한국어 · English

Alleydex Privacy Policy

Effective: 2026-07-29 · Last updated: 2026-07-29 · The previous version (2026-07-06) is superseded by this one.
This is an English translation provided for your convenience. The Korean version is the authoritative text and prevails in case of any discrepancy.

Alleydex (Korean name 줍냥이, “Jupnyangi”; the “App”) is operated by an individual developer in the Republic of Korea and complies with the Korean Personal Information Protection Act (“PIPA”), the Act on the Protection and Use of Location Information (“Location Information Act”) and other applicable laws. This policy describes, factually, what the App actually collects, where it is sent, how long it is kept, and how you can control it.

0. At a glance

1. What we process, why, and for how long

The App processes the items below. Items marked as account-linked are stored on our server together with the identifier of your signed-in account.

① Processed even if you never sign in or use backup

ItemPurposeHow it is handled / recipientRetention
Animal photos you take or select AI character card generation; coat pattern and colour detection Sent through a developer-operated relay server (Vercel) to Google Gemini (United States). The request is anonymous and keyed to a device identifier. The relay does not store photos; it only forwards them. Google's retention is not verified by us and follows the recipient's API data policy.
Coarse location (a coordinate blurred to roughly 200–500 m) The “met here” minimap on the back of a card Stored on your device. When a map is drawn, the blurred coordinate and your device IP are sent to MapTiler (abroad). The on-device value is removed when you delete the card or the App. MapTiler's retention is not verified by us and follows the recipient's policy.
Device identifier (installId, a UUID stored in the device keychain) Relay usage control, anonymous analytics, identifying your support tickets Sent to the relay (Vercel) and to Supabase (Seoul). It is an anonymous identifier not combined with your name or email, but it may survive deleting and reinstalling the App. Follows the retention of the record it belongs to (see the analytics and support rows).
IP address Blocking excessive API calls (rate limiting) Stored by the relay (Vercel) in Upstash Redis as a rate-limit key. The storage region is not verified. Expires automatically after about 2 days
Anonymous usage analytics (device ID, session ID, app version, OS version, locale, event name) Product improvement, error diagnosis Sent through the relay and stored in Supabase (Seoul). Not linked to an account. Until the improvement purpose is fulfilled. You can turn this off at any time in Collection > Privacy & Consent.
Advertising identifier and other data processed by the ad SDK Serving and measuring rewarded ads Processed by the Google AdMob SDK (United States). If you decline tracking (App Tracking Transparency) on iOS, or choose Delete advertising ID under Settings > Privacy > Ads on Android, non-personalised ads are shown instead. Per Google's advertising policies (policies.google.com/technologies/ads).

② Stored on our server and linked to your account when you sign in and use backup

The items below are stored on the developer-operated server (Supabase, Seoul ap-northeast-2 region) linked to your account identifier, only once you have signed in with Apple or Google and use backup. If you do not sign in, none of it is sent to the server.

ItemPurposeWhen collectedRetention
Email address and name (as provided by Apple / Google sign-in) Account creation and identification, restoring your backup across devices At sign-in Until account deletion
Nickname Shown in the friends list and gifting. Visible to your friends. When you save a nickname Until account deletion (deleted together with your account)
Photo copy (a metadata-stripped JPEG — faces and licence plates are not obscured) Card backup and restore When you create or sync a card while backup is on Deleted when you delete that card or your account
Card artwork (PNG) Card backup and restore Same as above Same as above
Card data — card name, abilities, personality, stats, species (cat / dog), coat pattern and colour, rarity, coarse location (blurred coordinate), capture time, affinity, and similar Card backup and restore, collection display Same as above Same as above
Push notification token (APNs on iOS, FCM on Android) Sending notifications When notifications are on and you are signed in Deleted when you sign out, and deleted together with your account
Friendships, invite codes, gift and trade ledger Providing the friends, gifting and trading features When you add a friend, send a gift or make a trade Until account deletion. However, gift and trade history is preserved for the other party's records: only your account identifier is removed and the entry remains together with the nickname recorded at the time (see §8).

③ Statutory records created when you use the location feature

ItemPurposeRecipientRetention
Records confirming the use and provision of location information — user identifier, date and time, use/provision type, recipient (our server or the map provider), and count Statutory recording and retention under Article 16(2) of the Location Information Act Supabase (Seoul) Automatically destroyed after 6 months. These records are kept for that period even if you delete your account (a statutory obligation).

The coordinate values themselves are not included in these records. You may request access to, and notification of, these records (Article 7 of the Location-Based Service Terms).

④ Processed when you contact support or report content

ItemPurposeRecipientRetention
Ticket body, ticket category, reply contact, nickname, app version, platform, device ID Receiving and answering your inquiry, handling follow-up inquiries Supabase (Seoul). Linked to your account if you are signed in, otherwise to your device ID. 3 years after the ticket is closed (for dispute handling). Support tickets are not deleted when you delete your account.
Full text of the support conversation Automatically generating a draft reply for the operator to review Anthropic, PBC (United States) — sent as soon as the ticket is submitted Per the recipient's API data policy (retention not verified by us).
Ticket body, nickname, AI draft reply Notifying the operator (a solo developer) immediately Telegram FZ-LLC (abroad) — sent as soon as the ticket arrives Remains in the operator's messenger chat until the operator deletes it. It is not deleted automatically.
Report reason and a snapshot of the reported card Handling inappropriate content, preventing repeat and false reports Supabase (Seoul), linked to your account 3 years from the date the report is filed (destroyed only once the report has been handled; reports still open are kept until handling is complete). Abuse reports are not deleted when you delete your account.

⑤ Payments

In-app purchases are processed by Apple's App Store billing (StoreKit) on iOS and Google Play Billing on Android. The App does not collect payment-method details such as card numbers, and does not validate or store receipts on its own server. Payment data is processed under the privacy policy of the relevant store operator (Apple or Google).

2. Important — how photos are handled before they are sent

3. Transfer of personal data abroad

Personal data is transferred outside the Republic of Korea in the cases below. In accordance with Article 28-8 of PIPA we disclose the following and obtain your consent. You may decline to consent to a cross-border transfer, but in that case the corresponding features (card generation, map display, support, notifications) cannot be used.

① Photo → AI card generation

Items transferredAnimal photo (EXIF-stripped where possible, otherwise the original — see §2. Faces and licence plates are not obscured)
RecipientGoogle LLC (Gemini API)
Recipient contact1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · privacy enquiries: support.google.com/policies (policy: policies.google.com/privacy)
CountryUnited States
Date and method of transferTransmitted over a network (HTTPS API) at the moment you generate a card or classify a photo
Purpose of useAI character card generation; coat pattern and colour detection
Retention and use periodPer the recipient's (Google's) API data policy. The App operator has not been able to verify the recipient's actual retention period. The relay server on the transmission path does not store photos.

② Coarse location → map display (card-back minimap)

Items transferredCoarse location (a coordinate blurred to roughly 200–500 m), device IP address
RecipientMapTiler AG
Recipient contactHöfnerstrasse 98, 6314 Unterägeri, Switzerland · privacy@maptiler.com (policy: maptiler.com/privacy-policy)
CountryAbroad (Switzerland / EU and a global CDN)
Date and method of transferTransmitted as map tile requests (HTTPS) each time you view the back of a card
Purpose of useRendering the “met here” map image on the back of a card
Retention and use periodPer the recipient's (MapTiler's) policy. The App operator has not been able to verify the recipient's actual retention period.

③ Support conversation → AI draft reply

Items transferredFull text of the support conversation (the ticket you wrote and any follow-up messages)
RecipientAnthropic, PBC (Claude API)
Recipient contact548 Market St, PMB 90375, San Francisco, CA 94104, USA · privacy@anthropic.com (policy: anthropic.com/legal/privacy)
CountryUnited States
Date and method of transferTransmitted over a network (HTTPS API) as soon as you submit a ticket or send a reply
Purpose of useAutomatically generating a draft reply for the operator to review and edit
Retention and use periodPer the recipient's (Anthropic's) API data policy. The App operator has not been able to verify the recipient's actual retention period. We recommend that you do not include unnecessary personal data such as names or contact details in the ticket body.

④ Support notification → operator's messenger

Items transferredTicket body, nickname, AI draft reply
RecipientTelegram FZ-LLC (Telegram Bot API)
Recipient contactBusiness Center, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE · dpo@telegram.org (policy: telegram.org/privacy)
CountryAbroad (United Arab Emirates and the provider's global servers)
Date and method of transferTransmitted over a network (HTTPS API) as soon as a ticket is received
Purpose of useNotifying the solo operator that a ticket has arrived, and approving the reply
Retention and use periodStored in the operator's messenger chat and remains there until the operator deletes it. If you request deletion of your support history, the operator will also delete the corresponding chat messages.

⑤ Push notification delivery

Items transferredAPNs push token, notification content
RecipientApple Inc. (Apple Push Notification service)
Recipient contactOne Apple Park Way, Cupertino, CA 95014, USA · policy: apple.com/legal/privacy
CountryUnited States
Date and method of transferTransmitted over a network (APNs) at the moment a notification is sent
Purpose of useDelivering push notifications for friends, gifts, support replies and similar
Retention and use periodFor as long as delivery requires; thereafter per Apple's policy.

The table above applies to iOS (APNs); the table below applies to Android (FCM).

Items transferredFCM registration token, notification content
RecipientGoogle LLC (Firebase Cloud Messaging)
Recipient contact1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · policy: policies.google.com/privacy
CountryUnited States
Date and method of transferTransmitted over a network (FCM HTTP v1 API) at the moment a notification is sent
Purpose of useDelivering push notifications for friends, gifts, support replies and similar
Retention and use periodFor as long as delivery requires; thereafter per Google's policy.

⑥ Advertising

Items transferredAdvertising identifier and device / network information related to the ad request (collected by the Google AdMob SDK)
RecipientGoogle LLC (Google AdMob)
Recipient contact1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · policies.google.com/technologies/ads
CountryUnited States
Date and method of transferTransmitted through the ad SDK at the moment a rewarded ad is loaded
Purpose of useAd delivery, frequency capping, performance measurement
Retention and use periodPer Google's advertising data policy. If you decline tracking under iOS Settings > Privacy & Security > Tracking, non-personalised ads are shown.

For matters concerning the use of location information, please also see the Location-Based Service Terms.

4. Entrustment of personal data processing

To provide the service, the App entrusts personal data processing as set out below. Each processor handles personal data only within the scope of the entrusted purpose.

ProcessorEntrusted taskProcessing region
Supabase Inc.Hosting the server, database and file storage, and account authentication (storing account data, card data, photo and artwork copies, support and report records, notification tokens, analytics)Republic of Korea, Seoul region (ap-northeast-2)
Vercel Inc.Hosting the relay (proxy) server — forwarding AI requests and relaying analytics. It does not store photos.The deployment region is not verified and may be the United States.
Upstash, Inc.Temporary storage of IP addresses for rate limiting (expires after about 2 days)The storage region is not verified.
Google LLCAI image generation and analysis (Gemini API), ad serving (AdMob), push delivery (FCM, Android), in-app purchase processing (Google Play, Android)United States
MapTiler AGProviding map tiles for the back of a cardAbroad
Anthropic, PBCGenerating draft support repliesUnited States
Telegram FZ-LLCDelivering support notifications to the operatorAbroad
Apple Inc.Push delivery (APNs, iOS), in-app purchase processing (App Store, iOS)United States

5. Provision of personal data to third parties

Apart from the cross-border transfers and the entrusted processing described in §3 and §4, the App does not provide your personal data to third parties. We may, however, comply where there is a specific provision of law or where an investigative authority makes a request in accordance with the procedures and methods prescribed by law.

If you use the friends and gifting features, the nickname you set and the card data you exchange are displayed in the App to the friends you have connected with. This is a disclosure that results from your own use of the feature; if you do not want it, you can choose not to use the friends feature, or remove a friend.

6. Destruction of personal data

Personal data whose retention period has expired or whose processing purpose has been achieved is destroyed without delay. Electronic files are deleted in a manner that makes them unrecoverable. As set out in §8 below, however, certain items are retained separately after account deletion for dispute handling and abuse prevention.

7. Your rights, and those of a legal representative, and how to exercise them

8. What account deletion actually removes — and what it does not

Stated factually, so that you know exactly where you stand.

ItemOn account deletion
Account data (email, name), and backed-up photo copies, card artwork and card data (including the coarse location)Deleted.
Cards and photos stored on your deviceRemoved from the device when you delete the App or reset your collection.
Support tickets (ticket body, category, reply contact, nickname, app version, device ID)Not deleted with your account. Retained for 3 years from the date the ticket is closed to handle disputes over support and refunds, then destroyed. If you want them deleted sooner, email tsetse012@gmail.com and we will delete them to the extent no statutory retention duty applies.
Abuse reports (report reason, snapshot of the reported card)Not deleted with your account. Retained for 3 years from the date the report is filed to prevent re-posting of inappropriate content and repeat or false reports, then destroyed (this applies to reports that have been handled).
Records confirming the use and provision of location information (date and time, use/provision type, recipient, count)Not deleted with your account. Article 16 of the Location Information Act requires operators to record and retain these for 6 months, so they are kept for that period after you leave and then destroyed. They contain no coordinate values and no card content.
Support notifications already delivered to the operator's messenger (Telegram)Not deleted automatically. The operator will delete those messages on request.
Nickname, push notification token, friendships and invite codes, block listDeleted.
Gift and trade historyYour user identifier (account ID) is deleted, but the record itself remains. This is because the other party to the gift or trade must still be able to see “who this card came from” on their own card. What remains is only the nickname string recorded at the time of the gift; it is not linked to an account, an email address or a device.
Data already transferred to overseas recipients (Google, MapTiler, Anthropic, Telegram, Apple)The App operator cannot delete it directly; each recipient's own data policy applies.

9. Personal data of children under 14

The App is not directed at children under the age of 14, and only users who have confirmed that they are 14 or older may use it. If we learn that the personal data of a child under 14 has been collected without the consent of a legal representative, we destroy that data without delay. In addition, under the Location Information Act, the consent of a guardian is required to use the location information of a child aged 8 or under and certain other protected persons (see the Location-Based Service Terms).

10. Measures to secure personal data

11. Data controller, privacy officer and contact

Data controller: Nunchi (눈치) — a sole proprietorship registered in the Republic of Korea, business registration no. 640-51-00912
Privacy officer: Subin Kim (김수빈), proprietor
Privacy enquiries, access and deletion requests: tsetse012@gmail.com

You may report or seek advice about an infringement of your personal data with the following Korean authorities: Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr) · Privacy Infringement Report Centre (118, privacy.kisa.or.kr) · Supreme Prosecutors' Office Cybercrime Investigation Division (1301) · National Police Agency Cyber Bureau (182).

12. Changes to this policy

This policy applies from 29 July 2026. The previous policy (effective 6 July 2026) is superseded by this one. Where content is added, removed or amended, the changes are posted on this page, and changes that materially affect your rights are additionally announced within the App.

한국어 원문 보기 · Read the authoritative Korean version