PUKABU Global Privacy Policy

PUKABU Global Privacy Policy

INFORMATIONAL MACHINE TRANSLATION — This document is an informational machine translation of the binding authoritative Turkish master. In the event of any discrepancy, the Turkish master prevails.

Global core + Türkiye/KVKK + EU/EEA/GDPR + conditional US/state annexes

Document codePUKABU-PRIVACY-JR-V1-TR
Version / StatusFINAL — effective on the publication date
Preparation dateAugust 24, 2026
Communicationpukabupuzzle@gmail.com

FINAL TEXT: This document is issued in Türkiye by Kader Narin as operator and data controller and takes effect on its publication date. Contact: pukabupuzzle@gmail.com.

1. Global realities of shared data processing

PUKABU is a general audience puzzle application featuring six games, primarily offline. this policy describes the local profile, progress, store payment, optional analytics/bug reporting, advertising, and web components seen in the application's verified verified dependency inventory, all within a single global core.

Firebase Analytics, Firebase Crashlytics, Google Mobile Ads, and UMP are active production services. The local profile and game progress remain on the device; rights specific to local law are detailed in separate annexes.

2. Data controller and contact information

The operator and data controller of the PUKABU service is Kader Narin. The operator is established in Türkiye.

For general privacy and data subject requests, use the electronic request channel: pukabupuzzle@gmail.com.

3. Categories of data collected and not collected

The app account, server-side user profile, or social sharing service provided has not been verified. Local username, avatar preference, game progress, settings, achievements, and score data are stored on the device.

The PUKABU app does not request, process, or store credit card numbers, CVVs, or payment card identification information. Payment data is processed by Google Play or Apple under their respective agreements.

CategorySourceAimThe current situation
Local profileUser's on-device inputUsername and avatar appearanceLocal on the device
Game progressGame interactionsLocation, score, and achievement.Local on the device
Purchase statusGoogle Play / AppleConfirming your premium subscription.Through the store
Diagnosis/analysisFirebase SDKError and usage measurementActive; anonymous usage measurement and technical diagnostics
Advertisement/permissionGoogle Mobile Ads / UMPAdvertising and consent managementActive in the free version; UMP consent gate and non-personalized ads
Web transferCanvasKit/CDNWeb graphics runtimeHTTP metadata if web is used

4. Local profile, username, and gallery avatar

The profile name and selected raven/gallery avatar are for on-device personalization. The image selected from the gallery is processed on the device to be converted into the profile avatar; there is no proof of upload to the application server in the current product architecture. Whether the photo is accessible by the operating system selector is subject to the device platform's own permissions and privacy controls.

Users can remove local profile data using in-app reset/delete functions or device app data clearing tools. For the current application, the iOS photo library permissions and platform notifications must be verified one last time.

5. Shared Preferences and On-Device Progression

Shared Preferences are used for small local preference/progress records such as language, theme, selected profile, points, badges, and unique completed puzzle IDs. The transfer of these records to the PUKABU server in the normal workflow is not shown. Uninstalling the application or clearing platform data may delete these records.

6. StoreKit and Google Play Billing

Premium purchases and subscriptions are processed through Apple StoreKit or Google Play Billing. PUKABU may use the product, transaction status, and entitlement information returned by the store to provide premium access and restore the purchase. Payment method data is not received by PUKABU.

Subscription management, cancellation, and, where applicable, refund processes are handled within the scope of the relevant store account and mandatory consumer law.

7. Firebase Analytics and Crashlytics

Firebase Analytics is active in production to measure anonymous app usage events, and Firebase Crashlytics is active for technical crash, error, and performance diagnostics. These flows may process technical data such as app/version, device characteristics, event or session information, and error records.

PUKABU does not use Firebase setUserId and does not send a username, email address, profile photo, free-form user content, or game progress to Analytics or Crashlytics. Ad-personalization signals are disabled by default.

8. Google Mobile Ads and UMP

The free version uses Google Mobile Ads (AdMob) to serve ads; the Premium version displays no ads and makes no new ad request while Premium is active. The banner is limited to the Home ad slot, and an interstitial may be used only after an actual game completion.

In the EEA, United Kingdom, and Switzerland, the Google User Messaging Platform (UMP) consent flow runs before an ad request. UMP collects legal advertising and data-processing choices; it does not replace Apple App Tracking Transparency (ATT). On iOS, when the UMP choice permits trackable advertising and the ATT status is not determined, Apple's separate ATT system permission is requested. If ATT is denied, restricted, or not determined, PUKABU does not use IDFA or initiate cross-app tracking and requests only non-personalized/limited ads.

9. Image Picker, URL Launcher and Package Info

Image Picker is used solely to process the user's selected local image on the device for use as a profile avatar. URL Launcher delegates the email or store/subscription link to the operating system or an external application; further processing is subject to the respective provider's policies. Package Info reads technical information from the device, such as the application name and version.

10. Web CanvasKit/CDN migration

In the web version, CanvasKit components Flutter can be retrieved from a CDN such as www.gstatic.com. During this request, the usual HTTP metadata such as IP address, user agent, time, and request header can reach the CDN provider. Self-hosting or CDN selection should be finalized for the current application and must be consistent with store/web declarations.

11. Legal grounds

On-device game and profile functions are assessed under contract performance or the service requested by the user; security and error prevention under legitimate interests; and store transactions under contract and legal obligations. Anonymous usage measurement, technical diagnostics, and advertising follow the consent and UMP choices required by applicable law; ads are not personalized without consent.

If a feature's underlying release configuration doesn't match the actual data flow, the feature won't be enabled; the policy and permission flow will be updated first.

12. Storing and deleting

Local profiles and progress may remain on the device until the user deletes the app, clears app data, or uninstalls the app. Store transaction logs are subject to the store's and mandatory financial regulations' deadlines. Communication requests are held for the duration of the request's processing and legal dispute/defense periods.

Technical data processed by Firebase Analytics, Crashlytics, and AdMob is subject to the configured retention/deletion controls in the relevant provider consoles and applicable law. Requests may be sent to pukabupuzzle@gmail.com; the local profile and game progress are not sent into these SDK retention flows.

13. International transfer

The local profile, avatar, score, and game progress are not sent to a developer server. StoreKit/Google Play, CDN, Firebase Analytics/Crashlytics, and AdMob/UMP technical services may use provider infrastructure in different countries; transfers are limited by applicable KVKK/GDPR safeguards, provider agreements, and consent/notice requirements.

14. Security

Data minimization, local storage, access restrictions, dependency version tracking, and platform security controls are implemented. No technical method provides an absolute guarantee of security. Suspicious events and data requests can be reported to pukabupuzzle@gmail.com.

15. Policy regarding the 13+ target audience and children

PUKABU is a general-purpose application with a minimum age of 13. It does not specifically target children under 13 and does not knowingly collect personal data from those under 13. If the digital consent age in the applicable country is higher than 13, the user must meet that age requirement or have the necessary parental/guardian consent.

13. If it is discovered that personal data of a person under 13 years of age is being processed, the relevant use will be stopped, the data processing source will be investigated, and the data will be deleted if there is no legal obligation to retain it. Parents/guardians can apply via pukabupuzzle@gmail.com. This approach does not mean that a service for children or a COPPA parental consent system is being established.

Store age rating is a separate content/store classification and does not replace the minimum user age decision.

16. User requests

Requests can be sent to pukabupuzzle@gmail.com. Additional information proportionate to the request and risk may be requested for identity verification; unnecessary identification documents will not be collected. KVKK applications are answered as soon as possible and within 30 days at the latest; if GDPR applies, requests are generally answered within one month. In case of refusal, the reason and applicable complaint/legal remedy will be notified.

17. Türkiye / KVKK annex

With regard to processing in Türkiye, the Law No. 6698 on the Protection of Personal Data and its secondary regulations are applicable to the extent that they are applicable. The data subject may exercise the rights to learn whether processing is taking place, to request information, to learn the purpose and appropriate use, to know the recipients of the transfer, to request correction, deletion/destruction and notification, to object to an adverse result solely from automated analysis and to request compensation for damages.

The KVKK Information Text and KVKK Application Form, specific to Türkiye, are separate canonical documents. Foreign language versions are merely informative translations specific to Türkiye; they do not replace GDPR, CCPA/CPRA or any other country's rights/application mechanisms.

18. EU/EEA / GDPR annex

GDPR may be applied to a business operator outside the country in situations such as supplying goods or services to persons established in the EU/EEA or monitoring their conduct. For the current application, an assessment of Article 3 should be documented based on the target market, store distribution, language/currency and actual monitoring activities.

If GDPR applies, the data controller shall be notified of the purpose/basis, data categories, recipients, third-country transfer safeguards, retention period and rights of access, rectification, deletion, restriction, objection, portability, withdrawal of consent and complaint to the supervisory authority. Automated decision/profiling with legal or similar significant effect has not been verified to date.

If Article 3(2) falls within the scope of GDPR while there is no resident status in the EU/EEA, the need for an Article 27 representative must be assessed with concrete data flow, including the exception for occasional and low-risk processing. Currently, no EU representative or DPO has been appointed; a non-existent person/institution cannot be listed. If the need arises, the appointment and contact information will be a condition that must be resolved before the relevant service is offered.

19. U.S. and state rights - only insofar as they are applicable

The application of CCPA/CPRA is not automatically accepted. As of January 1, 2025, the annual gross income threshold is 26.625.000 USD. Alternatively, purchasing, selling, or sharing the personal information of 100.000 or more California residents/households, or generating at least 50 percent of annual income from such sale/sharing, will be considered.

Revenue, California user/household count, and sales/sharing facts cannot be verified without claiming that CCPA is applicable. The sale of personal information has not been verified in the current locally-weighted architecture. If advertising is enabled, California's definition of 'sharing', opt-out, sensitive data, and under-16 user policies should also be reviewed.

20. Amendments and entry into force

This policy takes effect on its publication date. The effective version and a summary of material changes are published simultaneously in the in-app Legal Center and on the public legal pages. Notification and renewed-consent processes required by applicable law are followed for material changes.

Official references

GDPR full text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

European Commission - data owner requests: https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/dealing-requests-individuals_en

European Commission - child data: https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/legal-grounds-processing-data/are-there-any-specific-safeguards-data-about-children_en

FTC - COPPA FAQ: https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions

California CPPA - 2025 thresholds: https://cppa.ca.gov/announcements/2024/20241217.html

KVKK Institution - application right: https://www.kvkk.gov.tr/Icerik/2062/Basvuru-Hakki

KVKK Institution - obligation to respond: https://www.kvkk.gov.tr/Icerik/2046/Ilgili-Kisiler-Tarafindan-Yapilan-Basvurularin-Cevaplanmasi-Yukumlulugu