Pilsa Time Privacy Policy
Flago (the “Company”) complies with the Personal Information Protection Act of Korea and other applicable laws, and establishes this Privacy Policy to process users’ personal information safely.
This Policy applies to the mobile application “Pilsa Time” (Korean: 필사의 시간).
1. Purposes of Processing
The Company processes personal information for the following purposes:
- Membership registration and management (Apple Sign In, identity verification, fraud prevention, withdrawal)
- Service provision (Bible handwriting, session/progress storage, handwriting/drawing data, favorites and notebooks, emotion/reflection notes, display name, etc.)
- Paid subscription provision and verification of payment/subscription status (Apple StoreKit)
- Usage analytics and service improvement (including Firebase Analytics)
- Customer inquiries and delivery of notices/replies (including email)
- Compliance with legal obligations and dispute handling
2. Categories of Personal Information Processed
- Upon Apple Sign In: Apple user identifier, email address (including Apple Hide My Email relay), and name (if the user consents to provide it)
- Information registered or created while using the Service: display name, handwriting sessions and progress, drawing/handwriting data, emotion records, reflection notes, favorited verses, notebook/page layouts
- Information collected automatically: device information (OS type/version, device model), app usage logs, access logs, crash/error logs, analytics event logs (Firebase Analytics)
- When using paid subscriptions: product information, payment status, and subscription status (payment instrument details are processed by Apple; the Company does not collect them directly)
- When submitting customer inquiries: inquiry content, reply email address, and inquiry handling records
3. Retention and Use Period
- In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved.
- If a Member withdraws, the Company retains personal information for 30 days from the withdrawal date for fraud prevention and dispute handling, then destroys it without delay.
- Notwithstanding the above, the following records are retained separately for the periods required by law:
- Records on contracts or withdrawal of offers: 5 years (Act on the Consumer Protection in Electronic Commerce, etc.)
- Records on payment and supply of goods/services: 5 years (same Act)
- Records on consumer complaints or dispute resolution: 3 years (same Act)
- Service usage logs: 3 months (Protection of Communications Secrets Act)
4. Provision to Third Parties
The Company processes personal information only within the purposes stated above and does not provide personal information to third parties except with the user’s consent or where specially permitted under Articles 17 and 18 of the Personal Information Protection Act.
5. Entrustment and Cross-Border Transfer
To provide the Service, the Company entrusts processing as follows and stipulates safeguards in entrustment arrangements.
| Processor | Entrusted work | Destination country | Timing & method | Retention |
|---|---|---|---|---|
| Apple Inc. | Apple Sign In authentication; StoreKit in-app subscription payments | United States | Transmitted over the network when the Service is used | Until end of entrustment or as required by law |
| Google LLC (Firebase Analytics) | App usage analytics; crash/event log collection | United States | Transmitted over the network when the Service is used | Until end of entrustment or as required by law |
| Google LLC (Gmail SMTP) | Sending inquiry receipt and reply emails | United States | Transmitted over the network when inquiries/replies are processed | Until the email delivery purpose is achieved |
Users who do not want cross-border transfer may stop using the Service and request withdrawal. Because Apple Sign In, StoreKit, and Firebase are essential to operating the Service, refusing cross-border transfer may limit use of the Service.
6. Rights of Data Subjects and How to Exercise Them
- Users (or legal guardians of children under 14) may request access, correction, deletion, or suspension of processing of personal information at any time.
- Rights may be exercised via in-app Settings (including withdrawal) or by written request/email to the Privacy Officer below. The Company will act without delay.
- Users may view and edit certain information such as display name in Settings.
7. Destruction of Personal Information
- When retention periods expire or processing purposes are achieved, the Company destroys personal information without delay.
- Electronic files are deleted using technical methods that prevent recovery.
- Upon withdrawal, handwriting records, drawings, notebooks, and similar data are destroyed after the retention period above. Inquiry and payment-related records that must be kept by law are segregated and destroyed when those periods end.
8. Security Measures
The Company takes measures including:
- Secure management of access credentials such as auth tokens and sessions
- Minimizing and controlling access to personal information
- Installing and updating security programs against hacking and similar threats
- Encrypted communications such as HTTPS in production environments
9. Children’s Personal Information
- Children under 14 may use the Service.
- When processing personal information of children under 14, the Company obtains consent of a legal guardian as required by the Personal Information Protection Act.
- Legal guardians may contact the Privacy Officer below to exercise rights of access, correction, deletion, or suspension regarding the child’s personal information.
10. Automatic Collection Tools
The Company may automatically collect device and usage data through analytics tools such as Firebase Analytics. Users may limit some related features through device settings (e.g., tracking restrictions, resetting advertising identifiers). Minimal logs necessary to operate the Service may still be collected.
11. Privacy Officer
The Company designates the following Privacy Officer to oversee personal information processing and handle complaints and remedies.
- Name: Eunju Kim (Representative)
- Email: thanksman1211@gmail.com
12. Changes to This Policy
If this Policy is added to, deleted from, or amended due to changes in law, policy, or security technology, the Company will notify users through in-app notices at least 7 days before the effective date. For changes unfavorable to users, the Company will provide prior notice as required by law.
13. Effective Date
This Privacy Policy takes effect on September 7, 2026.
Business Information
- Trade name: Flago (플라고)
- Representative: Eunju Kim (김은주)
- Business registration number: 162-10-02135
- Address: 9-dong 2F #11, 7 Bokji-ro 120beon-gil, Siheung-si, Gyeonggi-do, Republic of Korea (Daeya-dong, Yeongnam Apt.)