Legal
Privacy Policy
1. Introduction
This Privacy Policy explains how Scratchy Us (package ID com.slt.scratchyus) collects, uses, stores, and shares personal information when you use the mobile app and this website (the “Service”).
Scratchy Us is a private couple product. Memories, comments, and the shared map are visible only to the two paired accounts. There is no public feed and we do not sell personal information for advertising.
2. Controller
The personal information controller (operator) for Scratchy Us is DJ.H (Do Jin-hyeon).
Privacy requests: cmjh951330@gmail.com
During launch the Service is operated as an independent product. We do not operate a separate corporate privacy office; the operator email above is the primary contact channel.
3. Information we collect
Depending on how you use Scratchy Us, we may process the categories below. Exact fields can vary by sign-in provider and device platform.
| Category | Examples | Notes |
|---|---|---|
| Account | Firebase Auth UID; email if the provider supplies it; display name; auth provider type (email, Google, Apple) | Required to sign in and restore your account on a new device. |
| Couple | Invite code; pairing timestamps; anniversary date; which partner has scratched each country | Needed to lock the app to two people and to open countries only when both of you scratch. |
| Memories | Photos, videos, voice notes, captions, comments, optional place text, trip dates, scratch progress | Visible only to the paired partner. Uploaded when you post a memory. |
| Device and push | FCM device token; Firebase installation ID; approximate OS / platform; app version | Enables optional nudges (your turn, a country opened, a comment) when you grant notification permission. |
| Diagnostics | Firebase Crashlytics stacks; Firebase Analytics and Mixpanel product events (screens, feature use, identified by account id); App Check attestation signals | Helps us find crashes, understand feature use at an aggregate level, and harden the client. |
| Infrastructure logs | IP address, connection metadata, and standard server access logs | Collected automatically by hosting infrastructure for security and reliability — not for advertising profiles. |
We do not collect
- Precise GPS or continuous location tracking. You pick countries by tapping them on the map.
- Device contacts or address book. Pairing uses an invite code, not your contacts.
- Payment card details or in-app purchase receipts. Scratchy Us has no paid features.
- Health, fitness, or biometric templates.
- Android advertising ID (GAID) or IDFA. Analytics does not collect advertising identifiers.
Camera, photo library, and microphone access are optional. They are used only when you add a photo, video, or voice note to a memory, or save a map card to Photos.
4. How we collect
- Directly from you — when you sign in, set a name, pair with a partner, scratch a country, post a memory, comment, or contact support.
- Automatically from the app — scratch progress, diagnostic SDKs (Crashlytics, Firebase Analytics, Mixpanel, App Check), and push-token registration.
- From authentication providers — identity assertions (UID, email/name when provided) via Firebase Auth (email, Google, or Sign in with Apple).
- From hosting logs — IP and connection metadata recorded by servers and gateways.
5. Purpose of use
We use personal information to:
- Provide and operate the Service, including accounts, couple pairing, the shared map, feed, and albums.
- Store and display memories only to the two paired accounts.
- Send optional push notifications related to scratching, opened countries, and comments (where you grant permission).
- Diagnose crashes, improve stability, and secure the client with App Check.
- Measure app use with Firebase Analytics and Mixpanel so we can understand retention and feature use. We do not collect the Android advertising ID or IDFA. Mixpanel may derive approximate region from IP for analytics, not for ads.
- Respond to support and account-deletion requests.
We do not sell personal information. We do not use advertising identifiers.
6. Legal basis
Where GDPR or similar frameworks apply, we typically rely on: (a) performance of a contract — providing the account, map, and memories you request; (b) legitimate interests — security, crash diagnostics, and service improvement, balanced against your rights; and (c) consent — where required for optional camera, microphone, photo library, or push notifications.
Under Korean personal information law, we process information as necessary to provide the Service you use, to fulfill statutory obligations, and — where required — based on your consent for optional features.
7. Retention
- Account, couple, and memories — retained while your account remains active.
- Couple disconnect — either partner can unpair from Profile. You both return to browsing without a pair. Shared map and memory data stays stored but is no longer shown in the app.
- Account deletion — we remove your login from the profile, anonymize your display name, and drop your avatar. You may create a new account with the same Google, Apple, or email login. Shared map and memories stay visible to the remaining partner, with your name shown as “Deleted user”. New countries no longer open. See Delete Account.
- Device tokens — removed or rotated when the app unregisters the token, you reinstall, or the token expires.
- Diagnostics — retained according to Firebase product defaults, generally weeks to months. Mixpanel event and people records follow Mixpanel’s project retention settings, typically months unless we delete a profile after an account-deletion request.
- Infrastructure logs — commonly 30–90 days unless an incident requires longer review.
8. Sharing and processors
We do not sell personal information. We share data with processors who help us run the Service:
- Google Firebase — authentication, analytics, crash reporting, Cloud Messaging, and App Check.
- Mixpanel — product analytics (events, sessions, and an identified user profile keyed to the account id; display name when you set one). Not used for advertising or cross-app tracking.
- Supabase — database and file storage for couple progress, posts, comments, and media.
These processors act on our instructions. We may also disclose information if required by law, to protect the Service, or in connection with a transfer of the product, in which case this Policy would continue to apply or you would be notified.
9. International transfers
Firebase, Mixpanel, and Supabase may process data on servers outside your country, including the United States and other regions. By using the Service you understand that your information may be transferred to those locations. We rely on the contractual and technical safeguards offered by those providers.
10. Security
We transmit data over HTTPS. Access to memories is limited by authentication and couple pairing. No method of transmission or storage is completely secure; we work to protect the Service with industry-standard practices including App Check on the client.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent for optional features. Sign-out is available in the app. Account deletion is handled as described on Delete Account.
Email cmjh951330@gmail.com to exercise these rights. We may need to verify that the request comes from the account holder.
12. Children
Scratchy Us is a couple product intended for adults 18 and over. It is not directed at anyone under 18, and we do not knowingly collect personal information from children. If you believe a person under 18 has created an account, contact us and we will delete it. Child sexual abuse and exploitation material is prohibited; we will remove it and report confirmed CSAM to the relevant authority.
13. Cookies and this website
This marketing website does not set advertising cookies. It is a static site. The browser may store ordinary technical data (such as IP address in host logs). We do not run ads, analytics pixels, or cross-site tracking on this site.
14. Changes
We may update this Policy. The effective date at the top will change when we publish a revision. Material changes may also be noted in the app or on this page.
15. Contact
Operator: DJ.H (Do Jin-hyeon)
Email: cmjh951330@gmail.com
See also: Terms of Service · Delete Account