Effective date: July 9, 2026 · Last updated: August 28, 2026. This policy applies to the KeyKey mobile app, the keykeymobile.app website, and the handling of customer support and account deletion requests.
Personal Information Controller and Privacy Officer
The personal information controller for KeyKey is AMINI STUDIO (에이미니 스튜디오) (Business Registration Number: 385-22-02328). The operator's primary domain is https://amini-studio.com, and the service domain is https://keykeymobile.app.
The Privacy Officer and the contact for privacy-related complaints is the privacy team at AMINI STUDIO (Representative: Kim Domin), reachable by phone at 010-7295-0752 and by email at privacy@keykeymobile.app. Requests to access, correct, delete, or suspend the processing of personal information, to withdraw consent, or for customer support can be sent to privacy@keykeymobile.app or support@keykeymobile.app.
Personal Information We Process
Account and authentication data: an anonymous Supabase account identifier and authentication session data are processed. When you sign in with or link Google, the account identifiers, email address, and basic profile information provided by Supabase Auth and Google OAuth may be processed. When you use Sign in with Apple or link Apple, the account identifier, the email address you choose to share (including an Apple private relay address), the name that may be provided on the first authorization, and authentication session data provided by Apple and Supabase Auth may be processed.
Profile and support data: display name, KeyKey ID, Support ID, friend code, account type, language/region settings, and information you provide by email when you contact support or request account deletion may be processed.
In-app feedback data: when you use the feedback feature, the feedback type and body, processing status, developer response, app version, OTA update ID, platform, screen where the feedback was written, language setting, and submission/status-change timestamps may be processed together with your account identifier.
Selected feedback photo attachment: if you choose to attach one photo to a letter to the operator, KeyKey processes a regenerated JPEG with a maximum long edge of 1,600 pixels, its file size and dimensions, and its linked feedback and account identifiers. The original EXIF metadata and your entire photo library are not uploaded. KeyKey does not use the camera for this feature. The attachment is optional, and you can still send text feedback if you deny access or do not choose a photo.
Pre-report private context: when you open a friend search result or quick-invite preview, the internal account identifiers of the viewing and target accounts, source, creation and expiry times, and consumed state may be processed as a private authorization record even if you do not submit a report. The app receives an opaque identifier instead of the raw target identifier. KeyKey keeps up to 20 unconsumed live contexts per viewing account; if that cap has been reached when a new context is issued, the oldest still-valid record may be deleted before its expiry.
Friend profile report data: the internal account identifiers for the reporting user and reported user, report reason and optional details, your report-or-block choice and its result, processing status, moderation outcome, and internal review note, and the reported public display name, KeyKey ID, and friend relationship state at the time of the report are processed as private records. When a comparison with the snapshot is needed, the current public display name and KeyKey ID are shown only to authorized moderation operators in the moderation view.
Operator profile-review audit records: the internal account identifier of the authorized reviewing operator, report identifier and review request identifier, review outcome, before-and-after status and action, and whether the public identity was reset are processed in a separate private record. These audit records do not contain the report reason, details, display name, KeyKey ID, or internal review note.
Game progress data: owned keycaps and switches, equipped combinations, favorites and likes, KeyDex progress, tap counts, daily/weekly tap records, attendance and rewards, box and pack openings, achievements, collection albums, wallet balance and wallet ledger, and friend request and block status may be processed.
Reports and moderation data: league participant reports (including the abusive-profile reason), their reasons and report details, reporting and reported participants, review status, review notes, reviewer account identifier, reviewed timestamp, review metadata, and moderation actions may be processed. Blocking and report outcomes may be used for safety measures such as blocking, warnings, league removal, account action, or dismissal of a report.
Purchase data: for purchases made through Google Play Billing or Apple In-App Purchase, the product ID, store product ID, platform, purchase status, currency and amount, purchase/verification/refund timestamps, and verification results may be processed. Google Play purchases may include a purchase-token hash. App Store purchases may include the transaction identifier and original transaction identifier, storefront, Sandbox or Production environment, purchase date, product type, and refund or revocation state. The raw Google Play purchase token and Apple signed transaction JWS are used only during server verification and are not stored in the database; KeyKey retains transaction identifiers, hashes, and a verification payload with sensitive values removed.
Advertising and reward data: when you use rewarded ads, the ad placement, ad reward request ID, server verification status, AdMob ad unit, reward amount, AdMob transaction identifier, and ad start/complete/fail events may be processed. The Google Mobile Ads SDK may collect or share IP address, app interactions, diagnostic information, and device or account identifiers for advertising, analytics, and fraud prevention.
Notification data: when you configure or receive notifications, the raw push token and its SHA-256 hash, installation identifier, notification permission status, notification preferences, push-registration runtime and build versions, token-invalidation and registration-deactivation reasons, device locale, timezone, platform, notification type, relevant timestamps, dispatch, delivery, open, and failure status, provider ticket and receipt identifiers, and error states, codes, and messages may be processed. The notification content and generation context, routing and linkage information, and a deduplication key may also be processed. These fields may include a friend actor UUID and friendship ID, feedback ID, attendance service date and effective timezone, and reminder-window timestamps. A deduplication key may include a recipient or related-object identifier and attendance date. The token is used to deliver notifications, and the hash is used to prevent duplicates and detect token changes or invalidation.
Analytics, device, and technical data: Firebase Analytics may process screen names, feature-use and advertising-related events with limited event parameters, app-instance or device identifiers, device/operating-system/app-version/language information, and SDK delivery-performance information. KeyKey also records separate first-party Supabase operational and analytics events with event names, session or device identifiers, timestamps, and limited metadata needed to understand feature, reward, error, and operational status. The app may generate a random per-device identifier in app storage to manage tap sessions and may process technical information needed for service stability, such as network status and error messages. When you visit the website, the hosting provider may process standard access logs such as IP address, User-Agent, requested URL, and access time. If you allow web analytics, Google Analytics 4 may process public-web page paths and titles, page views, scrolling, outbound-link clicks, approximate location, browser and device information, random client/session identifiers, and normalized UTM campaign fields.
Photo library data: when you save or share a combination image or choose one photo for feedback, the app may use the device photo library or system photo picker. KeyKey uses only the item you explicitly choose for the requested feature and does not upload your entire photo library.
KeyKey intentionally does not collect data that is not needed to provide the service, such as resident registration numbers, contact address books, precise location, health information, microphone recordings, or camera captures.
Purposes of Use
To create accounts and sign in, maintain guest progress, link Apple or Google accounts, and identify users and manage sessions.
To provide core KeyKey features such as keycap collection, tap rewards, wallet balance, purchase restoration, ad rewards, attendance and events, friend features, and profile display.
To verify payments, review refunds and purchase history, prevent fraudulent payments and reward abuse, prevent duplicate rewards, and maintain service security and incident response.
To process in-app feedback and customer inquiries, handle account deletion requests, respond to disputes, comply with legal obligations, analyze app feature use through Firebase Analytics, optionally analyze public-web use through Google Analytics 4, and review service improvements and operational statistics.
A selected feedback photo is used only to understand a bug or suggestion and allow an operator to respond or take action. It is not used for advertising personalization or tracking, and only authorized operators can view it through a private preview.
A pre-report private context is used to bind the report target to the viewing account and source, prevent forged-target submission and reuse by another account, and submit a report safely.
Friend profile report data is used for report handling, safety review, abuse prevention, handling-history audits, and safe replay of the same request. Only authorized moderation operators can access report contents and private snapshots. Questions about report handling can be sent to support@keykeymobile.app.
Information That May Be Visible Through Profile and Friend Features
Your KeyKey ID, display name, friend code, featured keycap combination, weekly tap count, total tap count, and collection summary may be visible to other users in friend search, friend requests, the friends list, and friend profiles.
The Support ID is a value used for customer support and identity verification and, unlike the friend code, is not a general-purpose sharing identifier. When you send an account deletion or support request, do not include sensitive values such as your full user ID, payment tokens, or raw receipts.
Retention and Use Period
Account, profile, progress, wallet, owned items, friend relationships, in-app feedback, ad rewards, and purchase history are, in principle, retained while the account exists. When you permanently delete the account, ordinary account-linked data is deleted. KeyKey may retain only the minimum purchase and ledger records that do not directly identify you and minimum paid-benefit restoration tombstones, only for the legally or operationally required period. These records are limited to payment or refund disputes, ledger integrity, restoration of remaining paid benefits, security, and abuse prevention.
A feedback photo attachment is stored privately for 90 days from submission and then deleted through bounded scheduled cleanup. If you permanently delete your account earlier, KeyKey deletes the attachments for that account before deleting the authentication account. An upload that was not linked to a completed feedback submission becomes eligible for cleanup after one hour. Because cleanup runs in bounded batches, an expired or eligible file may remain temporarily until the next cleanup run.
Anonymous accounts that have no purchase history and no recent economic activity or tap progress may be cleaned up under operational policy; the criteria and cycle for cleanup are determined by operational circumstances.
Where e-commerce laws apply, records on contracts or the withdrawal of an order, and records on payment and the supply of goods, may be retained for 5 years; records on consumer complaints or dispute handling for 3 years; and records on labeling/advertising for 6 months.
A pre-report private context's expiry time is set to exactly 30 minutes after creation. However, when a viewing account has reached 20 unconsumed live contexts and a new context is issued, the oldest still-valid context is deleted before its expiry. It is also deleted earlier if either the viewing or target account is deleted. It cannot be used for a report once expired, but the expired row itself is removed through bounded opportunistic, manual, and optional scheduled cleanup, so it may remain temporarily until a later cleanup batch. Optional scheduled cleanup is registered only where the database scheduler is available.
Each received friend profile report and its private snapshots are retained for exactly 24 months from the time the original report is created and then become eligible for deletion. If the reporting or reported account is deleted first, the linked internal account identifiers are removed, but the report record and private snapshots may remain after the internal account identifiers are removed until the original retention period ends.
The replay receipt has no separate expiry and is deleted when its linked report is deleted; it is used to safely return the result of the same request. A receipt for a duplicate report may link to an older report, so 24 months from the receipt's own creation time is not guaranteed, and it may be deleted earlier if the reporting account is deleted.
Expired report records are removed in bounded batches through cleanup during relevant requests and manual maintenance; a daily cleanup job is registered only where the database scheduler is available. Scheduled cleanup is not guaranteed to run in every environment, and bounded batches mean an expired record may remain temporarily until a later cleanup batch.
Operator profile-review audit records have no automatic expiry and may remain after the report record is deleted for exact review replay and audit. They are accessible only to authorized operators and, including where a longer period is required by applicable law, may be retained while the service operates or until an operator deletes them. If the reviewing operator account is deleted, its internal account identifier is removed.
KeyKey currently uses the Supabase Pro plan and the Vercel free (Hobby) plan. Under the current Supabase Pro plan, system logs and daily database backups may each be retained for up to 7 days. Personal information deleted from operational data is removed from service queries, but it may remain temporarily in backups created before deletion until those backups rotate out. Website access logs on the Vercel free (Hobby) plan are not stored long-term; only recent records are available for a short period.
Provision to Third Parties and Delegated Processing
KeyKey does not sell your personal information and, in principle, does not provide it to third parties without your prior consent. However, personal information may be processed in accordance with applicable law to the extent necessary to provide the service, comply with legal obligations, protect rights, and respond to disputes.
Processors (service providers acting on our behalf): Supabase provides authentication, database, server functions, session storage, and processing of account/progress/in-app-feedback/purchase/reward data, first-party operational analytics and notification-registration data, friend profile reports, private snapshots, pre-report private contexts, and minimal operator audit records. This includes database storage and server-function execution for safe report-target binding, moderation review, abuse prevention, exact replay, and audit, as well as enforcement of a limit of 20 unconsumed live contexts per viewing account and early deletion of the oldest still-valid context. Vercel hosts keykeymobile.app and processes access logs; and 650 Industries, Inc. operates Expo/EAS build, distribution, and OTA update infrastructure and relays notifications through the Expo Push Service.
Feedback photo attachments are stored in private Supabase Storage and are accessible only to the account owner and authorized operators through limited signed URLs. Supabase processes attachment upload, private storage, 90-day expiry, account-deletion cleanup, and cleanup of unlinked uploads on KeyKey's behalf.
Third-party services and recipients: Apple services, including Sign in with Apple, Apple In-App Purchase, the App Store Server API, and APNs, provide account authentication, payment and refund verification, and iOS notification delivery. Google services, including Google Sign-In, Google Play Billing, Firebase Analytics, Google Analytics 4, Google Mobile Ads/AdMob, and FCM, provide account authentication, payment verification, analytics, advertising and reward verification, and Android notification delivery. These services process information under the provider's policies and your account and consent settings.
For this policy, Supabase, Vercel, and 650 Industries, including the Expo Push Service, are classified as processors for the work described above. Apple and Google authentication, store, analytics, advertising, APNs, and FCM functions are classified as third-party services or recipients. A transfer for a particular function may not occur if you do not use that function.
International Transfers
Because KeyKey uses cloud-based services, personal information may be processed or stored outside the Republic of Korea as described below. For each recipient, the transfer destination and contact, the items transferred, the purpose, the timing and method, the retention period, and the legal basis are as follows.
Supabase Inc. — Destination: United States (AWS us-east-1). Contact: privacy@supabase.io, https://supabase.com/privacy. Items: anonymous, Apple, and Google account identifiers, email and basic profile, authentication sessions, game progress, wallet, in-app feedback and authoring-context information, purchase verification data, friend profile report data and private snapshots, pre-report private contexts, and minimal operator audit records, the raw push token and its SHA-256 hash, installation identifier, notification permission status, notification preferences, push-registration runtime and build versions, token-invalidation and registration-deactivation reasons, device locale, timezone, platform, notification type, relevant timestamps, dispatch, delivery, open, and failure status, provider ticket and receipt identifiers, error states, codes, and messages, notification content and generation context, routing and linkage information, deduplication keys (including the friend actor UUID, friendship ID, feedback ID, and attendance service date and effective timezone), league participant reports (including the abusive-profile reason), report details, reporting and reported participants, review status, review notes, reviewer account identifier, reviewed timestamp, review metadata, moderation actions, and first-party Supabase operational and analytics events. Purpose: authentication, database storage and synchronization, feedback receipt and handling, safe report-target binding, moderation review, abuse prevention, exact replay, audit, and server-function execution; purchase verification, notification registration and delivery-status management, and analysis of feature, reward, error and operational status. Timing/method: transmitted over encrypted (TLS) connections when you use the service, configure or receive notifications, open a friend search or quick-invite preview, submit a report or block a user, review a report as an operator, or generate a first-party event. Retention: each category follows the record-specific rules in the Retention and Use Period section above. Report data and snapshots may remain until 24 months after the original report was created even if identifiers are removed earlier. Pre-report contexts have an expiry time 30 minutes after creation, but when a new context is issued after the viewing account has reached the limit of 20 unconsumed live contexts, the oldest still-valid record is deleted before the new context is issued; a context is also deleted immediately if either linked account is deleted, and expired rows are cleaned up in bounded batches. Replay receipts are deleted with the linked report or reporting account; and minimal operator audit records have no automatic expiry and may remain after report or account deletion. These records are not all destroyed immediately upon account deletion. Ordinary account-linked data is destroyed upon account deletion; only minimum purchase and ledger records that do not directly identify you and paid-benefit restoration tombstones may be retained for the legally or operationally required period. Legal basis: performance of the contract to provide the service to you.
Supabase feedback-photo supplement — Items: one feedback photo you explicitly select and its JPEG file size and dimensions. Purpose: private storage and review by an authorized operator to understand the feedback. Timing/method: transmitted over encrypted TLS to Supabase in AWS us-east-1 in the United States when you choose a photo and submit feedback. Retention: until 90 days after submission or account deletion, whichever occurs first; an upload not linked to a completed submission becomes eligible for cleanup after one hour. Legal basis: performance of the contract to provide the feedback feature you requested.
Google LLC — Destination: United States. Contact: https://policies.google.com/privacy. Items: Google sign-in account identifier, email, and basic profile; purchase verification data; Firebase Analytics app-instance or device identifiers, screen and feature-use events, and app/device technical information; if you allow web analytics, Google Analytics 4 public-web page, interaction, browser, device, approximate-location, client, and session information; advertising identifiers and ad diagnostic information; and push tokens and notification payloads sent to FCM. Purpose: Google Sign-In, Google Play Billing payment and verification, Firebase Analytics app feature-use analytics, Google Analytics 4 public-web analytics and service improvement, Google Mobile Ads/AdMob ad delivery and reward verification, and Android notification delivery. Timing and method: transmitted over encrypted connections when you use sign-in, payment, app, or advertising features, after you allow public-web analytics, or when a notification is sent. Retention: the period required under Google policy and for providing the feature. Legal basis: performance of the contract to provide the service or consent where required by applicable law.
Apple Inc. — Destination: United States. Contact: https://www.apple.com/legal/privacy/contact/. Items: Apple account authentication data (account identifier, email and name you choose to share), App Store transaction identifier, product ID, purchase environment, date, amount, currency, storefront, refund or revocation state, and device push tokens and notification payloads sent to APNs. Purpose: Sign in with Apple authentication, Apple In-App Purchase processing, transaction and refund-state verification through the App Store Server API, revocation of Sign in with Apple authorization during account deletion, and iOS notification delivery. Timing and method: transmitted over encrypted (TLS) connections when you use Apple sign-in, purchase, or account-deletion features, or when a notification is sent. Retention: the period required under Apple policy and to provide the relevant feature. Legal basis: performance of the contract to provide the service to you.
Vercel Inc. — Destination: United States. Contact: privacy@vercel.com, https://vercel.com/legal/privacy-policy. Items: website access logs (IP address, User-Agent, requested URL, access time). Purpose: hosting and security/operations of the keykeymobile.app website. Timing and method: transmitted when you access the website. Retention: the period under Vercel's log retention policy. Legal basis: performance of the contract to provide the website.
650 Industries, Inc. (Expo/EAS and Expo Push Service) — Destination: United States. Contact: secure@expo.dev, https://expo.dev/privacy. Items: app build, update, and diagnostic information, push tokens, and notification payloads. Purpose: operating app build, distribution, and over-the-air (OTA) update infrastructure and relaying notifications to APNs and FCM. Timing and method: transmitted when the developer builds and distributes the app, when the app checks for or downloads OTA updates, or when a notification is sent. Retention: the period under Expo policy and for providing the feature. Legal basis: performance of the contract to distribute and update the app and provide notifications you configured.
KeyKey maintains comparable safeguards by using applicable contracts and data-processing terms, encryption in transit (TLS), access restrictions, and minimization or hashing of tokens and receipts. We also review each recipient's published privacy and security terms to maintain safeguards comparable to those required in Korea.
You may refuse the international transfer of your personal information, and you can submit a refusal request to privacy@keykeymobile.app. Upon receipt, we will confirm the scope that can be refused and the impact on your use of the service. Among the transfers above, those for account authentication, data storage, payment verification, website delivery, and app distribution and updates are necessary to provide the service. If you refuse a transfer related to an optional feature such as advertising, only that feature may be limited.
Destruction of Personal Information
Personal information whose retention period has ended or whose processing purpose has been achieved is deleted in a manner that makes recovery difficult, or anonymized so that a specific individual can no longer be identified.
Electronic files and database records are destroyed through deletion, anonymization, access restriction, or expiry of the backup cycle. Records that must be retained under law are stored separately or have access restricted, and are used only for that purpose.
Account Deletion
A signed-in user can permanently delete the account in the app settings. If you cannot sign in or use the app, use the instructions at https://keykeymobile.app/en/account/delete or email delete@keykeymobile.app. After you confirm deletion in the app, deletion of the account and linked data is immediate and cannot be undone.
The deletion scope includes the profile, progress, wallet balance, owned items, friend relationships, and activity records linked to your Apple, Google, or anonymous account. When you delete an Apple-linked account in the app, KeyKey also requests revocation of the Sign in with Apple authorization. Only minimum purchase and ledger records that do not directly identify you and minimum restoration tombstones for remaining paid benefits may remain for payment disputes, legal retention, ledger integrity, restoration, security, and abuse prevention.
KeyKey does not currently offer a way to delete only specific game data while keeping your account. Web and email paths may require identity verification and operational handling, but successful permanent deletion in the app does not wait for separate approval before account-linked data is deleted.
Your Rights and How to Exercise Them
You may request to access, correct, delete, or suspend the processing of your personal information, to withdraw consent, or to delete your account. Requests can be submitted through the account deletion menu in the app settings screen, the web account deletion page, or by email to privacy@keykeymobile.app or support@keykeymobile.app.
Where identity verification is required, KeyKey may verify the requester using minimal information such as an Apple or Google sign-in email (including an Apple private relay address), Support ID, and account status. Where there is a legitimate reason — such as infringement of another user's rights, a legal retention obligation, or a payment dispute — processing of the request may be limited or some information may be retained.
Remedies for Rights Infringement
If you need consultation or wish to report a personal information infringement, you can seek help from relevant agencies such as the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 without an area code), the Personal Information Dispute Mediation Committee (kopico.go.kr), the Supreme Prosecutors' Office (spo.go.kr), and the National Police Agency Cyber Crime reporting system (ecrm.police.go.kr).
For requests directly related to the KeyKey service, please first contact privacy@keykeymobile.app or support@keykeymobile.app, and we will review and respond.
Automatic Collection, Advertising Identifiers, and Cookies
The KeyKey app uses in-app storage and Supabase Auth sessions to provide the service. The website loads Google Analytics 4 code only after you explicitly select Allow analytics. Before a choice or after a decline, the website does not load Google analytics code or send web-analytics requests to Google.
If you allow analytics, Google Analytics 4 may set first-party cookies such as `_ga` and `_ga_<measurement ID>` to distinguish users and maintain session state. KeyKey stores your analytics-consent choice in browser localStorage, and you can change it at any time through Analytics settings in the footer.
KeyKey removes query strings and URL fragments before sending page locations so friend invite codes and other URL parameters are not included in web analytics. The hosting provider may process standard access logs for security and operations regardless of analytics consent.
When web attribution is enabled, after you allow analytics KeyKey normalizes only six fields — `utm_source`, `utm_medium`, `utm_campaign`, `utm_id`, `utm_content`, and `utm_term` — and keeps them in sessionStorage for the same browser tab. A current touch may be sent through Google Analytics 4 standard campaign fields, and approved Google Play buttons may pass those normalized values as a referrer helper for comparing store-click sources; this does not prove an install or first open. Raw query strings and raw referrers, advertising click IDs, friend codes, invite IDs, email addresses, and other arbitrary parameters are not kept in this attribution storage or custom events. The same-tab attribution value is deleted when analytics is declined or revoked.
When AdMob ads are shown, the Google Mobile Ads SDK may process advertising identifiers, IP address, app interactions, diagnostic information, and device or account identifiers for the purposes of ad delivery, analytics, and fraud prevention. You can adjust ad personalization and advertising-ID settings in your device settings or Google Ads settings.
Children's Personal Information
KeyKey is not designed for or marketed to users under the age of 16 and is intended for users aged 16 and older. KeyKey does not collect a date of birth or verify age. If we learn that the personal information of a user under 16 has been processed, a guardian may request deletion at privacy@keykeymobile.app or support@keykeymobile.app.
Security Measures
KeyKey protects personal information through measures such as Supabase Row Level Security, authentication sessions, separation of server-function privileges, restriction of administrator privileges, hashing of purchase tokens, removal of raw receipts and sensitive tokens, and access restriction.
However, because security risks cannot be entirely eliminated in internet and mobile environments, you should manage your own account access and the security of any linked Apple or Google account.
Changes to This Policy
If this Privacy Policy changes, we will post the updated version at keykeymobile.app/en/privacy, and we may additionally announce significant changes in the app or on the website.
This policy takes effect on July 9, 2026.
Language
This Privacy Policy is available in Korean and English. Both versions are intended to convey the same information. If there is any inconsistency between the two versions, the Korean version will prevail to the extent permitted by applicable law.
Contact
For privacy-related inquiries, contact privacy@keykeymobile.app or support@keykeymobile.app.
Change Log
August 28, 2026: Added the optional collection of a selected feedback photo, private Supabase Storage, authorized operator access, 90-day retention, cleanup of unlinked uploads, and early deletion with the account.
August 24, 2026: Added friend-profile report reason and details, report-time public-profile and relationship snapshots, the 30-minute pre-report private context, restricted operator access, processing purposes, actual retention for reports, replay receipts, and operator audit records, and Supabase processing and international-transfer details.
August 23, 2026: Clarified notification, reporting, blocking and moderation data; separate first-party Supabase operational analytics; permanent account deletion and limited restoration tombstone retention; Supabase transfer items; and international-transfer recipients, classifications, and safeguards.
August 13, 2026: Added disclosure of six normalized UTM fields after consent, same-tab storage, GA4 standard campaign handling, optional Google Play click helper, exclusion of raw query and friend values, and deletion on revocation.
July 28, 2026: Added optional public-web Google Analytics 4 measurement, cookies, consent storage and withdrawal, URL-parameter exclusion, and Google international-processing disclosures, and updated log and daily-backup retention for the Supabase Pro upgrade.
July 22, 2026: Added Sign in with Apple and App Store authentication, transaction verification, refund, and account-deletion disclosures; added Firebase Analytics and in-app feedback processing; and made purchase and account language consistent across Google Play and the App Store.
July 13, 2026: Made retention periods concrete for the free plan, listed the Privacy Officer contact, separated processor and third-party disclosures, refined the minimum-age wording, and noted that selective data deletion is not offered.
July 11, 2026: Added the English version, expanded international-transfer disclosures (per-recipient country, items, purpose, retention, and legal basis), clarified account deletion and language provisions, and added a last-updated date.
July 9, 2026: Initial publication.