Libercube Privacy Policy

Publication date: 2026-09-03
Effective date: 2026-09-03

Welcome to our product. Libercube (the "Product and Services") is developed and operated by LumiLoki (Chongqing) Tech Co.,Ltd. ("we", "us", or "our"), which is the data controller for personal information processed under this Policy. Protecting your data security and privacy is our top priority. This Privacy Policy describes the data we collect when you access and use our Product and Services, and how that data is processed. This app is provided as a free service.

This Privacy Policy applies to the Libercube App and related products and services that we provide directly and that expressly reference this Policy, including account services, smart cube Bluetooth connection, color recognition, training and result records, and 1v1 online matches. For third-party services accessed through Libercube, those third parties may process your personal information under their own privacy policies. We describe them in the "Third-Party Services" section below.

Please read this Privacy Policy carefully and make sure you fully understand all of its rules and key points before continuing to use our product. By choosing to use the Product and Services, you acknowledge this Privacy Policy. If you do not agree to this Policy or any of its terms, you should stop using our Product and Services, or stop using the specific features related to those terms. Where we rely on consent under the GDPR or similar laws, you may withdraw that consent as described below without affecting the lawfulness of processing before withdrawal.

This Privacy Policy helps you understand:

This product is currently available on the App Store in the United States and in the European Union / European Economic Area. We process personal information in accordance with applicable U.S. law (including COPPA and, where applicable, the California Consumer Privacy Act / California Privacy Rights Act, CCPA/CPRA) and, for users in the EU, EEA, or United Kingdom, the GDPR or UK GDPR.

How We Collect and Use Your Personal Information

Personal information (or personal data) means information that identifies or can reasonably be linked to a natural person. We follow the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, and storage limitation. All information you provide comes from you (or, for child users, a parent or guardian) when you actively provide it during registration or use of related features, or is generated when you use the Services.

Specifically, we collect and use information in the following scenarios:

1. Registration, login, account management, and parental consent. This product is intended for users of all ages, including children. When a user is a child or minor, account registration must be completed by a parent or guardian: the registration flow requires a parent/guardian email address, which we use to send verification information. A child account is created and activated only after verifiable parental consent is obtained. We process: the parent/guardian email address and verification status; user account ID; login status and necessary authentication information; and account information you actively authorize through third-party sign-in services (Apple, Google, or Facebook). This information is used to verify the guardian's identity, create and manage the account, keep you signed in, prevent account abuse and unusual logins, and sync account-related data. We do not ask you for third-party account passwords unrelated to the login feature. A parent or guardian may contact us at any time through the verified email address to access or correct a child's account information, or to request account deletion or withdrawal of consent.

2. User profile. When you set or update your profile, we may process your nickname, avatar, bio, user ID, and other public or semi-public profile information associated with your account, in order to display your profile and identify you in matches, records, leaderboards, and similar contexts. Please do not include unnecessary sensitive information such as ID numbers, bank card details, or home addresses in your nickname, avatar, or bio.

3. Smart cube and Bluetooth. When you actively connect a smart cube, the App will request Bluetooth access and process technical data necessary to establish, maintain, and restore the device connection, including Bluetooth connection status, device connection information, cube state, and rotation or operation status. This is used to discover and connect devices, sync the physical cube state to the App in real time, restore connections, and provide training, timing, and analysis features. We do not actively read data from other Bluetooth devices unrelated to this service merely because you use Bluetooth.

4. Camera and cube color recognition. When you actively use cube color recognition or other camera-based features, we may request camera permission to capture cube color information and to help recognize or enter cube state. Camera frames and original images used for cube color recognition are processed only on your device. We do not upload original camera frames or photos to our servers for this feature.

5. Photos and avatars. When you actively choose a local image as your avatar or for other image-based features, we may request access to the photo you select. We only access the image you choose and do not read your entire photo library merely because you set an avatar. If you upload an avatar, that avatar may be uploaded to our cloud storage and associated with your account.

6. Training, results, and cube usage data. When you use training, timing, algorithms, solvers, cube records, or similar features, we may process training records, completion times, operation results, cube state, solver results, scores, and other business records associated with your account, in order to save your training and usage history, display past results, calculate statistics, and improve the product experience. The actual scope of collection depends on the features currently provided.

7. 1v1 online matches. When you use online match features, we may process user ID, player nickname and avatar, matchmaking information, room or match identifiers, match status, real-time operation data, match time and results, records, ranking or rating information, and technical information necessary to establish a real-time network connection. This is used for player matching, creating and maintaining match rooms, syncing live match state, determining results, saving records, and maintaining fair play and system security. To prevent cheating, fabricated results, or disruption of fair competition, we may perform necessary security analysis of unusual match behavior. Because this feature involves real-time interaction and mutual visibility of nicknames and avatars, we do not provide open text chat or private messaging. During a match, we only display timing, solve status, and other information related to the match itself, in order to reduce risks for child users in interactive features.

8. Product analytics. To understand product usage and improve the experience, we may use analytics services such as PostHog to process App usage and interaction events, App version, operating system version, device type, feature usage, and necessary technical identifiers. We do not sell your personal information merely because we use product analytics.

9. Crash and diagnostic information. To discover and fix software faults, we may use services such as Firebase Crashlytics to process crash logs, App state, device model, operating system version, App version, and other diagnostic information, in order to locate crashes, analyze errors, and improve product stability and security.

Legal Bases for Processing (GDPR / UK GDPR)

If you are in the European Union, the European Economic Area, or the United Kingdom, we process personal data only where a legal basis applies, including:

You may withdraw consent at any time as described in "Your Rights". Withdrawal does not affect processing that was lawful before withdrawal.

Device Permissions

We request system permissions only when a related feature requires them. You may manage these permissions at any time in your device settings.

How We Store and Protect Your Personal Information

We retain your personal information only for as long as needed to fulfill the purposes for which it was collected (for example, while you maintain an account to receive services from our product). In general, basic account information is retained for the life of the account; training records, match records, and similar business data are retained for as long as needed to provide history, statistics, and security features; and crash and analytics logs are retained according to the actual configuration of the relevant services. To comply with legal obligations, or to establish, exercise, or defend legal claims within applicable limitation periods, we may need to retain archived personal information after those periods expire and may be unable to delete it upon request. When your personal information is no longer needed, we will ensure it is fully deleted or anonymized. If you confirm that you will no longer use our Product and Services and actively delete your account as required, all information will be fully deleted except where retention is required by law.

We use industry-standard security measures to protect the personal information you provide, including access control, identity authentication, transmission encryption, database permission management, key and credential management, logging and anomaly monitoring, security updates, and data backup and recovery, to prevent unauthorized access, public disclosure, use, modification, damage, or loss.

No internet service can guarantee absolute security. If a personal information security incident occurs that may affect users' rights and interests, we will take remedial measures and fulfill applicable notification or reporting obligations under applicable law, including GDPR breach-notification rules where they apply.

Service Region, Storage Location, and International Transfers

This product is currently available on the App Store in the United States and in the European Union / European Economic Area. User authentication, database, and file storage services (Supabase) are located in East US (Ohio). Real-time online match sync services (Colyseus) are located in the United States. Analytics events are processed by PostHog in the United States.

The data controller, LumiLoki (Chongqing) Tech Co.,Ltd., is established in China. Personal information is stored in the United States. Authorized personnel may access that information from China as needed to operate, support, and secure the Services.

If you are in the EU, EEA, or United Kingdom, transferring your personal data to the United States and making it accessible from China is an international transfer. Where required by GDPR or UK GDPR, we take steps to implement appropriate safeguards for such transfers. You may contact us at the email below for more information about the safeguards that apply in your case.

Your Rights

Depending on your jurisdiction, you (or, for child users, a parent or guardian) may have the rights described below. We will respond within the time required by applicable law (generally one month under the GDPR, and 45 days under the CCPA/CPRA, subject to permitted extensions). Submit requests to software@lumiloki.com or through the in-product feedback channel. We may need to verify your identity (and, for a child account, the parent–account relationship) before fulfilling a request.

GDPR / UK GDPR (EU, EEA, and UK users). You may have the right to access personal data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).

CCPA/CPRA (California residents). You may have the right to know the categories and specific pieces of personal information we collect, use, and disclose; to request deletion or correction; and to non-discrimination for exercising your rights. We do not sell personal information and we do not share personal information for cross-context behavioral advertising. In the last 12 months we have collected the categories described in this Policy (identifiers such as account ID and email; customer records such as profile and account data; internet or electronic activity such as App usage and crash diagnostics; and inferences such as match ratings where applicable) for the purposes stated above. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, other than as needed to provide the Services.

COPPA. Parents of children under 13 in the United States may review, refuse further collection of, or request deletion of their child's personal information, as described in "How We Handle Children's Personal Information".

For child users, the rights above are exercised by the parent or guardian who completed registration verification. Withdrawal of consent does not affect processing that was lawfully based on valid authorization before withdrawal. After you turn off a permission, features that directly depend on that permission may become unavailable, but other features that do not depend on it and can operate independently will not be affected.

Account Deletion and Cancellation

If you (or a child user's parent or guardian) no longer wish to use Libercube, you may request account deletion through the relevant in-app feature. For a child account, the deletion request should be initiated by the parent who completed registration verification, using the verified email or the contact details at the end of this Policy. Account deletion typically includes: stopping the provision of services through that account; deleting or unlinking user profile information; deleting account-related personal information that no longer needs to be retained; clearing related login status and authentication information; and handling associated data such as avatars and settings as applicable.

For a limited amount of information that we are required by law to retain, or that we have a legitimate need to retain for network security, dispute resolution, or fraud prevention, we may continue to store it for the necessary period to the extent permitted by law, and restrict its use during that period. For users who sign in with a third-party account, we will also handle related authorizations in accordance with the relevant platform and applicable rules during account deletion. Once an account is deleted, some data may not be recoverable. Please proceed with care.

How We Share, Transfer, or Publicly Disclose Your Personal Information

We will not provide your personal information to third parties without a legitimate basis, will not sell personal information as a business model, and will not sell user personal information for direct monetary consideration. To provide product features (such as cloud database, cloud storage, sign-in services, crash analysis, product analytics, and real-time match networking), we engage the third-party service providers listed later in this Policy to process necessary information as processors or service providers, and require them to process it within a reasonable scope in accordance with applicable law and our agreements.

We may share your personal information externally as required by laws and regulations, or pursuant to lawful requests such as court orders or subpoenas. Where permitted by law, when we receive such a disclosure request, we will require corresponding legal documents. We believe that, to the extent permitted by law, we should remain as transparent as possible about the information we are required to provide.

In the following circumstances, sharing, transferring, or publicly disclosing your personal information does not require your prior consent:

Third-Party Services

Please note that this app uses third-party services that have their own privacy policies governing data processing. The third-party providers currently used, and their purposes, are as follows:

We will update the third-party service list above as product features and third-party services change.

How We Handle Children's Personal Information

This product has an App Store age rating of 4+ and is intended for users of all ages, including children. We understand that a large number of our users are children, so we have designed the following dedicated protections:

For users in the United States, we process personal information of children under 13 in accordance with COPPA, including obtaining verifiable parental consent before collection. For users in the EU, EEA, or United Kingdom, where we offer information society services directly to a child, we obtain consent from a parent or holder of parental responsibility in line with the applicable digital consent age (16 under the GDPR, unless a Member State has set a lower age of not less than 13). We apply dedicated protections before creating and activating a minor's account.

If we discover that we have collected a child's personal information without first obtaining verifiable parental consent, we will take steps to delete the related data as soon as possible. If you are a parent or guardian of a minor and have any questions about the minor's use of our services or the information provided to us, please contact us promptly using the details at the end of this Policy.

Changes to This Privacy Policy

Our features, third-party services, or legal requirements may change, so we may update this Privacy Policy from time to time. For material changes, we will provide reasonable notice in accordance with applicable law, such as in-app notices, pop-ups, or on-page prompts. We therefore recommend that you review this page regularly for updates. If any changes are made, we will post the new Privacy Policy on this page, and the updated Policy will apply from the stated effective date.

This version is effective as of 2026-09-03 and applies to users in the United States and the European Union / European Economic Area. If we later adjust service regions, data processing practices, or if legal requirements change, we will update this Policy to reflect the actual situation and notify you in advance as required by applicable law.

Contact Us

If you have any questions, comments, complaints, or requests about this Policy, our processing of personal information, or your personal information rights, please contact our support team at software@lumiloki.com or through the in-product feedback channel. We will do our best to respond and resolve your issue within the time required by applicable law.

We have not appointed an EU or UK representative under Article 27 GDPR / UK GDPR. You may contact the controller directly using the details above.