English | 한국어
Privacy Policy
- Published by
- Jeong Seong-yun (individual developer)
- App
- Onsaemigol (온새미골)
- Contact
- onsaemigol@gmail.com
This is an English translation provided for convenience. The Korean version is the binding text.
Jeong Seong-yun (the "Developer") values users' personal data and complies with the Personal Information Protection Act of the Republic of Korea. This Policy explains the categories, purposes and retention periods of the personal data processed by Onsaemigol (the "App"), and the rights of users.
1. Purposes of Processing
The Developer processes personal data only for the purposes below and will obtain prior consent if these purposes change.
- Account identification and save ownership — identifying the account created through Sign in with Apple and linking game progress data to that account.
- Cloud save backup and restore — restoring game progress data after a device change or reinstall.
- Compatibility checks and bug fixing — checking the device, OS and app version, and analysing the causes of crashes.
- Usage statistics (optional) — reviewing pseudonymised usage statistics only where the user has given optional consent.
- Delivering tuning values and blocking abnormal clients — delivering game balance values and blocking access by tampered clients.
The App shows no advertising, performs no user tracking, and has no payment features.
2. Categories of Data and How They Are Collected
| Item | When / how collected | Purpose | Required / optional |
|---|---|---|---|
| Firebase uid (based on the Apple user identifier) | Generated automatically on Sign in with Apple | Account identification, save ownership | Required when using an account |
| Name supplied by Apple | Returned by Apple once, on the first Sign in with Apple | Not used — discarded immediately on receipt; never stored, displayed or transmitted | — |
| Nickname | Entered directly by the user in the App | In-game name | Required |
| Game save (progress, inventory) | On cloud sync | Cloud restore | Required when using an account |
| Device model, OS version, app version | Automatically when the App runs | Compatibility checks, crash analysis | Required |
| Analytics app instance ID (pseudonymous) | Automatically on first launch after optional consent | Usage statistics | Optional |
| Firebase Installations ID | Automatically at app start (tuning-value and device attestation calls) | Identifying targets for tuning-value delivery, device attestation | Required |
| Crash logs (stack trace, device state) | Automatically when a crash occurs, after optional consent | Bug fixing | Optional |
| IP address | During communication with servers | Handling communications | Required |
Not collected: email address, phone number, location information, contacts, photos or camera, advertising identifier (IDFA), payment information. The App does not link AdSupport.framework and does not track users, so it does not display an App Tracking Transparency (ATT) prompt.
Using the App without an account: if you play without Sign in with Apple, your uid, nickname and game save are stored only on your device and are not transmitted to the Developer.
3. Processing and Retention Periods
| Item | Retention period |
|---|---|
| uid, nickname, game save | For as long as the account exists; destroyed immediately upon account deletion |
| Name supplied by Apple | Not retained (discarded immediately on receipt) |
| Analytics data (including device information) | Expires automatically after 2 months at the user level |
| Crash logs | Expire automatically after 90 days |
| Firebase Installations ID | Google's service processing period; reissuance stops when the App is deleted |
| IP address | Not stored (processed only temporarily in the course of handling communications) |
4. Provision to Third Parties
The Developer does not provide users' personal data to third parties. The entrustment of processing described in sections 5 and 6 below is not provision to third parties.
5. Entrustment of Processing
To operate the service, the Developer entrusts the processing of personal data as set out below. When entering into an entrustment contract, the Developer includes provisions on the secure management of personal data in the contract and supervises whether the entrusted party complies with them.
| Entrusted party | Entrusted work | Entrusted data |
|---|---|---|
| Google LLC | Firebase Authentication (sign-in token verification, account identification) | uid, IP, access time |
| Cloud Firestore (cloud save storage and restore) | uid, nickname, game save, sync metadata, IP | |
| Google Analytics for Firebase (usage statistics) — only with optional consent | App instance ID (pseudonymous), device model / OS / app version, event logs, IP | |
| Firebase Crashlytics (crash cause analysis) — only with optional consent | Crash stack trace, device state, app version, IP | |
| Firebase Remote Config · App Check (tuning-value delivery, blocking abnormal clients) | Firebase Installations ID, App Attest attestation token, IP |
6. Transfer of Personal Data Abroad
Under the entrustment in section 5 above, personal data is transferred outside the Republic of Korea. The legal basis for the transfer is disclosure in this privacy policy for entrusted processing and storage under the Personal Information Protection Act; no separate consent is obtained.
| Recipient | Destination country | Data transferred | Time and method of transfer | Purpose | Retention and use period |
|---|---|---|---|---|---|
| Google LLC (USA) Privacy officer contact: Google privacy inquiry form |
USA (Authentication infrastructure) | uid, IP, access time | Transmitted over HTTPS (TLS) at the time the service is used | Sign-in token verification, account identification | For as long as the account exists |
| Stored in the Seoul region, Republic of Korea. May be accessed from the USA and countries where Google data centers are located in the course of operations and support | uid, nickname, game save, sync metadata, IP | Cloud save storage and restore | For as long as the account exists | ||
| USA and countries where Google data centers are located | App instance ID (pseudonymous), device information, event logs, IP | Usage statistics | 2 months | ||
| USA and countries where Google data centers are located | Crash stack trace, device state, app version, IP | Crash cause analysis | 90 days | ||
| USA and countries where Google data centers are located | Installations ID, App Attest attestation token, IP | Tuning-value delivery, blocking abnormal clients | Google's service processing period |
How to refuse and the consequences: users may refuse the transfer abroad. To refuse, do not give the required consent on the notice screen shown at first launch, or, if you have already created an account, delete your account in the App. If you refuse, the cloud save (account features) cannot be provided, but you may continue to play with data stored only on your device, without an account.
7. Relationship with Apple Inc.
- Sign in with Apple is an authentication method through which Apple provides a user identifier to the Developer. In this process the Developer does not provide users' personal data to Apple and does not entrust the processing of personal data to Apple. Apple's privacy policy applies to Apple's processing.
- For beta distribution through TestFlight, testers' email addresses and device information are processed by Apple under its own policies. The Developer does not separately collect or retain tester email addresses.
8. Destruction Procedure and Method
- Personal data is destroyed without delay when the retention period ends or the purpose of processing has been achieved.
- When account deletion is requested, the uid, nickname and game save stored in the cloud are deleted immediately and the Sign in with Apple link is revoked. Electronic files are deleted by a method that makes them unrecoverable.
- If in-app deletion fails, a request sent to the email address in section 13 below will be destroyed manually within 10 days.
- Analytics and Crashlytics data expire automatically under Google's processing procedures once the periods in section 3 above have passed. The Analytics identifier is also reset upon account deletion.
9. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
Users may exercise the following rights at any time:
- Request access to personal data · request correction where there are errors · request deletion · request suspension of processing
There are two ways to exercise these rights:
- In the App — under Settings > Account you can change your nickname and delete your account yourself.
- By email — send a request to onsaemigol@gmail.com; it will be handled and the result will be sent to you within 10 days.
Users may also exercise their rights through a legal representative or a person to whom they have delegated authority. In that case, a power of attorney must be submitted.
10. Security Measures
- Encryption in transit — all communications are encrypted with HTTPS (TLS).
- Access control — security rules are applied to the cloud database so that a signed-in user can read and write only their own document. Other users' data cannot be accessed.
- Minimal administrator accounts — there is one administrative console account that handles personal data, and two-factor authentication is applied to it.
- Device attestation — device attestation based on Apple App Attest is used to block access by tampered clients.
11. Installation, Operation and Refusal of Devices That Automatically Collect Personal Data
The App does not use a web browser and therefore does not use cookies. The SDKs below collect information automatically while the App is running.
| SDK | Information collected | How to refuse |
|---|---|---|
| Firebase Authentication | uid, IP | Does not operate unless you use Sign in with Apple |
| Cloud Firestore | Save data, IP | Does not operate unless you use Sign in with Apple |
| Google Analytics for Firebase | App instance ID (pseudonymous), device information, events | Do not give optional consent, or turn it off in Settings at any time |
| Firebase Crashlytics | Crash stack trace, device state | Do not give optional consent, or turn it off in Settings at any time |
| Firebase Remote Config · App Check | Installations ID, attestation token, IP | Required for the App to operate, so individual refusal is not offered; collection stops when the App is deleted |
12. Personal Data of Children Under 14
The Developer does not collect personal data of children under the age of 14. The user's age is checked at first launch. If the user is confirmed to be under 14, account (Sign in with Apple) features are not provided, usage statistics and crash data are not collected, and tuning values are not fetched. In that case, game data is stored only on the user's device and is not transmitted to the Developer.
13. Privacy Officer and Channel for Receiving and Handling Access Requests
- Privacy officer
- Jeong Seong-yun
- Position
- Developer (individual)
- Contact
- onsaemigol@gmail.com
Requests for access to personal data are received and handled at the email address above. Inquiries, complaints and requests for remedies relating to personal data protection may also be sent to the same channel, and will be answered without delay. The Developer does not operate GitHub Issues or social media direct messages as contact channels.
14. Remedies for Infringement of Rights
To obtain remedies for infringement of personal data, you may apply for dispute resolution or consultation to the following bodies (Republic of Korea).
| Body | Responsibilities | Contact |
|---|---|---|
| Personal Information Infringement Report Center (KISA) | Reporting personal data infringement, requesting consultation | 118 (no area code) · privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | Personal data dispute mediation, collective dispute mediation | 1833-6972 · www.kopico.go.kr |
| Supreme Prosecutors' Office, Cyber Investigation Division | Investigation of personal data infringement | 1301 (no area code) · www.spo.go.kr |
| Korean National Police Agency, Cyber Investigation Bureau | Investigation of personal data infringement | 182 (no area code) · ecrm.police.go.kr |
In addition, if you object to the Developer's action on a request for access, correction, deletion or suspension of processing of personal data, you may file an administrative appeal under the Personal Information Protection Act.
15. Effective Date and Revision History
This Privacy Policy applies from September 14, 2026. When any content is added, deleted or modified, notice will be given in the App and on this page from 7 days before the effective date. However, changes that materially affect users' rights will be notified 30 days in advance.
| Version | Effective date | Changes |
|---|---|---|
| v1 | September 14, 2026 | Initial version |