Privacy Policy
Effective October 1, 2026 · Version 1
Useless Space Selfie is a web service that turns your pet photo into a spacesuit selfie inside your browser. Your photo is processed only on this device, and you use the service without an account.
At a glance
winterlog studio ("we", "us") runs Useless Space Selfie (wooju.bang9.dev). This policy explains what personal data we handle and why, who we share the work with, and how long we keep it.
- What: a random device cookie we create for each browser and the launch and payment records linked to it, a pseudonymized IP address used to count the free limit per network, the crew name you enter when you share a link, and usage records. Your pet photo is processed only on this device.
- Why: to count your free shot and the shots you paid for, show shared links, process payments and refunds, prevent abuse, and improve the service.
- Who and where: our servers run on Cloudflare (United States). The merchant of record Dodo Payments (United States) receives payments directly, and on screens with an ad slot your browser requests ads from Google AdSense (United States). Their names and countries are in the tables below.
- Worth knowing: on screens with an ad slot, Google can use cookies to collect your visits to this site and other sites and show you personalized ads. In the EU, the UK and Switzerland this happens only after you consent, and we keep no usage records of our own there.
- How long: device records for 400 days from last use (same as the cookie's lifetime), shared links for 30 days from creation, and payment records for 5 years from payment. Everything else is in the "How long we keep data" table below.
- Your rights and contact: you can ask to access, correct, delete or stop processing your data at support@bang9.dev. Anything on this device can be deleted right away by clearing site data in your browser.
Who is responsible
Controller: winterlog studio
- Owner: Hyungu Kang
- Address: 5-12 Gwangmyeong-ro 347beon-gil, Jungwon-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
- Phone: +82-10-9688-1157
- Email: support@bang9.dev
- Business registration number: 577-24-02412
Privacy contact
Our privacy contact (the person who handles privacy questions and complaints) is the owner, Hyungu Kang.
Contact: email support@bang9.dev · phone +82-10-9688-1157
Why we use your data and on what basis
What we process without asking for consent (needed to perform our contract with you, to follow the law, or to protect the service):
Counting your free shot and the shots you paid for, numbering launches
Data used Device cookie, launch records
Basis Performance of our contract (Korean PIPA Art. 15(1)(4), GDPR Art. 6(1)(b))
Showing the mission card of a link you shared
Data used Shared link records
Basis Performance of our contract — only when you choose to share a link
Confirming payments, adding the shots you paid for, refunds
Data used Checkout records, payment records
Basis Performance of our contract
Keeping transaction records
Data used Payment records, support emails
Basis Legal obligation (Korean E-Commerce Act, PIPA Art. 15(1)(2), GDPR Art. 6(1)(c))
Answering your questions
Data used Support emails
Basis Performance of our contract
Preventing abuse — the daily free limit per network and request rate limits
Data used Pseudonymized IP address, IP address
Basis Legitimate interest: blocking mass requests that get around the free limit, so we can keep running the service (PIPA Art. 15(1)(6), GDPR Art. 6(1)(f))
Our own usage analytics — seeing where people get stuck so we can fix it
Data used Usage records
Basis Legitimate interest: making the service easier to use. We do not record visitors from the EU, the UK or Switzerland
What we process with consent:
- Personalized ads (Google AdSense) — in the EU, the UK and Switzerland, Google's consent message asks for your consent on screens with an ad slot (GDPR Art. 6(1)(a)). In Korea we disclose the recipient, data, purposes and retention in this policy and do not ask for separate consent, and you can turn personalized ads off at any time.
What we collect and where it comes from
Device cookie (a random device identifier our server creates), whether you used your free shot, when it was created, when it was last used
Source Our server creates it and stores it in your browser on your first visit
Launch records: launch number, free or paid, status, a random seed that recreates the mission, the mission number you came from if you opened a shared link, launch and finish times, number of resumed shots
Source Our server creates them when you launch
Checkout records: a random payment reference, your device cookie value, the screen with the pay button, the number of tickets chosen, the device id and ad utm values used for usage records, the Dodo checkout session number, when checkout was created, and when you gave consent to immediate supply before paying, with the version of that wording (visitors from the EU, the EEA and the UK only)
Source Created in advance when the pay button is on screen and you can pay right away (the usage record values are absent for visitors from the EU, the UK and Switzerland)
Payment records: Dodo payment number, amount and currency, whether it was a test payment, whether it was refunded, payment time
Source The merchant of record tells us the payment result. That notice may include the payer's email, name, phone number, billing address and the last four digits of the card, but we do not store them (only the billing country goes on the payment line of the usage records). We never receive the full card number
Shared link records: what recreates the mission card (random seed, mission number, launch time, number of name rerolls), the crew name you typed (up to 12 characters), the sender's display language
Source Your browser sends them when you share a link. They contain no photo
Pseudonymized IP address (a value that cannot be turned back into the address) and the number of free launches that day
Source Our server creates it when you launch for free
IP address
Source Our server provider receives it with each request. We use it only while handling the request, for the pseudonymization above and request rate limits
Usage records: device id (a random value, different from the device cookie), screen paths viewed, names of features tapped with short values (grade, share method), the domain of the site you came from, display language, country (estimated from IP address), utm values if you came from an ad, payment amount
Source Your browser sends them (how consent works in each region is under "Consent and how to turn it off" below). Our server provider tells us the country from your IP address. The payment amount is recorded by our server after payment, and the country on that line is the billing country the merchant of record tells us
Support emails: the sender's email address and the message
Source Emails you send us
The email and card details you enter at checkout go directly to the merchant of record. When checkout ends by moving to another page, the merchant of record adds the payment number, payment status and the payer's email to the address it sends you back to, and our page removes these values from the address as soon as it opens.
What stays on this device
- Photo: the photo you pick is cropped and composited into the 3D space scene only inside this browser. The photo file and its pixels are never sent to our server or anywhere else.
- Last photo while you pay: so you can continue with the same photo after visiting checkout, we keep your last photo in this browser's storage (IndexedDB) only when checkout opens. We delete it as soon as it is reused or checkout closes, and if you never come back, it is deleted the next time you open the site after a day has passed.
- Last result: so your result does not disappear when you go back or reload, we keep in this browser's storage (IndexedDB) the result image you shot and the values needed to redraw the result screen (launch number and launch ticket, mission, ride type, crew name, number of name rerolls, and when you gave consent before paying). Your next shot replaces it, and it is deleted the next time you open the site after a day has passed.
- Result images: selfies and mission cards are made in this browser. Saving and sharing go straight through your device's save and share features without passing through our server.
- Values kept on this device: your display language, shutter sound setting, the ride type you picked last (spacesuit or satellite TV), title collection, the number of launches on this device, a mark that you opted out of sale and sharing (if you did), and the device id, ad utm values and TikTok ad click id used for usage records (not kept in the EU, the UK or Switzerland).
We do not store these values on our servers. You can delete all of them by clearing site data in your browser.
How long we keep data
Retention periods for each type of data are below.
Device cookie (a random device identifier), whether you used your free shot, when it was created and last used
Purpose Counting the free shot and paid shots for each browser
Retention 400 days from last use (same as the cookie's lifetime)
Launch records (launch number, free or paid, status, random seed, mission number you came from, times, number of resumes)
Purpose Checking launches, numbering missions
Retention 1 year from launch. Launches used with a payment are kept with the payment record for 5 years
Pseudonymized IP address and that day's free launches, requests within a short time
Purpose Daily free limit per network and request rate limits (preventing abuse)
Retention 2 days
Checkout records (payment reference, device cookie value, screen with the pay button, number of tickets chosen, usage record device id and utm values, checkout session number, time, and in the EU and the UK the time and wording version of your consent before paying)
Purpose Linking a payment to the browser that paid
Retention 30 days if not paid. If paid, 5 years with the payment record
Payment records (payment number, amount and currency, test or not, refunded or not, time, device cookie value that paid)
Purpose Adding paid shots and refunds, keeping transaction records
Retention 5 years from payment — Korean E-Commerce Act Enforcement Decree Art. 6(1) (records of payment and supply, 5 years)
Shared link records (mission card details, crew name, sender's display language — no photo)
Purpose Showing the same mission card to people who open the link
Retention 30 days from creation
Usage records (random device id, screens viewed, features tapped, where you came from, language, country, utm values, payment amount)
Purpose Seeing where people get stuck so we can fix it (our own analytics)
Retention 3 months from collection
Ad signals (ad cookie ids, IP address, browser and device details, page address, ad interactions — sent by your browser directly to Google)
Purpose Showing and measuring ads
Retention We do not keep them — under Google's policy
Support email address and content
Purpose Answering your questions, records of consumer complaints and disputes
Retention 3 years from collection — Korean E-Commerce Act Enforcement Decree Art. 6(1) (records of consumer complaints and disputes, 3 years)
What stays on this device (photo, last photo for checkout, last result image, display settings, title collection, sale and sharing opt-out mark, usage record id)
Purpose Continuing to use the service on this device
Retention On this device only (removed when you clear site data)
Payment and support records we must keep by law are kept apart from other records for the period set by the law shown in the Retention column.
How we delete data
When the retention period ends or the purpose is fulfilled, we delete the data without delay so that it cannot be recovered. Electronic records are deleted in a way that cannot be undone.
Records we must keep by law, such as payment records, are stored apart and used only for that purpose, then deleted when the period ends.
Deleted records remain in backups for up to 30 days and then disappear.
Disclosure to third parties
We never sell personal data for money. However, the companies in the table below are not processors that only do our work on our behalf: they receive data directly and handle it under their own policies. This is called disclosure to third parties (handing data to others who also use it for their own purposes). The recipients, purposes, data, retention and how to refuse are below.
Dodo Payments
Recipient's own purposes As reseller: payment, tax calculation and payment, refunds, fraud prevention
Data The email and card details and billing country you enter at checkout, connection data (IP address, browser details), and the product, currency, display language and payment reference our server passes on
Retention Periods set by the provider's policy and tax law
How to refuse, and what happens If you refuse you cannot pay (you can still use the free shot)
Country United States
Privacy policy dodopayments.com/legal/privacy-policy
Google LLC (Google AdSense)
Recipient's own purposes Showing and measuring ads, personalized ads, improving its own ad services (Google's policy)
Data Ad cookie ids, IP address, browser and device details, the address of the page you are viewing, ad interactions
Retention Under Google's policy
How to refuse, and what happens You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service
Country United States
Privacy policy policies.google.com/privacy
- Merchant of record Dodo Payments: you buy launch tickets from Dodo Payments. The email and card details you enter at checkout go directly to Dodo Payments; when checkout is created (in advance, when the pay button is on screen), our server passes on only the product, currency, display language and payment reference (plus the billing country "Republic of Korea" on the Korean site). This is needed to pay, so if you refuse you cannot pay.
- Ad provider Google AdSense: on screens with an ad slot, your browser requests ads directly. Google uses the data it receives to show ads and measure them, and can also use it to improve its own ad services. In Korea we disclose this in this policy without asking for separate consent, and you can turn personalized ads off in Google Ad Settings. Under some US state laws this can count as "sharing" personal data, and how to opt out is in the Your Privacy Choices section below.
Otherwise, we give personal data to third parties only if the law requires it or you separately agree.
Processors we use
We use the providers below. We require them, through their terms and data processing terms, to use personal data only for the work we give them and to protect it to the same standard as this policy.
Cloudflare, Inc.
What we use it for Servers, databases and shared link storage, keeping our usage records, forwarding support emails
Country United States
Privacy policy www.cloudflare.com/privacypolicy
NAVER Corp. (네이버 메일)
What we use it for Support email inbox
Country South Korea
Privacy policy policy.naver.com/policy/privacy.html
The merchant of record and the ad provider handle the data they receive under their own policies, so they are listed under "Disclosure to third parties" above rather than in this table.
Sub-processors used by these providers are listed in each provider's policy linked in the table. If a processor changes, we will update this policy and let you know.
International transfers
Personal data is transferred to the providers in the two tables above that are outside Korea. Details are below, including each recipient's privacy contact and the basis for each transfer.
Cloudflare, Inc. — dpo@cloudflare.com
Country United States
Data transferred All server-side data in this policy (device cookie, launch and payment records, shared links, usage records) and your IP address when you connect
When and how Each time you use the service, over an encrypted internet connection
Purpose Servers, databases and shared link storage, keeping our usage records, forwarding support emails
Retention As in the retention table above (restore history up to 30 days more)
Basis Korea: use of a processor and storage needed to perform our contract (PIPA Art. 28-8(1)(3)). EU and UK: Korea's adequacy decision, and the provider's DPF certification or standard contractual clauses (SCCs)
How to refuse, and what happens It is essential to the service, so if you refuse you cannot use it
Dodo Payments — support@dodopayments.com
Country United States
Data transferred The email and card details and billing country you enter at checkout, connection data (IP address, browser details), and the product, currency, display language and payment reference our server passes on
When and how When checkout is created (in advance, when the pay button is on screen) and when you pay, over an encrypted internet connection
Purpose Payment processing, tax calculation and payment, refund payouts (including what it is directly responsible for as merchant of record)
Retention Periods set by the provider's policy and tax law
Basis Korea: needed for the contract under which you buy launch tickets from Dodo Payments. EU and UK: necessary for the performance of the contract (GDPR Art. 49(1)(b))
How to refuse, and what happens If you refuse you cannot pay (you can still use the free shot)
Google LLC (Google AdSense) — Contact form
Country United States
Data transferred Ad cookie ids, IP address, browser and device details, the address of the page you are viewing, ad interactions
When and how Directly from your browser when you open a screen with an ad slot
Purpose Showing ads and measuring them (screens with an ad slot)
Retention Under Google's policy
Basis Korea: not strictly needed for the contract — disclosed in this policy without separate consent. EU and UK: consent (Google's consent message), and the provider's DPF certification or standard contractual clauses (SCCs)
How to refuse, and what happens You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service
Basis: Korea — the transfer to our server provider is use of a processor needed to perform our contract, disclosed in this policy (PIPA Art. 28-8(1)(3)). The transfer to the merchant of record is needed for the contract under which you buy launch tickets. The transfer to the ad provider is not strictly needed for the contract; we disclose it in this policy and do not ask for separate consent in Korea.
EU and UK — Korea, where we are based, has an EU adequacy decision (2022/254). For transfers to US providers, the provider is certified under the EU-U.S. Data Privacy Framework (DPF) or uses standard contractual clauses (SCCs).
Japan — each recipient maintains, through its contract with us, a system that meets the standards of Japan's Act on the Protection of Personal Information. On request, we tell you how that system is set up, an outline of the measures the recipient takes, and how we check them (APPI Art. 28(3) and Enforcement Rules Art. 18).
Laws in the receiving country: the United States has no comprehensive federal privacy law, only state laws. Each provider is bound by contract to protect your data to the same standard as this policy.
How to refuse, and what happens: transfers for servers and payments are essential to the service, so if you refuse you cannot launch or pay. For the ad provider, you can turn personalized ads off in Google Ad Settings or limit it as described in Consent and how to turn it off, and you can still use the service.
What we store and read
Useless Space Selfie stores and reads one cookie and some browser storage values. Some are essential for the service, such as counting your free shot and the shots you paid for, or your display settings; others are used for our own usage records.
On screens with an ad slot, Google's ad tools store and read cookies.
Cookies and ads
Set by Useless Space Selfie:
wj_owner (cookie)
Purpose Counting the free shot and paid tickets for each browser
Duration 400 days from last use
Essential Yes
wj_dnss (cookie)
Purpose Remembering that you opted out of sale and sharing — this browser's ads are requested with restricted data processing (not personalized)
Duration 400 days
Essential Yes
wj_lang · wj_sound · wj_mode · wj_dex · wj_launches (localStorage)
Purpose Your display language, shutter sound setting, the ride type you picked last (spacesuit or satellite TV), title collection, and the number of launches on this device (to skip the launch sequence from your second launch)
Duration Until deleted
Essential Yes
wooju (IndexedDB, store photo — keys last · result)
Purpose Continuing with the same photo after visiting checkout (last — your last photo), and keeping your result when you go back or reload (result — your last result image and the values to redraw the result screen)
Duration last is deleted as soon as it is reused or checkout closes, result is replaced by your next shot — both are deleted the next time you open the site after a day has passed
Essential Yes
wj_paid_before, wj_consent_at (sessionStorage)
Purpose Checking whether your paid tickets went up when you return from checkout, and for visitors from the EU, the EEA and the UK, when you gave consent before paying (shown in the confirmation on the result screen)
Duration Until you close the tab
Essential Yes
wooju:sid · wooju:utm · wooju:ttclid (localStorage), wooju:ad_land:… (sessionStorage)
Purpose Our usage records — a random device id, the utm values and TikTok ad click id (ttclid) of the ad you came from, and counting an ad arrival once. Not set in the EU, the UK or Switzerland
Duration Device id until deleted, utm values and click id 7 days, ad arrival mark until you close the tab
Essential No
wooju:notrack (localStorage)
Purpose Remembering that you turned usage records off
Duration Until deleted
Essential Yes
Tools from other companies:
Google LLC (Google AdSense)
Purpose Showing and measuring ads, personalized ads
Cookies Google ad cookies (__gads and __gpi on this site, IDE on doubleclick.net)
Duration As set out in Google's cookie information
Country United States
Essential No
How to turn off You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service
Checkout: when you tap pay, the checkout of the merchant of record Dodo Payments opens and can use its own cookies needed for processing payments and preventing fraud.
On screens with an ad slot, third-party vendors, including Google, use cookies to serve ads based on your prior visits to this site or other sites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and/or other sites on the Internet.
You can opt out of personalized advertising in Google Ad Settings. You can opt out of other vendors' use of cookies for personalized advertising at aboutads.info or youronlinechoices.eu.
To learn how Google uses this information, see How Google uses information from sites that use its services.
If you delete the device cookie, we can no longer find your free-shot record or the shots you paid for in this browser. Consent by region and how to turn things off are in the next section.
Consent and how to turn it off
- Korea: we disclose our usage records and the ad tools in this policy and do not ask for separate consent. You can turn them off at any time as described below.
- EU, UK and Switzerland: cookies and storage that are not strictly necessary may only be used with your consent. When you visit from these countries (judged by IP address), we keep no usage records of our own. On screens with an ad slot, Google's consent message asks for your consent before ad cookies are used, and you can use the service without consenting.
- United States: you can opt this browser out of sharing and sale for targeted advertising in the Your Privacy Choices section below, and we treat a browser's GPC signal as the same opt-out.
How to turn it off: Turn off usage records in this browser — open it once and our usage records stay off in this browser (turn back on). You can turn personalized ads off in Google Ad Settings. You can also clear or block cookies in your browser settings, but if you block essential cookies, we cannot count your free shot or the shots you paid for, and you cannot launch.
The one line our server records after a payment (the payment amount in usage records) is not turned off this way.
Global Privacy Control (GPC)
We treat a Global Privacy Control (GPC) signal from your browser as an opt-out of sale and sharing. Details are in Opting out with Global Privacy Control (GPC) below.
Advertising ID
On screens with an ad slot, Google shows ads using ad cookies in your browser rather than your phone's advertising ID. You can turn personalized ads off in Google Ad Settings, and you can block third-party cookies in your browser settings.
Children and minors
Useless Space Selfie is for people aged 13 or older (14 or older in Korea). The age at which someone counts as a child differs by country (under 14 in Korea, under 13 in the US, under 13 to 16 in the EU), but the service is not directed to children.
We do not knowingly collect children's personal data. If we learn that a child's data has reached us, we delete it. Parents can ask for deletion at support@bang9.dev.
We do not target personalized ads at children.
Your rights and how to use them
You can ask at any time to access, correct, delete or stop the processing of your personal data, and withdraw consent for processing you agreed to.
What you can do right now: anything on this device (your last photo and result, title collection, display settings, usage record id) can be deleted by clearing site data in your browser. You can turn off our usage records with Turn off usage records in this browser, and personalized ads in Google Ad Settings.
For requests about server records, email support@bang9.dev. Server records are linked to the device cookie in your browser. If you paid, include the payment number from your receipt email; for a shared link, include the link. If you give us little to go on, we answer as far as we can find. A legal representative or someone you authorize can also ask on your behalf with a written authorization.
We reply to users in Korea within 10 days of receiving the request (PIPA Enforcement Decree Art. 41), and to users elsewhere within the deadline set by the law where they live. If we cannot do what you ask, we tell you why, and you can ask us to review it again at the same email.
Your Privacy Choices
Under the privacy laws of several US states, you can opt out of the sale and sharing of your personal information right here. The status of this browser is just below; if this browser has not opted out yet, you can opt out right there.
Do Not Sell or Share My Personal Information
We do not sell personal information for money. However, ad signals sent to Google on screens with an ad slot (ad cookie ids, the address of the page you are viewing) can count as "sharing" or a "sale" for targeted advertising under some US state laws.
How to opt out: (1) Tap "Opt out in this browser" under "Status in this browser" above (a browser that sends a GPC signal is already opted out, so the link is not shown). We set an opt-out cookie in this browser and request its ads under Google's "restricted data processing", so no personalized ads are requested (Google then acts only as our service provider). (2) You can turn Google's personalized ads off in Google Ad Settings. (3) Email support@bang9.dev with "Do not sell or share".
An opt-out applies only to that browser. Please opt out separately in other browsers and on other devices. Clearing your browser's cookies also clears the opt-out in (1).
Opting out with Global Privacy Control (GPC)
When your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of sale and sharing, so no personalized ads are requested in that browser. "Status in this browser" above shows whether we received the signal.
Appeals
If we cannot do what you ask, we tell you why. If you disagree, email the same address with "Appeal". We tell you the result within 60 days, and if it is still not resolved you can contact your state attorney general.
How we protect data
- Organizational: only authorized people can access personal data and our providers' admin consoles.
- Technical: all traffic is encrypted (HTTPS). The device cookie cannot be read by scripts. IP addresses are pseudonymized and counted per day only. We check signatures on launch tickets and payment notifications to prevent forgery, and request rates are limited.
- Physical: servers run in our providers' data centers.
Where to get help
If you need help with a privacy issue, please tell us first at support@bang9.dev. You can also contact these Korean agencies:
- Personal Information Dispute Mediation Committee: 1833-6972 (kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
Users in the EU, the EEA and the UK can complain to their local data protection authority (see "Users in the EU, EEA and UK" below).
Changes to this policy
This policy (version 1) was announced on October 1, 2026 and takes effect on October 1, 2026.
If we change this policy, we'll announce it on this page before the change takes effect (on the effective date at the latest) and show what changed side by side with the previous version. If a new purpose or a new recipient is added, we'll tell you before that processing starts and ask for your consent where the law requires it.
Language
This document was originally written in Korean. Translations are provided for convenience. If they differ, the original prevails, unless the law of the country where you live says otherwise.
Users in the EU, EEA and UK
The controller is winterlog studio (contact details above under "Who is responsible").
Our legal bases are listed above under "Why we use your data". You can object at any time to processing based on legitimate interests (preventing abuse); if you do, we stop unless we can show compelling legitimate grounds.
Your rights: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (processing before withdrawal remains lawful). Send requests to support@bang9.dev. We do not make decisions that have legal effects on you based solely on automated processing.
International transfers: Korea, where we are based, has an adequacy decision. For US providers we rely on the DPF or standard contractual clauses (SCCs). The basis for each provider is in the "International transfers" table above. You can request a copy of the SCCs at support@bang9.dev.
If you do not provide data: without the data the service needs (the device cookie, payment details), you cannot use those features. No law requires you to provide it.
Cookies: cookies and storage that are not strictly necessary may only be used with your consent. When you visit from these countries we keep no usage records of our own, and on screens with an ad slot Google's consent message asks for your consent before ad cookies are used.
Complaints: you can complain to the supervisory authority where you live, work or where the issue occurred (the ICO in the UK). If you are in the UK and send us a complaint first, we acknowledge it within 30 days (UK Data (Use and Access) Act 2025).
Users in the United States
Categories of personal information collected in the past 12 months: identifiers (device cookie id, usage record device id, IP address, ad cookie ids), commercial information (payment records), internet activity (screens viewed, features tapped), approximate location (country estimated from IP address), and content you write (crew names, support emails). Sources, purposes, recipients and retention are as described in the sections above.
Selling and sharing: we do not sell personal information for money. Ad signals sent to Google on screens with an ad slot can count as "sharing" for targeted advertising under state laws, and you can opt out at Your Privacy Choices.
Sensitive personal information: we do not collect it.
Your rights: to know, delete, correct, obtain a copy, and opt out of selling and sharing. We will not discriminate against you for using them. Email support@bang9.dev and we reply within 45 days. If we refuse, you can appeal at the same email, and if the appeal does not resolve it, you can contact your state attorney general.
Do Not Track: we do not respond to browser Do Not Track signals. We treat a Global Privacy Control (GPC) signal as an opt-out of sale and sharing, so no personalized ads are requested in that browser (Your Privacy Choices).
Third-party tracking: the ad provider can collect information about your activity on this site and other sites.
When this policy changes, we post it on this page with the effective date.
Users in Japan
The name, address and owner of the business handling personal information are listed above under "Who is responsible". The purposes of use of retained personal data are listed under "Why we use your data".
Send requests for disclosure, correction, suspension of use or disclosure of third-party provision records to support@bang9.dev. There is no fee.
Our security measures are described under "How we protect data". Personal data is handled in Korea, where we are based, and by providers in the United States. We have looked into the privacy systems of those countries and take security measures accordingly (awareness of the foreign environment). Korea has the Personal Information Protection Act and a supervisory authority, the Personal Information Protection Commission, and has an EU adequacy decision. The United States has no comprehensive federal privacy law, only state laws.
The names, countries and contact details of foreign providers, the systems in those countries, the measures the providers take, and how to request information about their qualifying systems are in the "International transfers" section above.
Our public notice on external transmission is in the External Transmission Disclosure (Japan) section above.
Complaints and inquiries: support@bang9.dev