Privacy · v1.4.0
개인정보처리방침
사진은 엽서를 만들기 위해 선택한 순간에만 처리합니다. 원본과 완성 엽서는 기본적으로 기기에 남고, 클라우드 계정은 크레딧·결제 복구와 생성 요청을 보호하는 데 사용합니다.
기기에 남는 것
원본 사진, 편집 문구, 작업 상태, 완성 PNG와 엽서함은 서버에 동기화하지 않습니다.
요청할 때 전송하는 것
생성 확인 시 메타데이터를 제거하고 긴 변을 768px로 제한한 사진 복사본을 전송합니다.
1. 계정과 로그인
앱은 가입 화면 없이 Firebase 익명 계정으로 시작합니다. 이용자가 선택하면 Google 계정을 연결해 같은 계정으로 크레딧과 구매 혜택을 복구할 수 있습니다. 이때 Firebase와 Google은 계정 식별자, 이메일·프로필 정보, 인증 메타데이터, IP·기기 보안 신호를 처리할 수 있습니다. AKRA 서버는 Firebase UID를 권한 경계로 사용하며 소셜 계정 비밀번호를 받지 않습니다. Apple 연결은 지원되는 iOS 배포에서 별도 제공될 수 있습니다.
2. 이미지 생성
이용자가 생성을 확인하면 앱은 선택 사진을 PNG로 다시 인코딩해 EXIF 같은 컨테이너 메타데이터를 제거하고, 비율을 유지한 채 긴 변을 최대 768px로 제한합니다. AWS의 서울 리전 서비스는 이 요청 복사본을 메모리에서 받아 OpenAI 이미지 API로 전달하며 입력 사진을 별도 객체로 저장하지 않습니다. 생성 결과는 재시도 복구를 위해 비공개 S3 저장소에 최대 8일, 생성 기록은 최대 7일 보관됩니다. OpenAI의 기본 악용 모니터링 보관은 최대 30일일 수 있으며 이 서비스는 Zero Data Retention을 사용한다고 표시하지 않습니다.
3. 크레딧, 결제와 광고
서버는 크레딧 잔액, 출석, 보상광고 영수증, 구매 의도·거래 식별자와 혜택 원장을 보관합니다. Google Play 결제 시 앱과 서버는 상품 ID, 구매 토큰, 난독화한 계정·프로필 연결값과 거래 상태를 Google Play와 확인합니다. 카드 번호는 AKRA가 받지 않습니다. 구매·환불 기록은 중복 지급 방지, 복구, 회계와 법적 의무를 위해 필요한 범위에서 보관될 수 있습니다.
Google Mobile Ads와 User Messaging Platform은 광고 제공·측정·부정행위 방지와 개인정보 선택을 위해 대략적 위치, 앱 상호작용, 진단 정보, 광고 ID, 기기·계정 식별자와 동의 선택을 처리할 수 있습니다. 필요한 지역에서는 광고 요청 전에 동의 상태를 확인하고 앱 안에서 개인정보 선택을 다시 열 수 있습니다.
첫 이용 크레딧
Android 앱은 첫 이용 크레딧을 요청할 때 Android ID를 HTTPS로 서버에 전송합니다. 서버는 전용 비밀키로 HMAC 참조값을 만들며 원본 Android ID를 저장하거나 로그에 남기지 않습니다. 재설치·계정 삭제 후 초기 보상이 반복 지급되지 않도록 참조값, 보상 정책과 기록 시각을 보관합니다. 이 기록에는 Firebase UID를 포함하지 않으며 광고, 다른 앱의 활동 추적이나 계정 복구에 사용하지 않습니다.
이 기기 기록은 클라우드 계정 삭제 후에도 유지되며 자동 만료되지 않습니다. 첫 이용 보상과 관련 악용 방지 목적이 종료되면 삭제합니다. 기기 소유자 변경이나 기록에 관한 문의는 help@akra.kr로 보낼 수 있습니다.
4. 삭제와 보관
앱의 내 정보 → 계정 · 크레딧 복구 → 클라우드 계정 삭제는 Firebase 계정과 AKRA가 관리하는 지갑, 출석·생성·광고·구매 원장 및 임시 결과를 삭제합니다. 구매의 중복 사용을 막는 거래·구매 의도 기록은 원문 UID를 제거한 상태로 자동 만료 없이 보관합니다. 늦게 도착한 요청이 지갑을 되살리지 못하도록 원문 UID가 아닌 SHA-256 파생 차단값을 30일 뒤 만료하도록 남깁니다. 기기에 저장한 엽서는 사적인 로컬 보관물이라 이 작업으로 지우지 않습니다. 자세한 절차는 계정 삭제 안내를 확인하세요.
5. 처리업체와 이용자 선택
- Firebase Authentication·App Check: 인증과 앱 무결성 확인
- Amazon Web Services: 서버 지갑, 생성 처리와 임시 결과 보관
- OpenAI API: 이용자가 요청한 이미지 생성
- Google Play: 앱 배포, 결제 검증과 환불 상태
- Google Mobile Ads·UMP: 광고, 측정과 개인정보 선택
- Google Analytics for Firebase·Crashlytics: 선택적인 사용 통계와 오류 보고
- GitHub: 서명된 AKRA 운영·정책 설정 전달
Android는 시스템 사진 선택기를 사용하며 전체 사진 보관함 권한을 요구하지 않습니다. 기기 광고 설정과 앱의 광고 개인정보 선택 화면을 사용할 수 있고, 적용 법률에 따른 열람·정정·삭제 등 요청은 help@akra.kr로 보낼 수 있습니다.
앱 개선 데이터
Android의 사용 통계와 오류 보고는 저장된 선택이 없으면 기본적으로 켜져 있습니다. 기존에 끈 설정은 유지하며 내 정보 → 앱 개선 데이터에서 언제든 끄거나 다시 켤 수 있습니다. 켜면 앱 설치 식별자, 기기·앱 정보, 화면 이용, 지갑 연결 및 광고 진행 이벤트와 충돌·응답 없음 보고서를 Google Analytics와 Crashlytics로 보냅니다. 사진, 엽서 문구, Firebase 계정 UID, 이메일, 인증 토큰이나 결제 영수증을 이 보고서에 첨부하지 않습니다.
광고 성과 측정을 위해 Analytics 이용 데이터는 AdMob에서, AdMob 광고 수익 데이터는 Analytics에서 사용할 수 있도록 연결합니다. 이 선택과 연결로 맞춤형 광고나 광고 잠재고객 활용을 켜지 않습니다. 공유를 끄면 이후 수집을 중단하지만 이미 받은 보고서는 Google의 보관 정책과 프로젝트 설정이 적용됩니다. 별도 설치 식별자를 사용하므로 클라우드 계정 삭제로 이 보고서를 특정하지 못합니다. 관련 요청은 help@akra.kr로 문의하세요. iOS와 web에서는 이번 보고 기능을 활성화하지 않습니다.
English summary
stillstamp Privacy Policy
stillstamp starts with an anonymous Firebase identity and lets users optionally link Google for credit and purchase recovery. Original photos, postcard text, finished PNGs, and the local library are not cloud-synced. Only after generation is confirmed, a metadata-stripped PNG copy limited to a 768-pixel longest edge is sent through AWS to OpenAI. The generated result may remain privately in AWS for up to 8 days; generation metadata for up to 7 days; and OpenAI default abuse-monitoring data for up to 30 days.
Google Play purchase tokens and transaction status are verified on the server; AKRA does not receive card details. Google Mobile Ads and UMP may process advertising identifiers, approximate location, interactions, diagnostics, and consent choices. Cloud-account deletion removes the Firebase identity and AKRA-controlled wallet, purchase/reward, generation, and temporary-result records, while local postcards remain on the device. Use My info → Account · recover credits → Delete cloud account. Purchase transaction and intent records remain without the raw UID and without automatic expiry to prevent replay. A UID-free deletion fence expires after 30 days. Contact help@akra.kr.
To grant first-use credit on Android, the app sends the Android ID over HTTPS. The server derives a keyed HMAC reference without storing or logging the raw Android ID. The reference, offer policy, and recording time prevent repeated starter grants after reinstallation or account deletion. This record has no Firebase UID and is not used for advertising, cross-app tracking, or account recovery. It remains after cloud-account deletion without automatic expiry until the offer and its abuse-prevention need end. Contact help@akra.kr about this record or a change of device ownership.
Optional Analytics and Crashlytics collection is on by default on Android when no saved choice exists. A previously saved off choice remains off. Use My info → App improvement data to turn it off or back on. Reports include installation identifiers, device/app metadata, bounded screen, wallet and ad events, crashes and ANRs. We do not attach photos, postcard text, Firebase account UIDs, emails, authentication tokens or payment receipts. Analytics usage data is made available to AdMob and AdMob revenue data to Analytics, without enabling personalized ads or advertising audiences. Withdrawal stops future collection, not reports already received by Google; provider retention and project settings apply. These separate installation reports cannot be selected by cloud-account deletion. Contact help@akra.kr. iOS and web do not enable these reports in this release.