Privacy Policy
Effective 17 Aug 2026 · Last updated 19 Sep 2026
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1. Who runs this service
K-affeine: Who Ordered This? ("the Service") is operated by Culturepresso of the KF Digital Public Diplomacy Academy ("we"). This policy explains what personal data the Service collects, why, and how you can control it. Contact: culturepresso00@gmail.com
2. What we collect
(a) Provided at sign-up (required): nickname (a made-up name, not your legal name) and birth year.
(a-2) Provided at sign-up (optional — you may skip any of these with no effect on signing up or using the app): country, the pre-play survey answer, and how you found us.
(b) Created while you play: gameplay records (day cleared, stars, tips, unlocked culture cards), in-app event logs, post-play survey answers, feedback you send us.
(c) Generated automatically: a randomly generated device identifier (UUID), an anonymous session identifier, app version, and your display-language setting.
(d) Only if you choose to link an account yourself, from the start screen or from Settings (optional): your email address and the sign-in provider identifier (Google or Apple). We never receive your password.
(e) If you open a share link (/i/…): your browser type (User-Agent) and referrer are recorded so we can count clicks. No name, account or device identifier is stored with that record.
(f) When you use the web version: the web-hosting processor's servers keep access logs (IP address, browser type, referrer).
We do not collect your name, phone number, precise location, address book, photos or advertising identifiers. The only information we request from the sign-in provider is your email address; we do not request your name or profile picture.
We do not collect or process sensitive data under Article 23 of the Personal Information Protection Act (beliefs, trade-union or political-party membership, political opinions, health, sex life, genetic data, criminal records) or unique identifiers under Article 24. There is therefore nothing to disclose about whether sensitive data may become public or how to opt out of that.
2-2. Information collected automatically, and how to refuse it
The Service uses the following automatic collection mechanisms to save your progress and identify your device. We do not use cookies or advertising identifiers for targeted advertising, and we have not installed any advertising SDK that collects behavioural data.
(a) Device storage (app: on-device storage / web: your browser's localStorage)
· Stored: a randomly generated device identifier (UUID), your profile, game progress, consent record, display language, events waiting to be uploaded, remote-config cache, dismissed notices, and your sign-in session token
· Purpose: to keep your progress without requiring an account, and to keep you signed in and in your chosen language
· How to refuse: in the app, Settings → Delete account, or uninstall the app. On the web, clear or block this site's stored data (site data / local storage) in your browser settings
· Effect: your progress will not be saved, so you will start over on every visit, and you will not stay signed in
(b) In-app event logs
· Stored: event name, timestamp, local date, device identifier, session identifier, app version and config version (e.g. sign-up completed, day cleared, culture card unlocked)
· Purpose: to aggregate the project's outcome metrics
· How to refuse: Settings → Delete account (this also discards events still waiting to upload)
(c) Web access logs and share-link click records
· Stored: IP address, browser type (User-Agent), referrer
· Purpose: to host the website and investigate outages, and to count how often a share link was opened (share-link click records are not stored together with a name, account or device identifier)
· How to refuse: web access logs cannot be separated from visiting the site. If you would rather not have them collected, use the app instead of the web version. No click record is created unless a share link (/i/…) is opened.
3. Why we use it
To run the game and keep your progress; to measure the public-diplomacy outcome of the project by comparing your pre-play and post-play survey answers; to aggregate participation statistics (country counts, retention, culture-card unlock rate) for the project report; to run the weekly country leaderboard; to see in aggregate which channel brought participants to the project (the only purpose of the optional "how you found us" question); to keep your progress across devices and let you recover your account when you choose to link a social account (optional); and to respond to your feedback. We do not show you targeted advertising and we do not build individual profiles, and we do not make automated decisions that produce legal effects on you.
4. How long we keep it
· Sign-up data (nickname, country, birth year) and progress: until you delete your account or 3 months after the Service closes, whichever comes first — basis: your consent
· Pre- and post-play survey answers and event logs: as above — basis: your consent
· Email address and provider identifier from account linking: until you unlink or delete your account
· If you ask us to delete your data earlier, we delete it without undue delay and in any case within 30 days of your request.
· We hold no transaction or communication records that other statutes would require us to retain (the Service has no payment, ordering or messaging features).
· Anonymous statistics that can no longer be linked to you may be kept for the project report.
· The bulk deletion date is in section 4-2.
4-2. How we delete personal data
When the retention period ends or the purpose has been achieved and the data is no longer needed, we delete it without undue delay.
· Procedure: data due for deletion is deleted after review by the privacy officer named in section 9-2.
· Method: data held electronically is deleted from our database (Supabase) by removing the records, so that they cannot be restored or reconstructed. The copy on your device is deleted by clearing all K-affeine data from local storage (profile, progress, device identifier, consent record, event queue, pending uploads, settings cache). The Service keeps no paper records.
· Bulk deletion: the Service remains available after the KF Digital Public Diplomacy Academy programme period (17 Aug 2026 - 20 Sep 2026) ends. If we do close the Service, we delete all data within 3 months of the closing date, and we announce the closing date in the app at least 30 days in advance.
· Deletion on your request: tapping Settings → Delete account immediately deletes your profile, progress, event logs, post-play survey answers, culture cards, scores, feedback and sign-in account from our servers, with no grace period. If you ask by email instead, we delete within 30 days of your request.
· Backups: encrypted daily backup copies are deleted automatically within 30 days of being created.
· What is not deleted: the statistics used in the project report. Those figures are produced before the underlying records are deleted, exclude device identifiers, nicknames and email addresses, and consist only of totals, averages and percentages by country, date and survey score. They cannot be traced back to an individual.
5. Providing data to third parties (none) and 5-2. Processors
5. Providing data to third parties (none)
We do not sell your data and we do not provide it to any third party. There is no third-party provision under Article 17 of the Personal Information Protection Act. The processing entrusted under 5-2 below is a processing arrangement under Article 26 and is distinct from third-party provision.
5-2. Processors (Processor | Task | Data handled | Country of processing | Retention)
· Supabase Inc. | Database and authentication hosting | Everything listed in section 2 | Singapore | Until the processing agreement ends
· Functional Software, Inc. (Sentry) | Crash and performance diagnostics (mobile only) | Error stacks, device model, OS version, app version | United States | Until the processing agreement ends
· Vercel Inc. | Web hosting and share-link handling | Access logs (IP, browser type, referrer) | United States | Until the processing agreement ends
· Expo (650 Industries, Inc.) | App update delivery | App version, platform, update identifier | United States | Until the processing agreement ends
· GitHub, Inc. | Storage of encrypted daily backups (GPG AES256) | Everything listed in section 2 plus email addresses | United States | Up to 30 days from creation (deleted automatically)
Each processor handles the data only on our instructions and under a data processing agreement. See section 5-3 for the statutory disclosures on transfers outside Korea.
5-3. Transfer of personal data outside Korea
To perform our agreement with you and to make the Service work, we transfer personal data outside the Republic of Korea as set out below. We publish these details in this policy under Article 28-8(1)3 of the Personal Information Protection Act, which is why no separate consent is requested.
(a) Supabase Inc.
· Destination country: Singapore (region ap-southeast-1)
· When and how: over an HTTPS (TLS) connection, when you sign up and while you use the Service
· Data transferred: everything listed in section 2 (nickname, country, birth year, pre- and post-play survey answers, how you found us, gameplay records, event logs, feedback, device identifier (UUID), session identifier, app version, display language, and — if you link an account — your email address and sign-in provider identifier)
· Purpose: database and authentication hosting
· Retention: until the processing agreement ends or the deletion date in section 4-2, whichever comes first
· Contact: Supabase Inc. — https://supabase.com/privacy
(b) Functional Software, Inc. (Sentry)
· Destination country: United States
· When and how: over an HTTPS (TLS) connection, when the mobile app launches and at the moment an error occurs
· Data transferred: error stack, device model, OS version, app version (the SDK is configured not to send identifying data such as your nickname, country or email, and it is not used at all in the web version)
· Purpose: crash and performance diagnostics
· Retention: until the processing agreement ends
· Contact: Functional Software, Inc. — https://sentry.io/privacy/
(c) Vercel Inc.
· Destination country: United States
· When and how: over an HTTPS (TLS) connection, when you open the web version or a share link
· Data transferred: access logs (IP address, browser type (User-Agent), referrer)
· Purpose: web hosting and share-link handling
· Retention: until the processing agreement ends
· Contact: Vercel Inc. — https://vercel.com/legal/privacy-policy
(d) Expo (650 Industries, Inc.)
· Destination country: United States
· When and how: over an HTTPS (TLS) connection, when the app launches and checks for updates
· Data transferred: app version, platform, update identifier
· Purpose: app update delivery
· Retention: until the processing agreement ends
· Contact: 650 Industries, Inc. — https://expo.dev/privacy
(e) GitHub, Inc.
· Destination country: United States
· When and how: once a day we create a database backup, encrypt it (GPG AES256) and upload it over an HTTPS (TLS) connection
· Data transferred: everything listed in section 2, plus your email address if you have linked an account
· Purpose: keeping backups against failure or incident
· Retention: up to 30 days from the day the backup is created (deleted automatically)
· Contact: GitHub, Inc. — https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
How to refuse, and what happens if you do: you may refuse these transfers. Email culturepresso00@gmail.com to do so. Because the transfers are essential to providing the Service, we cannot run the Service without them: if you refuse, we delete your account and the records stored on our servers, and you will no longer be able to use the Service. Settings → Delete account has the same effect.
6. Your rights
You may ask us to access, correct, delete or export your data, and you may withdraw your consent at any time. Two ways to do this:
(a) In the app: Settings → Delete account. Your profile, progress, event logs, post-play survey answers, culture cards, scores, feedback and sign-in account are erased immediately and permanently, along with the copy on your device. This cannot be undone. Encrypted backup copies are deleted automatically within 30 days. Share-link click records for your share code (section 2-2(c)) are deleted together with your account.
(b) By email: culturepresso00@gmail.com. Before we act on a request, we verify your identity. If you linked a sign-in account, we send a one-time verification code to the email address on record for your account and act only after you return that code (a request's From: address alone is not accepted as proof). If you did not link an account (a guest), we hold no email or password for you and cannot verify you remotely, so you can erase your data immediately via Settings → Delete account, while access, correction and export are handled after you link an account and complete the verification above. We reply within 30 days. The nickname and country you registered with only help us locate your record; they are not proof of identity, because they may be public (for example on a shared card).
You may also exercise these rights through a legal guardian or an authorised representative, by submitting a letter of authority in the form prescribed by the Notice on Personal Information Processing Methods (Form 11); we also complete the identity verification above (the one-time code for a linked account) to confirm that the person making a request is the data subject or a duly authorised representative. For a guest account we cannot verify identity remotely, so delegated requests are limited and erasure is handled via Settings → Delete account.
Withdrawing consent does not affect processing carried out before the withdrawal.
7. Notice for users in the EU / EEA and the UK (GDPR)
If you are in the EU, the EEA, or the UK, the following applies.
Controller: Culturepresso (KF Digital Public Diplomacy Academy), culturepresso00@gmail.com.
Legal basis: the device identifier created when the app starts and error diagnostics are the minimum processing necessary to provide the Service (Art. 6(1)(f), legitimate interests); everything else relies on the consent you give at sign-up (Art. 6(1)(a)). We do not process special-category data.
Your rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent at any time (Art. 7(3)).
International transfer: personal data of EU, EEA and UK users is provided by you directly to the Service. Where we entrust it to processors outside those regions (Singapore and the United States), it is protected by the EU Standard Contractual Clauses and the UK Addendum incorporated into our data processing agreement with each processor.
Complaints: you may lodge a complaint with your national supervisory authority.
8. Children under 14
The Service is for users aged 14 and over, and we do not collect personal data from children under 14. We have no process for obtaining the consent of a legal guardian, which the Act requires before a child under 14 may sign up, so children under 14 cannot register.
At sign-up we ask for your birth year and, alongside it, ask you to tick a box confirming that you are 14 or older. Age is counted by actual age including your birthday, not by calendar year.
If we learn that we have collected data from a child under 14, we delete it without undue delay. If you believe a child under 14 has registered, please tell us at culturepresso00@gmail.com.
9. Security
Data is transmitted over TLS and stored with row-level security so that one participant cannot read another participant's record. Access to the operations dashboard is limited to project members and protected by a token.
· The database runs in the managed, secured environment provided by our processor (Supabase); we do not operate servers ourselves.
· We never collect or store your password. Account linking goes through Google or Apple sign-in and your password is never passed to us.
· Because the nickname is not your legal name, the records we hold about a user who has not linked an account cannot on their own identify that user. If you have linked an account, you can be identified by your email address.
9-2. Privacy officer and where to send requests
We have a privacy officer who is responsible for personal data processing and for handling complaints and remedies. We are a small business within the meaning of Article 32 of the Enforcement Decree, so we are not required to formally designate one; under Article 31(2) of the Act, the representative of the operating team is the privacy officer.
· Privacy officer: Sooyoung Choi (Representative, Culturepresso)
· Responsible team: Culturepresso, KF Digital Public Diplomacy Academy
· Contact: culturepresso00@gmail.com (We do not operate a phone line; email is our only official channel.)
· To request access, correction, deletion or suspension of processing: Settings → Delete account in the app, or the email address above
You may bring any privacy question, complaint or request for remedy to this contact, and we will reply within 30 days of receipt.
9-3. How to seek redress
If your privacy has been infringed, you can apply to the following Korean bodies for dispute resolution or advice. They are independent of us — contact them if you are not satisfied with how we handled your case or if you need more help.
· Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
· Privacy Infringement Report Centre (KISA): 118 / privacy.kisa.or.kr
· Supreme Prosecutors' Office: 1301 / www.spo.go.kr
· Korean National Police Agency: 182 / ecrm.cyber.go.kr
You may also contact them if you disagree with how we responded to a request made under Articles 35 (access), 36 (correction and deletion) or 37 (suspension of processing) of the Personal Information Protection Act.
10. Changes and contact
If we change this policy we will post the new version in the app before it takes effect.
Change history:
· v1.0 — effective 17 Aug 2026 (initial version)
· v1.1 — effective 22 Aug 2026 (pre-play survey made optional; bulk-deletion date restated)
Email culturepresso00@gmail.com if you need an earlier version.
Questions, requests, or complaints: culturepresso00@gmail.com.