
- — Request a copy of data we hold about you
6.2 Correction
You can update or correct your account information at any time through the dashboard.
6.3 Deletion
You can request deletion of your account and associated data. Upon request:
- — Account data will be deleted within 30 days
- — Some data may be retained for legal compliance
- — Local files on your device are not affected
- — Payment records held by Polar are subject to their retention policies
6.4 Opt-Out Options
You can opt out of:
- — Marketing communications (unsubscribe link in emails)
- — Analytics collection (in app settings)
- — AI features (don't provide API key)
6.5 Do Not Track
We respect Do Not Track browser signals where applicable.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including:
- — United States (Polar, Google Gemini, infrastructure providers)
We ensure appropriate safeguards are in place, including:
- — Standard contractual clauses
- — Compliance with applicable data protection laws
8. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we discover such collection, we will delete the information promptly.
9. California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- — Know what personal information we collect
- — Request deletion of your personal information
- — Opt out of the sale of personal information (we do not sell your data)
- — Non-discrimination for exercising your rights
To exercise these rights, contact us at privacy@kuku.mom.
10. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- — Access your personal data
- — Rectify inaccurate data
- — Erase your data ("right to be forgotten")
- — Restrict processing
- — Data portability
- — Object to processing
- — Withdraw consent
- — Lodge a complaint with a supervisory authority
Legal Basis for Processing:
- — Contract performance (providing the Service)
- — Legitimate interests (improving the Service, security)
- — Consent (marketing communications)
- — Legal obligations (tax and accounting)
Data Controller: askitmore co., ltd
Payment Data Controller: Polar.sh (as Merchant of Record)
11. Korean Privacy Rights (PIPA)
If you are in the Republic of Korea, you have rights under the Personal Information Protection Act (PIPA), including:
- — Access to your personal information
- — Correction of inaccurate information
- — Deletion of your information
- — Suspension of processing
Personal Information Protection Officer:
Email: privacy@kuku.mom
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- — Notify affected users within 72 hours
- — Notify relevant supervisory authorities as required
- — Take immediate steps to mitigate the breach
13. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Material changes will be notified via email or in-app notification.
15. Contact Us
For privacy-related questions, concerns, or requests:
General Inquiries: privacy@kuku.mom
Support: support@kuku.mom
Company:
askitmore co., ltd
Seoul, Republic of Korea
Payment-Related Privacy Inquiries:
For questions about payment data, you may also contact Polar directly at support@polar.sh or visit Polar's Privacy Policy.
16. Summary
| What We Collect | What We Don't Collect |
|---|---|
| Account info (email, name) | Your local documents |
| Transaction records (from Polar) | Full payment card details |
| Usage statistics (anonymized) | Browsing history |
| Crash reports | Location data |
| Support messages | Contacts |
Key Points:
- — Your files stay on your device
- — AI features send only what you explicitly share
- — Voice transcription is 100% local
- — Payments are handled by Polar (Merchant of Record)
- — We don't sell your data
- — You can delete your account anytime
17. Security Vulnerability Reporting
If you discover a security vulnerability that may affect user data or privacy, we encourage responsible disclosure. Please report security issues to security@kuku.mom.
For our complete security policy, including what to report and our responsible disclosure guidelines, please visit our Security Policy page.
Last updated: January 30, 2026