KUROKI STUDIO
  • Apps
  • About
  • Support
  • Apps
  • About
  • Support

Privacy policy

Bracket privacy policy

Effective 2026-08-31. Applies to Bracket (Android package com.kurokistudio.bracket on Google Play, and Apple bundle com.kurokistudio.bracket on the App Store), published on Google Play and the App Store by Kuroki Studio.

1. Summary

Bracket does not collect personal data. All app data is stored locally on your device. The app does not include analytics, telemetry, advertising, or crash reporting. No account is required to use the app.

2. Data Bracket stores on your device

Bracket stores its working data (your settings, history, and content) in the app's private storage on your device. This data never leaves your device through Bracket. You can clear it at any time: on Android, clear the app's storage in Settings or uninstall the app; on iPhone or iPad, delete the app, which removes its on-device data.

Android's own backup system may include this data in your Google account backup if you have device backup enabled in Android Settings. That backup is controlled by Google and by your device settings; Kuroki Studio cannot access it.

On iPhone and iPad, if you have iCloud Backup or an encrypted device backup enabled, Apple's backup system may include this data. That backup is controlled by Apple and by your device settings; Kuroki Studio cannot access it.

3. Permissions Bracket requests and why

Camera (android.permission.CAMERA) (NSCameraUsageDescription)
For live QR and barcode scanning. The camera is active only while you are on the scan screen, and it is optional: Bracket still installs and scans from an image, a PDF, or the clipboard on a device with no camera. No video is recorded; frames are processed in memory and discarded.
Photo library (NSPhotoLibraryUsageDescription) · Apple only
On iPhone and iPad, to read a photo you choose so Bracket can scan a code in it, or use it as a logo on a code you design. Photos are read on your device only. On Android, the system Photo Picker handles this with no permission.
Storage (legacy Android) (android.permission.READ_EXTERNAL_STORAGE) · Android only
On Android 12 and below (capped at API 32), to load an image or PDF you pick. On Android 13 and newer, the system Photo Picker is used instead and no storage permission is requested.
Network state (android.permission.ACCESS_NETWORK_STATE) · Android only
Declared by the billing library and used to check connectivity before a purchase, restore, or optional feed refresh. No information about you is collected.
Change network state (android.permission.CHANGE_NETWORK_STATE) · Android only
When you tap Connect on a scanned Wi-Fi QR code, Bracket asks Android to make the connection and Android shows its own confirmation dialog. This replaced the older Wi-Fi approach and needs no location access; Bracket no longer requests location at all.
Internet (android.permission.INTERNET) · Android only
Used for the RevenueCat purchase and restore flow, and, if you opt in to Online URL safety in Settings (off by default), for downloading the community threat-intelligence feeds you enable. Bracket matches scanned URLs against those downloaded feeds on your device; the scanned URLs are not sent out. On iPhone and iPad, network access needs no permission.
Vibrate (android.permission.VIBRATE) · Android only
Tactile feedback on a successful scan. Toggleable in Settings.

4. Third-party services used in Bracket

Bracket is a paid app. To process your purchase and restore it on reinstall or a new device, it uses Google Play Billing on Android, Apple In-App Purchase (StoreKit) on iPhone and iPad, and RevenueCat on both. Where an app also has an optional feature that reaches the network (for example fetching live currency rates), the service behind that feature is listed below with the exact purpose it serves and the data it receives. No third-party services beyond those listed here are used.

Google Play Billing

Purpose: Processes the in-app purchase itself. All payment handling is performed by Google.

Data shared: Whatever Google Play collects to process a purchase on your Google account. Kuroki Studio never sees your payment details.

Their policy: https://policies.google.com/privacy

Apple In-App Purchase (StoreKit)

Purpose: Processes the one-time Pro purchase on iPhone and iPad. All payment handling is performed by Apple.

Data shared: Whatever Apple collects to process a purchase on your Apple Account. Kuroki Studio never sees your payment details.

Their policy: https://www.apple.com/legal/privacy/

RevenueCat

Purpose: Verifies your purchase and restores it on reinstall or on a new device signed in to the same store.

Data shared: An anonymous app-install identifier, the store purchase token (the Google Play purchase token on Android, or the App Store transaction on iPhone and iPad), your device platform and app version, and country (derived from IP at the time of purchase). No name, email, contacts, or location is sent.

Their policy: https://www.revenuecat.com/privacy/

URLhaus by abuse.ch (optional · off by default)

Purpose: If you enable it under Settings → Privacy → Online URL safety, Bracket downloads URLhaus's public list of recent malicious URLs to your device and checks scanned codes against that local copy.

Data shared: Only the standard metadata any web server receives when Bracket downloads the public feed: your IP address and a fixed request URL (urlhaus.abuse.ch/downloads/csv_recent/). The scanned URL is matched on your device and is never sent to URLhaus. No installation identifier, device identifier, user identifier, or RevenueCat identifier is attached, and Kuroki Studio operates no server in between.

Their policy: https://urlhaus.abuse.ch/

ThreatFox by abuse.ch (optional · off by default)

Purpose: If you enable it under Settings → Privacy → Online URL safety, Bracket downloads ThreatFox's public lists of recent malicious URLs and domains to your device and checks scanned codes against that local copy.

Data shared: Only the standard metadata any web server receives when Bracket downloads the public feeds: your IP address and fixed request URLs (threatfox.abuse.ch/export/csv/urls/recent/ and the matching domains feed). The scanned URL is matched on your device and is never sent to ThreatFox. No installation, device, user, or RevenueCat identifier is attached.

Their policy: https://threatfox.abuse.ch/

PhishTank (optional · off by default · requires your own API key)

Purpose: If you enable it under Settings → Privacy → Online URL safety and supply your own PhishTank API key, Bracket downloads PhishTank's verified-phishing list to your device and checks scanned codes against that local copy.

Data shared: Only the standard metadata any web server receives when Bracket downloads the public list, including the PhishTank API key you entered (it appears in the request URL, data.phishtank.com/data/<your-key>/online-valid.csv). Your API key is stored only on your device. The scanned URL is matched on your device and is never sent to PhishTank.

Their policy: https://phishtank.org/

5. Children's privacy

Bracket is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). Kuroki Studio does not knowingly collect any data from children. Because Bracket does not collect personal data from anyone, this also applies to children who use the app.

6. Your rights

Because Kuroki Studio does not hold any personal data about you in connection with Bracket, there is no personal-data record to access, correct, port, or erase on our end. To remove the app data stored on your device, clear the app's storage in Android Settings, or delete the app on iPhone or iPad. See the account and data deletion page for details.

Under Japan's Act on the Protection of Personal Information (APPI), under the EU General Data Protection Regulation (GDPR), under the UK GDPR, and under the California Consumer Privacy Act (CCPA), you have rights including access, correction, deletion, and (where applicable) the right to lodge a complaint with your data protection authority. If you have any question or request related to your privacy as it concerns Bracket, contact privacy@kurokistudio.com.

7. Changes to this policy

If Kuroki Studio changes this policy, the new version will be posted at this URL and the effective date at the top will be updated. Material changes (such as introducing a new third-party service) will additionally be noted in the app's "What's new" entry on Google Play and the App Store.

8. Contact

Kuroki Studio (Sole proprietorship, Kumamoto, Japan; D-U-N-S 699200333).
Privacy questions: privacy@kurokistudio.com
General support: support@kurokistudio.com

See also: studio-wide privacy policy · terms of service · back to Bracket

KUROKI STUDIO

© 2026 Kuroki Studio. All rights reserved.

Site Apps About Support
Legal Privacy policy Terms of service