모션앤닷 (the "Operator") establishes and discloses this Privacy Policy to protect the personal information of users of GIFdot (the "App") and to comply with applicable laws and regulations.
1. Principles of Processing
- The App's core functions, including media selection, conversion/editing, and saving, are generally performed on the user's device.
- The operator does not upload and store users' original photo or video files on a separate server for the App's core functions.
- However, certain information may be processed automatically through external service providers such as Firebase Analytics, Google Mobile Ads SDK, and RevenueCat in order to operate the service, improve quality, serve ads, and manage purchases and subscriptions.
- If a user separately consents to receive promotional information, information related to marketing notifications may be processed through Firebase Cloud Messaging (FCM), Apple Push Notification service (APNs), and Cloudflare.
- If a user consents to send error diagnostic information, a crash report may be processed through Cloudflare to improve App stability.
- If a user contacts the operator through "Contact" or customer support, a minimal amount of personal information may be processed to the extent necessary to handle the inquiry.
2. Purposes of Processing Personal Information
The operator may process personal information or information that may constitute personal information for the following purposes:
- Analyzing app usage and improving the service
- Analyzing errors, crashes, and performance issues and improving stability
- Serving ads, measuring ad performance, and preventing abuse
- Checking purchase and subscription status, validating receipts, providing Pro features, and analyzing purchases
- Sending promotional app push notifications, including GIFdot discounts, new features, and usage tips, based on separate opt-in consent
- Managing promotional notification consent and withdrawal records, classifying eligible recipients, and preventing misdelivery and abuse
- Receiving and responding to customer inquiries
- Responding to disputes and fulfilling legal obligations where necessary
3. Categories of Personal Information Processed
(1) Information that may be processed automatically during use of the App
The operator may automatically process the following information for app operation, quality improvement, and ad delivery:
- Device identifiers and app instance identifiers
- App usage information, such as screen or feature interactions
- Advertising-related data
- Purchase and subscription history, product and transaction identifiers, price, and currency information
- Approximate location information
- Crash data, performance data, and other diagnostic data
(2) When a user consents to receive promotional information
- App push registration tokens (FCM/APNs) and an app installation identifier
- Promotional notification consent or withdrawal status and timestamps, and nighttime notification consent or withdrawal status and timestamps
- App language, recipient category (free use or purchase/subscription type), app version, and consent notice version
- App integrity verification information, IP address, and request records
(3) When a user consents to send error diagnostic information
- Diagnostic report time, signal, exception and termination reason, and error call information
- App version and build, operating-system version, device type, and transmission consent type
- App integrity verification information, IP address, and request records
(4) When a user contacts support
- Required: Email address, inquiry details
- Optional: Attachments voluntarily provided by the user, such as screenshots, logs, or conversion outputs
4. Retention and Use Period
The operator deletes personal information without delay once the purpose of processing has been achieved.
- Information related to customer inquiries (email, inquiry content, attachments): retained for 1 year after the inquiry is resolved, then deleted
- Information processed automatically during app use: not separately stored directly by the operator, and may be processed by external service providers for periods determined by their policies and applicable law
- Active marketing notification subscription information: deleted when consent withdrawal or notification-permission revocation is reflected on the server, or when the processing purpose has been achieved
- Promotional notification consent and withdrawal records: retained for 3 years from the date each record is received by the server for legal compliance and dispute resolution, then deleted
- FCM/APNs registration tokens: not stored directly in the operator's notification server database. When consent is withdrawn, the App requests topic unsubscription and token deletion. Processing by external services is governed by each provider's policy.
- Error diagnostic information sent with consent: retained for 30 days from server receipt, then deleted by the daily cleanup process after that period (within 31 days of receipt)
5. Provision of Personal Information to Third Parties
Information may be transmitted to the following external service provider in order to operate the service:
- Recipient: Google LLC and its affiliates
- Purpose: Usage analytics, app quality improvement, ad delivery, and ad performance measurement
- Items: Device identifiers, app usage information, advertising-related data, approximate location information, and diagnostic data
- Recipient: RevenueCat, Inc.
- Purpose: Checking purchase and subscription status, validating receipts, providing Pro features, and analyzing purchases
- Items: Anonymous App User ID, purchase and subscription history, receipt or purchase token, product and transaction identifiers, price and currency, and basic technical information
6. Outsourcing of Personal Information Processing
The operator may outsource part of the processing activities to the following external services:
- Google Firebase Analytics
- Google Mobile Ads SDK (AdMob)
- RevenueCat, Inc.: Purchase and subscription receipt validation, entitlement management, and purchase analytics
- Google Firebase Cloud Messaging (FCM): Management of push registration tokens and topics, and notification delivery
- Apple Push Notification service (APNs): Delivery of push notifications to iOS devices
- Cloudflare, Inc. (Workers, D1, Queues): Management of consent and withdrawal records and active subscription information, processing of delivery requests, storage and deletion of consented error diagnostic information, and security
7. Overseas Transfer
When using Firebase Analytics and Google Mobile Ads SDK, personal information or information that may constitute personal information may be transferred outside the Republic of Korea.
- Recipient: Google LLC and its affiliates
- Destination Country: United States and other countries where Google operates service infrastructure
- Transferred Items: Device identifiers, app usage information, advertising-related data, approximate location information, and diagnostic data
- Timing and Method: Transmitted over the network when the App is launched or used
- Purpose: Usage analytics, app quality improvement, ad delivery, and ad performance measurement
Overseas Transfers for Purchase and Subscription Management
- Recipient: RevenueCat, Inc.
- Destination Countries: The United States and other countries where RevenueCat operates service infrastructure
- Transferred Items: Anonymous App User ID, purchase and subscription history, receipt or purchase token, product and transaction identifiers, price and currency, and basic technical information
- Timing and Method: Transferred over encrypted networks when the App launches, a purchase or restore occurs, or subscription status is checked
- Purpose: Checking purchase and subscription status, validating receipts, providing Pro features, and analyzing purchases
- Retention and Use Period: For the period necessary to provide the service and as required by RevenueCat's policies and applicable law
Overseas Transfers for Marketing Notifications
- Recipients: Google LLC and its affiliates (FCM), Apple Inc. and its affiliates (APNs), and Cloudflare, Inc. and its affiliates (Workers, D1, Queues)
- Destination Countries: The United States and other countries where each provider operates service infrastructure
- Transferred Items: App push registration tokens, app installation identifier or its hash, consent and withdrawal information, nighttime notification consent information, app language, recipient category, app version, app integrity verification information, IP address and request records, and notification delivery information
- Timing and Method: Transferred over encrypted networks when a user consents, withdraws consent, or changes settings; when the App verifies consent status; and when a notification is delivered
- Purpose: Managing consent for promotional app push notifications, classifying eligible recipients, delivering push notifications, preventing misdelivery and abuse, and responding to service failures
- Retention and Use Period: Consent and withdrawal records stored by Cloudflare are retained for 3 years. Active subscription information is retained until consent withdrawal or notification-permission revocation is reflected on the server, or until the purpose is achieved. Information processed by Google and Apple is retained in accordance with each provider's policy and for the period necessary to provide the service.
Overseas Transfers for Error Diagnostics
- Recipient: Cloudflare, Inc. and its affiliates (Workers, D1)
- Destination Countries: The United States and other countries where Cloudflare operates service infrastructure
- Transferred Items: Diagnostic report time, signal, exception and termination reason, error call information, App version and build, operating-system version, device type, transmission consent type, App integrity verification information, IP address, and request records
- Timing and Method: Transferred over encrypted networks when the user selects "Send This Time" or when error diagnostic information is created after automatic sending has been enabled
- Purpose: Analyzing errors and crashes and improving App stability
- Retention and Use Period: Error diagnostic information stored by Cloudflare is retained for 30 days from server receipt, then deleted by the daily cleanup process after that period (within 31 days of receipt)
8. Data Subject Rights and How to Exercise Them
Users may request access to, correction or deletion of, or suspension of processing of their personal information in accordance with applicable law.
- How to exercise: Request by email to appledev1920@gmail.com
- Handling: Processed within the period prescribed by applicable law, subject to any legal restrictions
- Withdraw consent to promotional notifications: Turn off "Consent to Receive Promotional Information" in the App's settings, or use the opt-out action provided in a promotional notification
- Block all App notifications: Disable notifications for GIFdot in iOS Settings
9. Procedures and Methods for Deletion
- Procedure: Deleted without delay after the processing purpose has been achieved, in accordance with internal policy and applicable law
- Method: Electronic files are deleted using methods that prevent recovery, and printed materials are shredded or incinerated
10. Security Measures
The operator implements reasonable safeguards to protect personal information, including minimizing access, protecting accounts, and observing retention periods.
11. Contact
- Personal Information Protection Officer: 모션앤닷
- Contact email: appledev1920@gmail.com
12. Changes to This Policy
This Policy may be revised due to changes in law or service updates. If there are any material changes, notice will be provided through the published documents together with the effective date.