한국어 · English
Effective: 2026-07-29 · Last updated: 2026-07-29 · The previous version (2026-07-06) is superseded by this one.
This is an English translation provided for your convenience. The Korean version is the authoritative text and prevails in case of any discrepancy.
Alleydex (Korean name 줍냥이, “Jupnyangi”; the “App”) is operated by an individual developer in the Republic of Korea and complies with the Korean Personal Information Protection Act (“PIPA”), the Act on the Protection and Use of Location Information (“Location Information Act”) and other applicable laws. This policy describes, factually, what the App actually collects, where it is sent, how long it is kept, and how you can control it.
The App processes the items below. Items marked as account-linked are stored on our server together with the identifier of your signed-in account.
| Item | Purpose | How it is handled / recipient | Retention |
|---|---|---|---|
| Animal photos you take or select | AI character card generation; coat pattern and colour detection | Sent through a developer-operated relay server (Vercel) to Google Gemini (United States). The request is anonymous and keyed to a device identifier. | The relay does not store photos; it only forwards them. Google's retention is not verified by us and follows the recipient's API data policy. |
| Coarse location (a coordinate blurred to roughly 200–500 m) | The “met here” minimap on the back of a card | Stored on your device. When a map is drawn, the blurred coordinate and your device IP are sent to MapTiler (abroad). | The on-device value is removed when you delete the card or the App. MapTiler's retention is not verified by us and follows the recipient's policy. |
Device identifier (installId, a UUID stored in the device keychain) |
Relay usage control, anonymous analytics, identifying your support tickets | Sent to the relay (Vercel) and to Supabase (Seoul). It is an anonymous identifier not combined with your name or email, but it may survive deleting and reinstalling the App. | Follows the retention of the record it belongs to (see the analytics and support rows). |
| IP address | Blocking excessive API calls (rate limiting) | Stored by the relay (Vercel) in Upstash Redis as a rate-limit key. The storage region is not verified. | Expires automatically after about 2 days |
| Anonymous usage analytics (device ID, session ID, app version, OS version, locale, event name) | Product improvement, error diagnosis | Sent through the relay and stored in Supabase (Seoul). Not linked to an account. | Until the improvement purpose is fulfilled. You can turn this off at any time in Collection > Privacy & Consent. |
| Advertising identifier and other data processed by the ad SDK | Serving and measuring rewarded ads | Processed by the Google AdMob SDK (United States). If you decline tracking (App Tracking Transparency) on iOS, or choose Delete advertising ID under Settings > Privacy > Ads on Android, non-personalised ads are shown instead. |
Per Google's advertising policies (policies.google.com/technologies/ads). |
The items below are stored on the developer-operated server (Supabase, Seoul ap-northeast-2 region) linked to your account identifier, only once you have signed in with Apple or Google and use backup. If you do not sign in, none of it is sent to the server.
| Item | Purpose | When collected | Retention |
|---|---|---|---|
| Email address and name (as provided by Apple / Google sign-in) | Account creation and identification, restoring your backup across devices | At sign-in | Until account deletion |
| Nickname | Shown in the friends list and gifting. Visible to your friends. | When you save a nickname | Until account deletion (deleted together with your account) |
| Photo copy (a metadata-stripped JPEG — faces and licence plates are not obscured) | Card backup and restore | When you create or sync a card while backup is on | Deleted when you delete that card or your account |
| Card artwork (PNG) | Card backup and restore | Same as above | Same as above |
| Card data — card name, abilities, personality, stats, species (cat / dog), coat pattern and colour, rarity, coarse location (blurred coordinate), capture time, affinity, and similar | Card backup and restore, collection display | Same as above | Same as above |
| Push notification token (APNs on iOS, FCM on Android) | Sending notifications | When notifications are on and you are signed in | Deleted when you sign out, and deleted together with your account |
| Friendships, invite codes, gift and trade ledger | Providing the friends, gifting and trading features | When you add a friend, send a gift or make a trade | Until account deletion. However, gift and trade history is preserved for the other party's records: only your account identifier is removed and the entry remains together with the nickname recorded at the time (see §8). |
| Item | Purpose | Recipient | Retention |
|---|---|---|---|
| Records confirming the use and provision of location information — user identifier, date and time, use/provision type, recipient (our server or the map provider), and count | Statutory recording and retention under Article 16(2) of the Location Information Act | Supabase (Seoul) | Automatically destroyed after 6 months. These records are kept for that period even if you delete your account (a statutory obligation). |
The coordinate values themselves are not included in these records. You may request access to, and notification of, these records (Article 7 of the Location-Based Service Terms).
| Item | Purpose | Recipient | Retention |
|---|---|---|---|
| Ticket body, ticket category, reply contact, nickname, app version, platform, device ID | Receiving and answering your inquiry, handling follow-up inquiries | Supabase (Seoul). Linked to your account if you are signed in, otherwise to your device ID. | 3 years after the ticket is closed (for dispute handling). Support tickets are not deleted when you delete your account. |
| Full text of the support conversation | Automatically generating a draft reply for the operator to review | Anthropic, PBC (United States) — sent as soon as the ticket is submitted | Per the recipient's API data policy (retention not verified by us). |
| Ticket body, nickname, AI draft reply | Notifying the operator (a solo developer) immediately | Telegram FZ-LLC (abroad) — sent as soon as the ticket arrives | Remains in the operator's messenger chat until the operator deletes it. It is not deleted automatically. |
| Report reason and a snapshot of the reported card | Handling inappropriate content, preventing repeat and false reports | Supabase (Seoul), linked to your account | 3 years from the date the report is filed (destroyed only once the report has been handled; reports still open are kept until handling is complete). Abuse reports are not deleted when you delete your account. |
In-app purchases are processed by Apple's App Store billing (StoreKit) on iOS and Google Play Billing on Android. The App does not collect payment-method details such as card numbers, and does not validate or store receipts on its own server. Payment data is processed under the privacy policy of the relevant store operator (Apple or Google).
tsetse012@gmail.com.Personal data is transferred outside the Republic of Korea in the cases below. In accordance with Article 28-8 of PIPA we disclose the following and obtain your consent. You may decline to consent to a cross-border transfer, but in that case the corresponding features (card generation, map display, support, notifications) cannot be used.
| Items transferred | Animal photo (EXIF-stripped where possible, otherwise the original — see §2. Faces and licence plates are not obscured) |
|---|---|
| Recipient | Google LLC (Gemini API) |
| Recipient contact | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · privacy enquiries: support.google.com/policies (policy: policies.google.com/privacy) |
| Country | United States |
| Date and method of transfer | Transmitted over a network (HTTPS API) at the moment you generate a card or classify a photo |
| Purpose of use | AI character card generation; coat pattern and colour detection |
| Retention and use period | Per the recipient's (Google's) API data policy. The App operator has not been able to verify the recipient's actual retention period. The relay server on the transmission path does not store photos. |
| Items transferred | Coarse location (a coordinate blurred to roughly 200–500 m), device IP address |
|---|---|
| Recipient | MapTiler AG |
| Recipient contact | Höfnerstrasse 98, 6314 Unterägeri, Switzerland · privacy@maptiler.com (policy: maptiler.com/privacy-policy) |
| Country | Abroad (Switzerland / EU and a global CDN) |
| Date and method of transfer | Transmitted as map tile requests (HTTPS) each time you view the back of a card |
| Purpose of use | Rendering the “met here” map image on the back of a card |
| Retention and use period | Per the recipient's (MapTiler's) policy. The App operator has not been able to verify the recipient's actual retention period. |
| Items transferred | Full text of the support conversation (the ticket you wrote and any follow-up messages) |
|---|---|
| Recipient | Anthropic, PBC (Claude API) |
| Recipient contact | 548 Market St, PMB 90375, San Francisco, CA 94104, USA · privacy@anthropic.com (policy: anthropic.com/legal/privacy) |
| Country | United States |
| Date and method of transfer | Transmitted over a network (HTTPS API) as soon as you submit a ticket or send a reply |
| Purpose of use | Automatically generating a draft reply for the operator to review and edit |
| Retention and use period | Per the recipient's (Anthropic's) API data policy. The App operator has not been able to verify the recipient's actual retention period. We recommend that you do not include unnecessary personal data such as names or contact details in the ticket body. |
| Items transferred | Ticket body, nickname, AI draft reply |
|---|---|
| Recipient | Telegram FZ-LLC (Telegram Bot API) |
| Recipient contact | Business Center, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE · dpo@telegram.org (policy: telegram.org/privacy) |
| Country | Abroad (United Arab Emirates and the provider's global servers) |
| Date and method of transfer | Transmitted over a network (HTTPS API) as soon as a ticket is received |
| Purpose of use | Notifying the solo operator that a ticket has arrived, and approving the reply |
| Retention and use period | Stored in the operator's messenger chat and remains there until the operator deletes it. If you request deletion of your support history, the operator will also delete the corresponding chat messages. |
| Items transferred | APNs push token, notification content |
|---|---|
| Recipient | Apple Inc. (Apple Push Notification service) |
| Recipient contact | One Apple Park Way, Cupertino, CA 95014, USA · policy: apple.com/legal/privacy |
| Country | United States |
| Date and method of transfer | Transmitted over a network (APNs) at the moment a notification is sent |
| Purpose of use | Delivering push notifications for friends, gifts, support replies and similar |
| Retention and use period | For as long as delivery requires; thereafter per Apple's policy. |
The table above applies to iOS (APNs); the table below applies to Android (FCM).
| Items transferred | FCM registration token, notification content |
|---|---|
| Recipient | Google LLC (Firebase Cloud Messaging) |
| Recipient contact | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · policy: policies.google.com/privacy |
| Country | United States |
| Date and method of transfer | Transmitted over a network (FCM HTTP v1 API) at the moment a notification is sent |
| Purpose of use | Delivering push notifications for friends, gifts, support replies and similar |
| Retention and use period | For as long as delivery requires; thereafter per Google's policy. |
| Items transferred | Advertising identifier and device / network information related to the ad request (collected by the Google AdMob SDK) |
|---|---|
| Recipient | Google LLC (Google AdMob) |
| Recipient contact | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · policies.google.com/technologies/ads |
| Country | United States |
| Date and method of transfer | Transmitted through the ad SDK at the moment a rewarded ad is loaded |
| Purpose of use | Ad delivery, frequency capping, performance measurement |
| Retention and use period | Per Google's advertising data policy. If you decline tracking under iOS Settings > Privacy & Security > Tracking, non-personalised ads are shown. |
For matters concerning the use of location information, please also see the Location-Based Service Terms.
To provide the service, the App entrusts personal data processing as set out below. Each processor handles personal data only within the scope of the entrusted purpose.
| Processor | Entrusted task | Processing region |
|---|---|---|
| Supabase Inc. | Hosting the server, database and file storage, and account authentication (storing account data, card data, photo and artwork copies, support and report records, notification tokens, analytics) | Republic of Korea, Seoul region (ap-northeast-2) |
| Vercel Inc. | Hosting the relay (proxy) server — forwarding AI requests and relaying analytics. It does not store photos. | The deployment region is not verified and may be the United States. |
| Upstash, Inc. | Temporary storage of IP addresses for rate limiting (expires after about 2 days) | The storage region is not verified. |
| Google LLC | AI image generation and analysis (Gemini API), ad serving (AdMob), push delivery (FCM, Android), in-app purchase processing (Google Play, Android) | United States |
| MapTiler AG | Providing map tiles for the back of a card | Abroad |
| Anthropic, PBC | Generating draft support replies | United States |
| Telegram FZ-LLC | Delivering support notifications to the operator | Abroad |
| Apple Inc. | Push delivery (APNs, iOS), in-app purchase processing (App Store, iOS) | United States |
Apart from the cross-border transfers and the entrusted processing described in §3 and §4, the App does not provide your personal data to third parties. We may, however, comply where there is a specific provision of law or where an investigative authority makes a request in accordance with the procedures and methods prescribed by law.
If you use the friends and gifting features, the nickname you set and the card data you exchange are displayed in the App to the friends you have connected with. This is a disclosure that results from your own use of the feature; if you do not want it, you can choose not to use the friends feature, or remove a friend.
Personal data whose retention period has expired or whose processing purpose has been achieved is destroyed without delay. Electronic files are deleted in a manner that makes them unrecoverable. As set out in §8 below, however, certain items are retained separately after account deletion for dispute handling and abuse prevention.
Collection > Privacy & Consent.Settings > Privacy & Security > Location Services on iOS, or Settings > Apps > Alleydex > Permissions > Location on Android. All other features work normally without the location permission.Collection > Privacy & Consent screen in the App. After withdrawal the consent screen is shown again on the next launch, and the App cannot be used until you consent again — this covers the whole App, including the yard and the collection, not only card generation. Cards stored on your device are not deleted and can be viewed again once you consent.Settings > Account > Delete account in the App. You may also request it by email (tsetse012@gmail.com).Stated factually, so that you know exactly where you stand.
| Item | On account deletion |
|---|---|
| Account data (email, name), and backed-up photo copies, card artwork and card data (including the coarse location) | Deleted. |
| Cards and photos stored on your device | Removed from the device when you delete the App or reset your collection. |
| Support tickets (ticket body, category, reply contact, nickname, app version, device ID) | Not deleted with your account. Retained for 3 years from the date the ticket is closed to handle disputes over support and refunds, then destroyed. If you want them deleted sooner, email tsetse012@gmail.com and we will delete them to the extent no statutory retention duty applies. |
| Abuse reports (report reason, snapshot of the reported card) | Not deleted with your account. Retained for 3 years from the date the report is filed to prevent re-posting of inappropriate content and repeat or false reports, then destroyed (this applies to reports that have been handled). |
| Records confirming the use and provision of location information (date and time, use/provision type, recipient, count) | Not deleted with your account. Article 16 of the Location Information Act requires operators to record and retain these for 6 months, so they are kept for that period after you leave and then destroyed. They contain no coordinate values and no card content. |
| Support notifications already delivered to the operator's messenger (Telegram) | Not deleted automatically. The operator will delete those messages on request. |
| Nickname, push notification token, friendships and invite codes, block list | Deleted. |
| Gift and trade history | Your user identifier (account ID) is deleted, but the record itself remains. This is because the other party to the gift or trade must still be able to see “who this card came from” on their own card. What remains is only the nickname string recorded at the time of the gift; it is not linked to an account, an email address or a device. |
| Data already transferred to overseas recipients (Google, MapTiler, Anthropic, Telegram, Apple) | The App operator cannot delete it directly; each recipient's own data policy applies. |
The App is not directed at children under the age of 14, and only users who have confirmed that they are 14 or older may use it. If we learn that the personal data of a child under 14 has been collected without the consent of a legal representative, we destroy that data without delay. In addition, under the Location Information Act, the consent of a guardian is required to use the location information of a child aged 8 or under and certain other protected persons (see the Location-Based Service Terms).
Data controller: Nunchi (눈치) — a sole proprietorship registered in the Republic of Korea, business registration no. 640-51-00912
Privacy officer: Subin Kim (김수빈), proprietor
Privacy enquiries, access and deletion requests: tsetse012@gmail.com
You may report or seek advice about an infringement of your personal data with the following Korean authorities: Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr) · Privacy Infringement Report Centre (118, privacy.kisa.or.kr) · Supreme Prosecutors' Office Cybercrime Investigation Division (1301) · National Police Agency Cyber Bureau (182).
This policy applies from 29 July 2026. The previous policy (effective 6 July 2026) is superseded by this one. Where content is added, removed or amended, the changes are posted on this page, and changes that materially affect your rights are additionally announced within the App.