Kokonenne Privacy Policy · Version 2.0

Operator: SnackApp
Contact: snackappthss@gmail.com

Kokonenne helps caregivers play sleep sounds. It has no name or email sign-up, baby profiles, microphone recording or location-tracking feature.

On-device information
Language, player settings, favorites, presets and verified access are stored on your device. Audio is bundled with the app and is not streamed for playback. Uninstalling removes local information. System backup of app data is disabled.

Service information
An anonymous installation identifier derived from an Android Keystore public key and Google Play Integrity verify requests. The private key remains on your device. The server stores the public key and temporary API-session hashes; salted network-address hashes limit abusive requests. The service processes product IDs, encrypted Play purchase tokens, purchase state and expiry, as well as reward sessions, completion times and transaction identifiers. These support purchase restoration, reward verification, renewals, refunds and abuse prevention. Google Play handles payment; the app does not collect card details.
If you enter an access code, the server verifies it and stores its hashed reference and enabled status with your anonymous identifier. The plaintext code is not stored on your device or in the entitlement database. This optional information enables the access granted by the code and is removed with your service profile.

Advertising
Google AdMob and consent-management tools are used. Google may process IP addresses, device and advertising identifiers, app interactions and diagnostic information for ad delivery, measurement and fraud prevention. Consent notices are shown where applicable. Available ad privacy choices can be changed in Settings. Ads are not shown during playback. Declining reward ads does not prevent free online playback.

Providers and international processing
Google Play handles purchases and app integrity; AdMob handles advertising. Cloudflare Workers and D1 process and store anonymous installation identifiers, verified purchase records, reward sessions and access-code associations. This global service is not restricted to Seoul; data may be processed in countries where Cloudflare and Google operate. Firebase Spark Hosting serves public policy and support pages only, without Firebase authentication or an entitlement database. The providers' policies and applicable consent choices also apply.
https://policies.google.com/privacy
https://www.cloudflare.com/privacypolicy/

Retention and deletion
Local settings remain until you delete them. Purchase verification records are retained for restoration and refund processing. Reward sessions are scheduled for deletion after 7 days and reward deduplication records after 30 days. Request-limit records are eligible for deletion after 2 minutes, authentication challenges after 5 minutes, and API sessions after 1 hour. A bounded hourly cleanup processes expired records, so actual deletion may be delayed by workload or service outages. Contact support to request deletion; only information necessary to verify the request will be requested. Any legal or dispute-related retention will be explained with its purpose and period.

Service outages
A server error does not immediately revoke previously verified access. Its verified expiry and the current-session protection rules continue to apply. Refunds and changed purchase status take effect at the next successful online verification; they cannot be delivered immediately to an offline device.

Changes
Changes to processed data, purposes or providers will be disclosed in the app and on the public policy page.