Privacy Policy
This document is a translation provided for convenience. In the event of any discrepancy or conflict between this translation and the Korean version, the Korean version shall prevail.
BookBuddy (hereinafter referred to as the 'Service') values the user's personal information and complies with relevant laws and regulations of the Republic of Korea, including the Personal Information Protection Act. This Privacy Policy informs you what information the Service collects, how it is used, and how it is securely managed.
The announcement date of this Policy is September 30, 2026 (2026-09-30), and the effective date is September 30, 2026 (2026-09-30).
1. Personal Information Items Collected and Collection Methods
The Service collects the minimum necessary personal information for smooth service provision and stable data synchronization. Reading data recorded by users is synchronized and stored in a cloud database through encrypted communication channels so that it can be securely viewed and backed up across multiple devices.
① Information collected during membership registration and account management
- Google account information: Login identifier (UID), email address, name
- Profile information: Nickname, profile introduction, representative character type, BookBuddy friend code (6-digit alphanumeric), profile completion status, consecutive reading days
② Information collected and stored during reading logging and cloud synchronization
Reading records registered and tracked by users in the bookshelf are stored on the server for secure cloud synchronization.
- Book basic and detailed records: Book identifier, ISBN, book title, author, genre, book spine color, total pages, current read pages, reading status (want to read / reading / finished), reading start and finish timestamps, rating, one-line review, reading notes
- Reading session records: Session identifier, tracked reading duration (seconds), start and end pages, session start and end timestamps, session status, closing label
- Collected quote cards and book tags: Quoted sentence content per book, page number, ink color, stamp type, list of book tags
- User-registered book cover photos: Book cover image files directly selected and registered by the user on the device (stored in cloud storage and public access URL generated)
③ Information processed when using reading social (BookBuddy) and friend features
- Real-time reading status: Title, author, cover image URL, reading progress rate, reading start timestamp, status (reading/paused/idle) of the book currently being read (displayed in real time to accepted BookBuddy friends)
- Friend-shared bookshelf: Book title, author, cover image URL, reading progress rate, rating, reading status, registration timestamp (shared for mutual bookshelf browsing among accepted BookBuddy friends)
- Reading activity and statistics among friends: Daily reading time (minutes) for the past 14 days, book start and completion event timestamps and book titles, cumulative completed books, total reading time, consecutive reading days (provided for mutual activity timeline browsing among accepted BookBuddy friends)
- Friend memo sharing (optional feature): Only when the user enables 'Share memos with friends' in Settings, quoted sentences and page numbers of collected quote cards are shared with accepted BookBuddy friends. (Default is private, and it is not exposed to friends when disabled.)
- Friend relationship information: Friend requests, acceptances, rejections, blocking records, request messages
- Push notification information: Device push token (Firebase Cloud Messaging token)
④ Information collected and stored when using virtual currency, shop, and study room decoration features
- BookBuddy coin history: Coin balance, coin acquisition and usage history, transaction reason (reading completion, ad viewing, shop purchase, bookshelf sharing, etc.), transaction number to prevent duplicate grants, daily free recharge count and share reward grant timestamp
- Decoration item ownership information: Owned decoration item identifier, acquisition route (default grant, shop purchase, achievement, season quest, data migration, etc.), acquisition timestamp, origin reference identifier
- Study room decoration arrangement information: Arrangement status of furniture and props in the study room per character (coordinates, size, rotation, etc.), update timestamp
- Server unlock and quest achievement records:
- Character unlock records: Account identifier, character identifier, unlock timestamp, completed books at unlock, cumulative reading time (minutes) at unlock
- Season quest claim records: Account identifier, season identifier, claim timestamp, reading days at claim
(Stored for server validation of eligibility and prevention of duplicate claims for character unlocks, achievement items, and season quest rewards based on reading volume and season reading days)
⑤ Information collected and stored when using paid payment (in-app purchase) features
- In-app purchase receipts and transaction history: Payment platform (Android Google Play), product identifier, purchase token, order identifier, verification status, encrypted value for account verification, list price in KRW, purchase country code, actual purchase timestamp, receipt registration timestamp
⑥ Information processed when using the bookshelf share card feature
- Bookshelf share card: Only when the user manually executes the share feature, a share image card containing the displayed study room decoration image (representative character, background, furniture, props) and this month's reading statistics (books read and reading duration this month) is generated in the device temporary directory and passed to the sharing app selected by the user (messenger, SNS, etc.).
- For privacy protection, personal identification information such as nicknames and profile photos is not included in the shared card image at all.
- The generated share card image is not transmitted to or stored on BookBuddy external servers, and is managed in temporary storage on the device after sharing.
- When granting rewards for sharing (2 coins once per day), only the reward grant timestamp and transaction number are recorded in the coin ledger to prevent duplicate grants.
⑦ Information collected and stored when using account preferences features
To maintain personalized settings even when switching devices, the following items are synchronized with the server:
- Account preferences information: App analytics collection consent status, app language setting, BookBuddy notification reception status, quiet hours setting, daily reading reminder setting, daily reminder time, retrospect notification setting, device timezone
⑧ Information stored only inside the user's device (locally) and not transmitted to the server
- Local personal settings: Reading goal settings (daily/monthly goal books and time), timer sound settings (background music selection, white noise selection, volume)
- Temporary cache data: Temporary cache of Kakao book cover images (up to 150MB in device storage, refreshed after 30 days), temporary cache of book search results, offline pending changes not yet reflected on the server, decoration item / background / season list cache (common information retrieved from server and does not constitute personal information)
⑨ Information collected in the course of service use and ad viewing
- Mobile advertising identifier: Mobile advertising identifier (Android AAID / iOS IDFA) for providing Google AdMob rewarded ads
- App usage statistics: Screen view records, feature usage event logs (reading session start/complete, coin consumption, onboarding complete, etc.), user properties (completed book range, login state, character level, etc.)
- When collecting statistics, personal identifying information such as book title, author, ISBN, reading notes, nickname, and email is never collected, and book identifiers are converted into non-recoverable 12-digit one-way hash values before transmission.
- Upon service login, the service account identifier (UID) may be linked to analytics tools (Firebase Analytics) for user-level usability analysis. (Users may opt out of statistics collection at any time in the app settings.)
- App crash and error information: Error records when the app crashes or encounters errors (technical information including occurrence location), device model, operating system version, app version, error timestamp, randomized identifier per app installation. Personal identifying information such as name, email, nickname, and reading records is excluded, and collection can be refused through the same setting as app usage statistics.
⑩ Information collected during customer inquiry support
- Email inquiry information: Sender email address, app version and build number, device model name, account verification code (one-way hash of UID), inquiry message content
2. Purposes of Using Personal Information
The collected information is used solely for the following purposes:
- Member identification and Google account integration login management
- Profile configuration, BookBuddy friend making, friend search
- Real-time cloud synchronization and backup across devices for bookshelf books, reading session records, notes, and quote cards
- Displaying real-time reading status, shared bookshelf, and activity timeline among friends
- Sharing quote cards (reading notes) among friends based on user choice
- Sending friend request and acceptance notifications (push notifications)
- Managing BookBuddy coin grants, deductions, item purchases, and inventory
- Verifying eligibility and preventing duplicate claims for character unlocks, achievement items, and season quest rewards based on reading volume (completed books and reading time) and season reading days
- Supporting bookshelf share card generation and granting daily reward BookBuddy coins for sharing while preventing duplicate grants
- Synchronizing study room decoration layout status per character
- Validating in-app purchase receipts and granting paid BookBuddy coins (Google Play billing integration)
- Providing rewarded ads and granting reward coins upon ad viewing confirmation (Google AdMob integration)
- Synchronizing account preferences (analytics collection consent, notification settings, timezone, etc.)
- Receiving customer inquiries, investigating bug/error causes, resolving customer complaints
- Diagnosing app errors, improving services, and statistical analysis
3. Retention and Use Period of Personal Information
In principle, the Service retains and uses the user's personal information until account withdrawal (account deletion).
- Upon account withdrawal: User account information, profiles, friend relationships, shared bookshelves, push tokens, coin ledger, item inventory, room layouts, character unlocks and season quest claim records, account preferences, all reading records synchronized to the cloud (books, sessions, notes, one-line reviews, quote cards, tags), and uploaded cover photos are immediately and permanently deleted. Statutorily required retention of payment records is segregated and stored according to the criteria below.
- Data stored on the device: When a user deletes their account within the app or deletes the app, the SQLite database and cached images on the device are also reset and deleted.
- Retention pursuant to relevant laws: Where retention is required under provisions of relevant laws, records are stored separately for the periods prescribed by such laws.
- Act on Consumer Protection in Electronic Commerce:
- Records on contracts or withdrawal from the purchase, etc.: 5 years
- Records on payment and supply of goods, etc.: 5 years
- Records on consumer complaints or dispute settlement: 3 years
- Payment records (order ID, product, payment timestamp, product list price) are segregated and stored until 5 years from the payment date pursuant to the Electronic Commerce Act and then destroyed, and are not used for any other purpose during this period. Upon account withdrawal, verified payment receipts (including product list price and Google Play purchase timestamp) and coin credit amounts are moved to a separate segregated storage, and originals are deleted along with the account. To prevent leaks of personal information during segregated storage, personal identifiers such as email and nickname as well as the original purchase token are not stored; user identifiers and purchase tokens are converted into non-recoverable one-way cryptographic hashes (SHA-256), and only the order number, product identifier, granted coins, product list price (in KRW), purchase timestamp, and archiving timestamp are isolated. The actual local currency amount paid is maintained by Google Play, which processed the payment, and the Company does not receive it. After the retention period (5 years from payment date) expires, records are permanently destroyed through automated daily database jobs.
4. Procedures and Methods for Destroying Personal Information
The Service destroys personal information without delay when it becomes unnecessary due to expiration of retention periods or fulfillment of processing purposes.
- Destruction procedure: When executing account deletion in the app, linked databases (profiles, bookshelves, notes, sessions, unlock records, coin ledger, etc.) and cloud storage files are automatically destroyed permanently via auth server integration. Legally segregated payment records are permanently destroyed via daily automated database jobs once 5 years have elapsed from the payment date.
- Destruction method: Personal information stored in electronic file formats is permanently deleted using technical methods that make records irrecoverable. Locally stored databases and image cache files on the device are also initialized immediately upon completion of account deletion.
5. Provision of Personal Information to Third Parties
The Service processes personal information only within the scope announced in advance, and in principle does not provide personal information to third parties without prior user consent. However, for providing customized rewarded ads, third-party provision is conducted as follows:
Third-Party Provision for Rewarded Ads
- Recipient: Google LLC
- Purpose: Providing Google AdMob rewarded ads, measuring ad performance, preventing abuse
- Items provided: Mobile advertising identifier (Android AAID / iOS IDFA), device information
- Retention and use period: Subject to Google's Privacy Policy
6. Entrustment and Overseas Transfer of Personal Information Processing
The Service entrusts the processing of personal information to specialized companies as follows for smooth service provision and global cloud infrastructure management. Due to the nature of cloud infrastructure, data may be stored and processed on overseas servers.
① Entrustment of database, storage, and backend operations
- Trustee: Supabase, Inc.
- Transferred country: Singapore (Supabase operational project region: Southeast Asia (Singapore))
- Entrusted tasks: Database hosting, user authentication management, cloud storage (cover photos) operations, server function execution
- Transferred items: Account identifier, profile information, overall reading records (book info, session records, notes, one-line reviews, quote cards, tags), uploaded cover photos, friend relationships and activity timeline, push tokens, coin ledger, decoration items and room layouts, server unlock records, season quest claim records, account preferences, payment verification receipts (including product list price, purchase country, purchase timestamp), and statutorily segregated payment records upon withdrawal (hashed)
- Transfer timestamp and method: Transferred intermittently via internet network (encrypted communication) during service use
- Retention and use period: Until member withdrawal or service termination
② Entrustment of notification dispatch and app analytics
- Trustee: Google LLC
- Transferred country: United States and other countries where Google LLC operates data centers
- Entrusted tasks: Push notification transmission (Firebase Cloud Messaging), app usage analytics (Firebase Analytics), app error analytics (Firebase Crashlytics)
- Transferred items: Device push notification token, service account identifier (UID), app usage analytics event logs and user properties, app crash records and device information (excluding personal identifying text)
- Retention and use period: Until member withdrawal, push token deletion, or achievement of analytics purposes (subject to Google's data retention policy; crash logs retained for 90 days after collection)
③ In-app purchase verification
Payments are processed by Google Play, and the Company does not receive payment method information such as credit card numbers. The Company verifies purchase tokens via Google LLC's Google Play Developer API to confirm purchases.
- Recipient: Google LLC
- Transferred country: United States and other countries where Google LLC operates data centers
- Task description: Verifying validity of purchase receipts (inquiry of purchase state, order number, purchase time, purchase country)
- Transferred items: Purchase token, product identifier, package name
- Retention and use period: Until expiration of retention periods under relevant laws such as the Electronic Commerce Act
④ Provision of book search service (Reference)
- Integrated service: Kakao Book Search API and Daum Book Cover CDN (Kakao Corp.)
- Processing details: Search keywords entered by users when searching books are queried via Kakao Book Search API, and search results are temporarily cached on the server and device for 1 hour. Book cover thumbnails are loaded into device temporary directories via Kakao CDN.
- Transferred items: Search queries (no member identifying information or personal profile information is ever transmitted to Kakao.)
7. Rights of Data Subjects and Legal Representatives and How to Exercise Them
Users may exercise the following rights at any time:
- Request to view personal information: You may view your personal information and reading records at any time in the Bookshelf tab, Statistics screen, Profile screen, and More screen within the app.
- Request to rectify personal information: You may edit nicknames, introductions, etc., in the Profile Edit screen within the app, and directly edit registered book details, notes, ratings, etc., in the Bookshelf screen.
- Request to delete personal information: You may delete your account and request complete destruction of personal information at any time via the Delete Account menu in the app, and individual books or notes can also be deleted immediately in the app.
- Request to suspend processing of personal information: You may stop analytics directly by turning off 'Send app usage statistics' in the app Settings menu, or request suspension of processing via customer support.
- In the case of children under the age of 14, legal representatives may exercise the rights to view, rectify, delete, or suspend processing of the child's personal information.
8. How to Opt Out of App Usage Statistics Collection
Users may opt out of the collection of app usage analytics and crash logs at any time:
1. Navigate to the 'More' tab in the app.
2. Enter the 'Settings' screen.
3. Turn off the 'Send app usage statistics' switch under the 'Privacy' section.
4. Collection and transmission of analytics and error reports are discontinued immediately upon turning off the switch, and this setting is synchronized to the user's account and maintained even when switching devices.
9. How to Delete Account (Membership Withdrawal)
Users may delete their account directly within the app at any time:
1. Press the 'Delete Account' button at the bottom of the 'Settings' screen in the 'More' tab within the app.
2. After reviewing the notices (permanent deletion of profiles, friendships, shared bookshelves, coins and items, device and cloud reading records), proceed with Step 1 'Continue' and Step 2 'Delete'.
3. When deletion proceeds:
- User-registered book cover photos stored in cloud storage on the server are permanently deleted.
- Account information, profiles, friend relationships, shared bookshelves, coin ledger, item inventory, room layouts, character unlocks/season quest claim records, account settings, and all synchronized reading records (books, sessions, notes, quote cards, tags) stored in the server database are immediately permanently deleted and cannot be recovered.
- However, verified payment records are segregated and stored with personal identifiers removed and one-way hashed (SHA-256) until 5 years from the payment date pursuant to the Electronic Commerce Act, and then automatically destroyed.
- The SQLite local database, settings cache, and local cover image folder stored on the device are also initialized immediately.
- Push notification tokens are destroyed immediately on both server and device, and the user is logged out.
10. Measures to Ensure the Security of Personal Information
The Service takes the following technical and managerial measures to securely protect users' personal information:
- Network encryption: Applies standard SSL/TLS encrypted communication across all data transmission channels between clients, servers, and third-party APIs.
- Database row-level security policy (RLS, Row Level Security): Applies database security policies to fundamentally block data access other than by the user and approved friends.
- Storage access control: Enforces strict storage policies so that user-uploaded files can only be written and deleted within unique paths of authenticated accounts.
- De-identification of analytics data: Sensitive text such as book titles, authors, and notes is excluded when collecting app usage analytics, and book identifiers are transmitted after being converted to one-way hashes based on FNV-1a.
- De-identification hash measures for retained payment records: Payment records segregated and stored until 5 years from the payment date under the Electronic Commerce Act completely exclude identifying information such as email and nickname, and safely isolate user identifiers and purchase tokens by converting them into SHA-256 one-way hashes.
- Token lifecycle management: Push notification tokens are destroyed immediately on both server and device upon logout and account deletion, and invalidated tokens are automatically detected and deleted.
11. Data Protection Officer and Inquiries
The Service designates a Data Protection Officer as follows to take overall responsibility for personal information processing and to handle user complaints and remedy damages:
Data Protection Officer
Operator Information
- Operator Name: Soonmu Shop (순무샵)
- Address: 902, 9th Floor, 42 Metapolis-ro, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea (경기 화성시 동탄구 메타폴리스로 42 9층 902)
- Inquiries: soonmu.devforge@gmail.com
12. Modification and Notice of Privacy Policy
This Privacy Policy may be modified to reflect changes in legislation or service changes. If the policy is revised, notice will be provided in advance through in-app announcements or update screens.
- Announcement date: 2026-09-30
- Effective date: 2026-09-30