Privacy policy
Umka Privacy Policy
Effective August 2, 2026 | Last updated August 9, 2026
This policy explains how Sfumato Studios LLC handles information through the Umka iOS app, the Umka website, and support communications.
The short version: The current app has no account and shows no ads. Child learning, the Parent PIN, and selected-app information stay on the device. We do advertise Umka, and Apple measures those ads: the app tells Apple once that it was installed, and Apple may send the ad network a delayed, coarse report. A campaign link to our website can also carry a short campaign label we wrote, which the website adds to the App Store link so Apple can report campaign performance to us in aggregate; it names a campaign, not a person or a child, and never enters the app. RevenueCat processes an anonymous purchase-support ID, purchase history, subscription status, and limited technical information for subscription functionality and purchase analytics. The website uses Vercel Web Analytics for anonymous, aggregate page-view and referral reporting without analytics cookies. We also receive information someone chooses to send in a support email.
Information stored on the device
Umka stores the information needed to run the family's routine in private on-device storage, including an Apple App Group container and the iOS Keychain. Depending on how a parent configures Umka, this can include:
- a child nickname and grade selected by the parent;
- the parent's approved-time, learning-break, and app-management settings;
- selected-app information represented by opaque Apple tokens;
- questions, answers, correctness, learning and exposure history, adaptive state, and records of learning breaks;
- device and Screen Time operating state needed to run the selected-app routine; and
- the Parent PIN and Face ID preference.
The current app does not transmit this child, profile, learning, PIN, or selected-app information to Sfumato Studios, RevenueCat, an analytics provider, an advertising provider, or another remote product service.
Information the current app does not send to RevenueCat
The current app does not send RevenueCat:
- a child's or parent's name, email address, phone number, or account details;
- the child's nickname, grade, answers, correctness, performance, learning history, or adaptive state;
- selected apps, Apple selection tokens, browsing history, or general device-usage reports;
- the Parent PIN or Face ID information;
- advertising identifiers, location, contacts, photos, audio, or free-form content;
- screens, taps, session recordings, unrestricted text, child answers, or child learning events; or
- Umka setup events, selected-app identities, or child product-usage analytics.
Umka contains no third-party advertising. RevenueCat is a subscription infrastructure provider whose purchase-history processing includes dashboard analytics. Umka does not use RevenueCat for advertising or to track activity across other companies' apps or websites.
If a future version adds parent-funnel analytics, crash reporting, accounts, a third-party attribution or advertising integration, or another remote data flow, we will review that version separately and update this policy and the applicable notice and App Store disclosures before the new collection begins.
Apple install attribution for our ads
We advertise Umka, and some of those ads send a person straight to the App Store. Apple performs the measurement for them.
When Umka is installed and opened, the app registers one constant install conversion with Apple: value 0 and coarse value low, with the first reporting window closed immediately. It uses Apple's AdAttributionKit on iOS 17.4 and later and Apple's SKAdNetwork on iOS 17.0 through 17.3. There is nothing else to send and no second registration, so the signal cannot carry a campaign, a purchase, a subscription state, a timestamp, product behavior, or any child or learning information.
Apple matches an ad platform's signed ad click to the installation on its own systems and may send the advertising network a delayed, coarse postback. Sfumato Studios does not receive a user-level attribution result, an advertising identifier, a click identifier, a device identifier, or a profile from this process, and Umka sends the advertising network nothing directly.
Umka does not use the App Tracking Transparency prompt because it does not track you: it uses no advertising identifier (IDFA), no fingerprinting, no advertising or measurement SDK, and no developer-operated attribution endpoint. The app stores one boolean in its own app storage so a successful registration is not repeated. Apple's handling of this measurement is governed by Apple's Privacy Policy.
This app registration is separate from the campaign label our website can add to an App Store link, which is described in the website section below. The app neither reads nor receives that label, and the constant install conversion above still carries no campaign value.
How Umka uses Apple's Screen Time frameworks
Umka uses Apple's Family Controls, Device Activity, and Managed Settings frameworks to pause and restore only the apps, categories, or websites selected by the parent. Apple gives Umka opaque selection tokens rather than a readable list of selected apps. Umka does not receive browsing history or a general report of device activity. Apple's handling of information is governed by Apple's Privacy Policy.
RevenueCat subscription processing
Umka configures RevenueCat without a custom user ID. The RevenueCat SDK creates and stores a random anonymous App User ID on the device. Sfumato Studios and RevenueCat can use that identifier to locate the associated subscription record, but Umka does not link it to a name, email address, account, child profile, selected apps, or learning history.
RevenueCat receives and processes purchase history and subscription status from Apple, along with limited end-user technical information such as device type, operating system, app version, IP address, locale, currency, and last-seen time. This supports receipt validation, entitlements, purchase restoration, fraud prevention, support, and RevenueCat customer-history, chart, and experiment analytics. Umka does not enable advertising attribution integrations or send an advertising identifier or customer attributes to RevenueCat.
RevenueCat acts as a service provider for this processing. Its handling of data is also described in RevenueCat's Privacy Policy.
Website information
The Umka website uses Vercel Web Analytics to understand aggregate page visits and referral sources. A page-view record may include its timestamp, page path, filtered query parameters, referrer, approximate location, browser, operating system, device type, and analytics-script version. The website does not send Vercel child-learning information, selected-app information, support-message content, or information from the Umka iOS app through Web Analytics.
Vercel states that Web Analytics page views are anonymous, are not associated with an individual or IP address in the analytics results, and do not use cookies. Vercel creates a temporary hash from a request to distinguish visits for aggregate reporting and says that visitor session information is discarded after 24 hours. The website does not add advertising pixels, account login, forms, browser cookies, local storage, or session storage. See Vercel's Web Analytics privacy and compliance documentation for more information.
Like most websites, Vercel may also process standard request information—such as an IP address, browser or device information, requested page, and request time—to deliver, protect, and troubleshoot the site. We require website providers to use information only for the services described here and to retain it only as reasonably necessary for those purposes or as otherwise required by law.
Campaign links to the App Store
Some of our ads send a person to the Umka website before the App Store. A link we publish for one of those campaigns may include a c query parameter, which holds a short campaign label we wrote ourselves—for example, a name for one ad or one placement.
When that parameter is present, the website builds a campaign label from it in the browser. It removes every character that is not a letter, a digit, or an underscore, converts what remains to lower case, keeps at most the first 30 characters, and adds the prefix meta_. It then adds that label to the App Store links on the page as Apple's ct campaign-token parameter, so that Apple can report campaign performance to us in aggregate through App Store Connect. If the c parameter is missing or empty, the website changes nothing.
That campaign label is written by us to name a campaign, not read from the visitor, the device, or a child. It describes no person, no purchase, and nothing about how the Umka app is used. It is not copied into the Umka app, a child profile, learning records, or any other app state. It is not sent to Meta or another advertising network by the website or the app, and it is not written to a cookie, local storage, or session storage.
Because the label travels in the page's address, it may appear in the website request and page-view information described above, and it is supplied to Apple when someone follows the App Store link. It is separate from the app's install conversion described above.
Online tracking signals
The website does not collect information about visitors' activities over time and across third-party websites or services for behavioral advertising. Because the website does not conduct that type of tracking, browser Do Not Track and Global Privacy Control signals do not change its behavior. We do not authorize other parties to conduct cross-site behavioral tracking through the website.
Support and privacy requests
If you email us, we receive the email address you use, the contents of your message, and any information you choose to include. We use it to respond, provide support, handle a privacy request, maintain appropriate business records, and meet legal obligations. Please do not send a child's name, answers, learning records, Parent PIN, or selected-app information in a support message.
Our email and infrastructure providers may process support communications on our behalf. We do not use support messages for advertising profiles or sell them to third parties.
App Store and Apple services
Apple processes information when someone downloads Umka, uses App Store services, manages an Apple subscription or purchase, or grants system permissions. Apple may provide developers with aggregate or transaction-related App Store reports. Those Apple-controlled practices are governed by Apple's Privacy Policy. Umka uses RevenueCat to validate, restore, and understand purchases as described above, and relies on Apple's own install attribution for ad measurement as described above.
How we disclose information
- Vercel processes website request information and anonymous page-view information to host, protect, troubleshoot, and provide aggregate Web Analytics for the website.
- Apple receives the single constant install-conversion registration described above and, on its own systems, may send an advertising network a delayed, coarse install report. When someone follows a campaign-coded App Store link from our website, Apple also receives the short campaign label described above.
- Email and infrastructure providers may process technical data or communications as needed to operate the website and provide support.
- RevenueCat processes anonymous purchase and subscription information and limited technical information to provide subscription functionality, purchase support, fraud prevention, and purchase analytics.
- Authorities or other parties may receive information if we reasonably believe disclosure is required by law, necessary to protect rights or safety, or needed to investigate fraud or misuse.
- Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and protections for the information.
We require service providers to use information only to provide services to us, protect it consistently with this policy and applicable requirements, and delete or return it according to our instructions and applicable law.
We do not sell or rent personal information. We do not use information for behavioral advertising, data brokerage, fingerprinting, or tracking activity across other companies' apps or websites. Umka contains no third-party ads.
Children's privacy
Umka is designed to be installed and configured by a parent or guardian. We do not ask a child to submit a name, email address, phone number, location, photo, recording, or public content. Umka has no account, chat, social, or public-profile features. Child answers, performance, learning history, nickname, grade, Parent PIN, and selected-app data stay on the device and are not sent to Sfumato Studios, RevenueCat, Meta, or an analytics service. Apple's install attribution described above carries a single constant value and no information about a child or how the app is used. The campaign label our website can add to an App Store link is a name we chose for one of our own campaigns; it contains no child information, and the app never reads it.
If we learn that a child sent personal information to us through a support message, we will take appropriate steps to delete it. A parent or guardian may contact us with questions or a deletion request.
Retention and deletion
- Local app information remains on the device until a parent uses Reset all data, the operating system removes it, or it is otherwise cleared through device controls.
- Reset all data in Parent Settings erases Umka's app-controlled local setup, profile, plan, selected-app tokens, learning records, and Parent PIN, and then starts setup again. It does not revoke Apple-controlled permissions such as Screen Time, notifications, or Face ID enrollment; those can be changed in iOS Settings.
- Deleting Umka removes its app-container data. Because iOS Keychain items can survive app deletion, a previously stored Parent PIN may remain in the Keychain until Umka is reinstalled. On the first launch after reinstall, Umka detects the fresh installation and removes any stale Umka PIN. For the most complete app-controlled deletion before uninstalling, use Reset all data first.
- Support and privacy-request communications are kept only as long as reasonably needed to respond, maintain necessary records, resolve disputes, enforce agreements, and meet legal obligations.
- RevenueCat purchase records and their anonymous App User ID are kept as long as reasonably needed to validate and restore purchases, provide subscription access and support, prevent fraud, produce purchase analytics, and meet legal obligations. A verified deletion request can be used to delete the RevenueCat customer record. Deleting that record does not cancel an Apple subscription, and Apple purchase information may be sent again if the app later restores or synchronizes an active purchase.
- Website request logs are kept by Vercel only as long as reasonably necessary to deliver, secure, and troubleshoot the site or as otherwise required by law. Vercel Web Analytics records follow the retention available under our Vercel plan and Vercel's terms; Vercel says the temporary visitor session information used for aggregate reporting is discarded after 24 hours.
Access, correction, and privacy rights
Because the current app does not send its local records to us, Sfumato Studios cannot access, correct, or delete those records remotely. A parent can review or change relevant information in the Parent area and can erase app-controlled local records using Reset all data.
You may contact us to ask what support or other information we hold about you, request a correction or deletion, or exercise other privacy rights available where you live. We may need to verify a request and may retain information where required or permitted by law. We will respond as required by applicable law.
For a RevenueCat purchase-record request, include the anonymous Purchase support ID shown in Umka's Parent Settings. Do not include a child's name, answers, learning history, Parent PIN, or selected-app information. Deleting a RevenueCat record does not cancel an Apple subscription; subscriptions are managed through Apple.
Security
We use administrative, technical, and organizational safeguards designed for the limited information described in this policy. Umka minimizes remote data, keeps child learning and app-selection information on the device, and stores the Parent PIN in the iOS Keychain. No storage or transmission method can be guaranteed completely secure.
United States processing and international users
Sfumato Studios is based in the United States. Vercel, email, and infrastructure providers may process the limited website or support information described in this policy in the United States or other countries where they operate, subject to applicable safeguards.
Changes to this policy
We may update this policy when Umka, our providers, or legal requirements change. We will post the revised policy with a new "Last updated" date. If a change introduces or materially expands remote collection, we will update the relevant notice and obtain any permission required by law before the change takes effect.
Contact us
Sfumato Studios LLC operates Umka: Math for Screen Time.
For privacy questions, access or deletion requests, or support, email support@learnwithumka.com.