Stay Vibe(이하 "회사")는 「개인정보 보호법」 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 다음과 같이 개인정보처리방침을 수립·공개합니다.
본 방침은 회사가 제공하는 모든 애플리케이션 및 서비스에 공통으로 적용됩니다.
시행일: 2026-08-10
최종 개정일: 2026-09-29
제1조 (개인정보 처리의 원칙)
① 회사는 서비스 이용에 있어 회원가입을 요구하지 않습니다. 계정을 만들지 아니하여도 모든 기능을 이용할 수 있습니다.
② 이용자가 원하는 경우에 한하여 다음 각 호의 방법으로 계정을 연결할 수 있습니다(선택). 이는 기기를 변경하거나 응용프로그램을 삭제한 경우에도 기록을 복구하기 위한 것이며, 연결하지 아니하여도 서비스 이용에 아무런 제한이 없습니다. 서비스별로 제공하는 연결 방법은 다를 수 있습니다.
1. 전자우편주소의 등록 2. Google 계정을 이용한 로그인 또는 연결 3. Apple 계정을 이용한 로그인 또는 연결
③ 회사가 처리하는 개인정보는 서비스 이용 과정에서 생성되는 기록과 제2항에 따라 계정을 연결하는 때에 처리하는 정보(제3조 제1-2호 및 제1-3호)에 한정됩니다.
④ 다만 광고가 게재되는 서비스의 경우 광고 사업자가 광고식별자를 수집하며, 이에 관하여는 제4조에서 정합니다.
제2조 (수집하지 않는 정보)
회사는 다음 각 호의 정보를 수집하지 않습니다.
항목
성명 (Google 또는 Apple 계정으로 계정을 연결한 경우 해당 사업자로부터 전달받는 이름은 제외하며, 이는 제3조 제1-3호에서 정합니다)
전화번호, 주소
전자우편주소 (계정을 연결하지 아니한 이용자에 한합니다. 전자우편주소, Google 계정 또는 Apple 계정으로 계정을 연결한 이용자의 전자우편주소는 제3조에 따라 수집합니다)
주민등록번호 등 고유식별정보
계좌번호, 신용카드번호, 결제 비밀번호
연락처, 단말기에 저장된 사진, 통화기록
얼굴, 지문 등 생체인식정보
사상·신념, 건강, 성생활 등 민감정보
회사는 금융기관 및 신용카드사와 연동하지 아니하며, 정보주체의 실제 지출 내역을 확인할 수 있는 수단을 보유하지 않습니다.
제3조 (수집하는 개인정보의 항목 및 수집방법)
1. 계정 식별자
서비스를 최초로 실행하는 때에 성명이 결부되지 않은 계정이 자동으로 생성됩니다. 해당 계정은 임의로 생성된 식별번호(UUID) 1개로 구성되며, 그 자체만으로는 특정 개인을 알아볼 수 없습니다.
1-2. 전자우편주소 (전자우편주소로 계정을 연결한 이용자만 해당)
이용자가 전자우편주소로 계정 연결을 선택하는 경우 전자우편주소와 비밀번호를 등록합니다.
항목
처리 내용
전자우편주소
본인 확인 및 기기 변경 시 기록의 복구에만 이용합니다. 광고·마케팅에 이용하지 않습니다
비밀번호
복원할 수 없는 방식으로 변환하여 저장합니다. 회사가 원문을 열람할 수 없습니다
연결의 해제를 원하는 이용자는 제12조의 방법으로 삭제를 요청할 수 있습니다.
1-3. Google 또는 Apple 계정 정보 (해당 계정으로 로그인하거나 계정을 연결한 이용자만 해당)
이용자가 Google 계정 또는 Apple 계정으로 로그인하거나 이를 계정에 연결하는 경우, 회사는 해당 사업자로부터 다음 정보를 전달받아 계정 정보로 저장합니다.
연결 수단
전달받는 항목
Google 계정
전자우편주소, 이름, 프로필 사진의 주소(URL), Google 계정 식별번호
Apple 계정
전자우편주소, Apple 계정 식별번호, 이름(Apple이 전달하는 경우에 한함)
① Apple 계정으로 로그인하면서 이용자가 '나의 이메일 가리기'를 선택한 경우, 회사는 실제 전자우편주소가 아닌 Apple이 발급한 전달용 주소를 전달받습니다. 해당 주소로 발송된 전자우편은 Apple이 이용자의 실제 전자우편주소로 전달합니다.
② 회사는 Google 계정 또는 Apple 계정의 비밀번호를 전달받지 않습니다. 로그인 과정의 본인 인증은 Google LLC 또는 Apple Inc.가 수행하며, 해당 사업자는 자사의 개인정보처리방침에 따라 정보를 처리합니다.
③ 위 정보는 본인 확인 및 기기 변경 시 기록의 복구에만 이용하며, 광고·마케팅에 이용하지 않습니다. 이름과 프로필 사진의 주소는 로그인 과정에서 함께 전달되어 저장될 뿐이며, 회사는 이를 서비스 화면에 표시하거나 그 밖의 목적으로 이용하지 않습니다.
④ 위 정보의 삭제를 원하는 이용자는 제12조의 방법으로 요청할 수 있습니다. 서비스 내 계정 삭제 기능을 이용하는 경우 위 정보는 계정 및 기록과 함께 삭제됩니다.
2. 서비스 이용 과정에서 생성되는 정보
서비스별로 그 내용은 상이하나, 유형은 다음과 같습니다.
유형
세부 항목
이용자가 서비스 내에서 생성한 기록
저장한 항목, 진행 상황, 달성 내역
이용자가 선택한 설정값
기능의 활성화 여부, 선택한 외관
서비스 내 재화 및 보유 항목
잔액, 증감 내역, 보유 항목
이용 기록
접속 일시, 이용한 기능
3. 이용자가 직접 입력한 문자정보
서비스에 따라 이용자가 문자를 입력할 수 있습니다(예: 별칭, 메모). 입력 내용은 이용자가 자율적으로 결정합니다. 회사는 실명 또는 민감한 내용을 입력하지 아니할 것을 권고합니다.
4. 자동으로 생성·수집되는 정보
서비스의 정상적인 제공 여부를 확인하기 위하여 다음 정보가 자동으로 생성됩니다.
항목
수집 목적
접속 일시
장기 미이용 계정의 정리
기기 모델, 운영체제 버전, 응용프로그램 버전
오류 발생 환경의 파악
접속 국가 및 언어 설정
해당 언어에 따른 화면 제공
5. 단말기 내에만 저장되는 정보
일부 설정값은 회사의 서버로 전송되지 아니하고 이용자의 단말기 내에만 저장되며, 응용프로그램을 삭제하는 때에 함께 삭제됩니다.
제4조 (광고식별자의 처리)
본 조는 광고가 게재되는 서비스에 한하여 적용됩니다.
1. 처리 주체
광고의 선택 및 게재는 회사가 아닌 Google LLC의 AdMob이 수행합니다. 이에 따라 다음 정보가 회사를 경유하지 아니하고 응용프로그램에서 Google LLC로 직접 전송됩니다.
전송 항목
세부 내용
광고식별자
Android의 광고 ID, iOS의 IDFA. 이용자가 언제든지 삭제하거나 재설정할 수 있는 식별번호
IP 주소
개략적인 접속 지역의 확인에 이용
기기 정보
모델, 운영체제, 화면 규격
광고 관련 행태정보
광고의 노출 여부 및 클릭 여부
처리 목적: 광고의 선택, 동일 광고의 반복 노출 방지, 광고 노출의 측정, 부정클릭의 차단
2. 처리 기준
Google LLC는 위 정보를 회사의 방침이 아닌 자사의 개인정보처리방침에 따라 처리합니다. 그 구체적인 내용은 다음에서 확인할 수 있습니다.
정보주체는 다음의 방법으로 언제든지 맞춤형 광고를 거부할 수 있습니다. 거부하는 경우에도 광고는 계속 노출되나, 관심분야에 기반한 맞춤형 광고에는 해당하지 아니합니다.
운영체제
설정 경로
Android
설정 ▸ Google ▸ 모든 서비스 ▸ 광고 ▸ 광고 ID 삭제
iOS, iPadOS
설정 ▸ 개인정보 보호 및 보안 ▸ 추적 ▸ 앱이 추적을 요청하도록 허용 해제
iOS 및 iPadOS에서 광고식별자(IDFA)는 이용자가 운영체제의 확인 창에서 앱의 추적을 허용한 경우에만 수집됩니다. 서비스는 광고를 처음 게재하기 전에 이 확인 창으로 허용 여부를 확인하며, 이용자가 허용하지 아니하는 경우 광고는 광고식별자 없이 게재됩니다. 허용 여부는 위 설정 경로에서 언제든지 변경할 수 있습니다.
4. 보상형 광고
서비스에 따라 광고의 시청에 대하여 재화 등을 지급하는 기능이 제공될 수 있습니다.
① 해당 광고는 이용자가 직접 선택하여 실행하는 경우에 한하여 재생되며, 회사는 광고의 시청을 강제하지 않습니다.
② 광고를 시청하지 아니하는 경우에도 서비스의 기본적인 기능은 모두 이용할 수 있습니다.
제5조 (결제 관련 정보의 처리)
본 조는 유료 기능이 제공되는 서비스에 한하여 적용됩니다.
1. 결제의 처리 주체
결제는 Apple Inc.의 App Store 및 Google LLC의 Google Play를 통하여 이루어지며, 회사가 직접 결제를 수령하지 않습니다. 이에 따라 신용카드번호, 계좌번호, 결제 비밀번호는 회사의 서버로 전송되지 아니하며 회사가 이를 열람할 수 없습니다.
2. 회사가 수령하는 정보
결제가 완료되는 때에 위 사업자로부터 다음 정보를 수령합니다.
수령 항목
처리 목적
사업자가 발급한 거래식별번호(영수증)
해당 결제의 유효성을 사업자에게 조회하여 확인
구매 항목, 구매 일시, 유효기간
구매 내역의 서비스 반영 및 환불 시 회수
위 정보에는 성명, 신용카드번호, 청구지 주소가 포함되지 않습니다.
3. 환불
환불은 구매가 이루어진 사업자(Apple Inc. 또는 Google LLC)가 처리합니다. 회사는 해당 사업자로부터 환불 사실을 통지받는 때에 서비스 내 구매 내역을 그에 따라 조정합니다.
제6조 (개인정보의 처리 목적)
회사는 개인정보를 다음 각 호의 목적으로 처리하며, 그 목적 외의 용도로는 이용하지 않습니다.
목적
세부 내용
서비스의 제공
이용자의 기록을 재현하여 제공
기능의 구현
기간의 산정, 재화의 지급, 진행 상황의 표시
부정이용의 방지
동일한 보상의 중복 취득 차단
결제의 확인
결제의 유효성 확인 및 구매 내역의 반영
오류의 개선
장애 발생 환경의 파악 및 수정
문의의 처리
이용자의 문의사항에 대한 회신
회사는 개인정보를 광고 목적으로 이용하지 아니하며, 이를 판매하지 않습니다.
제7조 (개인정보의 보유 및 이용 기간)
① 회사는 개인정보를 다음 각 호에 따라 보유합니다.
구분
보유 기간
서비스를 이용하는 기간
계속 보유
이용자가 로그아웃한 경우
해당 계정으로의 재접속이 불가능
이용자가 계정을 삭제하거나 삭제를 요청한 경우
삭제일 또는 요청일부터 7일 이내 파기
12개월 이상 접속하지 아니한 경우
별도의 통지 없이 파기할 수 있음
결제에 관한 기록
「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 5년
② 관계 법령에 따라 보존하여야 하는 정보는 해당 법령이 정한 기간 동안 보존합니다.
제8조 (개인정보의 파기)
① 회사는 보유기간이 경과하거나 처리 목적이 달성되는 등 개인정보가 불필요하게 되는 때에 지체 없이 해당 개인정보를 파기합니다.
② 파기의 절차: 파기 사유가 발생한 개인정보를 선정하고, 개인정보 보호 업무 담당자의 확인을 거쳐 파기합니다.
③ 파기의 방법: 전자적 파일 형태로 저장된 개인정보는 복구가 불가능한 방법으로 영구 삭제합니다.
④ 단말기 내에만 저장된 정보는 응용프로그램의 삭제로 함께 삭제됩니다.
⑤ 관계 법령에 따라 보존하여야 하는 결제 기록은 다른 개인정보와 분리하여 저장·관리하고, 해당 기간의 경과 후 제3항의 방법으로 파기합니다.
제9조 (개인정보 처리업무의 위탁)
① 회사는 원활한 서비스의 제공을 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.
수탁자
위탁업무의 내용
Supabase, Inc.
개인정보의 보관 및 계정의 관리
Google LLC
광고의 게재 (광고가 게재되는 서비스에 한함)
Apple Inc., Google LLC
결제의 처리 및 영수증의 검증 (유료 기능이 제공되는 서비스에 한함)
② 회사는 위탁계약 체결 시 개인정보의 안전한 관리에 관한 사항을 규정하고, 수탁자가 이를 준수하는지를 감독합니다.
③ 위탁은 제3자 제공과 구별됩니다. 수탁자는 위탁받은 업무의 범위를 초과하여 개인정보를 이용할 수 없습니다.
④ 위탁업무의 내용이나 수탁자가 변경되는 경우, 회사는 본 방침을 개정하여 공개합니다.
제10조 (개인정보의 국외 이전)
① 회사가 이용하는 서버는 대한민국(서울)에 있습니다. 이용자의 기록은 국내에 저장됩니다.
② 제1항에도 불구하고 다음의 경우 개인정보가 국외로 이전되거나 국외에서 조회될 수 있습니다.
이전받는 자
국가
이전되는 항목
이용 목적
Supabase, Inc.
미국 (서버 소재지는 대한민국 서울)
제3조의 정보
서버의 운영 및 기술지원 과정에서의 접근
Google LLC
미국
제4조의 정보
광고의 게재 (광고가 게재되는 서비스에 한함)
Apple Inc., Google LLC
미국
제5조의 정보
결제의 검증 (유료 기능이 제공되는 서비스에 한함)
③ 이전의 일시 및 방법은 서비스 이용 기간 중 수시로, 정보통신망을 통한 전송이며, 이전받는 자의 보유 기간은 제7조와 같습니다.
④ 정보주체는 개인정보의 국외 이전을 거부할 수 있습니다. 다만 이 경우 서버에 개인정보를 저장할 수 없어 서비스의 이용이 불가능합니다.
⑤ 광고 목적의 이전만을 거부하고자 하는 경우에는 제4조 제3항의 방법에 따릅니다.
제11조 (개인정보의 제3자 제공)
① 회사는 정보주체의 개인정보를 제3자에게 제공하지 않습니다.
② 제1항에도 불구하고 다음 각 호의 경우에는 예외로 합니다.
1. 정보주체로부터 별도의 동의를 받은 경우 2. 법률에 특별한 규정이 있거나, 수사기관이 영장 등 적법한 절차에 따라 요구하는 경우
③ 제9조의 수탁자는 제3자 제공의 상대방이 아니라 회사의 지시에 따라 업무를 처리하는 수탁자이며, 위탁받은 업무 외의 목적으로 개인정보를 이용할 수 없습니다.
제12조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 회사에 대하여 언제든지 다음 각 호의 권리를 행사할 수 있습니다.
1. 개인정보 열람의 요구 2. 오류 등이 있는 경우 정정의 요구 3. 삭제의 요구 4. 처리정지의 요구
② 제1항에 따른 권리 행사는 다음의 방법으로 할 수 있습니다.
1. 서비스 내 계정 삭제 기능의 이용 (설정 ▸ 계정 삭제. 가장 신속하고 확실한 방법입니다) 2. stayvibe33@gmail.com 으로의 전자우편 발송
③ 회사는 제1항에 따른 요구를 받은 날부터 10일 이내에 필요한 조치를 하고 그 결과를 통지합니다.
④ 제1항에 따른 권리 행사는 법정대리인이나 위임을 받은 자 등 대리인을 통하여 할 수 있습니다.
⑤ 제2항 제1호의 계정 삭제 기능을 이용하는 경우 다음 각 호와 같이 처리됩니다.
1. 계정과 서버에 저장된 이용자의 정보(서비스 이용 기록, 보유 재화 및 항목, 연결된 전자우편주소 및 Google·Apple 계정 정보를 포함합니다)가 삭제되며, 삭제된 계정과 기록은 복구할 수 없습니다. 2. 결제에 관한 기록은 제7조의 보존 기간 동안 계정과의 연결을 해제한 상태로 제8조 제5항에 따라 분리하여 보관한 후 파기합니다. 3. 계정의 삭제로 App Store 또는 Google Play의 구독이 해지되지는 않습니다. 구독의 해지는 해당 사업자의 설정에서 하여야 합니다.
제13조 (개인정보 자동 수집 장치의 설치·운영 및 그 거부)
장치
운영 여부
거부 방법
쿠키
응용프로그램에서는 운영하지 않음
해당 없음
광고식별자
광고가 게재되는 서비스에서 광고 사업자가 운영
제4조 제3항
단말기 내 저장소
설정값의 보관 목적으로 운영
응용프로그램의 삭제
제14조 (만 14세 미만 아동의 개인정보)
① 만 14세 미만의 아동은 회사의 서비스를 이용할 수 없습니다.
② 회사는 서비스를 아동을 대상으로 제공하지 아니하며, 아동을 대상으로 하는 맞춤형 광고를 게재하지 않습니다.
③ 회사는 서비스 이용을 개시하는 시점에 이용자로부터 만 14세 이상임을 확인받으며, 그 밖의 별도의 연령 확인 절차는 운영하지 아니합니다. 회사는 이용자가 만 14세 미만임을 알게 된 경우 해당 계정의 개인정보를 지체 없이 파기합니다.
④ 법정대리인은 아동의 개인정보가 처리되고 있음을 확인한 경우 stayvibe33@gmail.com 으로 통지할 수 있으며, 회사는 확인 후 이를 파기합니다.
제15조 (개인정보의 안전성 확보조치)
회사는 개인정보의 안전성 확보를 위하여 다음의 조치를 취하고 있습니다.
1. 전송 구간의 암호화: 응용프로그램과 서버 간의 모든 통신은 암호화된 프로토콜(HTTPS)로 이루어집니다. 2. 접근권한의 제한: 데이터베이스에 행 수준 접근제어를 적용하여 이용자가 자신의 개인정보에만 접근할 수 있도록 합니다. 3. 취급자의 최소화: 서버에 접근할 수 있는 인원을 최소한으로 제한합니다. 4. 결제정보의 미보유: 결제정보는 회사의 서버로 전송되지 아니하므로 유출의 대상이 존재하지 않습니다.
제16조 (개인정보 보호 문의처)
정보주체는 개인정보의 처리에 관한 문의, 불만처리, 피해구제 등에 관한 사항을 다음의 연락처로 문의할 수 있습니다. 회사는 지체 없이 답변하고 처리합니다.
정보주체는 개인정보 침해로 인한 구제를 받기 위하여 다음의 기관에 분쟁해결이나 상담 등을 신청할 수 있습니다.
기관
전화
웹사이트
개인정보 침해신고센터
118
privacy.kisa.or.kr
개인정보 분쟁조정위원회
1833-6972
kopico.go.kr
대검찰청 사이버수사과
1301
spo.go.kr
경찰청 사이버수사국
182
ecrm.police.go.kr
「개인정보 보호법」 제35조(개인정보의 열람), 제36조(개인정보의 정정·삭제), 제37조(개인정보의 처리정지 등)의 규정에 의한 요구에 대하여 회사가 행한 처분 또는 부작위로 인하여 권리 또는 이익의 침해를 받은 자는 행정심판법이 정하는 바에 따라 행정심판을 청구할 수 있습니다.
제18조 (개인정보처리방침의 변경)
① 본 방침의 내용을 변경하는 경우, 회사는 변경사항의 시행 7일 전부터 응용프로그램 내 공지 및 본 페이지를 통하여 이를 공지합니다.
② 정보주체에게 불리한 내용으로 변경하는 경우에는 30일 전부터 공지합니다.
③ 변경된 내용과 시행일은 본 페이지의 상단 및 아래의 개정 이력에 기재합니다.
개정 이력
일자
내용
2026-08-10
제정
2026-09-29
Google·Apple 계정 연결 시 처리하는 정보 명시(제1조·제2조·제3조), iOS의 추적 허용 여부 확인에 관한 사항 명시(제4조), 계정 삭제 기능의 경로 및 처리 내용 명시(제7조·제12조)
Stay Vibe ("the Company", "we") is the controller responsible for the personal data described in this Policy. We publish this Policy to explain how personal data is collected, used, disclosed, transferred and protected.
This Policy applies uniformly to all applications and services provided by the Company.
Effective date: 2026-08-10
Last amended: 2026-09-29
1. Principles of processing
1.1 The Company does not require registration. Every feature is available without creating an account.
1.2 Only if the user chooses to, the account may be linked by any of the following means. This exists so that records can be recovered after a device change or a reinstall. Declining places no restriction of any kind on the use of the service. The means available may differ between services.
(a) registration of an email address; (b) signing in with, or linking, a Google account; or (c) signing in with, or linking, an Apple account.
1.3 The personal data processed by the Company is limited to records generated in the course of using the services and, where an account has been linked, the data processed on linking under paragraph 1.2 (Articles 3.1-2 and 3.1-3).
1.4 Where a service displays advertising, an advertising identifier is collected by the advertising provider. Article 4 governs that processing.
2. Data we do not collect
The Company does not collect any of the following.
Category
Name (other than a name passed to the Company by Google or Apple where the account is linked through that provider, as set out in Article 3.1-3)
Telephone number, postal address
Email address (applies only to users who have not linked an account. The email address of a user who links an account by email, Google or Apple is collected under Article 3)
National identification numbers or equivalent government identifiers
Bank account numbers, payment card numbers, payment passwords
Contacts, photographs stored on the device, call logs
Biometric data, including facial and fingerprint data
Special category data, including data concerning beliefs, health or sexual life
The Company does not connect to any bank or card issuer and has no means of ascertaining a user's actual expenditure.
3. Personal data we collect
3.1 Account identifier
An account not associated with any name is created automatically when the application is first launched. It consists of a single randomly generated identifier (a UUID) which does not, in itself, identify an individual.
3.1-2 Email address (accounts linked by email only)
Where a user chooses to link an account by email, an email address and a password are registered.
Item
How it is handled
Email address
Used only to verify the account and to recover records after a device change. Never used for advertising or marketing
Password
Stored in an irreversible form. The Company cannot read it
A user who wishes to unlink may request deletion by the means set out in Article 13.
3.1-3 Google or Apple account information (users who sign in with or link such an account only)
Where a user signs in with a Google account or an Apple account, or links one to their account, the Company receives the following from the provider and stores it as account information.
Means of linking
Items received
Google account
Email address, name, the address (URL) of the profile picture, Google account identifier
Apple account
Email address, Apple account identifier, name (only where Apple provides it)
(a) Where a user signing in with Apple chooses Hide My Email, the Company receives a relay address issued by Apple rather than the user's actual email address. Apple forwards email sent to that address to the user's actual email address.
(b) The Company does not receive the password for the Google or Apple account. Authentication during sign-in is performed by Google LLC or Apple Inc., each of which processes information under its own privacy policy.
(c) The above is used only to verify the account and to recover records after a device change, and is never used for advertising or marketing. The name and the profile picture address are stored only because the provider passes them to the Company during sign-in. The Company does not display them within the service or use them for any other purpose.
(d) A user who wishes this information to be erased may so request by the means set out in Article 13. Where the account deletion function within the service is used, this information is erased together with the account and its records.
3.2 Data generated through use of the service
The specifics differ between services; the categories do not.
Category
Examples
Records created by the user within the service
Saved items, progress, achievements
Settings selected by the user
Features enabled or disabled, appearance selected
In-service currency and holdings
Balance, transaction history, items held
Usage records
Times of access, features used
3.3 Text entered by the user
Certain services permit the entry of free text (for example, a nickname or a note). The content is determined solely by the user. We recommend that users do not enter their real name or any sensitive information.
3.4 Data generated automatically
The following is generated automatically in order to confirm that the service is functioning correctly.
Item
Purpose
Time of access
Identification of dormant accounts for deletion
Device model, operating system version, application version
Identification of the environment in which faults occur
Country of access and language setting
Presentation of the service in the appropriate language
3.5 Data stored only on the device
Certain settings are stored solely on the user's device, are not transmitted to our servers, and are deleted when the application is removed.
4. Advertising identifiers
This Article applies only to services in which advertising is displayed.
4.1 Recipient
Advertising is selected and served by Google AdMob, operated by Google LLC, and not by the Company. Accordingly, the following is transmitted from the application directly to Google LLC, without passing through the Company.
Item transmitted
Detail
Advertising identifier
The Advertising ID on Android and the IDFA on iOS. An identifier the user may delete or reset at any time
IP address
Used to determine the approximate region of access
Device information
Model, operating system, screen dimensions
Advertising interaction data
Whether an advertisement was displayed and whether it was tapped
Purposes: selection of advertisements, frequency capping, measurement of advertisement delivery, and prevention of fraudulent clicks.
4.2 Applicable policy
Google LLC processes the above under its own privacy policy and not under this Policy. Further information is available at:
Users may opt out at any time by the following means. Advertising continues to be displayed, but is no longer tailored to inferred interests.
Operating system
Path
Android
Settings ▸ Google ▸ All services ▸ Ads ▸ Delete advertising ID
iOS, iPadOS
Settings ▸ Privacy & Security ▸ Tracking ▸ disable Allow Apps to Request to Track
On iOS and iPadOS, the IDFA is collected only where the user allows the app to track in the operating system's permission prompt. The service shows this prompt before advertising is first displayed. Where the user does not allow tracking, advertising is displayed without the advertising identifier. The choice may be changed at any time via the path above.
4.4 Rewarded advertising
Certain services offer in-service items in return for viewing an advertisement.
(a) Such advertisements play only where the user affirmatively elects to view them. The Company does not compel the viewing of advertising.
(b) All core functionality remains available to users who do not view advertising.
5. Payment data
This Article applies only to services offering paid features.
5.1 Party processing payment
Payment is processed through the Apple App Store, operated by Apple Inc., and Google Play, operated by Google LLC. The Company does not receive payment directly. Payment card numbers, bank account numbers and payment passwords are not transmitted to the Company's servers and cannot be accessed by the Company.
5.2 Data the Company receives
On completion of a transaction, the Company receives the following from the store operator.
Item received
Purpose
The transaction identifier (receipt) issued by the store operator
Verification of the transaction with the store operator
Item purchased, date of purchase, expiry
Application of the purchase within the service and reversal upon refund
The foregoing does not include the user's name, payment card number or billing address.
5.3 Refunds
Refunds are administered by the store operator through which the purchase was made (Apple Inc. or Google LLC). On notification of a refund, the Company adjusts the corresponding entitlement within the service.
6. Purposes of processing
The Company processes personal data for the following purposes and does not process it for any incompatible purpose.
Purpose
Detail
Provision of the service
Reproducing the user's records
Operation of features
Calculation of periods, award of items, display of progress
Prevention of abuse
Preventing repeated claims of the same reward
Verification of payment
Confirming validity and applying entitlements
Correction of faults
Identifying the environment in which faults occur
Handling of enquiries
Responding to enquiries submitted by users
The Company does not process personal data for advertising purposes and does not sell personal data.
7. Basis for processing
The Company processes personal data on the following bases.
Processing
Basis
Creation of the account and provision of the service
Performance of the agreement with the user
Verification of payment and administration of entitlements
Performance of the agreement with the user
Prevention of abuse, correction of faults, security
The Company's legitimate interest in operating the service securely
Personalised advertising and the associated identifiers
The user's consent
Consent may be withdrawn at any time by the means set out in Article 4.3. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Retention
8.1 The Company retains personal data as follows.
Circumstance
Retention
During use of the service
Retained
Where the user signs out
The account can no longer be accessed
Where the user deletes the account or requests deletion
Erased within 7 days of the deletion or the request
Where there has been no access for 12 months or more
May be erased without notice
Records of payment
Retained for the period required by applicable law (in the Republic of Korea, 5 years)
8.2 Data which the Company is required by law to preserve is retained for the period prescribed by that law.
9. Erasure
9.1 Where the retention period expires or the purpose of processing is achieved, the Company erases the personal data concerned without undue delay.
9.2 Procedure: the personal data in respect of which grounds for erasure have arisen is identified and erased following review.
9.3 Method: personal data held in electronic form is permanently erased by means from which recovery is not possible.
9.4 Data held solely on the user's device is erased upon removal of the application.
9.5 Payment records which must be preserved by law are stored and managed separately from other personal data and are erased in accordance with paragraph 9.3 upon expiry of the applicable period.
10. Processors
10.1 The Company engages the following processors in order to provide the service.
Processor
Nature of processing
Supabase, Inc.
Storage of records and administration of accounts
Google LLC
Delivery of advertising (services displaying advertising only)
Apple Inc., Google LLC
Processing of payment and verification of receipts (services offering paid features only)
10.2 The Company imposes obligations relating to the secure handling of personal data upon each processor and monitors compliance.
10.3 Engagement of a processor is distinct from disclosure to a third party. A processor may not use personal data beyond the scope of the processing entrusted to it.
10.4 Where the identity of a processor or the nature of the processing changes, the Company will amend and publish this Policy.
11. International transfers
11.1 The servers used by the Company are located in the Republic of Korea (Seoul). User records are stored within that country.
11.2 Notwithstanding paragraph 11.1, personal data may be transferred to, or accessed from, the following.
Recipient
Country
Data transferred
Purpose
Supabase, Inc.
United States (servers located in Seoul, Republic of Korea)
The data in Article 3
Access in the course of operating the servers and providing technical support
Google LLC
United States
The data in Article 4
Delivery of advertising (services with ads only)
Apple Inc., Google LLC
United States
The data in Article 5
Verification of payment (services with paid features only)
11.3 Transfers occur continuously during use of the service, by transmission over the network, and retention by each recipient is as stated in Article 8.
11.4 Users may object to international transfer. However, personal data could not then be stored, and the service could not be provided.
11.5 Users wishing to object only to transfer for advertising purposes may do so by the means set out in Article 4.3.
12. Disclosure to third parties
12.1 The Company does not disclose personal data to third parties.
12.2 Paragraph 12.1 does not apply where:
(a) the user has given separate consent; or
(b) disclosure is required by law, or is sought by a law enforcement authority pursuant to due legal process, such as a warrant.
12.3 The processors identified in Article 10 are not recipients of a third party disclosure. They are processors acting on the Company's documented instructions and may not use personal data for any other purpose.
13. Rights of the individual
13.1 Users may exercise the following rights at any time.
(a) the right of access; (b) the right to rectification of inaccurate data; (c) the right to erasure; (d) the right to restriction of processing; (e) the right to withdraw consent at any time; and (f) any further right conferred by the law of the user's country of residence, including rights of portability and of objection where that law provides for them.
13.2 Rights may be exercised by either of the following means.
(a) the account deletion function within the service (Settings ▸ Delete account; the most direct and reliable method); or (b) email to stayvibe33@gmail.com.
13.3 The Company will act upon a request and notify the outcome within 10 days, or within such shorter or longer period as applicable law requires.
13.4 Rights may be exercised through a legal guardian or an authorised representative.
13.5 Users may lodge a complaint with the data protection authority competent in their country of residence.
13.6 Where the account deletion function referred to in paragraph 13.2(a) is used:
(a) the account and the user's data stored on the Company's servers (including records of use, in-service currency and items held, and any linked email address and Google or Apple account information) are erased, and an erased account and its records cannot be restored;
(b) records of payment are retained for the period set out in Article 8 with the link to the account removed, are stored separately in accordance with paragraph 9.5, and are erased thereafter; and
(c) deleting the account does not cancel a subscription on the App Store or Google Play. A subscription must be cancelled in the settings of the relevant store.
14. Additional information for residents of California
14.1 The Company does not sell personal information as that term is defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
14.2 Where personalised advertising is enabled, the disclosure of an advertising identifier to Google LLC may constitute "sharing" for the purposes of cross-context behavioural advertising. Users may opt out at any time by the means set out in Article 4.3, which the Company treats as a request to opt out of such sharing.
14.3 California residents have the right to know, to delete, to correct, and to opt out of sharing, and shall not be subjected to discriminatory treatment for exercising any of those rights.
15. Automated collection and how to refuse it
Mechanism
Operated
Means of refusal
Cookies
Not operated within the applications
Not applicable
Advertising identifiers
Operated by the advertising provider in services displaying advertising
Article 4.3
On-device storage
Operated for the retention of settings
Removal of the application
16. Children
16.1 Persons under the age of 14 may not use the Company's services.
16.2 The Company does not direct its services to children and does not deliver advertising targeted at children.
16.3 The Company obtains a confirmation from the user, at the point of first use of the Service, that the user is at least 14 years of age. The Company does not operate any further age verification process. Where the Company becomes aware that a user is under the age of 14, it erases the personal data associated with that account without undue delay.
16.4 A parent or guardian who becomes aware that a child's personal data is being processed may notify stayvibe33@gmail.com, and the Company will verify and erase it.
16.5 Where applicable law prescribes a higher age for consent to the processing of personal data, that higher age applies.
17. Security measures
The Company implements the following measures.
(a) Encryption in transit: all communication between the application and the Company's servers is carried over an encrypted protocol (HTTPS).
(b) Access control: row level security is applied to the database so that a user may access only their own records.
(c) Minimisation of personnel: the number of personnel able to access the servers is kept to a minimum.
(d) No retention of payment credentials: payment credentials are not transmitted to the Company's servers, and there is accordingly nothing capable of disclosure.
Enquiries, complaints and requests relating to personal data are all received at the address above.
19. Amendment of this Policy
19.1 Where this Policy is amended, the Company will publish notice of the amendment and its effective date within the application and on this page not less than 7 days in advance.
19.2 Where an amendment is disadvantageous to users, notice will be given not less than 30 days in advance.
19.3 The substance of each amendment and its effective date are recorded at the head of this page and in the amendment history below.
Amendment history
Date
Summary
2026-08-10
Established
2026-09-29
Data processed when a Google or Apple account is linked (Articles 1, 2 and 3); the iOS tracking permission (Article 4); the path and effect of the account deletion function (Articles 8 and 13)
決済は、Apple Inc. が運営する App Store および Google LLC が運営する Google Play を通じて行われ、当社が直接収受することはありません。 したがって、クレジットカード番号、口座番号および決済用パスワードは、当社のサーバーに送信されず、当社が閲覧することもできません。
2. 当社が受領する情報
決済が完了した時点で、当社は前記の事業者から次の情報を受領します。
受領する項目
目的
事業者が発行した取引識別番号(レシート)
当該決済の有効性を事業者に照会して確認するため
購入した項目、購入日時、有効期限
購入内容をサービスに反映し、返金時に回収するため
前記の情報に、氏名、クレジットカード番号および請求先住所は含まれません。
3. 返金
返金は、購入が行われた事業者(Apple Inc. または Google LLC)が処理します。 当社は、当該事業者から返金の通知を受けた時点で、サービス内の購入内容をこれに応じて調整します。
(1) アカウントおよび当社のサーバーに保存された利用者の情報(サービスの利用記録、財貨および保有物、連携された電子メールアドレスならびに Google・Apple のアカウント情報を含みます)が消去され、消去されたアカウントおよび記録は復元できません。 (2) 決済に関する記録は、第7条の保存期間中、アカウントとの紐づけを解除した状態で第8条第5項に従い分離して保管し、その後消去します。 (3) アカウントを削除しても、App Store または Google Play のサブスクリプションは解約されません。サブスクリプションの解約は、当該事業者の設定から行ってください。