Privacy Policy
プライバシーポリシー
01 Who we are
Kobako is an iPhone app for keeping ideas. It is made by Aleksandr Gaidash, an independent developer, contactable at hello@kobako.app. This policy explains what this website records, what the app records, and what you can do about either. The short version: your ideas stay yours, on your device or in your own iCloud, and we run no servers that hold them.
02 This website
There is no analytics on this page. No tracking pixel, no advertising tag, no cookie. The page makes no requests to any third-party server — the fonts, the artwork and the music are all served from this domain, so nothing about your visit is handed to anyone else in the course of loading it.
A few things are remembered in your own browser and never sent anywhere: which room you last looked at, that you have cleared the notes, and which of Kapi's small secrets you have found. Clearing site data in your browser erases all of it.
The site is hosted on Cloudflare. Like any web host, Cloudflare handles the network request itself — including your IP address — in order to deliver the page and to block attacks. We do not receive that as a report, and we keep no server logs of our own.
03 The waitlist
If you enter an email address, we store that address and the date you gave it. Nothing else: no name, no IP address, no browser details, no profile. It is held in a Cloudflare database in the European region.
We will use it once — a single email telling you the app is out. It is not a newsletter, and it is never sold, shared, or passed to any advertising or analytics service. To come off the list, write to hello@kobako.app and the row is deleted; no account, no reason needed. The list is deleted in full once the launch email has gone out.
04 The tap counter
The number at the top of the page counts how many times Kapi has been patted, by everyone, ever. It is a single number with nothing attached to it — no session, no visitor identifier, no record of who tapped or when.
05 The app: what stays on your device
Everything you put into Kobako — your ideas, their history, your folders, your focus, your progress with Kapi and the rooms — is stored on your iPhone, in the app's own database. We operate no server that receives, stores or can read it. Like the rest of your iPhone's data, it is encrypted at rest by iOS whenever the device is locked with a passcode.
Reminders the app offers are scheduled locally by iOS on your device; there is no push server behind them. Deleting the app deletes everything it stored on the device.
06 iCloud sync, if you turn it on
The app can keep your ideas in sync across your devices through your own iCloud account, using Apple's CloudKit private database. Your small profile — the name you chose, your bond with Kapi, your avatar — syncs the same way, through iCloud's key-value store. This data travels between your device and Apple; it is protected by your Apple account, and we cannot read it — a private database is exactly that.
Sync is controlled by a switch in Settings. Turn it off and the app stops sending anything to iCloud; you can also remove the app's iCloud data from your device's iCloud storage settings. Apple's handling of iCloud is governed by Apple's own privacy policy.
07 Anonymous analytics and crash reports
So we can tell whether a feature is used at all — and whether the app is crashing — Kobako uses Google Firebase Analytics and Crashlytics. What is sent is a stream of small technical events: the app was opened, a screen was viewed, an idea was created or archived (as a random identifier and a character count — never the text), a room theme was changed, an error of a certain type occurred. No idea text, no folder names, no profile names ever leave the device this way.
Alongside the events, Firebase records the usual technical context: a random app-instance identifier, the device model, iOS version, app version, language, and the approximate region Google derives from the connection. Crash reports carry the technical state of the app at the moment it failed. The app contains no advertising, requests no ad-tracking permission, and does not use the advertising identifier (IDFA).
This data is processed by Google LLC under Google's data-processing terms, is not linked to your identity, and is retained by Google for up to 14 months (crash data for 90 days). Deleting the app resets the app-instance identifier, disconnecting any future data from the old stream.
08 One small file on launch
Once per launch the app fetches a single configuration file from kobako.app — the mechanism by which we can show a notice (say, about an update) without shipping a new build. The request carries no identifiers, no account information, nothing about you or your ideas; it is an ordinary web request, handled by the same Cloudflare hosting as this page.
09 Support and feedback
"Contact support" in Settings opens an email to help@kobako.app with a plain-text log of your current session attached — the last four hours of the app's own status messages: timestamps, categories, outcomes, plus the app version, iOS version and device model. It contains no idea text and no names, and you can read the whole attachment in the mail composer before deciding to send it. Feedback and rating emails work the same way, minus the log.
We keep support and feedback emails for as long as they are needed to resolve the matter, then delete them. Write to the same address to have a past thread deleted sooner.
10 Purchases
Subscriptions and one-off purchases are handled entirely by Apple through the App Store. Apple processes the payment; we never see your card number, billing address or Apple ID. What we receive is what any App Store developer receives: anonymous, aggregated sales reporting, and an anonymous analytics event that a purchase of a given product occurred — not who made it. Refunds and billing questions go through Apple, but if you write to us we will help you find the way.
11 Children
Kobako is not directed at children under 13, and we do not knowingly collect personal information from children. There is nothing in the app aimed at them — and if you believe a child has given us personal information (the waitlist is the only place one could), write to hello@kobako.app and it will be deleted.
12 Your rights
You can ask us for access to the personal data we hold about you, a copy of it, a correction, or its deletion — write to hello@kobako.app and we will answer within 30 days. Depending on where you live, these rights may be backed by law (such as the GDPR); we honour them for everyone, because there is very little to hold: an email address if you joined the waitlist, and any support threads you started.
Everything else is already in your hands. Your ideas live on your device and in your own iCloud — edit and delete them in the app, or delete the app to remove them entirely. The analytics stream is not linked to your identity, so there is nothing there we could look up by name; deleting the app resets its identifier.
13 Changes to this policy
If this policy changes in a way that matters — new data, a new third party, a new purpose — the app will say so before the change takes effect, and this page will show the new date at the top. Quiet edits are limited to clarity and typos.
14 Contact
Write to hello@kobako.app for anything in this policy, or help@kobako.app for help with the app. A person reads both.