Privacy policy
This policy explains what personal data KUMODeck collects, why, who it goes to, and how long it is kept. KUMODeck is operated by the KUMODeck operator ("we"). Questions and requests: [email protected].
Effective date: 2026-10-02
Who this covers#
- Creators: people who sign up for KUMODeck to build and host their apps. We decide how this data is used.
- Users of creators' apps: people who use an app or game built on KUMODeck. The creator decides what their app collects and is responsible for it; we store and process that data on the creator's behalf and only to run the service for them. See "Data in creators' apps" below.
What we collect from creators#
| Data | Where it comes from | Why |
|---|---|---|
| Email address, display name, password (stored only as a one-way hash) | You, when you sign up | Your account and sign-in |
| Email address, name and account ID from Google or GitHub | The provider, if you sign in with it | Sign-in. We do not keep your profile picture |
| Passkey public key and label | Your device, if you add a passkey | Sign-in |
| Sign-in sessions (stored as a hash, 30 days) | Created when you sign in | Keeping you signed in |
| Projects, deployed files, settings and a record of account actions | You and your AI agent or CLI | Running your projects; security and support |
| Usage amounts per project and day | Measured by the service | Usage fees |
| Prepaid balance, top-ups, invite credit, and the Stripe IDs of a saved card | You and Stripe | Billing. Card numbers go directly to Stripe and never reach us |
| Request logs: IP address, browser user agent, the page or API called, time | Your browser, CLI or AI agent | Security, abuse prevention and fixing errors |
We use your email only for messages about your account and service: email verification, password reset, security notices (for example a new sign-in method or a connected AI agent), changes to your projects, and low-balance notices. We do not send creators marketing email.
Who we share it with#
We do not trade or rent personal data. We share it only with the service providers that run KUMODeck for us, and only what each one needs:
| Provider | What it does | Location |
|---|---|---|
| Cloudflare | Hosting, compute, file storage, request logs, relaying realtime and voice traffic | Worldwide |
| Neon | Main database | United States (AWS us-east-1) |
| Resend | Sending account emails | United States |
| Stripe | Prepaid top-ups and saved cards | United States and others |
| Amazon Web Services (SES) | Sending KUMODeck news to people who asked for it | United States (us-east-1) |
| Google, GitHub | Sign-in, only if you choose it | United States |
| Google Fonts | Fonts on this site and the dashboard (your browser asks Google for them, which shows Google your IP address) | Worldwide |
Your data may therefore be stored and processed outside your country, including in the United States. We may also disclose data when the law requires it.
How long we keep it#
| Data | How long |
|---|---|
| Account data | Until you close the account. After closing, the account is anonymised (email, name, sign-in methods and passkeys removed) once no balance remains |
| Billing and ledger records | As long as accounting and tax law require (up to 7 years) |
| Sign-in sessions | 30 days, or until you sign out |
| Request logs and Functions logs | About 7 days |
| Database backups | Up to 30 days |
Your choices and rights#
- Users of creators' apps can download or delete their own data where the app offers it (the API is
GET /v1/players/me/exportandDELETE /v1/players/me), and creators can do the same for any of their users from the dashboard or their server. Deletion is permanent; records needed for accounting are anonymised and kept. - Creators can close their account from the dashboard after deleting their projects. To get a copy of your account data, or to correct or delete it, email [email protected].
- Depending on where you live, you may have further rights (for example to object or to complain to a data protection authority). Contact us and we will answer within the time the law requires.
Cookies and browser storage#
There is no analytics or tracking on this site, the dashboard or the CLI, and no advertising cookies.
- This site stores only your light / dark theme choice in your browser.
- The dashboard keeps your session, your last sign-in method and your language in browser storage.
- Signing in from an AI agent sets two short-lived cookies (10 minutes) for the sign-in step only.
Data in creators' apps#
When a creator uses KUMODeck, data about their users is stored by KUMODeck: accounts (display name, email and sign-in identities from email, Google, Discord, Apple or X; passwords only as a hash), saves and app data, uploaded files, and the creator's own databases and storage. Realtime and voice traffic is relayed and not recorded.
The creator decides what to collect and must tell their users in their own privacy policy. We use this data only to provide the service to the creator, do not use it for our own purposes, and help creators answer their users' requests with the export and delete tools above. If you use an app built on KUMODeck, contact the app's creator first; if you cannot reach them, contact us.
KUMODeck news: some apps show a box to get news from KUMODeck. If an adult ticks it and confirms by email, we keep the email address and a record of that consent to send our news. Every message has a link to stop it.
Changes#
We will post changes on this page and update the effective date. For significant changes we will also tell creators by email.