한국어 정본 (Korean authoritative version) → · 日本語 →

Pilmie Privacy Policy

Effective date: July 5, 2026

Bullets (Operator: Jiyoung Ryu; the “Operator”), operating Pilmie (the “Service”), complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws, and establishes and discloses this Privacy Policy to protect users’ personal information.

This document is a reference translation provided for convenience. The Korean version (개인정보처리방침) is the authoritative and legally binding version; translations into other languages, including English and Japanese, are provided for reference only. In the event of any inconsistency between the Korean version and a translated version, the Korean version shall prevail.

Article 1 (General Provisions)

  1. The Service is a mobile application (iOS/Android) for recording reading activity and sharing book reviews.
  2. The Operator processes personal information only within the purposes and scope stated in this Policy. If a purpose changes, the Operator will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

Article 2 (Personal Information Collected and Collection Methods)

The Operator collects the following personal information.

1. At sign-up and login

Category Items Collection method
Required Email address of the social account, name of the social account, unique member identifier (UID) Collected automatically upon Google Sign-In (Android) or Sign in with Apple (iOS)
Required Nickname Entered directly by the user on the sign-up screen
Optional One-line bio, profile image Entered or registered directly by the user on the sign-up or profile edit screen
Required Consent status for the terms and personal-information collection, time of consent, version of the policy consented to, and marketing communications consent status (optional consent) Recorded automatically during the sign-up process

2. Information created by users while using the Service

3. Automatically collected information

4. Information stored only on the device (not transmitted to servers)

The following information is stored only on the user’s device and is not transmitted to the Operator’s servers. It is deleted when the app is uninstalled.

Article 3 (Purposes of Processing Personal Information)

Purpose Items used
Member identification, sign-up/login processing, and account management Email, name, UID, nickname
Provision of the Service (review, bookshelf, and community features) Nickname, profile image, one-line bio, and user-created content
Sending push notifications and in-app notifications (follow, like, and comment notifications, etc.) FCM token, notification data
Sending marketing information (event and benefit announcements) — only for users who gave optional consent FCM token, marketing consent status
Preventing fraudulent use, handling reports, and protecting users UID, report records, block list
Improving service quality and responding to errors Error and crash diagnostic information
Producing service usage statistics and improving features (usage analytics) Service usage analytics information
Evidencing consent history Consent status, time of consent, and policy version

Article 4 (Retention and Use Period of Personal Information)

  1. The Operator destroys collected personal information without delay once the user completes membership withdrawal (account deletion).
  2. However, the following information is exceptionally retained for the periods stated below.
Retained items Basis and purpose of retention Retention period
Report records (identifiers of the reporter and the reported user, report reason and details, and report time) Preventing fraudulent use and responding to disputes 3 years after withdrawal
Information subject to statutory retention obligations The applicable statute The period prescribed by the applicable statute
  1. Upon withdrawal, traces of the withdrawn member remaining in other users’ content (likes, follow relationships, reviewer aggregates, and comments written by other users on reviews authored by the withdrawn member, etc.) are also deleted. If any information is not deleted immediately due to a system error or similar cause, the Operator will delete it as soon as it becomes aware of it. However, information related to the withdrawn member contained in other users’ data (e.g., identifiers stored in other users’ block lists) may remain as those users’ data; after account deletion, such identifiers alone cannot identify a specific individual.

Article 5 (Provision of Personal Information to Third Parties)

The Operator does not provide users’ personal information to third parties, except in the following cases:

  1. Where the user has given separate prior consent
  2. Where required by statute, or where an investigative agency makes a request in accordance with the procedures and methods prescribed by statute for investigative purposes

Article 6 (Entrustment of Personal Information Processing and Overseas Transfer)

  1. To provide the Service, the Operator entrusts personal information processing to the following overseas service providers. This falls under Article 28-8(1)3 of the Personal Information Protection Act (entrustment of processing or storage necessary for the performance of a contract for the provision of services).
Trustee (recipient of transfer) Country of transfer Items transferred Entrusted work (purpose) Time and method of transfer Retention period
Google LLC (Firebase) — privacy@google.com United States All items in Article 2, Sections 1 through 3 (email, name, UID, nickname, profile image, content, FCM token, service usage analytics information, etc.) Member authentication (Firebase Authentication), data storage (Cloud Firestore), file storage (Cloud Storage), push notification delivery (Firebase Cloud Messaging), usage analytics (Google Analytics for Firebase), app configuration delivery (Firebase Remote Config) Transmitted over the network at the time of Service use Until membership withdrawal or termination of the entrustment agreement
Apple Inc. — apple.com/legal/privacy United States Apple account authentication information (email, name) Sign in with Apple authentication (iOS) Transmitted over the network at the time of using Sign in with Apple In accordance with Apple’s privacy policy
Functional Software, Inc. (Sentry) — sentry.io/privacy United States Error and crash diagnostic information (error details, device model, OS and app version, and app usage records around the time of the error — no identifying information included) Collection and diagnosis of app errors Transmitted over the network at the time an error occurs in official release builds 90 days from collection (Sentry’s default retention period)
  1. Users may refuse the overseas transfer of their personal information. However, because the Service is provided on infrastructure operated by the above trustees, refusing the overseas transfer makes use of the Service (sign-up) impossible. A user may refuse the transfer by not signing up or by withdrawing membership, and inquiries may be made to the contact in Article 13.
  2. When searching for books, the search terms are transmitted to the book search API of NAVER Corp. No account information or device identifiers of the user are transmitted, and search terms alone cannot identify an individual.

Article 7 (Procedures and Methods of Destroying Personal Information)

  1. The Operator destroys personal information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose.
  2. Personal information in electronic file form is permanently deleted using methods that make recovery or restoration impossible.
  3. Membership withdrawal can be performed directly in the app via [Settings → Delete Account] (for security, re-login for identity verification may be required if a certain period has passed since the last login). Upon withdrawal, the profile, reviews, star ratings, comments, quoted passages, bookshelf records, follow relationships, likes, block list, notifications, and profile image file are deleted, and the authentication account is deleted (except for the retention exceptions in Article 4, Paragraph 2).

Article 8 (Rights and Obligations of Data Subjects and How to Exercise Them)

  1. Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.
  2. How to exercise these rights:
    • Access to and correction of profile information (nickname, one-line bio, profile image): the profile edit feature in the app
    • Editing and deleting content (reviews, comments, quoted passages, etc.): the edit and delete features for the relevant content in the app
    • Deleting the account and all data: [Settings → Delete Account] in the app
    • Other requests (access, suspension of processing, etc.): by email to the Personal Information Protection Officer in Article 13
  3. For requests received by email, the Operator will act without delay (no later than 10 days) and notify the user of the result.
  4. Rights may also be exercised through the user’s legal representative or an authorized agent, in which case a document evidencing lawful authorization must be submitted.
  5. Users are responsible for keeping their personal information up to date. A user who signs up by misappropriating another person’s personal information may lose membership and be punished under applicable laws.

Article 9 (Personal Information of Children Under 14)

Only users aged 14 or older may sign up for the Service, and the Operator does not collect personal information of children under 14. The sign-up process requires confirmation that the user is 14 or older. If it is confirmed that a child under 14 has signed up, the account and its personal information will be deleted without delay.

Article 10 (Installation, Operation, and Refusal of Automatic Collection Devices)

  1. The Service is provided as a mobile app and does not use cookies.
  2. Push notifications are sent only when the user grants notification permission, and the user may refuse to receive notifications at any time via the device’s notification settings or the in-app settings. Refusing notifications does not restrict use of the Service other than receiving notifications.
  3. The collection of error diagnostic information is for maintaining service quality and does not include information that can identify an individual.
  4. The Operator does not collect advertising identifiers (ADID/IDFA) and does not use advertising SDKs for delivering advertisements.
  5. The Service uses Google Analytics for Firebase to produce usage statistics and improve quality. This tool collects usage information such as screen views and feature-usage events based on a pseudonymous (app-instance) identifier, which may be associated with the member identifier (UID). It does not collect advertising identifiers and is not used for advertising purposes; the collected information is used solely to produce service usage statistics and improve quality. Users may request suspension of the processing of their usage analytics information via the contact in Article 13.

Article 11 (Notice on the Public Nature of Content)

  1. The Service is a community service for sharing reading records. A user’s profile (nickname, one-line bio, profile image, and follower/following lists) and the content the user creates (reviews, star ratings, comments, quoted passages, and the reading status of the bookshelf) are visible to other users of the Service.
  2. Please take care not to include information you do not wish to disclose in your content. Users may edit or delete their own content at any time.
  3. Block lists and report records are not disclosed to other users.

Article 12 (Measures to Ensure the Security of Personal Information)

The Operator takes the following measures to ensure the security of personal information:

  1. Encryption in transit: all data is transmitted over HTTPS (TLS) encrypted communication.
  2. Access control: database security rules (Firebase Security Rules) restrict write access to a user’s own data to that user, and sensitive data such as block lists can be viewed only by the user concerned.
  3. Minimization of access privileges: administrative access to personal information is minimized to the Operator.
  4. Collection minimization: only the minimum information necessary to provide the Service is collected.

Article 13 (Personal Information Protection Officer)

The Operator designates the following Personal Information Protection Officer to oversee personal information processing and to handle users’ complaints and provide remedies related to personal information processing.

Users may direct all inquiries, complaints, and requests for remedies regarding personal information arising from use of the Service to the contact above, and the Operator will respond and act without delay.

Article 14 (Remedies for Infringement of Rights)

If you need to report or consult about a personal information infringement, you may contact the following organizations (Republic of Korea):

Article 15 (Changes to This Privacy Policy)

  1. If the contents of this Policy are added to, deleted, or modified, notice will be given at least 7 days before the effective date (or at least 30 days for changes unfavorable to users or otherwise significant) through in-app notice or the page where this Policy is published.
  2. Previous versions of this Policy are available upon request via the contact in Article 13.

Addendum

This Privacy Policy takes effect on July 5, 2026.