1 · Scope and developer
Who this policy covers.
This policy describes Cub Draw, a Cub Suite drawing app developed by Nanda Kusumadi. Contact: cubdrawsupport@nandakusumadi.com.
Cub Draw is designed for young children under parent or guardian control. Core drawing is local-first, works without creating a Cub Draw account, and does not require family synchronization.
2 · On-device data
What Cub Draw stores on the device.
- Drawings: editable PencilKit strokes, page orientation, optional template image and settings, sticker placements, creation/modification dates, and derived thumbnails.
- Drawing history: a bounded local undo/redo history for strokes and sticker actions. This history is not synchronized through CloudKit.
- Stickers and templates: imported sticker images, category names/order/pictures, child-visibility settings, tracing templates, maze themes and scene/template choices.
- Device setup: the selected installation role, active Child Space reference, app-only preferences and synchronization tokens.
- Parent gate: child iPads use an on-screen addition question. Cub Draw no longer creates or stores a parent PIN and removes the previous PIN verifier during upgrade. Parent-only devices rely on their device lock; existing shared-iPad setups may use device-owner authentication.
- Identifiers: random drawing, sticker, category and Child Space identifiers used to keep files and synchronization records separate and consistent.
These files live in Cub Draw’s app container or the Cub Suite App Group container used for same-device suite sharing. Other apps cannot browse these containers through Cub Draw.
3 · Optional private family sync
What can use Apple iCloud and CloudKit.
When a parent creates or joins a private Child Space, Cub Draw uses Apple CloudKit and CKShare. Nanda Kusumadi does not operate a separate Cub Draw content server.
Depending on the features a family uses, the Child Space can contain:
- the parent-entered child display name;
- editable drawing strokes, thumbnails, page orientation, templates/settings and sticker placements;
- imported sticker imagery, categories, child-visibility state, deletion state and maze-theme assignments;
- record, drawing, sticker, category and Child Space identifiers; and
- the Apple CloudKit account identifier needed to scope the correct account and Child Space.
Cub Draw’s Apple privacy manifest conservatively declares linked Name, Photos or Videos, Other User Content and User ID, all used only for app functionality and not for tracking.
4 · Use and disclosure
Who can see family content.
CloudKit content is private to the owner unless the parent creates a CKShare. It is shared only with the Apple Accounts and devices the parent invites to that Child Space. Each Child Space uses a separate CloudKit zone so one child’s family content is not intentionally mixed with another’s.
External sharing is parent initiated through Apple’s system share sheet. A child or shared iPad must pass the parent gate before a drawing can leave Cub Draw. Parent-only devices rely on the device lock.
No public profiles or feed
No chat
No advertising
No third-party analytics
No tracking
No purchase prompts on child screens
Colouring-pack update
Optional purchases and child access.
The live 1.1 app has no in-app purchases. The upcoming 1.2 update adds optional one-time colouring-pack purchases in Parent Mode. The following describes that update; it does not mean the packs are already available to buy.
Apple processes purchases and restores through StoreKit. Cub Draw checks verified entitlement information to decide which packs are available. Cub Draw does not receive payment-card details and does not upload full receipts or StoreKit transaction payloads to a separate server.
When a parent directly purchases a pack, Cub Draw makes it available to every paired Child Space by default, including children paired later. A parent can turn a pack off for an individual child. Each Child Space’s private CloudKit zone stores the app, pack and product identifiers, purchaser identity, ownership type, selection and access status, and verification and expiry dates. Invited participants receive the grant so their devices can make that pack available. The app caches access information and downloaded artwork on the device, outside device backup.
Turning a pack off or losing its purchase entitlement disables the grant on the parent and sends the change to paired devices at their next successful sync. The grant record may retain the selection and inactive status for restore and synchronization. A fully offline child may retain access until the current allowance expires, at most 90 days after the parent’s recorded verification. Existing drawings retain their embedded artwork. Removing an app does not erase records already stored in a Child Space.
The 1.2 privacy manifest also declares linked Purchase History for app functionality because a scoped grant identifies the purchased pack and its purchaser. This information is not used for advertising or tracking. Core drawing stays free, and children do not see prices, locked-pack promotions or purchase prompts.
5 · Photos and sensitive images
Photo access is requested only at the point of use.
Parents choose source pictures through Apple’s system Photos picker, which does not give Cub Draw broad access to the photo library. Cub Draw requests add-only Photos permission only when a parent chooses Save to Photos for finished artwork. The app does not request camera, microphone, location, contacts or tracking permission.
Foreground extraction and tracing conversion run on-device. A selected tracing source remains in memory; only the derived template becomes part of a drawing and may synchronize if that drawing belongs to a paired Child Space.
When the person has enabled Sensitive Content Warning or Communication Safety, imported or synchronized child-visible images can be screened on-device using Apple’s Sensitive Content Analysis framework. Flagged stickers remain parent-only; flagged tracing sources are not accepted. The classification result is used in memory for that decision and is not persisted, synchronized or uploaded by Cub Draw.
6 · Retention and deletion
How drawings and family data can be removed.
Local drawings
Past drawings can be deleted after the parent gate. On an unpaired installation, there is no CloudKit recovery copy. The active Current Drawing is not deletable from My Drawings.
Recently Deleted
For a paired Child Space, cloud drawings marked deleted stay in the parent’s Recently Deleted view until a parent restores or permanently deletes them. Cub Draw 1.0 does not apply an automatic expiry period.
Permanent drawing deletion
A parent can confirm Delete Permanently in Recently Deleted. Cub Draw deletes the CloudKit drawing record/assets and its scoped parent cache entry. This cannot be undone.
Sticker deletion
Deleting a custom sticker removes it from library views. If a local, synchronized or recoverable drawing still references that sticker, a hidden scoped backing asset is retained so the drawing does not change.
Unpairing and participants
The Child Space owner can use Manage invitation to change participants or stop sharing through Apple’s CloudKit sharing controls. Revoking access stops future shared access but may not erase local copies already stored on another device.
Removing the app
Removing Cub Draw should not be used as the sole cloud-deletion method. CloudKit data remains in the owner’s Child Space and may return after reinstalling and pairing. Unsynchronized local work and local-only undo history are not stored in CloudKit and may not return.
Deletion from Cub Draw does not promise immediate removal from Apple backups, disaster-recovery copies, temporary caches or records Apple must retain under its own terms. Apple controls those systems and their retention.
7 · Children and parental control
Parents control setup, imports and sharing.
Cub Draw is intended for the App Store’s Made for Kids — Ages 5 and under category, with ages four to five as the primary design and testing cohort. A parent or guardian controls setup, imported content, family invitations, external sharing and deletion.
The child experience does not ask a child to register, enter contact details, create a public profile, send a message, or submit information to Nanda Kusumadi. Parents should use the support email on a child’s behalf and send only the information needed to answer the request.
8 · Security and international processing
How Cub Draw protects family data.
Cub Draw uses Apple app-container and Keychain protections on the device, private CloudKit zones, explicit CKShare invitations and parent gates for sensitive actions. No system can be described as completely secure; families should protect their Apple Accounts and device passcodes and remove participants they no longer trust.
Optional CloudKit content is processed by Apple under the family’s Apple service terms. Apple may store or process that data in countries other than the family’s own. Nanda Kusumadi does not choose Apple’s data-centre location and does not operate a parallel Cub Draw content server.
9 · This website
The website is separate from the app.
This policy covers the Cub Draw app. The website separately uses server logs and Umami Cloud analytics, as described in the website privacy notice. Those website practices do not add analytics to Cub Draw or expose family drawings through the website. Please use the support email as a parent rather than sending child content through public channels.
10 · Changes, questions and parent requests
Contact the developer.
This policy may change when Cub Draw’s features or privacy practices change. A revised policy will show a new effective date. A parent or guardian may ask what Cub Draw data is involved, request correction where possible, ask for participant removal, or request help with permanent deletion.
Developer: Nanda Kusumadi
Email: cubdrawsupport@nandakusumadi.com