개인정보처리방침
친절한 소피(Friendly Sophie, 이하 “개발자”)는 모바일 게임 K-디펜스(이하 “앱”)를 이용하는 분의 개인정보를 「개인정보 보호법」 등 관련 법령에 따라 처리합니다. 이 방침은 앱이 어떤 정보를, 왜, 얼마 동안 처리하며, 이용자가 어떻게 권리를 행사할 수 있는지 설명합니다.
어린이를 위한 쉬운 설명
- 이 게임은 이름, 전화번호, 사는 곳, 생일을 묻지 않아요.
- 게임 기록을 저장하려고 앱이 알아서 번호표(사용자 ID)를 하나 만들어요.
- 광고는 누구에게나 괜찮은(전체 이용가) 광고만 나오고, 나를 따라다니는 맞춤 광고는 나오지 않아요.
- 위치, 사진, 연락처, 카메라, 마이크는 쓰지 않아요.
- 기록을 모두 지우고 싶으면 설정 → 계정 삭제를 누르면 돼요.
- 무언가를 사기 전에는 꼭 부모님께 먼저 여쭤 보세요.
1. 처리하는 개인정보와 목적
| 구분 | 항목 | 목적 | 수집 방법 |
|---|---|---|---|
| 기본(필수) | Firebase 익명 사용자 ID | 이용자 구분, 게임 기록 저장·복원 | 앱을 처음 실행할 때 자동 생성 |
| 게임 이용(필수) | 게임 진행·저장 데이터(레벨, 스테이지 기록, 영웅·아이템 보유 현황, 단어 학습 기록, 게임 설정), 닉네임, 국가 코드, 랭킹 점수 | 클라우드 저장, 기기 변경 시 복원, 랭킹 표시 | 게임 이용 중 생성되거나 이용자가 입력 |
| 계정 연결(선택) | Google 또는 Apple 계정의 고유 식별자, 이메일 주소, 표시 이름 (Apple의 ‘나의 이메일 가리기’를 고르면 Apple이 발급한 중계 주소) |
계정 연결, 다른 기기에서 로그인·기록 복원 | 이용자가 연결할 때 Firebase Authentication을 통해 수집 |
| 유료 결제 시 | 결제 스토어(Google Play·원스토어), 상품 ID, 주문 번호, 결제 토큰의 해시값(원문은 저장하지 않음), 테스트 결제 여부, 처리 결과(지급·환불 등), 기록 시각, 사용자 ID, 앱 정보(앱 버전·빌드 번호, 운영체제 종류·버전, 언어 설정) | 결제 진위 확인, 중복 지급·영수증 재사용 방지, 구매 복원, 환불·분쟁 대응 | 결제 직후 서버가 해당 스토어에 조회 |
| 자동 생성 | 서버 이용 기록(요청 시각, 사용자 ID, 오류 정보) | 보안, 장애 대응, 부정 이용 방지 | 결제 확인 등 서버 기능을 이용할 때 |
| 자동 생성 | 앱 오류 기록(오류 내용과 발생 위치, 발생 시각, 앱 버전·빌드 번호, 기기 모델, 운영체제 버전, Firebase 설치 식별자, 사용자 ID) | 앱 비정상 종료·오류의 원인 파악과 수정 | 앱이 비정상 종료되거나 오류가 날 때 Firebase Crashlytics로 자동 전송(광고 식별자는 보내지 않음) |
| 문의 시 | 이메일 주소, 문의 내용(계정 삭제 요청 시 닉네임·사용자 ID) | 문의 응답, 본인 확인, 요청 처리 | 이용자가 이메일을 보낼 때 |
카드 번호 등 결제 수단 정보는 Google Play와 원스토어가 직접 처리하며 개발자는 받지 않습니다. 광고 과정에서 Google이 처리하는 정보는 3. 광고에 따로 적었습니다.
2. 처리하지 않는 정보
- 위치, 연락처, 사진·파일, 카메라, 마이크에 접근하지 않습니다.
- 실명, 생년월일, 전화번호, 주소를 묻지 않습니다.
- 하트 충전 알림은 기기 안에서 예약되는 로컬 알림입니다. 푸시 서버를 쓰지 않으며, 알림을 위해 서버로 보내는 정보는 없습니다.
- 단어 그림 자료는 Firebase Storage에서 내려받습니다. 이때 개인정보를 보내지 않습니다 (통신 과정에서 IP 주소는 Google 서버에 전달됩니다).
3. 광고
앱은 Google AdMob으로 보상형·전면 광고를 보여 주며, 모든 광고 요청을 다음과 같이 설정합니다.
- 아동 대상 처리(tagForChildDirectedTreatment)를 요청합니다.
- 비개인 맞춤 광고만 요청합니다. 관심사 기반 맞춤 광고나 리마케팅을 하지 않습니다.
- 광고 콘텐츠 등급을 G(전체 이용가)로 제한합니다.
다만 Google은 광고 제공, 노출 빈도 제한, 부정 클릭 방지, 집계 보고를 위해 기기 식별자와 IP 주소 등을 Google 정책에 따라 처리할 수 있습니다. 개발자는 이 정보를 받지 않습니다. 자세한 내용은 Google 파트너 사이트·앱의 데이터 사용 방식을 참고하세요.
4. 보유 기간
- 계정과 게임 데이터: 계정을 삭제할 때까지. 앱에서 삭제하면 바로, 이메일로 요청하면 7일 이내에 파기합니다.
- 결제 기록: 「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 5년 (대금 결제 및 재화 등의 공급에 관한 기록, 계약 또는 청약철회에 관한 기록). 계정을 삭제해도 이 기간 동안은 보관합니다.
- 문의·분쟁 처리 기록: 같은 법률에 따라 3년.
- 서버 이용 기록: 30일 후 자동 삭제.
- 앱 오류 기록: 90일 후 자동 삭제(Firebase Crashlytics 보관 주기).
다른 법령이 더 긴 보관을 요구하면 그 기간 동안 해당 목적으로만 보관합니다.
5. 제3자 제공
개발자는 이용자의 개인정보를 제3자에게 제공하지 않습니다. 다만 법령에 따라 수사기관 등이 적법한 절차로 요구하는 경우는 예외입니다.
6. 처리 위탁과 국외 이전
앱 운영을 위해 다음 업체의 서비스를 이용하며, 이 과정에서 개인정보가 국외로 전송·보관될 수 있습니다.
| 받는 자 | 국가 | 항목 | 목적 | 시기·방법 | 보유 기간 |
|---|---|---|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Logging, Firebase Crashlytics) |
미국 등 Google 데이터센터 소재국 | 사용자 ID, 연결 계정 정보, 게임 데이터, 결제 기록, 서버 이용 기록, 앱 오류 기록 | 인증, 데이터 저장, 결제 확인 서버 운영, 앱 오류 분석 | 앱 이용 중 네트워크로 수시 전송 | 4항의 기간 |
| Google LLC (AdMob) |
미국 등 | 기기 식별자, IP 주소, 광고 노출·클릭 정보 | 광고 제공과 측정 | 광고를 불러올 때 전송 | Google 정책에 따름 |
| Google LLC (Google Play 결제) |
미국 등 | 결제 토큰, 상품 ID | 결제 진위 확인 | 결제 직후 서버가 조회 | Google 정책에 따름 |
| 원스토어 주식회사 | 대한민국 | 결제 토큰, 상품 ID | 결제 진위 확인 | 결제 직후 서버가 조회 | 원스토어 정책에 따름 |
국외 이전을 원하지 않으면 앱 이용을 멈추고 계정을 삭제할 수 있습니다. 이 경우 게임 기록 저장 등 서비스를 이용할 수 없습니다. 각 업체의 방침: Google 개인정보처리방침, Firebase 개인정보 보호, 원스토어.
7. 파기 절차와 방법
보유 기간이 끝나거나 처리 목적을 이룬 정보는 지체 없이 파기합니다. 전자 파일은 복구할 수 없는 방법으로 삭제하며, 클라우드 서비스의 백업에 남은 사본은 해당 서비스의 보관 주기에 따라 순차적으로 삭제됩니다. 법령에 따라 보관하는 결제 기록은 다른 정보와 분리해 보관하고, 기간이 끝나면 파기합니다.
8. 이용자와 법정대리인의 권리
이용자(만 14세 미만 아동은 법정대리인)는 언제든지 개인정보의 열람, 정정, 삭제, 처리 정지를 요구할 수 있습니다.
- 삭제: 앱의 설정 → 계정 삭제, 또는 계정 삭제 안내에 따라 이메일로 요청
- 열람·정정·처리 정지: service@friendlysr.com로 요청
요청을 받으면 본인(또는 법정대리인) 여부를 확인한 뒤 10일 이내에 조치하고 결과를 알려 드립니다. 법령에 따라 보관해야 하는 정보는 삭제 요청이 있어도 그 기간 동안 보관할 수 있으며, 이 경우 그 사유를 알려 드립니다.
9. 만 14세 미만 아동
앱은 만 14세 미만을 포함한 학생을 위해 만들었습니다. 그래서 이름·생년월일·연락처 같은 정보를 묻지 않고, 게임 이용에 꼭 필요한 정보만 처리합니다.
- 「개인정보 보호법」에 따라 만 14세 미만 아동의 개인정보 처리에 동의가 필요한 경우에는 법정대리인(부모 등)의 동의를 받아야 합니다. Google·Apple 계정 연결(선택)은 보호자와 함께 해 주세요.
- 법정대리인은 아동의 개인정보에 대해 열람, 정정, 삭제, 처리 정지를 요구할 수 있으며, 동의를 철회할 수 있습니다. service@friendlysr.com로 연락하시면 법정대리인임을 확인한 뒤 처리합니다.
- 광고는 아동 대상으로 처리되며 비개인 맞춤·전체 이용가 광고만 요청합니다(3항).
- 미성년자의 유료 결제와 취소는 이용약관을 참고하세요.
10. 자동 수집 장치
앱과 이 웹사이트는 쿠키를 쓰지 않습니다. 행태정보에 기반한 맞춤형 광고도 하지 않습니다. AdMob이 기기의 광고 식별자를 처리하는 것을 원하지 않으면 기기 설정에서 광고 ID를 삭제하거나 재설정할 수 있습니다(Android: 설정 → Google → 광고 / iOS: 설정 → 개인정보 보호 및 보안 → 추적).
11. 안전성 확보 조치
- 앱과 서버 사이의 모든 통신은 암호화(HTTPS/TLS)됩니다.
- 데이터베이스 보안 규칙으로 본인의 게임 데이터만 읽고 쓸 수 있게 합니다.
- 결제 기록은 서버만 쓸 수 있고, 결제 토큰은 원문 대신 해시값만 저장합니다.
- 스토어 연동 비밀 키는 코드가 아닌 비밀 관리 서비스(Secret Manager)에 보관합니다.
- 개인정보에 접근할 수 있는 관리 권한을 최소한으로 제한합니다.
12. 개인정보 보호책임자
개인정보 처리에 관한 문의, 불만, 피해 구제는 아래로 연락해 주세요.
개인정보 보호책임자: 친절한 소피 (Friendly Sophie)
이메일: service@friendlysr.com
13. 권익 침해 구제 방법
개인정보 침해에 대한 상담이나 분쟁 해결이 필요하면 다음 기관에 문의할 수 있습니다.
- 개인정보분쟁조정위원회: (국번 없이) 1833-6972, www.kopico.go.kr
- 개인정보침해신고센터: (국번 없이) 118, privacy.kisa.or.kr
- 대검찰청: (국번 없이) 1301, www.spo.go.kr
- 경찰청: (국번 없이) 182, ecrm.police.go.kr
14. 방침의 변경
이 방침을 바꾸면 시행 7일 전(이용자에게 불리하거나 중요한 변경은 30일 전)부터 앱 또는 이 웹사이트에 알립니다.
이 방침은 2026년 10월 10일부터 시행합니다. 이전 방침은 2026년 9월 30일부터 시행했습니다.
Privacy Policy
Friendly Sophie (친절한 소피, “we”) operates the mobile game K-Defense (the “App”). This policy explains what information the App processes, why, for how long, and how you can exercise your rights. If the Korean and English versions differ, the Korean version prevails.
1. Information we process
- Anonymous user ID (Firebase) — created automatically on first launch to identify your game data.
- Game data — progress and save data (level, stage records, heroes and items, word-learning history, settings), nickname, country code and ranking scores, stored in Cloud Firestore for cloud save, restore and rankings.
- Linked account (optional) — if you link Google or Apple sign-in, the account identifier, email address and display name via Firebase Authentication (or Apple’s private relay address if you choose “Hide My Email”).
- Purchase records — store (Google Play / ONE store), product ID, order ID, a SHA-256 hash of the purchase token (never the token itself), test-purchase flag, outcome (granted, refunded, etc.), timestamp, user ID and app details (app version and build, operating system and version, language setting), used to verify payments, prevent duplicate grants and receipt reuse, restore purchases, handle refunds and troubleshoot.
- App error reports — when the App crashes or hits an error, Firebase Crashlytics automatically sends the error details and location, time, app version and build, device model, OS version, a Firebase installation ID and your user ID, so we can find and fix the cause. No advertising ID is sent.
- Server logs — request time, user ID and error details when you use server features such as purchase verification, for security and troubleshooting.
- Support emails — your email address and message (and nickname / user ID for deletion requests).
Payment card details are handled by Google Play and ONE store; we never receive them.
2. What we do not collect
The App does not access location, contacts, photos/files, camera or microphone, and does not ask for your real name, date of birth, phone number or address. Heart-recharge reminders are local notifications scheduled on your device; there is no push server. Word-picture packs are downloaded from Firebase Storage without sending personal information (your IP address is visible to Google’s servers as part of the connection).
3. Advertising
The App shows rewarded and interstitial ads through Google AdMob. Every ad request is tagged for child-directed treatment (tagForChildDirectedTreatment), requests non-personalized ads only, and limits ad content to rating G. No interest-based advertising or remarketing is used. Google may still process device identifiers and IP addresses for ad delivery, frequency capping, fraud prevention and reporting under Google’s policies. We do not receive this data.
4. Retention
- Account and game data: until you delete your account (immediately in the App, or within 7 days of an email request).
- Purchase records: 5 years, as required by the Korean Act on Consumer Protection in Electronic Commerce, even after account deletion.
- Complaint and dispute records: 3 years under the same Act.
- Server logs: deleted automatically after 30 days.
- App error reports: deleted automatically after 90 days (Firebase Crashlytics retention).
5. Sharing and processors
We do not sell or provide your personal information to third parties, except where required by law. We use the following service providers, which may store data outside Korea:
- Google LLC (USA) — Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Logging and Firebase Crashlytics (authentication, storage, purchase-verification server, error reports); AdMob (advertising); Google Play (payment verification).
- ONE store Co., Ltd. (Korea) — payment verification.
If you do not want this transfer, you can stop using the App and delete your account.
6. Your rights
You (or the legal guardian of a child under 14) may request access to, correction, deletion or suspension of processing of your personal information. Delete your account in the App under Settings → Delete account, or follow the account deletion guide. For other requests, email service@friendlysr.com. We will verify the requester and respond within 10 days.
7. Children
The App is designed for students, including children under 14. We process only what is needed to run the game and do not ask for names, birthdays or contact details. Under the Korean Personal Information Protection Act, where consent is required to process the personal information of a child under 14, it must come from a legal guardian; please link a Google or Apple account together with a parent. Guardians may request access, correction or deletion of their child’s data, or withdraw consent, by contacting us. For purchases by minors, see the Terms of Service.
8. Security
All traffic is encrypted (HTTPS/TLS). Database security rules restrict each player to their own game data. Purchase records are written only by the server, and purchase tokens are stored only as hashes. Store API secrets are kept in Secret Manager, not in code.
9. Contact
Privacy officer: Friendly Sophie (친절한 소피)
Email: service@friendlysr.com
10. Changes
We will announce changes in the App or on this website at least 7 days before they take effect (30 days for material changes). This policy is effective from October 10, 2026; the previous version was effective from September 30, 2026.