PRIVACY

Privacy Policy

Last updated: 1 October 2026

1. Personal information we process

Android closed-test applications: We collect the Google Play account email address entered on the invite page through Google Forms. We use it only to review the request, add testers, and provide participation instructions. New-response notifications go to adminppip@gmail.com. We delete the response when you withdraw your request or the test ends. Applying does not create an app account.

Account

Profile

Receivers and decorations

Signals exchanged

Relationships, groups and settings

Notifications, Focus and payments

Kept only on your device

The following are not sent to the server and are stored only on your device: wallpaper choice, voice volume, the ALWAYS setting, anything made in practice mode, whether you have seen the guide, and temporary copies of recently received voices.

We process keycap design/placement, weekly and lifetime counts between friends, deduplication identifiers and milestone notification records. Reports include reporter/subject identifiers, reason, description, signal identifier, status, action, completion time and necessary retention grounds. We also manage the results of privacy requests and deletion jobs.

2. Purposes of processing

3. Retention and use periods

WhatHow long
Voices, pages and audio files24 hours after sending; 30 days if either party has ppip+. Group rules follow Article 8 of the Terms. Cleanup deletes expired data.
Records between friendsUnfriending/blocking removes the relationship and signal access and deletes related records. Stored files are physically deleted by cleanup jobs.
Greetings, profile, settings, friendships, blocks, Apple refresh tokenUntil changed, deleted or account deletion, subject to the transaction/report exceptions below.
Invite codes7 days from issue.
Groups and membershipWhile the group exists. Your membership is deleted when you leave or delete your account.
Unreferenced audio/photosCleanup after 24 hours without references. Failed file deletions are retried and monitored.
Authentication history in the app databaseRecords older than 90 days are cleaned hourly. Account deletion removes records linked by account ID or email. These records may include IP, time, authentication action and account identifiers.
Reports and actionsOpen reports: 90 days from receipt. Closed ordinary reports: 30 days after closure. Applicable consumer complaint/dispute records: 3 years after closure. Records needed for ongoing legal proceedings may be held with a documented basis, reviewed at least every 90 days, and deleted when no longer justified. Account deletion does not erase an ongoing report.
ppip+ transaction historyProduction purchase/supply/cancellation records: 5 years from the latest applicable purchase, end-of-supply or refund date for the record. Test purchases: 90 days on the same basis. Account deletion removes the app account; necessary transaction and account-linking identifiers are retained separately. Apple retains its own records under its policy. Google Play subscription verification records (a hash of the purchase token, product and expiry time) are kept until account deletion; Google retains its own records under its policy.
KeycapsSettings until deletion/account deletion; relationship counts and milestones until unfriending/account deletion. Deduplication records are cleaned after 14 days; per-device notification queue/results after 7 days from the event.
Rate limits and operational checksUsed within short feature-specific windows. Account rate limits are cleaned on account deletion. Cleanup counts and latest status, without personal content, support operational checks.
Deletion receiptsOnly the deleted account ID and deletion time are retained for 90 days to verify deletion and reapply it after backup restoration.

Retained transaction/report records have access separated from ordinary app data and are used only for their retention purpose. Hourly jobs delete expired records and retry failures. Supabase platform operational/security logs and backups are managed under its contract/settings and are distinct from these app-database cleanup jobs.

4. Provision to third parties

ppip does not sell personal information and does not provide it to third parties for advertising. Information moves only in the following cases.

5. Processing entrusted and transferred abroad

Accounts, audio, photos and report bodies are stored in the Seoul region, Republic of Korea. We do not send report bodies or user IDs to Discord or Slack. We use Supabase authentication/storage and the login, notification and payment services of Apple (iPhone) and Google (Android); cross-border access/transfers may occur in these workflows. Necessary contractual processing entrustment/storage uses disclosure under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. Transfers requiring separate consent are not performed without that consent. Contact section 10 to inquire or object; affected features depend on the necessity of the particular transfer.

ProcessorContactCountry / regionItems and purposeWhen and howRetention
Supabase, Inc. privacy@supabase.io Republic of Korea (Seoul region). Supabase, Inc. is a US corporation, however, and may access data from abroad in the course of incident response and technical support. The personal information listed in section 1 (authentication, database/file storage, report handling and transaction record retention) Over encrypted connections (HTTPS) while using the Service The periods in section 3 of this Policy
Apple Inc. apple.com/legal/privacy/contact United States and that company's global processing locations Sign-in identifier and email (Sign in with Apple), token revocation on account deletion, sender name, notification text and temporary audio address (APNs notifications), payment and receipt information (App Store, ppip+), app distribution information Over encrypted connections at sign-in, when a notification occurs, at payment and at account deletion Per your account and Apple's policies
Google LLC policies.google.com/privacy · firebase.google.com/support/privacy United States and that company's global processing locations Sign-in identifier, email, name and profile photo address (Google sign-in), FCM registration token, sender name, notification text, signal identifiers and temporary audio address (Firebase Cloud Messaging notifications), purchase token, hashed account identifier and subscription status (Google Play billing, ppip+), app distribution information Over encrypted connections at sign-in, when a notification occurs and at payment Per your account and Google's policies

6. Your rights and how to exercise them

After account deletion, the transaction/report records in section 3 remain only for their stated purposes and periods. Physical file deletion follows section 8.

7. Children under 14

ppip does not accept sign-ups from children under 14 and does not collect the personal information of children under 14. Only those aged 14 and over may sign up. If we confirm that a child under 14 has signed up, we delete that account and its information without delay.

A legal guardian may ask us to check and delete a child's account through the contact in section 10 below.

8. Deletion procedure

We delete information without delay when its retention period or purpose ends. Account/relationship deletion and physical file deletion are separate steps; queued file deletions are retried on failure. Ordinary app data is distinguished from separately retained transaction/report records. Data is deleted using methods that prevent recovery. Before restored backups are used for service, deletion requests must be checked and reapplied. Backups are not used for routine access or service delivery.

9. Security measures

10. Privacy contact / officer

Business name: Hyunii LAB (혀니랩)

Business registration number: 183-12-02965

Privacy officer: the representative of Hyunii LAB

Contact: adminppip@gmail.com

Privacy rights requests are handled within applicable statutory deadlines. Access requests are generally handled within 10 days of receipt; statutory restrictions or delays are explained with the objection procedure.

If you need to report or seek advice about a privacy violation, you may contact the Korea Internet & Security Agency (KISA) Privacy Infringement Report Center (privacy.kisa.or.kr, 118 within Korea) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), among others.

Read the Terms of Service →

11. Region-specific disclosures

The following applies in addition to everything above, depending on where you live. Where the two differ, this section prevails.

European Economic Area and the United Kingdom

For the purposes of the GDPR and the UK GDPR, the controller is Hyunii LAB, reachable at the contact in section 10.

Legal bases for processing

Creating accounts, signing in and managing accountsPerformance of a contract (Art. 6(1)(b))
Delivering and playing signals, groups, voicemail, push notificationsPerformance of a contract (b)
Confirming ppip+ subscriptions and providing their featuresPerformance of a contract (b)
Receiving and reviewing blocks and reports, preventing abuse, rate limitingLegitimate interests (f) — protecting users and keeping the Service safe
Microphone use, showing notifications, ALWAYSConsent (a) — taken as a device permission and withdrawable at any time
Retaining transaction records and report-handling recordsLegal obligation (c)
Investigating errors and improving featuresLegitimate interests (f)

Your rights — access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) and withdrawal of consent (Art. 7(3)). Requests go to the contact in section 10. The Service makes no automated decisions producing legal effects, and does no profiling (Art. 22).

Supervisory authority — you may lodge a complaint with the authority where you live or work (Art. 77). In France this is the CNIL (cnil.fr); in the United Kingdom, the ICO (ico.org.uk).

International transfers — accounts, audio and photos are stored in the Seoul region of the Republic of Korea. The European Commission adopted an adequacy decision for the Republic of Korea on 17 December 2021, so transfers from the EEA to Korea need no standard contractual clauses or other separate safeguards. Information used for sign-in, notifications and payments is passed to Apple or Google and follows each company's own transfer arrangements.

Brazil

Under the LGPD, our bases for processing are performance of a contract (Art. 7, V), consent (I), compliance with a legal obligation (II) and legitimate interests (IX); the basis for each activity is as set out in the table above.

Your rights (Art. 18) — confirmation that processing takes place, access, correction, anonymization, blocking or deletion, portability, withdrawal of consent, and information about sharing with third parties.

The data protection officer (encarregado) and the channel for requests are the contact in section 10. The supervisory authority is the ANPD (gov.br/anpd).

Mexico

This document also serves as the privacy notice (aviso de privacidad) under the LFPDPPP. The responsable is Hyunii LAB, reachable at the contact in section 10. The information we process is in section 1 and the purposes are in section 2. We do not process personal information for purposes that are not necessary to provide the Service, such as advertising or marketing.

ARCO rights — access (Acceso), rectification (Rectificación), cancellation (Cancelación) and objection (Oposición) may be exercised through the contact in section 10. Consent may be withdrawn the same way.

Changes to this notice are announced within the Service and by updating this document. You have the right to lodge a complaint with the competent supervisory authority.