Privacy Policy
tk2 labs, llc (“we,” “us,” or “our”) operates mpath (the app and website at plaympath.com, together the “Service”). This policy describes what mpath specifically collects, how advertising and purchases work, and your privacy rights.
‘Personally Identifiable Information’ (‘PII’) is information that can be used on its own or with other information to identify, contact, or locate a single person.
What personal information do we collect from people that use mpath?
mpath is designed so that no personal information is required to use it. There is no account, no login, and no email address collected anywhere in the app or on the website. Every puzzle — daily and archive — can be played without providing any personal information.
What other information does mpath collect that does not reveal a specific identity?
Your game progress (which equations you’ve found, which puzzles you’ve solved, whether you’ve purchased Premium) is stored only on your own device, using standard local storage (AsyncStorage on iOS, localStorage on web). It is not sent to our servers and is not linked to any identity.
Advertising. mpath is supported by advertising through Google AdMob (iOS) and Google AdSense (web). We are enrolled in AdMob’s Designed for Families (DFF) program:
- Ads shown in mpath are non-personalized for all users — they are not based on your browsing history, interests, or any profile of you.
- Google’s ad-serving systems still receive some non-personal technical data (such as a device or advertising identifier, IP address, and app/session context) in order to deliver an ad, prevent fraud, and cap how often the same ad is shown. This is standard for any ad-supported app and is not used to build a profile of you.
- On the web version, Google’s advertising script may set third-party cookies in your browser for these same purposes. mpath’s own code does not set any cookies.
- We do not request or show ads while the in-app tutorial or the Premium upgrade screen is open.
Purchases. mpath offers an optional one-time “Premium” purchase ($4.99) that removes ads and unlocks additional features. Purchases are processed entirely by Apple’s App Store — mpath never sees or stores your payment details. We use RevenueCat to validate your purchase and keep your Premium status working if you reinstall the app or restore purchases; RevenueCat receives an anonymous purchase record and device identifier for this purpose only.
When do we collect personal information?
We don’t. mpath has no account creation, no login, and no form anywhere that asks for personal information.
How do we protect information?
Puzzle content that mpath downloads travels over encrypted (HTTPS/SSL) connections. The app and website themselves run on Amazon Web Services; the non-personal ad-delivery and purchase-validation data described above is instead handled on Google’s and RevenueCat’s own infrastructure, under their own security practices.
Can I delete, correct, or request a copy of my information?
Because mpath doesn’t collect personal information or maintain user accounts, there is normally nothing tied to you to delete or export. If you believe we’ve collected something in error, or have any other privacy question about mpath specifically, email compliance@numoku.com.
How long do you keep information?
Game progress lives only on your device and is kept until you delete the app or clear its data — we never receive a copy. Non-personal ad-delivery and purchase-validation data described above is retained by Google and RevenueCat under their own respective policies.
Do we use ‘cookies’?
mpath’s own app and website code does not set cookies. On the web version, Google’s advertising script may set third-party cookies for ad delivery, as described under Advertising above. You can control or block these through your browser’s cookie settings.
Third-party disclosure
We do not sell, trade, or otherwise transfer your Personally Identifiable Information to outside parties. Non-personal technical data is shared with Google (AdMob/AdSense) for ad delivery and with RevenueCat for purchase validation, strictly as described above.
Third-party links
mpath’s app and website do not currently link out to third-party sites or services beyond the advertising and purchase-processing integrations described above.
California Online Privacy Protection Act (CalOPPA)
In accordance with CalOPPA, we confirm:
- You can use mpath anonymously — no login is required or offered.
- This privacy policy is linked from the mpath website.
- This policy’s link includes the word “Privacy” and is easy to find.
- You will be notified of changes to this policy on this page.
- There is no account, so there is no personal information to update via login.
California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected about you, request deletion or correction of it, opt out of the “sale” or “sharing” of it, limit use of sensitive personal information, and not be discriminated against for exercising these rights. As described throughout this policy, mpath collects essentially no personal information: there is no account, and the only outside data sharing is the non-personal, non-personalized advertising and purchase-validation data described under Advertising and Purchases above. We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as CCPA/CPRA defines that term — mpath's ads are non-personalized for every user. To exercise any of these rights or ask a question, email compliance@numoku.com.
Other U.S. state privacy laws
Several other states (including Virginia, Colorado, Connecticut, Utah, and others) have their own comprehensive privacy laws with rights similar to CCPA/CPRA. Because mpath collects the same minimal, non-personal information described in this policy regardless of where you live, we extend the same practices — no sale of personal information, no behavioral-advertising sharing, and the same contact path for questions or requests — to residents of those states as well.
European Economic Area, UK, and Switzerland (GDPR)
If you are located in the EEA, the UK, or Switzerland, tk2 labs, llc is the data controller for mpath. Under the GDPR (and the UK and Swiss equivalents), you have the right to access, correct, or erase your data, restrict or object to its processing, and request data portability. As described throughout this policy, mpath collects essentially no personal data — there is no account, and the only outside data sharing is the non-personal, non-personalized advertising and purchase-validation data described under Advertising and Purchases above. Ads shown to every mpath user, everywhere, are non-personalized, regardless of location — we do not operate a separate consent-gathering flow for EEA/UK/Swiss users at this time, since no personalized advertising is served to anyone. To exercise any of these rights or ask a question, email compliance@numoku.com.
How does mpath handle Do Not Track signals?
mpath does not build profiles of users or engage in the kind of cross-context behavioral tracking that Do Not Track signals are designed to address — the only device identifiers used are for ad frequency-capping and fraud prevention, as described under Advertising above. Because there is no behavioral tracking to disable, we do not respond differently to Do Not Track signals.
Does mpath allow third-party behavioral tracking?
No. Ads shown in mpath are non-personalized for all users under Google AdMob’s Designed for Families program — they are not based on behavioral profiling.
COPPA (Children’s Online Privacy Protection Act)
mpath is a general-audience app, not one directed specifically at children — but we serve non-personalized advertising to every user, of any age, as a privacy-protective default rather than as a response to any particular user's age. This is why mpath is enrolled in Google AdMob’s Designed for Families (DFF) program. Where a device or advertising identifier is used (for frequency-capping or fraud prevention, as described under Advertising above), that use falls within COPPA’s “support for internal operations” exception, since it is never used for targeted advertising or combined with other data to build a profile. mpath does not collect personal information from anyone, including children under 13, in a manner subject to COPPA. If you believe information has been collected improperly, email compliance@numoku.com.
Fair Information Practices
Should a data breach occur affecting mpath, we will notify affected users via in-app or in-website notice within 2 business days of verifying the breach, or as soon as practicable. Where the GDPR applies, we will separately notify the relevant supervisory authority within 72 hours of becoming aware of a breach, as required by law. We agree to the Individual Redress Principle: individuals have the right to pursue enforceable rights against data collectors and processors who fail to adhere to the law.
CAN-SPAM Act
mpath does not collect email addresses and does not send marketing email. If you contact us directly, we will only use your email to respond to your inquiry.
Contacting us
Questions about this policy or about mpath’s data practices: compliance@numoku.com