CHALLY PORTER policies

Privacy Policy

CHALLY PORTER (the “Service”) complies with the Personal Information Protection Act of the Republic of Korea and related laws, and processes only the personal information it needs.

Effective September 18, 2026 Operator: CHALLY PORTER (developer: hyodong Lee, individual developer)

This English version is provided for convenience. If it differs from the Korean version, the Korean version prevails.

1. Information we process

Category Items When and how
Account (required) The sign-in identifier from Apple, Google, or Kakao; your email address where the provider supplies one (including the private relay address Apple creates if you choose “Hide My Email”); and your name and profile image URL where the provider supplies them Received from your sign-in provider (Apple, Google, or Kakao) when you sign in. Kakao does not supply an email address, and an account can exist without one.
Profile Nickname (required); profile photo and bio (optional) Entered by you. If you sign up with a social account, the profile image URL your provider supplies may be saved as your initial profile photo.
Your content Verification photos and videos with captions, comments, likes, challenges you create, and participation and progress records (verification count, streak, completion rate, rank) Created or uploaded by you while using the Service
Safety Reports (target, reason, details) and your block list When you report or block
Device, settings, and notifications Push notification token, notification settings, app language (Korean or English), and the IANA time zone recorded per challenge so days are counted correctly When you allow notifications, change settings, join a challenge, or use the app
Generated automatically Service logs (such as access times and errors) Recorded automatically by our infrastructure providers
Some information comes from a third party, not from you The account details above do not come from you directly. We receive them from the sign-in provider you choose: Apple Inc., Google LLC, or Kakao Corp. The source is that provider, the purposes are the ones listed in section 2, and you can ask us to stop processing this information at any time. (This disclosure is made under Article 20 of Korea's Personal Information Protection Act.) With Kakao, sharing your nickname and profile image is optional — you can decline and still use the Service.
What we don't collect We do not collect location information, track you for advertising, or sell personal information. We do not ask for government ID numbers, sensitive information, or payment details.

Please avoid including other people's faces or personal information in your verification photos and videos. Verifications in public challenges may be visible to other users.

2. Why we process it

  • Account management: sign-in, identifying your account, and account deletion
  • Providing the Service: discovering, joining, and creating challenges; posting verifications; calculating progress and rankings; feed, likes, and comments; creating and sharing result cards; showing the app in your chosen language and counting days in your time zone
  • Notifications: rank changes, challenge endings, likes and comments, and daily reminders
  • Safety and moderation: reviewing reports, acting on content that violates our Terms, preventing abuse, and providing blocking
  • Support: reviewing and answering your inquiries
  • Legal compliance: meeting legal obligations and handling disputes

4. How long we keep it

We keep your personal information until you delete your account, and delete it without delay when you do. You can delete your account in the app under MY → Settings → Delete account.

The following exceptions apply:

  • Where retention is required by applicable law: for the period the law requires
  • Reports: up to 1 year from submission, to prevent abuse and handle disputes, then deleted

5. How we delete it

When the retention period ends or the purpose is fulfilled, we delete the information without delay. Deleting your account removes your profile, verification records, comments, likes, notifications and push token from the database along with it.

Uploaded photo and video files work slightly differently. A scheduled cleanup runs every day at 04:10 Korea Standard Time and removes stored files that are more than a day old, so files are deleted from storage within about 24 hours (at most roughly 28 hours) after you delete the content or your account. They stop appearing in the app and on the web immediately.

Electronic records are deleted so they cannot be restored, and information remaining in system backups is deleted when the backup retention cycle ends.

6. Sharing with third parties

We do not provide or sell your personal information to third parties, except with your prior consent or where specifically required by law.

Content you post (nickname, profile, verifications, comments, rank) is visible to other users within the visibility you or the challenge creator chose. Result card links or images you share are visible to whoever receives them.

7. Processors and international transfers

We entrust the following companies with processing to operate the Service. In the process, personal information may be transferred abroad or stored on systems managed by companies outside Korea.

Processor (country) Task Items transferred When and how Retention Privacy contact
Supabase Inc.
(US company; servers in Seoul, Republic of Korea, AWS ap-northeast-2)
Database, authentication, file (photo/video) storage All Service data described in section 1 Transmitted over the network whenever you use the Service Until account deletion or end of contract supabase.com/privacy
Expo (650 Industries, Inc.)
(USA)
Push notification delivery Push token and notification content Transmitted over the network each time a notification is sent Until account deletion or end of contract expo.dev/privacy
Apple Inc.
(USA)
Sign in with Apple; notification delivery via Apple Push Notification service (APNs) Sign-in identifier, push token, notification content Transmitted over the network when you sign in or a notification is sent Until account deletion or end of contract apple.com/legal/privacy/contact
Google LLC
(USA)
Google sign-in (account authentication) Sign-in identifier, email address, and name and profile image URL where supplied Transmitted over the network when you sign in Until account deletion or end of contract policies.google.com/privacy
Kakao Corp.
(Republic of Korea)
Kakao sign-in (account authentication) Sign-in identifier, and nickname and profile image URL if you agreed to share them Transmitted over the network when you sign in Until account deletion or end of contract kakao.com/policy/privacy

Kakao Corp. is a Korean company, so Kakao sign-in does not involve a transfer outside Korea.

Refusing international transfers

You can stop notification-related transfers by turning off notifications in your device settings or in the app (you will no longer receive notifications). Database storage and sign-in are essential to the Service; to refuse them, please delete your account, after which you won't be able to use the Service.

Basis for transfers from the EEA and the UK

Service data is stored in the Seoul region of the Republic of Korea. Korea is covered by an adequacy decision of the European Commission, so transfers from the EEA and the UK to Korea rely on that decision. Transfers to our processors located in the United States (Expo, Apple, Google, and Supabase Inc.) rely on the European Commission's Standard Contractual Clauses, and each processor is contractually limited to processing the data for the purpose we entrusted to it.

8. Tracking and advertising

The Service does not use advertising SDKs or tracking technologies for advertising, and does not show personalized ads. We have not built in an analytics SDK to measure how you use the app either. The app stores on your device only what it needs to keep you signed in. This website does not use cookies or visitor analytics.

9. Your rights

You may exercise the following rights at any time:

  • Access: find out what personal information we hold about you and get a copy.
  • Rectification: have inaccurate or out-of-date information corrected.
  • Erasure: ask us to delete your personal information.
  • Restriction: ask us to limit how we process your information.
  • Portability: receive the information you gave us in a structured, machine-readable format, or have it sent to another provider where technically feasible.
  • Objection: object, on grounds relating to your particular situation, to processing we base on our legitimate interests.
  • Withdrawing consent: withdraw consent at any time where we rely on it, such as for push notifications.
  • Complaint to a supervisory authority: lodge a complaint with Korea's Personal Information Protection Commission or, if you are in the EEA or the UK, with the supervisory authority where you live, where you work, or where the issue occurred (see section 14).

You can edit your profile, delete your verifications and comments, change notification settings, and delete your account directly in the app. For anything else, email tunttuntlab2026@gmail.com and we will act without delay after verifying your identity. You may also exercise these rights through a legal representative or an authorized agent, who will need to provide proof of authorization. We will never treat you differently for exercising these rights.

Requests may be limited where the law requires retention or where fulfilling them could infringe on others' rights. In that case we will explain why.

10. California residents

This section applies if the California Consumer Privacy Act (as amended by the CPRA) covers you. In the past 12 months we have collected these categories of personal information:

  • Identifiers: the account identifier from your sign-in provider, email address, and nickname — collected from your sign-in provider and from you.
  • Audio and visual information: verification photos and videos, and your profile photo — collected from you.
  • Internet or network activity: service logs such as access times and errors — recorded automatically by our infrastructure providers.
  • Other information you write: your bio, comments, report details, and your notification, language, and time zone settings.

We collect these for the purposes in section 2 and keep them for the periods in section 4. We do not collect sensitive personal information, precise geolocation, or financial information.

California residents have the right to:

  • Know: what categories of personal information we collect, where they come from, why we collect them, who we disclose them to, and what specific information we hold.
  • Delete: request deletion of the personal information we hold about you.
  • Correct: request correction of inaccurate personal information.
  • Opt out: direct us not to sell your personal information or share it for cross-context behavioral advertising.
  • Non-discrimination: we will not deny you service, charge you differently, or give you a lower quality of service because you exercised any of these rights.
We do not sell your information We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have never sold or shared the personal information of users under 16. There is therefore no separate opt-out process to go through.

You can exercise these rights in the app (editing your profile, deleting your account) or by emailing tunttuntlab2026@gmail.com. We verify who is making the request before acting on it, and you may use an authorized agent.

11. Age requirements

In Korea, the Service is intended for users aged 14 and over, and children under 14 may not sign up. If we learn that we have collected personal information from a child under 14, we will delete the account and its information without delay.

Children under 13 may not use the Service anywhere, and we do not knowingly collect personal information from them (US Children's Online Privacy Protection Act, COPPA). If we learn that we have information from a child under 13, we delete it immediately. Parents or guardians who believe their child's information has been collected can reach us at tunttuntlab2026@gmail.com.

In the EEA, each country sets its own digital age of consent for information society services, between 13 and 16. If you are below the age set by the country you live in, you may not use the Service.

12. Security measures

  • Encryption in transit: all communication between the app and our servers uses TLS (HTTPS).
  • Access control: database row-level security limits each user to the data they are allowed to access.
  • Least privilege: administrative access and secret keys are used only where necessary and are never included in the app.
  • Upload checks: photo and video files are checked for type and size before they are stored.

13. Privacy officer

For questions, complaints, or remedies regarding personal information, please contact:

Privacy officer Name: hyodong Lee (CHALLY PORTER developer)
Email: tunttuntlab2026@gmail.com

14. Remedies

You can also contact the following Korean authorities for reports or counseling:

  • Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
  • Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
  • Supreme Prosecutors' Office: 1301
  • Korean National Police Agency: 182

If you are in the EEA or the UK, you may also lodge a complaint with the data protection supervisory authority where you live, where you work, or where the issue occurred.

15. Changes to this policy

If we add, remove, or change anything in this policy, we will announce it in the app or on this website at least 7 days before it takes effect, or at least 30 days before for changes that materially affect your rights.

Effective date: September 18, 2026