PRIVACY
Privacy policy
How Puzzlog handles personal information.
This English translation is provided for convenience. The Korean version is the original and prevails in case of any discrepancy. 한국어 원문 보기
The latest document could not be checked. This is the bundled version, with the effective date shown below. Please check again later for updates.
zerobacklabs (the “Company”) establishes and publishes this Puzzlog Privacy Policy under applicable law, including the Personal Information Protection Act of the Republic of Korea, to protect data subjects’ personal information and address related concerns.
1. Processing purposes, categories, and retention periods
The Company processes the minimum personal information necessary to provide the Service as follows.
| Purpose | Personal information processed | Collection method | Legal basis | Retention period |
|---|---|---|---|---|
| Registration and account management | Sign-in provider (Google or Apple), provider-issued member identifier, email address, name and profile information (if provided), registration and withdrawal request times | Received from Google or Apple; entered by the user | Article 15(1)(4) of the Personal Information Protection Act | Up to 30 days after withdrawal is requested; destroyed if the request is not canceled |
| Sign-in and service protection | Authentication information, access logs, IP address, device and app information, app installation identifiers | Generated through service use | Article 15(1)(4) of the same Act | As needed for operation and security; members’ information is destroyed when withdrawal becomes final |
| Service provision | Photos and videos registered by members, content registration times, puzzle and theme information | Registered by the user; generated through service use | Article 15(1)(4) of the same Act | Until the user deletes it or withdrawal becomes final |
| Group features | Group joining and leaving records, invitations, content sharing and reaction records | Generated through service use | Article 15(1)(4) of the same Act | Until use of the relevant group or feature ends; destroyed when withdrawal becomes final |
| App error analysis and stability improvements | Error and crash information (error messages and technical information identifying where errors occurred), device model, OS version, app version and build number, error time | Automatically generated when an app error occurs | Article 15(1)(4) of the same Act | Up to 90 days from collection |
| Push notifications | Push notification tokens, device type, group notification preferences, delivery results | Generated through service use | Article 15(1)(4) of the same Act | While notifications are used; delivery stops upon a withdrawal request and information is destroyed when withdrawal becomes final |
| Inquiries, complaints, rights-infringement reports, and privacy rights requests | Email address, inquiry, report or deletion request, attachments, and Company replies | Provided by the user by email | Article 15(1)(4) of the same Act | Until the inquiry or request has been resolved |
Notifications scheduled on the device, such as daily puzzle reminders, are handled on the user’s device, and their settings are not transmitted to the Company.
Guest use
While using the Service without signing in, photos, videos, and puzzle records registered by the user are stored only on the user’s device, not on the Company’s servers.
When a signed-out user retrieves public content such as themes or default puzzle settings, only access logs for those requests remain on the Company’s servers. They are processed for the sign-in and service protection purpose above. App error information is processed for error analysis and stability improvements in the same way as for members.
When the user signs in, photos, videos, and puzzle records stored on the device are transferred to the signed-in account and are then processed for the service provision purpose above.
Social sign-in
For Google sign-in, the Company may receive a member identifier, email address, name, profile photo, and similar information from Google.
For Apple sign-in, the Company may receive a member identifier, email address, name, and similar information from Apple. Some information, such as the name, may be provided only at the first sign-in.
When Apple’s Hide My Email feature is used, the Company may receive an Apple-generated private email relay address instead of the actual email address.
The information actually provided depends on the member’s settings and each provider’s policies.
The Company does not request unique identification information such as resident registration numbers, or sensitive information such as health information, as separate input fields for registration or use. Photos and videos uploaded by members may nevertheless contain sensitive information, as explained in Section 8.
Membership withdrawal and deletion grace period
When a member requests withdrawal, service use, sign-in, and notification delivery stop immediately, and the member’s group-shared content is hidden from other members.
To address accidental or mistaken account deletion, the Company retains the account and User Content in a recoverable state for 30 days from the request. Personal information is used only for account recovery during this period.
Members may cancel the request within 30 days by signing in again or using another method provided by the Company.
If the request is not canceled within 30 days, withdrawal and termination of the service agreement become final. The Company promptly destroys personal information except information that must be retained under applicable law.
If a member explicitly requests immediate deletion during the grace period, the Company verifies identity as necessary and promptly destroys personal information except information subject to legal retention requirements. The account and content cannot then be recovered.
Information subject to a legal retention obligation or a lawful need for retention, such as handling a legal dispute, is retained for the necessary period and then destroyed.
De-identified usage statistics
The Company collects app usage statistics in a form that cannot identify individuals to understand service use and improve features and stability.
Collected items are a device-generated random identifier, app session identifier, type and result of activity (app launches, screen views, puzzle views, photo or video upload starts and results, recap creation and sharing, and use of camera, gallery, recap, and group puzzle features), event time to the minute, OS type, app major and minor version, and sign-in status. Photo or video content, theme names, group information, and location information are not included.
Usage statistics are distinguished only by the device-generated random identifier. The Company does not link them to accounts, device identifiers, or IP addresses. Accordingly, these statistics do not constitute personal information under the Personal Information Protection Act.
Users can turn off the transmission of app usage statistics in the app’s settings.
2. Children under 14
① The Company does not accept members under 14 and does not directly collect their personal information for registration.
② If the Company discovers that a child under 14 has registered, it terminates the account and promptly destroys related personal information.
3. Destruction of personal information
① The Company promptly destroys personal information when it is no longer needed, such as when its retention period expires or its processing purpose is fulfilled.
② For an ordinary withdrawal request, personal information is deemed no longer needed when the 30-day grace period in Section 1 ends and is promptly destroyed, except information that must be retained under other laws.
③ If a member requests immediate deletion during the grace period, the Company verifies identity, ends the grace period, and promptly destroys personal information except information that must be retained under other laws.
④ Information subject to retention under other laws is stored and managed separately from other personal information and destroyed when its retention period ends.
⑤ Electronic files are securely deleted so that they cannot be recovered or reproduced. Photo and video files are also deleted from their storage locations.
4. Provision to third parties
The Company does not, in principle, provide data subjects’ personal information to third parties.
It may do so to the extent permitted by the Personal Information Protection Act, for example where the data subject gives separate consent or a specific legal provision permits it.
5. Outsourcing of personal information processing
The Company entrusts the following processing tasks to service providers.
| Service provider | Entrusted task |
|---|---|
| Amazon Web Services, Inc. | Operation of service servers and storage for photos, videos, and other data |
| 650 Industries, Inc. (Expo) | Relay of push notification delivery |
| Functional Software, Inc. (Sentry) | Collection and analysis of app errors and crashes |
Google and Apple social sign-in services are not processors entrusted by the Company. Rather, the Company receives member identification and related information when members use those sign-in services.
When outsourcing processing, the Company takes measures required by applicable law, including prohibiting processing beyond the entrusted purpose, ensuring safeguards for personal information, and managing and supervising providers.
Changes to entrusted tasks or providers are disclosed through this Privacy Policy.
6. Overseas transfers of personal information
The Company entrusts some processing to overseas providers to provide the Service, and personal information may consequently be transferred abroad.
These transfers involve outsourced processing or storage necessary to enter into and perform a contract with the data subject. The following information is provided under Article 28-8 of the Personal Information Protection Act.
6-1. Service servers and storage
| Item | Details |
|---|---|
| Recipient | Amazon Web Services, Inc. |
| Contact | [email protected] |
| Country | United States |
| Information transferred | Personal information processed on service servers and storage, including account and sign-in information, User Content, and group activity information |
| Timing and method | Transmitted over networks when information is generated or stored during service use |
| Purpose | Operation of service servers and storage for photos, videos, and other data |
| Retention and use | The retention periods specified for each category in Section 1 |
| How to refuse | Stop using the Service and withdraw membership |
| Effect of refusal | Because the transfer is necessary to provide the Service, the Service cannot be used if it is refused |
6-2. Push notification delivery
| Item | Details |
|---|---|
| Recipient | 650 Industries, Inc. (Expo) |
| Contact | [email protected] |
| Country | United States |
| Information transferred | Push notification tokens, device-related information, and information needed for delivery |
| Information that may appear in notifications | Other members’ display names, group names, theme names, and other information necessary for notifications |
| Timing and method | Transmitted over networks when a push notification is sent |
| Purpose | Relay of push notification delivery |
| Retention and use | Tokens: as long as necessary to provide notifications; notification content: as long as necessary to transmit it |
| How to refuse | Do not enable notifications, or disable them in app or device settings |
| Effect of refusal | Push notifications will not be received; other service features remain available |
6-3. App error analysis
| Item | Details |
|---|---|
| Recipient | Functional Software, Inc. (Sentry) |
| Contact | [email protected] |
| Country | United States |
| Information transferred | App errors and crashes, device model, OS version, app version and build number, error time |
| Timing and method | Transmitted over networks when an app error occurs |
| Purpose | App error analysis and stability improvements |
| Retention and use | Up to 90 days from collection |
| How to refuse | Stop using the Service and, for members, withdraw membership |
| Effect of refusal | Because the transfer is necessary for app stability, the Service cannot be used if it is refused |
Collection is limited so that error information does not include identifying information such as IP addresses, photos, videos, or email addresses.
The Company implements safeguards required by applicable law during overseas transfers.
7. Security safeguards
The Company implements necessary technical and organizational safeguards under applicable law, including the Personal Information Protection Act, such as managing access permissions, access controls, transmission protection, and access log management.
8. Possible disclosure of sensitive information and how to keep it private
① The Company does not require members to enter sensitive information such as health information, political opinions, religion, or beliefs as separate information fields.
② Photos and videos registered by members may nevertheless contain sensitive information about themselves or others. If content is shared to a group, that group’s members can view it.
③ Members can limit display to others by not sharing content to groups, deleting registered content, or leaving groups.
④ When a member requests withdrawal, their content is hidden from other members even during the deletion grace period.
⑤ The Company does not separately analyze sensitive information in User Content or use it to infer sensitive characteristics such as health, political opinions, religion, or beliefs.
9. Data subjects’ rights and how to exercise them
① Data subjects may request access, correction, deletion, suspension of processing, withdrawal of consent, and other rights under applicable law.
② Members can use app features to delete photos or videos, leave groups, change display names, disable notifications, and request withdrawal.
③ Even during the 30-day grace period after requesting withdrawal, members may request immediate deletion. After necessary identity verification, the Company promptly deletes information except information that must be retained under other laws. The account and User Content cannot then be recovered.
④ Other privacy requests, including immediate deletion, may be emailed to the privacy officer. The Company communicates the result within the periods and procedures prescribed by applicable law.
⑤ Data subjects may also exercise rights through an authorized representative. The Company may verify the identity or authority of the person making the request where necessary.
⑥ If access, correction, deletion, suspension, or other rights are restricted by applicable law, the Company explains the reasons to the data subject.
10. Privacy officer
The Company designates the following privacy officer to oversee processing and protection and to handle privacy inquiries, complaints, and remedies.
| Item | Details |
|---|---|
| Privacy officer | Choi Junwoo (최준우) |
| [email protected] |
Data subjects may use this contact for privacy inquiries, complaints, remedies, exercise of rights, or immediate deletion requests arising from use of the Service.
11. Remedies for privacy infringements
Data subjects may contact the Company or request advice or dispute mediation from the following bodies regarding privacy infringements.
| Organization | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center | 118 (no area code within Korea) | privacy.kisa.or.kr |
12. Changes to this Privacy Policy
① This Privacy Policy applies from October 8, 2026.
② If the policy changes, the Company publishes the changes and effective date on the service information website or similar channels. Changes that materially affect data subjects’ rights are separately communicated through reasonable means such as in-app notices.
③ Where previous policies exist, the Company makes them available through the service information website or similar channels so data subjects can review them.
Revision history
| Effective date | Main changes |
|---|---|
| October 8, 2026 | Added guest use and de-identified usage statistics; updated push notification processing categories |
| September 28, 2026 | Initial policy |