개인정보 처리방침 Privacy Policy

VibeStep(바이브스텝) VibeStep

← 앱으로 돌아가기 ← Back to the app

1. 총칙

VibeStep(이하 “서비스”)은 이용자의 개인정보를 소중히 여기며, 「개인정보 보호법」 등 관련 법령을 준수합니다. 본 방침은 서비스가 어떤 정보를 수집해 어떤 목적으로 이용하고 언제 파기하는지를 설명합니다.

서비스는 2D 관절 키프레임으로 춤을 만들어 공유하는 소셜 앱입니다. 서비스 이용에 필요한 최소한의 정보만 수집합니다. 소셜 로그인은 이메일·프로필 등 추가 권한(scope)을 요구하지 않으며, 이메일 로그인은 인증에 필요한 이메일 주소만 사용합니다.

서비스 이용 규칙과 이용자 콘텐츠에 대한 정책은 이용약관에서 확인할 수 있습니다.

2. 수집하는 개인정보 항목과 방법

가. 회원 가입 및 인증

  • Firebase 계정 고유 식별자(UID) 및 로그인 수단(Google, Apple 또는 이메일)
  • 인증 과정은 Google Firebase Authentication을 통해 이루어집니다. 이메일로 가입하면 이메일 주소는 Firebase Authentication에 인증 정보로 저장되지만 서비스의 Firestore 데이터베이스에는 저장하지 않습니다. 비밀번호는 Firebase가 처리하며 서비스 서버는 비밀번호를 받거나 저장하지 않습니다. 소셜 로그인에서는 실명·프로필 사진 등 추가 정보를 요청하지 않습니다.

나. 이용자가 직접 입력하거나 만든 정보

  • 닉네임(영문·숫자 2~20자, 최초 1회 등록 후 변경 불가)
  • 춤 데이터 — 관절 키프레임, 낙서 배경, 사운드 루프, 의상 구성
  • 게시물 — 제목, 내용, 공개/비공개 설정
  • 댓글(텍스트·모션 이모지) 및 이모지 반응

다. 서비스 이용 과정에서 생성되는 정보

  • 재화 잔액, 인앱 결제·상점 구매 이력 및 구매 일시
  • 보상형 광고 시청·보상 기록(광고 단위, 보상 종류·수량, 거래 식별자, 마지막 보상 시각). 광고 제공 과정에서 Google Mobile Ads가 IP 주소, 기기·광고 식별자, 광고 상호작용 및 진단 정보를 처리할 수 있습니다.
  • 보관함 슬롯 수·키프레임 한도 등 계정에 적용된 기능 설정
  • 텍스트 댓글 쿨타임 기록, 계정 생성·수정 시각
  • 앱 충돌·오류 진단 정보(Android 앱). Firebase Crashlytics가 충돌 및 비치명 오류의 스택 트레이스, 발생 시각, 앱 버전·빌드 번호, 설치 스토어 채널, 접속 서버 환경, 기기 모델·OS 버전, Firebase 설치 식별자를 수집합니다.
  • 앱 이용 통계(Android 앱). Firebase Analytics가 앱 실행·세션 등 자동 이벤트, 앱 버전, 설치 스토어 채널, 기기 모델·OS 버전, 언어, IP 주소로 추정한 국가 단위 위치, Firebase 설치 식별자를 수집합니다. Analytics의 광고 ID 수집과 광고 개인 맞춤 신호는 꺼 두었으며, 이용 통계는 광고와 연결하지 않습니다.
  • 접속 로그, IP 주소, 기기·브라우저 정보 등 서버 인프라(Google Cloud Run)가 보안·장애 대응을 위해 자동으로 기록하는 정보

라. 이용자 단말에 저장되는 정보

  • 로그인 유지를 위한 인증 토큰(액세스·리프레시 토큰)
  • 언어 설정 등 앱 사용 편의를 위한 값
  • 위 값은 단말의 로컬 저장소(웹의 경우 브라우저 저장소)에 보관되며, 모바일 앱은 보상형 광고 제공과 동의 관리를 위해 Google Mobile Ads SDK를 사용합니다. 이용 가능한 지역에서는 앱의 마이페이지 → 설정 → 광고 개인정보 설정에서 광고 개인정보 선택을 다시 확인하거나 변경할 수 있습니다.

마. 결제 정보

모바일 앱에서는 Apple App Store 또는 Google Play 인앱 결제로 재화를 구매할 수 있습니다. 결제와 환불은 각 스토어가 처리하며, 서비스는 카드번호를 받거나 저장하지 않습니다. 구매 권한 확인과 복원을 위해 RevenueCat이 스토어 구매 영수증, 앱 사용자 식별자와 구매 상태를 처리하며, 서비스 서버는 검증된 거래 식별자와 지급 내역을 보관합니다.

3. 개인정보의 이용 목적

  • 회원 식별과 로그인 유지, 본인 계정 콘텐츠의 소유권 확인
  • 춤 보관·게시·댓글·이모지 반응 등 서비스 기능 제공
  • 닉네임 중복 방지 및 유일성 보장
  • 댓글 쿨타임, 보관함 슬롯, 키프레임 한도 등 이용 정책의 집행
  • 인앱 결제 검증, 재화 지급·차감과 구매·광고 보상 이력 관리
  • 보상형 광고 제공, 빈도 제한, 광고 동의 및 부정 보상 방지
  • 부정 이용·비정상 접근 탐지 및 서비스 안정성 확보
  • 앱 충돌·오류 진단과 수정, 이용자 수·리텐션·버전 채택률 등 이용 통계 분석
  • 문의 응대 및 서비스 개선

4. 보유 및 이용 기간

대상보유 기간
계정 정보(UID·provider·닉네임, 이메일 가입 시 이메일 주소), 재화, 계정 설정 회원 탈퇴 또는 삭제 요청 시까지
춤 보관함, 게시물, 댓글, 이모지 반응 이용자가 삭제하거나 탈퇴할 때까지
인앱 결제·구매 이력, 광고 보상 거래 기록 탈퇴 시까지. 다만 결제 기록은 관련 법령 및 스토어 정책이 정한 기간
서버 접속 로그 인프라 정책에 따라 최대 1년 이내 자동 삭제
앱 충돌·오류 진단 정보, 앱 이용 통계 Firebase 보존 정책에 따라 충돌 보고는 최대 90일, 이용자 단위 이용 통계는 최대 14개월 보관 후 삭제. 집계 통계는 개인을 식별할 수 없는 형태로만 유지

다만 다음 두 가지는 구조상 즉시 사라지지 않을 수 있습니다. 첫째, 게시물·댓글에는 작성 시점의 닉네임이 함께 저장되어 목록에 표시됩니다. 둘째, 춤 데이터는 내용 해시로 식별되는 불변 에셋으로 저장되어 다른 게시물이 같은 데이터를 참조할 수 있습니다. 이 경우 계정과의 연결(작성자 식별자)을 먼저 끊고, 더 이상 참조되지 않는 데이터는 정기적으로 정리합니다.

5. 제3자 제공 및 처리 위탁

서비스는 이용자의 개인정보를 판매하지 않습니다. 다만 서비스 운영, 결제 검증 및 이용자가 선택한 보상형 광고 제공에 필요한 범위에서 다음 사업자가 정보를 처리할 수 있습니다.

수탁자위탁 업무
Google LLC / Google Cloud Firebase Authentication(로그인 인증), Cloud Firestore(데이터 저장), Cloud Run(API 서버 운영), Firebase Hosting(웹 배포), Firebase Crashlytics(앱 충돌·오류 진단), Firebase Analytics(앱 이용 통계)
Apple Inc. Apple로 로그인 이용 시 계정 인증, App Store 인앱 결제 처리
Google LLC / Google Play / Google Mobile Ads Google 로그인, Play 인앱 결제, 보상형 광고 제공·측정·부정행위 방지 및 광고 동의 관리
RevenueCat, Inc. 인앱 결제 영수증 검증, 구매 권한 확인과 복원

서비스 데이터와 API 서버는 미국 리전(us-west1, Oregon)에서 운영합니다. Firebase 및 소셜 로그인 인증 처리는 각 사업자의 글로벌 인프라에서 이루어질 수 있으며, 국외에서 처리되는 항목은 계정 고유 식별자, 이메일 가입 시 이메일 주소, 인증 토큰, 결제 상태, 광고·기기 식별자, 충돌·오류 진단 정보 및 서비스 이용 데이터입니다.

6. 이용자의 권리와 행사 방법

  • 열람·정정: 마이페이지에서 닉네임, 재화 잔액, 보관함, 게시물, 구매 이력을 확인할 수 있습니다. 닉네임은 유일성 보장을 위해 최초 등록 후 변경할 수 없습니다.
  • 삭제: 춤, 게시물, 댓글, 이모지 반응은 앱에서 직접 삭제할 수 있습니다.
  • 광고 개인정보 선택: 해당 옵션이 제공되는 지역에서는 앱의 마이페이지 → 설정 → 광고 개인정보 설정에서 선택을 다시 관리할 수 있습니다.
  • 회원 탈퇴 및 계정 삭제: 앱의 마이페이지 → 설정 → 계정 삭제에서 직접 탈퇴할 수 있습니다. 탈퇴하면 계정 정보와 함께 게시물, 댓글, 이모지 반응, 보관한 춤, 구매 이력, 차단 목록이 삭제되며 닉네임은 다시 사용할 수 있게 풀립니다. 앱에 접속할 수 없는 경우 아래 문의처로 요청하시면 본인 확인 후 10일 이내에 계정과 관련 데이터를 삭제하고 요청하신 경로로 회신합니다.
  • 처리 정지·동의 철회: 아래 문의처로 요청할 수 있으며, 요청 시 서비스 이용이 제한될 수 있습니다.
  • 법정대리인 또는 위임받은 자를 통해서도 위 권리를 행사할 수 있습니다.

7. 파기 절차 및 방법

보유 기간이 지나거나 처리 목적이 달성된 개인정보는 지체 없이 파기합니다. 전자적 파일 형태의 정보는 복구할 수 없는 방법으로 데이터베이스에서 삭제하며, 백업본에 남은 정보는 백업 순환 주기에 따라 함께 삭제됩니다.

8. 안전성 확보 조치

  • 클라이언트는 데이터베이스에 직접 접근할 수 없으며, 모든 읽기·쓰기는 서버 API를 경유합니다.
  • 모든 통신은 HTTPS로 암호화합니다.
  • 서버는 자체 발급 JWT로 요청자를 검증하고, 본인 소유 데이터에만 접근을 허용합니다.
  • 서비스 계정 키 등 비밀 정보는 저장소에 포함하지 않고 별도로 관리합니다.
  • 운영 데이터 접근 권한은 최소한의 인원으로 제한합니다.

9. 만 14세 미만 아동의 개인정보

서비스는 만 14세 미만 아동의 가입을 받지 않으며, 아동의 개인정보를 알면서 수집하지 않습니다. 만 14세 미만 아동의 정보가 수집된 사실을 확인하면 지체 없이 해당 계정과 데이터를 삭제합니다.

10. 개인정보 보호책임자 및 문의처

개인정보 관련 문의, 열람·삭제 요청, 불만 처리는 위 연락처로 접수하며 성실하게 답변드립니다.

11. 권익침해 구제 방법

개인정보 침해로 도움이 필요하시면 아래 기관에 문의할 수 있습니다.

  • 개인정보침해 신고센터 — 국번 없이 118 / privacy.kisa.or.kr
  • 개인정보 분쟁조정위원회 — 1833-6972 / www.kopico.go.kr
  • 대검찰청 사이버수사과 — 1301
  • 경찰청 사이버범죄 신고시스템 — 182 / ecrm.police.go.kr

12. 방침의 변경

본 방침의 내용을 추가·삭제·수정할 경우 시행 최소 7일 전에 앱 내 공지 또는 본 페이지를 통해 알립니다. 다만 이용자 권리에 중대한 변경이 있는 경우에는 최소 30일 전에 알립니다.

  • 공고일: 2026년 9월 9일
  • 시행일: 2026년 9월 16일

1. Overview

VibeStep (“the Service”) respects your privacy and complies with the Korean Personal Information Protection Act (PIPA) and other applicable laws. This policy explains what we collect, why we use it, and when we delete it.

VibeStep is a social app for creating and sharing dances built from 2D joint keyframes. We collect only what the Service needs to work. We request no additional scopes (such as email or profile access) during social sign-in; email sign-in uses only the email address needed for authentication.

The rules for using the Service and our policy on user content are in the Terms of Use.

2. Information We Collect

a. Account and authentication

  • Your Firebase account identifier (UID) and sign-in provider (Google, Apple, or email).
  • Authentication runs through Google Firebase Authentication. When you create an email account, Firebase Authentication stores the email address as an authentication record, but we do not store it in the Service's Firestore database. Firebase processes the password; our server never receives or stores it. Social sign-in requests no additional real-name or profile-photo data.

b. Content you enter or create

  • Nickname (2–20 letters and digits; set once and cannot be changed)
  • Dance data — joint keyframes, doodle backgrounds, sound loops, outfits
  • Posts — title, body, and public/private setting
  • Comments (text and motion emoji) and emoji reactions

c. Information generated through use

  • Currency balance, in-app payment and shop purchase history, and purchase timestamps
  • Rewarded-ad viewing and reward records (ad unit, reward type and amount, transaction identifier, and last reward time). Google Mobile Ads may process IP address, device or advertising identifiers, ad interactions, and diagnostic information while delivering ads.
  • Account limits such as storage slots and keyframe capacity
  • Text-comment cooldown state, account creation and update timestamps
  • Crash and error diagnostics (Android app). Firebase Crashlytics collects stack traces of crashes and non-fatal errors, the time they occurred, app version and build number, install store channel, API server environment, device model and OS version, and a Firebase installation identifier.
  • App usage statistics (Android app). Firebase Analytics collects automatic events such as app opens and sessions, app version, install store channel, device model and OS version, language, country-level location inferred from IP address, and a Firebase installation identifier. Advertising-ID collection and ad-personalization signals are disabled for Analytics, and usage statistics are not linked to ads.
  • Access logs, IP address, and device/browser information recorded automatically by our hosting infrastructure (Google Cloud Run) for security and reliability

d. Information stored on your device

  • Authentication tokens (access and refresh) that keep you signed in
  • Preferences such as your language setting
  • These are kept in local device storage (browser storage on the web). The mobile app uses the Google Mobile Ads SDK to provide rewarded ads and manage consent. Where available, you can revisit your choices under My Page → Settings → Ad privacy settings.

e. Payment information

On mobile, you can purchase in-app currency through Apple App Store or Google Play. Those stores process payment and refunds; the Service does not receive or store card numbers. RevenueCat processes store receipts, an app user identifier, and purchase status so we can verify and restore purchases. Our server retains the verified transaction identifier and currency-grant record.

3. How We Use Information

  • Identifying you, keeping you signed in, and tying content to your account
  • Providing core features: dance storage, posting, comments, and reactions
  • Guaranteeing nickname uniqueness
  • Enforcing service rules such as comment cooldowns, storage slots, and keyframe limits
  • Verifying in-app purchases, granting and deducting currency, and keeping purchase and ad-reward records
  • Providing rewarded ads, enforcing frequency limits, managing ad consent, and preventing reward fraud
  • Detecting abuse and abnormal access, and keeping the Service stable
  • Diagnosing and fixing crashes and errors, and analyzing usage statistics such as active users, retention, and version adoption
  • Responding to inquiries and improving the Service

4. Retention Periods

DataRetention
Account data (UID, provider, nickname, and email for email accounts), currency, account settings Until you delete your account or request deletion
Saved dances, posts, comments, reactions Until you delete them or close your account
In-app payment and purchase history; ad-reward transaction records Until account closure, except payment records retained as required by law or store policy
Server access logs Deleted automatically within one year per infrastructure policy
Crash and error diagnostics; app usage statistics Per Firebase retention policy: crash reports up to 90 days and user-level usage data up to 14 months, then deleted. Aggregated statistics are kept only in a form that cannot identify you

Two things may not disappear immediately. First, posts and comments store the nickname used at the time of writing so lists can render without extra lookups. Second, dance data is stored as immutable, content-hashed assets that other posts may reference. In those cases we first sever the link to your account (the author identifier) and periodically purge assets that are no longer referenced.

5. Sharing and Processors

We do not sell your personal information. The following providers may process information as needed to operate the Service, verify purchases, and deliver rewarded ads that you choose to watch.

ProcessorPurpose
Google LLC / Google Cloud Firebase Authentication (sign-in), Cloud Firestore (data storage), Cloud Run (API server), Firebase Hosting (web delivery), Firebase Crashlytics (crash and error diagnostics), Firebase Analytics (app usage statistics)
Apple Inc. Sign in with Apple and App Store in-app payment processing
Google LLC / Google Play / Google Mobile Ads Google sign-in, Play in-app payments, rewarded-ad delivery and measurement, fraud prevention, and ad consent management
RevenueCat, Inc. In-app purchase receipt validation, entitlement checks, and purchase restoration

Service data and the API server run in the United States region (us-west1, Oregon). Firebase and social sign-in verification may also take place on the providers' global infrastructure. Data processed outside Korea includes your account identifier, email address for email accounts, authentication tokens, purchase status, ad or device identifiers, crash and error diagnostics, and Service usage data.

If you are in the EEA or the UK, we process your data to perform our contract with you (providing the Service) and on the basis of our legitimate interest in keeping the Service secure. You may contact us to exercise your access, rectification, erasure, and objection rights.

6. Your Rights

  • Access and correction: Your nickname, currency balance, saved dances, posts, and purchase history are visible in My Page. Nicknames cannot be changed after the initial registration because they must stay unique.
  • Deletion: You can delete dances, posts, comments, and reactions yourself in the app.
  • Ad privacy choices: Where this option is available, revisit your choices under My Page → Settings → Ad privacy settings.
  • Account closure: You can close your account yourself under My Page → Settings → Delete account. Deleting your account removes your account record along with your posts, comments, reactions, saved dances, purchase history, and block list, and releases your nickname for reuse. If you cannot reach the app, contact us at the address below and, after verifying your identity, we will delete your account and related data within 10 days and confirm the result.
  • Restriction and withdrawal of consent: Contact us to request this; note that it may limit your ability to use the Service.
  • A legal representative or authorized agent may exercise these rights on your behalf.

7. Deletion Procedure

Once the retention period ends or the purpose of processing is fulfilled, we delete the data without delay. Electronic records are removed from the database in a manner that prevents recovery, and copies remaining in backups are removed as those backups rotate out.

8. Security Measures

  • Clients never access the database directly; every read and write goes through the server API.
  • All traffic is encrypted with HTTPS.
  • The server verifies each request with its own JWT and permits access only to data you own.
  • Secrets such as service account keys are kept out of the repository and managed separately.
  • Access to production data is limited to the minimum number of people.

9. Children

The Service is not intended for children under 14, and we do not knowingly collect their personal information. If we learn that we have collected data from a child under 14, we delete the account and its data without delay.

10. Contact

Send privacy questions, access or deletion requests, and complaints to the address above and we will respond in good faith.

11. Remedies (Korea)

If you need help with a privacy matter, you may also contact:

  • Privacy Infringement Report Center — 118 / privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee — +82-1833-6972 / www.kopico.go.kr
  • Supreme Prosecutors' Office Cyber Investigation Division — 1301
  • National Police Agency Cybercrime Report — 182 / ecrm.police.go.kr

12. Changes to This Policy

If we add to, remove from, or revise this policy, we will announce it in the app or on this page at least 7 days before it takes effect — at least 30 days ahead when the change materially affects your rights.

  • Announced: September 9, 2026
  • Effective: September 16, 2026