Trust Center
A summary of how we handle privacy, security, and quality across every app we build. These are plain-language summaries of our internal company policies — see our App Release Compliance Checklist for where each app currently stands.
Accessibility
We target WCAG 2.1 Level AA across our apps: sufficient colour contrast, resizable text, full screen-reader support (VoiceOver/TalkBack), and layouts that work for right-to-left languages. Accessibility is part of what "done" means for every feature, not an afterthought. Report an accessibility problem to enlightnkugen@gmail.com — we treat these as high priority.
GDPR & data protection
Nku App Services is established in Finland, so EU GDPR governs how we handle personal data. We process data on clear legal bases, honour data-subject rights (access, correction, erasure, portability, objection, and more) within one month of a request, and — in the unlikely event of a personal-data breach that risks your rights — notify Finland's Data Protection Ombudsman within 72 hours and affected users without undue delay.
How we build our apps
iOS and Android are equal, first-class platforms — a feature isn't done until it works well on both. Every release goes through automated checks (static analysis, tests) and is verified on real devices before it ships. Privacy, security, and accessibility are build requirements, not afterthoughts, on every feature.
How we respond to incidents
If something goes wrong — a security issue or a data exposure — we contain it immediately, assess who's affected, fix the root cause, and notify affected users and, where legally required, the relevant authority, within the legally required timeframes. We'd rather over-communicate than downplay an issue.
Open source, done responsibly
Our apps are built on open-source software, used in compliance with its licences. Every new dependency is reviewed for licence terms, maintenance health, and security history before it ships, and we publish the required licence attributions in-app.
Privacy, by design
We collect only what a feature genuinely needs, never repurpose data without a new legal basis, default to the most privacy-protective setting, and are transparent about what we collect and why. You can access, correct, export, and delete your data at any time. We never sell personal data.
Security
All traffic between our apps and our servers is encrypted (HTTPS/TLS); data is encrypted at rest. Every developer console we use (Apple, Google, Firebase, our cloud host, GitHub) requires multi-factor authentication. Secrets and keys are never committed to source code. Found a vulnerability? Email enlightnkugen@gmail.com — responsible disclosure is welcomed.