1. Why personal information is handled
The Operator handles personal information only as needed for the purposes below. If a purpose changes, the Operator will obtain separate consent or take another step required under Article 18 of Korea’s Personal Information Protection Act and other applicable law.
Providing the Service and performing contracts
Information is used to authenticate Accounts and restore sessions; create and join invite-only Groups; show a friend’s presence; send messages; provide characters and customization items; and verify, restore, or refund purchases.
Managing users and the Service
Information is used to identify users, enforce Group capacity and usage limits, prevent misuse, maintain security, respond to errors, questions, and disputes, and deliver service notices.
SIDEY does not handle personal information for interest-based advertising, personalized recommendations, or promotional messages.
2. Information handled
- Profile: nickname and selected character
- Google account connection: Google account identifier and email address
- Sign in with Apple: Apple account identifier and, when Apple provides it, an email address
- Account and session: anonymous user UUID, sign-in provider, and session identifiers
- Groups: Group name, Group and membership identifiers, owner status, and join time
- Messages and real-time state: message text, creation time, sender and Group identifiers, presence, and typing signals generated only in the SIDEY message field
- Purchases: order and transaction identifiers, product, amount, payment, cancellation and refund status, and the time and content of policy consent
- Support: reply email address, inquiry, and information voluntarily attached by the user
- Connection information: IP address, access time, and request information that service providers may create for security and incident response
Elapsed time since the last system input and screen-lock state are checked locally to show away status. SIDEY does not collect the content of input or a history of app use from these signals.
3. How information is collected
Information is collected when you create a profile or Group, send a message, connect a Google account, use Sign in with Apple, request payment, restoration, or a refund, or contact support. Presence and typing signals are processed in real time while connected to the Service.
SIDEY does not collect screen contents, lists of active apps, keys pressed in other apps, global pointer coordinates, file contents, microphone audio, or camera video. It does not inspect what you type outside the SIDEY message field.
4. Retention
- Messages: three days after creation
- Presence and typing signals: processed only while the real-time display is active and not retained persistently
- Account, profile, Group, and membership: until Account deletion or termination of the Service; a membership link is deleted when you leave a Group
- Incomplete anonymous Account without a profile or Group: may be removed after seven days
- Sign-in session stored on a device: until sign-out, Account deletion, or deletion of app data
Records that must be retained by law are used only for that purpose. Display and advertising records may be kept for six months; contract or cancellation records and payment or digital-delivery records for five years; and consumer complaint or dispute records for three years.
5. Sharing and third-party disclosure
The Operator does not disclose personal information to a third party unless you consent or applicable law provides a specific basis.
Members of the same Group
To provide invite-only Groups, your nickname, character, presence and typing state, and messages are shown to members of the same Group you joined. Messages are retained for three days; real-time state signals are handled only while their display is active.
Authorities acting under law
Information may be disclosed within the scope and period permitted by law when an investigative or other authorized authority makes a request through a lawful process such as a warrant.
6. Service providers and overseas handling
The Operator uses the following providers only as needed to provide the Service. Changes to the provider or purpose will be disclosed through this Policy.
- Supabase Inc.: handles Account UUIDs, profiles, Groups, messages, purchase status, and connection information for authentication, database, and real-time communication. Data is retained until Account deletion, termination of the Service, or the end of the service contract; messages are deleted after three days.
- Google LLC: handles the account identifier, email address, and authentication result for Google account connection until disconnection, Account deletion, or completion of the purpose.
- Apple Inc.: handles Account and transaction identifiers and authentication and payment status for Sign in with Apple, App Store payment, and purchase restoration until Account deletion or for the period required by law and Apple’s policies.
- Korea PortOne Co., Ltd. and connected payment service providers: handle order and payment identifiers, amount, and payment result for payment, cancellation, and refund in a direct distribution build, retaining them for the period required by e-commerce law.
- GitHub, Inc.: may generate IP addresses and connection information while hosting the public website and may retain them under GitHub’s privacy practices and applicable law.
Supabase, Google, Apple, and GitHub are based in the United States, and information may be transmitted over communications networks when their services are used. Where law requires separate notice or consent for overseas handling, the recipient, country, items, purpose, method, and retention period will be disclosed before the relevant feature is used. You may choose not to connect Google, but refusing overseas handling essential to authentication or data storage may limit or prevent use of part or all of SIDEY.
7. Payment information and outside services
Apple processes Mac App Store payments. For a payment offered in a direct distribution build, a payment service provider opened through PortOne handles the full card number, payment password, and bank-account authentication information. SIDEY does not receive or retain full payment credentials; it handles only the identifiers and results needed to verify, cancel, or refund an order.
When you use an outside sign-in page, payment window, or linked website, the provider’s own terms and privacy policy apply to information it collects independently.
8. Your rights and how to exercise them
You may request access to, correction or deletion of, suspension of processing of, or withdrawal of consent for your personal information. A user of Sign in with Apple can delete an Account in the app’s settings after reauthentication. Other Account or data requests can be sent by email to the Privacy Officer below.
You may exercise rights through a legal representative or another authorized person. The Operator may request the authorization form and minimum information needed to confirm the identity of the user and representative as permitted by law. Within 10 days after receiving an access request, the Operator will explain how access will be provided or, where law permits restriction, delay, or refusal, explain the reason and how to object.
Deletion may be limited while another law requires a record to be retained. SIDEY does not make automated decisions that produce legal or similarly significant effects on users.
9. Deletion
Personal information is deleted without undue delay when its retention period ends or its purpose is achieved. Electronic records are deleted using methods intended to prevent recovery. Transaction records subject to separate retention duties are separated from general service data, used only for the required purpose, and deleted when that period ends.
Deleting an Account removes the profile, Group connections, and active SIDEY entitlement links. Minimum transaction records may be retained separately for legal and settlement purposes with user linkage minimized. Account deletion does not automatically delete transaction records held by Apple or a payment service provider and is not a refund request.
10. Security measures
The Operator limits access to personal information to what is needed for the work and separates operational privileges and secrets. SIDEY uses database row-level access controls, server-side Group capacity and membership checks, encrypted transport, and operating-system secure storage. Invitation codes are not stored in plaintext on the server, and payment secret keys and administrative privileges are not included in the app or public website.
SIDEY is not represented as a service with implemented and verified end-to-end encryption.
11. Cookies and similar technologies
The SIDEY public website does not install cookies for personalized advertising, visitor-behavior analytics, or individual recommendations. A browser or hosting provider may process connection information or use technical storage to serve static files and protect the service.
An outside provider may use cookies for functionality and security when you visit a Google or Apple sign-in page or a payment page. See that provider’s privacy settings for available controls.
12. Privacy Officer
- Privacy Officer: Taehyun Ryu
- Email: ryu200112@gmail.com
Questions, complaints, remedies, and requests to exercise privacy rights may be sent to the email above. The Operator will review and respond without undue delay.
13. Remedies for privacy infringement
If you need advice or wish to report a privacy infringement in Korea, you may contact:
- Personal Information Dispute Mediation Committee · 1833-6972
- KISA Privacy Infringement Report Center · 118
- Supreme Prosecutors’ Office · 1301
- Korean National Police Agency Cybercrime Report System · 182
14. External services outside this Policy
The SIDEY website and app may link to services operated by other providers. This Policy does not govern information handled by an external service the Operator does not control. Review the privacy policy of the service you visit.
15. Changes to this Policy
If this Policy changes because of law, the Service, or outside processing relationships, the effective date and material changes will be announced through the website or app. A change with a significant impact on user rights will be announced in advance for the period required by law.
16. Effective date
This Privacy Policy takes effect on September 4, 2026.