PRIVACY
Privacy Policy
Last updated: 1 October 2026
1. Personal information we process
Android closed-test applications: We collect the Google Play account email address entered on the invite page through Google Forms. We use it only to review the request, add testers, and provide participation instructions. New-response notifications go to adminppip@gmail.com. We delete the response when you withdraw your request or the test ends. Applying does not create an app account.
Account
- Apple: We process the login identifier supplied by Apple and, when supplied, your email and name. The name initializes your editable display name. Hide My Email supplies a relay address instead of your real email. We do not collect passwords.
- Apple refresh token: when you sign in, we exchange the code Apple gives us for a token and keep one row of it. We use it only to revoke the connection with Apple when your account is deleted, so that ppip does not stay behind in your Apple ID settings. Not even you can read this row, and it disappears with your account. If you sign in with Apple on Android, we do not receive this token.
- Google (Android): the account identifier and email address supplied by Google, together with the name and profile photo address Google passes along, are stored in the sign-in records of the authentication server (Supabase Auth). The app does not use that name or photo for your display name or receiver. We request only basic sign-in information (openid, email, profile), and we do not keep your password or Google's access token.
- Authentication access log: the IP address and access time Supabase Auth records in the course of signing you in. We use it only to check errors and prevent abuse, and how long it is kept is in the table in section 3.
Profile
- Pager number: a ten-digit number starting with
01and the time it was last claimed. It is used only inside the app; we do not collect your phone number. - Your ID (3–20 lowercase letters, digits and underscores), display name (up to 30 characters) and the time it was last changed, language setting, and time zone.
- The kind of tone that plays when a ppip arrives for you, and whether you accept friend requests that come by number.
- Coins: the in-app count used to send a page, and the date and time you last received a daily grant. To judge the once-a-day grant, the app also sends today's date on your device.
- Greeting: one short recording that ppip+ users record in advance. Friends hear it.
Receivers and decorations
- The shape and color of your receiver, the kinds and positions of decorations (stickers and lettering), whether the receiver is lifted and when that expires, and your quiet hours setting.
- Photos used in decorations: one photo attached to a receiver. Cropping and cutting out happen on your device, and only the resulting image is uploaded to private storage. The app does not access your whole photo library — only the photo you pick. This image is visible to your friends.
- Closet: saved receiver decoration sets (name, shape, color, photo path, decoration details).
Signals exchanged
- Voices: audio recordings of up to 5 seconds (30 seconds on ppip+), their length, the sender and recipient, the time sent, and — for a reply — one field referring to the original signal. The microphone is used only when you send a voice.
- Pages: numeric signals sent by keying in numbers on the payphone screen. The numbers sent are kept along with an identifier that ties one call together.
- Codes (codebook): a list attaching meanings to numbers. Some are yours alone and some are made together with a friend; those made together are erased when you and that friend disconnect.
- Delivery decisions: whether a signal rang right away or went to voicemail, the reason it went there, and the time it rang. The reason is not shown to the sender.
Relationships, groups and settings
- Friendships, friend requests exchanged (by invite code, QR or number), invite codes and their expiry times.
- Groups: the group name, the group number starting with
02, the creator, the member list and when each joined, and invitations along with members' agreement records. A signal sent to a group is kept as one row per recipient. - Per-friend settings: whether it rings right away, whether it plays automatically on the lock screen, the daily limit, and where that person's receiver sits on your wall.
- Block list, and report records (who was reported, one of four reasons, a description of up to 500 characters, and the signal concerned).
- Rate-limit records: to prevent number sweeping and report flooding, we briefly count recent calls to certain features per user.
Notifications, Focus and payments
- Push: on iPhone, device identifier, APNs token, platform (iOS) and build environment. On Android, device identifier, Firebase Cloud Messaging (FCM) registration token and app identifier. When you sign out, we first deregister that device.
- ALWAYS: if you turn on the feature that lets voices be heard past the silent switch, a separate short-lived token for that feature is registered. When you turn the feature off or the token expires, that row is deleted. On Android, the ALWAYS setting is stored only on the device and no separate token is registered.
- Notification permission: if ppip notifications are turned off on your device, one value recording that you cannot receive notifications is sent to the server.
- Focus: the app does not read your Focus state on the sly. Only if you have added ppip yourself under Settings › Focus › Filters is a single on/off value sent to the server when Focus turns on and off. On Android, whether Do Not Disturb is on is checked only on the device and is not sent to the server.
- ppip+: We process Apple-verified transaction and original transaction IDs, product, purchase, expiry and refund times, price and currency when supplied by Apple, production/test environment and an account-linking identifier. Transaction history is managed separately from subscription access to reconcile renewals/refunds and retain required records. We do not receive card details or your Apple account password. If you subscribe through Google Play on Android, our server verifies the purchase token with Google and then records only a hash of the token, the product, the expiry time and whether it was a test purchase, not the token itself. To tell whether a purchase belongs to this account, a hash of your account identifier is attached to the purchase and sent to Google. We do not receive payment method details or your Google account password.
- Android device permissions: the only permissions we ask you for are the microphone (recording voices) and notifications (Android 13 and later). We receive only the photo you pick in the system photo picker, so we do not request photo or storage permissions. You can turn permissions off at any time in device settings.
Kept only on your device
The following are not sent to the server and are stored only on your device: wallpaper choice, voice volume, the ALWAYS setting, anything made in practice mode, whether you have seen the guide, and temporary copies of recently received voices.
We process keycap design/placement, weekly and lifetime counts between friends, deduplication identifiers and milestone notification records. Reports include reporter/subject identifiers, reason, description, signal identifier, status, action, completion time and necessary retention grounds. We also manage the results of privacy requests and deletion jobs.
2. Purposes of processing
- Creating accounts, signing in and managing accounts
- Issuing pager numbers, finding friends, sending and accepting friend requests, issuing invite links
- Delivering and playing voices and pages, and keeping them in voicemail
- Creating groups and managing members, and delivering signals sent to a group
- Deciding whether to ring or hold in voicemail, according to the rules the recipient has set (quiet hours, daily limit, whether it rings right away, Focus, notification permission)
- Sending push notifications
- Decorating receivers and showing walls
- Receiving blocks and reports, and preventing abuse such as number sweeping and flooding
- Confirming ppip+ subscriptions and providing their features
- Responding to inquiries, investigating errors and improving features
- Reconciling transactions and refunds, retaining required records, reviewing reports and objections, and monitoring deletion failures
3. Retention and use periods
| What | How long |
|---|---|
| Voices, pages and audio files | 24 hours after sending; 30 days if either party has ppip+. Group rules follow Article 8 of the Terms. Cleanup deletes expired data. |
| Records between friends | Unfriending/blocking removes the relationship and signal access and deletes related records. Stored files are physically deleted by cleanup jobs. |
| Greetings, profile, settings, friendships, blocks, Apple refresh token | Until changed, deleted or account deletion, subject to the transaction/report exceptions below. |
| Invite codes | 7 days from issue. |
| Groups and membership | While the group exists. Your membership is deleted when you leave or delete your account. |
| Unreferenced audio/photos | Cleanup after 24 hours without references. Failed file deletions are retried and monitored. |
| Authentication history in the app database | Records older than 90 days are cleaned hourly. Account deletion removes records linked by account ID or email. These records may include IP, time, authentication action and account identifiers. |
| Reports and actions | Open reports: 90 days from receipt. Closed ordinary reports: 30 days after closure. Applicable consumer complaint/dispute records: 3 years after closure. Records needed for ongoing legal proceedings may be held with a documented basis, reviewed at least every 90 days, and deleted when no longer justified. Account deletion does not erase an ongoing report. |
| ppip+ transaction history | Production purchase/supply/cancellation records: 5 years from the latest applicable purchase, end-of-supply or refund date for the record. Test purchases: 90 days on the same basis. Account deletion removes the app account; necessary transaction and account-linking identifiers are retained separately. Apple retains its own records under its policy. Google Play subscription verification records (a hash of the purchase token, product and expiry time) are kept until account deletion; Google retains its own records under its policy. |
| Keycaps | Settings until deletion/account deletion; relationship counts and milestones until unfriending/account deletion. Deduplication records are cleaned after 14 days; per-device notification queue/results after 7 days from the event. |
| Rate limits and operational checks | Used within short feature-specific windows. Account rate limits are cleaned on account deletion. Cleanup counts and latest status, without personal content, support operational checks. |
| Deletion receipts | Only the deleted account ID and deletion time are retained for 90 days to verify deletion and reapply it after backup restoration. |
Retained transaction/report records have access separated from ordinary app data and are used only for their retention purpose. Hourly jobs delete expired records and retry failures. Supabase platform operational/security logs and backups are managed under its contract/settings and are distinct from these app-database cleanup jobs.
4. Provision to third parties
ppip does not sell personal information and does not provide it to third parties for advertising. Information moves only in the following cases.
- To your friends: your ID, display name, receiver shape and decorations and photo, and the voices and pages you send, are delivered to them to be seen and heard. They are delivered only to people who are friends with you.
- To members of the same group: a signal sent to a group, along with the sender's name, is delivered to that room's members. The condition for joining a room is being a friend of the person who made it, so members may not be friends with one another.
- To someone receiving a request by number: when you request a connection with your number, your ID and display name appear in that person's friend request list. The caller always gets the same answer, so it cannot be told apart whether the other person uses that number, has closed requests, or has blocked them.
- Apple (APNs): to send a notification, the sender's name, the notification text, and a temporary address from which the audio file can be downloaded for a short time are passed to Apple. The audio file itself is not carried in the notification.
- Google (Firebase Cloud Messaging): to send a notification to an Android device, the sender's name, the notification text, identifiers that distinguish the signal, and a temporary address from which the audio file can be downloaded for a short time are passed to Google. The audio file itself is not carried in the notification.
- Requests under the law: where there is a lawful request based on applicable law.
5. Processing entrusted and transferred abroad
Accounts, audio, photos and report bodies are stored in the Seoul region, Republic of Korea. We do not send report bodies or user IDs to Discord or Slack. We use Supabase authentication/storage and the login, notification and payment services of Apple (iPhone) and Google (Android); cross-border access/transfers may occur in these workflows. Necessary contractual processing entrustment/storage uses disclosure under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. Transfers requiring separate consent are not performed without that consent. Contact section 10 to inquire or object; affected features depend on the necessity of the particular transfer.
| Processor | Contact | Country / region | Items and purpose | When and how | Retention |
|---|---|---|---|---|---|
| Supabase, Inc. | privacy@supabase.io | Republic of Korea (Seoul region). Supabase, Inc. is a US corporation, however, and may access data from abroad in the course of incident response and technical support. | The personal information listed in section 1 (authentication, database/file storage, report handling and transaction record retention) | Over encrypted connections (HTTPS) while using the Service | The periods in section 3 of this Policy |
| Apple Inc. | apple.com/legal/privacy/contact | United States and that company's global processing locations | Sign-in identifier and email (Sign in with Apple), token revocation on account deletion, sender name, notification text and temporary audio address (APNs notifications), payment and receipt information (App Store, ppip+), app distribution information | Over encrypted connections at sign-in, when a notification occurs, at payment and at account deletion | Per your account and Apple's policies |
| Google LLC | policies.google.com/privacy · firebase.google.com/support/privacy | United States and that company's global processing locations | Sign-in identifier, email, name and profile photo address (Google sign-in), FCM registration token, sender name, notification text, signal identifiers and temporary audio address (Firebase Cloud Messaging notifications), purchase token, hashed account identifier and subscription status (Google Play billing, ppip+), app distribution information | Over encrypted connections at sign-in, when a notification occurs and at payment | Per your account and Google's policies |
6. Your rights and how to exercise them
- Viewing and changing: display name, receiver, decorations and photo can be changed directly in the app, and quiet hours, arrival tone, greeting, voice volume, wallpaper and whether to allow requests by number are changed under the gear on the friends board → Settings. The display name can only be changed at the set interval. Your ID and pager number are the handles friends use to find you, so they cannot be changed.
- Turning off requests by number: turning off REQUESTS in Settings stops connection requests arriving by number, so friendships grow only through invite codes and QR codes.
- Unfriending, blocking and reporting: open that person on the friends board and you will find these at the bottom. Unfriending erases what the two of you exchanged. Blocking means there is no reconnecting by ID, number or invite; you can unblock under Blocked numbers at the bottom of the friends board.
- Turning off notifications: turn off ppip notifications in your device settings, or set individual friends not to ring right away.
- Deleting your account: the gear on the friends board → Settings → Delete account. You have to type your ID to go through. Audio, photo and greeting files, the signals exchanged, friendships and requests, group membership records, invites, blocks, registered devices, receivers, profile, pager number, Apple refresh token and the account itself are all erased, and we also ask Apple to disconnect the sign-in. This cannot be undone. A ppip+ subscription is tied to the Apple Account or Google Account you paid with and we cannot cancel it; if you are subscribed, Apple's subscription management screen (on Android, Google Play's) opens just before deletion. For accounts that signed in with Google, and accounts that signed in with Apple on Android and have no refresh token, ppip cannot disconnect the sign-in for you; you can remove it yourself in your Google Account or Apple ID settings.
- Other requests to access, correct, delete or suspend processing can be sent to the contact in section 10 below.
After account deletion, the transaction/report records in section 3 remain only for their stated purposes and periods. Physical file deletion follows section 8.
7. Children under 14
ppip does not accept sign-ups from children under 14 and does not collect the personal information of children under 14. Only those aged 14 and over may sign up. If we confirm that a child under 14 has signed up, we delete that account and its information without delay.
A legal guardian may ask us to check and delete a child's account through the contact in section 10 below.
8. Deletion procedure
We delete information without delay when its retention period or purpose ends. Account/relationship deletion and physical file deletion are separate steps; queued file deletions are retried on failure. Ordinary app data is distinguished from separately retained transaction/report records. Data is deleted using methods that prevent recovery. Before restored backups are used for service, deletion requests must be checked and reapplied. Backups are not used for routine access or service delivery.
9. Security measures
- We do not take passwords, so we do not store them either. Authentication is handled by Sign in with Apple, Google sign-in and Supabase Auth.
- The database uses row-level access control so that only your own and your friends' data can be read.
- Signal records and the locations of audio files are not exposed to the app directly, and are reached only through set procedures.
- Not even you can read the Apple refresh token; only the server that performs account deletion reads it.
- Audio, photo and greeting files are kept in private storage, and can only be downloaded through short-lived signed addresses.
- Notifications do not carry audio files, only a temporary address.
- Number lookup and reporting have call-count limits.
- Payment entitlements are recorded only from receipts Apple has verified or purchases our server has verified with Google Play, and are read and written only with the server's administrative privileges.
- All communication is encrypted with HTTPS.
- We do not use advertising identifiers or tracking cookies for personalized advertising. Automatically generated records needed for authentication, security and service operation are described in sections 1 and 3.
10. Privacy contact / officer
Business name: Hyunii LAB (혀니랩)
Business registration number: 183-12-02965
Privacy officer: the representative of Hyunii LAB
Contact: adminppip@gmail.com
Privacy rights requests are handled within applicable statutory deadlines. Access requests are generally handled within 10 days of receipt; statutory restrictions or delays are explained with the objection procedure.
If you need to report or seek advice about a privacy violation, you may contact the Korea Internet & Security Agency (KISA) Privacy Infringement Report Center (privacy.kisa.or.kr, 118 within Korea) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), among others.
11. Region-specific disclosures
The following applies in addition to everything above, depending on where you live. Where the two differ, this section prevails.
European Economic Area and the United Kingdom
For the purposes of the GDPR and the UK GDPR, the controller is Hyunii LAB, reachable at the contact in section 10.
Legal bases for processing
| Creating accounts, signing in and managing accounts | Performance of a contract (Art. 6(1)(b)) |
| Delivering and playing signals, groups, voicemail, push notifications | Performance of a contract (b) |
| Confirming ppip+ subscriptions and providing their features | Performance of a contract (b) |
| Receiving and reviewing blocks and reports, preventing abuse, rate limiting | Legitimate interests (f) — protecting users and keeping the Service safe |
| Microphone use, showing notifications, ALWAYS | Consent (a) — taken as a device permission and withdrawable at any time |
| Retaining transaction records and report-handling records | Legal obligation (c) |
| Investigating errors and improving features | Legitimate interests (f) |
Your rights — access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) and withdrawal of consent (Art. 7(3)). Requests go to the contact in section 10. The Service makes no automated decisions producing legal effects, and does no profiling (Art. 22).
Supervisory authority — you may lodge a complaint with the authority where you live or work (Art. 77). In France this is the CNIL (cnil.fr); in the United Kingdom, the ICO (ico.org.uk).
International transfers — accounts, audio and photos are stored in the Seoul region of the Republic of Korea. The European Commission adopted an adequacy decision for the Republic of Korea on 17 December 2021, so transfers from the EEA to Korea need no standard contractual clauses or other separate safeguards. Information used for sign-in, notifications and payments is passed to Apple or Google and follows each company's own transfer arrangements.
Brazil
Under the LGPD, our bases for processing are performance of a contract (Art. 7, V), consent (I), compliance with a legal obligation (II) and legitimate interests (IX); the basis for each activity is as set out in the table above.
Your rights (Art. 18) — confirmation that processing takes place, access, correction, anonymization, blocking or deletion, portability, withdrawal of consent, and information about sharing with third parties.
The data protection officer (encarregado) and the channel for requests are the contact in section 10. The supervisory authority is the ANPD (gov.br/anpd).
Mexico
This document also serves as the privacy notice (aviso de privacidad) under the LFPDPPP. The responsable is Hyunii LAB, reachable at the contact in section 10. The information we process is in section 1 and the purposes are in section 2. We do not process personal information for purposes that are not necessary to provide the Service, such as advertising or marketing.
ARCO rights — access (Acceso), rectification (Rectificación), cancellation (Cancelación) and objection (Oposición) may be exercised through the contact in section 10. Consent may be withdrawn the same way.
Changes to this notice are announced within the Service and by updating this document. You have the right to lodge a complaint with the competent supervisory authority.