FlarePilot
English

FlarePilot Privacy Policy

Effective date: August 19, 2026, Version 1.0

This is an English translation of the Korean original, provided for convenience. If there is any discrepancy in interpretation between this translation and the Korean version, the Korean version prevails.

Seoyeon Bae (hereinafter the "Operator"), in providing FlarePilot (hereinafter the "Service"), processes personal information lawfully and manages it safely in compliance with the Personal Information Protection Act (개인정보 보호법) and other relevant statutes in order to protect the freedom and rights of data subjects.
Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Operator establishes and discloses this privacy policy as follows in order to inform data subjects of the procedures and standards for the processing and protection of personal information and to handle related grievances promptly and smoothly.

FlarePilot does not transmit the user's Cloudflare credentials to the Operator's servers.

API tokens and OAuth refresh tokens are stored only inside the user's device, and the app communicates directly with api.cloudflare.com and dash.cloudflare.com.
Because the Operator does not hold the user's credentials, it can neither view them nor revoke them on the user's behalf.
The Google AdMob SDK, which serves the banner advertisements displayed in the iOS and Android versions, also does not access the user's credentials.
The Operator does not provide personalized advertising at all, and every advertisement is served as a non-personalized advertisement that does not reflect the user's interests.

1. Purposes of Processing Personal Information

The Operator processes personal information for the following purposes.
The personal information being processed is not used for any purpose other than the following, and where the purpose of use is changed, the Operator will implement the necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

  1. Connection to and authentication of a Cloudflare account: The Operator processes personal information for the purpose of providing the function of viewing and managing the resources of the user's Cloudflare account (domains, DNS, WAF, R2, Workers, and the like) by storing on the device the means of authentication entered by the user or issued through Cloudflare sign-in.
  2. Provision of the app lock function: The Operator processes personal information for the purpose of providing an identity verification step when the app is launched, by storing on the device the lock passcode set by the user and whether biometric authentication is used.
  3. Analysis of service use and quality improvement: The Operator processes personal information for the purpose of improving the stability and usability of the Service by analyzing usage statistics such as the number of app launches, screen transitions, the frequency of function use, and the status of error occurrences.
  4. Delivery of advertisements and measurement of advertising performance: In order to secure the funds for providing the Service free of charge, the Operator processes personal information for the purpose of displaying banner advertisements and rewarded advertisements that the user chooses to watch on the user's own initiative in the iOS and Android versions, and of measuring the impressions and clicks of those advertisements.
    Because the Operator does not provide personalized advertising reflecting the user's interests, it does not process personal information for the purpose of inferring areas of interest or selecting advertisements accordingly, nor does it collect or use advertising identifiers.
    Processing for this purpose is carried out by Google LLC in the course of displaying advertisements, and the Operator neither collects nor retains that information; because the delivery of advertisements is incidental to the use agreement, that processing is carried out without the consent of the data subject on the basis of Article 15 (1) 4 of the Personal Information Protection Act.
    Matters concerning this are set out in Article 2 (2).
  5. Management of the ad-free period granted upon watching a rewarded advertisement: The Operator processes personal information for the purpose of storing on the device and checking the expiry time of the period during which advertisements are not displayed where the user has watched a rewarded advertisement to the end.
  6. Handling of grievances and responses to inquiries: The Operator processes personal information for the purpose of replying to the user's inquiries and error reports and informing the user of the progress of their handling.

2. Items of Personal Information Processed and the Method of Obtaining Consent

The Operator processes only the minimum personal information necessary for the provision of the Service.

CategoryItems collectedMethod of collectionStorage location
Cloudflare authentication information The information for the connection method chosen by the user among the following: ① OAuth access and refresh tokens, ② a Cloudflare API token, ③ the Cloudflare account email address and Global API Key. Together with these, the account identifier (Account ID) and the account display name Direct entry by the user, or the Cloudflare sign-in (OAuth) procedure Inside the user's device
App lock settings The hash value of the 6-digit lock passcode (an SHA-256 value computed with a random salt appended), and whether biometric authentication is used Direct configuration by the user Inside the user's device
Service usage records App instance identifier (Firebase installation ID), event names and times of occurrence, screen names, app version, operating system version, device model, country and language settings, approximate location (country and city level), network type Automatically generated and collected when the app is used (iOS and Android versions only) Google LLC (United States)
Advertising delivery records IP address, device information (model, operating system version), approximate location (country level), records of ad impressions and clicks. Advertising identifiers (the Android advertising ID (AAID) and the iOS advertising identifier (IDFA)) are not included. Automatically collected through the Google AdMob SDK when a banner advertisement or a rewarded advertisement is displayed in the app (iOS and Android versions only). Because the under-age-of-consent tag applied by the Operator blocks the transmission of advertising identifiers, no advertising identifier is collected. Google LLC (United States)
Ad-free period information The expiry time of the ad-free period granted upon the completion of watching a rewarded advertisement Automatically generated only where the user has watched a rewarded advertisement to the end (iOS and Android versions only) Inside the user's device
Inquiry handling records Email address, content of the inquiry, records of replies Collected only where the user makes an inquiry by email Server managed by the Operator (Oracle Cloud Infrastructure, Seoul region)

Method of storage on the device: The Cloudflare authentication information and the app lock settings are stored using the protection means provided by the operating system.
iOS uses the Keychain and Android uses EncryptedSharedPreferences (AES-256).

Method of obtaining consent: In accordance with Article 22 (1) of the Personal Information Protection Act, the Operator displays a consent screen when the app is first launched, distinguishes each matter of consent, informs the data subject so that the data subject can clearly recognize it, and then obtains consent item by item.
On the consent screen, in accordance with each subparagraph of Article 15 (2) of the same Act, the Operator also informs the user of the purposes of collecting and using personal information, the items of personal information to be collected, the period of retention and use of personal information, the fact that the user has the right to refuse consent, and the disadvantages of refusing consent.
The consent screen also displays links through which the full text of this privacy policy and of the Terms of Service can be reviewed.

CategoryConsent itemPurposeInformation concernedRetention periodWhere consent is refused
Mandatory Confirmation of being 14 years of age or older Verification of whether the user is a child as defined in Article 22-2 of the Personal Information Protection Act The fact of confirmation that the user is 14 years of age or older. Information on age as such, such as date of birth or age, is not collected. Until the app is deleted The Service cannot be used.
Mandatory Consent to the Terms of Service Formation of the use agreement The fact of consent Until the app is deleted The Service cannot be used.
Mandatory Consent to the collection and use of personal information Connection to and authentication of a Cloudflare account, provision of the app lock function, management of the ad-free period, and handling of grievances and responses to inquiries The Cloudflare authentication information, app lock settings, ad-free period information, and inquiry handling records in the table above The periods specified in Article 4 Because the essential functions of the Service cannot be provided, the Service cannot be used.
Optional Consent to the collection of usage statistics Analysis of service use and quality improvement The service usage records in the table above 14 months from the date of collection Usage statistics are not collected. All functions of the Service remain available without restriction.
  1. Distinction between mandatory consent and optional consent: Mandatory consent items and optional consent items are displayed separately on the screen, and for each item the user is informed whether it is mandatory or optional.
    The user may choose separately, item by item, whether to consent.
  2. Information processed without obtaining consent: In the course of displaying advertisements in the app, the Google AdMob SDK communicates with the advertising servers of Google LLC, and in that course the IP address, device information (model, operating system version), approximate location (country level), and records of ad impressions and clicks are processed by Google LLC.
    The Operator neither collects nor retains this information, and does not receive it on its servers.
    Because FlarePilot is provided without a usage fee and the delivery of advertisements is incidental to that use agreement, the Operator carries out this processing without obtaining the consent of the data subject, on the basis of the case prescribed in Article 15 (1) 4 of the Personal Information Protection Act, namely "where it is necessary to perform a contract concluded with the data subject or to take measures at the request of the data subject in the course of concluding a contract".
    Because the Operator does not provide personalized advertising at all and does not process advertising identifiers either, this processing does not constitute the processing of personal information for advertising purposes that requires separate consent.
    This subparagraph is intended to disclose, in accordance with Article 22 (3) of the same Act, the items of personal information that may be processed without consent and the legal basis for that processing, separately from the personal information processed on the basis of consent.
    Specific matters concerning this are set out in Article 11, and matters concerning the overseas transfer are set out in Article 9.
  3. The right to refuse optional consent: In accordance with Article 16 (3) and Article 22 (5) of the Personal Information Protection Act, the Operator does not refuse to provide the Service on the ground that the user does not consent to an optional consent item.
    Even where the user does not consent to the collection of usage statistics, all functions of FlarePilot remain available without restriction.
  4. Withdrawal of consent: In accordance with Article 37 (1) of the Personal Information Protection Act, the user may withdraw consent at any time.
    Optional consent to the collection of usage statistics may be withdrawn or given again under More > Send Usage Statistics in the app, and the withdrawal takes effect immediately.
    Mandatory consent to the collection and use of personal information may be withdrawn by selecting Withdraw consent to the collection and use of personal information on the More > Usage Statistics and Terms screen of the app.
    In this case, in accordance with paragraph (3) of the same Article, the Operator deletes the Cloudflare authentication information, app lock settings, and consent records stored on the device so that they cannot be restored or reproduced and signs the user out of the app, and the procedure and method therefor are specified in Article 5.
    Because mandatory consent is a precondition for using the Service, once the withdrawal is complete the app returns immediately to the consent screen, and in order to use the Service again the user must go through the consent procedure from the beginning on that screen.
    The intent to withdraw may also be expressed by signing out of the app or deleting the app.
  5. Why no consent item concerning personalized advertising is provided: The Operator does not provide personalized advertising at all, and applies the under-age-of-consent tag (tagForUnderAgeOfConsent) provided by Google AdMob across the entire app so that every ad request is transmitted as a request for non-personalized advertising.
    Because the Operator has declared the target age groups on Google Play as 13 to 15, 16 to 17, and 18 and over, and has chosen to apply the Families policy across the entire app, it provides only non-personalized advertising uniformly to all users without a separate age screening.
    Accordingly, no optional item concerning personalized advertising is provided on the consent screen, and no function for turning personalized advertising on or off is provided on the settings screen.
  6. Separate consent procedures required by foreign statutes: For users in regions to which the European General Data Protection Regulation (GDPR) and the personal information protection statutes of individual states of the United States apply, the Operator carries out a consent procedure through Google UMP (User Messaging Platform).
    This procedure is displayed only in regions where the statutes concerned require it, and for users in those regions the item Reset advertising consent is displayed on the More screen of the app so that they may review and change the content of that consent at any time.
    This procedure is not intended to obtain consent to personalized advertising, and, regardless of its outcome, the Operator provides only non-personalized advertising to all users.
  7. Access permissions on the device: The only access permissions used by FlarePilot are network connectivity and, only for users who use the app lock, biometric authentication.
    Because biometric authentication is not an access permission that is indispensable for providing the Service, in accordance with Article 22-2 (2) of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (정보통신망 이용촉진 및 정보보호 등에 관한 법률), the Operator does not refuse to provide the Service even where it is not allowed.
    The Operator does not request access permissions to other information and functions on the device, such as contacts, photos, location, microphone, or camera.

FlarePilot does not collect at all any name, unique identifying information including a resident registration number, payment information, telephone number, precise location information, or personal material on the device such as contacts, photos, or call records.
The Operator does not collect or use advertising identifiers (the Android advertising ID (AAID) or the iOS advertising identifier (IDFA)).
The under-age-of-consent tag applied across the entire app blocks the transmission of advertising identifiers as such, and the specific details are set out in Article 11.
Advertising delivery records are processed by Google LLC only for the purpose of delivering non-personalized advertisements and measuring their performance in the iOS and Android versions, and the Operator neither collects nor retains them.
The expiry time of the ad-free period granted upon watching a rewarded advertisement is stored only inside the user's device and is not transmitted to the Operator's servers.
The advertising SDK does not access information stored inside the device, such as Cloudflare authentication information and app lock settings.

3. Verification of Being 14 Years of Age or Older and Protection of Children's Personal Information

FlarePilot is a service intended for web infrastructure operators who hold a Cloudflare account; it is not directed at children under 14 years of age and does not collect the personal information of children under 14 years of age.

  1. Age verification procedure: On the consent screen displayed when the app is first launched, the Operator requires the user to consent to an item confirming that the user is 14 years of age or older.
    Because this item is mandatory, a user who does not consent to it cannot complete the consent procedure and cannot use the Service.
  2. Information not collected: For the purpose of age verification, the Operator does not collect information on age as such, such as date of birth, age, or resident registration number, and records only the fact that the user has been confirmed to be 14 years of age or older inside the user's device.
    This record is not transmitted to the Operator's servers.
  3. Where the user is under 14 years of age: A person under 14 years of age may not use FlarePilot.
    Where the Operator confirms that a user is under 14 years of age, it destroys without delay the personal information collected in respect of that user in accordance with Article 21 (1) of the Personal Information Protection Act and discontinues that user's use of the Service.
    The user or the user's legal representative may notify the Operator of that fact at [email protected] and request destruction.
  4. Matters concerning the consent of a legal representative: Article 22-2 (1) of the Personal Information Protection Act provides that, where a personal information controller must obtain consent in order to process the personal information of a child under 14 years of age, it must obtain the consent of that child's legal representative and verify whether the legal representative has consented.
    Because the Operator does not process the personal information of children under 14 years of age and provides the Service only to users confirmed to be 14 years of age or older as set out in the preceding subparagraphs, it maintains no procedure for obtaining the consent of a legal representative under that paragraph.
    Should the Operator come to process personal information directed at children under 14 years of age in the future, it will obtain the consent of the legal representative by the methods prescribed in the same Article and in Article 17-2 of the Enforcement Decree of the same Act, and will give notice using an easily understandable form and clear and plain language in accordance with paragraph (3) of the same Article.
  5. Exercise of rights by a legal representative: In accordance with Article 38 (2) of the Personal Information Protection Act, the legal representative of a child under 14 years of age may request access to, correction or deletion of, suspension of the processing of, and withdrawal of consent to the child's personal information, and the method therefor is set out in Article 12.

4. Period of Processing and Retention of Personal Information

CategoryRetention period
Cloudflare authentication informationUntil the user signs out of the app or deletes the app
App lock settingsUntil the user disables the app lock or deletes the app
Service usage records14 months from the date of collection (in accordance with the Google Analytics data retention setting)
Advertising delivery recordsUp to 180 days from the date of collection (in accordance with Google's advertising data retention policy). Because advertising identifiers are not collected, there is no retention period for them.
Ad-free period informationUntil three days have passed from the completion of watching a rewarded advertisement, or until the user withdraws consent to the collection and use of personal information or deletes the app
Inquiry handling records3 years from the date on which the inquiry was handled

Where another statute prescribes a separate retention period, the information is kept for the period prescribed by that statute.

5. Procedure and Method for Destroying Personal Information

Where personal information becomes unnecessary, such as where the retention period has elapsed or the purpose of processing has been achieved, the Operator destroys that personal information without delay (within five days unless there are justifiable grounds).

  1. Destruction procedure: The authentication information and app lock settings stored on the device are deleted as soon as the user signs out of the app or deletes the app.
    Inquiry handling records kept on the server are destroyed after verification by the Personal Information Protection Officer once the retention period expires.
  2. Destruction method: Information in the form of electronic files is permanently deleted by a method that makes restoration and reproduction impossible, and information printed on paper is destroyed by shredding or incineration.
  3. Revocation of the connection permission on the Cloudflare side: Signing out of the app deletes the tokens stored on the device.
    However, because the Operator cannot revoke the app connection permission that remains in the Cloudflare account, the user must revoke it directly under My Profile > Access Management > Connected Applications in the Cloudflare dashboard.
    An API token issued by the user can be revoked under My Profile > API Tokens in the Cloudflare dashboard.
  4. Destruction upon withdrawal of consent: Where the user selects Withdraw consent to the collection and use of personal information on the More > Usage Statistics and Terms screen of the app, the Operator destroys the Cloudflare authentication information, app lock settings, and consent records stored on the device without delay so that they cannot be restored or reproduced, in accordance with Article 37 (3) of the Personal Information Protection Act, and signs the user out of the app.
    This destruction is carried out by permanently deleting the information by a method that makes restoration impossible, in accordance with Article 16 (1) 1 of the Enforcement Decree of the same Act.
    At that time the ad-free period information granted upon watching a rewarded advertisement is deleted as well.
    Because the mandatory consent ceases to exist, the user cannot use the Service from that point, and the app returns immediately to the consent screen.
  5. Where the app is deleted: Where the user deletes the app, no values stored on the device remain.
    The Android version is configured not to use the automatic backup function of the operating system (allowBackup=false) so that values stored on the device are not backed up to external storage or restored upon reinstallation.
    Because, by the nature of the operating system, values may remain in the Keychain in the iOS version even after the app is deleted, where the app confirms that it has been reinstalled it first deletes the values remaining in the Keychain before any other processing.

6. Provision of Personal Information to Third Parties

The Operator processes the personal information of data subjects only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only where the case falls under Article 17 or Article 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.
At present there is no case in which FlarePilot provides personal information to a third party.

The entrustment of personal information processing work for the provision of the Service is set out in Article 8, and matters concerning overseas transfers are set out in Article 9.
Matters concerning the information processed by Google LLC for the delivery of banner advertisements are likewise set out in Articles 8 and 9.
The entrustment of processing work and overseas transfers are types of processing distinct from provision to a third party under the Personal Information Protection Act.

7. Matters Concerning Additional Use and Provision

In accordance with Article 15 (3) and Article 17 (4) of the Personal Information Protection Act, the Operator does not additionally use or provide personal information without the consent of the data subject.
Should additional use or provision become necessary in the future, the Operator will take into account the criteria for determination prescribed in Article 14-2 of the Enforcement Decree of the same Act and will disclose the details in advance through this privacy policy.

8. Entrustment of Personal Information Processing Work

For the smooth provision of the Service, the Operator entrusts personal information processing work as follows.

Entrusted party (trustee)Details of the entrusted workProcessing location
Google LLC Collection and analysis of service usage statistics and aggregation of error occurrences (Google Analytics for Firebase) United States: see Article 9
Google LLC Delivery of non-personalized banner advertisements and rewarded advertisements and measurement of their performance (Google AdMob), and provision of consent procedures in regions where foreign personal information protection statutes apply (Google User Messaging Platform). Limited to the iOS and Android versions; advertising identifiers are not transmitted. United States: see Article 9
Cloudflare, Inc. Static hosting of the sign-in callback page and the policy pages, and blocking of security threats (Cloudflare Pages) United States and elsewhere: see Article 9
Cloudflare, Inc. Receipt of inquiry emails and their forwarding to the Operator's mailbox (Cloudflare Email Routing) United States and elsewhere: see Article 9
Oracle Corporation Provision of the cloud infrastructure for the server on which inquiry handling records are kept (Oracle Cloud Infrastructure) Republic of Korea (Seoul region)
  1. In accordance with Article 26 of the Personal Information Protection Act, when concluding an entrustment agreement the Operator specifies, in documents such as the data processing terms presented by the trustee, matters concerning the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on re-entrustment, the management and supervision of the trustee, liability such as damages, and the like, and supervises whether the trustee processes personal information safely.
  2. Where the details of the entrusted work or the trustee change, the Operator will disclose this through this privacy policy without delay.
  3. Matters concerning work entrusted overseas are set out together in Article 9 (Overseas Transfer of Personal Information).

9. Overseas Transfer of Personal Information

For the provision of the Service, the analysis of use, and the delivery of advertisements, the Operator transfers personal information overseas (entrustment of processing) as follows, on the basis of Article 28-8 (1) 3 (a) of the Personal Information Protection Act (where the entrustment of processing or the storage of personal information is necessary for the conclusion and performance of a contract with the data subject and the matters listed in each subparagraph of paragraph (2) of the same Article have been disclosed in the privacy policy under Article 30 of the same Act).
The table below and the accompanying explanations are intended to disclose the items of personal information transferred, the country, timing, and method of the transfer, the name and contact details of the transferee, the transferee's purpose of use and its retention and use period, and the method and procedure for refusing the transfer and the effect of such refusal, as prescribed in each subparagraph of paragraph (2) of the same Article.

TransfereeCountry of transferItems transferredTiming and method of transferPurpose of useRetention and use period
Google LLC
[email protected]
United States App instance identifier (Firebase installation ID), event names and times of occurrence, screen names, app version, operating system version, device model, country and language settings, approximate location (country and city level), network type Encrypted transmission over the network (TLS) at the time the app is used Analysis of service usage statistics, identification of the causes of errors, and quality improvement (Google Analytics for Firebase) 14 months from the date of collection
Google LLC
https://support.google.com/admob
United States IP address, device information (model, operating system version), approximate location (country level), records of ad impressions and clicks. Advertising identifiers (AAID, IDFA) are not transmitted. Encrypted transmission over the network (TLS) at the time a banner advertisement or a rewarded advertisement is displayed in the app; limited to the iOS and Android versions Delivery of non-personalized banner advertisements and rewarded advertisements and measurement of their performance (Google AdMob) Up to 180 days from the date of collection
Cloudflare, Inc.
[email protected]
United States (via the global edge network) Connecting IP address, time of connection, browser information (when accessing the OAuth sign-in callback page and the policy pages) Encrypted transmission over the network (TLS) at the time the webpage concerned is accessed Static hosting of the sign-in callback page and the policy pages, and blocking of security threats In accordance with Cloudflare's log retention policy (up to 30 days)

Method of refusing the transfer and its effect: The user may refuse the transfer of usage records to Google LLC at any time by turning off More > Send Usage Statistics in the app.
Even in this case all functions of FlarePilot remain available without restriction, and there is no disadvantage whatsoever in using the Service.
Transfers relating to advertising do not include advertising identifiers.
Because the under-age-of-consent tag applied by the Operator across the entire app blocks the transmission of advertising identifiers, the scope of this transfer does not change even where the user restricts or resets the use of the advertising identifier in the operating system settings of the device.
Because the IP address and device information must inevitably be transmitted to Google LLC in order to deliver advertisements, no method of refusing this transfer alone is provided.
The user may stop this transfer by withdrawing consent to the collection and use of personal information or by deleting the app, as provided below.
Because the Operator does not provide personalized advertising, only non-personalized advertisements that do not reflect the user's interests are ever displayed to the user.
However, no paid option for not displaying advertisements at all is currently provided.
Where the user withdraws consent to the collection and use of personal information or deletes the app, advertisements are no longer displayed from that point, so this transfer also ceases.
Because the transfer to Cloudflare, Inc. serves to perform the essential function of the Service, namely connection to a Cloudflare account, the Service cannot be used if this transfer is refused.
In that case the user may stop the transfer by deleting the app.

The user's Cloudflare API token, Global API Key, and OAuth refresh token are stored only on the user's device and are not transferred to the Operator's servers or to any other third party.
Communication between the app and Cloudflare takes place directly from the user's device to api.cloudflare.com and dash.cloudflare.com, and this constitutes the user's own use of the service under the contract between the user and Cloudflare, Inc.

10. Measures to Ensure the Safety of Personal Information

The Operator takes the following measures to ensure the safety of personal information.

  1. Administrative measures: The Operator minimizes the number of persons handling personal information to one, namely the Personal Information Protection Officer, and establishes and implements an internal management plan for personal information.
  2. Technical measures
    • Cloudflare authentication information and the lock passcode are stored in the iOS Keychain and in Android EncryptedSharedPreferences (AES-256).
    • The lock passcode is not stored in plain text; only the hash value computed with a salt newly generated for each device appended is stored.
    • All communication between the app and external services is encrypted with TLS.
    • PKCE (S256) is applied to OAuth sign-in so that no token is issued even if the authorization code is intercepted.
    • The app lock (lock passcode and biometric authentication) function is provided so that unauthorized access can be blocked if the device is lost.
  3. Physical measures: The server on which inquiry handling records are kept is located in an access-controlled data center, and administrator access is restricted to key-based authentication.

11. Matters Concerning the Installation and Operation of Devices That Automatically Collect Personal Information and the Refusal Thereof

App instance identifier: For the analysis of service use, the Operator uses the app instance identifier (Firebase installation ID) generated by Google Analytics for Firebase.
This is a technology similar to web cookies; a random value is assigned to each device on which the app is installed and is used to aggregate usage statistics.

  1. Purpose of collection: To aggregate app launches, screen transitions, function use, and the status of error occurrences as anonymous statistics and thereby improve the quality of the Service.
  2. Items collected: The same as the "service usage records" item in Article 2.
  3. Management of consent signals: Google Analytics for Firebase operates in Consent Mode.
    The Operator keeps the advertising-related consent signals ad_storage, ad_user_data, and ad_personalization_signals fixed in the denied state at all times, regardless of the user's choice.
    The only consent signal whose value varies with the user's choice under More > Send Usage Statistics is analytics_storage.
    Accordingly, usage statistics are under no circumstances used for advertising purposes.
  4. Method of refusal: Turning off More > Send Usage Statistics in the app switches analytics_storage to the denied state, so the collection of usage records stops immediately and the app instance identifier assigned up to that point is deleted.
    Even in this case, however, only the number of accesses is aggregated anonymously without any identifier, including the app instance identifier, and because this aggregation is in a form in which no particular user or particular device can be recognized, it does not constitute personal information.
    Collection may also be stopped by deleting the app.
  5. Disadvantages of refusal: Even where the user refuses the collection of usage statistics, all functions of FlarePilot remain available without restriction.

Advertising identifiers: The Operator neither collects nor uses the advertising identifiers provided by the operating system (the Android advertising ID (AAID) and the iOS advertising identifier (IDFA)).
The Operator applies the under-age-of-consent tag (tagForUnderAgeOfConsent) provided by Google AdMob across the entire app, and, according to Google's guidance, this tag blocks the transmission of advertising identifiers as such.

  1. Effect of the under-age-of-consent tag: Where this tag is applied, the transmission of the Android advertising ID (AAID) on Android and of the advertising identifier (IDFA) on iOS is blocked.
    In addition, personalized advertising including remarketing is disabled for all ad requests, and no requests are made to third-party advertising vendors such as ad measurement pixels or third-party ad servers.
    Accordingly, no value identifying the user is generated or transmitted in the course of the app delivering advertisements.
  2. Why this approach was chosen: The Operator has declared the target age groups on Google Play as 13 to 15, 16 to 17, and 18 and over, and has chosen to apply the Families policy across the entire app.
    As a result, only non-personalized advertising is provided uniformly to all users without a separate age screening.
    Accordingly, no procedure for obtaining consent to personalized advertising is maintained, and no function for turning personalized advertising on or off is provided on the settings screen.
    The consent procedure carried out through Google UMP in regions where foreign personal information protection statutes apply is set out in Article 2 (6), and, regardless of its outcome, only non-personalized advertising is provided to all users.
  3. Information processed for the delivery of advertisements and the legal basis therefor: Even though advertising identifiers are not transmitted, communication is necessary in order to display an advertisement on the screen, and therefore the IP address, device information (model, operating system version), approximate location (country level), and records of ad impressions and clicks are transmitted to Google LLC.
    This processing is carried out by Google LLC in the course of displaying advertisements, and the Operator neither collects nor retains that information and does not receive it on its servers.
    Because FlarePilot is provided without a usage fee and the delivery of advertisements is incidental to that use agreement, this processing is carried out without the consent of the data subject on the basis of Article 15 (1) 4 of the Personal Information Protection Act.
    The specific items are the same as the "advertising delivery records" item in Article 2 and as Article 2 (2), and matters concerning the overseas transfer are set out in Article 9.
  4. Method of refusal: Because advertising identifiers are not transmitted in the first place, the scope of the information processed in relation to FlarePilot does not change even where the user resets the advertising identifier or restricts its use in the operating system settings of the device.
    Because the delivery of advertisements is incidental to the use agreement, no method of refusing this processing alone is provided; where the user discontinues the use of the Service by deleting the app or by withdrawing consent to the collection and use of personal information on the More > Usage Statistics and Terms screen of the app, advertisements are no longer displayed from that point, so this processing also ceases.
  5. Disadvantages of refusal: Until the use of the Service is discontinued by the methods above, advertisements continue to be displayed, and apart from that the user suffers no disadvantage in the Service.
    However, where consent is withdrawn, the mandatory consent ceases to exist and the Service can no longer be used, and the effect thereof is set out in Article 5.
  6. Measurement of advertising performance on iOS: The iOS version participates in SKAdNetwork provided by the operating system in order to aggregate the conversion performance of advertisements.
    This is a function at the operating system level that conveys only advertising performance to the ad network in a form that does not identify an individual user or an individual device, and there is no information separately collected by the Operator.
    Because the Operator does not track the user's activity across other apps or websites, it does not request App Tracking Transparency permission.

Ad-free period information: Where the user watches a rewarded advertisement to the end on the settings screen of the app, the Operator does not display advertisements for three days from that point, and stores only the expiry time of that period inside the user's device in order to determine this.

  1. Items stored and their location: Only a single value, the expiry time of the ad-free period, is stored inside the user's device, and neither the content of the advertisement watched nor a viewing history is stored.
    This value is not transmitted to the Operator's servers, and is neither provided to third parties nor transferred overseas.
  2. Method of refusal: Because watching a rewarded advertisement is a matter of the user's own choice, this value is not generated if the user does not watch one.
    A value already stored is deleted once the expiry time has passed, or where the user withdraws consent to the collection and use of personal information or deletes the app.
  3. Disadvantages of refusal: Even where the user does not watch a rewarded advertisement, all functions of FlarePilot remain available without restriction.

Because FlarePilot does not process advertising identifiers that identify the user, it does not accumulate behavioral information from which the user's interests and tendencies could be ascertained and analyzed, and personalized advertising using behavioral information is under no circumstances provided.
The scope of what Google LLC processes in order to deliver non-personalized advertisements and measure their performance is limited to the items specified in the table in Article 9.
The advertising SDK does not access information stored inside the device, such as the user's Cloudflare authentication information and app lock settings.

12. Rights and Obligations of Data Subjects and Their Legal Representatives and the Method of Exercising Them

A data subject may exercise the following personal information protection rights against the Operator at any time.

  1. Request for access to personal information (Article 35 of the Personal Information Protection Act)
  2. Request for correction where there is an error or the like (Article 36 of the same Act)
  3. Request for deletion (Article 36 of the same Act)
  4. Request for suspension of processing (Article 37 (1) of the same Act)
  5. Withdrawal of consent to the processing of personal information (Article 37 (1) of the same Act)
  6. Refusal of an automated decision and requests for an explanation and the like (Article 37-2 of the same Act). However, as set out in Article 13, the Operator does not make automated decisions.

Rights may be exercised in writing or by email to [email protected], and the Operator will take measures without delay (within 10 days from the date on which the request is received) and inform the requester of the result.
Where a data subject has requested the correction or deletion of an error or the like in personal information, the Operator does not use or provide the personal information concerned until the correction or deletion is completed.
In accordance with Article 38 (4) of the Personal Information Protection Act, the Operator provides methods and procedures for exercising rights that are no more difficult than the methods and procedures for collecting personal information.

Objections: A data subject who is dissatisfied with the Operator's refusal of a request for access, correction or deletion, suspension of processing, or withdrawal of consent, or with any other measure taken by the Operator, may raise an objection at [email protected] in accordance with Article 38 (5) of the same Act.
The Operator will reply with the result of its reconsideration and the reasons therefor within 10 days from the date on which the objection is received, and, where the objection is found to be well founded, will take the necessary measures without delay.
With respect to the Operator's measures, a data subject may also apply for dispute mediation or counseling to the institutions set out in Article 15.

In accordance with Article 38 (1) of the Personal Information Protection Act and Article 45 (1) of the Enforcement Decree of the same Act, rights may be exercised through an agent, such as the data subject's legal representative or a person duly authorized by the data subject.
In this case, in accordance with Article 45 (2) of the same Decree, a power of attorney in the form prescribed by public notice of the Personal Information Protection Commission (Form 11 annexed to the Public Notice on the Methods of Processing Personal Information (개인정보 처리 방법에 관한 고시)) must be submitted.
In accordance with Article 38 (2) of the same Act, the legal representative of a child under 14 years of age may exercise the rights above with respect to that child's personal information.

The exercise of a data subject's rights may be restricted under Article 35 (4), Article 37 (2), and other provisions of the Personal Information Protection Act.

The authentication information and app lock settings stored on the device can be deleted immediately by the user directly through More > Sign out in the app or by deleting the app, without any separate request.
Optional consent to the collection of usage statistics may be withdrawn or given again at any time under More > Send Usage Statistics in the app, and even where optional consent is withdrawn, all functions of FlarePilot remain available without restriction.
Mandatory consent to the collection and use of personal information may be withdrawn by selecting Withdraw consent to the collection and use of personal information on the More > Usage Statistics and Terms screen of the app; upon withdrawal, the authentication information, app lock settings, and consent records stored on the device are deleted, the user is signed out, and the Service can no longer be used.
The method of withdrawing each consent and its effect are set out in Articles 2 and 5, and the information processed for the delivery of advertisements and the method of refusing it are set out in Article 11.
In accordance with Article 38 (4) of the Personal Information Protection Act, the Operator provides these methods and procedures for withdrawal within the app screens so that they are no more difficult than the methods and procedures for obtaining consent.

13. Matters Concerning Automated Decisions

The Operator does not make automated decisions under Article 37-2 (1) of the Personal Information Protection Act (decisions made by processing personal information with a fully automated system, including a system applying artificial intelligence technology, that have a material effect on the rights or obligations of a data subject).
Accordingly, there is also no processing in respect of which a data subject could refuse an automated decision or request an explanation or the like under the same Article.
Should the Operator come to make automated decisions in the future, it will disclose the criteria and procedures therefor and the manner in which personal information is processed in this privacy policy in accordance with paragraph (4) of the same Article.

14. Personal Information Protection Officer and the Department Receiving and Handling Requests for Access

In order to take overall responsibility for the work relating to the processing of personal information and to handle data subjects' inquiries, complaints, and remedies for damage relating to the processing of personal information, the Operator designates the sole proprietor himself or herself as the Personal Information Protection Officer as follows, in accordance with Article 31 of the Personal Information Protection Act and Article 32 (3) 2 (a) of the Enforcement Decree of the same Act.
As the Operator is a sole individual developer, the Personal Information Protection Officer also performs the work of receiving and handling requests for access and the work of handling grievances.

CategoryDetails
Service nameFlarePilot (iOS, Android)
Personal information controllerSeoyeon Bae (individual developer)
Personal Information Protection OfficerSeoyeon Bae
Contact[email protected]
Receipt and handling of requests for access to personal informationPersonal Information Protection Officer ([email protected])
Person in charge of grievance handlingConcurrently held by the Personal Information Protection Officer
Customer supporthttps://cf.getsdata.com/en/support/

Data subjects may direct to the Personal Information Protection Officer all matters relating to personal information protection inquiries, complaint handling, remedies for damage, and the like that arise while using FlarePilot.
The Operator will answer and handle data subjects' inquiries without delay.

15. Remedies for Infringement of the Rights and Interests of Data Subjects

In order to obtain relief from an infringement of personal information, a data subject may apply for dispute resolution, counseling, or the like to the Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회), the Privacy Infringement Report Center of the Korea Internet and Security Agency (한국인터넷진흥원 개인정보침해 신고센터), or the like.
For other reports of and counseling on personal information infringement, please contact the institutions below.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
  2. Privacy Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
  3. Supreme Prosecutors' Office (대검찰청): 1301 (no area code) (www.spo.go.kr)
  4. National Police Agency (경찰청): 182 (no area code) (ecrm.police.go.kr)

A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in respect of a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, Etc.) of the Personal Information Protection Act may request an administrative appeal as prescribed by the Administrative Appeals Act (행정심판법).

Central Administrative Appeals Commission (중앙행정심판위원회): 110 (no area code) (www.simpan.go.kr)

16. Items That Do Not Apply

Among the items to be stated under the Guidelines for Preparing a Privacy Policy (개인정보 처리방침 작성지침) of the Personal Information Protection Commission, the following do not apply to FlarePilot and therefore no separate content is provided for them.
Should such matters arise in the future, they will be reflected in this privacy policy and disclosed.

  1. The possibility of sensitive information being disclosed and the method of choosing non-disclosure: The Service does not process sensitive information, and there is no function by which a user's information is disclosed to other users.
  2. Processing of pseudonymized information: The Operator does not pseudonymize and use personal information.
  3. Designation of a domestic representative: Article 31-2 (1) of the Personal Information Protection Act requires personal information controllers that have no address or place of business in Korea and that are prescribed by Presidential Decree to designate a domestic representative.
    Because the Operator is a personal information controller with an address in Korea, it is not subject to that designation.
  4. Operation and management of fixed and mobile visual data processing devices: The Operator does not install or operate visual data processing devices.

17. Changes to This Privacy Policy

This privacy policy applies from August 19, 2026.
Where there is an addition, deletion, or modification of its content due to a change in statutes, policies, or security technology, notice will be given through this page and through an in-app announcement seven days before the effective date of the change.
However, where a material change to the rights of data subjects occurs, such as a change in the items of personal information collected or in the purposes of use, notice will be given at least 30 days in advance.
If a previous version of the privacy policy is needed, it will be sent upon request to [email protected].

VersionEffective datePrincipal changes
1.02026-08-19Initial establishment