Privacy Policy
Effective Date: 2026-05-02
Last Updated: 2026-05-02
Site: https://games.kio-ku.com (the "Site")
Operator: Kioku Games (the "Operator", "we", "us", "our")
This Privacy Policy describes how Kioku Games (operated as part of the Kioku family of products) collects, uses, and shares information when you use the Site.
1. Information We Collect
1.1 Information stored locally on your device
We use browser LocalStorage to save the following on your device only:
- Your in-game progress and personal best scores
- Display preferences (language, theme, sound on/off)
- A self-chosen player nickname (only if you submit it to a leaderboard)
This data never leaves your device unless you explicitly submit it (e.g., via the leaderboard).
1.2 Information sent to our servers
When you submit a score to the global leaderboard, we receive:
- The nickname you chose
- The score and game session metadata (duration, in-game events for anti-cheat)
- A SHA-256 hash of your IP address (we do not store the raw IP)
- A timestamp
1.3 Cookies and similar technologies
We use the following:
- Strictly necessary technologies (LocalStorage) to provide core features
- Analytics: Cloudflare Web Analytics (cookie-free, privacy-friendly)
- Advertising: Google AdSense and partner ad networks may set cookies for ad personalization, frequency capping, fraud prevention, and reporting. We use a Google-certified Consent Management Platform (CMP) to obtain consent in regions where it is required (e.g., EEA, UK, Switzerland, California).
You can manage your consent at any time via the "Privacy Settings" link in the footer.
2. How We Use Information
We use the information we collect to:
- Provide and maintain the Site and its features
- Display global leaderboards and a hall of fame for top weekly players
- Show advertisements to support the free service
- Detect and prevent fraud, abuse, and cheating
- Comply with legal obligations
We do not:
- Sell personal information
- Use your data to train AI models
- Share your data with third parties for their own marketing
3. Legal Bases (GDPR / UK GDPR)
For users in the European Economic Area, the United Kingdom, and similar jurisdictions, we rely on the following legal bases:
- Legitimate interests: providing the Site, fraud prevention, basic analytics
- Consent: personalized advertising and non-essential cookies (collected via CMP)
- Legal obligation: when required by law
4. Advertising
This Site is supported by advertising. We work with Google AdSense and may work with additional ad networks in the future. Ad partners may use cookies and other technologies to:
- Show ads relevant to your interests (only with consent where required)
- Measure ad performance and prevent fraud
For more information about Google's advertising practices and your choices, visit:
- https://policies.google.com/technologies/ads
- https://adssettings.google.com/
5. Children
This Site is intended for users aged 13 and over. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child under 13 has provided personal information, please contact us at the email below and we will delete it.
For users in the EU and UK, the minimum age may be higher (e.g., 16 in some countries) under local law.
6. Data Retention
- LocalStorage on your device: kept until you clear your browser data
- Weekly leaderboard entries: deleted automatically every Monday 00:00 UTC, except for the top scorer of each game, which is moved to the "Hall of Fame" and kept indefinitely
- IP address hashes: kept for up to 30 days for abuse detection, then deleted
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion
- Object to or restrict certain processing
- Withdraw consent (for processing based on consent)
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us using the information in Section 10. Note that because most data is stored on your device, you can delete it yourself by clearing your browser's site data.
8. International Transfers
Our service is hosted on Cloudflare's global network. Data may be processed in countries other than your own. We rely on Cloudflare's contractual safeguards for international data transfers.
9. Security
We implement reasonable technical and organizational measures to protect data, including:
- HTTPS encryption in transit
- IP address hashing
- Rate limiting and bot mitigation (hCaptcha)
- Minimal data collection by design
No method of transmission over the Internet is 100% secure.
10. Contact
For privacy-related questions or to exercise your rights, contact:
Email: privacy@kio-ku.com
11. Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Material changes will be announced on the Site.