Pseudonymous ID, device information (OS, app version, model), access logs, error logs, ad identifiers (ADID/IDFA), cookies and similar technologies
Service improvement, analytics, and security management
Future Features (Planned)
Photos, external links, community posts, AI recommendation data
For providing new features
Information Not Collected:
Passwords: Only social logins are supported; no password storage.
Payment details: In-app purchases are processed via App Store or Play Store; no financial data (e.g., card numbers) are stored by Pebbling.
Article 3 (Retention and Destruction of Personal Information)
General Rule: Data are deleted immediately upon account deletion. Backup data are securely removed within a regular system cycle.
Retention by Law:
Contract, withdrawal, and payment records — 5 years
Consumer complaints or dispute records — 3 years
Advertising and display records — 6 months
Tax-related transaction records — 5 years
Fraud Prevention: Data may be retained for up to 1 year to prevent illegal registrations or misuse.
Destruction Method: Electronic files are permanently deleted beyond recovery; paper documents are shredded or incinerated.
Article 4 (Provision of Personal Information to Third Parties)
Pebbling does not share personal data with third parties unless:
Required by law, or
The user has provided explicit consent for a specific purpose.
Article 5 (Entrusted Processing and Overseas Transfers)
Processor
Country
Purpose of Processing
Data
Retention Period
Supabase
Korea (Seoul), U.S.
Database hosting
All collected data in Article 2
Until account deletion or contract termination
Google Firebase
U.S. and others
Error monitoring & analytics
Logs, device info, ad ID
According to Google policy
Apple App Store / Google Play
Various
In-app purchase processing
Payment metadata
According to store policy
Meta SDK
U.S. and others
Marketing performance measurement
Advertising ID
According to Meta policy
Article 6 (Reasonably Related Use Beyond Original Purpose)
Pebbling may use or provide personal data for purposes reasonably related to the original intent of collection, considering factors such as user expectations, relationship relevance, and data security.
Article 7 (User and Legal Guardian Rights)
Users may request access, correction, deletion, suspension of processing, or withdrawal of consent at any time.
Requests can be made via the in-app inquiry form, by email ([email protected]), or in writing.
For minors, legal guardians may exercise the same rights on behalf of the user with proper authorization.
Some data may be retained if required by law (e.g., tax records).
California Residents (CCPA/CPRA): Have rights to access, correct, delete, and opt-out of data sharing.
International Users (e.g., GDPR): Have the right to file complaints with their national data protection authorities. In Korea, users may contact the Personal Information Protection Commission (www.pipc.go.kr, ☎118).
Article 8 (Breach Notification)
If any data breach or leakage occurs, Pebbling will promptly notify affected users and relevant authorities as required by law, including details on the breached items, time of occurrence, response measures, and mitigation steps.
Article 9 (Data Security Measures)
Administrative: Internal management plan, staff training
Technical: Data encryption in storage and transmission, access control minimization, security software installation
Physical: Restricted access to servers, controlled data storage areas
Thank you for entrusting your precious personal reflections to Pebbling. Your privacy and trust are our top priorities.
We use your information only to provide a better service experience. We never use personal information for advertising or third-party sale purposes.
All records are encrypted and stored securely. The records you create are stored in encrypted form, and even Pebbling's operations team cannot directly view the original content.
Individuals cannot be identified during data analysis. We manage data through pseudonymization and anonymization so that individuals cannot be identified.
We disclose everything transparently. This Policy clearly explains what information we collect, how we use it, and with whom we share it.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes.
Membership registration and account management
Service provision and operation, such as storing and viewing records
Handling complaints and responding to customer inquiries
Complying with legal obligations, such as tax and consumer protection laws
Improving service quality and user experience
Marketing and advertising, only when the user has separately consented; refusal of consent does not restrict use of the basic service
Minimum processing necessary to protect life, body, or property in emergency situations
Article 2 (Personal Information Processed)
Category
Collected Items
Purpose of Use
Membership Registration
[Provided by Apple/Google] Name (or nickname), email
Account creation and management
Service Use
Preferred reference (he/she/that person), written records (text), photos
Record storage and viewing
Service Use (Automatically Collected)
Pseudonymous ID, device information (OS, app version, model name), access logs, error logs, cookies and similar technologies
Service improvement and analytics, security management
Future Features (Planned)
External links, community posts, AI recommendation-related data
Providing new features
Information We Do Not Collect
Passwords: Only social login is supported, and passwords are not stored.
Payment information: In-app payments are processed through the app stores, and card numbers or other financial information are not stored.
Article 3 (Retention and Destruction of Personal Information)
General rule: Personal information is destroyed without delay when a member withdraws. However, backup data is securely deleted within a regular system cycle for operational reasons.
Retention required by law
Records of contracts, withdrawal of offers, and payments: 5 years
Records of consumer complaints and dispute handling: 3 years
Records of labeling and advertising: 6 months
Tax-related transaction books and supporting documents: 5 years
Prevention of misuse: Information may be retained for 1 year when necessary to prevent fraudulent registration or misuse.
Destruction procedure and method: Electronic files are securely deleted so they cannot be restored, and paper documents are shredded or incinerated.
In-app payments are processed through Apple/Google, and the Company does not store card numbers or other sensitive payment information. However, purchase status, such as subscription status, and receipt identifiers may be retained for the legally required period to provide the Service.
Article 4 (Provision of Personal Information to Third Parties)
The Company does not provide personal information to third parties in principle.
However, information may be provided within the minimum necessary scope when there is a legal basis or when the user has separately consented.
Article 5 (Entrusted Processing and Overseas Transfer of Personal Information)
Processor
Country
Entrusted Work
Items
Retention and Use Period
Supabase
Republic of Korea (Seoul), United States
Database hosting
All collected items in Article 2
Until withdrawal or termination of entrustment
Google Firebase
United States and others
Error monitoring and analytics
Logs, device information, advertising ID
According to the processor's policy
Apple App Store / Google Play
Various countries
In-app payment processing
Payment-related metadata
According to the store's policy
The processors' servers may be located overseas, and in such cases personal information may be transferred to the relevant countries.
Article 6 (Use Within a Scope Reasonably Related to the Purpose of Collection)
The Company may additionally use or provide personal information within a scope reasonably related to the original purpose of collection, after comprehensively considering relevance, predictability, and whether security measures are in place.
Article 7 (Rights and Obligations of Users and Legal Guardians, and How to Exercise Them)
Users may request access, correction, deletion, suspension of processing, or withdrawal of consent for personal information at any time.
Rights may be exercised through various methods, including in-app inquiries, email ([email protected]), or written requests.
For minors, legal guardians may exercise the same rights, and the representative must submit a power of attorney.
Some rights may be restricted under applicable laws, and information that must be retained under laws such as tax laws cannot be deleted.
California residents (CCPA/CPRA): You have the rights to access, delete, and correct information and to opt out of information sharing.
International rights (including GDPR): You have the right to lodge a complaint with the personal information protection supervisory authority in your country of residence. Korean users may file complaints with the Personal Information Protection Commission (www.pipc.go.kr, 118).
Article 8 (Personal Information Breach Notification)
If the Company becomes aware of a personal information leak or other breach, it will notify data subjects and supervisory authorities without delay in accordance with applicable laws. The notice may include the leaked items, time of occurrence, response measures, and measures to minimize harm.
Article 9 (Measures to Ensure Security of Personal Information)
Administrative measures: Establishment of an internal management plan and employee training
Technical measures: Encrypted storage and transmission, minimum access privileges, and installation of security programs
Physical measures: Access control for server rooms and management of data storage areas
Thank you for entrusting your precious personal reflections to Pebbling. Your privacy and trust are our top priorities.
We use your information only to provide a better service experience. We never use personal information for advertising or third-party sale purposes.
Records are stored securely in accordance with cloud security standards. Your records are encrypted at the disk level in a secure cloud environment, and our team does not arbitrarily access them except when necessary for service operations or customer support.
Your records are not used to train AI models. We may send record text to an external AI service to provide a better experience and personalized feedback, but we do not opt in to providing that data for model training. The AI provider may retain abuse-monitoring logs for up to 30 days.
We do not send account identifiers such as your name or email together with record text for AI analysis.
We disclose everything transparently. This Policy clearly explains what information we collect, how we use it, and with whom we share it.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes.
Membership registration and account management
Service provision and operation, such as storing and viewing records, AI analysis, and personalized feedback
Handling complaints and responding to customer inquiries
Complying with legal obligations, such as tax and consumer protection laws
Improving service quality and user experience
Marketing and advertising, only when the user has separately consented; refusal of consent does not restrict use of the basic service
Minimum processing necessary to protect life, body, or property in emergency situations
Article 2 (Personal Information Processed)
Category
Collected Items
Purpose of Use
Membership Registration
[Provided by Apple/Google] Name (or nickname), email
Account creation and management
Service Use
Preferred reference (he/she/that person), written records (text), photos, metadata
Record storage and viewing, analysis of record content through an AI model, and personalized feedback
Service Use (Automatically Collected)
Pseudonymous ID, device information (OS, app version, model name), access logs, error logs, cookies and similar technologies
Service improvement and analytics, security management
Information We Do Not Collect
Passwords: Only social login is supported, and passwords are not stored.
Payment information: In-app payments are processed through the app stores, and card numbers or other financial information are not stored.
Article 3 (Retention and Destruction of Personal Information)
General rule: Personal information is destroyed without delay when a member withdraws. However, backup data is securely deleted within a regular system cycle for operational reasons.
Retention required by law
Records of contracts, withdrawal of offers, and payments: 5 years
Records of consumer complaints and dispute handling: 3 years
Records of labeling and advertising: 6 months
Tax-related transaction books and supporting documents: 5 years
Prevention of misuse: Information may be retained for 1 year when necessary to prevent fraudulent registration or misuse.
Destruction procedure and method: Electronic files are securely deleted so they cannot be restored, and paper documents are shredded or incinerated.
In-app payments are processed through Apple/Google, and the Company does not store card numbers or other sensitive payment information. However, purchase status, such as subscription status, and receipt identifiers may be retained for the legally required period to provide the Service.
Article 4 (Provision of Personal Information to Third Parties)
The Company does not provide personal information to third parties in principle.
However, information may be provided within the minimum necessary scope when there is a legal basis or when the user has separately consented.
Article 5 (Entrusted Processing and Overseas Transfer of Personal Information)
Processor
Country
Entrusted Work
Items
Retention and Use Period
OpenAI OpCo, LLC
United States
AI analysis and text processing of user records
Written records (text)
Up to 30 days for abuse-monitoring logs, subject to legal or security exceptions
Supabase
Republic of Korea (Seoul), United States
Database hosting
All collected items in Article 2
Until withdrawal or termination of entrustment
Google Firebase
United States and others
Error monitoring and analytics
Logs, device information, advertising ID
According to the processor's policy
Apple App Store / Google Play
Various countries
In-app payment processing
Payment-related metadata
According to the store's policy
The processors' servers may be located overseas, and in such cases personal information may be transferred to the relevant countries.
The transfer to OpenAI occurs over an encrypted network when the user requests AI analysis. OpenAI may be contacted at [email protected]. Users may refuse the transfer by not using the AI analysis feature; in that case, record storage and viewing remain available, but AI analysis and personalized feedback are not provided.
Article 6 (Use Within a Scope Reasonably Related to the Purpose of Collection)
The Company may additionally use or provide personal information within a scope reasonably related to the original purpose of collection, after comprehensively considering relevance, predictability, and whether security measures are in place.
Article 7 (Rights and Obligations of Users and Legal Guardians, and How to Exercise Them)
Users may request access, correction, deletion, suspension of processing, or withdrawal of consent for personal information at any time.
Rights may be exercised through various methods, including in-app inquiries, email ([email protected]), or written requests.
For minors, legal guardians may exercise the same rights, and the representative must submit a power of attorney.
Some rights may be restricted under applicable laws, and information that must be retained under laws such as tax laws cannot be deleted.
California residents (CCPA/CPRA): You have the rights to access, delete, and correct information and to opt out of information sharing.
International rights (including GDPR): You have the right to lodge a complaint with the personal information protection supervisory authority in your country of residence. Korean users may file complaints with the Personal Information Protection Commission (www.pipc.go.kr, 118).
Article 8 (Personal Information Breach Notification)
If the Company becomes aware of a personal information leak or other breach, it will notify data subjects and supervisory authorities without delay in accordance with applicable laws. The notice may include the leaked items, time of occurrence, response measures, and measures to minimize harm.
Article 9 (Measures to Ensure Security of Personal Information)
Administrative measures: Establishment of an internal management plan, minimizing personnel who handle personal information, and security training
Technical measures: AES-256 disk- and backup-level encryption through Supabase infrastructure, SSL/TLS encryption in transit between user devices, servers, and external APIs, and minimum access privileges
Physical measures: Data center access controls and management of data storage areas by cloud infrastructure providers