심해 다이버 개인정보처리방침
시행일: 2026년 7월 15일
1. 처리하는 정보
앱은 최고 기록, 난이도, 게임 모드, 언어, 배경음·효과음 설정, 필수 이용 동의 상태, 검증된 사용자 표시와 계정 데이터 캐시를 기기 내부에 저장합니다. 같은 계정을 재실행 시 복원하기 위한 Supabase 세션 갱신 정보도 앱 전용 저장소에 보관합니다.
게임을 이용하려면 첫 실행에서 고지 요약과 전문 링크를 확인하고 필수 처리에 동의하고 바로 시작 CTA를 누른 뒤 Google Play Games 프로필 연결 및 최초 서버 확인을 완료해야 합니다. 별도 체크박스·거부/취소 CTA·게스트 경로는 없으며, 완료하지 않으면 게임플레이에 진입할 수 없습니다. 동의 상태는 설치 앱 데이터의 수명 동안 유지되어 고지 문구나 버전 변경, 부활, 광고 선택 또는 사망 시 다시 표시하지 않으며 앱 데이터 삭제 또는 재설치 때 초기화됩니다. Supabase auth.users.id를 앱 계정의 기준 키로 사용하며, 서버 생성 공개 별칭, 선택형 비공개 표시 이름, 모드·난이도·수심·플레이 시간·게임 결과, 크라켄 이벤트 기록, 코인과 보상 내역, 보유·장착 스킨, 일일 퀘스트 진행과 보상 청구 정보가 서버에 저장됩니다. 연결 과정에서 기술적인 임시 인증 세션이 일시 생성될 수 있으나 Play Games 확인이 취소되거나 실패하면 신규 임시 세션을 폐기합니다.
게임 이용을 위해 사용자가 Play Games 프로필을 선택하고 서버 확인을 완료해야 합니다. 이때 앱은 Play Games 서비스 권한과 함께 Google OPEN_ID와 EMAIL 권한을 요청하며 별도의 PROFILE 권한은 요청하지 않습니다. 서버가 확인한 Google OpenID 로그인 식별자(sub)와 확인된 이메일 주소는 Supabase 인증 정보로 저장되어 현재 앱 계정을 연결하고 다른 기기에서 복원하는 데 사용됩니다. 이메일은 앱 화면, 랭킹 또는 일반 Edge Function 응답에 표시하지 않습니다.
최초 연결 이후에는 기기에 저장된 Supabase 세션과 검증된 사용자 표시가 동일한 사용자·Google 연결에 속하는지 확인해 계정을 복원하므로, 앱을 실행할 때마다 Play Games 서버 인증 코드를 다시 요청하지 않습니다. 로그아웃, 서버 계정 삭제, Supabase 세션 취소·만료 또는 계정 불일치가 확인된 경우에만 Play Games 재검증이 필요합니다.
서버는 Google Play Games players/me 응답의 플레이어 ID와 게이머태그를 확인합니다. 플레이어 ID는 플랫폼 프로필 확인 과정에서만 일시 처리하고 저장하거나 앱에 반환하지 않습니다. 게이머태그도 연결 확인 과정에서만 일시 처리하고 저장하거나 공개하지 않으며 공개 별칭 생성에 사용하지 않습니다. 공개 랭킹과 기록에는 서버가 무작위 생성한 변경 불가능한 Diver_XXXXXX 별칭만 표시됩니다. 사용자가 선택적으로 입력하는 표시 이름은 본인 화면과 인증된 소유자 응답에서만 사용하고 다른 사용자나 랭킹에 표시하지 않습니다. 기존 닉네임은 별칭 전환 시 표시 이름으로 복사하지 않고 폐기합니다. 일회용 서버 인증 코드와 교환된 Google 액세스 토큰·ID 토큰은 연결 요청 처리 후 앱 기기나 운영 서버에 영구 저장하지 않습니다.
2. 이용 목적
- 게임 진행, 개인·오늘·주간·글로벌 기록 제공
- 코인 보상, 스킨 구매·장착, 일일 퀘스트 동기화
- 최초 Play Games 확인, 선택한 Google 로그인 ID와 앱 계정 연결, 재실행·재설치·새 기기에서 계정 복원
- 보상 요청 검증, 부정 사용 방지, 서비스 보안
- 선택형 보상 광고 제공과 광고 성과 측정
3. 광고와 제3자 서비스
앱은 별도의 자체 보상형 광고 동의 화면을 두지 않으며, 부활·광고 선택·사망 시 필수 개인정보 처리 동의를 다시 요청하지 않습니다. 보상형 광고는 사용자가 일반 모드 부활 또는 결과 코인 추가 버튼을 직접 선택한 경우에만 요청합니다. 법적으로 필요한 지역의 광고 선택과 변경은 필수 게임 동의와 분리된 Google User Messaging Platform(UMP)이 처리합니다. 앱은 첫 게임 화면이 표시된 뒤 UMP 동의 정보를 갱신하고 canRequestAds()가 광고 요청을 허용하기 전에는 광고를 초기화하거나 불러오지 않습니다. 이는 Google이 제공하는 지역별 광고 선택 절차이며 게임 이용에 필요한 개인정보·계정 처리 동의와 개인 맞춤 광고 동의를 하나로 강제하는 것이 아닙니다. Google Mobile Ads SDK는 광고 제공, 분석, 사기 방지와 보안을 위해 IP 주소에서 유도되는 대략적 위치, 광고 ID와 기기·계정 식별자, 광고 상호작용, 앱 정보와 진단·성능 정보를 자동 수집하고 Google 및 광고 파트너와 공유할 수 있습니다.
Google Play Games 서비스와 SDK는 Play Games 인증, 프로필 선택과 서비스 운영을 위해 게이머 ID, 사용 분석 및 진단 정보를 처리합니다. Play Games에서 게임 또는 프로필 데이터를 삭제하는 절차와 개발자가 관리하는 심해 다이버 서버 계정 삭제 절차는 서로 다릅니다.
Supabase는 인증, 온라인 기록, 코인, 스킨과 퀘스트 기능의 서비스 제공자로서 계정 및 서버 저장 정보를 처리합니다. 운영자는 광고 식별자나 광고 로그를 직접 판매하지 않으며 Play Games 데이터를 광고 목적으로 사용하지 않습니다.
Play Games 계정 연결 요청은 Vercel Functions 게이트웨이를 경유합니다. Vercel은 요청 전달, 요청 횟수 제한과 부정 사용 방지를 위해 IP 주소, Supabase Bearer 토큰과 일회용 Google 서버 인증 코드를 전송 중 일시 처리합니다. 앱 운영 서버는 인증 코드와 교환된 Google 토큰을 연결 요청 처리 후 보관하지 않습니다.
4. 권한과 보안
앱은 인터넷 연결과 네트워크 상태 확인 권한을 사용합니다. 광고 SDK는 광고 ID와 Android Privacy Sandbox 관련 권한을 포함할 수 있습니다. 위치, 연락처, 사진·동영상, 마이크와 카메라 권한은 요청하지 않습니다.
온라인 기능, Play Games, Supabase와 광고 SDK 통신은 HTTPS/TLS 등 전송 중 암호화된 연결을 사용합니다. Google OAuth 클라이언트 보안 비밀과 Supabase 서비스 역할 키는 앱에 포함하지 않고 서버 비밀로 관리합니다.
5. 보관과 삭제
앱 계정과 서버 게임 데이터는 사용자가 계정을 삭제할 때까지 게임 기능, 보안과 부정 사용 방지를 위해 보관됩니다. 앱의 설정 → 온라인 기능 → 서버 계정 삭제에서 확인하면 인증 사용자를 영구 삭제하며, 서버 측 Supabase 세션과 연결된 Google 로그인 식별자·이메일, 공개 별칭·비공개 표시 이름, 온라인 기록, 코인·원장, 보유·장착 스킨, 실행 세션, 일일 퀘스트 및 보상 청구 데이터도 외래 키 관계에 따라 함께 삭제되어 복구할 수 없습니다.
서버 계정을 삭제해도 기기 내부의 설정과 로컬 최고 기록은 남습니다. 해당 데이터는 Android 앱 데이터 삭제 또는 앱 제거로 별도 삭제할 수 있습니다.
앱에 접근할 수 없는 경우 rhtmdwh19@gmail.com으로 서버 계정 삭제를 요청할 수 있습니다. 제목에 ‘심해 다이버 계정 삭제’를 적고, 연결된 Google 이메일에서 보내거나 공개 별칭·마지막 이용 시점 등 계정을 식별할 수 있는 정보를 포함해 주세요. 운영자는 계정 소유 확인에 필요한 추가 정보를 요청할 수 있으며 비밀번호나 일회용 인증 코드는 요구하지 않습니다. 소유 확인이 끝난 요청은 합리적으로 신속히 처리하고 완료 사실 또는 예상 완료 시점을 회신합니다.
심해 다이버 서버 계정 삭제는 Google 계정, Play Games 프로필 또는 Google이 보관하는 게임 데이터를 삭제하지 않습니다. 반대로 Google Play Games에서 게임 데이터를 삭제해도 Supabase의 심해 다이버 서버 계정은 삭제되지 않으므로 각각의 삭제 절차를 이용해야 합니다.
광고 ID는 Android 설정에서 재설정하거나 삭제할 수 있으며 광고 관련 데이터의 보관은 Google과 광고 파트너의 정책을 따릅니다.
6. 아동의 개인정보
앱은 아동을 대상으로 개인정보를 직접 수집하도록 설계되지 않았습니다. 만 14세 미만 사용자는 보호자의 동의 아래 앱을 이용해야 합니다.
7. 문의와 변경
개인정보·지원 문의는 rhtmdwh19@gmail.com으로 보내 주세요. 방침이 변경되면 앱 또는 공개 배포 페이지를 통해 고지합니다.
Abyss Diver Privacy Policy
Effective date: July 15, 2026
1. Information we process
The app stores high scores, difficulty, game mode, language, music and sound settings, required game-consent state, a verified-user marker, and account-data caches on the device. Supabase session-refresh data used to restore the same account after relaunch is also retained in app-private storage.
On first launch, gameplay requires the single explicit Agree to required processing and start CTA after a notice summary and full-policy link, followed by Google Play Games profile connection and initial backend verification. There is no checkbox, decline/cancel CTA, or guest path; not completing acceptance and verification keeps gameplay unavailable. Acceptance remains valid for the lifetime of installed app data across notice-copy/version changes and is reset only when app data is cleared or the app is reinstalled. The app does not show its own consent screen again at revive, ad selection, or death. Supabase auth.users.id is the canonical app-account key. A server-generated public alias, optional private display name, mode, difficulty, depth, play time, run results, Kraken event records, coin and reward history, owned and equipped skins, daily quest progress, and reward claims are stored on the server. A technical provisional authentication session may be created transiently during linking; a newly created provisional session is discarded if Play Games verification is cancelled or fails.
To use the game, the user must select a Play Games profile and complete server verification. Alongside Play Games service authorization, the app requests Google OPEN_ID and EMAIL and does not request a separate PROFILE scope. The server-verified Google OpenID login identifier (sub) and verified email address are stored as Supabase authentication information to link the current app account and restore it on another device. The email is not displayed in the app UI, rankings, or ordinary Edge Function responses.
After the initial link, the app restores the account by confirming that the saved Supabase session and verified-user marker belong to the same user and Google link, so it does not request a new Play Games server authorization code on every launch. Play Games verification is requested again only after logout, server-account deletion, Supabase session revocation or expiry, or a confirmed account mismatch.
The server verifies the player ID and gamer tag returned by Google Play Games players/me. The player ID is processed transiently only to verify the platform profile and is not stored or returned to the app. The gamer tag is also processed only during linking and is neither stored nor published or used to construct the public alias. Public rankings and records show only a random, immutable server-generated Diver_XXXXXX alias. An optional user-entered display name is used only in the owner's UI and authenticated owner responses and is never shown to another player or in rankings. Existing nicknames are discarded during alias migration rather than copied into display names. The one-time server authorization code and exchanged Google access and ID tokens are not persistently retained on the app device or by the operator's backend after the linking request.
2. How information is used
- Provide game progress and personal, daily, weekly, and global records
- Synchronize coin rewards, skin purchases and equipment, and daily quests
- Complete initial Play Games verification, link the selected Google login identity to the app account, and restore it after relaunching, reinstalling, or moving to a new device
- Validate reward requests, prevent abuse, and protect the service
- Provide optional rewarded ads and measure advertising performance
3. Advertising and third-party services
The app has no separate first-party rewarded-ad consent screen and does not repeat required privacy consent at revive, ad selection, or death. A rewarded ad is requested only after the user explicitly chooses a General Mode revive or result-coin bonus. Where legally required, Google User Messaging Platform (UMP) separately presents and manages regional advertising choices after the first gameplay frame. The app does not initialize or load an ad until canRequestAds() permits ad requests. This is Google's regional advertising-choice process; the app does not bundle consent to personalized advertising into the required privacy and account-processing consent. Google Mobile Ads may automatically collect and share IP-derived approximate location, advertising and device or account identifiers, ad interactions, app information, diagnostics, and performance data with Google and advertising partners for ad delivery, analytics, fraud prevention, and security.
Google Play Games services and the SDK process gamer identity, usage analytics, and diagnostics to provide Play Games authentication, profile selection, and service operations. Deleting a game or profile from Play Games is separate from deleting the Abyss Diver server account managed by the developer.
Supabase processes authentication and server-stored account, record, coin, skin, and quest information as a service provider. The operator does not directly sell advertising identifiers or ad logs and does not use Play Games data for advertising.
Play Games account-linking requests pass through a Vercel Functions gateway. Vercel transiently processes the IP address, Supabase bearer token, and one-time Google server authorization code in transit to forward requests, enforce request limits, and prevent abuse. The app backend does not retain the authorization code or exchanged Google tokens after processing the linking request.
4. Permissions and security
The app uses internet and network-state permissions. The advertising SDK may include advertising ID and Android Privacy Sandbox permissions. The app does not request access to location, contacts, photos, videos, microphone, or camera.
Online, Play Games, Supabase, and advertising SDK communications use encrypted connections such as HTTPS/TLS. The Google OAuth client secret and Supabase service-role key are kept as server secrets and are not bundled in the app.
5. Retention and deletion
The app account and server game data are retained for game features, security, and abuse prevention until the user deletes the account. After confirmation under Settings → Online Features → Delete Server Account, the app permanently deletes the authentication user. Server-side Supabase sessions, the linked Google login identifier and email, public alias, private display name, online records, coin wallet and ledger, owned and equipped skins, run sessions, daily quests, and reward claims are deleted through their foreign-key relationships and cannot be recovered.
Device settings and local high scores remain after server-account deletion. They can be removed separately by clearing Android app data or uninstalling the app.
If the app is unavailable, request server-account deletion at rhtmdwh19@gmail.com. Put “Abyss Diver account deletion” in the subject and either send from the linked Google email or include account-identifying details such as the public alias and approximate last-use date. The operator may request additional information needed to verify ownership and will never ask for a password or one-time authorization code. A verified request is processed within a reasonably prompt period, followed by confirmation or an expected completion date.
Deleting the Abyss Diver server account does not delete the Google Account, Play Games profile, or game data held by Google. Conversely, deleting game data in Google Play Games does not delete the Abyss Diver server account stored in Supabase; each deletion process must be completed separately.
The Android advertising ID can be reset or deleted in device settings. Advertising data retention follows the policies of Google and its advertising partners.
6. Children's privacy
The app is not designed to collect personal information directly from children. Users under 14 should use the app with consent from a parent or guardian.
7. Contact and changes
Send privacy and support inquiries to rhtmdwh19@gmail.com. Material changes will be announced in the app or on the public distribution page.