한국어 버전
SummonerMate Privacy Policy
Effective: 2026-09-15 (last updated: 2026-10-03)
1. Information we collect
- When you sign up: email address, password (stored encrypted by Supabase Auth; our server never stores plaintext passwords)
- When you apply for rank verification: 2 profile/match-history screenshots, in-game nickname, and season (used only for review by our staff; the photos are deleted immediately once reviewed, keeping only a hash of each photo and the review outcome)
- When you sign in with Google or Kakao: the email address, display name and other basic profile information that service provides
- When you set up your profile: display name, bio, profile image URL, language setting
- When you use the service: community posts/comments you write, item builds you save, favorited champions/items, like/follow relationships, notification history
- When you use 1:1 chat: the messages, photos and stickers you exchange with the other person
- When you purchase points (in-app purchase): the product purchased, purchase time, and the receipt token needed to verify the purchase. Payment details such as card numbers are handled directly by Google Play and never reach our server.
- When you opt into push notifications: a device push token (FCM token) used to deliver notifications
- When you view a post: we process the post ID and the view request to keep a per-post view count. We do not keep a separate list of viewers or a per-account/per-device view history on the server. The app stores the post ID and the last count attempt time on-device only, to cut down duplicate counting over a 30-minute cooldown; expired entries are cleaned up locally and this record (or any separate device identifier) is never sent to the server. If you're signed in, your existing session is used to check access.
2. Purpose of use
We use this information only for member identification and sign-in, providing community/build-sharing features, 1:1 chat, follow/notification features, showing post view counts, processing and verifying point purchases (in-app purchases), and handling reports of inappropriate content.
3. Storage and processors
Account and service data is stored and processed via Supabase (database/auth, ap-northeast-1 region) and Google Cloud Platform (API server hosting, asia-northeast1 region). Signing in with Google or Kakao uses that provider's own OAuth sign-in; push notifications are delivered via Firebase Cloud Messaging. Point purchases (in-app purchases) are processed through Google Play Billing, and we never store your payment method details ourselves. Using "View translation" on a post or comment sends its title and body to Google Cloud Translation for translation; the result is cached on our server for up to 30 days so the same text isn't translated twice. When you watch a rewarded ad to earn points, Google AdMob processes device information such as the advertising identifier to serve and measure the ad; users in the EEA, UK and Switzerland choose whether to consent to personalized ads through Google's consent screen (UMP) before any ad is shown. All of the services above encrypt data at rest under their own security policies.
Payment records (product purchased, purchase time, receipt token) are kept for 5 years as required by law; when an account is deleted, the record is unlinked from the account (so it can no longer identify you) and kept until that period passes, then destroyed.
Posts, comments and builds you delete yourself stop being visible to other users immediately, are kept for 30 days in case a report needs reviewing, then permanently deleted.
4. Disclosure to third parties
We do not sell your information to third parties. Information is shared with the services listed in Section 3 (Supabase, Google Cloud, Firebase, Google Play, Google AdMob) only to the extent needed to provide each service.
5. Your rights
You can edit your information from the profile screen in the app. You can delete your account and personal data yourself from Account > Delete account in the app; if you can't use the app, email us at the address below and we'll process your request promptly. See Account & data deletion for what is deleted versus retained. You can revisit your rewarded-ad personalization choice anytime from Account > Ad Privacy Settings in the app (shown only to users in the EEA, UK and Switzerland).
6. Notice for users in the EEA, UK and Switzerland (GDPR)
- Controller: This service is operated by Afterglow (an individual developer based in South Korea); see Section 7 for contact details. No separate EU representative has been appointed.
- Legal basis for processing: providing the service itself (sign-up, community, chat, builds, etc.) relies on performance of our contract with you; preventing abuse and handling reports relies on our legitimate interest; push notifications and personalized ads rely on your consent.
- Your rights as a data subject: you have the right to access, rectify, erase and restrict processing of your personal data, the right to data portability, the right to object to processing, and — for anything processed on the basis of consent — the right to withdraw that consent at any time (without affecting the lawfulness of processing before the withdrawal). Email us at the address in Section 7 to exercise these.
- International transfers: as described in Section 3, data is processed mainly in South Korea and Japan (Asia-Pacific regions), which is a transfer outside the EEA. Supabase and Google (including AdMob) apply their own GDPR-recognized safeguards, such as Standard Contractual Clauses.
- Right to lodge a complaint: you may lodge a complaint with your country's data protection supervisory authority.
7. Contact
Contact: afterglow.play.studio@gmail.com