Privacy Policy
This is the privacy policy of the Android game "The Oddballs I Met" (peek-a-moo, package name org.j2w2.peekamoo). This English version is provided for convenience; if it differs from the Korean version, the Korean version prevails.
Summary — This app has no sign-up and no login. It does not collect information that directly identifies users, such as name, email or phone number, and it does not access location, contacts, photos or the microphone. However, it creates an anonymous identifier to keep your game progress, and because the app contains ads, the ad SDK collects the advertising ID.
Article 1 (General Provisions)
WISP (the "Company") processes users' personal information in the mobile game "The Oddballs I Met" (the "App"), which the Company develops and operates, and uses this policy to inform users of the items processed, the purposes, the retention periods and users' rights. The same game is also offered as a mini app inside the Toss app; how users are identified in the mini app is described separately in Article 4.
Article 2 (Information Collected and Purposes)
| Item | Details | Purpose | Retention |
|---|---|---|---|
| Anonymous device identifier | A random UUID generated by the App on first launch. It is stored on the device and is not linked to the advertising ID, phone number or any account. | To show your game progress continuously without sign-up | Until the App is deleted |
| Game progress data | Answers attempted and whether they were correct, hint use, rice grains held, titles, collection progress, missions completed | Providing game features; calculating the number of correct answerers and statistics | For as long as the service is operated, keyed to the anonymous identifier |
| Advertising ID (AAID) | Collected by the Google AdMob SDK. The App does not read or store this value itself. | Serving ads and controlling ad frequency | According to Google's policies |
Article 3 (Information Not Collected)
The App does not collect any of the following information.
- Name, email address, phone number, date of birth, gender
- Location, contacts, photos and media, microphone or camera input
- Call logs, list of installed apps, web search history
- Financial or payment information — the App has no in-app purchases. The game currency 'rice grains' is earned only through play and by watching ads
The App requests only the following three Android permissions.
INTERNET— communication with the game servercom.google.android.gms.permission.AD_ID— serving adsPOST_NOTIFICATIONS— notifications. Not used in the current version.
The App has no feature for users to talk to each other, so it does not process chat content or information passed between users. "Brag (자랑하기)" is a feature that shares via the Android share sheet, and the shared content does not include the answer or oddball images.
Article 4 (User Identification in the Toss Mini App)
The same game is also offered as a mini app inside the Toss app. In the mini app, users are distinguished by an anonymous key provided by Toss instead of the Android app's device UUID, and the Company cannot learn the user's Toss account information, real name or contact details from this value.
If the user uses the App's Account Sync (계정 싱크; link code) feature, they can choose which of the two identifiers to use. Only the link information about which account to continue the game with is transferred, and no new personal information is collected.
Article 5 (Provision to Third Parties and Outsourcing of Processing)
The Company does not sell users' information. The following providers are used to operate the service, and each provider's processing policies also apply.
| Processor | Outsourced task |
|---|---|
| Google AdMob | Serving ads. Collects items set by Google, such as the advertising ID. |
| Google Cloud Platform | Operating the game server (Cloud Run) |
| Cloudflare | Secure tunnel between the game server and the database |
| Viva Republica (Toss) | When offered as a Toss mini app: the app runtime environment, issuing anonymous keys, and providing ad slots |
Progress data is not actually stored in the cloud. The game server runs on Google Cloud, but the database is on a server the Company operates itself in Korea and is not exposed to the public internet. The server and the database are connected only through a Cloudflare tunnel.
Article 6 (Retention Period and Destruction)
- The anonymous identifier stored on the device is deleted when the App is deleted.
- Once the App is deleted, the progress data remaining on the server is no longer linked to any user.
- If you want the progress data stored on the server to be completely deleted, you can request it using the method in Article 8.
Article 7 (Advertising and User Choice)
The App has a bottom ad slot and rewarded ads (extra hints, bonus rounds) that play only when the user chooses to watch them. Rewarded ads play only when the user taps the button, and you can keep playing the game without watching them.
Users can reset their advertising ID or turn off personalized ads in Android Settings → Google → Ads.
Article 8 (User Rights and Deletion Requests)
Users may request deletion of their data at any time. Because the App has no login and the Company cannot directly identify users, you must include the link code shown on the App's Missions & Titles (미션·칭호) → Account Sync (계정 싱크) screen with your request so that the relevant data can be identified.
The detailed procedure is described on the Account and Data Deletion page. Requests are processed within 30 days of the request date.
Article 9 (Children's Personal Information)
The App is not primarily intended for children under 14, and does not knowingly collect personal information from children. The target age in the store is planned to be registered as 13 and over.
Article 10 (Security Measures)
- All communication between the App and the server is encrypted end to end with HTTPS.
- The server does not hold information that directly identifies users in the first place.
- The database is not exposed to the public internet and is accessed only through a Cloudflare tunnel.
- Server access credentials and authentication keys are kept in a secrets management service, not in code.
Article 11 (Changes to This Policy)
If the contents of this policy change, the changes and the effective date will be posted on this page. For changes that add collected items or purposes of use, the policy is revised before the relevant feature is released.
Article 12 (Contact)
Please send inquiries about the processing of personal information and deletion requests to the contact below.
- Contact: WISP Privacy Officer
- Email: [email protected]
- Processing: within 30 days of the request date
If you need counseling or want to report an infringement of personal information, you can contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 with no area code), the Supreme Prosecutors' Office Cyber Investigation Division (spo.go.kr, 1301), or the Korean National Police Agency Cyber Investigation Bureau (ecrm.police.go.kr, 182).