Service policy effective August 20, 2026 · Android information added September 9, 2026 · English text prepared September 10, 2026.
1. About this policy
This policy describes personal information processing by the individual developer who operates TokTokTok (the “operator”). The service includes Apple Watch and Wear OS apps, iPhone, iPad and Android apps, Mac and Windows helpers, the motion shop and the website. The policy is published under Article 30 of the Republic of Korea’s Personal Information Protection Act.
2. Information processed and how it is collected
| Sign-in and accounts | Name, email address and user identifier (uid). iOS uses Sign in with Apple. Android uses Google sign-in or an operator-provided email account. Apple’s Hide My Email can provide a relay address instead of your actual email. For an iOS guest motion purchase, Firebase creates an anonymous user identifier without requesting your name or email. If you later link an Apple sign-in, purchases can be associated with that account. |
|---|---|
| Purchases and use | Pro and purchased motions, App Store or Google Play transaction identifiers and purchase tokens, verification and refund status, and pass/coupon ownership and use. Apple or Google handles payment-method details; the operator does not receive card or bank account numbers. |
| User content | Ratings, comments, posting times and reports. |
| Creator information | When submitting motions: nickname, contact email, terms acceptance time and tax classification information needed for settlement. |
| Problem reports | For iOS/web reports: app version, device model, OS version, connection state, internal error logs and an anonymous installation identifier. These are sent when you choose to submit a problem report. A signed-in report also records the uid so that a reward coupon can be issued. Reports without sign-in are accepted but cannot receive account coupons. Android opens a share sheet with app version, manufacturer, model and Android version. You can edit the content and choose its recipient; that feature does not automatically attach a uid or internal app error logs. |
| Reward coupons | Recipient uid, reason for issuance, issue/expiry/use times and the motion obtained. These records are created when the operator issues a coupon; no additional form input is needed. |
| Advertising | Ad impressions and clicks, app interactions, device/app identifiers, approximate location inferred from IP address (such as country or city), and app/ad SDK performance and error diagnostics. Google AdMob processes this information for non-personalized advertising. |
Information is entered by users or generated when a feature is used. A service account is created at first sign-in. Operator-provided review/support email accounts use Firebase Authentication for password authentication.
3. Information on devices and local connections
Control preferences, themes, pairing tokens, approved device names and downloaded motion files are stored on devices. The device name, pairing information, commands and selected motions needed for connection are exchanged between the phone, watch and computer you connect. Remote commands do not use the operator’s cloud as their relay. Some Android-to-helper local Wi-Fi connections use unencrypted WebSocket transport; use a trusted network.
Pairing tokens are random strings created when you approve a device and are stored in platform-protected storage. Device names identify which device is being approved. Downloaded motions are stored for playback. Use the helper’s Disconnect action to remove a device pairing; uninstalling apps removes their app data, subject to platform storage behavior.
4. Purposes
- Identify accounts and motion ownership, including restoration on other devices.
- Verify purchases, prevent duplicate grants, handle refunds and manage promotional coupons.
- Issue, redeem and revoke operator reward coupons.
- Display ratings/comments, receive reports and act on inappropriate content.
- Settle creator proceeds and process taxes.
- Investigate reports you submit and assess any report reward.
- Provide non-personalized advertising and prevent invalid ad activity.
5. Retention and deletion
| Account/profile | Deleted without delay following account deletion. Public creator names are changed to “Deleted creator” where published motions need to remain available to existing users. Internal creator identifiers and approved submission records needed to provide published motions and link purchase and settlement records are retained for those purposes. |
|---|---|
| Purchase/payment records | Under Korea’s Act on Consumer Protection in Electronic Commerce: contract/withdrawal records for five years; payment and supply records for five years; consumer complaint/dispute records for three years. |
| Settlement/tax records | For the periods required by relevant tax laws. |
| Posts, comments, ratings and attachments | Until the user deletes the content or deletes their account. |
| Problem-report diagnostics | Deleted within one year after processing is completed. |
| Reward coupons | Deleted within one year after use or expiry. Ownership of a motion obtained with a coupon is retained as a purchase/use record. |
Electronic files are permanently deleted using methods intended to prevent recovery. Printed records, if any, are shredded or destroyed.
6. Service providers and international transfers
The service uses the cloud and advertising providers below. Processing and storage needed to perform the user contract are disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act.
| Google LLC / Google Cloud | Firebase Authentication, Cloud Firestore, Cloud Storage and Cloud Functions provide authentication, storage, processing and motion-file delivery. The account, purchase/use, user-content, creator, report and reward-coupon information listed above is transferred through encrypted network connections during service use. Processing occurs in the United States and other countries where Google Cloud operates data centers. Retention follows Section 5 and the processing purpose or service contract. |
|---|---|
| Google LLC / AdMob | Provides non-personalized advertising, ad measurement and invalid-activity prevention. Ad/app interactions, device/app identifiers, IP-based approximate location and diagnostics are transferred through encrypted network connections when ads are served, to the United States and other processing locations. Retention follows Google’s advertising data policies. |
AdMob collects and shares advertising information for ad delivery, measurement and fraud prevention. Apart from this processing, the operator does not sell personal information or provide it directly to advertisers. Disclosure may occur where required by law or a lawful request from authorities. Apple/Google sign-in and payment processing are also governed by those providers’ policies. Payment-method details are not provided to the operator.
7. Advertising and automatic collection
- The app uses Google AdMob to support free use. It does not request personalized ads based on interests or behavioral history. The iOS app does not request App Tracking Transparency permission or use IDFA for tracking.
- A one-time ad-removal purchase disables the app’s ads, subject to purchase entitlement and refunds.
- You can manage advertising settings in iOS Settings → Privacy & Security → Apple Advertising and Tracking, or the relevant Google advertising settings on Android. Where the app offers privacy choices, use them to change advertising consent.
- The website does not use behavioral tracking cookies or analytics tools.
8. Your rights
You may request access, correction, deletion or suspension of processing, and withdraw consent. A legal representative may exercise these rights for a child under 14.
- Delete an account in iOS Settings → Support → Delete Account, or Android Settings → Purchase Account → Delete Account. If you cannot use the app, follow the account and data deletion instructions.
- Request deletion of your comments or ratings using the available in-app controls or the contact address below.
- Other requests are handled, with a response, within 10 days.
We may verify that a request comes from the relevant person. Information subject to legal retention may be excluded from deletion; the reason will be explained.
9. Children under 14
The service is not directed at children under 14 and does not knowingly collect their personal information. Features requiring sign-in use the applicable Apple/Google account or a provided email account. If the operator learns that a child’s information was collected without the required representative’s consent, it is deleted without delay.
10. Security measures
- HTTPS/TLS for cloud account, purchase, download and advertising communications, and cloud-provider encryption of stored data. Local connections are described in Section 3.
- Restricted server privileges and separately authorized administrator accounts.
- Database access rules limiting access to authorized data.
- Pairing tokens restricting local commands to approved devices.
11. Privacy contact
Privacy officer and operator: Lee Junhee.
Email: history8720@gmail.com.
12. Complaints and dispute assistance
In Korea, you can contact the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), the privacy infringement reporting center (privacy.kisa.or.kr, 118), the Supreme Prosecutors’ Office cyber investigation division (1301), or the National Police cyber bureau (182).
13. Changes
Changes and their effective date are announced on the policy page at least seven days before taking effect. Changes unfavorable to users are announced at least 30 days beforehand.