정보주체는 다음의 방법으로 언제든지 맞춤형 광고를 거부할 수 있습니다. 거부하는 경우에도 광고는 계속 노출되나, 관심분야에 기반한 맞춤형 광고에는 해당하지 아니합니다.
운영체제
설정 경로
Android
설정 ▸ Google ▸ 모든 서비스 ▸ 광고 ▸ 광고 ID 삭제
iOS, iPadOS
설정 ▸ 개인정보 보호 및 보안 ▸ 추적 ▸ 앱이 추적을 요청하도록 허용 해제
4. 보상형 광고
서비스에 따라 광고의 시청에 대하여 재화 등을 지급하는 기능이 제공될 수 있습니다.
① 해당 광고는 이용자가 직접 선택하여 실행하는 경우에 한하여 재생되며, 회사는 광고의 시청을 강제하지 않습니다.
② 광고를 시청하지 아니하는 경우에도 서비스의 기본적인 기능은 모두 이용할 수 있습니다.
제5조 (결제 관련 정보의 처리)
본 조는 유료 기능이 제공되는 서비스에 한하여 적용됩니다.
1. 결제의 처리 주체
결제는 Apple Inc.의 App Store 및 Google LLC의 Google Play를 통하여 이루어지며, 회사가 직접 결제를 수령하지 않습니다. 이에 따라 신용카드번호, 계좌번호, 결제 비밀번호는 회사의 서버로 전송되지 아니하며 회사가 이를 열람할 수 없습니다.
2. 회사가 수령하는 정보
결제가 완료되는 때에 위 사업자로부터 다음 정보를 수령합니다.
수령 항목
처리 목적
사업자가 발급한 거래식별번호(영수증)
해당 결제의 유효성을 사업자에게 조회하여 확인
구매 항목, 구매 일시, 유효기간
구매 내역의 서비스 반영 및 환불 시 회수
위 정보에는 성명, 신용카드번호, 청구지 주소가 포함되지 않습니다.
3. 환불
환불은 구매가 이루어진 사업자(Apple Inc. 또는 Google LLC)가 처리합니다. 회사는 해당 사업자로부터 환불 사실을 통지받는 때에 서비스 내 구매 내역을 그에 따라 조정합니다.
제6조 (개인정보의 처리 목적)
회사는 개인정보를 다음 각 호의 목적으로 처리하며, 그 목적 외의 용도로는 이용하지 않습니다.
목적
세부 내용
서비스의 제공
이용자의 기록을 재현하여 제공
기능의 구현
기간의 산정, 재화의 지급, 진행 상황의 표시
부정이용의 방지
동일한 보상의 중복 취득 차단
결제의 확인
결제의 유효성 확인 및 구매 내역의 반영
오류의 개선
장애 발생 환경의 파악 및 수정
문의의 처리
이용자의 문의사항에 대한 회신
회사는 개인정보를 광고 목적으로 이용하지 아니하며, 이를 판매하지 않습니다.
제7조 (개인정보의 보유 및 이용 기간)
① 회사는 개인정보를 다음 각 호에 따라 보유합니다.
구분
보유 기간
서비스를 이용하는 기간
계속 보유
이용자가 로그아웃한 경우
해당 계정으로의 재접속이 불가능
이용자가 삭제를 요청한 경우
요청일부터 7일 이내 파기
12개월 이상 접속하지 아니한 경우
별도의 통지 없이 파기할 수 있음
결제에 관한 기록
「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 5년
② 관계 법령에 따라 보존하여야 하는 정보는 해당 법령이 정한 기간 동안 보존합니다.
제8조 (개인정보의 파기)
① 회사는 보유기간이 경과하거나 처리 목적이 달성되는 등 개인정보가 불필요하게 되는 때에 지체 없이 해당 개인정보를 파기합니다.
② 파기의 절차: 파기 사유가 발생한 개인정보를 선정하고, 개인정보 보호 업무 담당자의 확인을 거쳐 파기합니다.
③ 파기의 방법: 전자적 파일 형태로 저장된 개인정보는 복구가 불가능한 방법으로 영구 삭제합니다.
④ 단말기 내에만 저장된 정보는 응용프로그램의 삭제로 함께 삭제됩니다.
⑤ 관계 법령에 따라 보존하여야 하는 결제 기록은 다른 개인정보와 분리하여 저장·관리하고, 해당 기간의 경과 후 제3항의 방법으로 파기합니다.
제9조 (개인정보 처리업무의 위탁)
① 회사는 원활한 서비스의 제공을 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.
수탁자
위탁업무의 내용
Supabase, Inc.
개인정보의 보관 및 계정의 관리
Google LLC
광고의 게재 (광고가 게재되는 서비스에 한함)
Apple Inc., Google LLC
결제의 처리 및 영수증의 검증 (유료 기능이 제공되는 서비스에 한함)
② 회사는 위탁계약 체결 시 개인정보의 안전한 관리에 관한 사항을 규정하고, 수탁자가 이를 준수하는지를 감독합니다.
③ 위탁은 제3자 제공과 구별됩니다. 수탁자는 위탁받은 업무의 범위를 초과하여 개인정보를 이용할 수 없습니다.
④ 위탁업무의 내용이나 수탁자가 변경되는 경우, 회사는 본 방침을 개정하여 공개합니다.
제10조 (개인정보의 국외 이전)
① 회사가 이용하는 서버는 대한민국(서울)에 있습니다. 이용자의 기록은 국내에 저장됩니다.
② 제1항에도 불구하고 다음의 경우 개인정보가 국외로 이전되거나 국외에서 조회될 수 있습니다.
이전받는 자
국가
이전되는 항목
이용 목적
Supabase, Inc.
미국 (서버 소재지는 대한민국 서울)
제3조의 정보
서버의 운영 및 기술지원 과정에서의 접근
Google LLC
미국
제4조의 정보
광고의 게재 (광고가 게재되는 서비스에 한함)
Apple Inc., Google LLC
미국
제5조의 정보
결제의 검증 (유료 기능이 제공되는 서비스에 한함)
③ 이전의 일시 및 방법은 서비스 이용 기간 중 수시로, 정보통신망을 통한 전송이며, 이전받는 자의 보유 기간은 제7조와 같습니다.
④ 정보주체는 개인정보의 국외 이전을 거부할 수 있습니다. 다만 이 경우 서버에 개인정보를 저장할 수 없어 서비스의 이용이 불가능합니다.
⑤ 광고 목적의 이전만을 거부하고자 하는 경우에는 제4조 제3항의 방법에 따릅니다.
제11조 (개인정보의 제3자 제공)
① 회사는 정보주체의 개인정보를 제3자에게 제공하지 않습니다.
② 제1항에도 불구하고 다음 각 호의 경우에는 예외로 합니다.
1. 정보주체로부터 별도의 동의를 받은 경우 2. 법률에 특별한 규정이 있거나, 수사기관이 영장 등 적법한 절차에 따라 요구하는 경우
③ 제9조의 수탁자는 제3자 제공의 상대방이 아니라 회사의 지시에 따라 업무를 처리하는 수탁자이며, 위탁받은 업무 외의 목적으로 개인정보를 이용할 수 없습니다.
제12조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 회사에 대하여 언제든지 다음 각 호의 권리를 행사할 수 있습니다.
1. 개인정보 열람의 요구 2. 오류 등이 있는 경우 정정의 요구 3. 삭제의 요구 4. 처리정지의 요구
③ 회사는 제1항에 따른 요구를 받은 날부터 10일 이내에 필요한 조치를 하고 그 결과를 통지합니다.
④ 제1항에 따른 권리 행사는 법정대리인이나 위임을 받은 자 등 대리인을 통하여 할 수 있습니다.
제13조 (개인정보 자동 수집 장치의 설치·운영 및 그 거부)
장치
운영 여부
거부 방법
쿠키
응용프로그램에서는 운영하지 않음
해당 없음
광고식별자
광고가 게재되는 서비스에서 광고 사업자가 운영
제4조 제3항
단말기 내 저장소
설정값의 보관 목적으로 운영
응용프로그램의 삭제
제14조 (만 14세 미만 아동의 개인정보)
① 만 14세 미만의 아동은 회사의 서비스를 이용할 수 없습니다.
② 회사는 서비스를 아동을 대상으로 제공하지 아니하며, 아동을 대상으로 하는 맞춤형 광고를 게재하지 않습니다.
③ 회사는 별도의 연령 확인 절차를 운영하지 아니하나, 이용자가 만 14세 미만임을 알게 된 경우 해당 계정의 개인정보를 지체 없이 파기합니다.
④ 법정대리인은 아동의 개인정보가 처리되고 있음을 확인한 경우 stayvibe33@gmail.com 으로 통지할 수 있으며, 회사는 확인 후 이를 파기합니다.
제15조 (개인정보의 안전성 확보조치)
회사는 개인정보의 안전성 확보를 위하여 다음의 조치를 취하고 있습니다.
1. 전송 구간의 암호화: 응용프로그램과 서버 간의 모든 통신은 암호화된 프로토콜(HTTPS)로 이루어집니다. 2. 접근권한의 제한: 데이터베이스에 행 수준 접근제어를 적용하여 이용자가 자신의 개인정보에만 접근할 수 있도록 합니다. 3. 취급자의 최소화: 서버에 접근할 수 있는 인원을 최소한으로 제한합니다. 4. 결제정보의 미보유: 결제정보는 회사의 서버로 전송되지 아니하므로 유출의 대상이 존재하지 않습니다.
제16조 (개인정보 보호 문의처)
정보주체는 개인정보의 처리에 관한 문의, 불만처리, 피해구제 등에 관한 사항을 다음의 연락처로 문의할 수 있습니다. 회사는 지체 없이 답변하고 처리합니다.
정보주체는 개인정보 침해로 인한 구제를 받기 위하여 다음의 기관에 분쟁해결이나 상담 등을 신청할 수 있습니다.
기관
전화
웹사이트
개인정보 침해신고센터
118
privacy.kisa.or.kr
개인정보 분쟁조정위원회
1833-6972
kopico.go.kr
대검찰청 사이버수사과
1301
spo.go.kr
경찰청 사이버수사국
182
ecrm.police.go.kr
「개인정보 보호법」 제35조(개인정보의 열람), 제36조(개인정보의 정정·삭제), 제37조(개인정보의 처리정지 등)의 규정에 의한 요구에 대하여 회사가 행한 처분 또는 부작위로 인하여 권리 또는 이익의 침해를 받은 자는 행정심판법이 정하는 바에 따라 행정심판을 청구할 수 있습니다.
제18조 (개인정보처리방침의 변경)
① 본 방침의 내용을 변경하는 경우, 회사는 변경사항의 시행 7일 전부터 응용프로그램 내 공지 및 본 페이지를 통하여 이를 공지합니다.
Stay Vibe ("the Company", "we") is the controller responsible for the personal data described in this Policy. We publish this Policy to explain how personal data is collected, used, disclosed, transferred and protected.
This Policy applies uniformly to all applications and services provided by the Company.
Effective date: 2026-08-10
Last amended: 2026-08-10
1. Principles of processing
1.1 The Company does not require registration. Every feature is available without creating an account.
1.2 Only if the user chooses to, an email address may be registered in order to link the account. This exists so that records can be recovered after a device change or a reinstall. Declining places no restriction of any kind on the use of the service.
1.3 The personal data processed by the Company is limited to records generated in the course of using the services and, where an account has been linked, the email address referred to in paragraph 1.2.
1.4 Where a service displays advertising, an advertising identifier is collected by the advertising provider. Article 4 governs that processing.
2. Data we do not collect
The Company does not collect any of the following.
Category
Name, telephone number, postal address
Email address (only where the user has linked an account. Not collected from users who have not)
National identification numbers or equivalent government identifiers
Bank account numbers, payment card numbers, payment passwords
Contacts, photographs, call logs
Biometric data, including facial and fingerprint data
Special category data, including data concerning beliefs, health or sexual life
The Company does not connect to any bank or card issuer and has no means of ascertaining a user's actual expenditure.
3. Personal data we collect
3.1 Account identifier
An account not associated with any name is created automatically when the application is first launched. It consists of a single randomly generated identifier (a UUID) which does not, in itself, identify an individual.
3.1-2 Email address (linked accounts only)
Where a user chooses to link an account, an email address and a password are registered.
Item
How it is handled
Email address
Used only to verify the account and to recover records after a device change. Never used for advertising or marketing
Password
Stored in an irreversible form. The Company cannot read it
A user who wishes to unlink may request deletion by the means set out in Article 13.
3.2 Data generated through use of the service
The specifics differ between services; the categories do not.
Category
Examples
Records created by the user within the service
Saved items, progress, achievements
Settings selected by the user
Features enabled or disabled, appearance selected
In-service currency and holdings
Balance, transaction history, items held
Usage records
Times of access, features used
3.3 Text entered by the user
Certain services permit the entry of free text (for example, a nickname or a note). The content is determined solely by the user. We recommend that users do not enter their real name or any sensitive information.
3.4 Data generated automatically
The following is generated automatically in order to confirm that the service is functioning correctly.
Item
Purpose
Time of access
Identification of dormant accounts for deletion
Device model, operating system version, application version
Identification of the environment in which faults occur
Country of access and language setting
Presentation of the service in the appropriate language
3.5 Data stored only on the device
Certain settings are stored solely on the user's device, are not transmitted to our servers, and are deleted when the application is removed.
4. Advertising identifiers
This Article applies only to services in which advertising is displayed.
4.1 Recipient
Advertising is selected and served by Google AdMob, operated by Google LLC, and not by the Company. Accordingly, the following is transmitted from the application directly to Google LLC, without passing through the Company.
Item transmitted
Detail
Advertising identifier
The Advertising ID on Android and the IDFA on iOS. An identifier the user may delete or reset at any time
IP address
Used to determine the approximate region of access
Device information
Model, operating system, screen dimensions
Advertising interaction data
Whether an advertisement was displayed and whether it was tapped
Purposes: selection of advertisements, frequency capping, measurement of advertisement delivery, and prevention of fraudulent clicks.
4.2 Applicable policy
Google LLC processes the above under its own privacy policy and not under this Policy. Further information is available at:
Users may opt out at any time by the following means. Advertising continues to be displayed, but is no longer tailored to inferred interests.
Operating system
Path
Android
Settings ▸ Google ▸ All services ▸ Ads ▸ Delete advertising ID
iOS, iPadOS
Settings ▸ Privacy & Security ▸ Tracking ▸ disable Allow Apps to Request to Track
4.4 Rewarded advertising
Certain services offer in-service items in return for viewing an advertisement.
(a) Such advertisements play only where the user affirmatively elects to view them. The Company does not compel the viewing of advertising.
(b) All core functionality remains available to users who do not view advertising.
5. Payment data
This Article applies only to services offering paid features.
5.1 Party processing payment
Payment is processed through the Apple App Store, operated by Apple Inc., and Google Play, operated by Google LLC. The Company does not receive payment directly. Payment card numbers, bank account numbers and payment passwords are not transmitted to the Company's servers and cannot be accessed by the Company.
5.2 Data the Company receives
On completion of a transaction, the Company receives the following from the store operator.
Item received
Purpose
The transaction identifier (receipt) issued by the store operator
Verification of the transaction with the store operator
Item purchased, date of purchase, expiry
Application of the purchase within the service and reversal upon refund
The foregoing does not include the user's name, payment card number or billing address.
5.3 Refunds
Refunds are administered by the store operator through which the purchase was made (Apple Inc. or Google LLC). On notification of a refund, the Company adjusts the corresponding entitlement within the service.
6. Purposes of processing
The Company processes personal data for the following purposes and does not process it for any incompatible purpose.
Purpose
Detail
Provision of the service
Reproducing the user's records
Operation of features
Calculation of periods, award of items, display of progress
Prevention of abuse
Preventing repeated claims of the same reward
Verification of payment
Confirming validity and applying entitlements
Correction of faults
Identifying the environment in which faults occur
Handling of enquiries
Responding to enquiries submitted by users
The Company does not process personal data for advertising purposes and does not sell personal data.
7. Basis for processing
The Company processes personal data on the following bases.
Processing
Basis
Creation of the account and provision of the service
Performance of the agreement with the user
Verification of payment and administration of entitlements
Performance of the agreement with the user
Prevention of abuse, correction of faults, security
The Company's legitimate interest in operating the service securely
Personalised advertising and the associated identifiers
The user's consent
Consent may be withdrawn at any time by the means set out in Article 4.3. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Retention
8.1 The Company retains personal data as follows.
Circumstance
Retention
During use of the service
Retained
Where the user signs out
The account can no longer be accessed
Where the user requests deletion
Erased within 7 days of the request
Where there has been no access for 12 months or more
May be erased without notice
Records of payment
Retained for the period required by applicable law (in the Republic of Korea, 5 years)
8.2 Data which the Company is required by law to preserve is retained for the period prescribed by that law.
9. Erasure
9.1 Where the retention period expires or the purpose of processing is achieved, the Company erases the personal data concerned without undue delay.
9.2 Procedure: the personal data in respect of which grounds for erasure have arisen is identified and erased following review.
9.3 Method: personal data held in electronic form is permanently erased by means from which recovery is not possible.
9.4 Data held solely on the user's device is erased upon removal of the application.
9.5 Payment records which must be preserved by law are stored and managed separately from other personal data and are erased in accordance with paragraph 9.3 upon expiry of the applicable period.
10. Processors
10.1 The Company engages the following processors in order to provide the service.
Processor
Nature of processing
Supabase, Inc.
Storage of records and administration of accounts
Google LLC
Delivery of advertising (services displaying advertising only)
Apple Inc., Google LLC
Processing of payment and verification of receipts (services offering paid features only)
10.2 The Company imposes obligations relating to the secure handling of personal data upon each processor and monitors compliance.
10.3 Engagement of a processor is distinct from disclosure to a third party. A processor may not use personal data beyond the scope of the processing entrusted to it.
10.4 Where the identity of a processor or the nature of the processing changes, the Company will amend and publish this Policy.
11. International transfers
11.1 The servers used by the Company are located in the Republic of Korea (Seoul). User records are stored within that country.
11.2 Notwithstanding paragraph 11.1, personal data may be transferred to, or accessed from, the following.
Recipient
Country
Data transferred
Purpose
Supabase, Inc.
United States (servers located in Seoul, Republic of Korea)
The data in Article 3
Access in the course of operating the servers and providing technical support
Google LLC
United States
The data in Article 4
Delivery of advertising (services with ads only)
Apple Inc., Google LLC
United States
The data in Article 5
Verification of payment (services with paid features only)
11.3 Transfers occur continuously during use of the service, by transmission over the network, and retention by each recipient is as stated in Article 8.
11.4 Users may object to international transfer. However, personal data could not then be stored, and the service could not be provided.
11.5 Users wishing to object only to transfer for advertising purposes may do so by the means set out in Article 4.3.
12. Disclosure to third parties
12.1 The Company does not disclose personal data to third parties.
12.2 Paragraph 12.1 does not apply where:
(a) the user has given separate consent; or
(b) disclosure is required by law, or is sought by a law enforcement authority pursuant to due legal process, such as a warrant.
12.3 The processors identified in Article 10 are not recipients of a third party disclosure. They are processors acting on the Company's documented instructions and may not use personal data for any other purpose.
13. Rights of the individual
13.1 Users may exercise the following rights at any time.
(a) the right of access; (b) the right to rectification of inaccurate data; (c) the right to erasure; (d) the right to restriction of processing; (e) the right to withdraw consent at any time; and (f) any further right conferred by the law of the user's country of residence, including rights of portability and of objection where that law provides for them.
13.2 Rights may be exercised by either of the following means.
(a) the deletion function within the service (the most direct and reliable method); or (b) email to stayvibe33@gmail.com.
13.3 The Company will act upon a request and notify the outcome within 10 days, or within such shorter or longer period as applicable law requires.
13.4 Rights may be exercised through a legal guardian or an authorised representative.
13.5 Users may lodge a complaint with the data protection authority competent in their country of residence.
14. Additional information for residents of California
14.1 The Company does not sell personal information as that term is defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
14.2 Where personalised advertising is enabled, the disclosure of an advertising identifier to Google LLC may constitute "sharing" for the purposes of cross-context behavioural advertising. Users may opt out at any time by the means set out in Article 4.3, which the Company treats as a request to opt out of such sharing.
14.3 California residents have the right to know, to delete, to correct, and to opt out of sharing, and shall not be subjected to discriminatory treatment for exercising any of those rights.
15. Automated collection and how to refuse it
Mechanism
Operated
Means of refusal
Cookies
Not operated within the applications
Not applicable
Advertising identifiers
Operated by the advertising provider in services displaying advertising
Article 4.3
On-device storage
Operated for the retention of settings
Removal of the application
16. Children
16.1 Persons under the age of 14 may not use the Company's services.
16.2 The Company does not direct its services to children and does not deliver advertising targeted at children.
16.3 The Company does not operate an age verification process. Where the Company becomes aware that a user is under the age of 14, it erases the personal data associated with that account without undue delay.
16.4 A parent or guardian who becomes aware that a child's personal data is being processed may notify stayvibe33@gmail.com, and the Company will verify and erase it.
16.5 Where applicable law prescribes a higher age for consent to the processing of personal data, that higher age applies.
17. Security measures
The Company implements the following measures.
(a) Encryption in transit: all communication between the application and the Company's servers is carried over an encrypted protocol (HTTPS).
(b) Access control: row level security is applied to the database so that a user may access only their own records.
(c) Minimisation of personnel: the number of personnel able to access the servers is kept to a minimum.
(d) No retention of payment credentials: payment credentials are not transmitted to the Company's servers, and there is accordingly nothing capable of disclosure.
Enquiries, complaints and requests relating to personal data are all received at the address above.
19. Amendment of this Policy
19.1 Where this Policy is amended, the Company will publish notice of the amendment and its effective date within the application and on this page not less than 7 days in advance.
19.2 Where an amendment is disadvantageous to users, notice will be given not less than 30 days in advance.
19.3 The substance of each amendment and its effective date are recorded at the head of this page.
決済は、Apple Inc. が運営する App Store および Google LLC が運営する Google Play を通じて行われ、当社が直接収受することはありません。 したがって、クレジットカード番号、口座番号および決済用パスワードは、当社のサーバーに送信されず、当社が閲覧することもできません。
2. 当社が受領する情報
決済が完了した時点で、当社は前記の事業者から次の情報を受領します。
受領する項目
目的
事業者が発行した取引識別番号(レシート)
当該決済の有効性を事業者に照会して確認するため
購入した項目、購入日時、有効期限
購入内容をサービスに反映し、返金時に回収するため
前記の情報に、氏名、クレジットカード番号および請求先住所は含まれません。
3. 返金
返金は、購入が行われた事業者(Apple Inc. または Google LLC)が処理します。 当社は、当該事業者から返金の通知を受けた時点で、サービス内の購入内容をこれに応じて調整します。