Artgraph Privacy Policy

Privacy Policy

Artgraph Privacy Policy

Draft revision: September 13, 2026 Announcement and effective dates: September 17, 2026

This English version is provided for convenience. If there is any inconsistency between the English and Korean versions, the Korean version will prevail.

Artgraph (hereinafter, the “Operator”) values users’ personal information and complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws and regulations.

This Privacy Policy applies to the mobile games and related services provided by the Operator (collectively, the “Service”). It explains why and how personal information is processed and the measures taken to protect it.

Article 1. Purposes, Categories, and Legal Bases of Processing

The Operator processes the minimum personal information necessary for the following purposes.

Purpose Categories of Personal Information Legal Basis
User identification, login, and account linkage Internal user identifier, BACKND member identifier, and, when Google Play Games Services is used, Player ID, authentication result, server authentication code, and nickname Formation and performance of the Service agreement
Provision of game services Game progress, owned heroes, equipment and items, in-game currency, achievements, rankings, mailbox data, access records, sanction records, and other game-use data Performance of the Service agreement
Verification of in-app purchases, purchase restoration, and refunds Purchased product, purchase date and time, app marketplace order number, receipt or purchase token, and purchase or refund status Performance of a contract and compliance with legal obligations
Service operation, quality improvement, and security IP address, access date and time, access logs, device model, operating system, app version, language and country settings, app installation identifier, error, crash and diagnostic information, and Service-use records Performance of the Service agreement and the Operator’s legitimate interests
Service analytics and statistics App launches, screen transitions, button selections, game events and usage records, acquisition source, campaign information, app installation identifier, and a pseudonymous identifier derived from the internal account ID The Operator’s legitimate interests or user consent where required
Advertising and advertising performance measurement Advertising identifiers such as ADID and IDFA, IP address and approximate location inferred from it, device and app information, ad requests, impressions, clicks and views, diagnostic information, and app events such as tutorial completion, product views and purchases (product identifier, quantity, amount and currency) Processing permitted by law or user consent where required
Reward delivery and prevention of duplicate or fraudulent claims Account and game-save identifiers, reward attempt identifier, offer and reward identifiers, reward date and time, and delivery status Performance of the Service agreement and the Operator’s legitimate interests
Customer inquiries and complaint handling Email address, internal user identifier or nickname, inquiry details, attachments, device information, operating system, and app version Processing requested by the user or user consent

The Operator does not directly collect or store payment method information such as card or bank account numbers. Such information is processed directly by app marketplace payment providers, including Google Play.

The information above may be generated automatically during use of the Service, entered directly by the user, or processed through third-party SDKs and platforms integrated into the Service.

Article 2. Retention Periods

The Operator destroys personal information without undue delay when the purpose of processing has been achieved. Personal information may be retained for a longer period when required by law or separately notified to the user.

Information or Record Retention Period
Member identifiers and game data Until account deletion is completed. Minimal records needed to confirm deletion and prevent duplicate processing may be retained separately for that purpose
Account information processed through BACKND Until the account-deletion request has been processed. No seven-day withdrawal grace period is applied in the app. Records required by law or needed for payment, refund or fraud disputes are retained separately for the applicable period
Google Play Games Services server authentication code Until authentication is completed, after which it is destroyed without undue delay
General customer inquiry records One year after the inquiry is resolved
Access records used for security and prevention of improper use Three months from creation
Firebase Analytics data For the period determined by the Firebase Analytics data-retention settings and Google’s applicable service policy
Advertising-provider data and Meta app events Processed by Google, Unity and Meta for the periods described in their privacy policies, taking into account the purpose, deletion requests, security and legal obligations. Provider policies and contacts are listed in Articles 5 and 6
Game reward-delivery records Until the reward-delivery and duplicate-claim prevention purposes have been fulfilled. Records needed for a dispute or legal obligation are retained separately for the applicable period
Records concerning labeling and advertising Six months
Records concerning contracts or withdrawal of offers Five years
Records concerning payment and supply of goods or services Five years
Records concerning consumer complaints or dispute resolution Three years

Information retained under applicable law is stored separately and is not used for any purpose other than the legally required purpose.

Article 3. Provision to Third Parties

The Service uses Google, Unity and Meta services for advertising, app analytics and performance measurement. These providers may receive information through integrated SDKs or process it for their own purposes, as described in Articles 5 and 6. Other provision to third parties is limited to cases where:

  1. the user has given prior consent;
  2. applicable law specifically requires or permits such provision;
  3. the provision is necessary to deliver a service requested by the user and is supported by an applicable legal basis; or
  4. a competent investigative or administrative authority makes a lawful request.

Where consent is required for third-party provision or overseas transfers, this policy does not replace that consent. The recipient, purpose, information, retention and available controls are described in Articles 5 and 6.

Article 4. Outsourcing of Personal Information Processing

The Operator may outsource personal information processing as follows to provide the Service efficiently.

Service Provider Outsourced Work Retention Period
AFI Inc. (BACKND) Member authentication and account management, storage and operation of game data, receipt verification, service operation, and incident response Until account deletion or termination of the outsourcing agreement, unless a longer period is required by law or the applicable service policy
Google LLC (Firebase Analytics) Service analytics and statistics using app events and pseudonymous identifiers The Firebase Analytics data-retention settings and applicable service policy
Google LLC (Firebase Remote Config) Delivery of app configuration and feature settings Until the configuration-delivery purpose is fulfilled or the applicable service retention period expires
Google LLC (Cloud Firestore and Cloud Functions) Game-data storage and synchronization, purchase verification, currency transactions, account-deletion processing, and server operation Until account deletion or termination of the outsourcing agreement; payment, refund and other legally required records are retained separately for the applicable period. Minimal deletion-confirmation records may be retained separately for that purpose

When entering into an outsourcing agreement, the Operator includes provisions required by Article 26 of the Personal Information Protection Act, including restrictions on processing beyond the outsourced purpose, safeguards, restrictions on re-outsourcing, supervision, and liability.

Article 5. Overseas Processing and Transfers

Personal information may be transferred overseas or directly collected and processed by overseas providers through SDKs and platforms integrated into the Service.

1. Google LLC

2. Unity Technologies

3. Meta Platforms, Inc.

Users may request withdrawal of consent or suspension of optional advertising or analytics processing through available provider controls or help@artgraph.kr. The app’s advertising privacy options, when available, apply to the advertising services covered by that form; they do not automatically disable all Firebase or Meta App Events processing. See Article 6 for settings and their limits.

Refusing overseas processing that is essential for login or game-data storage may restrict account linkage, data restoration, or other parts of the Service. Refusing advertising processing may result in non-personalized or limited advertising instead of personalized advertising.

Article 6. Online Behavioral and Advertising Information

The following online behavioral information may be processed for advertising and advertising performance measurement.

Provider Information That May Be Processed Purpose
Google AdMob Advertising identifier, IP address and approximate location inferred from it, device and app information, ad impressions, clicks, video views, and diagnostic information Advertising, frequency capping, performance analysis, and fraud prevention
Unity Ads Advertising identifier, IP address and approximate location inferred from it, device and app information, advertising interactions and diagnostic information Advertising, performance analysis, service operation, security and fraud prevention
Meta Audience Network Advertising and device identifiers, IP address, device and app information, ad requests and interactions, and diagnostics Advertising delivery, attribution, performance measurement and fraud prevention
Meta App Events App launch, registration method, tutorial completion, product view, purchase initiation and completion, return-visit events, product identifier and quantity, purchase amount and currency, player level, app and device information and advertising identifiers App-use and purchase analysis, attribution and advertising performance measurement

Where consent is required by law, personalized advertising is provided only after consent has been obtained. Users who do not consent may receive non-personalized or limited advertising.

Rewarded-ad viewing is optional, but the app may initialize advertising SDKs and preload ads before the user selects a watch button, subject to applicable consent requirements. Meta App Events also records app and purchase events separately from ad viewing. Declining to watch an ad does not, by itself, stop all advertising or analytics data processing.

The Operator sends purchase amount, currency and product information to Meta for measurement, but does not include raw game purchase receipts, transaction hashes or the internal account ID in its Meta event parameters. Firebase Analytics uses a pseudonymous account identifier; pseudonymization is not the same as anonymization. The game separately stores records needed to deliver ad rewards and prevent duplicate claims.

Users may manage advertising identifiers or request restrictions through:

  1. privacy or advertising settings in Android or iOS;
  2. the app’s advertising privacy options, where available for the user’s region and consent status;
  3. app tracking permission settings provided by the operating system; or
  4. a processing objection submitted to the customer support email address.

Menu names and locations may vary by device and operating system. Restricting or deleting an advertising identifier does not automatically stop processing of IP addresses, diagnostics or app events, and does not delete data already collected. Requests about data held by a provider may also be submitted through the provider’s privacy contact in Article 5.

Article 7. Rights of Users and How to Exercise Them

Users may exercise the following rights regarding their personal information:

  1. request confirmation and access;
  2. request correction or deletion;
  3. request suspension of processing;
  4. withdraw consent; and
  5. delete the account and associated game data.

Requests, including account deletion requests, may be submitted through:

When rights are exercised through an agent, the Operator may verify proper authority, including by requesting a power of attorney. The Operator may also request the minimum information necessary to verify the requester’s identity.

Deletion or suspension requests may be restricted where retention is required by applicable law.

Article 8. Personal Information of Children Under 14

Where consent is legally required to process personal information of a child under 14, the Operator obtains consent from and verifies the child’s legal representative.

If no legally compliant parental consent process is available, the Operator does not provide children under 14 with features that require consent, such as account registration or personalized advertising.

Article 9. Destruction of Personal Information

Personal information is destroyed without undue delay when the retention period expires or the purpose of processing is achieved.

Electronic files are deleted using methods that make restoration or reproduction impracticable. Any paper records are shredded or incinerated.

Information that must be retained by law is separated from other information and destroyed after the applicable retention period expires.

Article 10. Security Measures

The Operator implements the following measures to prevent loss, theft, leakage, falsification, alteration, or damage:

  1. minimization of personnel and access privileges;
  2. management of access rights to personal information systems;
  3. encryption during transmission;
  4. retention of access records and prevention of unauthorized alteration;
  5. maintenance of current security software and SDK versions;
  6. incident response and recovery procedures; and
  7. periodic review of processors and third-party services.

Article 11. Privacy Officer and Remedies

The Operator designates the following contact to oversee personal information processing and respond to complaints and requests.

Privacy Officer: Representative of Artgraph

Access request and complaint contact: Representative of Artgraph

Email: help@artgraph.kr

Users may also contact the following independent organizations for consultation or remedies:

These organizations are independent of the Operator. Requests concerning Artgraph should first be submitted to help@artgraph.kr.

Article 12. Automated Decision-Making

The Operator does not make decisions that materially affect a user’s rights or obligations solely through automated processing.

Statistical or automated processing that does not materially affect legal rights or obligations may be used for advertising recommendations, content placement, or game balance analysis.

Article 13. Changes to This Privacy Policy

If this Privacy Policy is added to, deleted, or amended, the Operator will generally provide notice through an in-game announcement or official webpage at least seven days before the effective date.

Material changes affecting user rights will be announced at least 30 days in advance or handled through a separate consent process where required by law.

Draft revision: September 13, 2026 Announcement and effective dates: September 17, 2026