NawaplayAX PRODUCT STUDIO
하는 일작업 사례만든 앱블로그소개
01하는 일02작업 사례03만든 앱04블로그05소개
Back to Only You
Terms of Service
한국어English日本語

Only You Privacy Policy

Effective date: August 11, 2026
Last updated: August 11, 2026

Nawaplay (“we,” “us,” or the “Company”) respects the privacy of people whose personal information is processed through the Only You (오직 너, 君だけ) mobile app, its related web pages, customer support, and privacy-rights procedures (collectively, the “Service”). We comply with the laws that apply to our processing.

The Korean, English, and Japanese versions are intended to have the same meaning. No difference between translations limits rights granted by mandatory law in the place where you live.

1. Who is responsible for your information

  • Service operator: Nawaplay
  • Representative and Privacy Officer: Kangho Lee
  • Address: Rm 713-E14, 7th Floor, Innermass Hangang, 190 Gimpohangang 9-ro 75beon-gil, Gimpo-si, Gyeonggi-do, Republic of Korea
  • Privacy requests, complaints, and customer support: kenny@nawaplay.com
  • Telephone: 0507-1469-0797

2. Information we process

Category Information Source Purpose Retention
Account and authentication Internal account ID, Firebase UID, sign-in provider ID, verified email address, verified phone number, and country code You; Apple, Google, or email sign-in; Firebase Authentication Registration, sign-in, SMS multi-factor authentication, number changes, account recovery, and duplicate-number protection Until account deletion. A comparison token for a previous number is kept for 90 days after a number change
Age eligibility Whether you are at least 17, age-range signal, verification method and time, and applicable country Operating system, app marketplace, or you Enforcing age restrictions As needed for eligibility. We generally do not retain your exact date of birth
Chosen person and connection candidate A protected target token derived from the one number you choose, selection and last-signal times, expiration time, connection eligibility, and conditional prior consent Your device and use of the Service Maintaining a pre-registration connection candidate and checking a mutual choice 90 days from the latest signal, renewed by a new signal; deleted on a change, expiration, or valid opt-out request
Feelings and private journal Signal time, the date your feelings began, dates you confirm you want to remember, optional text, compressed photos or video, and media metadata You Private timeline, archive, subscription, and synchronization features Until you delete the entry or your account
Relationship and conversation Mutual-choice result, account IDs of both people, disclosure status, and messages and times after connection Your use of the Service and information you submit Simultaneous identity disclosure and the private space for two connected people Until the relationship ends or an account is deleted, plus any period required by law
Subscription App Store or Google Play transaction ID, product and tier, trial history, and payment, renewal, and expiration status Apple or Google Subscription access, storage allowance, and payment support While the account is maintained and for any transaction-record period required by law
Analytics and diagnostics App-instance ID, app opens, sessions and feature events, device, OS and app version, approximate region, crash logs, and related app state App; Firebase Analytics and Crashlytics Measuring Service quality, resolving errors, and improving reliability According to Firebase project settings and Google’s applicable policies
Security and technical data IP address, user agent, App Check result, request time, errors, security incidents, and rate-limit information App, device, Firebase, and Google Cloud Preventing abuse, security, and incident response General technical logs for the minimum period needed; security-incident records without phone numbers for up to one year
Support and privacy requests Request, response, verification result for a person or number owner, and handling history Requester Support, privacy-rights handling, and dispute response Three years after completion or for a period required by law
Phone-number connection opt-out Suppression target token created without retaining the number in plain text, and opt-out, withdrawal, and ownership-verification status Phone-number owner Deleting existing candidates and preventing new candidates for the same number Until withdrawal of the opt-out or confirmation that number ownership has changed

Information that remains on your device

The app does not upload your entire address book. The system contact picker lets the app process only the number of the one person you select. The contact name, birthdays or creation dates stored in your address book, and contacts you did not select are not sent to our servers. If you confirm a date and save it as part of your private journal, only that confirmed date may become account data.

The selected phone number is normalized on the device and used in a blinded tokenization process. We do not retain the original number in our database as part of the target-matching data. We do not treat the resulting target token as anonymous information; we protect it as personal information.

3. How and why we use information

We use personal information only to:

  • create accounts, sign users in, provide SMS multi-factor authentication, change phone numbers, and recover accounts;
  • let you choose one person and maintain feelings, a private timeline, and an archive;
  • maintain pre-registration connection candidates, determine mutual choice, and disclose identities simultaneously;
  • provide a relationship space and conversation after connection;
  • operate subscriptions, trials, media-storage allowances, and customer support;
  • process deletion, access, correction, restriction, consent withdrawal, and phone-number connection opt-out requests; and
  • analyze use, diagnose errors, protect the Service, prevent abuse, and comply with law.

We do not use your chosen person, private journal, or relationship data for advertising, the sale of data, cross-context or third-party behavioral advertising, or credit, employment, or insurance decisions. Before all mutual-choice conditions are met, we do not disclose whether the other person has joined, how many people sent signals, who sent them, or the exact time of a signal.

4. Legal and operational grounds

  • Republic of Korea: We process information to enter into and perform the service agreement, comply with legal obligations, act on consent where separate consent is required, and pursue legitimate interests where permitted by law.
  • United States: We process information to provide the requested Service, maintain security and prevent abuse, comply with law, act on consent, and carry out the disclosed business purposes. We do not sell personal information or share it for cross-context behavioral advertising.
  • Japan: We process information only as needed for the published purposes of use. Where consent is required for a third-party disclosure or international transfer, we rely on consent or another safeguard allowed by law.

5. Service providers and international processing

Provider Role and information Main processing location Safeguards
Google LLC / Firebase Authentication Apple, Google, and email sign-in and SMS multi-factor authentication; email, phone number, IP address, user agent, Firebase UID, and authentication status United States Google data-processing terms, encryption in transit and at rest, and access controls
Google LLC / Cloud Firestore, Cloud Run, and App Check Account and journal metadata, target tokens, relationship and security state, and API requests Firestore nam5 (U.S. multi-region); Cloud Run us-central1 Google Cloud Data Processing Addendum, least privilege, and server-only data areas
Google LLC / Cloud Storage for Firebase Compressed photos and video and object metadata Dedicated bucket in us-central1 Owner-only paths, Public Access Prevention, encryption, and upload validation
Google LLC / Firebase Analytics and Crashlytics Usage analytics and crash and error diagnostics Google’s global infrastructure Restricted project access and a development rule against placing direct identifiers in analytics events
Apple Inc. Sign in with Apple, iOS age-range signal, and App Store subscriptions Under Apple’s policies and infrastructure Apple authentication and payment procedures and receipt validation
Google LLC Google Sign-In, Android age-eligibility signals, and Google Play subscriptions Under Google’s policies and infrastructure OAuth authentication, Google Play payment, and purchase validation procedures

When you use the Service, authenticate, store an entry, or experience an error or event, information from Korea or Japan may be encrypted in transit to the United States or Google’s global infrastructure. Specific provider retention periods are governed by the applicable service terms, our project settings, and the retention principles in this Policy. If you object to international processing, essential account authentication and synchronization features may be unavailable. You may delete your account or submit a privacy request at any time.

6. Retention and deletion

  • A connection candidate remains for 90 days from the most recent signal and is renewed for 90 days by each new signal.
  • We delete relevant target tokens and connection state when you change the chosen person, a candidate expires, an account is deleted, or a valid phone-number connection opt-out is processed.
  • Ending a subscription does not delete feelings or journal entries. We delete them when you delete the entry or your account.
  • If you downgrade and exceed the new storage allowance, we do not automatically delete existing media; we restrict new uploads.
  • When account deletion is complete, we delete data from active systems. Residual disaster-recovery copies are isolated from ordinary processing and overwritten according to the provider’s backup cycle. Information that must be retained by law is separated and deleted when that period ends.

Electronic files are deleted in a manner designed to make recovery impracticable, which may include securely destroying encryption keys.

7. Your rights and rights of phone-number owners who have not joined

Depending on applicable law, you may request access or a copy, correction, deletion, restriction or suspension of processing, withdrawal of consent, and account deletion through app settings or the contact below. If law permits or requires us to deny or limit a request, we will explain the reason and any available appeal. We do not require a subscription or charge a fee for a legal privacy request, and we do not discriminate against you for exercising your rights.

A phone-number owner who has not joined may also request, free of charge:

  • legally required information about the purpose and source of a connection candidate directed to that number;
  • deletion or suspension of that candidate; and
  • an opt-out preventing future connection candidates directed to the same number.

We verify control of the number using a proportionate method such as SMS. We respond without unnecessarily revealing another user’s identity, the number of users or signals, signal times, or whether anyone has joined.

Submit requests to kenny@nawaplay.com. We generally acknowledge receipt within seven days and follow any shorter or different deadline required by law. Where the California CCPA applies, we generally respond within 45 days. For requests from Japan, we act without delay after reasonable identity verification.

8. Account deletion and subscription cancellation

Deleting an account and canceling an App Store or Google Play subscription are separate actions. Account deletion may not cancel the subscription, so you must also cancel through the subscription-management screen of the marketplace you used. Canceling only the subscription does not delete your account or journal. You can begin account deletion in either the iOS or Android app or ask for assistance by email.

9. Security measures

  • encryption in transit and at rest and least-privilege access controls;
  • verification of Firebase ID tokens and App Check;
  • default denial of client access to server-only data;
  • exclusion of target phone numbers, target tokens, and recovery secrets from logs;
  • audit records for number changes, recovery, deletion, and administrative actions;
  • separation of development and production environments and keys; and
  • incident response, legally required notices, and prevention of recurrence.

No method of transmission or storage can guarantee absolute security, but we continually apply reasonable safeguards appropriate to the nature and risk of the information.

10. Age eligibility

The Service is generally available only to people aged 17 or older. If local law or platform rules require a higher threshold, we apply that threshold or restrict registration. If we learn that information from a person under 17 has been processed, we delete or restrict the account and information and contact a guardian where appropriate.

11. Automated mutual-choice check

The mutual-choice feature applies a fixed rule to check whether both people selected each other and each completed 48 hours, signals on at least three different days, and conditional prior consent. It is not used for advertising profiles or decisions with legal or similarly significant effects involving credit, employment, or insurance.

12. United States and California notice

California residents may have rights under the CCPA to know, delete, correct, limit certain uses or disclosures of sensitive personal information, opt out of sale or sharing, and be free from discrimination for exercising a right. We have not sold personal information or shared it for cross-context behavioral advertising and do not intend to do so. We do not allow tracking across other services.

Even if we do not meet a CCPA applicability threshold, we offer the same request process where reasonably possible. See the California Attorney General’s CCPA page for general information about these rights.

13. Notice for Japan

We do not process personal information of users in Japan beyond the published purposes of use. This Policy explains the purposes for retained personal data, request procedures, a summary of security controls, and our contact details.

When we engage a provider in the United States, we use contracts and other reasonable measures intended to maintain protections equivalent to those required under Japan’s Act on the Protection of Personal Information (APPI), and we review those measures. Subject to applicable law, you may request disclosure, correction, addition or deletion, cessation of use, erasure, or cessation of third-party provision of retained personal data. More information is available from Japan’s Personal Information Protection Commission.

14. Changes to this Policy

We announce material changes in the app and on the public website before they take effect. Where required, we obtain separate consent for a new purpose, advertising use, a material extension of retention, or new international processing that affects your choices. We retain prior versions and their change dates.

15. Contact and complaints

For privacy questions or rights requests, contact kenny@nawaplay.com. You may also complain to the privacy or consumer-protection authority where you live. California residents can consult the California Department of Justice, and users in Japan can consult the Personal Information Protection Commission.

NawaplayAX PRODUCT STUDIO

AI 웹·앱 개발과 업무 자동화를 실제로 쓰이는 제품으로 만듭니다.

이메일 전화
BUSINESS INFO
상호
나와플레이
대표자
이강호
사업자등록번호
822-13-00749
통신판매업신고
제 2026-경기김포-4470 호

경기도 김포시 김포한강9로75번길 190, 7층 713호 E14(구래동, 이너매스한강)

© 2017–2026 Nawaplay. ALL RIGHTS RESERVED.
서비스블로그이용약관개인정보처리방침고객센터