This document is a translation of the Korean original. In the event of any discrepancy between this translation and the Korean original, the Korean original shall prevail.
Version: v1 (draft)
Status: Pending the operator's final approval. The provisions on in-app purchases, rewarded advertising, and social login will be reviewed again when those integrations go live.
Drafted: September 6, 2026
Effective date: To be fixed and stated on the app's release date.
Vibeline (Business Registration No.: 895-01-03886; the "Company") complies with applicable laws, including the Personal Information Protection Act of the Republic of Korea ("PIPA"), the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc., and the Act on the Consumer Protection in Electronic Commerce, Etc., and establishes and discloses this Privacy Policy as follows in order to protect users' personal information and respect their rights and interests.
This Policy applies to the mobile application Pogeun Onsen (Korean title: 포근포근 온천; package name com.vibeline.pogeunonsen; the "Service") operated by the Company. Pogeun Onsen is a relaxing merge game in which the player restores an old inherited hot spring by combining items.
Article 1 (Principles of Processing)
- The Company processes only the minimum information necessary to provide the Service and does not sell users' personal information.
- Immediately after installation, a user may start playing anonymously without signing up. Even in this state, an anonymous authentication identifier and the user's progress data are recorded on the Company's servers so that play can be resumed.
- After the tutorial is completed, linking a social account is required so that progress can be stored safely and carried over when the user changes devices. When an account is linked, the progress made anonymously is carried over to the linked account.
- The Company does not access the camera, photo library, contacts, microphone, or precise location, and does not collect dates of birth.
Article 2 (Personal Information Collected)
| Category | Items | Method of collection |
|---|---|---|
| Account identifiers | Anonymous authentication identifier; type of social login provider (Google, Apple, Kakao); the account identifier supplied by the provider; email address (where provided); name or nickname (where provided); the time the account was linked | Generated automatically on first launch; supplied by the provider when the user signs in |
| Gameplay data | Board state; balances of in-game currencies (coins, onsen eggs, energy); reputation points and level; state of generators, facilities, furniture, and unlocked areas; storage contents; quest progress; mailbox history; in-game news read status; tutorial completion time; last access time | Generated automatically as the user plays |
| Settings | Language setting (Korean, Japanese, English); push notification preferences | User input or device settings |
| Purchase information | App store transaction identifier; product identifier; the fact and time of a purchase, cancellation, or refund; the type and quantity of currency granted | Purchase notifications from the app stores and the purchase management service |
| Advertising-related information | The fact that a rewarded ad was watched to completion and the result of its server-side verification; the number of views per day. Advertising identifiers (Apple's IDFA and the Android advertising ID) and the device information and IP address sent with an ad request are collected by the advertising SDK and transmitted to the advertising provider; the Company does not store them in its own database (see Article 6) | When the user watches a rewarded ad |
| Push token | The token used to deliver push notifications (FCM, APNs) | Where the user has granted notification permission |
| Inquiry information | Subject and body of the inquiry; app version; device information (model, OS version); time of submission | When the user submits the in-app inquiry form |
| Automatically generated information | Service usage records; the IP address and access time processed while communicating with the server | Processed automatically during server communication |
The Company does not collect information other than the items listed above. If a user writes their own name or contact details into an inquiry, that information is received as well, so we recommend not including more than is needed for a reply.
Article 3 (Purposes of Processing)
- Account management and preservation of progress: identifying the user, carrying data over from the anonymous state to a linked account, restoring progress after a device change, and blocking unauthorized access
- Providing the Service: recording and synchronizing gameplay state on the server, calculating currencies and reputation accurately, and operating the quest, mailbox, and shop features
- Processing in-app purchases: confirming purchases, granting paid currency such as onsen eggs, preventing duplicate grants, clawing back currency on refund or cancellation, and handling purchase-related inquiries
- Providing rewarded advertising: verifying ad completion on the server, granting rewards, applying daily view limits, and preventing fraudulent repeated claims
- Sending notifications: delivering notifications the user has enabled, such as mail arrival and announcements
- Handling inquiries: reviewing the inquiry, investigating the facts, and replying with the outcome
- Improving the Service and ensuring stability: analyzing the cause of errors and outages, and detecting and responding to abnormal use
- Complying with legal obligations: retaining transaction records as required by the Act on the Consumer Protection in Electronic Commerce, Etc. and other applicable laws
Article 4 (Retention and Use Periods)
The Company destroys personal information without delay once the purpose of processing has been achieved. Retention periods by item are as follows.
| Item | Retention period |
|---|---|
| Account identifiers, gameplay data, settings | Until the user withdraws from membership. Where a user requests account deletion, the data is deleted immediately and cannot be recovered |
| Purchase information | Until the user withdraws from membership. Records that must be retained under the laws listed below are kept separately for the applicable period, are not used for any other purpose, and are then destroyed |
| Ad verification records | Retained until the user withdraws from membership in order to prevent fraudulent repeated claims. The per-day view count is used only in relation to that day |
| Push token | Until the user withdraws from membership, turns notifications off, deletes the app, or the token is invalidated |
| Inquiry information | Three years after the inquiry is resolved (records concerning consumer complaints or dispute resolution) |
| Automatically generated information | Deleted on rotation in accordance with the service providers' operating policies |
Records retained under applicable law are as follows.
- Records on contracts or withdrawal of subscription: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
- Records on payment and the supply of goods: 5 years (same Act)
- Records on consumer complaints or dispute resolution: 3 years (same Act)
- Records on labeling and advertising: 6 months (same Act)
⚠ Deleting an account permanently removes all unused currency, including purchased onsen eggs and coins, together with all gameplay progress, and none of it can be recovered. The app confirms this in two separate steps before an account is deleted.
Article 5 (Entrustment of Processing and Overseas Transfer)
In order to provide the Service smoothly, the Company entrusts the processing of personal information to the parties below. Some of them are located outside the Republic of Korea, so personal information is transferred overseas. The Company stipulates in each entrustment agreement the matters necessary for personal information to be managed safely.
| Processor | Country of transfer | Items transferred | Purpose | Retention and use period |
|---|---|---|---|---|
| Supabase, Inc. | United States | Account identifiers, gameplay data and settings, purchase and ad verification records, inquiry contents, push tokens | Authentication, database, and server functionality | Until withdrawal of membership or termination of the entrustment agreement |
| Google LLC (Sign in with Google) | United States | Account identifier, email address and name (where provided), sign-in token | Social login | In accordance with Google's privacy policy |
| Apple Inc. (Sign in with Apple) | United States | Account identifier, email address (the user may choose to hide it), name (where first provided), sign-in token | Social login | In accordance with Apple's privacy policy |
| Kakao Corp. | Republic of Korea | Account identifier, profile information provided, sign-in token | Social login | In accordance with Kakao's privacy policy |
| RevenueCat, Inc. | United States | Account identifier, app store transaction identifier, product information, device identifier | Managing in-app purchase state and verifying purchases | Until withdrawal of membership or termination of the entrustment agreement |
| Google LLC (Google AdMob) | United States | Advertising identifier, device information, IP address, ad usage records such as impressions and completed views | Serving rewarded ads, verifying completed views, preventing ad fraud | In accordance with Google's privacy policy and data retention policy |
| Expo, Inc. / Google LLC (FCM, Android) / Apple Inc. (APNs, iOS) | United States | Push token, device information | Delivering push notifications | Until withdrawal of membership or termination of the entrustment agreement |
| Apple Inc. / Google LLC (app stores) | United States | Information necessary to process payment | App distribution and in-app purchase processing | In accordance with each provider's policy |
- Statutory notice of overseas transfer: the table above contains the matters required to be disclosed for overseas transfers under Article 28-8 of PIPA (the recipient, the country of transfer, the items transferred, the purpose of transfer, and the period of use). A user may refuse the overseas transfer of their personal information. However, account linking and server storage as well as in-app purchase processing require such transfers in order to provide the Service, so refusing them may restrict the use of those features.
- Refusing transfers made for advertising purposes does not restrict use of the Service. The transfer of advertising identifiers for personalized advertising can be refused at any time by the methods described in Article 6, and all features of Pogeun Onsen remain available if it is refused.
- Any change to the entrusted work or to the processors will be disclosed through this Policy.
Article 6 (Rewarded Advertising and Behavioral Information)
- The only advertising in the Service is rewarded advertising that the user chooses to watch. There are no banner ads or interstitial ads that appear automatically. All features of the Service are available without watching any advertising.
- Advertising is served through Google AdMob operated by Google LLC. When a user watches a rewarded ad, the advertising SDK included in the app collects behavioral information such as the advertising identifier, device information, IP address, and records of impressions and completed views, and transmits it to Google. The Company does not store this information in its own database, and the retention and use period of the transmitted information follows Google's privacy policy and data retention policy.
- How to consent to or refuse personalized advertising
- iOS: before the app first displays an advertisement, it asks for consent through the iOS App Tracking Transparency prompt, and personalized advertising using the advertising identifier is provided only where consent is given. The choice can be changed at any time under Settings > Privacy & Security > Tracking on the device.
- Android: the device's advertising settings apply. Selecting "Delete advertising ID" or opting out of ad personalization under Settings > Google > Ads refuses personalized advertising.
- Refusal does not restrict use of the Service; advertisements unrelated to the user's interests will be shown instead.
- Ad verification records: in order to grant rewards accurately and prevent fraudulent repeated claims, the Company retains the fact that an ad was watched to completion, the result of its server-side verification, and the number of views per day. These records do not contain the advertising identifier.
- Information on how Google processes data for advertising purposes is available in the Google Privacy Policy and in How Google uses information from sites or apps that use our services.
Article 7 (Push Notifications)
- The Company may send push notifications for matters such as the arrival of mail, announcements, and in-game progress reminders.
- Notifications are sent only where the user has granted notification permission on the device and has enabled them in the app settings.
- A user may refuse notifications at any time under Settings > Notifications in the app or in the device's operating system settings. Turning notifications off does not restrict use of the Service.
- Where promotional information is sent as a notification, the Company obtains separate prior consent as required by applicable law and marks the notification as advertising.
Article 8 (Withdrawal of Membership and Destruction of Personal Information)
- A user may request withdrawal of membership at any time under Settings > Delete account in the app.
- The app confirms in two separate steps that the deletion cannot be undone and that unused currency, including purchased onsen eggs and coins, will be lost.
- Once the withdrawal has been processed, account identifiers and gameplay data are deleted immediately and cannot be recovered. The app returns to the initial anonymous state.
- Transaction records that must be retained under applicable law are kept separately for the period set out in Article 4, are not used for any other purpose, and are then destroyed.
- Information held in electronic files is deleted using a method that makes recovery impossible.
- Deleting the app alone does not delete the account or the data held on the server. To delete an account, please use the account deletion function in the app or contact us at the address in Article 12.
- Withdrawal of membership is not the same as cancelling an auto-renewing product. The Service does not offer auto-renewing subscriptions, and refunds or cancellations of app store purchases follow each app store's policies and procedures.
Article 9 (Rights of Data Subjects and How to Exercise Them)
- A user may at any time request access to, correction or deletion of, or suspension of the processing of their personal information, and may withdraw consent.
- The following can be done directly within the app.
- Change the language setting (Settings > Language)
- Change push notification preferences (Settings > Notifications)
- Delete the account (Settings > Delete account)
- Restore purchases (Settings > Restore purchases)
- Other requests and inquiries may be submitted through the in-app inquiry form or the email address in Article 12, and the Company will act on them without delay. Where identity verification is necessary, the Company may request the minimum additional information appropriate to the scope of the request.
- A user may exercise these rights through a legal representative or an authorized agent.
Article 10 (Children Under 14)
- The Service is not directed to children under the age of 14 and is not declared as a child-directed app in the app stores' target audience declarations.
- The Company does not collect dates of birth or any other age verification information. Users under the age of 14 must not link a social account or make in-app purchases without the consent of a legal representative.
- If the Company becomes aware that the personal information of a child under 14 has been processed without the consent of a legal representative, it will verify the facts and delete the information without delay. A legal representative may request access or deletion through the contact in Article 12.
Article 11 (Security Measures and Features Not Used)
The Company applies the following measures for the safe processing of personal information.
- Minimizing the items collected and not requesting device permissions unnecessary to operating the Service
- Encryption in transit
- Row-level access control in the database and separation of data by account
- Server-side verification governing the granting of currency and rewards, and prevention of duplicate grants
- Minimizing the number of people authorized to handle personal information
For the sake of transparent disclosure, the items the Service does not use are stated below.
- It does not access the camera, photo library, contacts, microphone, or precise location.
- It does not collect dates of birth, telephone numbers, addresses, or payment instrument details such as card numbers.
- It does not serve banner or interstitial advertising.
- It does not use any external product analytics tool or crash reporting tool.
- It does not sell personal information and does not provide it to third parties beyond the purpose of providing the Service.
If the Company introduces any of the above, it will amend this Policy before doing so and give notice in accordance with Article 14.
Article 12 (Personal Information Protection Officer)
The Company designates the following Personal Information Protection Officer to take overall responsibility for the processing of personal information and to handle related inquiries, complaints, and remedies.
- Personal Information Protection Officer: Younghwan Kim (Representative)
- Contact (email): admin@vibeline.co.kr
- In-app: Settings > Contact us
Article 13 (Remedies for Infringement of Rights)
A user may apply to the following bodies for consultation or dispute mediation in order to obtain relief from an infringement of personal information rights.
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Center (Korea Internet & Security Agency): 118 / privacy.kisa.or.kr
- Cybercrime Investigation Division, Supreme Prosecutors' Office: 1301 / www.spo.go.kr
- Cyber Bureau, National Police Agency: 182 / ecrm.police.go.kr
Article 14 (Changes to This Policy)
- This v1 document is kept at its URL so that users can review the content exactly as they saw it.
- Where there is a material change, such as the addition of new items collected, new processors, or new purposes of processing, a new version will be published at a separate URL and notice will be given through an in-app announcement or this page.
- Where a change is unfavorable to users, notice will be given at least 30 days before the effective date.
Addendum
- Trade name: Vibeline (Business Registration No.: 895-01-03886)
- Inquiries (email): admin@vibeline.co.kr
- Drafted: September 6, 2026
- Date of announcement and effective date: to be fixed and stated at the time of the app's release.