← Back to Mukdek

Privacy notice

Your data in Mukdek

Mukdek is designed for a small, permissioned group. It does not use advertising trackers or Google Analytics. This notice explains what is stored, why, for how long, and how to export or delete account-linked data.

Effective August 14, 2026

Short version

Data inventory and retention

DataWhy it is usedDefault retentionWho can access it
Google account email, Google user ID, access-request name, and pseudonymous server-side session recordAuthentication, current-role checks, session revocation, allowlists, and access reviewAccess requests: 30 days. Session records expire with the cookie or are removed on logout, revocation, or deletion. Approved account details remain in deployment configuration; profile preferences remain until deletion.The account holder and authorized administrators
Profile name, initials, avatar color, and family-member linkIdentify a player inside the private groupUntil the user deletes account-linked data or an administrator removes the configured family identitySigned-in users with the relevant family access
Gameplay nickname or emoji, opaque revocable session ID, room state, moves, statistics, and resultsOperate multiplayer games, verify room membership, restore rooms, and show score historyIdle rooms: 15 days. Gameplay cookie and server-side session record: 30 days unless revoked sooner. Scores and results: 90 days.Verified players and spectators in the room; result history requires sign-in
Food-game initials and scoreDisplay the leaderboard90 daysVisitors to that leaderboard
Push endpoint or mobile notification tokenSend requested turn or message alertsRemoved after 90 days without activity, on unsubscribe, or on deletionThe server and the selected push provider
Messaging email, device public keys, encrypted envelopes, and encrypted identity backupDeliver end-to-end encrypted admin messages and restore a messaging identityMessages: 365 days. Inactive devices: 180 days. Encrypted identity backups: 365 days.Messaging participants; the server stores ciphertext and public key material, not plaintext message content
Family boards, tasks, financial rewards, behavior charts, and watch stateProvide ongoing family planning and caregiving toolsUntil an authorized family administrator deletes or replaces the shared recordOnly users with the relevant family role
Space Dice saved stateRestore the signed-in player’s game90 days after the last saveThe signed-in player and server administrators
Operational logsSecurity, reliability, and troubleshootingApp-managed logs: 14 days. Hosting-platform logs must be configured to the same or shorter period by the operator.Authorized operators
Encrypted server backupsDisaster recovery30 daysOperators holding the separate encryption key

Service providers and analytics

Google is used for sign-in and may be used as an optional game-results spreadsheet when the operator enables that integration. Browser and mobile push providers receive a push endpoint or token and generic notification payload. The hosting provider processes network metadata needed to serve requests.

Google Analytics is disabled. Mukdek’s public game previously loaded a Google Analytics tag without a consent gate. It was removed during the August 2026 privacy review because the game may be used by children and analytics was not necessary to provide gameplay. Mukdek does not send names, account IDs, game behavior, or advertising identifiers to Google Analytics.

Children’s privacy

Mukdek contains child-oriented games and a child account role. A parent or guardian should manage a child’s access and notification settings. Mukdek does not use targeted advertising or third-party analytics on the public game.

COPPA can apply when a commercial website or online service is directed to children under 13, or when a general-audience operator has actual knowledge that it is collecting personal information from a child under 13. Whether Mukdek is legally covered depends on facts that source code cannot establish, including how the service is offered and its actual audience. The operator should treat child-accessible areas as COPPA-sensitive and obtain qualified legal review before enabling collection beyond what is necessary to operate the requested feature. See the FTC’s COPPA compliance plan and COPPA FAQs.

Your choices

Signed-in users can download account-linked profile, access-request, gameplay, saved-state, push, device, and encrypted-message records. Deletion removes those account-linked records and signs the user out. Shared family data and legacy name-only game results require administrator review because deleting them automatically could erase another person’s record.

Sign in to use privacy controls

Contact

Contact the Mukdek administrator who provided your access to ask about shared records, a child’s data, consent, or a legacy record that the automatic controls cannot identify.