Effective date: August 1, 2026 · Last updated: August 1, 2026
Yummy Monsters: Kids Cooking (“the App”) is made by Yuliia Kulakova, trading as Kulakova Apps (“the Developer”, “we”). The App is designed for children of roughly two to six years old and is listed in the App Store Kids Category, so this policy is written for the grown-up who installed it. It describes version 1.0 of the App for iPhone and iPad, and this website.
None. We do not collect, receive, store, transmit, sell or share any personal information from you or your child. Specifically, we do not collect names, e-mail addresses, postal addresses, telephone numbers, dates of birth, photographs, voice recordings, contacts, location, advertising identifiers, device identifiers, IP addresses, usage analytics, crash reports or any other identifier. (Apple prepares aggregated reports of its own for every developer — what those are, and how to switch them off, is in section 8.)
This is not a promise about how carefully we handle data — it is a description of how the App is built. There is no networking code in the App at all: no web requests, no sockets, no web view, no software development kit that could make one. There is no server belonging to us for information to be sent to, and no account for your child to create.
Exactly two things ever cross the network, and neither one is ours:
The App keeps a small amount of information in its own private storage on your device, so the game remembers where your child got to. We have no access to any of it. In detail, it is:
None of this identifies your child. There is nowhere in the App to type a name, an age or an e-mail address; the only thing anyone ever types is the four digits of an adult’s birth year at the parental gate, and that is not stored (section 7).
We want to be exact here rather than comfortable. The App itself never sends anything anywhere. But everything described in section 2 lives inside the App’s ordinary storage on your device, and iOS includes that storage in your device backup. So if you have iCloud Backup switched on — or if you back the device up to a computer — your child’s progress and dish pictures are part of that backup, exactly like the data of every other app on the device.
That backup is yours and Apple’s, not ours: it is covered by Apple’s privacy policy, it is controlled from Settings on your device, and we can neither see it nor reach it. The App does not use iCloud Drive, CloudKit or any sync of its own — progress does not follow your child from one device to another.
The game is fully playable with every one of these switched off, because each physical gesture also has a plain tap alternative. Nothing here is recorded, stored or transmitted.
Used so a child can blow at the screen to cool hot food. From each short block of incoming sound the App works out one number — how loud it was — compares it against a threshold, and throws the sound away. No audio is recorded, written to disk, saved or transmitted, no speech is recognised, and nothing is sent off the device. The microphone is only listening while a “blow” step is on screen.
iOS asks for microphone permission at one moment only: when an adult switches the “Blow (mic)” gesture on in the Parent Zone. The App never raises that request in the middle of play, where a two-year-old would be the one answering it.
Used for shake-to-sprinkle and tilt-to-pour, read from the accelerometer while the relevant cooking step is on screen. Readings are used in the moment and discarded; nothing is recorded or transmitted.
To be accurate about how iOS works: reading the accelerometer this way does not produce a permission prompt — the “Motion & Fitness” prompt belongs to step-counting and activity history, which the App does not use. We still declare in the App’s information file why motion is used, and an adult can turn both gestures off in the Parent Zone.
Used only to save a picture of a finished dish into your device’s Photos library, and only after a grown-up has passed the parental gate. The App requests add-only access, which means it can place a new picture in your library but cannot read, browse, search or delete anything already there. iOS asks the first time an adult saves a picture; if you refuse, the game carries on normally and the picture simply stays inside the App.
All reminders are local notifications, scheduled by the App on the device itself. There is no push server, no Apple Push Notification token, and nothing leaves the device.
Being precise about when the App asks: iOS shows the notification permission request once, either when an adult turns “Reminders” on in the Parent Zone, or the first time your child finishes cooking a dish. If permission is granted at that moment, reminders are switched on; if it is refused, or never granted, nothing is ever scheduled. An adult can turn them off again in the Parent Zone or in iOS Settings at any time.
When reminders are on there are three of them: one gentle daily invitation to cook, at 4 p.m. local time; a note that a surprise chest is ready; and, after three days away, a “we miss you” note. Notifications are only ever delivered between 10 a.m. and 7 p.m. local time, so one can never arrive while a child is asleep. None of them mentions money, prices or the subscription.
There is no code in the App for any of the following, and no permission for them is ever requested: the camera, location, contacts, calendars, reminders, Bluetooth, local network, health or fitness data, Face ID, speech recognition, or App Tracking Transparency. There is no sign-in, no social login, no chat, no messaging, no user-generated content that anyone else can see, and no way for any person to contact your child through the App.
One thing is worth explaining plainly, because the word “photo” is misleading here. The App has no camera access and takes no camera photographs. When your child taps the little camera button after cooking, the App draws a picture of what is on the screen — the finished dish, the monster guest and Foxy — and mounts it on a paper-style frame. It is a picture of the game, not of the room your child is sitting in.
Before the Parent Zone, before anything to do with money, before the Terms of Use and Privacy Policy links inside the App, and before saving a picture into the device’s Photos library, the screen asks for the year of birth of an adult. The answer is accepted only if it falls between 18 and 100 years ago.
The year is never stored. It exists only as the four characters being typed, is checked on the spot, and is discarded immediately — it is not written to the device, not logged, and not sent anywhere. A wrong answer simply clears the field and says “Try again”; there is no penalty and no limit.
A parental gate is a reasonable safeguard against a small child wandering somewhere they shouldn’t — it is not a security lock against a determined older child. If you want in-app purchases to be impossible on a device, iOS can do that properly: Settings → Screen Time → Content & Privacy Restrictions → iTunes & App Store Purchases → In-app Purchases → Don’t Allow.
The App offers one auto-renewing subscription, in a monthly and a yearly plan. All payments are handled by Apple and charged to the Apple ID of the account holder. We never see, receive or store any payment details, card numbers, billing addresses or Apple ID credentials, and no purchase can happen without the account holder’s own authentication with Apple.
Purchases are made and verified through Apple’s StoreKit framework, which communicates with Apple, not with us. Apple’s handling of that transaction is covered by Apple’s privacy policy. What the App keeps afterwards is only the yes/no answer described in section 2.
From Apple we receive, through App Store Connect, the standard reports every developer gets: aggregated sales and subscription figures, and — only if the device owner has left “Share With App Developers” switched on in iOS Settings → Privacy & Security → Analytics & Improvements — aggregated, anonymised usage and crash statistics prepared by Apple. These are counts and averages: they arrive already grouped, they identify nobody, and we cannot use them to reach an individual person or device. You can switch that sharing off in iOS Settings at any time.
There are none. The App contains no analytics kit, no crash-reporting kit, no advertising, attribution or measurement software, no social login, no chat or moderation service, and no software development kit supplied by any other company. It is built exclusively on frameworks that ship with iOS. Nothing about you or your child is disclosed, sold or shared with anyone, because nothing is collected in the first place.
The App contains no advertising of any kind, behavioural or otherwise, and no promotion of other apps. Its music, voice-over and artwork are bundled inside the App and are not fetched from anywhere.
This website, kulakovaapps.com, is a plain set of pages. It has no advertising, no comment system, no analytics script and no cookie banner, because it sets no cookies of its own. Our hosting provider keeps ordinary server logs, as all web hosting does, and we do not use them to identify anyone.
The App is designed for young children, carries a 4+ age rating and is listed in the App Store Kids Category in the “Ages 5 & Under” band.
The Children’s Online Privacy Protection Act regulates the collection of personal information from children under 13. The App collects no personal information from children of any age, and discloses nothing to third parties. We do not knowingly contact or collect personal information from children under 16, and there is no feature in the App through which a child could send us anything.
Because there is no collection, no verifiable parental consent mechanism is required, and there is no data for a parent to review, correct or ask us to delete — we hold none. Our retention practice is stated in full in section 13 rather than in a separate document: nothing is transmitted, everything lives in the App’s own storage on your device, and deleting the App deletes it. There are no third-party recipients of any kind, in any category, for any purpose.
We will never begin collecting personal information from children without first updating this policy and obtaining verifiable parental consent as COPPA requires.
We do not process personal data within the meaning of the GDPR. There is no controller-held data, no profiling, no automated decision-making, no advertising or legitimate-interest processing, and no international transfer of personal data, because no personal data is collected. Article 8 consent for a child’s data is therefore not engaged: there is no processing for a parent to consent to. Information created during play stays in the App’s storage on your own device, under your own control.
Apps in the Kids Category must not include behavioural advertising, must not transmit personally identifiable information or device identifiers to third parties, and must place purchases and links out of the app behind a parental gate. The App complies with all three: it shows no advertising at all, sends nothing to anyone, and puts the subscription, the Restore Purchases action, the Terms of Use and Privacy Policy links, the Parent Zone and saving a picture to the Photos library behind the gate described in section 7.
We do not collect, and therefore do not sell or share, personal information as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have never sold or shared personal information, and we do not sell or share the personal information of consumers under 16. There are no categories of personal information collected, no purposes of collection, no retention periods and no third parties to disclose here, and there is nothing for us to act on in response to a request to know, delete, correct, opt out or limit — but you are welcome to send one and we will answer it in writing. We will not discriminate against anyone for exercising a privacy right. The App does not respond to Do Not Track signals, because it makes no web requests to track.
The most useful security property of this App is how little there is to secure: no account, no password, no server, no transmission. Everything the App stores sits inside its own sandboxed container on your device, which iOS protects with the device’s own encryption and keeps out of reach of other apps. Protecting the device itself — a passcode, Face ID or Touch ID, and whatever backup arrangement you choose — is the part that is in your hands.
We retain nothing, because we receive nothing. There is no request you need to send us to have a child’s data deleted, and no waiting period: everything is on your device, and you can remove it yourself, immediately.
Pictures that were deliberately saved out into your Photos library stay there until you delete them, like any other photo. A subscription is cancelled through Apple: Settings → your name → Subscriptions.
Data protection laws give you rights of access, correction, deletion, restriction, objection and portability over personal data held about you, and the right to complain to your national data protection authority. We hold no personal data about you or your child, so in practice there is nothing for us to produce, correct or erase — but the right to ask is real, and so is the answer. Write to the address in section 16, tell us you are a parent or guardian asking about this App, and we will reply in writing, normally within a few days and in any case within 30 days. We do not need to verify your identity for this, because there is no account to look up and nothing to hand over.
If this policy changes, the current version will always be published at this address with its “Last updated” date, and the previous statements are superseded by it. If a future version of the App were ever to start collecting anything at all, that change would be described here, and reflected in the App Store privacy card, before it took effect — and where the law requires consent, it would be asked for first.
This is a one-person studio, and the person is a parent too. Questions about this policy, requests from parents and guardians, and anything else about the App go to the same address, and are answered by me.
Yuliia Kulakova — Kulakova Apps
Email: shepeleva.yulia1999@gmail.com
No ads No data collected No third-party SDKs Works offline