sosone (hereinafter referred to as the “Company”) values users’ privacy and complies with the Personal Information Protection Act of Korea and other applicable laws and regulations.
This Privacy Policy applies to the mobile applications and related services provided by the Company that link to this Policy.
The Company does not provide account registration features and does not separately request or store direct identifiers such as users’ names, email addresses, or telephone numbers on servers operated by the Company.
However, third-party services integrated into the applications may automatically process device information, application usage information, identifiers, error information, and diagnostic information for purposes such as usage analysis, error diagnosis, advertising, and service improvement.
The Company may process personal information and application usage information for the following purposes:
Information is processed only to the extent necessary for the purposes described above. If the purposes of processing change, the Company will take the measures required under applicable laws and regulations.
The Company does not separately request direct identifiers such as users’ names, email addresses, or telephone numbers.
However, the following information may be generated automatically or processed by third-party service providers while users use the applications:
| Category | Information That May Be Processed |
|---|---|
| Application usage information | Application launches, screen views, feature usage, usage duration, in-app activities, and interaction information |
| Device and application information | Device model, operating system and version, application version, language, and regional settings |
| Identifiers | Application instance identifiers, installation identifiers, and advertising identifiers such as ADID or IDFA |
| Network and location information | IP address, network status, and approximate location inferred from an IP address |
| Advertising information | Advertisement views, impressions, clicks, and other interactions with advertisements |
| Error and diagnostic information | Crash logs, error timestamps, stack traces, application status, device status, and technical diagnostic information |
The information actually processed may vary depending on the user’s device, operating system, application version, privacy settings, advertising consent status, and the third-party services integrated into the relevant application.
Google Mobile Ads SDK may, by default, process IP addresses, device identifiers, app usage interactions, and diagnostic information, and Firebase Crashlytics may process crash stack traces and related installation identifiers.
Some applications may store information entered or generated by the user, usage records, and application settings on the user’s device to provide application features.
Such information may include records created or saved within an application, progress information, usage history, favorites, saved or clipped content, game progress, scores, and application preferences.
This information is generally stored only on the user’s device and is not transmitted to servers operated by the Company. The Company cannot directly access or view this information.
Information stored on the device is generally deleted when the user deletes the application or clears the application data through the operating system.
However, depending on the user’s device and operating system backup settings, such information may be included in a device backup provided by Google or Apple.
The Company does not directly store or separately retain users’ personal information on servers operated by the Company.
The retention and use periods for information processed through third-party services, including Firebase Analytics, Firebase Crashlytics, and Google AdMob, are determined by the Company’s applicable service settings and the policies of each service provider.
If the Company directly retains personal information in the future, it will retain the information until the relevant processing purpose has been fulfilled, unless a different retention period is required by applicable law.
If the Company directly retains personal information, it will destroy the information without undue delay when the purpose of processing has been fulfilled or the applicable retention period has expired.
Personal information stored in electronic files will be deleted using methods intended to make recovery or restoration difficult.
Information processed by third-party service providers will be handled in accordance with the retention and deletion standards of the relevant service provider.
Information stored on a user’s device may be deleted through the following methods:
Information included in an operating system backup may be managed separately according to the backup settings of the user’s Google or Apple account.
The Company does not sell users’ personal information and does not provide personal information to third parties without the user’s consent or another lawful basis.
However, personal information may be provided in the following circumstances in accordance with applicable laws:
The processing of information by third-party services integrated into the applications, including Firebase and Google AdMob, is described separately below.
The Company may use the following third-party services for application usage analysis, error diagnosis, and advertising:
| Processor or Service Provider | Service | Purpose of Processing |
|---|---|---|
| Google LLC and its affiliates | Firebase Analytics | Analyzing application usage and improving services |
| Google LLC and its affiliates | Firebase Crashlytics | Diagnosing application crashes, errors, and technical issues |
| Google LLC and its affiliates | Google AdMob | Providing advertisements, measuring advertising performance, and preventing fraudulent or improper use |
Not all applications use all of the services listed above. Each service is used only in applications in which it has been integrated.
In providing these services, the third-party service providers may process the application usage information, device and application information, identifiers, advertising information, error information, and diagnostic information described in Section 2.
The Company endeavors to review and manage relevant agreements, service settings, and security measures so that third-party service providers process personal information securely.
Personal information may be transferred outside Korea when the Company uses Firebase Analytics, Firebase Crashlytics, and Google AdMob.
| Legal basis for the international transfer | Outsourced processing and storage of personal information under Article 28-8(1)(3) of the Personal Information Protection Act of Korea |
|---|---|
| Recipient | Google LLC and its affiliates |
| Destination countries | The United States and other countries in which Google’s global data centers are located |
| Categories of information transferred | Device identifiers such as ADID and IDFA, application instance and installation identifiers, IP addresses, approximate location information, application usage and activity logs, advertising information, application crash and error logs, and technical diagnostic information |
| Purposes of transfer | Application usage analysis through Firebase Analytics, error and crash analysis through Firebase Crashlytics, and advertisement delivery, advertising performance measurement, and fraud prevention through Google AdMob |
| Timing of transfer | When the application is launched, a relevant feature is used, an advertisement is requested, or an error occurs |
| Method of transfer | Transmission through encrypted network communications |
| Retention and use period | The period determined by the retention policies of the applicable Google service and the Company’s service settings |
Users may restrict or refuse international transfers through the following methods:
Applications using Firebase Analytics, Firebase Crashlytics, or Google AdMob may transfer relevant information outside Korea as part of providing those services.
If a user refuses an international transfer, features such as application usage analysis, error diagnosis, and advertising may not function normally. If a third-party service is essential to the operation of an application, access to some or all of the application may be restricted.
Some applications may automatically process application usage information and advertising-related behavioral information through SDKs such as Firebase Analytics and Google AdMob.
Depending on the user’s region, device settings, and consent status, personalized advertisements, non-personalized advertisements, or limited advertisements may be provided.
Users may delete or reset their advertising identifier and change personalized advertising or application tracking settings through their device’s operating system.
Depending on the device and operating system version, advertising-related settings may be available under a menu similar to:
Settings → Privacy → Ads
Users may be able to delete or reset their advertising ID and change advertising privacy settings from this menu.
Users may change application tracking permissions through the following menu:
Settings → Privacy & Security → Tracking
Where an application provides a separate privacy or advertising consent management feature, users may also change their preferences through that feature.
The Company endeavors to apply the following technical and organizational measures to prevent personal information from being lost, stolen, leaked, falsified, altered, or damaged:
Users may exercise the following rights regarding the processing of their personal information:
Because the Company does not maintain user accounts or direct identifiers, it may be difficult for the Company to individually identify, access, or delete information processed through Firebase or AdMob for a particular user.
Users may restrict the storage and processing of certain information by deleting the application, clearing application data, deleting or resetting advertising identifiers, or changing privacy settings in the operating system.
Requests to exercise these rights may be submitted to the privacy contact email address provided below. The Company will take appropriate measures without undue delay to the extent required by applicable law.
A legal representative of a user under the age of 14 may exercise the same rights with respect to the child’s personal information.
The Company does not intentionally collect direct personal information from children under the age of 14, such as their names, contact details, or account information.
Even where an application provides features relating to children or infants, if a name, date of birth, or usage record entered by the user is stored only on the user’s device and is not transmitted to the Company, the Company cannot directly access or view that information.
If the Company directly collects personal information from children under the age of 14 in the future or provides a service requiring the consent of a legal representative, the Company will verify the legal representative’s consent and implement the protections required under applicable law.
Users may contact the following Korean authorities for consultation or remedies relating to personal information infringement:
| Authority | Contact Number |
|---|---|
| Personal Information Infringement Report Center | 118, without an area code |
| Personal Information Dispute Mediation Committee | 1833-6972 |
| Korean National Police Agency Cybercrime Reporting System | 182, without an area code |
| Supreme Prosecutors’ Office | 1301, without an area code |
These authorities operate independently from the Company. Requests or questions concerning the Company’s processing of personal information may first be submitted to the privacy contact listed below.
The Company designates the following privacy officer to oversee personal information processing and respond to privacy-related inquiries, complaints, and requests to exercise user rights:
Privacy-related inquiries, complaints, or requests to exercise rights may be submitted to the email address above.
This Privacy Policy may be amended to reflect changes in applicable laws, application features, or third-party services.
When this Privacy Policy is amended, the Company will publish the revised content and its effective date on this page.
If a change materially affects users’ rights, the Company may also provide separate notice through an in-app announcement or another reasonable method.
This Privacy Policy may be provided in Korean and English.
In the event of any inconsistency between the Korean and English versions, the Korean version will prevail to the extent permitted by applicable law.