Privacy Policy
Itemtify Privacy Policy
This is an unofficial English translation provided for convenience. In the event of any discrepancy between this translation and the Korean original, the Korean version prevails.
Effective Date: August 6, 2026
Cubed (representative: Ruan) (the "Operator"), in providing the mobile application "Itemtify" (the "Service"), complies with the Personal Information Protection Act and other applicable laws, and establishes and discloses the following Privacy Policy to process users' personal information safely.
1. Items of Personal Information Collected and Methods of Collection
Upon Membership Registration
| Registration Method | Items Collected |
|---|---|
| Google account linking | Google account email address, Google account identifier |
| Apple account linking | Apple account identifier, email address (if the user selects Apple's "Hide My Email," the relay address provided by Apple) |
- The Service does not create or store a separate password. Authentication is performed through the login procedures of Google and Apple.
- A Nickname is automatically generated and stored upon registration.
In the Course of Using the Service
- Photographs: The original photographs taken by the user with the in-app camera and the background-removed images
- Room background photo: A photograph the user selects from the device photo library to use as a Room background. It is stored in the form the user adjusted for the background, and nothing other than the selected photograph is stored.
- Photo identifier: A hash value (SHA-256) of the original photograph — used to verify the authenticity of the Item
- Service usage records: Item and Room information, Gold grant and deduction history, auction and bid history, Item holding transfer history, appraisal results, and attendance, mission achievement, and reward receipt records
- Content created by the user: Comments and memos left on Items, profile images drawn by the user, and the content of inquiries and feedback the user sends (including star ratings)
- Report and block records: The reported target and time, and the list of blocked users (for responding to inappropriate content and protecting users)
- Room sharing information: Shared Room connection relationships and Participant information
- Automatically collected information: Service access records (access date and time, access date, error logs, etc.), app language settings, device information (operating system category and device model name), and the app version in use
- Whether device notifications are allowed: Whether notifications for this app are enabled on the device, and the time this was checked. This is used so that notifications are not repeatedly sent to members they cannot reach; the contents of notifications and other device settings are not collected. It is updated each time the app is launched and is a different value from the in-app "Notification settings" the member chooses.
In the Course of Collecting App Usage Statistics
- Usage statistics information: Information collected by Google Analytics (Firebase) to improve the Service and measure advertising performance — a per-installation identifier (app instance ID), usage events such as first launch and subsequent launches, device information (model, operating system version, screen size, language), and the country and region estimated from the access IP address
- This information is processed for statistical purposes, not to identify individual users. The app instance ID disappears when the app is deleted.
- On iOS, install performance is aggregated in a form that cannot identify individuals, through the advertising performance measurement method provided by Apple (SKAdNetwork).
- Install source information (Android): A value indicating the route through which the app was downloaded, delivered by Google Play at the time of installation (the attribution marker contained in an advertisement or link). It is recorded once on the member account and is not changed thereafter. It is not collected on iOS.
When Using the Friend Referral Feature
- Referral code: A six-character value automatically generated for each account upon registration. It is used when a Member recommends the Service to another person, and it does not change.
- Referral relationship: Where a Member enters another Member's referral code, the identifier of the inviting Member and the time of entry are recorded. A referrer may be designated only once, within the period set by the Service after registration, and cannot be changed thereafter.
- Referral reward grant history: The recipient, amount, and grant time of Gold paid out through referrals
- Installation identifier: A random value the app stores on the device. It identifies neither an individual nor the device itself. It is recorded only at the moment a referrer is registered, in order to prevent the repeated acquisition of referral rewards by switching accounts on a single device, and it disappears if the app is deleted or its app data is cleared. It is destroyed upon withdrawal.
- This information serves as the basis for reward payment and as a means of preventing duplicate or fraudulent payment, and is processed together with Gold grant records.
When Using Push Notifications
- Device registration token: A per-device token issued by Firebase Cloud Messaging and device category information to deliver notifications to that device. If you do not wish to receive notifications, you may block them in the in-Service settings or device settings, and they are destroyed upon withdrawal.
In the Course of Displaying Advertisements
- The advertising service (Google AdMob) may collect an advertising identifier (ADID/IDFA) and device information to serve advertisements. See Section 6 below for details.
When Paying for Paid Products
- Payment records: The identifier of the purchased product, the transaction identifier issued by the store (purchase token, order number, etc.), and the payment and grant times. Used to process payment and confirm product grant, prevent duplicate grants, and retain records under applicable laws.
- Actual payment (payment-method information such as card numbers) is processed by Apple and Google, and the Service does not store it.
※ The Service does not access location information or contacts. Camera permission is used only when taking photographs to create Items. The photo library is used only when the user chooses a Room background photo, solely to receive the single photograph selected at that moment; the Service does not view other photographs or collect any listing of the library. The "country and region" in the usage statistics above is an approximate value estimated from the access IP address; the device's location permission is not used.
2. Purposes of Processing Personal Information
| Purpose | Items Used |
|---|---|
| Member identification, registration and login processing | Google and Apple account information |
| Item creation, storage, and display | Photographs, background-removed images, hash values |
| Room background display (Room decoration) | Room background photo |
| Item appraisal (assigning grade and name) | Photographs (including originals) |
| Providing features such as Gold and auctions | Nickname, profile image, Gold, auction, and transfer records |
| Providing interaction among Members such as Room sharing and comments | Nickname, profile image, Shared Room information, comments |
| Paying attendance and mission rewards | Attendance and achievement records, Gold history |
| Sending push notifications | Device registration token, notification receipt settings, language settings |
| Identifying members who cannot be reached and guiding them to enable notifications | Whether device notifications are allowed, the time and number of times the guidance was shown, and the member's choice |
| Serving advertisements and paying rewards | Advertising identifier, device information |
| Paying for and granting paid products, preventing duplicate grants | Purchased product identifier, transaction identifier, payment time |
| Ensuring Service stability and preventing fraudulent use | Access records, usage records, device information |
| Service improvement, usage statistics, multilingual support | Access date, language settings, device information |
| Measuring advertising performance (confirming the app install source) | App instance ID, first-launch record, device information, advertising identifier, install source information |
| Paying friend referral rewards, preventing duplicate or fraudulent payment | Referral code, referral relationship, referral reward grant history, Nickname, installation identifier |
| Receiving and responding to inquiries and feedback | Inquiry and feedback content, star rating, Nickname |
3. Retention and Use Period of Personal Information
- A Member's personal information is destroyed without delay upon withdrawal of membership. However, the following are exceptions.
- Where retention is required under applicable laws, the information is stored separately for the relevant period.
- Service access records under the Protection of Communications Secrets Act: 3 months
- Records of contracts, payments, and supply of goods under the Act on the Consumer Protection in Electronic Commerce: 5 years (payment and supply of goods); Records of consumer complaints or dispute handling: 3 years
- Records necessary to maintain transaction integrity, such as Gold grants and deductions, Item holding transfers, and friend referral relationships and reward grant history, are processed so that individuals cannot be identified upon withdrawal and then preserved. This is to ensure that the transfer history of Items held by other users is not broken.
- To prevent fraudulent use, use-restriction records may be retained for 1 year after withdrawal.
4. Provision of Personal Information to Third Parties
The Operator does not provide users' personal information to third parties. However, the following are exceptions.
- Where the user has consented in advance
- Where required by the provisions of law or by an investigative agency in accordance with the procedures prescribed by law
※ Due to Service features, the following information is displayed to other users.
| Feature | Information Displayed to Other Users |
|---|---|
| Auction | Nickname, profile image, registered Item (photo, name, grade, memo), view count |
| Comments | Nickname, profile image, comment content |
| Room sharing | Nickname, profile image, Items placed in the Shared Room (photo, name, grade, memo), Room background photo |
| Room publishing (Explore) | Nickname, profile image, the published Room's name, one-line introduction, greeting, background photo and any text written in the Room, and the photo, name, grade, value and memo of the Items placed in it |
| Item holding history | Nickname of the previous holder |
| Ranking | Nickname, size of holdings, ranking |
| Friend referral | The Nickname and participation time of the invited Member, shown to the inviting Member / the Nickname of the inviting Member, shown to the person who received the referral link or code (including on the web page seen before the app is installed) |
※ For features that only begin when the user turns them on — such as Room publishing — the screen used to turn the feature on explains what will be shown and to whom, and the user makes the choice. In such cases the items collected by the Operator do not increase; only the scope the user has chosen to make public changes. Publishing can be turned off at any time, but what other users have already seen while it was public cannot be undone.
5. Entrustment of Personal Information Processing
The Operator entrusts the processing of personal information as follows to provide the Service.
| Trustee | Entrusted Work | Storage Location |
|---|---|---|
| Supabase, Inc. | Member authentication, infrastructure operation such as database and file storage | Republic of Korea (Seoul) region (AWS) |
6. Overseas Transfer of Personal Information
In the course of providing Service features, information is transmitted to and processed by overseas providers as follows.
| Transferee | Country | Items Transferred | Purpose of Transfer | Retention Period |
|---|---|---|---|---|
| Replicate, Inc. | United States | Photographs | Photo background removal | Destroyed after processing |
| Google LLC (Gemini API) | United States | Photographs (including originals) | AI appraisal of Items | Destroyed after processing |
| Google LLC (Firebase Cloud Messaging) | United States | Device registration token, notification content | Sending push notifications | Until token revocation or withdrawal |
| Google LLC (AdMob) | United States | Advertising identifier, device information | Serving ads and measuring performance | Per Google policy |
| Google LLC (login) | United States | Google account authentication information | Social login | Per Google policy |
| Apple Inc. | United States | Apple account authentication information | Social login | Per Apple policy |
| Apple Inc. (App Store) | United States | Purchased product identifier, transaction identifier | In-app payment processing and receipt verification | Per Apple policy |
| Google LLC (Google Play) | United States | Purchased product identifier, transaction identifier | In-app payment processing and receipt verification | Per Google policy |
| Google LLC (Google Analytics) | United States | App instance ID, usage events, device information, access country and region | Usage statistics analysis and advertising performance measurement | Per Google policy |
| Apple Inc. (SKAdNetwork) | United States | Aggregated advertising performance values (containing no personally identifying information) | Anonymous aggregation of iOS app install performance | Per Apple policy |
- Transmission is carried out over encrypted communication (TLS) at the time of Service use (Item creation and appraisal, notification receipt, advertisement viewing, social login).
- If you do not wish to have information transferred, you may refuse by not using the relevant feature (e.g., blocking notifications) or by withdrawing membership. However, if you refuse transfers related to essential Service features such as login or Item creation, Service use may be restricted.
- Details on Google's processing of personal information: https://policies.google.com/privacy
- Details on Apple's processing of personal information: https://www.apple.com/legal/privacy/
- Details on Replicate's processing of personal information: https://replicate.com/privacy
7. Procedures and Methods for Destroying Personal Information
- Personal information for which a reason for destruction has arisen is destroyed without delay.
- Information in electronic file form is deleted by a method that cannot be recovered, and other records are shredded or incinerated.
- Upon withdrawal, original photographs, image files of held Items, Room background photos, device registration tokens, and access records are deleted, and profile information such as Nicknames is replaced with unidentifiable values.
8. Users' Rights and How to Exercise Them
- A user may at any time request access, correction, deletion, or suspension of processing of their personal information.
- Rights may be exercised through in-Service features (re-drawing a Nickname, notification receipt settings, Item deletion, membership withdrawal, etc.) or through the contact in Section 10 below, and the Operator takes measures without delay.
- Personal information of children under 14 years of age is not collected. If it is confirmed that a person under 14 has registered, the relevant account and information are deleted without delay.
9. Measures to Ensure the Security of Personal Information
- End-to-end encrypted communication (TLS). The Service does not store passwords and delegates authentication to external providers (Google and Apple).
- Database access control: separation of access rights per user (row-level security, RLS), and separate storage of server-only keys
- Design to prevent forgery or alteration of Gold and Item transfer records (append-only ledger)
- Minimization of access rights to personal information
10. Personal Information Protection Officer
| Category | Details |
|---|---|
| Personal Information Protection Officer | Ruan |
| Contact | ruan@cubed.im |
Inquiries, complaints, and requests for relief regarding personal information may be received at the above contact. For other reports and consultations, you may contact the following organizations.
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (no area code)
- Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
11. Changes to the Privacy Policy
If the contents of this Policy are added, deleted, or modified, the Operator will announce the changes and their effective date through in-Service announcements or a notice shown when the app is launched.
Addendum
This Policy takes effect on August 6, 2026.