1. Controller and scope
Woodyworld (“we,” “us,” or the “Operator”) operates the SlayerGuide Android and iOS apps and this legal website and is the controller of personal information processed through the app.
- Operator: Woodyworld (우디월드)
- Privacy contact: woodyworld7201@gmail.com
- Covered services: the SlayerGuide app, account sync, app ad-removal purchase verification, customer support, and this website
You may use the app without signing in. If you choose Google or Apple sign-in, we process additional information to provide account sync and link purchase access.
2. Information we process
| Category | Information | When and how |
|---|---|---|
| Account and authentication | Supabase user ID, Google or Apple provider identifier, email or Apple private relay email, display name, linked sign-in methods, session and refresh tokens | Collected over encrypted connections when you complete Google or Apple sign-in |
| Synced data | Saved Black Orb stats and modification time; up to five saved Idle Efficiency results; record IDs and created or modified times | Collected during first migration, saves, and sync after sign-in |
| Purchases and entitlements | Store, product ID, order or transaction identifier, purchase token or signed transaction evidence, purchased, pending, refunded, or revoked status, and verification times | Collected on purchase, restore, app launch or resume, and periodic server reverification |
| App analytics | App-instance ID, device, OS and app version, language, approximate region, and non-identifying screen, button, and ad-funnel events | Automatically collected by Firebase Analytics during app use |
| Crash diagnostics | Crash stacks, device, OS and app version, Crashlytics installation identifiers, event time, and technical state | Automatically collected by Firebase Crashlytics when a crash or error occurs |
| Advertising | IP address, device and advertising identifiers where permitted, ad request, impression, click, reward, and error data, and consent or restriction settings | Collected by Google AdMob when a user without ad-removal access requests an ad |
| Support | Email address, message content, identity-verification result, and minimum order details where needed | Collected when you email support or request deletion |
| Legal website | IP address, request time, user agent, and related delivery or security logs | Automatically processed by Cloudflare to deliver pages and prevent abuse |
We do not directly collect or store your payment-card number, bank-account number, or Google or Apple password. Current calculator inputs and results, comparison slots, screen settings, NEW view state, and the not-yet-implemented game profile are not synced to your account.
This legal site does not run its own analytics or advertising scripts and does not set marketing cookies. Cloudflare may process technical information needed for secure delivery and abuse prevention. We do not make automated decisions that produce legal or similarly significant effects on you.
3. Purposes and processing grounds
- Accounts: provide sign-in, session restoration, provider linking, sign-out, and account deletion.
- Sync: continue selected saved data across devices and resolve conflicts.
- Purchase performance: verify app ad-removal purchases on the server and provide shared access on Android and iOS for the same account.
- Service quality: understand feature flows without direct identifiers and diagnose crashes and errors.
- Free service operation: show app ads and grant ad rewards to users without ad-removal access.
- Security and legal compliance: prevent fraudulent purchases, reused transaction evidence, account compromise, and refund disputes, and preserve legally required records.
Depending on the context and applicable law, we rely on your choice or consent, processing needed to enter into or perform the service agreement, compliance with law, and other lawful grounds. If you decline processing required for an account, you can still use guest features, but sync, purchases, and cross-platform restoration will not be available.
4. Retention and deletion
We delete information without undue delay after its purpose is fulfilled. Where Korean law or another applicable law requires retention, we keep only the minimum records, store them separately from active account data, restrict access, and delete or anonymize them after the period below or a longer legally required period.
| Information | Retention | Deletion rule |
|---|---|---|
| Account, linked identities, display profile, and synced data | Until account deletion or the purpose ends | Deleted from the live database; any restricted backup copy is rotated out within 30 days |
| Sessions, tokens, and local account cache | Until sign-out, deletion, expiry, or app-data removal | Deleted or invalidated in the app and service |
| Advertising and display records required by law | 6 months | Stored separately and deleted or anonymized after the statutory period |
| Contract, withdrawal, payment, and supply records | 5 years | Stored separately and deleted or anonymized after the statutory period |
| Consumer complaints, disputes, and support email | 3 years | Deleted after the dispute-handling period |
| Server purchase-reconciliation events and deletion-processing logs | Up to 90 days | Operational and audit status only, excluding raw sensitive evidence, then automatically deleted |
| Minimum scheduling state for active-purchase revalidation | While the purchase entitlement remains active | Only store and transaction hash references and the next validation time; removed immediately on refund, revocation, or account detachment |
| Firebase Analytics user- and event-level data | Up to 14 months | Automatically deleted under Firebase or Google Analytics settings; aggregate reports may remain |
| Firebase Crashlytics diagnostic data | 90 days | Google begins removal from live and backup systems under its service policy |
| Information independently handled by AdMob, identity providers, or app stores | Under each provider’s policy and legal duties | Controlled by that provider’s privacy settings and policy |
Electronic files are deleted using methods intended to prevent recovery. Legally retained records are not used to rebuild an account or for advertising or marketing.
5. External services and their roles
| Provider | Role | Main information |
|---|---|---|
| Supabase, Inc. | Authentication, PostgreSQL account storage, Edge Functions, purchase-verification and entitlement APIs | Account identifiers, synced data, purchase-verification evidence, and entitlement status |
| Google LLC | Google sign-in, Google Play billing and verification, Firebase Analytics and Crashlytics, Google AdMob | Google identity, app, device, event, crash and ad data, and Play purchase evidence |
| Apple Inc. | Apple sign-in, App Store billing, transaction verification, and server notifications | Apple identity or relay email and signed transaction status |
| Cloudflare, Inc. | Static delivery, TLS, security, and abuse prevention for this website | Web-request IP address, time, user agent, and security logs |
We do not sell personal information. Google and Apple also process some identity, store, and advertising information independently under their own terms. See the Google Privacy Policy, Apple Privacy Policy, Supabase Privacy, and Cloudflare Privacy Policy.
6. International processing and transfers
Identity, analytics, crash, advertising, store, and website services may use global infrastructure outside Korea. To perform the service agreement, we disclose the following processing and transmit information over encrypted networks.
| Recipient and contact | Countries, timing, method | Data and purpose | Retention |
|---|---|---|---|
| Supabase, Inc. privacy@supabase.com | Primary database region: Republic of Korea (ap-northeast-2). During support and service operations, the United States and disclosed subprocessor countries; TLS transfer during account, sync, and verification requests | Account, synced, and purchase-verification data / authentication, storage, and server verification | The account and transaction periods in this policy, or until contract termination and deletion processing |
| Google LLC Privacy inquiry | United States and countries where Google operates data centers; encrypted transfer during sign-in, app use, ads, and purchase verification | Google identity, app-instance, analytics, crash and ad data, Play purchase evidence / sign-in, analytics, diagnostics, ads, and verification | Analytics up to 14 months, Crashlytics 90 days, and other data under Google policy and legal duties |
| Apple Inc. Privacy contact | United States and countries where Apple operates facilities; encrypted transfer during sign-in, purchase, restore, and transaction-status changes | Apple identity or relay email, signed transaction and status / sign-in, payment, restoration, and fraud prevention | As required by Apple policy, law, and the transaction |
| Cloudflare, Inc. privacyquestions@cloudflare.com | United States and global edge locations; HTTPS transfer when a legal page is requested | IP, request time, and user agent / page delivery, security, and abuse prevention | As required by Cloudflare policy and security purposes |
You can decline optional international processing by not signing in or by stopping use of the app. If you decline transfers required for Google or Apple sign-in, account sync, store purchases, or restoration, we cannot provide those features. Contact the Operator about international processing or an available alternative.
7. Analytics, crash diagnostics, and advertising
Firebase Analytics and Crashlytics
We use Firebase Analytics and Crashlytics to understand app quality and feature flows. We do not put your email, raw Supabase user ID, calculator inputs or results, transaction IDs, purchase tokens, or raw signed transactions into analytics event parameters.
Google AdMob
To support free access, we may show banner, rewarded, and interstitial ads to users without ad-removal access. Depending on consent, age and content restrictions, and operating-system settings, AdMob may process advertising identifiers, IP address, device data, and ad interactions.
Once ad_free_lifetime is resolved as active, the user is excluded from ad-SDK initialization, ad requests, ad-funnel events, and the iOS App Tracking Transparency prompt. The last server-verified local entitlement may continue to apply after sign-out or while temporarily offline.
You can manage advertising identifiers and tracking permissions in Android or iOS privacy and advertising settings. Restricting these settings does not block core features, although ads may be less relevant.
8. Security measures
- Encrypted transport (HTTPS/TLS) and provider-recommended OAuth security flows.
- Protected platform storage for sessions, followed by removal or invalidation on sign-out and deletion.
- Supabase Row Level Security so users can access only their own synced data.
- Server verification before granting store entitlements; a client-only flag is never the source of truth.
- No service-role key, store secret, or raw transaction evidence in the app or analytics logs.
- Recent reauthentication for sensitive actions such as account deletion and provider linking.
No transmission or storage method is absolutely secure. If we confirm an incident, we will investigate, contain, notify, and prevent recurrence as required by applicable law.
9. Your rights and choices
Subject to applicable law, you may request access, correction, deletion, suspension of processing, withdrawal of consent, or information about international transfers.
- View account, linked methods, and sync status: My → Account in the app.
- Sign out and revoke the app session: My → Sign out.
- Delete your account: My → Account management → Delete account or follow the Account Deletion guide.
- Other requests: woodyworld7201@gmail.com.
To protect your account, we may ask for reasonable verification, such as reauthentication with the identity provider. An authorized agent may need to show valid authority and identity. We may limit a request where law requires retention or the request would affect another person’s rights, and will explain the applicable reason.
Users in Korea may also consult the Korea Internet & Security Agency Privacy Infringement Report Center or the Personal Information Dispute Mediation Committee.
10. Children’s information
The account and paid-purchase features are not designed for children under 14. A user under 14 must not create an account or make a purchase without valid consent from a legal guardian. If we learn that such information was collected without valid consent, we will verify and delete it and take appropriate action.
11. Contact, privacy lead, and policy changes
- Privacy function: Woodyworld Privacy
- Email: woodyworld7201@gmail.com
We will post changes on this page before they take effect and, when appropriate, notify you in the app. If a change materially affects collected information, purposes, recipients, or user rights, we will provide any additional notice or consent required by law. You can request an earlier version by email.
Related documents: Terms of Service · Account Deletion