스도쿠 키우기 개인정보처리방침

시행일: 2026년 8월 26일 · 버전: 1.7 · English

스도쿠 키우기 운영자(이하 “운영자”)는 서비스 제공에 필요한 개인정보만 처리합니다. 이 방침은 운영자가 어떤 정보를 왜 처리하는지와 이용자의 권리를 설명합니다.

1. 개인정보처리자와 문의처

개인정보처리자: 스도쿠 키우기 운영자
개인정보 보호 담당: 스도쿠 키우기 운영자
이메일: osm.dev.io@gmail.com

2. 처리하는 개인정보와 목적

처리 목적 처리 항목
게스트 계정 생성과 서비스 제공 서비스가 생성한 사용자 식별자와 닉네임, 임의의 설치별 게스트 생성 식별자(서버에는 해시값으로 저장), 계정 생성 시각
선택적인 소셜 계정 연결·인증 Google 또는 Apple 계정의 고유 식별자, 인증된 이메일 주소(Apple 비공개 릴레이 주소 포함), 표시 이름, 연결 시각
게임 진행·성장·순위 제공 게임 세션과 완료·실패·포기 기록, Brain Score, 스도쿠 코인과 거래 기록, 성장 구매 기록, 연속 기록, 힌트 사용 기록
세션 보안과 계정 접근 유지 게스트 또는 로그인 세션 정보, 해시 처리된 Refresh Token, 발급·갱신·폐기 시각
인증 요청 남용 방지 클라이언트 IP와 일정 시간 동안의 게스트 생성·세션 갱신 요청 횟수
고객 문의 처리 문의 본문, 앱 버전·빌드 번호, 플랫폼, 운영체제 버전, 접수 시각
광고 제공과 힌트 광고 검증 광고 플랫폼, 광고 단위 식별자, 보상형 광고 거래·네트워크 식별자와 힌트 청구 정보
선택적인 푸시 알림 등록·발송과 전달 오류 확인 계정 알림 선호도, 서비스 사용자와 연결된 임의의 설치 식별자, Expo Push Token, 플랫폼, 앱 환경·언어, 등록·갱신·비활성 시각과 사유, 연속 기록 알림 발송 시 닉네임·현재 연속 일수가 포함된 제목·본문, 임의의 알림 delivery 식별자, 일별 중복 방지·전달 확인·분석 전송 기록과 일시적인 ticket·receipt 상태·오류 코드
서비스 이용 분석과 품질 개선 서비스 사용자 식별자, 임의의 앱 인스턴스·익명 식별자, 앱·기기·운영체제 정보, 대략적인 지역, 앱 실행·foreground 복귀·background 전환·설치·업데이트, 화면 전환, 인증 경로, 게임 시작·재개·결과, 재화 획득·사용, 광고 동작, 푸시 전달 확인·열기 등 이용 이벤트와 별도 동의 시 일부 앱 화면·터치 위치 기록

운영자는 생년월일이나 정확한 나이를 별도로 수집하지 않습니다. 분석 서비스에는 서버가 발급한 서비스 사용자 식별자를 Google Analytics User-ID와 PostHog 사용자 식별자로 전송해 로그인 전후와 여러 이용 세션을 계정 단위로 분석합니다. 이메일, 닉네임, Google·Apple 계정 식별자, 사용자가 입력한 내용, 퍼즐 내용과 게임·구매·광고 거래 식별자는 분석 속성으로 보내지 않습니다. 푸시 전달 확인 대비 열기 비율에는 계정·설치·token과 분리된 임의의 일회성 delivery 식별자, 발송 기준일과 알림 유형만 사용하며 발송 언어와 제목·본문은 보내지 않습니다. 세션 리플레이에서는 이미지·입력값·닉네임을 가리고 인증·계정·내 정보·고객지원·광고 화면의 기록을 중단하지만, 그 밖의 일반 게임 화면과 터치 위치는 기록에 포함될 수 있습니다. 문의 본문에는 이용자가 직접 연락처 등 개인정보를 입력할 수 있으므로, 필요하지 않은 민감한 정보를 적지 않도록 유의해 주세요. 순위 화면에서는 서비스 닉네임, Brain Score와 순위를 다른 이용자에게 표시합니다. 인증 요청 제한에 사용하는 클라이언트 IP는 Nginx 메모리의 일시적인 요청 제한 상태에만 사용하며 애플리케이션 데이터베이스나 access log에 저장하지 않습니다. 운영체제 알림 권한 상태와 권한을 요청했는지 여부는 기기에만 저장합니다. 서버에는 운영체제 권한이 아니라 계정 전체의 알림 선호도만 보관합니다.

3. 보유·이용 기간과 파기

계정과 계정에 연결된 게임·문의 정보는 계정을 삭제할 때까지 보관하며, 미사용 기간만으로 자동 삭제하지 않습니다. 소셜 계정에 연결하지 않은 게스트는 앱을 삭제하거나 기기를 바꾸면 다시 접근하거나 복구할 수 없지만, 앱 삭제만으로 서버의 계정과 데이터가 삭제되지는 않습니다. 앱을 삭제하기 전 내 정보 → 계정 삭제에서 게스트 계정을 삭제하거나 소셜 계정을 연결해 주세요. 이용자가 앱의 내 정보 → 계정 삭제 또는 소셜 계정에 연결된 경우 공개 계정 삭제 페이지에서 삭제를 완료하면 운영 데이터베이스에서 계정, 로그인 정보, 게임·성장·순위·문의 정보를 즉시 삭제합니다. 앱이 삭제 완료 결과를 확인하면 해당 계정의 인증·게임 데이터를 기기에서도 제거하며, 정리 대기 상태가 기록된 뒤 기기 저장소 정리가 일시적으로 실패하면 다음 앱 실행에서 다시 시도합니다. 소셜 계정 연결 중 기존 진행과 게스트 진행 가운데 하나를 보존하기로 확정한 경우에도 선택하지 않은 계정의 운영 데이터베이스 정보는 같은 범위로 즉시 삭제하고, 앱이 완료 결과를 확인한 뒤 해당 기기 데이터를 정리합니다. 푸시 알림 설치 정보는 권한 거부, 로그아웃, 계정 삭제 또는 token 교체 때 삭제하거나 갱신합니다. 전달 공급자가 DeviceNotRegistered를 반환하면 해당 token을 다시 사용하지 않도록 설치 기록을 비활성화합니다. 비활성 설치 기록은 같은 설치가 다시 등록되면 갱신되고, token 교체 과정에서 대체되거나 계정 삭제로 제거되기 전까지 계정 정보와 함께 보관합니다. 연속 기록 알림의 유형·임의의 delivery 식별자·발송 기준일·대상 계정·설치·전달 확인과 분석 전송 상태는 일별 중복 방지와 전달 확인 대비 열기 집계를 위해 최대 35일, 발송 receipt와 오류 상태는 발송 뒤 최대 24시간만 보관합니다. 앱 삭제만으로 서버가 즉시 알 수 없는 경우에는 전달 공급자가 등록 해제를 알린 뒤 해당 token 사용을 중단합니다. Firebase Analytics의 이벤트·사용자 수준 데이터는 14개월, PostHog 제품 이벤트는 1년, PostHog 세션 리플레이는 30일 동안 보관합니다. 앱에서 로그아웃·계정 전환·계정 삭제를 완료하면 해당 기기의 분석 식별 상태를 초기화하지만, 분석 공급자에 이미 전송된 이벤트·세션 리플레이의 별도 삭제를 요청하지는 않습니다. 따라서 삭제 전에 전송된 자료와 이미 만들어진 집계 통계는 각 보관 기간까지 남을 수 있습니다. 공개 계정 삭제 페이지는 이용자의 기기를 제어할 수 없으므로 기기의 분석 식별 상태를 초기화하지 못합니다. 운영자는 법령상 보관 의무가 있는 정보가 확인되는 경우에만 해당 법령이 정한 기간 동안 보관합니다.

4. 외부 서비스와 개인정보 처리

외부 서비스 이용 목적
Google 이용자가 선택한 경우 Google 계정을 연결하고 인증합니다.
Apple 이용자가 선택한 경우 Apple 계정을 연결하고 인증합니다.
Expo Push Service, Apple APNs 및 Google FCM 이용자가 운영체제 알림을 허용한 경우 기기 token을 등록하고 푸시 알림과 전달 결과를 중계합니다.
Google AdMob 및 User Messaging Platform 광고를 제공하고, 필요한 경우 광고 개인정보 선택 사항을 표시합니다.
Google Firebase Analytics 계정과 앱 이용 흐름, 유입·플랫폼·기능·광고 동작을 집계해 서비스 품질을 분석하고 iOS 최초 실행 전환을 측정합니다.
PostHog Cloud EU 계정별 이용 흐름·재방문·기능 사용과 푸시 전달 확인 대비 열기를 분석하고, 별도 동의한 일부 세션의 화면·터치 기록과 Feature Flag를 처리합니다.
Cloudflare 서비스의 HTTPS 연결·보안·공개 문서 제공을 지원하고, PostHog Managed reverse proxy에서 분석 요청을 PostHog Cloud EU로 전달합니다.

Expo Push 국외 처리 안내

이전 근거 개인정보 보호법 제28조의8 제1항 제3호 가목에 따른, 이용자가 요청한 알림 서비스 계약 이행에 필요한 처리위탁·보관
이전 항목 기기 푸시 token과 Expo Push Token, Firebase installation ID, Expo 프로젝트 식별자, 알림 제목·본문과 ticket·receipt 식별·상태 정보. Expo와 하위 전달 공급자는 자체 정책에 따라 IP 주소 등 네트워크·기기 정보를 처리할 수 있습니다.
이전 국가·시기·방법 Expo는 미국, Apple은 미국을 포함한 전 세계 시설, Google FCM은 Google 또는 그 처리자가 시설을 운영하는 전 세계 국가에서 처리할 수 있습니다. 알림 허용 뒤 token 등록과 알림 발송·전달 확인이 필요한 시점에 암호화된 통신으로 전송합니다.
이전받는 자 Expo(650 Industries, Inc., 문의처), Apple Inc.(APNs, 개인정보 문의), Google LLC(FCM, 개인정보 문의)
목적·기간 APNs·FCM으로 알림과 전달 결과를 중계합니다. Expo는 token을 서비스 제공에 합리적으로 필요한 기간 처리하고, 알림 내용은 전달에 필요한 동안 메모리와 메시지 대기열에서만 처리하며 데이터베이스에는 저장하지 않는다고 고지합니다. FCM은 Firebase installation ID 삭제 요청 뒤 운영·백업 시스템에서 제거하기까지 최대 180일이 걸릴 수 있다고 고지합니다. Apple과 Google의 그 밖의 처리 기간은 각 공급자 정책을 따릅니다.
거부 방법·효과 첫 운영체제 권한 요청에서 거부하거나 언제든 내 정보 → 알림에서 계정 수신 여부를 바꾸고 기기 설정으로 이동할 수 있습니다. 거부하면 푸시 알림을 받을 수 없지만 게임 이용에는 영향이 없습니다.

PostHog와 Managed reverse proxy 국외 처리 안내

이전 근거 일반 제품 이벤트: 개인정보 보호법 제28조의8 제1항 제3호 가목에 따른 계약 이행에 필요한 처리위탁·보관
세션 리플레이: 같은 조 제1항 제1호에 따른 별도 동의
이전 항목 서비스 사용자 식별자, 앱 인스턴스·익명 식별자, 앱·기기·운영체제 정보, 대략적인 지역, 서비스 이용 이벤트와 별도 동의 시 일부 앱 화면·터치 위치 기록
이전 국가·시기·방법 Production 앱 사용 중 필요한 시점에 암호화된 네트워크 통신으로 전송합니다. 분석 요청은 사용자와 가까운 Cloudflare 데이터센터에서 먼저 처리되며 네트워크 상태에 따라 처리 국가가 달라질 수 있고 EU로만 제한되지 않습니다. 이후 독일의 PostHog EU 데이터 지역으로 전달됩니다.
이전받는 자 PostHog Inc. (privacy@posthog.com) 및 하위 처리자 Cloudflare, Inc. (dpo@cloudflare.com)
목적·기간 Cloudflare는 분석 요청의 TLS 연결과 PostHog 전달을 처리하며 edge에서 요청 본문을 캐시하거나 요청 로그로 보관하지 않습니다. PostHog는 제품 이용 흐름·재방문·기능 사용 분석, Feature Flag와 선택적 세션 리플레이를 제공하고 제품 이벤트는 1년, 세션 리플레이는 30일 보관합니다.
거부 방법·효과 일반 제품 이벤트는 서비스 운영에 포함되어 앱 안의 별도 거부 기능을 제공하지 않으며 앱을 이용하지 않는 방법으로 전송을 피할 수 있습니다. 세션 리플레이는 제안 화면에서 거절하거나 언제든 내 정보 → 앱 개선에 참여에서 끌 수 있고, 거절해도 게임 이용에는 영향이 없습니다.

광고 SDK는 이용자의 선택과 해당 제공자의 정책에 따라 광고 관련 데이터를 처리할 수 있습니다. Firebase Analytics의 광고 저장, 광고 사용자 데이터와 광고 개인화 동의는 거부 상태로 유지하고 Google Signals와 광고 개인화에는 사용하지 않습니다. Firebase Analytics는 iOS 앱 설치 뒤 최초 실행 전환을 집계하기 위해서만 Google Ads와 연결됩니다. iOS 전환 측정은 ATT·IDFA나 이용자가 제공한 계정 정보를 사용하지 않고 기기 안에서 처리한 비식별 임시 이벤트 데이터를 사용합니다. Google의 개인정보 처리에 관한 자세한 내용은 Google 개인정보처리방침에서 확인할 수 있습니다. Apple의 개인정보 처리에 관한 자세한 내용은 Apple 개인정보 보호정책에서 확인할 수 있고, Expo Push의 처리에 관한 내용은 Expo Privacy Policy, PostHog의 처리에 관한 내용은 PostHog Privacy Notice, Cloudflare의 처리에 관한 내용은 Cloudflare Privacy Policy에서 확인할 수 있습니다. 앱의 PostHog 분석 요청은 자체 서브도메인의 Managed reverse proxy를 통해 Cloudflare edge를 거쳐 PostHog Cloud EU로 전달됩니다. PostHog는 EU(Frankfurt)에서 분석 정보를 처리하며 네트워크 요청의 IP로 대략적인 지역을 계산한 뒤 원시 IP를 버리도록 설정합니다. Google, Apple, Expo, PostHog와 Cloudflare는 대한민국 밖에서 정보를 처리할 수 있으며, 각 제공자의 처리 위치·보유 기간·이용자 권리는 해당 제공자의 정책과 서비스 설정에 따릅니다. 운영자는 이용자의 개인정보를 판매하거나, 위 목적 외로 제3자에게 제공하지 않습니다. 다만 서비스 운영을 위해 접근 권한을 제한한 Telegram 운영 그룹에 신규 가입 알림을 보냅니다. 모든 가입 알림에는 서비스가 기록한 발생 시각과 내부 사용자 ID를 포함합니다. 게스트 가입은 게스트 여부를, Google·Apple 가입 또는 게스트의 소셜 연결은 검증된 이메일과 OAuth 제공자를 함께 포함합니다. OAuth subject, 인증 정보와 요청 본문은 포함하지 않습니다.

5. 개인정보 보호를 위한 조치

운영자는 개인정보 접근을 필요한 업무 범위로 제한하고, 인증 정보와 비밀값을 저장소와 일반 로그에 남기지 않으며, HTTPS 통신과 접근 권한 관리 등 개인정보 보호를 위한 기술적·관리적 조치를 적용합니다.

6. 자동 수집 장치

운영자는 공개 문서에서 자체 쿠키를 사용하지 않습니다. 다만 Google AdMob 및 User Messaging Platform은 광고 제공과 개인정보 선택 사항을 위해 자체 기술을 사용할 수 있으며, 이에 관한 내용은 Google의 정책을 따릅니다. 신규 계정은 생성 뒤 첫 홈 진입에서, 업데이트한 기존 이용자는 알림 권한이 아직 결정되지 않은 경우 다음 홈 진입에서 운영체제 알림 권한을 한 번 요청합니다. 별도 앱 설명 화면은 먼저 표시하지 않으며, 거부하면 자동으로 다시 묻지 않습니다. 요청 여부는 해당 기기에만 저장됩니다. 내 정보 → 알림은 계정 전체의 사용자 알림을 켜거나 끄며, 현재 기기의 운영체제 권한이 없으면 꺼진 상태로 표시됩니다. 이를 켜려 하면 권한 요청 또는 운영체제 앱 설정으로 안내하고, 권한을 허용한 뒤 돌아오면 계정 알림도 켭니다. 한 기기의 운영체제 권한 변경은 다른 기기의 권한을 바꾸지 않습니다. 운영용 iOS·Android 앱은 Firebase Analytics와 PostHog 제품 이벤트를 자동으로 사용합니다. 일반 분석 이벤트를 위한 별도의 최초 동의 체크박스나 앱 내부 중단 설정은 제공하지 않습니다. 세션 리플레이는 첫 퍼즐을 완료한 뒤 별도로 동의한 기기에서만 시작하며, 동의한 세션 중 원격 설정으로 선택한 20%만 기록합니다. 거절하면 자동으로 다시 묻지 않으며 내 정보 → 앱 개선에 참여에서 다시 켜거나 언제든 끌 수 있습니다. 끄면 진행 중인 기록은 즉시 중단되고 기존 기록은 30일 안에 삭제됩니다. 이 선택은 해당 기기에만 저장됩니다. 개발·미리보기 앱과 웹에서는 분석 이벤트와 세션 리플레이를 보내지 않습니다.

7. 이용자의 권리와 행사 방법

이용자는 자신의 개인정보에 대해 열람, 정정, 삭제, 처리 정지를 요청할 수 있습니다. 앱 또는 공개 계정 삭제 페이지에서 직접 계정을 삭제할 수 있으며, 그 밖의 요청은 본인 확인에 필요한 최소한의 절차를 거쳐 위 문의처로 접수할 수 있습니다. 다른 이용자의 개인정보나 계정 존재 여부는 안내하지 않습니다.

8. 권익 침해 구제

개인정보 침해에 관한 상담·분쟁 조정이 필요하면 개인정보침해 신고센터, 개인정보 분쟁조정위원회 또는 수사기관에 도움을 요청할 수 있습니다. 운영자는 이용자의 문의와 불만을 위 문의처에서 우선 처리합니다.

9. 방침의 변경

이 방침은 법령, 서비스 또는 개인정보 처리 방식이 바뀌는 경우 변경될 수 있습니다. 변경 시 공개 문서에 버전과 시행일을 표시합니다.

10. 문의

개인정보 처리와 관련한 문의는 osm.dev.io@gmail.com으로 보내 주세요.


Sudoku Grow Privacy Policy

Effective: August 26, 2026 · Version 1.7 · 한국어

The operator of Sudoku Grow processes only the information needed to provide, protect, advertise, and improve the service. Contact: osm.dev.io@gmail.com.

1. Information and purposes

The service processes account and authentication details, game sessions and progress, Brain Score, Sudoku Coin and upgrade records, streaks, hint records, support inquiries, temporary IP-based abuse-prevention state, and advertising or rewarded-hint records. Optional Google or Apple connection processes the provider identifier, verified email, display name, and connection time. The service stores an account-wide notification preference. If the user allows system notifications, it also processes a random installation identifier linked to the service user, an Expo Push Token, platform, native app environment and language, registration or disable times, and transient ticket or receipt status. A streak reminder send processes a title and body containing the nickname and current streak length, plus a random delivery identifier and daily delivery, provider-confirmation, and analytics-delivery state.

The Production iOS and Android apps use Google Firebase Analytics and PostHog to understand product usage and quality. They may process the service-issued user identifier, a random app-instance or anonymous identifier, app, device and operating-system information, approximate location, and events such as app launches, foreground returns, background transitions, installations, updates, screen changes, authentication paths, game starts, resumes and outcomes, virtual-currency earning or spending, advertising lifecycle, and push delivery confirmation or opening. The service user identifier is set as Google Analytics User-ID and the PostHog user identifier to connect pre-login and account activity. Analytics properties do not contain email, nickname, Google or Apple identifiers, user input, puzzle content, or game, purchase, or ad-transaction identifiers. Push open-rate analysis uses only a random one-time delivery identifier, scheduled date, and notification type separated from the account, installation, and token; it does not send the delivery language, title, or body.

With separate device-level consent, PostHog may also record some app screens and touch positions. Images, input values, and nicknames are masked, and recording stops on authentication, account, Profile, support, and advertising screens. Other ordinary game screens and touch positions may be visible in a replay.

2. Retention and deletion

Account-linked data is retained until the account is deleted and is not automatically removed merely because it is inactive. Deleting the app does not delete a guest account on the server. Use Profile → Delete account before uninstalling, or first connect a social account. An account connected to Google can also be deleted through the public deletion page.

Push installation data is removed or updated after permission denial, logout, account deletion, or token replacement. If the delivery provider returns DeviceNotRegistered, the installation record is disabled so that token is not used again. A disabled record is updated if that installation registers again and remains with the account until it is replaced during token rotation or removed on account deletion. Streak-reminder type, random delivery identifier, scheduled date, account, installation, provider-confirmation state, and analytics-delivery state are retained for no more than 35 days to prevent duplicate daily sends and measure confirmed-delivery open rates. Delivery receipt and error state is retained for no more than 24 hours. Uninstalling alone may not immediately notify the server; the token is disabled after the delivery provider reports it as no longer registered.

Firebase Analytics event- and user-level data is retained for 14 months, PostHog product events for one year, and PostHog session replays for 30 days. Logging out, switching accounts, or completing deletion inside the app resets that device's analytics identity. We do not separately request deletion of events or replays already sent to the analytics providers, so they and aggregate statistics may remain for the applicable retention period. The public deletion page cannot control the user's device and therefore cannot reset its analytics identity.

3. External services

Google supports optional sign-in, Firebase Analytics and limited iOS first-open conversion measurement, AdMob advertising, User Messaging Platform privacy choices, and FCM notification delivery. Apple supports optional sign-in and APNs notification delivery. Expo Push Service registers push tokens and relays notifications and delivery status through infrastructure in the United States to Apple APNs and Google FCM. Apple may process personal data in facilities around the world and generally stores it in the United States. FCM runs on Google's global infrastructure and may process data wherever Google or its processors maintain facilities. Push processing may include a native device token, Expo Push Token, Firebase installation ID, Expo project identifier, network and device information, notification content, and ticket or receipt details. Expo states that notification content is kept only in memory and message queues for delivery, not in a database, and retains information only as reasonably necessary for the service. Firebase states that deletion of a Firebase installation ID from live and backup systems may take up to 180 days after the customer requests deletion. See the Expo Privacy Policy and Expo contact page. PostHog Cloud EU supports product analytics, optional session replay, and Feature Flags. Analytics requests are sent through a PostHog Managed reverse proxy on our own subdomain. Cloudflare processes the TLS connection and forwards the requests to PostHog Cloud EU without caching the request content or retaining request logs at the edge. The Cloudflare edge location is selected near the user and is not restricted to the EU. After forwarding, PostHog processes analytics data in the EU (Frankfurt) and is configured to discard the raw IP address after deriving approximate location. Cloudflare also supports HTTPS, security, and public documents. These providers may process information outside Korea under their own policies. See the Google Privacy Policy and Apple Privacy Policy, and the PostHog Privacy Notice and Cloudflare Privacy Policy. We do not sell personal information. Limited signup notices are sent to an access-controlled operator Telegram group. They include the event time, internal service user ID and signup path, plus the verified email for Google or Apple signup or linking. They do not include OAuth subject values, credentials, or request bodies.

Firebase Analytics advertising storage, ad user data, and ad personalization consent stay denied. Analytics is not connected to Google Signals and is not used for ad personalization. Firebase Analytics is linked to Google Ads only to measure the first open after an iOS app installation. This iOS conversion measurement uses de-identified, temporary event data processed on the device without ATT, IDFA, or user-provided account information. AdMob and UMP may separately process advertising information according to the user's choices and Google's policies.

4. Automatic collection and choices

The public website does not set first-party cookies. The Production iOS and Android apps automatically use Firebase Analytics and PostHog product events without a separate first-run checkbox or an in-app Analytics off switch. Session replay starts only after separate consent following the first completed puzzle and records a remotely selected 20% of consented sessions. If declined, the app does not ask again automatically. The device-only choice can be enabled or disabled at any time under Profile → Help improve the app. Disabling it stops the current recording; existing replays are deleted within 30 days. Development, Preview, and web builds do not send analytics events or session replays. Where required, advertising privacy options remain available separately for AdMob.

After a new account is created, the app directly requests system notification permission on the first Home entry. An existing user whose permission is still undetermined receives the same request once after updating. The app does not automatically ask again after a denial. The attempt is stored only on that device. The single Profile → Notifications switch controls the account-wide preference and appears off when system permission is not granted on the current device. Trying to turn it on requests permission or opens system app settings; after permission is granted and the app resumes, the account preference is enabled. Changing system permission on one device does not change it on another. Refusing notifications does not affect gameplay.

5. Your rights and security

You may request access, correction, deletion, or restriction by using the app, the public deletion page where available, or the contact address above. We apply HTTPS, restricted access, and secret-handling controls. Requests and complaints are handled first through osm.dev.io@gmail.com. This policy may change when law, the service, or processing changes; the published version and effective date will be updated.