petspunk — Privacy Policy

App: PetsPunk: AI Usage Campfire (app.nlap.petspunk) · Operator: nlap (Republic of Korea) · Contact: [email protected]

Effective: 2026-09-30 · Canonical language: English. A Korean translation is provided for convenience (PRIVACY.ko.md).

1. What this app is

petspunk turns your AI-subscription usage into a small in-app currency that you spend at a shared pixel campfire with up to six people. There is no sign-up: the app creates an anonymous account on first launch. Campfire chat is relayed live and never stored on our servers. Wall posts (*Shout*) are different: they are public and stored — see §2.

2. Data we process and why

DataWhere it comes fromWhyKept
Install key — a random 32-byte value your device generates on first launchYour deviceIdentifies your anonymous account so the same install always returns to the same account (no e-mail, phone or password). We store only a salted hash.Until you delete your account
Device identifier (Android only) — a one-way hash derived from the Android device ID (ANDROID_ID/SSAID) and an app-specific saltYour Android deviceAccount continuity: if you uninstall and reinstall the app, this lets the app return to your account instead of creating a new one. Also used to limit abuse (one device, one recovering account). The raw device ID never leaves your device; we receive and store only the derived hash.Until you delete your account
Account token — issued by our serverOur serverAuthenticates your requests. Stored on your device in the secure keystore; stored on the server as a hash only.Rotated on each start; the last two are kept
Handle (@xxxxxxxx), chosen nickname and pet look (part/colour keys)Derived on the server / chosen by youPublic identity in rooms and in reports. The handle cannot be changed. The nickname and look are stored with the account so they follow you across reinstalls and device transfers.Until account deletion
In-app currency balances (firewood ✦, char ◆, ash ❖) and room events (firewood added, drops won)Generated by playThe game economy is server-authoritative.Until account deletion
AI usage level (a small integer per connected provider)Reported by the app after you connect a providerTo grant in-app currency. We do not store raw usage records or billing data, and we do not store provider account identifiers.Rolling window; see §6
Transfer code (8 characters, 10-minute validity)Generated when you ask to move your account to a new phoneLets a new device take over your account. Stored as a hash, single-use.10 minutes
Reports — when you press *Report* on someone, your device uploads the last room messages it holds (up to 30 lines of the room chat plus the reported person's last 8 messages — 40 lines at most, with names) plus the reported handle and reason. A copy is stored on your account and on the reported account, and an entry (who was reported, reason, time — no text) goes to a moderation queueYour device, only when you press ReportTrust & safety review (EULA §6).30 days, then deleted
Block list — the handles, display names and account ids of people you block, with the time (up to 200)You, when you press BlockSo you are not matched with them again. Stored on your account until you unblock or delete the account.
Reports about you — reason, reporter id and the attached chat lines when someone reports you (up to 100, kept 30 days)Other users, when they report youTrust & safety review. Kept for 30 days even if the reporter or you delete the account, so that abuse cannot be erased by deleting.
Connected-provider source key — a one-way SHA-256 hash (32 hex characters) of the provider account identifier you connect (e.g. the Google account id)Derived on your device when you connectTo count each AI account once for usage rewards and enforce the 3-accounts-per-provider limit. The raw identifier never leaves the device; the hash cannot be reversed.
In-app records — wallet balances, earnings ledger, unlocked characters, mail (shares left in rooms), room statistics (seats taken, firewood burned, whether you have chatted)Generated by playingGame functionality (currency, unlocks, progression). Until you delete the account.
Chat filter word list version — the version number of the word list your app hasYour app, when it checks for an updated listKeeping client-side masking current. Nothing personal is sent.
Push notification token — the registration token Firebase Cloud Messaging issues for this app on your device (on iPhone, Firebase maps it to Apple's push token), plus the platform (ios/android)Your device, only after you allow notificationsTo send the notifications you asked for (*the fire is open*, *someone lit a fire*). Stored on your account only — it is never included in anything we send to other users.Until you turn off Settings › Push notifications, move the account to another phone, delete the account, or a delivery attempt shows the token no longer works (e.g. the app was uninstalled)
Notification settings — on/off for *someone lit a fire*, whether you accept it at night, your device's time-zone offset (e.g. UTC+9, a number of minutes — not a city or location) and the app's display language, plus how many of these alerts you got todayYour device, sent together with the push tokenSo alerts respect your local quiet hours and daily limit (at most 2 a day) and arrive in your language.Until account deletion
Technical logs — request metadata (timestamps, status codes, IP address for rate limiting (kept only inside a short-lived counter, not logged with your account))Our infrastructure (Cloudflare)Security, abuse prevention, debugging. Chat text is never written to logs.7 days

Session diagnostics: when a connected AI provider session fails, the app may report why (event name, time, provider, a count) — never cookie names, values, tokens or messages. On by default; turn it off in Settings › Send session diagnostics. The server keeps the last 50 per account and deletes them with the account.

Wall posts (Shout): when you shout on the wall, the text, your display name, your handle and the time are shown to everyone on that wall channel and stored on our servers. Each channel keeps its newest 20,000 lines; older lines drop off automatically. When you delete your account, your wall posts are deleted too. Reported wall posts follow the report rules below.

Push notifications: notifications are sent through Google Firebase Cloud Messaging (Google LLC, USA); on iPhone Google hands them to Apple Push Notification service (Apple Inc., USA) for delivery. Both act as service providers for delivery only. A notification carries a short fixed text in your display language (for example "🔥 The fire is open" / "2 seated — tap to join"), the number of people seated and a random room id so that tapping it opens that room — never names, chat or usage. Notifications are off until you allow them; you can turn them off in Settings › Push notifications (the app then asks our server to delete the token — at the latest the next time you open the app) or in your phone's system settings (that stops notifications from showing, but does not by itself delete the token from our server).

Language in campfires: when you join a campfire, the app sends your chat language and display language. The people at that fire see your chat language as a small flag next to your name, matching uses it to seat people together, and the display language picks the language of notification text. Both are kept only with that room.

Connecting an AI provider: when you connect Claude, Codex or Antigravity, you sign in on the provider's own sign-in page (inside the app, or in a system browser sheet for Antigravity, which hands the result back to the app on your own device). That sign-in goes directly from your device to the provider — your password never passes through our servers, and the resulting session (cookies or access tokens) is kept only on your device — in the in-app browser's own storage, with a backup copy in the secure keystore (iOS Keychain / Android encrypted storage). The app then reads your usage from the provider directly on the device. Our server receives only the usage level (a small integer per provider) and a one-way hash of the provider account id (the *connected-provider source key* above) — never your provider password, cookies, tokens, e-mail or conversations.

Crash reports: if the app crashes or hits an error it cannot handle, it sends a crash report to our crash-reporting service provider, Sentry (Functional Software, Inc., USA), which stores it on our behalf. A report contains the error type and stack trace, the app version, the device model, the operating-system version and a random installation identifier created by the reporting library. Before a report leaves your device the app removes user and request information and deletes anything that looks like a token, cookie, e-mail address or web-address query; error texts that may contain chat (parsing errors) are dropped entirely. Screenshots, screen recordings, taps and network logs are never attached. Sentry scrubs again on its side and does not store IP addresses. Purpose: finding and fixing crashes (our legitimate interest in keeping the app working). On by default; turn it off in Settings › Send error reports — sending stops at once. Reports are deleted automatically within 90 days.

We do not collect: name, e-mail, phone number, contacts, precise location, photos, advertising identifiers, or behavioural analytics events. The app contains no advertising SDK and no analytics SDK. Third-party libraries that send data off your device: the crash reporter above (Sentry); Firebase Cloud Messaging, which registers this app installation with Google for push delivery (on Android this can happen when the app starts, before you allow notifications; the token reaches our server only after you allow them); and, on Android only, Google ML Kit, which translates chat on your device — it downloads language models from Google and may send Google limited technical information about how its APIs perform (such as device model, app version and error counts), but never the chat text.

3. Campfire chat is not stored

Campfire messages are relayed through a server process that keeps them in memory only long enough to forward them to the other people at the same campfire. They are not written to any database, file or log. Because nothing is stored, we cannot retrieve past conversations for you or for anyone else, except the lines your own device attaches to a report you file.

"Not stored" is not the same as "never leaves your phone". Relaying means the text does pass through our servers, so under Google Play's definition — data *collected* is data "transferred off the user's device" — chat counts as collected but processed ephemerally. That is exactly how it is declared in the Play Data Safety form; see Appendix A.

4. Where data lives and who can see it

Our servers run on Cloudflare's global network. Account data is stored in Cloudflare Durable Objects and encrypted at rest by the platform. We do not pin a storage region: Cloudflare places each stored object in one of its data centres (normally near where it was first used), so your data may be stored and processed in any country where Cloudflare operates, which may be outside your own country. The operator is based in the Republic of Korea.

We do not sell data and do not share it with third parties, except service providers acting on our instructions — Cloudflare (hosting), Sentry (crash reports, processed in the United States under Sentry's data processing addendum and its standard contractual clauses), Google Firebase Cloud Messaging and, on iPhone, Apple Push Notification service (delivering notifications, see §2) — and authorities when legally required.

5. Your controls

Your rights

You can ask us to access your data (a copy of what we hold about your account), to correct it, or to delete it, and you can object to or ask us to restrict processing. Much of this is self-service: you can change your nickname and look in the app (the handle cannot be changed), and *Delete account* removes the account at once. For anything else, e-mail [email protected] with your handle (@…). Because accounts are anonymous, we may ask you to confirm from inside the app that the account is yours before we act. We answer and carry out requests within 45 days, or sooner where the law where you live requires it. You may also complain to the data-protection authority where you live.

6. Retention summary

Account data: until you delete the account. Wall posts: until they drop out of the channel's newest 20,000 lines, or until you delete your account. Usage levels: rolling 30 days per connected provider. Reports (both the copy on the reporter's account and the copy on the reported account): 30 days, pruned when touched. Technical logs: 7 days. Crash reports: at most 90 days (Sentry). Transfer codes: 10 minutes. Push token: until you turn notifications off in the app, move or delete the account, or a delivery attempt shows the token no longer works. Chat and display language in a campfire: while that room exists. After deletion, data can remain in our hosting provider's point-in-time recovery history for up to 30 days before it is gone for good. Notification settings (time-zone offset, display language): until account deletion. Suspension flags: until the suspension ends.

7. Children

The app is rated 18+ and the EULA requires users to be 18 or older. We do not knowingly process data of anyone under 18.

8. Changes

We will post changes here with a new effective date. Material changes will be announced in the app.


Appendix A — Google Play Data Safety, exactly as declared (submitted 2026-09-21 · crash reports added 2026-09-25 · push token and notification settings added 2026-09-30)

This is not a summary. It is the declaration filed in the Play Console, line for line, so that the

store form and this policy cannot drift apart.

Data typeCollectedSharedEphemeralRequiredPurpose
Personal info → User ID (handle, nickname)YesNoNoRequiredApp functionality · Account management
App activity → App interactions (currency balances, room events)YesNoNoRequiredApp functionality
App activity → Other user-generated content (wall posts you shout; the chat lines your device attaches when you press *Report*)YesNoNo — wall: newest 20,000 lines per channel, deleted with your account · reports: 30 daysOptional (only when you shout or report)App functionality · Fraud prevention, security and compliance
Messages → Other in-app messages (campfire chat)YesNoYesRequiredApp functionality
Device or other IDs (Android device ID, hashed; push notification token once you allow notifications)YesNoNoRequiredApp functionality · Fraud prevention, security and compliance
Personal info → Other info (chat and display language — sent when you join a campfire, chat language shown to others as a flag; time-zone offset — only with notification settings)YesNoNoRequiredApp functionality
App info and performance → Crash logs (Sentry crash reports)YesNo — Sentry is a service providerNo — up to 90 daysOptional (Settings › Send error reports)Analytics (app stability)
App info and performance → Diagnostics (session diagnostics; device model and OS version in crash reports)YesNoNoOptional (Settings toggles)App functionality · Analytics (app stability)

Everything else — location, photos and videos, audio, contacts, calendar, financial info, health

and fitness, web browsing, other app performance data — is declared as not collected.

Form itemAnswer
Does your app collect or share user data?Collects: yes · Shares: no (Cloudflare, Sentry and Firebase Cloud Messaging are service providers processing on our behalf — Google's form does not count that as sharing)
All collected data encrypted in transitYes (TLS/WSS throughout)
Account creation methodsOther — "An anonymous account is created automatically on first launch from a key the device generates. There is no username, password, e-mail or social sign-in."
Way for users to request data deletionYes — https://petspunk.nlap.app/account/delete/ (and in-app: wallet chip → Delete account)

On "ephemeral" for chat. Google's form defines *ephemeral* as data that is accessed and used

only in memory, held no longer than needed to serve the request. That is what a relay does. Google

also states that ephemerally-processed data is still disclosed in this form, though it is not shown

to users in the store listing. So: chat is collected, ephemerally processed, never stored — the

three statements are consistent, and §3 above says the same thing in words.

Appendix B — Apple App Privacy

Data typeLinked to userTrackingPurpose
Identifiers → User ID (anonymous account/handle)YesNoApp functionality
Identifiers → Device ID (push notification token, only after you allow notifications)YesNoApp functionality
Usage Data → Product interaction (room events, balances)YesNoApp functionality
User Content → Other (Wall posts you shout; chat lines attached to a report — both user-initiated)YesNoApp functionality (Wall; safety)
Diagnostics → Crash Data (Sentry crash reports)NoNoApp functionality
Diagnostics → Other diagnostic data (request logs, session diagnostics, device model/OS in crash reports)NoNoApp functionality
Other Data → Other Data Types (time-zone offset and display language, sent with notification settings; chat language shown as a flag in campfires)YesNoApp functionality

No tracking; no data used for advertising.


한국어 번역본 — 해석이 다를 때는 위 영어본이 정본이다.

petspunk — 개인정보 처리방침 (한국어 번역본)

앱: PetsPunk: AI Usage Campfire (app.nlap.petspunk) · 운영자: nlap (대한민국) · 연락처: [email protected]

시행일: 2026-09-30 · 정본 언어: 영어(PRIVACY.md). 이 문서는 편의를 위한 번역이며 해석이 다를 때는 영어본을 따른다.

1. 이 앱은 무엇인가

petspunk 는 AI 구독 사용량을 작은 인앱 재화로 바꿔, 최대 6명이 둘러앉는 픽셀 모닥불에서 쓰게 하는 앱이다. 회원가입이 없다 — 첫 실행에 익명 계정이 만들어진다. 모닥불 채팅은 실시간으로 중계만 되고 서버에 저장되지 않는다. 담벼락 글(외치기)은 다르다 — 공개되고 저장된다(§2).

2. 처리하는 정보와 이유

정보출처이유보관
설치 키(도장) — 첫 실행 때 기기가 만드는 32바이트 난수사용자 기기익명 계정의 정체성. 같은 설치는 언제나 같은 계정으로 돌아온다(이메일·전화번호·비밀번호 없음). 서버는 솔트 해시만 저장한다.계정 삭제 시까지
기기 식별자(Android 만) — Android 기기 ID(ANDROID_ID/SSAID)에 앱 고유 솔트를 더해 만든 일방향 해시사용자의 Android 기기계정 연속성: 앱을 지웠다 다시 깔아도 새 계정이 아니라 원래 계정으로 돌아오게 한다. 부정 이용 제한(기기 하나에 복구 계정 하나)에도 쓴다. 기기 ID 원값은 기기를 떠나지 않고, 서버는 유도된 해시만 받아 저장한다.계정 삭제 시까지
계정 토큰 — 서버가 발급서버요청 인증. 기기에서는 보안 저장소(Keychain/Keystore)에, 서버에는 해시로만 저장.실행마다 회전, 최근 2개 보관
핸들(@xxxxxxxx) · 닉네임 · 펫 룩(파츠/컬러 키)서버 유도 / 사용자 선택방과 신고에서 쓰는 공개 식별자. 핸들은 바꿀 수 없다. 닉네임과 룩은 계정에 저장되어 재설치·기기 이전에서도 따라온다.계정 삭제 시까지
인앱 재화 잔액(장작 ✦·숯 ◆·재 ❖)과 방 사건(장작·드랍)플레이로 생성게임 경제는 서버가 관리한다.계정 삭제 시까지
AI 사용량 수준(연결한 제공자별 작은 정수)제공자를 연결한 뒤 앱이 보고인앱 재화 지급. 원시 사용 기록·결제 정보·제공자 계정 식별자는 저장하지 않는다.제공자별 최근 30일(§6 참조)
이전 코드(8자, 10분)새 폰으로 계정을 옮길 때 생성새 기기가 계정을 이어받게 한다. 해시로 저장, 1회용.10분
신고 — 누군가를 *신고*하면 사용자의 기기가 갖고 있는 최근 메시지(방 대화 최대 30줄 + 신고 대상의 최근 발언 8줄, 이름 포함 최대 40줄)와 신고 대상 핸들·사유를 올린다. 사본은 사용자 계정과 피신고 계정에 남고, 모더레이션 큐에는 누가·사유·시각만(본문 없음) 들어간다사용자 기기(신고 버튼을 눌렀을 때만)안전 검토(EULA §6).30일 뒤 삭제
차단 목록 — 내가 차단한 사람의 핸들·표시 이름·계정 id·시각(최대 200)차단을 누를 때다시 매칭되지 않게. 해제하거나 계정을 지울 때까지
나에 대한 신고 — 사유·신고자 id·첨부된 대화 줄(최대 100, 30일 보관)다른 사용자가 나를 신고할 때신뢰·안전 검토. 신고자나 내가 계정을 지워도 30일은 남는다(삭제로 증거를 지울 수 없게)
연결한 제공자 소스 키 — 연결한 AI 계정 식별자의 단방향 SHA-256 해시(32자)연결할 때 기기에서 계산계정당 한 번만 보상하고 제공자당 3계정 제한을 지키기 위해. 원문 식별자는 기기 밖으로 안 나가고 해시는 되돌릴 수 없다
앱 안 기록 — 지갑 잔액·획득 내역·해금한 캐릭터·우편·방 통계(앉은 횟수·태운 장작·말한 적 있는지)플레이하면서 생성게임 기능. 계정을 지울 때까지
세션 진단 이벤트 — 연결한 AI 제공자 세션이 끊긴 이유(사건 이름 · 시각 · 제공자 · 개수). 쿠키 이름·값·토큰·대화는 담기지 않는다연결이 실패했을 때 앱이 모아 보고(설정 세션 진단 보내기, 기본 켬, 끌 수 있음)«아무것도 안 했는데 세션이 만료된다» 류의 결함을 찾기 위해. 계정당 최근 50건, 계정을 지우면 함께 삭제
푸시 알림 토큰 — Firebase 클라우드 메시징(FCM)이 이 기기의 이 앱에 발급하는 등록 토큰(아이폰에서는 Firebase 가 애플 푸시 토큰과 연결한다)과 플랫폼(ios/android)사용자 기기(알림을 허용한 뒤에만)사용자가 켠 알림(*불이 열렸다*, *누가 불을 피웠다*)을 보내기 위해. 계정에만 저장하고, 다른 사용자에게 보내는 어떤 것에도 싣지 않는다.설정 › 푸시 알림을 끄거나, 계정을 다른 폰으로 옮기거나, 계정을 지우거나, 보내려다 토큰이 더는 쓰이지 않는 것(앱 삭제 등)이 확인될 때까지
알림 설정 — *누가 불을 피우면 알림* 켬/끔, 밤에도 받는지, 기기의 시간대 차이(예: UTC+9 — 분 단위 숫자이며 도시나 위치가 아니다)와 앱의 화면 언어, 그날 이 알림을 받은 횟수사용자 기기(푸시 토큰과 함께 보냄)사용자 기기 시각 기준으로 조용한 시간과 하루 상한(하루 2번)을 지키고, 사용자 언어로 알림을 보내기 위해.계정 삭제 시까지
기술 로그 — 요청 메타데이터(시각·상태 코드·레이트리밋용 대략적 IP)인프라(Cloudflare)보안·부정 방지·장애 분석. 채팅 본문은 로그에 쓰지 않는다.7일

담벼락 글(외치기): 담벼락에 외치면 글, 표시 이름, 핸들, 시각이 그 담벼락 채널의 모든 사람에게 보이고 서버에 저장된다. 채널마다 가장 최근 2만 줄까지 남고 그보다 오래된 줄은 자동으로 사라진다. 계정을 지우면 내 담벼락 글도 함께 지워진다. 신고된 담벼락 글은 아래 신고 규칙을 따른다.

푸시 알림: 알림은 Google Firebase 클라우드 메시징(Google LLC, 미국)을 거쳐 보내고, 아이폰에서는 Google 이 Apple 푸시 알림 서비스(APNs)(Apple Inc., 미국)에 넘겨 전달한다. 둘 다 전달만 맡는 서비스 제공자다. 알림에는 화면 언어로 된 짧은 정해진 문구(예: «🔥 불이 열렸다» / «2명이 앉았다 — 눌러서 들어간다»), 앉은 사람 수, 눌렀을 때 그 방으로 가기 위한 무작위 방 id 만 담긴다 — 이름·채팅·사용량은 담기지 않는다. 알림은 사용자가 허용하기 전까지 꺼져 있고, 설정 › 푸시 알림(끄면 앱이 서버에 토큰 삭제를 요청한다 — 늦어도 다음에 앱을 열 때)이나 폰의 시스템 설정에서 끌 수 있다(시스템 설정으로 끄면 알림이 뜨지 않을 뿐, 그것만으로 서버의 토큰이 지워지지는 않는다).

모닥불의 언어: 모닥불에 들어갈 때 앱은 채팅 언어와 화면 언어를 보낸다. 같은 불의 사람들에게는 채팅 언어가 이름 옆 작은 국기로 보이고, 매칭은 이것으로 자리를 모으며, 화면 언어는 알림 문구의 언어를 고르는 데 쓴다. 둘 다 그 방에만 남는다.

AI 제공자 연결: Claude·Codex·Antigravity 를 연결할 때는 제공자 자신의 로그인 화면(앱 안, Antigravity 는 시스템 브라우저 창 — 로그인 결과는 사용자 기기 안에서 앱으로 돌아온다)에 로그인한다. 이 로그인은 사용자 기기와 제공자 사이에서 곧바로 이루어진다 — 비밀번호는 우리 서버를 거치지 않고, 로그인으로 생긴 세션(쿠키나 접근 토큰)은 사용자 기기에만 둔다 — 앱 안 브라우저 자체 저장소에, 백업 사본은 보안 저장소(iOS Keychain / Android 암호화 저장소)에. 앱은 사용량도 기기에서 제공자에게 직접 읽어 온다. 우리 서버가 받는 것은 사용량 수준(제공자별 작은 정수)과 제공자 계정 id 의 단방향 해시(위 *연결한 제공자 소스 키*)뿐이다 — 제공자 비밀번호·쿠키·토큰·이메일·대화는 절대 받지 않는다.

오류 보고: 앱이 멈추거나 처리하지 못한 오류가 나면, 오류 보고 서비스 제공자 Sentry(Functional Software, Inc., 미국)에 보고서를 보내고 Sentry 가 우리를 대신해 보관한다. 보고서에는 오류 종류와 스택, 앱 버전, 기기 모델, OS 버전, 보고 라이브러리가 만든 무작위 설치 식별자가 담긴다. 보고서가 기기를 떠나기 전에 앱이 사용자·요청 정보를 비우고, 토큰·쿠키·이메일 주소·웹 주소의 질의 부분처럼 보이는 것을 지운다. 채팅이 섞일 수 있는 오류 문구(파싱 오류)는 통째로 버린다. 화면 캡처·화면 녹화·누른 곳·네트워크 기록은 붙이지 않는다. Sentry 도 받는 쪽에서 한 번 더 지우고 IP 주소를 저장하지 않는다. 목적: 앱이 멈추는 원인을 찾아 고치기(앱을 제대로 돌리려는 정당한 이익). 기본 켬이며 설정 › 오류 보고 보내기 에서 끌 수 있고, 끄면 곧바로 보내기가 멈춘다. 보고서는 90일 안에 자동 삭제된다.

수집하지 않는 것: 이름·이메일·전화번호·연락처·정밀 위치·사진·광고 식별자·행동 분석 이벤트. 광고 SDK 와 분석 SDK 가 없다. 기기 밖으로 정보를 보내는 서드파티 라이브러리는 셋이다 — 위의 오류 보고(Sentry), 이 앱 설치를 Google 에 푸시 전달용으로 등록하는 Firebase 클라우드 메시징(Android 에서는 알림을 허용하기 전, 앱이 시작할 때 등록될 수 있다 — 토큰이 우리 서버로 오는 것은 허용한 뒤뿐이다), 그리고 Android 에서만 채팅을 기기 안에서 번역하는 Google ML Kit. ML Kit 은 Google 에서 언어 모델을 내려받고, API 가 어떻게 동작했는지에 관한 제한된 기술 정보(기기 모델·앱 버전·오류 수 등)를 Google 에 보낼 수 있지만 채팅 글은 보내지 않는다.

3. 모닥불 채팅은 저장되지 않는다

모닥불 메시지는 같은 모닥불의 다른 사람에게 전달하는 동안만 서버 메모리에 머물고, 어떤 데이터베이스·파일·로그에도 쓰이지 않는다. 저장된 것이 없으므로 과거 대화를 누구에게도 되돌려 줄 수 없다. 예외는 사용자가 신고할 때 사용자 기기가 첨부하는 줄뿐이다.

«저장하지 않는다»와 «기기 밖으로 안 나간다»는 다른 말이다. 중계란 글자가 우리 서버를 거친다는 뜻이고,

Google Play 는 «수집»을 «기기 밖으로 전송되는 것» 으로 정의한다. 그래서 채팅은 **수집되되 임시로만

처리되는** 것으로 신고돼 있다(부록 A). 저장하지 않는다는 위 문장과 모순이 아니라, 같은 사실을 스토어 양식의

말로 옮긴 것이다.

4. 어디에 저장되고 누가 보는가

서버는 Cloudflare 글로벌 네트워크에서 돈다. 계정 데이터는 Cloudflare Durable Objects 에 저장되며 플랫폼이 저장 시 암호화한다. 저장 지역을 지정하지 않는다: Cloudflare 가 저장 객체마다 자기 데이터센터 한 곳(보통 처음 쓰인 곳 가까이)에 두므로, 데이터는 Cloudflare 가 운영하는 어느 나라에서든 저장·처리될 수 있고 사용자가 사는 나라 밖일 수 있다. 운영자는 대한민국에 있다.

데이터를 판매하지 않으며, 우리 지시에 따라 처리하는 서비스 제공자 — Cloudflare(호스팅), Sentry(오류 보고, Sentry 의 데이터 처리 부속서와 표준계약조항에 따라 미국에서 처리), Google Firebase 클라우드 메시징과 아이폰에서는 Apple 푸시 알림 서비스(알림 전달, §2) — 와 법적 요구가 있는 기관 외에는 제3자에게 제공하지 않는다.

5. 사용자가 할 수 있는 것

사용자의 권리

사용자는 자기 정보의 열람(계정에 대해 우리가 가진 정보의 사본), 정정, 삭제를 요청할 수 있고, 처리에 반대하거나 처리 제한을 요청할 수 있다. 많은 부분은 직접 할 수 있다 — 닉네임과 룩은 앱에서 바꿀 수 있고(핸들은 바꿀 수 없다), *계정 삭제*는 계정을 즉시 지운다. 그 밖의 요청은 핸들(@…)과 함께 [email protected] 으로 보낸다. 계정이 익명이라, 처리 전에 그 계정이 본인 것임을 앱 안에서 확인해 달라고 요청할 수 있다. 요청은 45일 안에 답하고 처리한다. 사는 곳의 법이 더 짧은 기한을 정하면 그 기한을 따른다. 사는 곳의 개인정보 감독기관에 민원을 낼 수도 있다.

6. 보관 기간 요약

계정 데이터: 계정 삭제 시까지. 담벼락 글: 채널의 최근 2만 줄에서 밀려나거나 계정을 지울 때까지. 사용량 수준: 제공자별 최근 30일. 신고(신고자·피신고자 양쪽 사본): 30일, 접근 시 정리. 기술 로그: 7일. 오류 보고: 최대 90일(Sentry). 이전 코드: 10분. 푸시 토큰: 앱에서 알림을 끄거나, 계정을 옮기거나 지우거나, 보내려다 토큰이 더는 쓰이지 않는 것이 확인될 때까지. 알림 설정(시간대 차이·화면 언어): 계정 삭제 시까지. 모닥불의 채팅·화면 언어: 그 방이 있는 동안. 지운 데이터도 호스팅 제공자의 시점 복구 기록에 최대 30일 남았다가 완전히 사라진다.

7. 아동

이 앱은 18+ 등급이며 EULA 가 18세 이상을 요구한다. 18세 미만의 정보를 고의로 처리하지 않는다.

8. 변경

변경 시 새 시행일과 함께 여기에 게시한다. 중요한 변경은 앱 안에서 알린다.


부록 A(Google Play 데이터 보안 매핑)·부록 B(Apple 앱 개인정보) 는 영어본 PRIVACY.md 를 따른다.

부록 A 는 요약이 아니라 2026-09-21 에 Play Console 에 실제로 신고한 내용 그대로다 — 스토어 양식과 이 방침이

따로 놀지 않게 하려는 것이다. 한 줄로: 수집하는 것은 **사용자 ID · 앱 상호작용 · 담벼락 글과 신고에 붙는 채팅 줄(선택) ·

채팅(임시) · 기기 ID 해시 다섯 가지에 오류 보고(충돌 기록·진단, 선택, 2026-09-25 추가) 와 푸시 알림 토큰(기기 ID 항목) · 모닥불의 채팅·화면 언어와 알림 설정의 시간대 차이(기타 정보, 2026-09-30 추가) 가 더해졌다. 제3자와 공유하는 것은 없다** — Cloudflare·Sentry·Firebase 클라우드 메시징은 우리를 대신해 처리하는 서비스 제공자이고, Google 양식은 이를 공유로 세지 않는다.