← Back to Useless Space Selfie

Privacy Policy

Effective October 1, 2026 · Version 1

Useless Space Selfie is a web service that turns your pet photo into a spacesuit selfie inside your browser. Your photo is processed only on this device, and you use the service without an account.

At a glance

winterlog studio ("we", "us") runs Useless Space Selfie (wooju.bang9.dev). This policy explains what personal data we handle and why, who we share the work with, and how long we keep it.

  • What: a random device cookie we create for each browser and the launch and payment records linked to it, a pseudonymized IP address used to count the free limit per network, the crew name you enter when you share a link, and usage records. Your pet photo is processed only on this device.
  • Why: to count your free shot and the shots you paid for, show shared links, process payments and refunds, prevent abuse, and improve the service.
  • Who and where: our servers run on Cloudflare (United States). The merchant of record Dodo Payments (United States) receives payments directly, and on screens with an ad slot your browser requests ads from Google AdSense (United States). Their names and countries are in the tables below.
  • Worth knowing: on screens with an ad slot, Google can use cookies to collect your visits to this site and other sites and show you personalized ads. In the EU, the UK and Switzerland this happens only after you consent, and we keep no usage records of our own there.
  • How long: device records for 400 days from last use (same as the cookie's lifetime), shared links for 30 days from creation, and payment records for 5 years from payment. Everything else is in the "How long we keep data" table below.
  • Your rights and contact: you can ask to access, correct, delete or stop processing your data at support@bang9.dev. Anything on this device can be deleted right away by clearing site data in your browser.

Who is responsible

Controller: winterlog studio

  • Owner: Hyungu Kang
  • Address: 5-12 Gwangmyeong-ro 347beon-gil, Jungwon-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
  • Phone: +82-10-9688-1157
  • Email: support@bang9.dev
  • Business registration number: 577-24-02412

Privacy contact

Our privacy contact (the person who handles privacy questions and complaints) is the owner, Hyungu Kang.

Contact: email support@bang9.dev · phone +82-10-9688-1157

Why we use your data and on what basis

What we process without asking for consent (needed to perform our contract with you, to follow the law, or to protect the service):

Counting your free shot and the shots you paid for, numbering launches

Data used Device cookie, launch records

Basis Performance of our contract (Korean PIPA Art. 15(1)(4), GDPR Art. 6(1)(b))

Showing the mission card of a link you shared

Data used Shared link records

Basis Performance of our contract — only when you choose to share a link

Confirming payments, adding the shots you paid for, refunds

Data used Checkout records, payment records

Basis Performance of our contract

Keeping transaction records

Data used Payment records, support emails

Basis Legal obligation (Korean E-Commerce Act, PIPA Art. 15(1)(2), GDPR Art. 6(1)(c))

Answering your questions

Data used Support emails

Basis Performance of our contract

Preventing abuse — the daily free limit per network and request rate limits

Data used Pseudonymized IP address, IP address

Basis Legitimate interest: blocking mass requests that get around the free limit, so we can keep running the service (PIPA Art. 15(1)(6), GDPR Art. 6(1)(f))

Our own usage analytics — seeing where people get stuck so we can fix it

Data used Usage records

Basis Legitimate interest: making the service easier to use. We do not record visitors from the EU, the UK or Switzerland

What we process with consent:

  • Personalized ads (Google AdSense) — in the EU, the UK and Switzerland, Google's consent message asks for your consent on screens with an ad slot (GDPR Art. 6(1)(a)). In Korea we disclose the recipient, data, purposes and retention in this policy and do not ask for separate consent, and you can turn personalized ads off at any time.

What we collect and where it comes from

Device cookie (a random device identifier our server creates), whether you used your free shot, when it was created, when it was last used

Source Our server creates it and stores it in your browser on your first visit

Launch records: launch number, free or paid, status, a random seed that recreates the mission, the mission number you came from if you opened a shared link, launch and finish times, number of resumed shots

Source Our server creates them when you launch

Checkout records: a random payment reference, your device cookie value, the screen with the pay button, the number of tickets chosen, the device id and ad utm values used for usage records, the Dodo checkout session number, when checkout was created, and when you gave consent to immediate supply before paying, with the version of that wording (visitors from the EU, the EEA and the UK only)

Source Created in advance when the pay button is on screen and you can pay right away (the usage record values are absent for visitors from the EU, the UK and Switzerland)

Payment records: Dodo payment number, amount and currency, whether it was a test payment, whether it was refunded, payment time

Source The merchant of record tells us the payment result. That notice may include the payer's email, name, phone number, billing address and the last four digits of the card, but we do not store them (only the billing country goes on the payment line of the usage records). We never receive the full card number

Shared link records: what recreates the mission card (random seed, mission number, launch time, number of name rerolls), the crew name you typed (up to 12 characters), the sender's display language

Source Your browser sends them when you share a link. They contain no photo

Pseudonymized IP address (a value that cannot be turned back into the address) and the number of free launches that day

Source Our server creates it when you launch for free

IP address

Source Our server provider receives it with each request. We use it only while handling the request, for the pseudonymization above and request rate limits

Usage records: device id (a random value, different from the device cookie), screen paths viewed, names of features tapped with short values (grade, share method), the domain of the site you came from, display language, country (estimated from IP address), utm values if you came from an ad, payment amount

Source Your browser sends them (how consent works in each region is under "Consent and how to turn it off" below). Our server provider tells us the country from your IP address. The payment amount is recorded by our server after payment, and the country on that line is the billing country the merchant of record tells us

Support emails: the sender's email address and the message

Source Emails you send us

The email and card details you enter at checkout go directly to the merchant of record. When checkout ends by moving to another page, the merchant of record adds the payment number, payment status and the payer's email to the address it sends you back to, and our page removes these values from the address as soon as it opens.

What stays on this device

  • Photo: the photo you pick is cropped and composited into the 3D space scene only inside this browser. The photo file and its pixels are never sent to our server or anywhere else.
  • Last photo while you pay: so you can continue with the same photo after visiting checkout, we keep your last photo in this browser's storage (IndexedDB) only when checkout opens. We delete it as soon as it is reused or checkout closes, and if you never come back, it is deleted the next time you open the site after a day has passed.
  • Last result: so your result does not disappear when you go back or reload, we keep in this browser's storage (IndexedDB) the result image you shot and the values needed to redraw the result screen (launch number and launch ticket, mission, ride type, crew name, number of name rerolls, and when you gave consent before paying). Your next shot replaces it, and it is deleted the next time you open the site after a day has passed.
  • Result images: selfies and mission cards are made in this browser. Saving and sharing go straight through your device's save and share features without passing through our server.
  • Values kept on this device: your display language, shutter sound setting, the ride type you picked last (spacesuit or satellite TV), title collection, the number of launches on this device, a mark that you opted out of sale and sharing (if you did), and the device id, ad utm values and TikTok ad click id used for usage records (not kept in the EU, the UK or Switzerland).

We do not store these values on our servers. You can delete all of them by clearing site data in your browser.

How long we keep data

Retention periods for each type of data are below.

Device cookie (a random device identifier), whether you used your free shot, when it was created and last used

Purpose Counting the free shot and paid shots for each browser

Retention 400 days from last use (same as the cookie's lifetime)

Launch records (launch number, free or paid, status, random seed, mission number you came from, times, number of resumes)

Purpose Checking launches, numbering missions

Retention 1 year from launch. Launches used with a payment are kept with the payment record for 5 years

Pseudonymized IP address and that day's free launches, requests within a short time

Purpose Daily free limit per network and request rate limits (preventing abuse)

Retention 2 days

Checkout records (payment reference, device cookie value, screen with the pay button, number of tickets chosen, usage record device id and utm values, checkout session number, time, and in the EU and the UK the time and wording version of your consent before paying)

Purpose Linking a payment to the browser that paid

Retention 30 days if not paid. If paid, 5 years with the payment record

Payment records (payment number, amount and currency, test or not, refunded or not, time, device cookie value that paid)

Purpose Adding paid shots and refunds, keeping transaction records

Retention 5 years from payment — Korean E-Commerce Act Enforcement Decree Art. 6(1) (records of payment and supply, 5 years)

Shared link records (mission card details, crew name, sender's display language — no photo)

Purpose Showing the same mission card to people who open the link

Retention 30 days from creation

Usage records (random device id, screens viewed, features tapped, where you came from, language, country, utm values, payment amount)

Purpose Seeing where people get stuck so we can fix it (our own analytics)

Retention 3 months from collection

Ad signals (ad cookie ids, IP address, browser and device details, page address, ad interactions — sent by your browser directly to Google)

Purpose Showing and measuring ads

Retention We do not keep them — under Google's policy

Support email address and content

Purpose Answering your questions, records of consumer complaints and disputes

Retention 3 years from collection — Korean E-Commerce Act Enforcement Decree Art. 6(1) (records of consumer complaints and disputes, 3 years)

What stays on this device (photo, last photo for checkout, last result image, display settings, title collection, sale and sharing opt-out mark, usage record id)

Purpose Continuing to use the service on this device

Retention On this device only (removed when you clear site data)

Payment and support records we must keep by law are kept apart from other records for the period set by the law shown in the Retention column.

How we delete data

When the retention period ends or the purpose is fulfilled, we delete the data without delay so that it cannot be recovered. Electronic records are deleted in a way that cannot be undone.

Records we must keep by law, such as payment records, are stored apart and used only for that purpose, then deleted when the period ends.

Deleted records remain in backups for up to 30 days and then disappear.

Disclosure to third parties

We never sell personal data for money. However, the companies in the table below are not processors that only do our work on our behalf: they receive data directly and handle it under their own policies. This is called disclosure to third parties (handing data to others who also use it for their own purposes). The recipients, purposes, data, retention and how to refuse are below.

Dodo Payments

Recipient's own purposes As reseller: payment, tax calculation and payment, refunds, fraud prevention

Data The email and card details and billing country you enter at checkout, connection data (IP address, browser details), and the product, currency, display language and payment reference our server passes on

Retention Periods set by the provider's policy and tax law

How to refuse, and what happens If you refuse you cannot pay (you can still use the free shot)

Country United States

Privacy policy dodopayments.com/legal/privacy-policy

Google LLC (Google AdSense)

Recipient's own purposes Showing and measuring ads, personalized ads, improving its own ad services (Google's policy)

Data Ad cookie ids, IP address, browser and device details, the address of the page you are viewing, ad interactions

Retention Under Google's policy

How to refuse, and what happens You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service

Country United States

Privacy policy policies.google.com/privacy

  • Merchant of record Dodo Payments: you buy launch tickets from Dodo Payments. The email and card details you enter at checkout go directly to Dodo Payments; when checkout is created (in advance, when the pay button is on screen), our server passes on only the product, currency, display language and payment reference (plus the billing country "Republic of Korea" on the Korean site). This is needed to pay, so if you refuse you cannot pay.
  • Ad provider Google AdSense: on screens with an ad slot, your browser requests ads directly. Google uses the data it receives to show ads and measure them, and can also use it to improve its own ad services. In Korea we disclose this in this policy without asking for separate consent, and you can turn personalized ads off in Google Ad Settings. Under some US state laws this can count as "sharing" personal data, and how to opt out is in the Your Privacy Choices section below.

Otherwise, we give personal data to third parties only if the law requires it or you separately agree.

Processors we use

We use the providers below. We require them, through their terms and data processing terms, to use personal data only for the work we give them and to protect it to the same standard as this policy.

Cloudflare, Inc.

What we use it for Servers, databases and shared link storage, keeping our usage records, forwarding support emails

Country United States

Privacy policy www.cloudflare.com/privacypolicy

NAVER Corp. (네이버 메일)

What we use it for Support email inbox

Country South Korea

Privacy policy policy.naver.com/policy/privacy.html

The merchant of record and the ad provider handle the data they receive under their own policies, so they are listed under "Disclosure to third parties" above rather than in this table.

Sub-processors used by these providers are listed in each provider's policy linked in the table. If a processor changes, we will update this policy and let you know.

International transfers

Personal data is transferred to the providers in the two tables above that are outside Korea. Details are below, including each recipient's privacy contact and the basis for each transfer.

Cloudflare, Inc. — dpo@cloudflare.com

Country United States

Data transferred All server-side data in this policy (device cookie, launch and payment records, shared links, usage records) and your IP address when you connect

When and how Each time you use the service, over an encrypted internet connection

Purpose Servers, databases and shared link storage, keeping our usage records, forwarding support emails

Retention As in the retention table above (restore history up to 30 days more)

Basis Korea: use of a processor and storage needed to perform our contract (PIPA Art. 28-8(1)(3)). EU and UK: Korea's adequacy decision, and the provider's DPF certification or standard contractual clauses (SCCs)

How to refuse, and what happens It is essential to the service, so if you refuse you cannot use it

Dodo Payments — support@dodopayments.com

Country United States

Data transferred The email and card details and billing country you enter at checkout, connection data (IP address, browser details), and the product, currency, display language and payment reference our server passes on

When and how When checkout is created (in advance, when the pay button is on screen) and when you pay, over an encrypted internet connection

Purpose Payment processing, tax calculation and payment, refund payouts (including what it is directly responsible for as merchant of record)

Retention Periods set by the provider's policy and tax law

Basis Korea: needed for the contract under which you buy launch tickets from Dodo Payments. EU and UK: necessary for the performance of the contract (GDPR Art. 49(1)(b))

How to refuse, and what happens If you refuse you cannot pay (you can still use the free shot)

Google LLC (Google AdSense) — Contact form

Country United States

Data transferred Ad cookie ids, IP address, browser and device details, the address of the page you are viewing, ad interactions

When and how Directly from your browser when you open a screen with an ad slot

Purpose Showing ads and measuring them (screens with an ad slot)

Retention Under Google's policy

Basis Korea: not strictly needed for the contract — disclosed in this policy without separate consent. EU and UK: consent (Google's consent message), and the provider's DPF certification or standard contractual clauses (SCCs)

How to refuse, and what happens You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service

Basis: Korea — the transfer to our server provider is use of a processor needed to perform our contract, disclosed in this policy (PIPA Art. 28-8(1)(3)). The transfer to the merchant of record is needed for the contract under which you buy launch tickets. The transfer to the ad provider is not strictly needed for the contract; we disclose it in this policy and do not ask for separate consent in Korea.

EU and UK — Korea, where we are based, has an EU adequacy decision (2022/254). For transfers to US providers, the provider is certified under the EU-U.S. Data Privacy Framework (DPF) or uses standard contractual clauses (SCCs).

Japan — each recipient maintains, through its contract with us, a system that meets the standards of Japan's Act on the Protection of Personal Information. On request, we tell you how that system is set up, an outline of the measures the recipient takes, and how we check them (APPI Art. 28(3) and Enforcement Rules Art. 18).

Laws in the receiving country: the United States has no comprehensive federal privacy law, only state laws. Each provider is bound by contract to protect your data to the same standard as this policy.

How to refuse, and what happens: transfers for servers and payments are essential to the service, so if you refuse you cannot launch or pay. For the ad provider, you can turn personalized ads off in Google Ad Settings or limit it as described in Consent and how to turn it off, and you can still use the service.

What we store and read

Useless Space Selfie stores and reads one cookie and some browser storage values. Some are essential for the service, such as counting your free shot and the shots you paid for, or your display settings; others are used for our own usage records.

On screens with an ad slot, Google's ad tools store and read cookies.

Cookies and ads

Set by Useless Space Selfie:

wj_owner (cookie)

Purpose Counting the free shot and paid tickets for each browser

Duration 400 days from last use

Essential Yes

wj_dnss (cookie)

Purpose Remembering that you opted out of sale and sharing — this browser's ads are requested with restricted data processing (not personalized)

Duration 400 days

Essential Yes

wj_lang · wj_sound · wj_mode · wj_dex · wj_launches (localStorage)

Purpose Your display language, shutter sound setting, the ride type you picked last (spacesuit or satellite TV), title collection, and the number of launches on this device (to skip the launch sequence from your second launch)

Duration Until deleted

Essential Yes

wooju (IndexedDB, store photo — keys last · result)

Purpose Continuing with the same photo after visiting checkout (last — your last photo), and keeping your result when you go back or reload (result — your last result image and the values to redraw the result screen)

Duration last is deleted as soon as it is reused or checkout closes, result is replaced by your next shot — both are deleted the next time you open the site after a day has passed

Essential Yes

wj_paid_before, wj_consent_at (sessionStorage)

Purpose Checking whether your paid tickets went up when you return from checkout, and for visitors from the EU, the EEA and the UK, when you gave consent before paying (shown in the confirmation on the result screen)

Duration Until you close the tab

Essential Yes

wooju:sid · wooju:utm · wooju:ttclid (localStorage), wooju:ad_land:… (sessionStorage)

Purpose Our usage records — a random device id, the utm values and TikTok ad click id (ttclid) of the ad you came from, and counting an ad arrival once. Not set in the EU, the UK or Switzerland

Duration Device id until deleted, utm values and click id 7 days, ad arrival mark until you close the tab

Essential No

wooju:notrack (localStorage)

Purpose Remembering that you turned usage records off

Duration Until deleted

Essential Yes

Tools from other companies:

Google LLC (Google AdSense)

Purpose Showing and measuring ads, personalized ads

Cookies Google ad cookies (__gads and __gpi on this site, IDE on doubleclick.net)

Duration As set out in Google's cookie information

Country United States

Essential No

How to turn off You can turn personalized ads off in Google Ad Settings, and in the EU, the UK and Switzerland you can decline in Google's consent message. You can still use the service

Checkout: when you tap pay, the checkout of the merchant of record Dodo Payments opens and can use its own cookies needed for processing payments and preventing fraud.

On screens with an ad slot, third-party vendors, including Google, use cookies to serve ads based on your prior visits to this site or other sites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and/or other sites on the Internet.

You can opt out of personalized advertising in Google Ad Settings. You can opt out of other vendors' use of cookies for personalized advertising at aboutads.info or youronlinechoices.eu.

To learn how Google uses this information, see How Google uses information from sites that use its services.

If you delete the device cookie, we can no longer find your free-shot record or the shots you paid for in this browser. Consent by region and how to turn things off are in the next section.

Global Privacy Control (GPC)

We treat a Global Privacy Control (GPC) signal from your browser as an opt-out of sale and sharing. Details are in Opting out with Global Privacy Control (GPC) below.

External Transmission Disclosure (Japan)

This site sends information from your browser to the companies below (Japan's Telecommunications Business Act, Art. 27-12). The Japanese version of this section is the disclosure required by that law.

Dodo Payments

Information sent When the pay button is on screen (connecting to the checkout server in advance) and when checkout opens: IP address, browser details, and what you enter in checkout

Purpose Processing payments and preventing fraud

Privacy policy dodopayments.com/legal/privacy-policy

Google LLC (Google AdSense)

Information sent Ad cookie ids, IP address, browser and device details, the address of the page you are viewing

Purpose Showing and measuring ads, personalized ads

Privacy policy policies.google.com/privacy

Transmissions to our servers and delivery network (Cloudflare) are essential to provide the service, so they are left out of this table.

How to turn them off is in Consent and how to turn it off above.

Advertising ID

On screens with an ad slot, Google shows ads using ad cookies in your browser rather than your phone's advertising ID. You can turn personalized ads off in Google Ad Settings, and you can block third-party cookies in your browser settings.

Children and minors

Useless Space Selfie is for people aged 13 or older (14 or older in Korea). The age at which someone counts as a child differs by country (under 14 in Korea, under 13 in the US, under 13 to 16 in the EU), but the service is not directed to children.

We do not knowingly collect children's personal data. If we learn that a child's data has reached us, we delete it. Parents can ask for deletion at support@bang9.dev.

We do not target personalized ads at children.

Your rights and how to use them

You can ask at any time to access, correct, delete or stop the processing of your personal data, and withdraw consent for processing you agreed to.

What you can do right now: anything on this device (your last photo and result, title collection, display settings, usage record id) can be deleted by clearing site data in your browser. You can turn off our usage records with Turn off usage records in this browser, and personalized ads in Google Ad Settings.

For requests about server records, email support@bang9.dev. Server records are linked to the device cookie in your browser. If you paid, include the payment number from your receipt email; for a shared link, include the link. If you give us little to go on, we answer as far as we can find. A legal representative or someone you authorize can also ask on your behalf with a written authorization.

We reply to users in Korea within 10 days of receiving the request (PIPA Enforcement Decree Art. 41), and to users elsewhere within the deadline set by the law where they live. If we cannot do what you ask, we tell you why, and you can ask us to review it again at the same email.

Your Privacy Choices

Under the privacy laws of several US states, you can opt out of the sale and sharing of your personal information right here. The status of this browser is just below; if this browser has not opted out yet, you can opt out right there.

Status in this browser

This browser is opted out of sale and sharing (no personalized ads are requested).

Undo opt-out

Do Not Sell or Share My Personal Information

We do not sell personal information for money. However, ad signals sent to Google on screens with an ad slot (ad cookie ids, the address of the page you are viewing) can count as "sharing" or a "sale" for targeted advertising under some US state laws.

How to opt out: (1) Tap "Opt out in this browser" under "Status in this browser" above (a browser that sends a GPC signal is already opted out, so the link is not shown). We set an opt-out cookie in this browser and request its ads under Google's "restricted data processing", so no personalized ads are requested (Google then acts only as our service provider). (2) You can turn Google's personalized ads off in Google Ad Settings. (3) Email support@bang9.dev with "Do not sell or share".

An opt-out applies only to that browser. Please opt out separately in other browsers and on other devices. Clearing your browser's cookies also clears the opt-out in (1).

Opting out with Global Privacy Control (GPC)

When your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of sale and sharing, so no personalized ads are requested in that browser. "Status in this browser" above shows whether we received the signal.

Appeals

If we cannot do what you ask, we tell you why. If you disagree, email the same address with "Appeal". We tell you the result within 60 days, and if it is still not resolved you can contact your state attorney general.

How we protect data

  • Organizational: only authorized people can access personal data and our providers' admin consoles.
  • Technical: all traffic is encrypted (HTTPS). The device cookie cannot be read by scripts. IP addresses are pseudonymized and counted per day only. We check signatures on launch tickets and payment notifications to prevent forgery, and request rates are limited.
  • Physical: servers run in our providers' data centers.

Where to get help

If you need help with a privacy issue, please tell us first at support@bang9.dev. You can also contact these Korean agencies:

Users in the EU, the EEA and the UK can complain to their local data protection authority (see "Users in the EU, EEA and UK" below).

Changes to this policy

This policy (version 1) was announced on October 1, 2026 and takes effect on October 1, 2026.

If we change this policy, we'll announce it on this page before the change takes effect (on the effective date at the latest) and show what changed side by side with the previous version. If a new purpose or a new recipient is added, we'll tell you before that processing starts and ask for your consent where the law requires it.

Language

This document was originally written in Korean. Translations are provided for convenience. If they differ, the original prevails, unless the law of the country where you live says otherwise.

Users in the EU, EEA and UK

The controller is winterlog studio (contact details above under "Who is responsible").

Our legal bases are listed above under "Why we use your data". You can object at any time to processing based on legitimate interests (preventing abuse); if you do, we stop unless we can show compelling legitimate grounds.

Your rights: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (processing before withdrawal remains lawful). Send requests to support@bang9.dev. We do not make decisions that have legal effects on you based solely on automated processing.

International transfers: Korea, where we are based, has an adequacy decision. For US providers we rely on the DPF or standard contractual clauses (SCCs). The basis for each provider is in the "International transfers" table above. You can request a copy of the SCCs at support@bang9.dev.

If you do not provide data: without the data the service needs (the device cookie, payment details), you cannot use those features. No law requires you to provide it.

Cookies: cookies and storage that are not strictly necessary may only be used with your consent. When you visit from these countries we keep no usage records of our own, and on screens with an ad slot Google's consent message asks for your consent before ad cookies are used.

Complaints: you can complain to the supervisory authority where you live, work or where the issue occurred (the ICO in the UK). If you are in the UK and send us a complaint first, we acknowledge it within 30 days (UK Data (Use and Access) Act 2025).

Users in the United States

Categories of personal information collected in the past 12 months: identifiers (device cookie id, usage record device id, IP address, ad cookie ids), commercial information (payment records), internet activity (screens viewed, features tapped), approximate location (country estimated from IP address), and content you write (crew names, support emails). Sources, purposes, recipients and retention are as described in the sections above.

Selling and sharing: we do not sell personal information for money. Ad signals sent to Google on screens with an ad slot can count as "sharing" for targeted advertising under state laws, and you can opt out at Your Privacy Choices.

Sensitive personal information: we do not collect it.

Your rights: to know, delete, correct, obtain a copy, and opt out of selling and sharing. We will not discriminate against you for using them. Email support@bang9.dev and we reply within 45 days. If we refuse, you can appeal at the same email, and if the appeal does not resolve it, you can contact your state attorney general.

Do Not Track: we do not respond to browser Do Not Track signals. We treat a Global Privacy Control (GPC) signal as an opt-out of sale and sharing, so no personalized ads are requested in that browser (Your Privacy Choices).

Third-party tracking: the ad provider can collect information about your activity on this site and other sites.

When this policy changes, we post it on this page with the effective date.

Users in Japan

The name, address and owner of the business handling personal information are listed above under "Who is responsible". The purposes of use of retained personal data are listed under "Why we use your data".

Send requests for disclosure, correction, suspension of use or disclosure of third-party provision records to support@bang9.dev. There is no fee.

Our security measures are described under "How we protect data". Personal data is handled in Korea, where we are based, and by providers in the United States. We have looked into the privacy systems of those countries and take security measures accordingly (awareness of the foreign environment). Korea has the Personal Information Protection Act and a supervisory authority, the Personal Information Protection Commission, and has an EU adequacy decision. The United States has no comprehensive federal privacy law, only state laws.

The names, countries and contact details of foreign providers, the systems in those countries, the measures the providers take, and how to request information about their qualifying systems are in the "International transfers" section above.

Our public notice on external transmission is in the External Transmission Disclosure (Japan) section above.

Complaints and inquiries: support@bang9.dev