코지팜

개인정보처리방침 v3.1 시행일: 2026-08-21 제공자: U2Games

적용 대상: 본 방침은 Android 네이티브 빌드(Google Play), iOS 네이티브 빌드(App Store), AppsInToss 미니앱 빌드에 모두 적용됩니다. 빌드마다 수집 항목이 다르므로 각 항목에 해당 빌드를 표기했습니다.

제1조 (수집하는 개인정보)

회사는 서비스 제공을 위해 다음 정보를 수집합니다:

  • 광고 식별자 — 광고 노출·빈도 관리·성과 측정 목적
    • Android 네이티브 빌드: Google Advertising ID (AAID)
    • iOS 네이티브 빌드: IDFA (Identifier for Advertisers) — 앱 추적 투명성(App Tracking Transparency) 다이얼로그에서 이용자가 허용한 경우에만 수집합니다. 허용하지 않으면 IDFA 는 전부 0 으로만 조회되며 회사와 광고 제휴사는 이를 이용할 수 없습니다. 이 경우에도 비개인화 광고는 계속 표시됩니다.
    • iOS 네이티브 빌드: IDFV (Identifier for Vendor) — 동일 개발사 앱 범위에서 유효한 기기 식별자. 광고·분석 SDK 가 사용합니다. 앱을 삭제하면 초기화됩니다.
    • AppsInToss 미니앱 빌드: 토스 플랫폼의 광고 서비스가 내부 식별자를 사용 (토스 정책에 따름, 회사는 직접 식별자를 보관하지 않음)
  • Google Play 플레이어 ID — Android 빌드 한정
    • Google Play Games 서비스에 로그인한 경우 자동 수집
    • 목적: 게임 진행 데이터의 클라우드 저장 및 기기 변경·재설치 후 복원
    • 보유 기간: Google 계정 삭제 시 또는 이용자의 삭제 요청 시
  • 게임 진행 데이터 — Android 빌드 한정 (클라우드 저장)
    • 레벨, 재화, 업그레이드 현황 등 게임 내 진행 상태
    • Google Play Games Saved Games 서비스를 통해 Google 서버에 저장
    • 보유 기간: Google 계정 삭제 시 또는 이용자의 삭제 요청 시
    • iOS 빌드에는 클라우드 저장 기능이 없습니다. 게임 진행 데이터는 기기 내부에만 저장되며 외부로 전송되지 않습니다. 앱을 삭제하면 함께 삭제됩니다.
  • 앱 사용 분석 데이터 — Android · iOS 빌드 (Firebase Analytics)
    • 게임 이벤트 18종: 레벨업, 구역 잠금 해제, 보상형 광고 시청, 인앱 결제, 재화 소비, 업그레이드 구매, 황금 작물 수확 등
    • 사용자 속성: 현재 레벨, 프레스티지 횟수
    • 앱 인스턴스 ID (익명화된 기기 식별자), 세션 정보
    • 목적: 서비스 이용 패턴 분석 및 게임 밸런스 개선
    • 보유 기간: 최대 14개월 (Firebase 정책 기준) 또는 이용자 요청 시
  • 대략적 위치 (국가·지역 수준) — Android · iOS 빌드
    • Firebase Analytics 및 광고 제휴사가 접속 IP 주소로부터 국가·지역을 추정합니다. 회사는 GPS 등 정밀 위치 권한을 요청하지 않으며 정밀 위치를 수집하지 않습니다.
    • 목적: 지역별 이용 통계, 광고 노출 지역 제어, 법령 적용 지역 판별(GDPR 등)
    • 보유 기간: 각 제휴사 정책에 따름 (Firebase 최대 14개월)
  • 앱 설치 전환 추적 데이터 — Android 빌드 한정 (Meta Facebook SDK)
    • 앱 설치 이벤트, 광고 클릭-설치 어트리뷰션
    • 광고 ID (GAID), 디바이스 정보 (모델명, OS 버전)
    • 목적: Meta 광고 캠페인 성과 측정 및 앱 설치 전환 추적
    • 보유 기간: Meta 정책에 따름 (최대 90일 어트리뷰션 윈도우)
    • iOS 빌드에는 Meta Facebook SDK 가 포함되어 있지 않습니다. iOS 에서는 Apple 의 SKAdNetwork 를 통해 개별 식별자 없이 집계된 형태로만 설치 성과가 측정됩니다. 다만 광고 노출용 Meta Audience Network 는 Android 빌드에 포함되어 있고, iOS 는 1.5.0 이후 빌드부터 포함됩니다. 이는 설치 전환 추적과는 별개로 제4조에 따로 안내합니다.
  • 결제 정보
    • 결제 수단(카드번호 등)은 회사가 일절 보관하지 않습니다. Google Play / Apple App Store / 토스 결제 시스템이 직접 처리합니다.
    • 결제 검증 데이터 (Android · iOS 빌드): 부정 결제 차단을 위해 거래 ID, 상품 ID, 스토어가 발급한 서명 영수증을 회사의 서버(Google Firebase)로 전송해 검증하고, 거래 ID·상품 ID·지급 상태·처리 시각을 기록합니다. 이름·이메일·결제 수단은 포함되지 않습니다.
    • iOS 는 Apple 의 App Store Server API 를 통해 환불 여부를 추가 확인합니다.
    • 보유 기간: 환불·중복 지급 분쟁 대응 목적으로 보관하며, 이용자 요청 시 삭제합니다.
  • 앱 무결성 증명 데이터 — Android · iOS 빌드
    • 변조된 앱의 서버 요청을 차단하기 위해 기기·앱이 정품인지 증명하는 토큰을 사용합니다.
    • Android: Google Play Integrity / iOS: Apple App Attest
    • 이용자 개인을 식별하는 정보는 포함되지 않으며, 검증은 Apple·Google 및 회사 서버에서 이루어집니다.
  • 디바이스 정보 (모델명, OS 버전) — 오류 수집·디버깅 목적 (Unity 엔진 충돌 보고 포함)
  • 알림 권한 (Android 13 이상 / iOS 전 버전, 선택)
    • 게임 내 수확 완료 알림 발송 목적 (기기 로컬 알림, 외부 서버 전송 없음)
    • 앱 내 설정 또는 기기 설정에서 언제든지 철회 가능
수집하지 않는 정보: 이름·이메일·전화번호 등 개인 식별 정보 / 정밀 위치(GPS) / 연락처 / 사진·카메라·마이크 / 건강·금융 정보 / 검색 기록 / 메시지
회사는 수집한 어떤 항목도 이용자의 실명 계정이나 신원 정보와 연결하지 않습니다.

제2조 (수집 방법)

  • 앱 실행 시 자동 수집 (광고 식별자, 디바이스 정보)
  • iOS: 최초 실행 시 앱 추적 투명성(ATT) 다이얼로그로 이용자 선택을 받은 뒤에만 IDFA 를 수집 — 거부 시 수집하지 않음
  • Google Play Games 자동 로그인(Silent Sign-in) 시 수집 (Player ID, 게임 데이터) — Android 빌드 전용
  • 게임 플레이 중 Firebase Analytics 이벤트 자동 수집 — Android · iOS 빌드
  • 앱 설치 및 실행 시 Meta Facebook SDK 이벤트 자동 수집 — Android 빌드 전용
  • 결제 완료 시 스토어가 발급한 거래 ID·서명 영수증을 회사 서버로 전송해 검증 — Android · iOS 빌드
  • 서버 요청 시 앱 무결성 증명 토큰 자동 첨부 (App Attest / Play Integrity)

제3조 (보유 기간)

항목보유 기간
광고 ID (AAID / IDFA)OS 설정에서 사용자가 초기화하기 전까지. iOS 는 ATT 허용을 철회하면 즉시 이용 중단
IDFV (iOS)앱 삭제 시 초기화
Google Play 플레이어 IDGoogle 계정 삭제 시 또는 이용자 요청 시
게임 진행 데이터 (클라우드, Android 한정)Google 계정 삭제 시 또는 이용자 요청 시
게임 진행 데이터 (iOS, 기기 로컬)앱 삭제 시 함께 삭제 (외부 전송 없음)
앱 사용 분석 데이터 (Firebase Analytics)최대 14개월 (Firebase 정책) 또는 이용자 요청 시
대략적 위치 (국가·지역)각 제휴사 정책에 따름 (Firebase 최대 14개월)
앱 설치 전환 추적 데이터 (Meta Facebook SDK, Android 한정)Meta 정책에 따름 (최대 90일 어트리뷰션 윈도우)
결제 검증 레코드 (거래 ID, 상품 ID, 지급 상태)환불·중복 지급 분쟁 대응 목적 보관, 이용자 요청 시 삭제
앱 무결성 증명 토큰 (App Attest / Play Integrity)검증 즉시 폐기 (별도 저장하지 않음)
결제 위탁 정보Google Play / Apple App Store / 토스 결제 시스템 정책에 따름

제4조 (제3자 제공 및 위탁)

회사는 다음 제3자에게 개인정보 처리를 위탁합니다.

Android 빌드

수탁업체위탁 업무처리 항목
Google LLC (Play Games)게임 데이터 클라우드 저장 및 복원Google Play 플레이어 ID, 게임 진행 데이터
Google LLC (Firebase Analytics)앱 사용 패턴 분석, 서비스 개선게임 이벤트, 사용자 속성, 앱 인스턴스 ID
Unity Technologies엔진 충돌 보고 (Unity Crash Reporter)충돌 로그, 스택트레이스, 디바이스 정보
IronSource LevelPlay (Unity)광고 미디에이션 중계광고 ID, 디바이스 정보
Google AdMobUMP 동의 관리 (EU GDPR / 미국 주법), 광고 노출광고 ID, 디바이스 정보
Unity Ads광고 노출 (미디에이션 경유)광고 ID, 디바이스 정보
Meta Platforms, Inc. (Facebook SDK)앱 설치 전환 추적 및 광고 성과 측정광고 ID, 앱 설치 이벤트, 디바이스 정보
Meta Platforms, Inc. (Audience Network)광고 노출 (미디에이션 경유) 및 광고 성과 측정광고 ID, 디바이스·앱 정보, 광고 노출·클릭 이벤트
Google Play Billing (Unity IAP 경유)결제 처리 위탁결제 완료 토큰 (결제 수단은 Google 직접 보관)

iOS 빌드

수탁업체위탁 업무처리 항목
Apple Inc. (App Store / StoreKit)결제 처리, 영수증 서명·환불 확인거래 ID, 상품 ID (결제 수단은 Apple 직접 보관)
Apple Inc. (App Attest)앱·기기 무결성 증명기기 무결성 증명 토큰 (개인 식별 정보 없음)
Apple Inc. (SKAdNetwork)개별 식별자 없는 집계 광고 성과 측정집계된 설치·전환 신호
Google LLC (Firebase Analytics)앱 사용 패턴 분석, 서비스 개선게임 이벤트, 사용자 속성, 앱 인스턴스 ID, 대략적 위치(국가·지역)
Google LLC (Firebase Functions / Firestore)결제 영수증 서버 검증 및 중복·환불 판별거래 ID, 상품 ID, 서명 영수증, 지급 상태
IronSource LevelPlay (Unity)광고 미디에이션 중계IDFA (ATT 허용 시), IDFV, 디바이스 정보
Google AdMobUMP 동의 관리 (EU GDPR / 미국 주법), 광고 노출IDFA (ATT 허용 시), IDFV, 디바이스 정보
Unity Ads광고 노출 (미디에이션 경유)IDFA (ATT 허용 시), 디바이스 정보
Meta Platforms, Inc. (Audience Network)광고 노출 (미디에이션 경유) 및 광고 성과 측정 — 1.5.0 이후 iOS 빌드부터IDFA (ATT 허용 시), 디바이스·앱 정보, 광고 노출·클릭 이벤트
Unity Technologies엔진 충돌 보고 (Unity Crash Reporter)충돌 로그, 스택트레이스, 디바이스 정보

iOS 빌드에는 Meta Facebook SDK 및 Google Play Games 가 포함되어 있지 않습니다. 따라서 iOS 에서는 설치 전환 추적 목적의 Meta 전송과 클라우드 세이브가 발생하지 않습니다. 다만 광고 노출 목적의 Meta Audience Network 전송은 1.5.0 이후 iOS 빌드에서도 발생하며, 위 표에 따로 기재했습니다.

AppsInToss 미니앱 빌드

수탁업체위탁 업무처리 항목
토스 (Viva Republica)미니앱 실행 환경, 게임 데이터 저장, 결제 처리, 광고 서비스게임 진행 데이터, 광고 식별자 (토스 정책에 따름)

각 제3자의 개인정보 처리 정책:

제5조 (개인정보의 국외 이전)

회사는 아래와 같이 개인정보를 국외로 이전합니다. 「개인정보 보호법」 제28조의8에 따라 사전 고지합니다.

① Google Play Games (클라우드 세이브)

항목내용
이전받는 자Google LLC
이전받는 자의 연락처Google 개인정보 문의
이전 국가미국 (및 Google 데이터센터 소재 국가)
이전 일시 및 방법Google Play Games 서비스 이용 시 네트워크를 통해 수시 이전
이전 목적게임 진행 데이터의 클라우드 저장 및 복원
이전 항목Google Play 플레이어 ID, 게임 진행 데이터
보유 및 이용 기간Google 계정 삭제 시 또는 이용자의 삭제 요청 시

② Firebase Analytics (앱 사용 분석)

항목내용
이전받는 자Google LLC
이전받는 자의 연락처Firebase 개인정보 문의
이전 국가미국 (및 Google 데이터센터 소재 국가)
이전 일시 및 방법게임 플레이 중 이벤트 발생 시 네트워크를 통해 수시 이전
이전 목적앱 사용 패턴 분석 및 서비스 개선
이전 항목게임 이벤트, 사용자 속성, 앱 인스턴스 ID
보유 및 이용 기간최대 14개월 (Firebase 정책) 또는 이용자 요청 시

③ Meta (Facebook SDK / Audience Network) (앱 설치 전환 추적 · 광고 노출)

항목내용
이전받는 자Meta Platforms, Inc.
이전받는 자의 연락처Meta 개인정보처리방침
이전 국가미국 (및 Meta 데이터센터 소재 국가)
이전 일시 및 방법앱 설치·실행 시 및 광고 요청·노출 시 네트워크를 통해 수시 이전
이전 목적앱 설치 전환 추적 및 광고 성과 측정 (Facebook SDK, Android 빌드 한정) / 미디에이션 경유 광고 노출 및 광고 성과 측정 (Audience Network, Android 빌드 및 1.5.0 이후 iOS 빌드)
이전 항목광고 ID (Android: GAID / iOS: IDFA — ATT 허용 시), 앱 설치 이벤트, 광고 노출·클릭 이벤트, 디바이스·앱 정보
보유 및 이용 기간Meta 정책에 따름 (설치 어트리뷰션 최대 90일 윈도우)

④ Apple (App Store 결제·영수증 검증·앱 무결성 증명) — iOS 빌드

항목내용
이전받는 자Apple Inc.
이전받는 자의 연락처Apple 개인정보 문의
이전 국가미국 (및 Apple 데이터센터 소재 국가)
이전 일시 및 방법인앱 결제·복원 시, 서버 요청 시 네트워크를 통해 수시 이전
이전 목적결제 처리, 영수증 서명·환불 확인, 앱·기기 무결성 증명, 집계 광고 성과 측정(SKAdNetwork)
이전 항목거래 ID, 상품 ID, 무결성 증명 토큰, 집계된 설치·전환 신호
보유 및 이용 기간Apple 정책에 따름

⑤ 광고 제휴사 (광고 노출 및 빈도 관리) — Android · iOS 빌드

항목내용
이전받는 자Unity Technologies (IronSource LevelPlay, Unity Ads), Google LLC (AdMob)
이전받는 자의 연락처Unity 개인정보처리방침 / Google 개인정보처리방침
이전 국가미국 (및 각 사 데이터센터 소재 국가)
이전 일시 및 방법광고 요청 시 네트워크를 통해 수시 이전
이전 목적광고 노출, 노출 빈도 관리, 광고 성과 측정
이전 항목광고 식별자(AAID / IDFA — iOS 는 ATT 허용 시에만), IDFV, 디바이스 정보, 대략적 위치(국가·지역)
보유 및 이용 기간각 사 정책에 따름

국외 이전에 동의하지 않을 경우 Android 빌드에서의 클라우드 세이브 및 분석 기능 이용이 제한될 수 있습니다. 게임 데이터는 기기 내 로컬 저장만으로 유지됩니다.

iOS 빌드에서 앱 추적 투명성(ATT) 요청을 거부하면 IDFA 는 이전되지 않습니다. 이 경우에도 게임은 정상 이용할 수 있으며 비개인화 광고가 표시됩니다. 결제 검증과 앱 무결성 증명은 서비스 제공·부정 이용 방지를 위한 필수 처리로, 거부 시 인앱 결제 이용이 제한될 수 있습니다.

제6조 (이용자 권리)

이용자는 다음 권리를 가집니다:

  1. 동의 철회 — 앱 내 "설정 → 동의 철회" 메뉴
  2. 클라우드 데이터 삭제
  3. Firebase Analytics 데이터 초기화
    • Android: 기기 설정 → 앱 → 코지팜 → 데이터 삭제 (앱 인스턴스 ID 초기화)
    • iOS: 앱 삭제 후 재설치 (앱 인스턴스 ID · IDFV 초기화)
    • 또는 [email protected]로 삭제 요청
  4. iOS — 앱 추적 투명성(ATT) 동의 철회
    • 기기 설정 → 개인정보 보호 및 보안 → 추적 → 코지팜 끄기
    • 끄면 IDFA 이용이 즉시 중단되며 비개인화 광고로 전환됩니다. 게임 이용에는 제한이 없습니다.
    • 같은 화면의 "앱이 추적을 요청하도록 허용" 을 끄면 모든 앱의 추적 요청이 일괄 차단됩니다.
  5. 광고 식별자 초기화
    • Android: 설정 → 개인정보 보호 → 광고에서 초기화 (Meta Facebook SDK 포함 모든 광고 추적에 적용)
    • iOS: 위 ATT 를 끄면 IDFA 가 제공되지 않습니다. IDFV 는 앱 삭제 시 초기화됩니다.
  6. iOS — 기기 내 게임 데이터 삭제 — iOS 는 클라우드 저장을 하지 않으므로 앱을 삭제하면 게임 진행 데이터가 함께 삭제됩니다.
  7. 알림 권한 철회
    • Android: 기기 설정 → 앱 → 코지팜 → 권한 → 알림 해제
    • iOS: 기기 설정 → 알림 → 코지팜 → 알림 허용 끄기
  8. 개인정보 열람·수정·삭제 요청 — [email protected] 로 문의

제7조 (변경 사항 통지)

방침 변경 시 게임 실행 시 재동의 화면을 통해 통지합니다.

제8조 (문의)

개인정보 관련 문의: [email protected]

개인정보 침해 신고는 개인정보보호위원회(privacy.go.kr) 또는 한국인터넷진흥원(118)에 문의하실 수 있습니다.

Privacy Policy v3.1 Effective: 2026-08-21 Provider: U2Games

Scope: This policy applies to the Android native build (Google Play), the iOS native build (App Store), and the AppsInToss Mini App build. Collection differs by build, so each item below states which builds it applies to.

Article 1 (Information We Collect)

The Company collects the following information to provide the Service:

  • Advertising Identifier — for ad delivery, frequency management, and performance measurement
    • Android native build: Google Advertising ID (AAID)
    • iOS native build: IDFA (Identifier for Advertisers) — collected only if you allow it in the App Tracking Transparency prompt. If you decline, the IDFA reads as all zeros and neither the Company nor its ad partners can use it. Non-personalized ads are still shown in that case.
    • iOS native build: IDFV (Identifier for Vendor) — a device identifier scoped to this developer's apps, used by the ad and analytics SDKs. It resets when the app is deleted.
    • AppsInToss Mini App build: the Toss ad service uses an internal identifier per Toss policy; the Company does not retain this identifier directly.
  • Google Play Player ID — Android build only
    • Automatically collected upon Google Play Games sign-in
    • Purpose: cloud storage of game progress and restoration after device change or reinstallation
    • Retention: until Google account deletion or upon user request
  • Game Progress Data — Android build only (cloud storage)
    • In-game progress including level, currency, and upgrade status
    • Stored on Google servers via Google Play Games Saved Games service
    • Retention: until Google account deletion or upon user request
    • The iOS build has no cloud storage feature. Game progress is stored only on the device and is never transmitted. It is deleted when the app is deleted.
  • App Usage Analytics Data — Android and iOS builds (Firebase Analytics)
    • 18 game event types: level-up, zone unlock, rewarded ad views, in-app purchases, currency spending, upgrade purchases, golden crop harvests, etc.
    • User properties: current level, prestige count
    • App instance ID (anonymized device identifier), session information
    • Purpose: analysis of service usage patterns and game balance improvement
    • Retention: up to 14 months (per Firebase policy) or upon user request
  • Coarse Location (country / region level) — Android and iOS builds
    • Firebase Analytics and our ad partners infer country and region from your IP address. The Company does not request GPS or any precise location permission and does not collect precise location.
    • Purpose: regional usage statistics, regional ad delivery control, and determining which regulations apply (GDPR, etc.)
    • Retention: per each partner's policy (Firebase: up to 14 months)
  • App Install Conversion Data — Android build only (Meta Facebook SDK)
    • App install events, ad click-to-install attribution
    • Advertising ID (GAID), device information (model, OS version)
    • Purpose: measurement of Meta ad campaign performance and app install conversion tracking
    • Retention: per Meta policy (up to 90-day attribution window)
    • The Meta Facebook SDK is not included in the iOS build. On iOS, install performance is measured only in aggregate through Apple's SKAdNetwork, without any individual identifier. However, Meta Audience Network, used for ad delivery, is included in the Android build and, from version 1.5.0 onward, in the iOS build as well; this is separate from install conversion tracking and is described in Article 4.
  • Payment Information
    • Payment instruments (card numbers, etc.) are never retained by the Company. They are handled directly by Google Play, the Apple App Store, or Toss.
    • Purchase verification data (Android and iOS builds): to prevent fraudulent purchases, the transaction ID, product ID, and the store-signed receipt are sent to the Company's server (Google Firebase) for verification, and the transaction ID, product ID, grant status, and timestamp are recorded. No name, email, or payment instrument is included.
    • On iOS, refunds are additionally checked through Apple's App Store Server API.
    • Retention: kept to resolve refund and duplicate-grant disputes; deleted upon user request.
  • App Integrity Attestation Data — Android and iOS builds
    • Used to block server requests from tampered apps by attesting that the device and app are genuine.
    • Android: Google Play Integrity / iOS: Apple App Attest
    • No personally identifying information is included. Verification takes place at Apple, Google, and the Company's server.
  • Device Information (device model, OS version) — for error reporting and debugging, including Unity engine crash reports
  • Notification Permission (Android 13 and above / all iOS versions, optional)
    • Used solely to deliver in-game harvest completion notifications (local device notifications only; no data sent to external servers)
    • Can be revoked at any time via in-app settings or device settings
Information we do NOT collect: name, email, phone number, or other personally identifiable information / precise location (GPS) / contacts / photos, camera, microphone / health or financial data / search history / messages
The Company does not link any collected item to your real-name account or identity.

Article 2 (How We Collect Information)

  • Automatically upon app launch (advertising identifier, device information)
  • iOS: the IDFA is collected only after you choose to allow it in the App Tracking Transparency prompt shown on first launch — nothing is collected if you decline
  • Via Google Play Games automatic sign-in (Silent Sign-in) upon first launch — Android build only (Player ID and game data)
  • Automatically during gameplay via Firebase Analytics event tracking — Android and iOS builds
  • Automatically upon app install and launch via Meta Facebook SDK event tracking — Android build only
  • Upon completing a purchase, the store-issued transaction ID and signed receipt are sent to the Company's server for verification — Android and iOS builds
  • An app integrity attestation token is attached automatically to server requests (App Attest / Play Integrity)

Article 3 (Retention Period)

DataRetention Period
Advertising ID (AAID / IDFA)Until reset by the user in OS settings. On iOS, use stops immediately if ATT permission is revoked
IDFV (iOS)Reset when the app is deleted
Google Play Player IDUntil Google account deletion or upon user request
Game Progress Data (cloud, Android only)Until Google account deletion or upon user request
Game Progress Data (iOS, on-device)Deleted with the app (never transmitted)
App Usage Analytics Data (Firebase)Up to 14 months (per Firebase policy) or upon user request
Coarse location (country / region)Per each partner's policy (Firebase: up to 14 months)
App Install Conversion Data (Meta Facebook SDK, Android only)Per Meta policy (up to 90-day attribution window)
Purchase verification record (transaction ID, product ID, grant status)Kept to resolve refund and duplicate-grant disputes; deleted upon user request
App integrity attestation token (App Attest / Play Integrity)Discarded immediately after verification (not stored)
Payment informationSubject to Google Play / Apple App Store / Toss payment system policies

Article 4 (Third-Party Disclosure and Processing)

The Company entrusts personal information processing to the following third parties.

Android Build

ProcessorPurposeData Involved
Google LLC (Play Games)Cloud storage and restoration of game dataGoogle Play Player ID, game progress data
Google LLC (Firebase Analytics)App usage analytics and service improvementGame events, user properties, app instance ID
Unity TechnologiesEngine crash reporting (Unity Crash Reporter)Crash logs, stack traces, device information
IronSource LevelPlay (Unity)Ad mediationAdvertising ID, device information
Google AdMobUMP consent management (EU GDPR / US state laws), ad deliveryAdvertising ID, device information
Unity AdsAd delivery (via mediation)Advertising ID, device information
Meta Platforms, Inc. (Facebook SDK)App install conversion tracking and ad performance measurementAdvertising ID, app install events, device information
Meta Platforms, Inc. (Audience Network)Ad delivery via mediation and ad performance measurementAdvertising ID, device and app information, ad impression and click events
Google Play Billing (via Unity IAP)Payment processingPurchase completion token (payment method retained by Google)

iOS Build

ProcessorPurposeData Involved
Apple Inc. (App Store / StoreKit)Payment processing, receipt signing and refund checksTransaction ID, product ID (payment method retained by Apple)
Apple Inc. (App Attest)App and device integrity attestationDevice integrity attestation token (no personally identifying information)
Apple Inc. (SKAdNetwork)Aggregate ad performance measurement without individual identifiersAggregated install and conversion signals
Google LLC (Firebase Analytics)Usage pattern analysis, service improvementGame events, user properties, app instance ID, coarse location (country/region)
Google LLC (Firebase Functions / Firestore)Server-side receipt verification, duplicate and refund detectionTransaction ID, product ID, signed receipt, grant status
IronSource LevelPlay (Unity)Ad mediationIDFA (only if ATT allowed), IDFV, device information
Google AdMobUMP consent management (EU GDPR / US state laws), ad deliveryIDFA (only if ATT allowed), IDFV, device information
Unity AdsAd delivery (via mediation)IDFA (only if ATT allowed), device information
Meta Platforms, Inc. (Audience Network)Ad delivery via mediation and ad performance measurement — from iOS build 1.5.0 onwardIDFA (only if ATT allowed), device and app information, ad impression and click events
Unity TechnologiesEngine crash reporting (Unity Crash Reporter)Crash logs, stack traces, device information

The iOS build does not include the Meta Facebook SDK or Google Play Games. No install-attribution data is therefore transmitted to Meta, and no cloud save takes place, on iOS. However, transmissions to Meta Audience Network for ad delivery do occur on iOS as well, from build 1.5.0 onward, as listed separately in the table above.

AppsInToss Mini App Build

ProcessorPurposeData Involved
Toss (Viva Republica)Mini app runtime, game data storage, payment processing, ad serviceGame progress data, advertising identifier (per Toss policy)

Third-party privacy policies:

Article 5 (International Transfer of Personal Information)

The Company transfers personal information internationally as follows. This notice is provided pursuant to applicable data protection laws.

① Google Play Games (Cloud Save)

ItemDetails
RecipientGoogle LLC
Recipient ContactGoogle Privacy Contact
Destination CountryUnited States (and countries where Google data centers are located)
Transfer Method and TimingTransferred via network on an ongoing basis when using Google Play Games services
PurposeCloud storage and restoration of game progress data
Data TransferredGoogle Play Player ID, game progress data
Retention PeriodUntil Google account deletion or upon user request

② Firebase Analytics (App Usage Analytics)

ItemDetails
RecipientGoogle LLC
Recipient ContactFirebase Privacy Contact
Destination CountryUnited States (and countries where Google data centers are located)
Transfer Method and TimingTransferred via network as game events occur during gameplay
PurposeApp usage analytics and service improvement
Data TransferredGame events, user properties, app instance ID
Retention PeriodUp to 14 months (per Firebase policy) or upon user request

③ Meta (Facebook SDK / Audience Network) (App Install Conversion Tracking · Ad Delivery)

ItemDetails
RecipientMeta Platforms, Inc.
Recipient ContactMeta Privacy Policy
Destination CountryUnited States (and countries where Meta data centers are located)
Transfer Method and TimingTransferred via network upon app install and launch, and upon each ad request and impression
PurposeApp install conversion tracking and ad performance measurement (Facebook SDK, Android build only) / ad delivery via mediation and ad performance measurement (Audience Network, Android builds and iOS builds from version 1.5.0 onward)
Data TransferredAdvertising ID (Android: GAID / iOS: IDFA, only if ATT allowed), app install events, ad impression and click events, device and app information
Retention PeriodPer Meta policy (install attribution window up to 90 days)

4. Apple (App Store payments, receipt verification, app integrity attestation) — iOS build

ItemDetails
RecipientApple Inc.
Recipient ContactApple Privacy Contact
Destination CountryUnited States (and countries where Apple data centers are located)
Timing and MethodTransferred over the network as needed at purchase, restore, and server request time
PurposePayment processing, receipt signing and refund checks, app and device integrity attestation, aggregate ad measurement (SKAdNetwork)
Data TransferredTransaction ID, product ID, integrity attestation token, aggregated install and conversion signals
RetentionPer Apple policy

5. Ad partners (ad delivery and frequency management) — Android and iOS builds

ItemDetails
RecipientUnity Technologies (IronSource LevelPlay, Unity Ads), Google LLC (AdMob)
Recipient ContactUnity Privacy Policy / Google Privacy Policy
Destination CountryUnited States (and countries where each company's data centers are located)
Timing and MethodTransferred over the network as needed on each ad request
PurposeAd delivery, frequency management, ad performance measurement
Data TransferredAdvertising identifier (AAID / IDFA — on iOS only if ATT is allowed), IDFV, device information, coarse location (country/region)
RetentionPer each company's policy

If you do not consent to international data transfer, cloud save and analytics functionality in the Android build may be unavailable. Game data will be maintained via local on-device storage only.

On iOS, declining the App Tracking Transparency request means the IDFA is not transferred. The game remains fully playable and non-personalized ads are shown instead. Purchase verification and app integrity attestation are required processing for service delivery and fraud prevention; declining them may prevent in-app purchases from completing.

Article 6 (Your Rights)

You have the following rights:

  1. Withdraw Consent — via "Settings → Withdraw Consent" in the app
  2. Delete Cloud Data
  3. Reset Firebase Analytics Data
    • Android: Device Settings → Apps → Cozy Farm → Clear Data (resets app instance ID)
    • iOS: delete and reinstall the app (resets app instance ID and IDFV)
    • Or contact [email protected] to request deletion
  4. iOS — Withdraw App Tracking Transparency consent
    • Device Settings → Privacy & Security → Tracking → turn off Cozy Farm
    • Use of the IDFA stops immediately and ads switch to non-personalized. Gameplay is unaffected.
    • Turning off "Allow Apps to Request to Track" on the same screen blocks tracking requests from every app at once.
  5. Reset Advertising Identifier
    • Android: Settings → Privacy → Ads → Reset Advertising ID (applies to all ad tracking including Meta Facebook SDK)
    • iOS: turning off ATT above stops the IDFA from being provided. The IDFV resets when the app is deleted.
  6. iOS — Delete on-device game data — iOS does not use cloud storage, so deleting the app deletes your game progress with it.
  7. Revoke Notification Permission
    • Android: Device Settings → Apps → Cozy Farm → Permissions → Notifications
    • iOS: Device Settings → Notifications → Cozy Farm → turn off Allow Notifications
  8. Request Access, Correction, or Deletion — contact [email protected]

Article 7 (Notification of Changes)

We will notify you of any changes to this policy via a re-consent screen upon app launch.

Article 8 (Contact)

Privacy inquiries: [email protected]