Deku
DEKUDOCS
v1.0
Home/Privacy Policy

PRIVACY POLICY

Versionv2.2
EffectiveJune 1, 2026
UpdatedMay 22, 2026
EntityDeku Studios LLC

1.Introduction

Deku Studios LLC ("Deku Studios," "we," "us," or "our") operates the Deku Studios mobile applications, websites (including deku.net and docs.deku.net), and related services (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Platform.

By creating an account or using the Platform, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy is incorporated into and governed by our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

U.S.-Focused Policy. The Platform is intended for users in the United States. Where required by applicable U.S. state privacy law, we provide additional disclosures and choices, as set forth in Section 8. The Platform is not directed to individuals outside the United States, and we do not knowingly collect personal data from individuals outside the United States.

2.Information We Collect

2.1Information You Provide Directly

We collect information that you provide when you create an account, participate in contests, make deposits or withdrawals, or contact us:

Account Information. Name, email address, username, display name, and avatar selection. If you sign in through Apple or Google, we receive the information you authorize those providers to share (typically name and email address).

Identity Verification Information. When you complete identity verification (KYC) through our third-party identity-verification provider, we receive a photograph of your government-issued identification document, a selfie photograph, and information extracted from your identification document (including full legal name, date of birth, address, and document number). Biometric identifiers (such as the facial-match comparison vector) are processed and retained by the verification provider pursuant to its policies; we retain only the verification results and related records as necessary for compliance, fraud prevention, and dispute resolution. See Section 2.4 for additional biometric-information notice.

Financial Information. When you make deposits or withdrawals, our third-party payment processors collect your payment credentials (credit- or debit-card number, bank-account information, or PayPal-account information). Deku Studios does not directly collect, store, or have access to your full card numbers or bank-account numbers. We receive and store transaction records including amounts, dates, payment-method type, and transaction status.

Tax Information. If your net contest winnings in a calendar year reach or exceed two thousand dollars ($2,000), the Form 1099-MISC reporting threshold applicable for calendar year 2026 under 26 U.S.C. § 6041(a) and IRS Publication 1099 (2026), we collect your Social Security Number ("SSN") or Individual Taxpayer Identification Number ("ITIN") for tax-reporting purposes, and we may collect backup-withholding information under 26 U.S.C. § 3406.

Communications. When you contact us for support or other inquiries, we collect the content of your messages, your email address, and any attachments you provide.

2.2Information Collected Automatically

When you use the Platform, we automatically collect certain information about your device and activity:

Device Information. Device model, operating system and version, application version, screen resolution, device language and locale, time zone, and unique device identifiers.

Location Information. With your permission, we collect precise GPS coordinates from your device to verify that you are in an Eligible Jurisdiction before you enter a cash-entry contest. We also collect the state or jurisdiction determined from your GPS coordinates. Location data is collected at the time of each contest entry and is not continuously tracked in the background.

Gameplay Data. For each contest you enter, we collect your submissions (words, swipe paths, plant routing, sudoku cell-fills, or other contest-specific inputs), scores, input timing, game-session duration, and contest results. We may also record input-replay data (touch positions, swipe paths, and timestamps) for anti-cheat purposes.

Usage Data. Screens viewed, features used, actions taken, time spent on the Platform, and crash or error logs.

Network Information. IP address, VPN or proxy detection signals, and connection type.

2.3Information from Third Parties

We may receive information about you from our third-party service providers:

Authentication Providers. If you sign in with Apple or Google, we receive the profile information you authorize.

Identity Verification Provider. Verification results including approval or rejection status, document-authenticity assessment, facial-match confidence score, liveness-check result, and anti-money-laundering screening results.

Payment Processors. Transaction status updates, dispute notifications, and fraud-risk assessments.

2.4Biometric Information Notice (BIPA, Tex. Bus. & Com. Code § 503.001, Wash. Rev. Code § 19.375)

In connection with our KYC workflow, biometric identifiers (specifically, a facial-image template and liveness-detection data) may be processed by our verification provider to compare the live selfie to the government-issued identification document. Certain U.S. states impose separate consent and notice requirements for the collection, use, retention, and destruction of biometric identifiers, including the Illinois Biometric Information Privacy Act, 740 Ill. Comp. Stat. 14/1 et seq. ("BIPA"); the Texas Capture or Use of Biometric Identifier Act, Tex. Bus. & Com. Code § 503.001; and the Washington biometric-identifier statute, Wash. Rev. Code § 19.375.020. The Platform collects affirmative written consent prior to processing biometric identifiers from users in these jurisdictions through the in-app KYC consent flow and retains biometric data only for the duration permitted under applicable state law (and in no event longer than three (3) years after the user's last interaction with the Platform). Biometric data is not sold, leased, traded, or otherwise profited from.

3.How We Use Your Information

We use the information we collect for the following purposes:

Platform Operation. To create and manage your account, process contest entries, calculate scores, distribute prizes, process deposits and withdrawals, and provide customer support.

Legal Compliance. To verify your age, verify your identity, verify your geographic location, comply with anti-money-laundering and OFAC sanctions-screening requirements, comply with federal tax-reporting obligations under 26 U.S.C. §§ 6041(a) and 6050W, comply with backup-withholding requirements under 26 U.S.C. § 3406, and respond to legal process.

Fair Play and Integrity. To detect and prevent cheating, bot usage, multi-accounting, collusion, external-solver use, and other prohibited conduct; and to monitor gameplay data for anomalies and conduct human review of flagged sessions.

Safety and Security. To detect and prevent fraud, unauthorized access, and other illegal activity; and to protect the security and integrity of the Platform.

Communication. To send you transactional communications (contest results, deposit confirmations, withdrawal status, account alerts), respond to your support inquiries, and send service announcements.

Improvement. To analyze usage patterns, diagnose technical issues, and improve the Platform's features and performance.

Responsible Gaming. To enforce deposit limits, self-exclusion periods, and other responsible-gaming controls you have configured.

4.How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

4.1Third-Party Service Providers

We share information with third-party service providers who process data on our behalf to operate the Platform. These providers include services for authentication and session management, payment processing, identity verification and compliance screening, player-funds banking, content delivery and security, application hosting, transactional email delivery, and push notifications. These providers are contractually required to use your information only for the purposes of providing services to us and to maintain appropriate security measures.

We may disclose your information when required to do so by law, regulation, legal process, or governmental request. This includes responding to subpoenas, court orders, or other legal process, and cooperating with law-enforcement or regulatory authorities, including in connection with OFAC sanctions screening, FinCEN information requests under USA PATRIOT Act § 314(a), and grand-jury subpoenas.

4.3Tax Reporting

We report contest winnings to the Internal Revenue Service as required by law. If your net winnings in a calendar year reach or exceed the applicable Form 1099-MISC reporting threshold (currently two thousand dollars ($2,000) for calendar year 2026 under 26 U.S.C. § 6041(a) and IRS Publication 1099 (2026)), we will file an IRS Form 1099-MISC that includes your name, address, SSN or ITIN, and the amount of winnings. Our payment processor may separately issue Form 1099-K for payments meeting the 26 U.S.C. § 6050W threshold.

4.4Protection of Rights

We may disclose your information when we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

4.5Business Transfers

If Deku Studios is involved in a merger, acquisition, bankruptcy, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you of any such change by posting notice on the Platform or by email.

4.6Aggregated and De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you (for example, aggregate statistics about contest participation, average scores, or Platform usage trends).

4.7Sharing With Other Players

When you participate in contests, certain information about you — your username, in-app profile (display name and avatar), in-app actions and achievements, and contest results — may be visible to other Players and may become publicly available within the Platform.

5.Data Retention

We retain your personal information for as long as your account is active and for the periods described below after account closure or data collection. After the applicable retention period, data is archived to cold storage and subsequently deleted in accordance with our internal data-lifecycle procedures. We do not hard-delete compliance records before the retention period expires.

Data TypeRetention PeriodRationale
Account information (name, email)Duration of account + 7 yearsTax and regulatory compliance
Transaction records7 years from transaction dateIRS financial-record requirements
Geofence-verification records7 yearsRegulatory audit evidence for state compliance
Age-verification records7 yearsProof of age-gate enforcement
KYC documents and verification results7 years after account closureAML/KYC regulatory retention
Biometric dataNot longer than 3 years after last interaction, or as required by BIPA / Tex. Bus. & Com. Code § 503.001 / Wash. Rev. Code § 19.375.020Biometric-statute compliance
Gameplay data and contest results7 yearsDispute resolution, anti-cheat review, regulatory compliance
Device informationDuration of account + 7 yearsAnti-cheat context, fraud investigation
Tax records (SSN, 1099 filings)7 years from applicable tax yearIRS requirements
Support communications3 years from resolutionCustomer-service quality

6.Data Security

We implement technical, administrative, and physical security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction:

Encryption. All data is encrypted in transit using TLS (Transport Layer Security). Data at rest is encrypted using industry-standard encryption at the database and infrastructure level.

Access Controls. Access to personal information is restricted to authorized personnel on a need-to-know basis. Administrative access is role-based with all actions logged in an audit trail.

Payment Security. We are PCI-compliant through our payment-processor integrations. Card data is tokenized before it reaches our servers. Full card numbers never touch Deku Studios systems.

Authentication Security. Player authentication supports Apple Sign-In, Google Sign-In, and email-based authentication. Multi-factor authentication is enforced for administrative access.

Monitoring. We employ automated fraud detection, transaction monitoring, and security alerting.

While we take commercially reasonable steps to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

7.Your Rights and Choices

7.1Account Information

You may update your account information (display name, email address, avatar) at any time through the Platform's settings.

7.2Location Permissions

You may revoke location permissions through your device settings at any time. If you revoke location permissions, you will be unable to enter cash-entry contests but may continue to use free-play features.

7.3Push Notifications

You may opt out of push notifications through your device settings or within the Platform's notification preferences.

7.4Account Deletion

You may request deletion of your account at any time through one of two channels: (i) within the Platform's iOS or Android application, by navigating to Profile → Privacy & Security → Delete Account and confirming by typing "DELETE" in the confirmation field; or (ii) by contacting support@deku.net. Both channels are processed through the same back-end deletion workflow and produce the same outcome.

Pre-Deletion Review. Before a deletion request is finalized, the Platform reviews your account for circumstances that warrant additional handling, including a positive cash-wallet balance, pending withdrawals, open disputes, active tournament entries, open support tickets, or calendar-year prize payouts that have reached the federal tax-reporting threshold. These conditions do not block your right to delete, but may require additional steps before completion.

Grace Period. If, at the time of your deletion request, your cash-wallet balance is greater than zero, your account enters a seven (7)-day grace period during which you may withdraw your remaining cash balance through the Platform's standard withdrawal flow (subject to identity verification and applicable processing times). During the grace period, your account remains accessible solely for the purpose of completing withdrawals; you may also cancel the deletion request and resume normal use of your account. If your cash-wallet balance is zero at the time of your deletion request, no grace period applies.

Forfeiture and Effect of Deletion. Upon expiration of the grace period (or, if no grace period applies, upon administrative review), your account will be deactivated and: (i) any remaining cash-wallet balance is forfeited; (ii) any remaining Acorns and Bonus Cash are forfeited; (iii) your personal information (including email address, display name, and avatar) is anonymized; (iv) financial transaction records, identity-verification records, and other compliance records are retained for the periods described in Section 5 and applicable law; and (v) the email address associated with your account may not be used to create a new Deku Studios account for thirty (30) days following the completion of deletion.

Cancelling a Deletion Request. While your deletion request is pending, you may cancel the request from within the application or by contacting support@deku.net, which will restore your account to its prior state. Once deletion is completed, it cannot be reversed.

7.5Data Access and Portability

You may request a copy of the personal information we hold about you by contacting privacy@deku.net. We will provide your data in a commonly used, machine-readable format within forty-five (45) days, subject to applicable identity-verification requirements.

8.U.S. State Privacy Rights

Depending on your state of residence, you may have additional rights under applicable U.S. state privacy laws, including the right to know, the right to delete, the right to correct, the right to opt out of certain processing activities (such as targeted advertising, sale, or profiling), and the right to data portability. The state privacy laws under which these rights may be conferred include:

  • California Consumer Privacy Act / California Privacy Rights Act, Cal. Civ. Code §§ 1798.100 et seq.
  • Virginia Consumer Data Protection Act, Va. Code §§ 59.1-575 et seq.
  • Colorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1301 et seq.
  • Connecticut Data Privacy Act, Conn. Gen. Stat. §§ 42-515 et seq.
  • Utah Consumer Privacy Act, Utah Code §§ 13-61-101 et seq.
  • Texas Data Privacy and Security Act, Tex. Bus. & Com. Code §§ 541.001 et seq.
  • Oregon Consumer Privacy Act, Or. Rev. Stat. §§ 646A.570 et seq.
  • Montana Consumer Data Privacy Act, Mont. Code Ann. §§ 30-14-2801 et seq.
  • Iowa Consumer Data Protection Act, Iowa Code §§ 715D.1 et seq.
  • Tennessee Information Protection Act, Tenn. Code Ann. §§ 47-18-3201 et seq.
  • Indiana Consumer Data Protection Act, Ind. Code §§ 24-15-1-1 et seq.
  • Florida Digital Bill of Rights, Fla. Stat. §§ 501.701 et seq.
  • New Jersey Data Privacy Act, N.J. Stat. §§ 56:8-166.4 et seq.
  • New Hampshire Data Privacy Act, N.H. Rev. Stat. §§ 507-H:1 et seq.
  • Delaware Personal Data Privacy Act, Del. Code tit. 6, §§ 12D-101 et seq.
  • Maryland Online Data Privacy Act, Md. Code Ann., Com. Law §§ 14-4601 et seq.
  • Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325O.05 et seq.
  • Rhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws §§ 6-48.1-1 et seq.
  • Kentucky Consumer Data Protection Act, Ky. Rev. Stat. §§ 367.3611 et seq.

8.1California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the rights described in the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"): the right to know what personal information we collect about you, the right to delete personal information, the right to correct inaccurate information, the right to opt out of sale or sharing for cross-context behavioral advertising, the right to limit use of sensitive personal information (as defined in CCPA), and the right to non-discrimination.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

Categories of personal information collected. Under CCPA categories, we collect: identifiers (name, email, SSN/ITIN where applicable); personal information under Cal. Civ. Code § 1798.80 (name, address, financial information); protected-classification characteristics (age, date of birth); commercial information (transaction records, contest history); internet or electronic-network activity (usage data, device information); geolocation data (GPS coordinates); sensory data (selfie and ID photographs for KYC); sensitive personal information under CCPA § 1798.140(ae) (SSN/ITIN, government-ID information, biometric data, precise geolocation); and inferences drawn from the above (fraud-risk scores, skill ratings).

How to exercise your rights. To exercise any state privacy right, contact us at privacy@deku.net or submit a request through the Platform's settings. We will verify your identity before processing your request. You may designate an authorized agent to submit a request on your behalf with written authorization. We will respond within forty-five (45) days, subject to extensions permitted by applicable law.

Right to appeal. If we deny your request, you may appeal by submitting a request to privacy@deku.net with the subject line "Privacy Appeal." We will respond to appeals within sixty (60) days. If your appeal is denied, you may contact your state attorney general to submit a complaint.

9.Children's Privacy

The Platform is not intended for children under the age of eighteen (18). We do not knowingly collect personal information from children under thirteen (13), and we do not permit users under the age of eighteen (18) on the Platform. If we become aware that we have collected personal information from a child under thirteen (13), we will promptly delete that information. For full details on our compliance with the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 ("COPPA"), see our COPPA Compliance Statement.

If you are a parent or guardian and believe your child under thirteen (13) has provided us with personal information, please contact us at privacy@deku.net.

10.International Users

The Platform is currently available only in the United States. If you access the Platform from outside the United States, you understand and consent to the transfer, processing, and storage of your information in the United States, where data-protection laws may differ from those of your country.

The Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access.

12.Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform and, where practicable, by sending notice to the email address associated with your account. The "Last Updated" date at the top of this policy indicates when it was most recently revised. Your continued use of the Platform after the effective date of any changes constitutes acceptance of the updated Privacy Policy.

13.Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Privacy Inquiries & Appeals: privacy@deku.net

General Support: support@deku.net

Mail: Deku Studios LLC, 418 Broadway #11209, Albany, NY 12207

Website: https://deku.net