Privacy policy

Umka Privacy Policy

Effective August 2, 2026 | Last updated August 15, 2026

This policy explains how Sfumato Studios LLC handles information through the Umka iOS app, the Umka website, and support communications.

The short version: The current app has no account or advertising. Child learning, the Parent PIN, and selected-app information stay on the device. RevenueCat processes an anonymous purchase-support ID, purchase history, subscription status, and limited technical information for subscription functionality and purchase analytics. The website uses Vercel Web Analytics for anonymous, aggregate page-view and referral reporting without analytics cookies, and PostHog to count daily website visitors and daily App Store clicks from two sanitized website events. Neither website measurement uses cookies or browser storage, and neither receives child, learning, selected-app, or Umka app data. We also receive information someone chooses to send in a support email.

Information stored on the device

Umka stores the information needed to run the family's routine in private on-device storage, including an Apple App Group container and the iOS Keychain. Depending on how a parent configures Umka, this can include:

The current app does not transmit this child, profile, learning, PIN, or selected-app information to Sfumato Studios, RevenueCat, an analytics provider, an advertising provider, or another remote product service.

Information the current app does not send to RevenueCat

The current app does not send RevenueCat:

Umka contains no third-party advertising. RevenueCat is a subscription infrastructure provider whose purchase-history processing includes dashboard analytics. Umka does not use RevenueCat for advertising or to track activity across other companies' apps or websites.

If a future version adds parent-funnel analytics, crash reporting, accounts, attribution integrations, or another remote data flow, we will review that version separately and update this policy and the applicable notice and App Store disclosures before the new collection begins.

How Umka uses Apple's Screen Time frameworks

Umka uses Apple's Family Controls, Device Activity, and Managed Settings frameworks to pause and restore only the apps, categories, or websites selected by the parent. Apple gives Umka opaque selection tokens rather than a readable list of selected apps. Umka does not receive browsing history or a general report of device activity. Apple's handling of information is governed by Apple's Privacy Policy.

RevenueCat subscription processing

Umka configures RevenueCat without a custom user ID. The RevenueCat SDK creates and stores a random anonymous App User ID on the device. Sfumato Studios and RevenueCat can use that identifier to locate the associated subscription record, but Umka does not link it to a name, email address, account, child profile, selected apps, or learning history.

RevenueCat receives and processes purchase history and subscription status from Apple, along with limited end-user technical information such as device type, operating system, app version, IP address, locale, currency, and last-seen time. This supports receipt validation, entitlements, purchase restoration, fraud prevention, support, and RevenueCat customer-history, chart, and experiment analytics. Umka does not enable advertising attribution integrations or send an advertising identifier or customer attributes to RevenueCat.

RevenueCat acts as a service provider for this processing. Its handling of data is also described in RevenueCat's Privacy Policy.

Website information

The Umka website uses Vercel Web Analytics to understand aggregate page visits and referral sources. A page-view record may include its timestamp, page path, filtered query parameters, referrer, approximate location, browser, operating system, device type, and analytics-script version. The website does not send Vercel child-learning information, selected-app information, support-message content, or information from the Umka iOS app through Web Analytics.

Vercel states that Web Analytics page views are anonymous, are not associated with an individual or IP address in the analytics results, and do not use cookies. Vercel creates a temporary hash from a request to distinguish visits for aggregate reporting and says that visitor session information is discarded after 24 hours. The website does not add advertising pixels, account login, forms, browser cookies, local storage, or session storage. See Vercel's Web Analytics privacy and compliance documentation for more information.

Like most websites, Vercel may also process standard request information—such as an IP address, browser or device information, requested page, and request time—to deliver, protect, and troubleshoot the site. We require website providers to use information only for the services described here and to retain it only as reasonably necessary for those purposes or as otherwise required by law.

Website measurement with PostHog

The Umka website also uses PostHog to answer two questions: how many distinct people visited the site on a given day, and how many distinct people opened an Umka App Store link on that day. We use those counts to understand whether the website is helping parents find Umka.

The website sends PostHog only two events: a page view when a public page loads, and an App Store click when someone activates one of the six Umka App Store links on the site. Each event carries only:

Everything else is removed before an event is sent. Campaign codes, query parameters, page anchors, page titles, link text, form or support content, and any information from the Umka iOS app cannot be included, and no other event can be sent.

The website does not give PostHog a cookie, a browser identifier, local storage, or session storage. PostHog's servers instead derive a visitor value by combining the request's IP address and browser user agent with a secret that rotates daily; in this mode the raw IP address is removed before the event is stored. Because the value rotates daily, it is not built to recognize the same visitor on a later day, and it does not tell us who someone is. Treat it as a pseudonymous counting value, not a guarantee that re-identification is impossible in every circumstance.

PostHog acts as a service provider and processes these events for us in the United States. Events in our PostHog project are currently retained for 12 months. Sfumato Studios uses one PostHog project across products, so every Umka website event carries a fixed site label that keeps Umka's counts separate.

This measurement receives no child data, learning data, selected-app data, Parent PIN, support-message content, or purchase data. The Umka iOS app does not use PostHog. PostHog's handling of data is also described in PostHog's privacy policy.

Online tracking signals

The website does not collect information about visitors' activities over time and across third-party websites or services for behavioral advertising. Because the website does not conduct that type of tracking, browser Do Not Track and Global Privacy Control signals do not change its behavior. We do not authorize other parties to conduct cross-site behavioral tracking through the website.

Support and privacy requests

If you email us, we receive the email address you use, the contents of your message, and any information you choose to include. We use it to respond, provide support, handle a privacy request, maintain appropriate business records, and meet legal obligations. Please do not send a child's name, answers, learning records, Parent PIN, or selected-app information in a support message.

Our email and infrastructure providers may process support communications on our behalf. We do not use support messages for advertising profiles or sell them to third parties.

App Store and Apple services

Apple processes information when someone downloads Umka, uses App Store services, manages an Apple subscription or purchase, or grants system permissions. Apple may provide developers with aggregate or transaction-related App Store reports. Those Apple-controlled practices are governed by Apple's Privacy Policy. Umka uses RevenueCat to validate, restore, and understand purchases as described above.

How we disclose information

We require service providers to use information only to provide services to us, protect it consistently with this policy and applicable requirements, and delete or return it according to our instructions and applicable law.

We do not sell or rent personal information. We do not use information for behavioral advertising, data brokerage, advertising fingerprinting, or tracking activity across other companies' apps or websites. The daily rotating value that counts website visitors is used only to count visits to our own website within a single day. Umka contains no third-party ads.

Children's privacy

Umka is designed to be installed and configured by a parent or guardian. We do not ask a child to submit a name, email address, phone number, location, photo, recording, or public content. Umka has no account, chat, social, or public-profile features. Child answers, performance, learning history, nickname, grade, Parent PIN, and selected-app data stay on the device and are not sent to Sfumato Studios, RevenueCat, or an analytics service. The website measurement described above runs only on our public website pages, never inside the app, and cannot receive any of that information.

If we learn that a child sent personal information to us through a support message, we will take appropriate steps to delete it. A parent or guardian may contact us with questions or a deletion request.

Retention and deletion

Access, correction, and privacy rights

Because the current app does not send its local records to us, Sfumato Studios cannot access, correct, or delete those records remotely. A parent can review or change relevant information in the Parent area and can erase app-controlled local records using Reset all data.

You may contact us to ask what support or other information we hold about you, request a correction or deletion, or exercise other privacy rights available where you live. We may need to verify a request and may retain information where required or permitted by law. We will respond as required by applicable law.

The website measurement described above has no account, login, or stored browser identifier, and its daily rotating visitor value is not designed to identify a person. We therefore usually cannot locate one visitor's website events in order to show or delete them individually. You can still write to us at the privacy contact below with a question or request about website measurement; we will explain what is available, act on what we can identify, and answer as applicable law requires.

For a RevenueCat purchase-record request, include the anonymous Purchase support ID shown in Umka's Parent Settings. Do not include a child's name, answers, learning history, Parent PIN, or selected-app information. Deleting a RevenueCat record does not cancel an Apple subscription; subscriptions are managed through Apple.

Security

We use administrative, technical, and organizational safeguards designed for the limited information described in this policy. Umka minimizes remote data, keeps child learning and app-selection information on the device, and stores the Parent PIN in the iOS Keychain. No storage or transmission method can be guaranteed completely secure.

United States processing and international users

Sfumato Studios is based in the United States. Vercel, PostHog, email, and infrastructure providers may process the limited website or support information described in this policy in the United States or other countries where they operate, subject to applicable safeguards. The website measurement events are processed in the United States.

Changes to this policy

We may update this policy when Umka, our providers, or legal requirements change. We will post the revised policy with a new "Last updated" date. If a change introduces or materially expands remote collection, we will update the relevant notice and obtain any permission required by law before the change takes effect.

Contact us

Sfumato Studios LLC operates Umka: Math for Screen Time.

For privacy questions, access or deletion requests, or support, email support@learnwithumka.com.