Effective date: July 9, 2026 · Last updated: July 22, 2026. This policy applies to the KeyKey mobile app, the keykeymobile.app website, and the handling of customer support and account deletion requests.
Personal Information Controller and Privacy Officer
The personal information controller for KeyKey is Amini Studio (에이미니 스튜디오) (Business Registration Number: 385-22-02328). The operator's primary domain is https://amini-studio.com, and the service domain is https://keykeymobile.app.
The Privacy Officer and the contact for privacy-related complaints is the privacy team at Amini Studio (Representative: Kim Domin), reachable by phone at 010-5206-8755 and by email at privacy@keykeymobile.app. Requests to access, correct, delete, or suspend the processing of personal information, to withdraw consent, or for customer support can be sent to privacy@keykeymobile.app or support@keykeymobile.app.
Personal Information We Process
Account and authentication data: an anonymous Supabase account identifier and authentication session data are processed. When you sign in with or link Google, the account identifiers, email address, and basic profile information provided by Supabase Auth and Google OAuth may be processed. When you use Sign in with Apple or link Apple, the account identifier, the email address you choose to share (including an Apple private relay address), the name that may be provided on the first authorization, and authentication session data provided by Apple and Supabase Auth may be processed.
Profile and support data: display name, username, Support ID, friend code, account type, language/region settings, and information you provide by email when you contact support or request account deletion may be processed.
In-app feedback data: when you use the feedback feature, the feedback type and body, processing status, developer response, app version, OTA update ID, platform, screen where the feedback was written, language setting, and submission/status-change timestamps may be processed together with your account identifier.
Game progress data: owned keycaps and switches, equipped combinations, favorites and likes, KeyDex progress, tap counts, daily/weekly tap records, attendance and rewards, box and pack openings, achievements, collection albums, wallet balance and wallet ledger, and friend request and block status may be processed.
Purchase data: for purchases made through Google Play Billing or Apple In-App Purchase, the product ID, store product ID, platform, purchase status, currency and amount, purchase/verification/refund timestamps, and verification results may be processed. Google Play purchases may include a purchase-token hash. App Store purchases may include the transaction identifier and original transaction identifier, storefront, Sandbox or Production environment, purchase date, product type, and refund or revocation state. The raw Google Play purchase token and Apple signed transaction JWS are used only during server verification and are not stored in the database; KeyKey retains transaction identifiers, hashes, and a verification payload with sensitive values removed.
Advertising and reward data: when you use rewarded ads, the ad placement, ad reward request ID, server verification status, AdMob ad unit, reward amount, AdMob transaction identifier, and ad start/complete/fail events may be processed. The Google Mobile Ads SDK may collect or share IP address, app interactions, diagnostic information, and device or account identifiers for advertising, analytics, and fraud prevention.
Analytics, device, and technical data: Firebase Analytics may process screen names, feature-use and advertising-related events with limited event parameters, app-instance or device identifiers, device/operating-system/app-version/language information, and SDK delivery-performance information. The app may generate a random per-device identifier in app storage to manage tap sessions and may process technical information needed for service stability, such as network status and error messages. When you visit the website, the hosting provider may process standard access logs such as IP address, User-Agent, requested URL, and access time.
Photo library data: when you save or share a combination image, the app may request permission to access your device photo library. KeyKey uses this permission to save combination images you create and does not upload your entire photo library to any server.
KeyKey intentionally does not collect data that is not needed to provide the service, such as resident registration numbers, contact address books, precise location, health information, microphone recordings, or camera captures.
Purposes of Use
To create accounts and sign in, maintain guest progress, link Apple or Google accounts, and identify users and manage sessions.
To provide core KeyKey features such as keycap collection, tap rewards, wallet balance, purchase restoration, ad rewards, attendance and events, friend features, and profile display.
To verify payments, review refunds and purchase history, prevent fraudulent payments and reward abuse, prevent duplicate rewards, and maintain service security and incident response.
To process in-app feedback and customer inquiries, handle account deletion requests, respond to disputes, comply with legal obligations, analyze feature use through Firebase Analytics, and review service improvements and operational statistics.
Information That May Be Visible Through Profile and Friend Features
Your username, display name, friend code, featured keycap combination, weekly tap count, total tap count, and collection summary may be visible to other users in friend search, friend requests, the friends list, and friend profiles.
The Support ID is a value used for customer support and identity verification and, unlike the friend code, is not a general-purpose sharing identifier. When you send an account deletion or support request, do not include sensitive values such as your full user ID, payment tokens, or raw receipts.
Retention and Use Period
Account, profile, progress, wallet, owned items, friend relationships, in-app feedback, ad rewards, and purchase history are, in principle, retained while the account exists. When you request account deletion, this data is deleted or anonymized, except for records that must be retained under applicable law and the minimum records needed to respond to disputes.
Anonymous accounts that have no purchase history and no recent economic activity or tap progress may be cleaned up under operational policy; the criteria and cycle for cleanup are determined by operational circumstances.
Where e-commerce laws apply, records on contracts or the withdrawal of an order, and records on payment and the supply of goods, may be retained for 5 years; records on consumer complaints or dispute handling for 3 years; and records on labeling/advertising for 6 months.
KeyKey currently uses the free plans of Supabase and Vercel. Supabase system logs are retained for about one day on the free plan and then deleted, and KeyKey does not use managed backups (daily backups or point-in-time recovery), so personal information deleted from operational data is not retained long-term in managed backups. Website access logs on the Vercel free (Hobby) plan are not stored long-term; only recent records are available for a short period.
Provision to Third Parties and Delegated Processing
KeyKey does not sell your personal information and, in principle, does not provide it to third parties without your prior consent. However, personal information may be processed in accordance with applicable law to the extent necessary to provide the service, comply with legal obligations, protect rights, and respond to disputes.
Processors (service providers acting on our behalf): Supabase provides authentication, database, server functions, session storage, and processing of account/progress/in-app-feedback/purchase/reward data; Vercel hosts the keykeymobile.app website and processes access logs; and Expo/EAS operates the app build, distribution, and over-the-air (OTA) update infrastructure we use.
Separate services and third-party integrations: the following are processed by each provider under its own terms and policies when you use the corresponding feature or the app. Sign in with Apple is used for Apple account authentication, while Apple In-App Purchase and the App Store Server API are used for payment, purchase verification, and refund-state checks. Google Sign-In is used for Google account authentication, Google Play Billing for payment and purchase verification, Firebase Analytics for screen and feature-use analytics and service improvement, and Google Mobile Ads/AdMob for ad delivery, measurement, and fraud prevention. The information these services process is also subject to Apple or Google policies and your account and consent settings.
The exact legal relationship with each provider (delegated processing or provision to a third party) and the scope of processing are determined based on each service's terms, data processing agreement (DPA), and actual data flows.
International Transfers
Because KeyKey uses cloud-based services, personal information may be processed or stored outside the Republic of Korea as described below. For each recipient, the transfer destination and contact, the items transferred, the purpose, the timing and method, the retention period, and the legal basis are as follows.
Supabase Inc. — Destination: United States (AWS us-east-1). Contact: privacy@supabase.io, https://supabase.com/privacy. Items: anonymous, Apple, and Google account identifiers, email and basic profile, authentication sessions, game progress, wallet, in-app feedback and authoring-context information, and purchase verification data. Purpose: authentication, database storage and synchronization, feedback receipt and handling, and server-function execution. Timing/method: transmitted over encrypted (TLS) connections when you use the service. Retention: the same as the Retention and Use Period of this policy — retained while the account exists and destroyed upon account deletion. Legal basis: performance of the contract to provide the service to you.
Google LLC — Destination: United States. Contact: https://policies.google.com/privacy. Items: Google sign-in account identifier, email, and basic profile; purchase verification data; Firebase Analytics app-instance or device identifiers, screen and feature-use events, and app/device technical information; and advertising identifiers and ad diagnostic information. Purpose: Google Sign-In, Google Play Billing payment and verification, Firebase Analytics feature-use analytics and service improvement, and Google Mobile Ads/AdMob ad delivery and reward verification. Timing/method: transmitted when you use sign-in, payment, the app, or advertising features. Retention: the period required under Google policy and for providing the feature. Legal basis: performance of the contract to provide the service or consent where required by applicable law.
Apple Inc. — Destination: United States. Contact: https://www.apple.com/legal/privacy/contact/. Items: Apple account authentication data (account identifier, email and name you choose to share), App Store transaction identifier, product ID, purchase environment, date, amount, currency, storefront, and refund or revocation state. Purpose: Sign in with Apple authentication, Apple In-App Purchase processing, transaction and refund-state verification through the App Store Server API, and revocation of Sign in with Apple authorization during account deletion. Timing/method: transmitted over encrypted (TLS) connections when you use Apple sign-in, purchase, or account-deletion features. Retention: the period required under Apple policy and to provide the relevant feature. Legal basis: performance of the contract to provide the service to you.
Vercel Inc. — Destination: United States. Contact: privacy@vercel.com, https://vercel.com/legal/privacy-policy. Items: website access logs (IP address, User-Agent, requested URL, access time). Purpose: hosting and security/operations of the keykeymobile.app website. Timing/method: transmitted when you access the website. Retention: the period under Vercel's log retention policy. Legal basis: performance of the contract to provide the website.
650 Industries, Inc. (Expo/EAS) — Destination: United States. Contact: secure@expo.dev, https://expo.dev/privacy. Items: app build, update, and diagnostic information. Purpose: operating app build, distribution, and over-the-air (OTA) update infrastructure. Timing/method: transmitted when the developer builds and distributes the app, and when the app checks for or downloads over-the-air (OTA) updates. Retention: the period under Expo policy and for providing the feature. Legal basis: performance of the contract to distribute and update the app.
You may refuse the international transfer of your personal information, and you can submit a refusal request to privacy@keykeymobile.app. Upon receipt, we will confirm the scope that can be refused and the impact on your use of the service. Among the transfers above, those for account authentication, data storage, payment verification, website delivery, and app distribution and updates are necessary to provide the service. If you refuse a transfer related to an optional feature such as advertising, only that feature may be limited.
Destruction of Personal Information
Personal information whose retention period has ended or whose processing purpose has been achieved is deleted in a manner that makes recovery difficult, or anonymized so that a specific individual can no longer be identified.
Electronic files and database records are destroyed through deletion, anonymization, access restriction, or expiry of the backup cycle. Records that must be retained under law are stored separately or have access restricted, and are used only for that purpose.
Account Deletion
You can submit an account deletion request through the app settings screen or the email path described at https://keykeymobile.app/en/account/delete. You can find how to request deletion through the web page even after uninstalling the app.
The scope of deletion includes the profile, progress, wallet balance, owned items, friend relationships, and activity records linked to your Apple, Google, or anonymous account. When you delete an Apple-linked account in the app, KeyKey also requests revocation of the Sign in with Apple authorization. The minimum records needed for payment disputes, legal retention, and security and abuse prevention may be retained for a defined period.
KeyKey does not currently offer a way to delete only specific game data while keeping your account; when an account deletion request is approved, the data linked to your account is deleted together.
Your Rights and How to Exercise Them
You may request to access, correct, delete, or suspend the processing of your personal information, to withdraw consent, or to delete your account. Requests can be submitted through the account deletion menu in the app settings screen, the web account deletion page, or by email to privacy@keykeymobile.app or support@keykeymobile.app.
Where identity verification is required, KeyKey may verify the requester using minimal information such as an Apple or Google sign-in email (including an Apple private relay address), Support ID, and account status. Where there is a legitimate reason — such as infringement of another user's rights, a legal retention obligation, or a payment dispute — processing of the request may be limited or some information may be retained.
Remedies for Rights Infringement
If you need consultation or wish to report a personal information infringement, you can seek help from relevant agencies such as the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 without an area code), the Personal Information Dispute Mediation Committee (kopico.go.kr), the Supreme Prosecutors' Office (spo.go.kr), and the National Police Agency Cyber Crime reporting system (ecrm.police.go.kr).
For requests directly related to the KeyKey service, please first contact privacy@keykeymobile.app or support@keykeymobile.app, and we will review and respond.
Automatic Collection, Advertising Identifiers, and Cookies
The KeyKey app uses in-app storage and Supabase Auth sessions to provide the service. The website does not currently install a separate marketing analytics script directly, but the hosting provider may process access logs for security and operations.
When AdMob ads are shown, the Google Mobile Ads SDK may process advertising identifiers, IP address, app interactions, diagnostic information, and device or account identifiers for the purposes of ad delivery, analytics, and fraud prevention. You can adjust ad personalization and advertising-ID settings in your device settings or Google Ads settings.
Children's Personal Information
KeyKey is not designed for or marketed to users under the age of 16 and is intended for users aged 16 and older. If we learn that the personal information of a user under 16 has been processed, a guardian may request deletion at privacy@keykeymobile.app or support@keykeymobile.app.
Security Measures
KeyKey protects personal information through measures such as Supabase Row Level Security, authentication sessions, separation of server-function privileges, restriction of administrator privileges, hashing of purchase tokens, removal of raw receipts and sensitive tokens, and access restriction.
However, because security risks cannot be entirely eliminated in internet and mobile environments, you should manage your own account access and the security of any linked Apple or Google account.
Changes to This Policy
If this Privacy Policy changes, we will post the updated version at keykeymobile.app/en/privacy, and we may additionally announce significant changes in the app or on the website.
This policy takes effect on July 9, 2026.
Language
This Privacy Policy is available in Korean and English. Both versions are intended to convey the same information. If there is any inconsistency between the two versions, the Korean version will prevail to the extent permitted by applicable law.
Contact
For privacy-related inquiries, contact privacy@keykeymobile.app or support@keykeymobile.app.
Change Log
July 22, 2026: Added Sign in with Apple and App Store authentication, transaction verification, refund, and account-deletion disclosures; added Firebase Analytics and in-app feedback processing; and made purchase and account language consistent across Google Play and the App Store.
July 13, 2026: Made retention periods concrete for the free plan, listed the Privacy Officer contact, separated processor and third-party disclosures, refined the minimum-age wording, and noted that selective data deletion is not offered.
July 11, 2026: Added the English version, expanded international-transfer disclosures (per-recipient country, items, purpose, retention, and legal basis), clarified account deletion and language provisions, and added a last-updated date.
July 9, 2026: Initial publication.