Tumbler collects no data

Privacy Policy

For Tumbler (com.tumbler.tumbler) on Google Play.
Effective 10 August 2026 · Last updated 10 August 2026

Tumbler does not collect, transmit or share any personal or business data. Every building, door, keying system, key symbol, bitting, cut key, custody movement and setting you enter is written to your own device and stays there. There is no account, no sign-in, no cloud sync, no analytics and no advertising.

1. Who publishes this app

Tumbler is published on Google Play by the organisation named below, which is the data controller for the purposes of this policy.

Publisher
COZYMOST ACCOMMODATIONS LTD
Play account type
Organisation
Registered address
2 Frederick Street, London, England, WC1X 0ND, United Kingdom
Email
contact@cozymostaccommodationsltd.store
Website
https://cozymostaccommodationsltd.store

2. What data we collect

None. Tumbler has no server, so there is nothing for it to send data to. Specifically, the app does not collect:

The building addresses, key holders’ names and cut codes you enter are yours, and they are among the most sensitive records a building has. They are stored on the device, they are never uploaded, and we never see them.

3. How your data is used

Everything you enter is used on the device, and only to run the features you asked for: resolving which key opens which door in both directions, computing pin charts from the bittings, validating a cut against its depth-and-space profile, tracking who holds which key and what is overdue, estimating what a lost key costs to contain, and drawing the charts on the Insights screen.

All of that arithmetic happens locally, in the app, on your phone. No processing is performed on any server, by us or by anyone else.

4. Data sharing

We share nothing, because we receive nothing. There are no third-party recipients, no data brokers, no advertising partners and no analytics providers.

You can share data deliberately: the Export screen writes CSV door schedules, bitting arrays, custody sheets and JSON backups into the app’s own folder, and you may then hand a file to Android’s share sheet yourself. What happens to a file after you choose to send it is governed by whichever app you sent it to, not by this policy.

5. Data security

Your records are stored in a local database on the device and are encrypted at rest using AES-256. The encryption key is held in Android’s hardware-backed secure storage (flutter_secure_storage, which uses the Android Keystore) and never leaves the device.

That matters more here than in most apps: a building’s keying schedule is exactly the record that should not sit on somebody else’s server. Because nothing is transmitted, there is no data in transit to intercept and no server-side database to breach. The practical security of your records is the security of your phone: keep a screen lock on it.

6. Data retention and deletion

Your records are kept on the device for as long as you keep the app. We hold no copy and therefore have nothing to retain or delete on your behalf.

7. No user accounts

Tumbler has no registration, no sign-in, no password and no profile. You cannot create an account because there is nothing to create one on, and we hold no credential of yours.

8. Children’s privacy

Tumbler is a work tool for locksmiths and the people who run keys for a building, and is not directed at children. It collects no data from anyone, including children under 13, so it cannot knowingly collect data from a child. It complies with COPPA by collecting nothing at all.

9. Your rights

Data-protection rights — access, correction, deletion, portability, objection — apply to data a company holds about you. We hold none, so there is nothing for us to disclose, correct or erase.

In practice you exercise every one of those rights directly inside the app: view and edit any record, export the whole book as CSV or JSON, and delete everything from Settings. No request to us is needed, and none would be answerable.

10. Third-party services

Tumbler integrates no third-party service. There is no advertising SDK, no analytics SDK, no crash reporter, no attribution library, no social login and no payment processor.

The app is built with open-source Flutter packages that run entirely on the device and make no network calls of their own.

11. Permissions

Tumbler requests exactly one Android permission:

android.permission.INTERNET
Used solely so that Settings → Privacy policy can load this page in an in-app web view. It is never used to transmit your records, and every other feature of the app works with the radio switched off.

The app does not request camera, microphone, location, contacts, storage, notification or any other permission. If Android ever shows you a permission prompt from Tumbler, something is wrong — please contact us.

12. Google Play Data safety declaration

Our Data safety section on Google Play declares that no data is collected and no data is shared. That declaration is accurate and matches this policy exactly. Data is encrypted at rest on the device, and there is no data in transit because the app transmits none.

13. Changes to this policy

If this policy changes, the updated version will be published at this same address and the “Last updated” date above will change. A change that materially affected how data is handled would also be described in the app’s release notes on Google Play.

14. Contact us

Questions about this policy, or about how Tumbler handles data, can be sent to the publisher:

Email
contact@cozymostaccommodationsltd.store
Postal address
COZYMOST ACCOMMODATIONS LTD, 2 Frederick Street, London, England, WC1X 0ND, United Kingdom

15. Legal basis and jurisdiction

Data controller. COZYMOST ACCOMMODATIONS LTD, at 2 Frederick Street, London, England, WC1X 0ND, United Kingdom, is the sole data controller for Tumbler. There is no joint controller and no processor, because no processing takes place outside your own device.

GDPR (EU/EEA and UK). Tumbler performs no processing of personal data by the controller: the app neither collects nor transmits personal data, so no lawful basis under Article 6 is engaged and no international transfer occurs.

CCPA/CPRA (California). We collect no personal information and therefore sell or share none. There is nothing to opt out of, and exercising a "Do Not Sell or Share" right would have no effect because no such activity exists.

Other jurisdictions. The same facts apply wherever you are: an app that transmits nothing cannot process, disclose or transfer your data.