Jellybara · AMINI STUDIO

Privacy Policy

Jellybara is a companion-character game that does not require login. Automatically generated player identifiers are also protected as personal information. We distinguish records stored on your device from information processed on servers.

Effective date 2026-09-30

1. Scope and contact

This policy applies to the Jellybara app and official website, jellybara.com. The data controller is AMINI STUDIO. Privacy matters and rights requests are handled by AMINI STUDIO's privacy contact (representative: Kim Do-min). Operator: 에이미니 스튜디오 (AMINI STUDIO) Representative: 김도민 (Kim Do-min) Business registration number: 385-22-02328 Address: Room 505-S288, 30 Nonhyeon-ro 10-gil, Gangnam-gu, Seoul 06314, Republic of Korea Phone: 010-7295-0752 Mail-order business registration: 2026-Seoul Seocho-2227 (issuing authority: Seocho-gu Office, Seoul) Privacy inquiries, access, correction, and suspension of processing: [email protected] Data deletion requests: [email protected] Service, payment, and general inquiries: [email protected] The policies of stores, linked external services, and payment platforms also apply to information they independently process.

2. Current features and processing grounds

The app uses on-device storage and Unity Gaming Services (UGS) guest authentication, nicknames and Remote Config. You may optionally link Apple or Google, or sign in to an existing linked account. Provider identifiers and authentication results are used for linking and recovery; we do not collect Apple or Google passwords. Google Cloud Run and Supabase are used for online game verification and currency records. Items relating to Unity IAP payments, Firebase Analytics / GA4, and online rankings apply when those features are actually provided and used. Naming a service in this document does not itself initiate collection. Analytics will be enabled only after separate optional consent and a withdrawal mechanism are provided. Information needed to provide the service is processed to perform the user agreement; optional behavioral analytics is based on consent; legally required retention is based on applicable statutory obligations.

3. Device storage and game operations

Your device stores an automatic player ID, nickname, settings such as sound and haptics, bonding progress, and discovery records. Bonding progress and discovery records are not currently backed up to the cloud. When online, UGS processes anonymous Player IDs and authentication information and stores your chosen nickname. Remote Config requests use information such as IP addresses, per-installation identifiers, and Player IDs. Basic device and app information and approximate IP-based region information may be used to deliver settings. Purposes include distinguishing players, retaining nicknames, providing announcements and compatible-version settings, and operating the service. Precise GPS location is not requested. Online minigame inputs, mode, score, duration and server-issued run identifiers are verified on Cloud Run. Supabase stores player mappings, run and settlement results, currency balances and changes. Full input payloads are used for verification but are not stored in the database. Inventory, progress, purchase and analytics structures only receive data from features actually connected. Rankings are not currently provided.

4. Payments and purchase entitlements

When paid content is offered, Unity IAP connects to Apple App Store or Google Play payments. To verify purchases, deliver and restore content, reflect refunds, and prevent duplicate delivery, we may process product IDs, transaction identifiers, receipts or purchase tokens, purchase and refund status, and the player's purchase entitlements. Server verification and entitlement management are linked to UGS player identifiers and Cloud Run/Supabase game records. Jellybara does not directly collect or retain full payment-method details such as card numbers or bank account information. Payment platforms handle these under their policies. If you do not make a purchase, purchase-verification information is not generated. Payments are not currently enabled in the app.

5. Optional behavioral analytics

Firebase Analytics / GA4 is used for behavioral analytics. In versions introducing analytics, only with consent, it processes app and web visits, sessions, screen and feature use, minigame starts and endings, product-screen use, and similar events; app-instance or web-analytics identifiers; app, browser, and operating-system versions; device type; language; and approximate region. The purpose is to understand and improve usage flows, return visits, and usability. Analytics events do not include nicknames, email addresses, inquiry contents, raw purchase receipts, or full UGS Player IDs. Ad personalization, Google Signals, advertising-account linking, and advertising-identifier collection are outside this analytics policy's scope. You may refuse or withdraw consent on the screen providing analytics. Refusal does not prevent basic play. Withdrawal stops subsequent collection; deletion of existing server data may be requested separately. Firebase Analytics / GA4 is not currently connected to the app or website, and no analytics events are sent.

6. Website, cookies, and inquiries

The public website uses Next.js, 3D character presentation and Markdown articles. Visiting it alone does not transmit app Player IDs or progress. Public visitor registration, comments and post uploads are not offered. Supabase use by the game server is separate from public website visits. If web analytics is introduced, cookies or similar storage for analytics identifiers will be used only after optional consent, with refusal and withdrawal available on the consent screen. Cookies can also be blocked or deleted in browser settings. Analytics cookies are not currently installed. If you contact us by email, your sender address, display name, message, and attachments you provide are used to receive and answer the inquiry and resolve issues. Do not send passwords, authentication tokens, identity documents, or full card numbers.

7. Retention and deletion

On-device records: retained until app data is deleted. Some copies may remain or be restored through operating-system app archiving, backup, or restoration features. Game accounts and server records: UGS Player IDs, linked sign-ins and nicknames, and actual server-side gameplay, currency, inventory and progress records are retained while providing the account service, then deleted without undue delay following a verified request or when their purpose ends. Uninstalling does not send a server-deletion request. Remote Config states that it does not retain personal information used to process requests. If optional analytics is introduced: GA4 user- and event-level retention will be set to two months, without resetting user-data retention on new activity. This differs from aggregated statistics not subject to the setting and Google's separate processing or backup-deletion schedules. No analytics data is currently stored. General inquiries: deleted within one year after resolution. A minimal record of completed deletion requests is retained for one year solely as evidence that the request was fulfilled. For transactions subject to statutory retention, only the necessary records are kept separately. Under the Republic of Korea's Electronic Commerce Act, where applicable, contract and withdrawal records and payment and supply records are retained for five years, consumer complaint and dispute records for three years, and labeling and advertising records for six months. They are deleted when the legal period ends. Electronic files are deleted in a manner that makes recovery difficult; paper records, if any, are shredded.

8. Processors, external services, and overseas processing

UGS operations are entrusted to service entities in the Unity Technologies group. Unity's privacy contact is [email protected]. Online authentication and settings requests transmit IDs, nicknames, and request information over encrypted connections. Purposes and retention periods are described in the game-operations and retention sections above. Unity's published subprocessing locations for the relevant services include the United States, Australia, Belgium, Brazil, Germany, Singapore, and Taiwan. This does not mean all data is stored in all of these countries. If Firebase Analytics / GA4 is introduced, Google LLC and other Google service entities process consented analytics information. It may be transferred over the internet to Google's processing facilities in the United States and elsewhere. Before collection begins, the consent screen will identify recipients, processing countries, data categories, retention periods, and how to refuse. Google's contact channels are available in its privacy policy linked below. Overseas outsourcing and storage for essential services rely on performance of the user agreement and notice requirements where permitted by applicable law. Transfers requiring separate consent will occur only after obtaining it. Refusing analytics prevents transmission of analytics information. To object to or stop essential online processing, contact [email protected]; this may restrict online profiles, rankings, purchase verification, or related services. We do not sell information or disclose it for a third party's independent purposes without processing under this policy, separate user consent, or a legal basis. Before introducing a new data-processing service, we will disclose the actual data, processors, and overseas transfers and obtain necessary consent. The game verification server uses Google Cloud Run and the database uses Supabase Pte. Ltd.; both deployments are configured in Seoul, Republic of Korea. Encrypted requests carry authenticated player identifiers and the game records described above. Provider support and subprocessing may occur elsewhere; Seoul deployment does not mean every ancillary operation is domestic. Purposes and retention follow the sections above.

9. Access, correction, deletion, and choices

Users or lawful representatives may request access, correction, suspension or withdrawal at [email protected]. Deletion instructions are available at https://jellybara.com/delete-account and requests may be sent to [email protected] without reinstalling or signing in. You must send the email to submit a request. Email is not automatic instant deletion; we reply with the processing timeline and completion after verifying ownership. We do not disadvantage users for privacy requests. Include your Player ID from Account management if known; you can still request deletion without it. A public nickname or ID alone does not prove ownership. We may ask for minimal additional verification, never passwords or authentication secrets. Requests are handled within the periods required by applicable law, with a reply explaining the outcome, reasons for any limitation, and additional procedures. For legally retained records, we explain the basis and remaining period and do not use them for other purposes. Our team cannot remotely access or delete local device records; app data must be deleted on the device.

10. Children, young people, and security

Jellybara is intended for users aged 14 and older and is not intended for use by, or collection of personal information from, children under 14. We do not knowingly collect personal information from children requiring legal-representative consent without verifying consent under applicable law. If we learn that a child's information was processed without required consent, we stop the relevant processing and take necessary verification and deletion measures. Guardians may contact [email protected] or [email protected]. Processing permissions are limited to what is needed for work. Reasonable safeguards include encryption in transit and access management. Users are also encouraged to lock shared devices and avoid personal information in nicknames.

11. Policy changes and remedies

If this policy changes, the effective date and changes will be announced in the app or on the website. Changes affecting user choices, including purposes, data categories, or recipients, will be announced before application, with renewed consent where legally required. This policy is not blanket consent to personal-information collection. Privacy matters not resolved by our response may be referred to the privacy supervisory or dispute-resolution authority with jurisdiction where you live. Users in the Republic of Korea may contact the Personal Information Infringement Report Center (privacy.kisa.or.kr) or the Personal Information Dispute Mediation Committee (kopico.go.kr).