Privacy Policy
BringItOn (the “Service”) treats your personal data with care and complies with
the Personal Information Protection Act of the Republic of Korea and other applicable law.
You can use the Service with a nickname alone, without signing up, and in that case
we collect no information that directly identifies you — no name, phone number or
email address.
Kakao sign-in is optional, and only if you choose it do we
receive your Kakao member number. We do not receive your name, email, phone
number or profile picture.
Play Games linking (Android) is also optional,
and even if you link, the Service stores nothing.
The Service collects the items below. Because there is no sign-up procedure, we do not collect your name, date of birth, contact number or email address.
| Category | Items | How it is collected |
|---|---|---|
| Entered by you | Nickname; avatar colour and face selection | Entered by you when the app is first opened |
| Generated automatically | Anonymous authentication identifier (random UUID) | Issued automatically when the app is first opened |
| Collected automatically | IP address, device model, OS version, app version, access time | Generated and collected automatically as you use the Service |
| Play records | Games played, rounds, scores, ranks, titles earned | Recorded automatically as a game is played |
| Advertising | Advertising identifier (Android AAID / iOS IDFA) | Collected automatically through the ad SDK (Google AdMob) |
| Usage analytics | App instance ID, screen navigation path, whether a feature was used | Collected automatically through the analytics tool (Google Analytics for Firebase) |
| Friends | The anonymous identifiers of two users who are friends, the time the friendship was made, and records of calling a friend into a room (the anonymous identifiers of caller and recipient, and the time of the call) | Recorded only when you add a friend or call a friend into a room |
| Reports and blocks | The anonymous identifiers of the reporter and the reported user, the time of the report, the report reason category, the anonymous identifier of a blocked user, and the time a nickname was reset | Recorded only when you use the report or block feature |
| Social sign-in | Kakao member number | Received through Kakao’s own consent flow, only if you choose Kakao sign-in |
| Push notifications | Push registration token (FCM token) | Issued and collected only if you consent to receive notifications |
| Purchases | Product identifier, store (Google Play / App Store), receipt fingerprint, purchase time | Recorded only if you purchase “Remove ads”. The original receipt travels no further than the purchase-verification server and is not stored. The fingerprint exists to stop the same receipt being used twice and cannot be turned back into the original receipt |
| Enquiries | The content and time of your enquiry, your anonymous authentication identifier, and your app version, device model and OS version | Collected only when you write to us through “Contact us” (device and app details are sent along automatically so we can identify the problem) |
Personal data we collect is destroyed without delay once the purpose of processing has been achieved.
| Item | Retention period |
|---|---|
| Anonymous authentication identifier, nickname, avatar settings — users who have not signed in with Kakao | 90 days from last access (deleted automatically thereafter) |
| Anonymous authentication identifier, nickname, avatar settings, Kakao member number — users who have signed in with Kakao | Until you run “Delete my data” (kept so your records carry over when you change device, so it is not deleted automatically) |
| Play records (history, scores, titles) | Deleted together with the anonymous authentication identifier |
| Access logs (IP, device details, access time) | 3 months from collection |
| Room information (invite code, participant list) | 24 hours after the game ends |
| Usage analytics data (app instance ID, screen navigation path) | 14 months from collection |
| Push registration token | Deleted on withdrawal of notification consent, deletion of the app, or 90 days of non-use |
| Friendships | Until the friendship is ended, or until either side’s anonymous authentication identifier is deleted |
| Records of calling a friend into a room | 24 hours from the call (deleted with the room) |
| Report records, block lists, nickname reset times | Deleted together with the relevant anonymous authentication identifier (90 days from last access) |
| Purchase records (product identifier, receipt fingerprint, purchase time) | Deleted together with the relevant anonymous authentication identifier |
| Device and app details sent with an enquiry | 1 year after the answer is given, or when the relevant anonymous authentication identifier is deleted — whichever comes first |
Where the law requires us to preserve certain records, we keep them for the period the law specifies.
The Service does not provide your personal data to third parties, except:
To operate the Service we entrust the processing of personal data as follows.
| Processor | Entrusted work |
|---|---|
| Supabase Inc. | Database storage and management, anonymous authentication, real-time communication |
| Google LLC | Serving advertising and measuring performance (Google AdMob) Service usage statistics (Google Analytics for Firebase) Sending push notifications (Firebase Cloud Messaging) |
| Telegram Messenger Inc. | Delivering and receiving user enquiries (operator notification) |
Our processing contracts set out compliance with data protection law, restrictions on sub-processing, and security measures.
The Service’s database is stored in the Republic of Korea (Seoul region). However, our processor Supabase Inc. (United States) may access that data from outside Korea for the purposes of system operation and incident response.
| Recipient | Country | Items transferred | Purpose |
|---|---|---|---|
| Supabase Inc. | United States | Anonymous authentication identifier, nickname, play records, access logs | System operation and technical support |
| Google LLC | United States | Advertising identifier, app instance ID, push registration token, IP address | Serving advertising, usage statistics, sending notifications |
| Telegram Messenger Inc. | Europe* | Enquiry content, anonymous authentication identifier, app version, device model, OS version | Receiving and answering enquiries |
Transfer takes place by network transmission at the time you use the Service, and the retention periods are those set out in section 3 above.
* Telegram Messenger Inc. does not disclose the exact country in which its data centres are located. Within what the Service was able to verify directly (network route and response-latency measurement), traffic was found to go to the European region, and we state that as measured. Enquiry content is sent over HTTPS each time you write to us; it is retained while it remains in the operator’s conversation and is deleted when the operator deletes it. Separately, enquiry content is also stored in the Service’s database, and that copy is deleted when you use “Delete my data”.
The Service shows one full-screen advertisement only, when you leave after finishing a full session. We do not show advertising during a game or between rounds, we do not use banner advertising at the bottom of the screen, and we do not use rewarded video advertising.
If this is your first time, no advertisement is shown at the end of your first session.
We use your device’s advertising identifier to serve advertising, and you can restrict this yourself:
Restricting the advertising identifier places no limit on playing; it only makes the advertising you see less relevant.
Once you are friends, the other person continues to see your nickname and avatar. They stop seeing them when the friendship ends.
Tapping a friend invite link does not by itself create a friendship. The link opens an “add friend” screen, and the friendship is created only after you accept it there yourself. An invite link stops opening 7 days after it is created.
Ending a friendship removes it from both lists at once, and the other person is not told. Friend invites from a user you have blocked do not open.
When a friend calls you into a room, a record of the call is kept and is deleted 24 hours later. That record is used only to send the notification and to stop the same person calling you repeatedly in a short space of time.
A public room is one anyone can enter without an invitation. If you enter one, your nickname and avatar are visible to users you do not know.
Public rooms have no room name. The list shows only the chosen game and the number of players; there is no free text written by users.
If you would rather not enter public rooms, use only rooms created with an invite code. An invited room can be entered only by someone who knows the code.
You can report another user whose nickname is inappropriate, and you can block a particular user so that you no longer see them. A report record keeps the anonymous identifiers of the reporter and the reported user, and is used only to filter out duplicate reports.
Where several different users report the same nickname, the Company may stop that nickname from being used any further. In that case the Company does not erase a nickname a user has already chosen.
The server keeps only the time of that action. The Company does not access your device storage directly.
Running “Delete my data” also deletes the reports you made. Reports that other users made about you belong to those users and therefore remain, but the value identifying you is removed from them.
Push notifications are sent only where you have consented, and a push registration token is issued when you consent. You can withdraw consent at any time.
There are two kinds of notification, different in nature, and consent is taken separately for each.
| Type | What it is | Default |
|---|---|---|
| Service notifications | Sent when a friend of yours calls you into a room. Someone you have not added as a friend cannot send one. | On |
| Marketing notifications | News and event announcements. Under the Korean Network Act, the sender’s name and contact details are shown with them. | Off (only if you consent) |
Service notifications are not advertising, so they are managed separately from consent to marketing notifications. Turning off one still leaves you receiving the other; turning off both deletes your push registration token.
Refusing notifications places no limit on playing. Note only that if you turn off room-invitation notifications, you will not be told when a friend calls you.
To improve the Service we collect statistics on which screens and features are used. The purpose is limited to statistical analysis; we do not identify individual users and do not track your activity on other apps or websites.
You may at any time ask to access, correct or delete your personal data, or to stop its processing.
You can make a request through the contact details in section 13 below.
Note that because the Service holds no sign-up information, we cannot verify your identity; to act on a request, you must include the anonymous identifier shown on the app’s settings screen.
Under the Personal Information Protection Act, processing the personal data of a child under 14 requires the consent of a legal guardian, and because the Service has no sign-up procedure it cannot verify such consent. Children under 14 therefore may not use Kakao sign-in.
If we find that personal data of a child under 14 has been collected, we destroy it without delay.
This policy may be amended as the law or the Service changes. Changes are posted in the in-app notices on the day they take effect.
However, we give notice from 30 days before a change takes effect where it:
For enquiries about the handling of personal data, complaints and redress, please contact us below. We will reply promptly once your message is received.