Skip to main content

User Privacy & Security

Apps that use user personal information must have security measures in place for protecting it. Additionally, when using personal information, details on its usage and any third parties it is shared with must be transparently provided, and user consent must be obtained. Misusing SDKs provided for app development or improperly using user data without authorization is strictly prohibited.

User Personal Data Usage

Personal data includes personally identifiable information, financial and payment details, and authentication information. Even if it cannot identify an individual directly, any data that can be easily combined with other information to do so is considered personal data.

Products that collect personal data must comply with the following requirements.

  • Access permissions must be minimized to the extent necessary for the service.
  • Users must be informed of legal notices (such as the types of personal information collected, processing purpose, retention period, and their right to refuse consent), and an explicit consent process must be implemented.
  • When informing users, the purpose of personal data collection and retention period must be specified clearly, and data should only be processed to the minimum extent necessary for the service purpose. It must not be used for any other purposes.
  • A privacy policy outlining personal data processing must be made available in an easily understandable manner, and users' rights, such as access requests, must be ensured in accordance with applicable laws.
    • For other matters, applicable personal data protection laws, such as GDPR, apply.
  • Services that store and use location data may be required to verify registration/reporting details under the laws and regulations of the service country. If verification fails or false documents are provided, the product may be suspended from sale.
ItemGuidelines to Follow
TransparencyIf the app accesses user personal data, it must clearly specify within the app itself the data collected, how it is used, and any sharing practices.
User Consent for Personal Data UsageApps using personal data must comply with relevant privacy laws. Additionally, proof of compliance with relevant laws or terms for personal data collection/use must be submitted to the App Market.
* These terms may be used as evidence if a violation of relevant laws is reported.
Personal Information Protection Committee
If an app intends to use user personal data (e.g., access/collection/usage/sharing), it must meet the [Transparency] criteria and obtain user consent.
When collecting children's personal data, the legal guardian must be informed beforehand and explicit consent must be obtained.
[User Consent Requirements (Mandatory)]
- The page or popup for selecting consent/refusal must be presented clearly and without ambiguity.
- Actions beyond pressing the provided consent button must not be considered as consent. (If you do not agree and go back, or touch an empty space on the screen)
- Access is limited to data from permissions granted by the user.

Security

All malicious code or actions that may expose user data or devices to risks, such as viruses, spyware, trojans, adware, and rooting, are prohibited. Using a user's device, applications, or network to harm users or others through spam, DDoS, or any malicious code or actions is prohibited. Any code or actions that cause inconvenience to users or deceive them are prohibited.

ItemGuidelines to Follow
Security ThreatsActions that intentionally damage, disrupt, interfere with, or tamper with a user's device, applications, or data, as well as installing code or programs without user consent, are prohibited.
- Detection of such attempts within the submitted app may result in immediate rejection.
Security Bypass AttemptsFunctions that purposely bypass, disable, or compromise system security protections are prohibited.
- Detection of such attempts within a submitted app may result in immediate rejection.
Unauthorized Use of User DataStealing or storing data without user consent, using personal data for advertising, or transmitting data to third parties without permission is prohibited.
User data may only be used for personalized advertising with explicit user consent regarding data use, storage, and third-party sharing.
- Users must be clearly notified if their data is being utilized, and consent must not be inferred through any action other than pressing the Consent button.
- Apps that include illegal content, inappropriate ads, spam, or disruptive recurring alerts may be removed from the App Market.
- Users must be allowed to revoke data-sharing consent at any time. When user consent is withdrawn, all in-app data usage paths must be disabled, and stored user data must be deleted immediately.
Prevention of Malicious BehaviorAll malicious code or actions that may expose user data or devices to risks are prohibited.
- Examples: viruses, spyware, trojans, adware, rooting, etc.
Using a user's device, applications, or network to harm users or others is prohibited.
- Examples: spam, DDoS, cryptojacking, etc.
Any code or actions that cause inconvenience to users or deceive them are prohibited.
- Examples: phishing, fraudulent advertisements.