Privacy Policy
Last updated: May 27, 2026
Introduction
Kumbuku (“Kumbuku,” “we,” “us,” or “our”) is a personal growth and self-alignment platform operated by Dunwell Labs LLC. This Privacy Policy explains how we collect, use, store, and protect your information when you use kumbukuremember.com and the Kumbuku web application (together, the “Service”).
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
We do not sell your personal data. We do not share your data with third parties except as needed to operate the Service, as described below. We do not use Google Calendar data for advertising or any purpose beyond the calendar import feature.
Information We Collect
We collect information in the following categories:
Account information
When you create an account, we collect your email address, an optional phone number, and a password. Passwords are hashed using bcrypt before storage — we never store your password in plain text.
Content you create
The Service is built around personal growth content you choose to store. This may include notes, actions, goals, habits, values, affirmations, journal entries, and similar data you enter or upload.
Google Calendar data
If you choose to connect your Google account, we access your Google Calendar events on a read-only basis. We only access calendar data when you explicitly connect Google and use the import feature. See the Google Calendar Data section below for full details.
File attachments
If you attach images or other media to notes, those files are stored in Amazon Web Services (AWS) S3.
Usage data
We collect activity logs, timestamps, and change history related to your use of the Service. This helps us provide features such as activity streams and maintain the integrity of your data.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate you and manage your account
- Store and display your personal growth content
- Import calendar events into Kumbuku when you use the Google Calendar connection (read-only)
- Process subscription payments through Stripe (we do not store payment card data)
- Send optional SMS reminders and verify phone numbers through Twilio, only if you opt in
- Power AI features such as daily note distillations, action extraction, and weekly reflections by sending relevant note content to OpenAI for processing
- Improve reliability, security, and support
We do not use your content to train AI models. When we send data to OpenAI, it is used for inference to deliver a specific feature response to you — not for model training.
Google Calendar Data
This section describes how Kumbuku handles data obtained through the Google Calendar API. It applies only if you choose to connect your Google account.
- Read-only access. We request read-only access to your Google Calendar. We do not create, modify, or delete calendar events on your behalf.
- Explicit connection only. We access your calendar only after you explicitly connect your Google account and use the calendar import feature.
- Limited use. Google Calendar data is used solely to let you import calendar events as actions or planning items within Kumbuku. We do not use Google user data for advertising, marketing, profiling, or any purpose other than this import feature.
- Limited retention. We do not store raw Google Calendar event data beyond what you explicitly choose to import into Kumbuku as part of your account content.
- No sale or sharing. We do not sell, rent, or share Google user data with third parties. Google Calendar data is not shared except as necessary to operate the import feature through Google's own API infrastructure.
- Revoke access anytime. You can disconnect Google Calendar at any time from your Kumbuku account settings, or revoke Kumbuku's access from your Google Account permissions. After revocation, we will no longer access your calendar data.
Kumbuku's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Third-Party Services
We work with trusted third-party providers to operate the Service. Each provider receives only the data needed for their role:
- Google Calendar API — read-only calendar access to import events when you connect your account
- Twilio — optional SMS reminders and phone number verification
- Stripe — subscription and payment processing; Stripe handles payment card data directly and we do not store it
- OpenAI — AI-powered features; note content may be sent for inference only, not for model training
- AWS S3 — storage for file attachments uploaded to notes
- Heroku — backend application hosting
- Cloudflare — DNS and content delivery network (CDN)
Data Storage and Security
We take reasonable measures to protect your information:
- Account authentication uses JSON Web Tokens (JWT) for secure session management
- Passwords are stored using bcrypt hashing
- File attachments are stored in AWS S3
- Application infrastructure is hosted on Heroku with DNS and CDN services provided by Cloudflare
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.
Data Retention
We retain your account data and content for as long as your account is active. If you request account deletion, we will delete or anonymize your personal data within a reasonable timeframe, except where we are required to retain certain information by law (for example, payment records processed through Stripe).
Disconnecting Google Calendar stops future access to your calendar but does not automatically delete content you previously imported into Kumbuku. You may delete imported items manually or request full account deletion.
Your Rights
Depending on where you live, you may have rights regarding your personal data. We will honor reasonable requests to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Revoke Google Calendar access at any time via Kumbuku settings or your Google Account
- Opt out of optional SMS reminders
To exercise these rights, contact us at hello@kumbukuremember.com. We will respond within a reasonable time.
Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Continued use of the Service after changes are posted constitutes acceptance of the updated policy. For significant changes, we may provide additional notice through the Service or by email.
Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Dunwell Labs LLC
Email: hello@kumbukuremember.com