Privacy notice
Your data in Mukdek
Mukdek is designed for a small, permissioned group. It does not use advertising trackers or Google Analytics. This notice explains what is stored, why, for how long, and how to export or delete account-linked data.
Effective August 14, 2026
Short version
- Mukdek collects only the information needed for sign-in, games, family tools, notifications, and encrypted messaging.
- The public game does not load Google Analytics or third-party advertising scripts.
- Account-linked data can be exported or deleted below. Shared family records require a family administrator because they may concern more than one person.
- Server backups are encrypted when backup encryption is configured. Message content is end-to-end encrypted before reaching the server.
Data inventory and retention
| Data | Why it is used | Default retention | Who can access it |
|---|---|---|---|
| Google account email, Google user ID, access-request name, and pseudonymous server-side session record | Authentication, current-role checks, session revocation, allowlists, and access review | Access requests: 30 days. Session records expire with the cookie or are removed on logout, revocation, or deletion. Approved account details remain in deployment configuration; profile preferences remain until deletion. | The account holder and authorized administrators |
| Profile name, initials, avatar color, and family-member link | Identify a player inside the private group | Until the user deletes account-linked data or an administrator removes the configured family identity | Signed-in users with the relevant family access |
| Gameplay nickname or emoji, opaque revocable session ID, room state, moves, statistics, and results | Operate multiplayer games, verify room membership, restore rooms, and show score history | Idle rooms: 15 days. Gameplay cookie and server-side session record: 30 days unless revoked sooner. Scores and results: 90 days. | Verified players and spectators in the room; result history requires sign-in |
| Food-game initials and score | Display the leaderboard | 90 days | Visitors to that leaderboard |
| Push endpoint or mobile notification token | Send requested turn or message alerts | Removed after 90 days without activity, on unsubscribe, or on deletion | The server and the selected push provider |
| Messaging email, device public keys, encrypted envelopes, and encrypted identity backup | Deliver end-to-end encrypted admin messages and restore a messaging identity | Messages: 365 days. Inactive devices: 180 days. Encrypted identity backups: 365 days. | Messaging participants; the server stores ciphertext and public key material, not plaintext message content |
| Family boards, tasks, financial rewards, behavior charts, and watch state | Provide ongoing family planning and caregiving tools | Until an authorized family administrator deletes or replaces the shared record | Only users with the relevant family role |
| Space Dice saved state | Restore the signed-in player’s game | 90 days after the last save | The signed-in player and server administrators |
| Operational logs | Security, reliability, and troubleshooting | App-managed logs: 14 days. Hosting-platform logs must be configured to the same or shorter period by the operator. | Authorized operators |
| Encrypted server backups | Disaster recovery | 30 days | Operators holding the separate encryption key |
Service providers and analytics
Google is used for sign-in and may be used as an optional game-results spreadsheet when the operator enables that integration. Browser and mobile push providers receive a push endpoint or token and generic notification payload. The hosting provider processes network metadata needed to serve requests.
Google Analytics is disabled. Mukdek’s public game previously loaded a Google Analytics tag without a consent gate. It was removed during the August 2026 privacy review because the game may be used by children and analytics was not necessary to provide gameplay. Mukdek does not send names, account IDs, game behavior, or advertising identifiers to Google Analytics.
Children’s privacy
Mukdek contains child-oriented games and a child account role. A parent or guardian should manage a child’s access and notification settings. Mukdek does not use targeted advertising or third-party analytics on the public game.
COPPA can apply when a commercial website or online service is directed to children under 13, or when a general-audience operator has actual knowledge that it is collecting personal information from a child under 13. Whether Mukdek is legally covered depends on facts that source code cannot establish, including how the service is offered and its actual audience. The operator should treat child-accessible areas as COPPA-sensitive and obtain qualified legal review before enabling collection beyond what is necessary to operate the requested feature. See the FTC’s COPPA compliance plan and COPPA FAQs.
Your choices
Signed-in users can download account-linked profile, access-request, gameplay, saved-state, push, device, and encrypted-message records. Deletion removes those account-linked records and signs the user out. Shared family data and legacy name-only game results require administrator review because deleting them automatically could erase another person’s record.
Contact
Contact the Mukdek administrator who provided your access to ask about shared records, a child’s data, consent, or a legacy record that the automatic controls cannot identify.