Hello. This is the Privacy Policy for the Metronome app (hereinafter the "Service"). We have written it in plain, easy-to-understand language rather than difficult legal terms.
Effective date: 2026-08-19 · Version: v4
1Personal Information We Collect
The Service collects the following information depending on whether you are a member or a guest.
Apple/Google account email (optional; Apple Hide My Email supported)
Not collected
Profile
Nickname, birth year
Not collected
Access logs
Access IP, device info (OS/version), device language settings and preferred language list, in-app display language, time zone (UTC offset), app usage logs
Not collected (only members can write in the community)
Friend relationships
Nickname, friend request/acceptance/block records, friend group composition
Not collected
Report/block records
Report target/reason/time, block target/time
Not collected
Only members (13 years or older) can write in the community.
Writing posts/comments, searching for and adding friends, and the report/block features are available only to social-login members. Guests (including children) can only view public posts and cannot create content or form friend relationships.
We do not collect passwords.
The Service is accessed only via Apple ID / Google account, and passwords are managed directly by Apple/Google. We never receive or store any password.
2Purposes of Collection
Member identification and login (social OAuth ID token verification)
Device identification for guest users (managing ad-watch and payment rewards)
Providing Premium features (managing expiration via payment/ads/coupons)
Preventing misuse (blocking service abuse such as repeated circumvention of the free trial period)
Creating and posting community content (board/comments) and managing friend relationships
Providing report/block features and acting on inappropriate content/users (hiding, deletion, usage restriction)
Analyzing usage statistics to improve the Service
Fulfilling legal obligations and handling disputes
3Retention Period
Member and guest information is retained according to the following criteria.
Member: Destroyed immediately upon account deletion. You may sign up again with the same Apple/Google account.
Guest: Only the device identifier is retained. Because it uses an OS-provided identifier (Android SSAID / iOS IDFV), it may identify the same device even after reinstalling the app, and is refreshed when the device is reset.
Community content: Posts/comments are deleted when the member deletes them directly or upon account deletion. However, content under report/dispute handling may be retained until the matter is resolved.
Friend relationship data: Upon account deletion, the friend/group relationships from your own perspective are deleted.
Report/block records: Retained for a certain period after resolution to check for repeated violations and to respond to disputes, then destroyed.
Payment / consumer-dispute records under the Act on Consumer Protection in Electronic Commerce: 5 years (transaction identifiers only)
Access logs (last access time, device info, language/time zone settings): deleted when you close your account. Used solely for service operation (inactivity checks), abuse prevention, and support inquiries.
One-way hash of your social account identifier (SHA-256, cannot be reversed to the original): retained when you delete your account, and used solely to prevent sign-up free benefits from being granted twice if you sign up again with the same account. It does not restrict re-signup itself.
No permanent blocking data is retained
The past email-signup-era policy of "permanently retaining an SHA-256 hash of the email" has been abolished.
In the social-login (Apple/Google sub) model, the same user is issued the same sub, so they are naturally identified without any separate blocking identifier.
The social-account-identifier hash retained upon deletion is not for blocking re-signup — its sole purpose is to prevent duplicate granting of sign-up free benefits, and you may freely sign up again.
4Provision to Third Parties and Processing Consignment
To provide the Service, we provide/consign some information to the following companies. All companies implement safety measures to protect personal information.
Company
Purpose
Items provided
Apple Inc. (USA)
Sign in with Apple OAuth authentication
Apple sub (provider UID), email (optional)
Google LLC (USA)
Google login OAuth authentication
Google sub (provider UID), email
Google Firebase (Cloud Messaging, USA)
Sending push notifications
FCM token, device info
Google AdMob (USA)
Rewarded ad delivery + Server-Side Verification
Advertising identifier, device info, member identifier
RevenueCat (USA)
In-app purchase processing/verification
Member identifier, purchase info
Oracle Cloud Infrastructure (OCI)
Server/database hosting
All (stored encrypted)
5Your Rights
You can exercise the following rights at any time.
Access/correction: You can change information such as your nickname directly on the Settings screen in the app.
Deletion: You can delete immediately via the "Delete Account" menu on the Settings screen.
Suspension of processing: We will process your request when you contact us at the address below.
Opt out of marketing push: You can turn it off at any time via the "Push Notifications" menu on the Settings screen.
6Security Measures
All communications are HTTPS-encrypted (TLS 1.2+)
JWT-based authentication tokens, automatically revoked on expiration
Social OAuth tokens are verified on the server for every request using Apple/Google's official JWKS public keys
Ad-watch rewards are protected against tampering via Google AdMob's ECDSA-signature-based Server-Side Verification
FCM tokens are mapped per user only, with no external exposure
All authentication tokens are revoked immediately on logout/account deletion
Access to personal information is minimized (operator-level access control)
7Cookies and Advertising Identifiers
The Service does not use web cookies. The mobile app uses advertising identifiers (IDFA / AAID) for ad delivery, and you can disable these in your device settings. Metronome delivers only non-personalized ads, and ads are limited to G-rated (safe for all ages).
8Protection of Children's Personal Information (COPPA / GDPR-K)
Children under 13 cannot register as members.
Metronome complies with the U.S. COPPA (Children's Online Privacy Protection Act) and the EU GDPR-K (protection of children under 16).
At sign-up, birth year entry ensures that only those 13 or older can register.
Children under 13 may use the app anonymously as guests based on a device UUID, and we collect no personal information such as email/name/birth year.
Ads have the G-rating + tagForUnderAgeOfConsent option applied, so only child-safe ads are delivered.
Marketing push notifications are sent only to members after their consent. We do not send marketing push to guests (including children).
If we confirm that a child under 13 has registered as a member, we delete that account immediately.
9Push Notifications and Marketing Consent
The Service sends two types of push notifications.
OS permission only (no separate marketing consent needed)
Marketing push
New feature launches, event coupons, discount notices
Members only, sent after separate opt-in consent
Under Korea's Network Act, marketing push is sent only after explicit consent, and you can withdraw consent at any time on the Settings screen. Marketing push is not sent to guests (including children).
10Privacy Officer and Contact
Contact person
Ahn Byeong-uk
Email
ahnsapp@gmail.com
For privacy-related inquiries and reports, please contact us at the email above. We respond within 7 business days.
11Notice of Policy Changes
This Policy may be amended in accordance with changes in law or the Service. In the event of significant changes, we will give notice from 7 days before the effective date via in-app notice or push notification, and obtain mandatory consent via a modal at first launch.