백색소음 · White Noise

백색소음 앱 개인정보처리방침

최종 업데이트일: 2026년 8월 16일

시행일: 2026년 8월 16일

핵심 안내

백색소음 앱은 회원가입을 요구하지 않으며 광고를 표시하지 않습니다. 앱 설정값은 원칙적으로 기기에 저장하며, 이용 분석·오류 진단 및 14일 무료 이용 기간 확인을 위해 Google Firebase가 일부 기기·이용 정보를 처리할 수 있습니다. 구독 결제수단 정보는 Apple 또는 Google이 직접 처리하며 SGTHL은 카드번호나 계좌정보를 수집하지 않습니다.

에스지티에이치엘(SGTHL, 이하 ‘운영자’)은 정보주체의 자유와 권리를 보호하기 위하여 「개인정보 보호법」 등 관계 법령을 준수하고, 개인정보를 적법하고 안전하게 처리합니다. 본 개인정보처리방침은 운영자가 제공하는 백색소음 모바일 애플리케이션 및 관련 서비스(이하 ‘앱’ 또는 ‘서비스’)에 적용됩니다.

제1조 (개인정보의 처리 목적)

운영자는 다음 목적에 필요한 최소한의 정보만 처리합니다.

  1. 백색소음·자연음·타이머·즐겨찾기·이명 맞춤 설정 등 앱 기능 제공
  2. 14일 무료 이용 기간 및 프리미엄 구독 상태 확인, 구매 복원과 고객지원
  3. 앱 이용 현황 분석, 기능 개선 및 서비스 품질 향상
  4. 오류·충돌 진단, 보안 유지, 부정 이용 방지와 서비스 안정성 확보
  5. 이용자 문의, 불만 및 분쟁 처리와 법적 의무 이행

운영자는 위 목적과 양립하지 않는 용도로 개인정보를 이용하지 않으며, 이용 목적이 변경되는 경우 관계 법령에 따라 필요한 조치를 합니다.

제2조 (처리하는 개인정보의 항목, 수집방법 및 보유기간)

① 앱은 회원가입을 요구하지 않으며, 일반적인 앱 이용을 위해 이름·전화번호·이메일 주소를 필수로 수집하지 않습니다.

② 서비스 이용 과정에서 다음 정보가 이용자가 제공하는 방법 또는 SDK·앱마켓 기능을 통해 처리될 수 있습니다.

구분처리 항목목적보유기간
고객문의이메일 주소, 이용자가 기재한 이름·닉네임, 문의 내용, 첨부파일, 기기 모델·운영체제·앱 버전, 이용자가 제출한 구매·구독 확인정보문의·불만·환불·분쟁 처리일반 문의는 처리 완료 후 1년, 소비자 불만·분쟁 기록은 관계 법령에 따라 3년
Cloud Firestore (무료 이용 기간 기록, Android)앱이 생성한 무작위 식별자(무료 이용 ID), 최초 이용 시각과 마지막 확인 시각(서버 시각), 플랫폼 구분. 이름·이메일·기기 ID 등 이용자를 직접 식별하는 정보와 연결되지 않음14일 무료 이용 기간 산정, 앱 재설치·기기 변경 시 무료 이용 기간 유지, 기기 시간 변경에 의한 부정 이용 방지무료 이용 기간 산정에 필요한 기간 동안 보관하며, 이용자가 제12조의 연락처로 삭제를 요청하면 지체 없이 삭제
Firebase Analytics앱 인스턴스·Firebase 설치 식별자, 기기·앱·운영체제 정보, 언어·국가, 앱 실행·세션·화면 및 기능 이용 이벤트이용 통계 분석, 기능·UI 개선, 서비스 품질 향상사용자·이벤트 수준 데이터 14개월(운영 설정 기준). 집계 보고서는 더 오래 보관될 수 있음
Firebase CrashlyticsCrashlytics 설치 UUID, Firebase 설치 식별자, 충돌 로그·스택 트레이스·미니덤프, 기기·앱·운영체제 상태 및 진단정보오류·충돌 분석, 앱 안정성 개선Google의 공개 기준상 90일 후 삭제 절차 개시
앱마켓 구독상품 식별자, 거래 식별자 또는 구매 토큰, 구매·갱신·만료·해지·취소 상태와 시각(카드번호·계좌정보 제외)구매 확인, 구독 권한 제공, 구매 복원 및 고객지원운영자 서버에는 별도 저장하지 않는 것을 원칙으로 함. 앱마켓 거래기록은 Apple 또는 Google의 정책에 따라 보관. 고객지원 과정에서 이용자가 제출한 구매·구독 확인자료는 일반 문의 처리 완료 후 1년 또는 소비자 불만·분쟁 기록에 해당하는 경우 3년

③ 즐겨찾기, 타이머, 페이드 아웃 지속 시간 및 이명 맞춤 설정값은 기기 내 저장소에서만 처리하며 운영자 서버로 전송하지 않습니다. 14일 무료 이용 기간의 시작 시점은 iOS에서는 기기 저장소와 App Store 앱 구매 정보(최초 다운로드 시점)만으로 판단하고, Android에서는 앱을 지우고 다시 설치해도 무료 이용 기간이 처음부터 다시 시작되지 않도록 앱이 생성한 무작위 식별자와 최초 이용 시각을 운영자의 Firebase 프로젝트(Google Cloud Firestore, 대한민국 서울 리전)에 저장하며 Google 계정에 연결된 백업 저장소(Block Store)에도 보관될 수 있습니다. 이 식별자는 이름·이메일·기기 ID 등 이용자를 직접 식별하는 정보와 연결되지 않습니다. 특히 이명 맞춤 설정값은 Firebase Analytics의 이벤트·사용자 속성·파라미터 또는 Firebase Crashlytics의 Custom Key·로그·사용자 식별값에 포함하지 않습니다. 해당 정보가 향후 서버 동기화, 계정 기능 또는 외부 SDK에 사용되는 경우 운영자는 전송 전에 본 방침을 변경하고 민감정보 해당 여부를 검토하여 관계 법령상 필요한 고지·동의 절차를 진행합니다.

④ 운영자는 Apple App Store 또는 Google Play가 처리하는 카드번호, 계좌번호, 결제 비밀번호 등 결제수단 정보를 직접 수집하거나 저장하지 않습니다. 앱마켓의 거래기록은 각 앱마켓 사업자가 자신의 정책과 관계 법령에 따라 보관합니다. 운영자가 구독 권한 확인을 위해 기기에서 거래 식별자·구매 토큰 또는 구독 상태를 일시적으로 확인하더라도, 별도 서버에 저장하지 않는 것을 원칙으로 합니다.

제3조 (개인정보 처리의 법적 근거)

운영자는 다음 근거가 있는 범위에서 개인정보를 처리합니다.

  1. 이용자의 동의: 선택적 분석 등 동의가 필요한 처리
  2. 이용자와의 계약 체결·이행: 앱 기능, 구독 권한, 구매 복원 및 고객지원 제공에 필요한 처리
  3. 법령상 의무 이행: 거래기록 보존, 분쟁 대응 등 법률이 요구하는 처리
  4. 정당한 이익: 이용자의 권리보다 명백히 우선하는 범위에서 오류 진단, 보안 유지 및 부정 이용 방지

제4조 (개인정보의 제3자 제공)

운영자는 정보주체의 개인정보를 제1조의 처리 목적 범위에서 이용하며, 원칙적으로 제3자에게 제공하지 않습니다. 다만, 정보주체가 사전에 동의한 경우, 법률에 특별한 규정이 있는 경우 또는 생명·신체의 급박한 위험을 보호하기 위해 법률상 허용되는 경우에는 예외로 합니다.

Google 분석·오류진단·데이터베이스 서비스 및 Apple·Google 앱마켓의 정보 처리는 아래 조항과 각 사업자의 개인정보처리방침에 따릅니다.

제5조 (외부 서비스, 개인정보 처리위탁 및 국외 이전)

① 운영자는 이용 분석, 오류 진단 및 무료 이용 기간 기록을 위해 아래 외부 서비스를 사용합니다. Google 공식 안내에 따르면 Firebase Crashlytics를 포함한 대부분의 Firebase 서비스는 글로벌 Google 인프라에서 운영되며, 위치 선택 기능이 없는 경우 Google 또는 그 대리인이 시설을 운영하는 국가에서 정보가 처리·보관될 수 있습니다. Google Analytics 역시 전 세계 Google 서버를 이용할 수 있습니다. 무료 이용 기간 기록에 쓰는 Cloud Firestore 데이터베이스는 대한민국(서울) 리전에 두었습니다. 운영자는 관계 법령이 요구하는 보호조치와 공개 의무를 이행합니다.

항목내용
이전받는 자Google LLC (개인정보 문의: Google Privacy Help Center)
이용 서비스Google Analytics for Firebase, Firebase Crashlytics, Cloud Firestore
이전 국가미국을 포함하여 Google 또는 그 대리인이 데이터 처리 시설을 운영하는 국가. Google은 해당 서비스별 처리 국가를 하나로 고정하거나 완전한 국가 목록으로 공개하지 않으며, 글로벌 인프라 운영에 따라 실제 처리 위치가 달라질 수 있음
이전 항목제2조의 Firebase Analytics, Crashlytics 및 Cloud Firestore 처리 항목
이전 목적앱 이용 분석, 오류·충돌 진단, 14일 무료 이용 기간 산정
이전 일시·방법앱 실행·이용 또는 오류 발생 시 암호화된 통신망을 통해 자동 전송
보유·이용기간Firebase Analytics 14개월, Crashlytics 90일 후 삭제 절차 개시, Cloud Firestore의 무료 이용 기간 기록은 산정에 필요한 기간 동안(삭제 요청 시 지체 없이 삭제)
이전 근거• Google Analytics for Firebase: 「개인정보 보호법」 제28조의8제1항제3호가목 (앱 이용 분석 및 서비스 품질 유지를 위한 국외 처리위탁·보관). 선택적 분석과 결합하여 동의를 받는 처리에는 같은 항 제1호를 적용
• Cloud Firestore: 같은 법 제28조의8제1항제3호가목 (14일 무료 이용 기간 산정을 위한 처리위탁·보관). 데이터베이스는 대한민국(서울) 리전에 두었으나 Google 인프라 운영상 국외에서 처리될 수 있음
• Firebase Crashlytics: 같은 법 제28조의8제1항제3호가목 (오류·충돌 진단과 서비스 안정성 유지를 위한 국외 처리위탁·보관)

국외 이전의 거부 및 영향: 이용자는 제12조의 이메일을 통해 국외 이전에 관한 동의를 철회하거나 처리 중지를 요청할 수 있습니다. 운영자는 적용되는 법적 근거와 기술적 가능성에 따라 조치합니다. 해당 SDK의 처리를 중지하면 이용 통계·오류 진단·무료 이용 기간 산정 기능이 제한될 수 있으나, 기본 음원 재생 등 핵심 기능에는 불필요한 제한이 생기지 않도록 운영합니다. Google 개인정보 문의는 Google Privacy Help Center에서 할 수 있습니다.

② Apple App Store 및 Google Play는 이용자와의 앱 배포·결제 관계에서 결제정보를 직접 처리합니다. 운영자는 앱마켓으로부터 구독 권한 확인에 필요한 최소한의 거래·구독 상태만 제공받을 수 있습니다. 각 앱마켓의 처리에는 해당 사업자의 개인정보처리방침이 적용됩니다.

③ 외부 서비스 또는 국외 이전 사항이 변경되는 경우 운영자는 변경 내용을 본 방침에 반영하고, 별도 동의가 필요한 경우 사전에 동의를 받습니다.

제6조 (자동 수집 기술과 이용자의 선택권)

① 앱 또는 제3자 SDK는 이용 분석, 오류 진단 및 서비스 제공을 위해 앱 인스턴스 식별자, SDK 등 유사한 기술을 사용할 수 있습니다. 앱은 광고를 표시하지 않으며 모바일 광고 식별자(IDFA/AAID)를 광고 목적으로 이용하지 않습니다. 앱 자체는 웹 브라우저 쿠키를 직접 설치하지 않지만, 앱에서 외부 웹페이지를 여는 경우 해당 웹사이트가 쿠키를 사용할 수 있습니다.

② 이용자는 다음 방법으로 일부 처리를 제한하거나 동의를 철회할 수 있습니다.

  1. iOS: 설정 > 개인정보 보호 및 보안 > 분석 및 향상에서 분석 데이터 공유 설정 변경(앱은 앱 추적 투명성 권한을 요청하지 않음)
  2. Android: 설정 > Google > 백업에서 앱 데이터 백업(무료 이용 기간 백업 포함) 사용 여부 변경(기기 버전에 따라 메뉴명이 다를 수 있음)
  3. 개인정보 관련 요청은 제12조의 고객지원 이메일로 접수

③ 이용자가 분석 데이터 처리의 중지를 요청하더라도 앱의 기본 기능은 계속 이용할 수 있으며, 일부 통계 기능만 제한될 수 있습니다. 네트워크 통신, 보안, 오류 진단 및 무료 이용 기간 산정에 필요한 최소 정보는 처리될 수 있습니다.

제7조 (개인정보의 보유 및 파기)

① 운영자는 처리 목적이 달성되거나 보유기간이 끝난 개인정보를 지체 없이 파기합니다.

② 운영자는 현재 앱마켓의 결제수단 정보와 완전한 거래기록을 직접 보관하지 않습니다. 아래 법정 보존기간은 운영자가 고객지원·분쟁처리 과정 등에서 해당 기록을 직접 생성·수령하여 보유하게 되거나 관계 법령상 직접 보존의무를 부담하는 경우에만 적용합니다. Apple 또는 Google이 보관하는 거래정보에는 각 사업자의 보유정책과 관계 법령이 적용됩니다. 운영자가 법령에 따라 기록을 보존하는 경우에는 다른 정보와 분리하여 보관하고 법정 목적 외로 이용하지 않습니다.

  1. 계약 또는 청약철회 등에 관한 기록: 5년
  2. 대금결제 및 재화 등의 공급에 관한 기록: 5년
  3. 소비자의 불만 또는 분쟁처리에 관한 기록: 3년
  4. 표시·광고에 관한 기록: 6개월

③ 전자적 파일은 복구 또는 재생이 어렵도록 안전한 방법으로 삭제하며, 종이 문서는 분쇄 또는 소각하여 파기합니다.

④ 앱 삭제는 기기에만 저장된 설정값의 처리를 종료하고 향후 SDK 전송을 중단시킬 수 있으나, 앱마켓의 구독을 자동 해지하거나 이미 Google·Apple 등 외부 서비스로 전송된 정보를 자동 삭제하지는 않습니다. 앱마켓 거래정보의 열람·삭제는 해당 사업자의 절차를 따르며, 운영자가 고객지원 과정에서 직접 보유한 정보는 제12조의 이메일로 권리 행사를 요청할 수 있습니다.

제8조 (정보주체와 법정대리인의 권리·의무 및 행사방법)

① 정보주체는 운영자에게 자신의 개인정보에 대해 열람, 정정·삭제, 처리정지, 동의 철회 및 설명을 요구할 수 있습니다.

② 권리 행사는 본인 또는 적법한 대리인이 제12조의 이메일로 요청할 수 있으며, 운영자는 본인확인 후 관계 법령에서 정한 기간과 절차에 따라 조치합니다.

③ 법령상 보존 의무가 있거나 다른 사람의 권리·안전을 침해할 우려가 있는 경우 등에는 일부 요청이 제한될 수 있으며, 이 경우 제한 사유를 안내합니다.

④ Google·Apple 등 독립적으로 처리되는 정보에 대한 요청은 해당 사업자의 개인정보 보호 절차를 통해 직접 행사해야 할 수 있습니다.

제9조 (대한민국 외 지역 이용자의 추가 권리)

① 유럽경제지역(EEA), 영국 또는 스위스의 이용자는 적용 법령에 따라 개인정보의 열람·정정·삭제, 처리 제한, 이동, 처리 반대 및 동의 철회를 요구할 수 있으며, 관할 감독기관에 불만을 제기할 수 있습니다. 동의 철회는 철회 전에 이루어진 처리의 적법성에 영향을 주지 않습니다.

② 미국 캘리포니아주 등 관련 법률이 적용되는 지역의 이용자는 개인정보의 수집·이용·공개 내역 확인, 열람, 정정, 삭제, 판매 또는 공유 거부 및 권리 행사에 따른 차별 금지를 요구할 수 있습니다. 운영자는 개인정보를 금전적 대가를 받고 판매하지 않습니다. 또한 운영자는 교차 맥락 행동광고 목적으로 개인정보를 ‘공유’하지 않습니다.

③ 지역별 권리는 거주지와 서비스 이용 방식에 따라 달라질 수 있습니다. 요청은 제12조의 고객지원 창구로 접수할 수 있으며, 운영자는 적용 법령에 따라 본인확인 및 처리 결과 안내를 진행합니다.

제10조 (만 14세 미만 아동의 개인정보)

① 앱은 만 14세 미만 아동을 주된 대상으로 하지 않으며, 운영자는 법정대리인의 동의 없이 만 14세 미만 아동의 개인정보를 고의로 수집하지 않습니다.

② 운영자가 만 14세 미만 아동의 개인정보를 법정대리인의 동의 없이 처리한 사실을 확인한 경우 지체 없이 삭제하며, 법정대리인은 제12조의 연락처로 삭제 또는 처리정지를 요청할 수 있습니다.

③ 보호자가 영유아 또는 아동 주변에서 앱을 사용하는 경우 보호자는 기기의 개인정보 설정, 적정 음량 및 이용 시간을 직접 관리하여야 합니다.

제11조 (개인정보의 안전성 확보조치)

운영자는 개인정보의 분실·도난·유출·위조·변조 또는 훼손을 방지하기 위해 다음과 같은 조치를 시행합니다.

  1. 개인정보 접근 권한의 최소화 및 담당자 관리
  2. 전송 구간 암호화와 안전한 통신 방식 사용
  3. 보안 업데이트, 취약점 점검 및 오류·접속 이상 모니터링
  4. 보유기간이 지난 정보의 정기적 파기
  5. 외부 서비스 사업자의 보안·개인정보 보호 조건 확인 및 필요한 감독

개인정보 유출 등 사고가 발생하여 법령상 통지가 필요한 경우 운영자는 사고의 내용, 영향을 받는 정보, 대응 조치 및 문의 방법을 관계 법령에서 정한 방식과 시기에 따라 알립니다.

제12조 (개인정보 보호업무 및 고충처리 담당부서)

개인정보 보호업무, 권리 행사, 불만 처리 및 피해구제 관련 문의는 아래 담당부서로 접수해 주시기 바랍니다.

항목내용
담당부서SGTHL 고객지원
이메일sgthl20@gmail.com
전화번호0502-1918-0106 (전화 상담은 운영하지 않으며 이메일 접수를 우선합니다)
주소경기도 성남시 수정구 논골로63번길 1, 101호

제13조 (권익침해 구제방법)

정보주체는 개인정보 침해에 대한 상담이나 분쟁 해결을 위해 아래 기관에 문의할 수 있습니다.

  1. 개인정보침해 신고센터: 국번 없이 118
  2. 개인정보분쟁조정위원회: 1833-6972
  3. 대검찰청: 국번 없이 1301
  4. 경찰청: 국번 없이 182

제14조 (제3자 서비스의 개인정보처리방침)

앱에서 사용하는 외부 서비스의 개인정보 처리에 관한 자세한 내용은 다음 문서에서 확인할 수 있습니다.

  1. Google 개인정보처리방침
  2. Firebase 개인정보 보호 및 보안
  3. Apple 개인정보처리방침
  4. Google Play 개인정보처리방침

제15조 (개인정보처리방침의 변경)

① 운영자는 관계 법령, 앱 기능 또는 외부 서비스 변경에 따라 본 방침을 수정할 수 있습니다.

② 변경 시 변경 내용과 시행일을 앱 또는 공개 웹페이지를 통해 원칙적으로 시행일 7일 전에 알립니다. 이용자 권리에 중대한 영향을 미치는 불리한 변경은 원칙적으로 30일 전에 알리고, 별도 동의가 필요한 경우 동의를 받습니다.

③ 이전 버전은 이용자의 요청이 있는 경우 확인할 수 있도록 관리합니다.

사업자 정보

  1. 상호: 에스지티에이치엘(SGTHL)
  2. 대표자: 이상걸, 유태훈
  3. 사업자등록번호: 293-01-01743
  4. 통신판매업 신고: 제2026-성남수정-0522호(성남시)

본 개인정보처리방침은 2026년 8월 16일부터 시행합니다.


White Noise App Privacy Policy

Last updated: August 16, 2026

Effective date: August 16, 2026

Key Notice

The White Noise app does not require account registration and does not display advertisements. App settings are generally stored on the device. Google Firebase may process certain device and usage information for usage analytics, error diagnostics, and verification of the 14-day free-use period. Apple or Google directly processes subscription payment-method information; SGTHL does not collect card or bank-account information.

SGTHL (hereinafter, the "Operator") complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws to protect the freedoms and rights of data subjects and processes personal information lawfully and securely. This Privacy Policy applies to the White Noise mobile application and related services provided by the Operator (the "App" or "Service").

Article 1 (Purposes of Processing Personal Information)

The Operator processes only the minimum information necessary for the following purposes:

  1. Providing App features, including white noise, nature sounds, timers, favorites, and personalized tinnitus settings
  2. Checking the 14-day free-use period and Premium subscription status, restoring purchases, and providing customer support
  3. Analyzing App usage, improving features, and enhancing service quality
  4. Diagnosing errors and crashes, maintaining security, preventing misuse, and ensuring service stability
  5. Handling user inquiries, complaints, and disputes, and complying with legal obligations

The Operator does not use personal information for purposes incompatible with those listed above. If a purpose changes, the Operator will take the measures required by applicable law.

Article 2 (Personal Information Processed, Collection Methods, and Retention Periods)

① The App does not require account registration and does not require users to provide a name, telephone number, or email address for ordinary use of the App.

② During use of the Service, the following information may be processed when provided by the user or through SDKs and app-market functions.

CategoryInformation processedPurposeRetention period
Customer inquiriesEmail address; name or nickname entered by the user; inquiry details; attachments; device model; operating system; App version; and purchase or subscription verification information submitted by the userHandling inquiries, complaints, refunds, and disputesGeneral inquiries: 1 year after completion; consumer complaint or dispute records: 3 years where required by applicable law
Cloud Firestore (free-use period record, Android)A random identifier generated by the App (free-use ID); the first-use time and last-checked time (server time); and platform. Not linked to information that directly identifies the user, such as name, email, or device IDCalculating the 14-day free-use period, preserving the free-use period across reinstalls and device changes, and preventing abuse by changing the device clockRetained for as long as needed to calculate the free-use period; deleted without delay upon a user's request to the contact in Article 12
Firebase AnalyticsApp instance and Firebase installation identifiers; device, App, and operating-system information; language and country; and App launch, session, screen, and feature-usage eventsUsage analytics, feature and UI improvement, and service-quality enhancementUser-level and event-level data: 14 months under the Operator's current setting. Aggregated reports may be retained longer.
Firebase CrashlyticsCrashlytics installation UUID; Firebase installation identifier; crash logs, stack traces, and minidumps; and device, App, operating-system status, and diagnostic informationError and crash analysis and App-stability improvementUnder Google's published standard, the deletion process begins after 90 days.
App-market subscriptionsProduct identifier; transaction identifier or purchase token; and purchase, renewal, expiration, termination, and cancellation status and time (excluding card and bank-account information)Purchase verification, subscription entitlement, purchase restoration, and customer supportAs a rule, not separately stored on the Operator's server. App-market transaction records are retained under Apple or Google policies. Purchase or subscription verification materials submitted during customer support are retained for 1 year after completion of a general inquiry, or for 3 years if they constitute consumer complaint or dispute records.

③ Favorites, timer settings, fade-out duration, and personalized tinnitus settings are processed only in on-device storage and are not transmitted to the Operator's server. The start time of the 14-day free-use period is determined on iOS solely from on-device storage and App Store app-purchase information (the original download date). On Android, so that the free-use period does not restart after the App is deleted and reinstalled, a random identifier generated by the App and the first-use time are stored in the Operator's Firebase project (Google Cloud Firestore, Seoul region, Republic of Korea) and may also be kept in the Google-account-linked backup storage (Block Store). This identifier is not linked to information that directly identifies the user, such as name, email, or device ID. In particular, personalized tinnitus settings are not included in Firebase Analytics events, user properties, or parameters, or in Firebase Crashlytics Custom Keys, logs, or user identifiers. If this information is later used for server synchronization, account features, or external SDKs, the Operator will revise this Policy before transmission, assess whether the information constitutes sensitive information, and provide any notice or obtain any consent required by applicable law.

④ The Operator does not directly collect or store payment-method information processed by the Apple App Store or Google Play, such as card numbers, bank-account numbers, or payment passwords. Each app-market operator retains transaction records according to its own policies and applicable law. Even if the Operator temporarily checks a transaction identifier, purchase token, or subscription status on the device to verify subscription entitlement, such information is, as a rule, not stored on a separate server.

Article 3 (Legal Bases for Processing Personal Information)

The Operator processes personal information only to the extent supported by one or more of the following legal bases:

  1. User consent: processing that requires consent, such as optional analytics
  2. Entering into or performing a contract with the user: processing necessary to provide App features, subscription entitlement, purchase restoration, and customer support
  3. Compliance with legal obligations: processing required by law, including retention of transaction records and dispute response
  4. Legitimate interests, to the extent recognized by applicable law: error diagnostics, security maintenance, and misuse prevention where the Operator's interests clearly outweigh the user's rights

Article 4 (Disclosure of Personal Information to Third Parties)

The Operator uses personal information within the purposes described in Article 1 and, in principle, does not disclose it to third parties. Exceptions apply where the data subject has consented in advance, where disclosure is specifically required or permitted by law, or where disclosure is legally permitted to protect a person from an imminent threat to life or physical safety.

The processing of information by Google's analytics, error-diagnostics, and database services and by the Apple and Google app markets is governed by the provisions below and each provider's privacy policy.

Article 5 (External Services, Processing Entrustment, and Cross-Border Transfers)

① The Operator uses the external services listed below for usage analytics, error diagnostics, and recording the free-use period. According to Google's official information, most Firebase services, including Firebase Crashlytics, operate on Google's global infrastructure. Where no location-selection feature is available, information may be processed and stored in countries where Google or its agents operate facilities. Google Analytics may also use Google servers worldwide. The Cloud Firestore database used to record the free-use period is located in the Seoul (Republic of Korea) region. The Operator implements safeguards and makes disclosures as required by applicable law.

ItemDetails
RecipientGoogle LLC (privacy inquiries: Google Privacy Help Center)
Services usedGoogle Analytics for Firebase, Firebase Crashlytics, and Cloud Firestore
Destination countriesThe United States and other countries in which Google or its agents operate data-processing facilities. Google does not assign these services to a single fixed processing country or publish a complete country list, and actual processing locations may vary due to the operation of its global infrastructure.
Information transferredThe Firebase Analytics, Crashlytics, and Cloud Firestore information listed in Article 2
PurposesApp usage analytics; error and crash diagnostics; and calculating the 14-day free-use period
Timing and methodAutomatically transmitted through encrypted communications when the App is launched or used or an error occurs
Retention and use periodFirebase Analytics: 14 months; Crashlytics: deletion process begins after 90 days; Cloud Firestore free-use-period records: for as long as needed for the calculation (deleted without delay upon request)
Legal basis for transfer• Google Analytics for Firebase: Article 28-8(1)(3)(a) of the Personal Information Protection Act of the Republic of Korea (overseas processing entrustment and storage for App usage analytics and maintaining service quality). Article 28-8(1)(1) applies to processing for which consent is obtained because analytics are optional.
• Cloud Firestore: Article 28-8(1)(3)(a) of the same Act (processing entrustment and storage for calculating the 14-day free-use period). The database is located in the Seoul (Republic of Korea) region but may be processed abroad in the course of operating Google's infrastructure.
• Firebase Crashlytics: Article 28-8(1)(3)(a) of the same Act (overseas processing entrustment and storage for error and crash diagnostics and maintaining service stability).

Refusal of cross-border transfers and effects: Users may withdraw consent to a cross-border transfer or request suspension of processing by using the email address in Article 12. The Operator will respond according to the applicable legal basis and technical feasibility. Stopping the relevant SDK processing may limit usage statistics, error-diagnostics, or free-use-period calculation functions; however, the Operator seeks to avoid unnecessary restrictions on core functions such as basic audio playback. Google privacy inquiries may be submitted through the Google Privacy Help Center.

② The Apple App Store and Google Play directly process payment information as part of their app-distribution and payment relationships with users. The Operator may receive only the minimum transaction and subscription-status information needed to verify subscription entitlement. Each app-market provider's privacy policy applies to its processing.

③ If an external service or cross-border-transfer arrangement changes, the Operator will update this Policy and will obtain consent in advance where separate consent is required.

Article 6 (Automated Collection Technologies and User Choices)

① The App or third-party SDKs may use App instance identifiers, SDKs, and similar technologies for usage analytics, error diagnostics, and service delivery. The App does not display advertisements and does not use mobile advertising identifiers (IDFA/AAID) for advertising purposes. The App itself does not directly set web-browser cookies, but an external website opened from the App may use cookies.

② Users may restrict certain processing or withdraw consent as follows:

  1. iOS: Go to Settings > Privacy & Security > Analytics & Improvements to change analytics-sharing settings (the App does not request App Tracking Transparency permission)
  2. Android: Go to Settings > Google > Backup to change whether app data (including the free-use-period backup) is backed up (menu names may vary by device version)
  3. Submit privacy-related requests to the customer-support email address in Article 12

③ Users may continue to use the App's basic features after requesting suspension of analytics processing; only certain statistics functions may be limited. Minimum information required for network communications, security, error diagnostics, and calculating the free-use period may still be processed.

Article 7 (Retention and Destruction of Personal Information)

① The Operator destroys personal information without delay when the processing purpose has been achieved or the retention period has expired.

② The Operator currently does not directly retain app-market payment-method information or complete transaction records. The statutory retention periods below apply only if the Operator directly creates, receives, and retains the relevant records through customer support or dispute handling, or if applicable law imposes a direct retention obligation on the Operator. Transaction information retained by Apple or Google is governed by each provider's retention policies and applicable law. Records retained by the Operator under law are stored separately and are not used for purposes other than the statutory purpose.

  1. Records concerning contracts or withdrawal of offers: 5 years
  2. Records concerning payment and supply of goods or services: 5 years
  3. Records concerning consumer complaints or dispute resolution: 3 years
  4. Records concerning labeling and advertising: 6 months

③ Electronic files are deleted using secure methods that make recovery or reproduction difficult, and paper documents are shredded or incinerated.

④ Deleting the App may end the processing of settings stored only on the device and stop future SDK transmissions. However, deleting the App does not automatically cancel an app-market subscription or delete information already transmitted to external services such as Google or Apple. Requests to access or delete app-market transaction information must follow the relevant provider's procedures. Users may exercise their rights regarding information directly retained by the Operator during customer support by using the email address in Article 12.

Article 8 (Rights and Obligations of Data Subjects and Legal Representatives; How to Exercise Rights)

① A data subject may request access to, correction or deletion of, suspension of processing of, withdrawal of consent to, or an explanation concerning the data subject's personal information.

② The data subject or a lawful representative may exercise these rights by sending a request to the email address in Article 12. After verifying identity, the Operator will act within the periods and according to the procedures prescribed by applicable law.

③ A request may be restricted where retention is required by law, where the request may infringe another person's rights or safety, or in other circumstances permitted by law. In such a case, the Operator will explain the reason for the restriction.

④ Requests concerning information independently processed by Google, Apple, or another provider may need to be submitted directly through that provider's privacy procedures.

Article 9 (Additional Rights of Users Outside the Republic of Korea)

① Users in the European Economic Area (EEA), the United Kingdom, or Switzerland may, subject to applicable law, request access, correction, deletion, restriction of processing, portability, objection to processing, or withdrawal of consent, and may lodge a complaint with the competent supervisory authority. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

② Users in California and other jurisdictions where similar laws apply may request information about the collection, use, and disclosure of personal information; access; correction; deletion; an opt-out from sale or sharing; and freedom from discrimination for exercising privacy rights. The Operator does not sell personal information for monetary consideration. The Operator also does not 'share' personal information for cross-context behavioral advertising.

③ Rights vary by place of residence and manner of using the Service. Requests may be submitted through the customer-support channel in Article 12. The Operator will verify identity and communicate the outcome as required by applicable law.

Article 10 (Personal Information of Children Under 14)

① The App is not primarily directed to children under 14, and the Operator does not knowingly collect the personal information of a child under 14 without consent from the child's legal representative.

② If the Operator learns that it has processed the personal information of a child under 14 without the consent of the child's legal representative, the Operator will delete it without delay. A legal representative may request deletion or suspension of processing through the contact information in Article 12.

③ Where a parent or guardian uses the App near an infant or child, the parent or guardian should manage the device's privacy settings, appropriate volume, and use time.

Article 11 (Measures to Safeguard Personal Information)

The Operator implements the following measures to prevent the loss, theft, leakage, forgery, alteration, or damage of personal information:

  1. Minimizing access privileges and managing personnel with access
  2. Encrypting information in transit and using secure communication methods
  3. Applying security updates, checking vulnerabilities, and monitoring errors and anomalous access
  4. Regularly destroying information after its retention period
  5. Reviewing the security and privacy conditions of external service providers and conducting necessary oversight

If a personal information breach or other incident occurs and notice is required by law, the Operator will notify affected users of the incident, the information affected, response measures, and contact methods in the manner and within the time prescribed by applicable law.

Article 12 (Department Responsible for Privacy and Grievance Handling)

Please direct inquiries concerning privacy matters, the exercise of rights, complaints, or remedies to the following department:

ItemDetails
DepartmentSGTHL Customer Support
Emailsgthl20@gmail.com
Telephone0502-1918-0106 (Telephone consultations are not offered; email requests are preferred.)
AddressRoom 101, 1, Nongol-ro 63beon-gil, Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea

Article 13 (Remedies for Infringement of Rights)

Data subjects may contact the following organizations for counseling or dispute resolution regarding a personal information infringement:

  1. Personal Information Infringement Report Center: 118 (no area code)
  2. Personal Information Dispute Mediation Committee: 1833-6972
  3. Supreme Prosecutors' Office: 1301 (no area code)
  4. Korean National Police Agency: 182 (no area code)

Article 14 (Privacy Policies of Third-Party Services)

For more information about personal information processing by external services used in the App, please see the following documents:

  1. Google Privacy Policy
  2. Firebase Privacy and Security
  3. Apple Privacy Policy
  4. Google Play Privacy Policy

Article 15 (Changes to this Privacy Policy)

① The Operator may revise this Policy due to changes in applicable law, App features, or external services.

② As a rule, the Operator will announce changes and their effective date through the App or a public webpage at least 7 days before the effective date. As a rule, an adverse change that materially affects user rights will be announced at least 30 days in advance, and consent will be obtained where separate consent is required.

③ Previous versions are maintained so that they can be made available upon a user's request.

Business Information

  1. Company name: SGTHL (에스지티에이치엘)
  2. Representatives: Lee Sang Gul and Yoo Taehoon
  3. Business registration number: 293-01-01743
  4. Mail-order business registration: No. 2026-Seongnam Sujeong-0522 (Seongnam City)

This Privacy Policy is effective as of August 16, 2026.