시행일: 2026년 9월 2일 · 문의: goodsahn@gmail.com
My Squishies: Make & Grow(한국어명: 왁뿌볼 키우기, 이하 “앱”)는 기능 제공, 구매 처리, 서비스 안정성 및 광고 제공을 위해 아래 정보를 처리할 수 있습니다. 앱은 iOS(App Store)와 Android(Google Play)에서 제공되며, 플랫폼에 따라 사용하는 서비스가 다른 항목은 아래에 구분해 표시합니다.
1. 처리하는 정보와 목적
- 게임 서비스 계정 정보: 앱 시작 시 플랫폼 게임 서비스가 제공하는 플레이어 식별자·표시 이름을 자동 인증, 업적, 순위표 제공에 사용합니다. 별도 로그인 양식이나 앱 자체 계정은 만들지 않습니다.
iOS: Apple Game Center(플레이어 식별자·표시 이름·제한 상태). Android: Google Play 게임즈 서비스(플레이어 ID·표시 이름). Android에서는 서버 인증을 위해 Google이 발급한 일회성 인증 코드를 앱 운영자 서버로 전달해 세션을 발급받습니다. - 연령 신호: 연령에 맞는 광고·분석 설정을 적용하기 위해 사용합니다. 정확한 생년월일이나 이름은 수집하지 않습니다.
iOS: Game Center가 제공하는 미성년 여부·제한 신호를 사용합니다. Android: Google Play 게임즈에는 연령 신호 API가 없어, 첫 실행 시 태어난 해만 중립적인 문구로 1회 선택받습니다. 선택한 해는 기기에만 저장되며 앱 운영자 서버나 제3자에게 전송하지 않습니다. 응답하지 않거나 확인할 수 없는 경우에는 아동 보호 기본값을 적용합니다.
선택한 해로 아동 해당 여부(예/아니오)만 판정하며, 「개인정보 보호법」의 아동 기준인 만 14세 미만을 적용하되 태어난 해만으로는 생일 도래 여부를 알 수 없으므로 경계에 해당하면 아동으로 봅니다. 이 예/아니오 판정 결과는 아동 대상 보호 설정을 켜기 위해 광고 중개 SDK(Unity LevelPlay)와 연결된 광고 네트워크에 전달됩니다. 태어난 해 자체는 전달되지 않습니다. - 게임 데이터: 제작한 볼(컬렉션), 재료, 프리셋·도감 발견 현황, 배지, 진행도, 설정을 앱 기능과 클라우드 저장·병합에 사용합니다.
iOS: 이용자의 비공개 iCloud(CloudKit) 데이터베이스. Android: 앱 운영자가 운영하는 클라우드 저장 서버(Google Cloud/Firebase)에 게임 서비스 계정 식별자를 키로 저장합니다. - 구매 정보: 상품 ID, 구매·복원 상태와 거래 식별자를 결제 처리, 권한 지급, 부정 사용 방지와 고객지원에 사용합니다. 전체 카드번호 등 결제수단 정보는 앱이 수집하지 않으며 각 스토어가 처리합니다.
iOS: Apple StoreKit. Android: Google Play 결제 시스템(Play Billing) 및 서버 영수증 검증. - 광고 요청 정보: 광고 식별자(iOS는 추적을 허용한 경우에만, Android는 광고 ID 설정에 따라), 기기·앱 정보, IP 주소 기반 대략적 위치(국가·지역 수준), 광고 노출·상호작용을 광고 제공, 노출 빈도 관리 및 성과 측정에 사용할 수 있습니다. 이용자가 추적을 허용한 경우 기기 식별자(광고 식별자)와 광고 데이터는 타사의 광고 목적 추적에 사용될 수 있습니다.
- 진단 정보: 비정상 종료 로그와 성능·오류 정보를 안정성 향상에 사용합니다. 광고 식별자는 포함하지 않습니다.
- 제품 사용 분석 정보: 앱을 처음 실행할 때 기기에 생성·저장되는 임의의 설치 식별자(계정·연락처·게임 서비스 식별자와 연결되지 않는 무작위 값), 기기 모델·운영체제 버전·화면 크기·앱 버전·언어 설정, 그리고 화면 이동과 제작·드로우·구매 퍼널 같은 미리 정의된 기능 사용 이벤트를 앱의 오류 진단과 기능 개선에 사용합니다. 이벤트 전송 시 접속 IP 주소로부터 대략적 위치(도시 수준)가 추정될 수 있습니다. 볼 이름 등 자유 입력 내용과 광고 식별자는 포함하지 않습니다. 이 분석은 연령 판정과 무관하게 모든 이용자에게 적용됩니다.
- 기기 무결성 정보: 부정 결제와 변조를 막기 위해 플랫폼이 제공하는 앱 무결성 신호(Android: Play Integrity, 공통: Firebase App Check)를 서버 요청 검증에 사용합니다.
- 고객지원 정보: 문의 내용과 회신 주소를 요청 처리와 분쟁 대응에 사용합니다.
- 사진·녹화: 이용자가 저장 또는 공유 버튼을 직접 선택한 경우에만 기기 저장소와 공유 기능을 사용합니다.
iOS: 사진 보관함·공유 시트. Android: 미디어 저장소(MediaStore)의 동영상 폴더 및 시스템 공유 시트.
2. 광고와 광고 식별자
앱은 광고 중개 플랫폼 Unity LevelPlay(ironSource)와 이에 연결된 광고 네트워크를 통해 배너, 전면 및 보상형 광고를 제공할 수 있습니다. 현재 연결되어 있거나 연결될 수 있는 광고 네트워크와 각 사의 개인정보 처리방침은 다음과 같습니다.
- Unity LevelPlay / Unity Ads — unity.com/legal/privacy-policy
- Google AdMob — policies.google.com/privacy, Google이 정보를 사용하는 방법
맞춤 광고 여부 — 이용자가 아래 iOS 항목의 추적 허용을 허용한 경우에만 맞춤(개인 맞춤) 광고를 제공하며, 허용하지 않았거나 결정하지 않은 경우와 Android에서는 비개인 맞춤 광고를 제공합니다. 모든 이용자에게 개인정보 판매·공유 거부 신호를 적용합니다. 미성년으로 표시되거나 연령 상태를 확인할 수 없는 이용자에게는 아동 대상 보호 설정을 추가로 적용합니다.
iOS: 앱은 첫 실행 시 Apple의 앱 추적 투명성(App Tracking Transparency, ATT) 권한 창을 표시해 추적 허용 여부를 묻습니다. 허용하시면 광고 식별자(IDFA)를 광고 중개 SDK(Unity LevelPlay)와 연결된 광고 네트워크에 전달해 맞춤 광고 제공, 노출 빈도 관리, 성과 측정에 사용하며, 이 목적을 위해 해당 사업자가 다른 앱·웹사이트에서 수집한 정보와 결합(추적)할 수 있습니다. 허용하지 않거나 결정하지 않은 경우 IDFA는 제공되지 않고 비개인 맞춤 광고만 표시됩니다. 허용 여부는 언제든 iOS 설정 > 개인정보 보호 및 보안 > 추적에서 변경할 수 있으며, 철회하면 이후 맞춤 광고 목적의 식별자 이용이 중단됩니다. 연령 판정에 따라 아동으로 판정된 이용자에게는 ATT 권한 창을 표시하지 않고 아동 대상 보호 설정을 적용합니다(아래 3항 참조).
Android: 앱과 광고·분석 SDK는 Google 광고 ID(AAID)를 사용하며, 광고 게재·빈도 관리·성과 측정과 분석 목적으로 처리하고 이 목적 범위에서 광고 네트워크와 공유합니다. 대략적 위치 정보도 같은 목적으로 광고 네트워크와 공유될 수 있습니다. 이용자는 Android 설정 > 개인정보 보호 > 광고에서 광고 ID를 재설정하거나 삭제할 수 있으며, 삭제하거나 맞춤 광고 선택 해제를 켜면 이후 맞춤 광고 목적의 식별자 이용이 중단되고 비개인 맞춤 광고만 제공됩니다.
EEA·영국·스위스 이용자 — 앱은 동의 관리 플랫폼(CMP)을 운영하지 않으며, 광고 SDK에 GDPR 동의 신호를 전송하지 않습니다. 따라서 해당 지역 이용자에게는 추적 허용 여부와 무관하게 비개인 맞춤 광고만 제공됩니다.
3. 아동 및 혼합 이용자
앱은 다양한 연령이 이용할 수 있는 혼합 이용자 서비스입니다. iOS에서는 Game Center의 미성년 제한 신호를, Android에서는 첫 실행 시 선택한 태어난 해를 기준으로 판단하며, 응답이 없거나 상태를 확인할 수 없으면 보호 기본값(아동으로 간주)을 적용합니다.
아동으로 판정된 경우 제한되는 것 — 개인 맞춤 광고를 제공하지 않고, 광고 중개 SDK(Unity LevelPlay)와 연결된 광고 네트워크에 아동 대상 보호 설정을 적용합니다. iOS에서는 앱 추적 투명성(ATT) 권한 창을 표시하지 않으며 광고 식별자를 요청하지 않습니다. 광고 목적의 식별자 이용과 프로필 기반 처리를 하지 않습니다. 연령 판정이 제한하는 범위는 광고에 한정되며, 아래 항목은 그대로 처리됩니다.
아동으로 판정된 경우에도 계속 처리되는 것 — 아래 항목은 앱의 기본 기능과 결제·보안에 필요하여 연령 판정과 무관하게 처리됩니다. 이용자가 이를 원하지 않으시면 앱 이용을 중단하시고 아래 연락처로 삭제를 요청해 주세요.
- 플랫폼 게임 서비스의 플레이어 식별자·표시 이름(자동 인증, 업적, 순위표)
- Android의 경우 서버 세션 발급을 위한 일회성 인증 코드
- 게임 진행 데이터와 이를 저장하는 클라우드 저장(식별자를 키로 사용)
- 구매·복원 상태와 거래 식별자
- 앱 무결성 신호(Play Integrity, Firebase App Check)
- 비개인 맞춤 광고 제공에 필요한 요청 정보(기기·앱 정보, IP 기반 대략적 위치, 광고 노출·상호작용 — 광고 식별자는 제외) 및 비정상 종료·성능 로그
- 앱의 오류 진단과 기능 개선을 위한 제품 사용 분석(설치 식별자, 기기·앱 정보, 화면 이동과 제작·드로우·구매 퍼널 등 미리 정의된 기능 사용 이벤트). 자유 입력 내용과 광고 식별자는 포함하지 않습니다.
클라우드 저장은 자동으로 시도되고 사용할 수 없으면 기기 내 게스트 저장으로 동작합니다. 녹화물의 저장·공유는 이용자가 해당 버튼을 직접 선택한 경우에만 실행됩니다.
보호자 요청 — 만 14세 미만 아동의 개인정보에 대해 보호자는 열람·정정·삭제 및 처리 정지를 요청할 수 있습니다. 제목을 My Squishies 아동 정보 요청으로 하여 goodsahn@gmail.com으로 연락해 주시면 확인 후 처리합니다. 처리 절차와 범위는 아래 데이터 삭제 요청 항목과 같습니다.
4. 제3자 제공 및 처리
기능 제공에 필요한 범위에서 다음 사업자가 각자의 정책에 따라 정보를 처리할 수 있습니다.
- Apple(App Store, CloudKit, Game Center) — iOS
- Google(Google Play, Google Play 결제, Google Play 게임즈 서비스, Play Integrity, Firebase/Google Cloud, Google Analytics for Firebase) — Android 및 공통
- Unity LevelPlay(ironSource, 광고 중개) 및 연결된 광고 네트워크 — 광고 게재·빈도 관리·성과 측정. 현재 Unity Ads와 Google AdMob이 이에 해당하며, 각 사의 개인정보 처리방침은 위 2항의 링크를 참고해 주세요.
- PostHog(PostHog Inc., 미국) — 제품 사용 분석(화면 이동·기능 사용·퍼널). 앱 사용 중 수시로 미국에 소재한 서버(us.i.posthog.com)로 전송되며, PostHog의 보관 정책에 따라 보관됩니다.
제품 사용 분석(Google Analytics for Firebase, PostHog)은 화면 이동과 제작·녹화·드로우·광고·구매 퍼널 같은 미리 정의된 제품 이벤트만 전송하며, 연령 판정이나 게임 서비스 인증 여부와 관계없이 모든 이용자에게 적용됩니다. 연령·인증 상태는 수집을 차단하는 조건이 아니라 통계를 나누기 위한 속성으로만 기록합니다. 이름, 이메일, 게임 서비스 식별자, 볼 이름 등 자유 입력 내용은 이벤트 매개변수로 전송하지 않습니다. 법적 의무 이행, 권리 보호 또는 보안 사고 대응에 필요한 경우에도 정보가 제공될 수 있습니다.
5. 보유, 보호 및 국외 처리
정보는 목적 달성 또는 법정 보유기간까지 보관한 뒤 삭제하거나 식별 불가능하게 처리합니다. 서비스 제공자의 서버가 다른 국가에 있을 수 있으며, 전송 시 암호화 등 합리적인 기술적·관리적 보호조치를 적용합니다. 앱이 수집·전송하는 데이터는 전송 구간에서 암호화됩니다.
6. 이용자의 선택과 권리
플랫폼 계정(Game Center·iCloud, Google Play 게임즈) 상태는 각 기기의 시스템 설정에서 관리할 수 있으며, 앱에 별도의 개발자 계정은 생성되지 않습니다. 사진·미디어 접근 권한은 시스템 설정에서 변경할 수 있고, Android 광고 ID는 설정 > 개인정보 보호 > 광고에서 재설정·삭제할 수 있습니다.
7. 데이터 삭제 요청
My Squishies(왁뿌볼 키우기) 이용자는 아래 절차로 계정 및 데이터 삭제를 요청할 수 있습니다.
- goodsahn@gmail.com으로 제목에 “데이터 삭제 요청”을 적어 메일을 보냅니다.
- 사용 중인 플랫폼(iOS 또는 Android)과 앱 내 표시 이름 또는 플레이어 식별자를 함께 알려주시면 확인이 빠릅니다. 본인 확인이 필요할 수 있습니다.
- 접수 후 30일 이내에 처리하고 결과를 회신합니다.
삭제되는 데이터: 클라우드에 저장된 게임 진행 데이터(제작한 볼·컬렉션·도감·배지·진행도·설정), 게임 서비스 계정 식별자와 연결된 서버 기록, 고객지원 문의 내역.
보관되는 데이터: 전자상거래·세무 관련 법령에 따라 보관 의무가 있는 결제·거래 기록은 관계 법령이 정한 기간 동안 보관한 뒤 삭제합니다. 기기에만 저장된 데이터는 앱을 삭제하면 함께 제거됩니다. 업적·순위표 기록은 각 플랫폼(Game Center, Google Play 게임즈) 계정에 속하며 해당 플랫폼 설정에서 관리·삭제할 수 있습니다.
8. 변경
서비스나 법적 요구사항이 바뀌면 이 방침을 갱신하며, 중요한 변경은 앱 또는 이 페이지에서 알립니다.
Privacy Policy
Effective September 2, 2026. My Squishies: Make & Grow is available on iOS (App Store) and Android (Google Play). The app may process a platform game-service player identifier and display name; gameplay and cloud save data; purchase status and transaction identifiers; achievement progress and leaderboard scores; advertising identifiers, coarse location, ad engagement, product interaction, crash and performance data; a random install identifier stored on the device together with device model, OS version, screen size, app version and language; app integrity signals; support messages; and photos or recordings only when the user chooses to save or share them. The app has no separate sign-in form and does not create its own account.
Platform differences. On iOS we use Apple Game Center for authentication, the user's private iCloud (CloudKit) database for saves, and StoreKit for purchases. On Android we use Google Play Games Services for authentication (a one-time server auth code is exchanged with our server to issue a session), our own cloud save service on Google Cloud/Firebase for saves, and Google Play Billing with server-side receipt validation for purchases. Recordings are written to the device Photos library on iOS and to MediaStore on Android, in both cases only after the user taps save or share.
Advertising and tracking. Ads are served through Unity LevelPlay (ironSource, mediation) and participating ad networks — currently Unity Ads and Google AdMob. See Unity’s privacy policy and Google’s privacy policy / How Google uses information. On iOS the app shows Apple’s App Tracking Transparency (ATT) prompt on first launch. If you allow tracking, your advertising identifier (IDFA) is shared with the mediation SDK and participating ad networks for personalized ads, frequency capping and measurement, and those companies may combine it with information collected in other apps and websites (tracking). If you decline or do not decide, no IDFA is provided and only non-personalized ads are shown. You can change this at any time in iOS Settings > Privacy & Security > Tracking. Users determined to be children are never shown the ATT prompt and receive child-directed settings. On Android the app and its ad SDKs use the Google Advertising ID (AAID) for ad delivery, frequency capping and measurement and share it with ad networks for those purposes; coarse location may be shared for the same purposes. You can reset or delete your advertising ID, or opt out of ad personalization, in Android Settings > Privacy > Ads. A do-not-sell/share signal is applied for all users. Because the app operates no consent management platform and sends no GDPR consent signal, users in the EEA, UK and Switzerland receive non-personalized ads only.
Mixed audience. iOS relies on Game Center's underage and restriction signals. Because Google Play Games provides no age signal, Android asks once, in neutral wording, for the user's birth year only; the year is stored on the device and is never sent to our servers or to third parties. If there is no answer, protective defaults apply (treated as a child). We never request a full date of birth or exact age. The year yields only a yes/no child determination, using the under-14 threshold of Korea's Personal Information Protection Act; because a year alone cannot tell whether a birthday has passed, borderline cases are treated as children. Only that yes/no result — never the year itself — is passed to the ad mediation SDK (Unity LevelPlay) and participating networks so child-directed settings can be applied.
What is restricted for children. No personalized advertising, and child-directed protection settings applied to the ad mediation SDK (Unity LevelPlay) and participating networks; no advertising identifier use and no profile-based processing for advertising purposes. The age determination restricts advertising only — the items below are processed regardless of it.
What still applies to children. Regardless of the age determination, the app processes the platform player identifier and display name, the one-time server auth code on Android, game progress and its cloud save keyed by that identifier, purchase and restore state with transaction identifiers, app integrity signals (Play Integrity, Firebase App Check), the request data needed for non-personalized ads plus crash and performance logs, and product usage measurement for error diagnosis and feature improvement (the install identifier, device and app information, and predefined feature-use events; no free-form content and no advertising identifier). These are required for the app's core features, billing, security and maintenance. If you do not want this, stop using the app and request deletion at the address below.
Guardian requests. For a child under 14, a legal guardian may request access, correction, deletion or suspension of processing. Email goodsahn@gmail.com with the subject My Squishies child data request; the process and scope match the data deletion section.
Third parties. Apple (App Store, CloudKit, Game Center), Google (Google Play, Play Billing, Play Games Services, Play Integrity, Firebase/Google Cloud, Google Analytics for Firebase), Unity LevelPlay and participating ad networks, and PostHog (PostHog Inc., United States) may process data under their own policies. Product usage analytics are sent to PostHog servers in the United States (us.i.posthog.com) while the app is in use and are retained under PostHog’s retention policy. Product analytics apply to all users regardless of the age determination or game-service authentication; age and authentication status are recorded only as attributes for segmenting statistics, never as conditions that block collection. Analytics events use predefined screen and feature values; names, email addresses, player identifiers, user-entered ball names and other free-form content are not sent as event parameters. Data in transit is encrypted.
Data deletion. To request deletion of your My Squishies data, email goodsahn@gmail.com with the subject “Data deletion request”, telling us your platform (iOS or Android) and your in-app display name or player identifier. Identity verification may be required. We respond within 30 days. Deleted data includes cloud-saved progress (created squishies, collection, codex, badges, progress and settings), server records tied to your game-service identifier, and support correspondence. Purchase and transaction records are retained for the period required by tax and e-commerce law and then deleted. Data stored only on your device is removed when you uninstall the app. Achievement and leaderboard records belong to your Game Center or Google Play Games account and can be managed there.
You can manage platform account status in system settings; the app does not create a separate developer account. Media permissions can be changed in system settings, and the Android advertising ID can be reset or deleted in Settings > Privacy > Ads.