한국어 English

Kokorang

Privacy Policy

Effective Date: June 21, 2026 · Version 1.0

Anarchy Inc. ("we", "us", or the "Company"), the operator of the Kokorang Service, respects your privacy and complies with applicable data protection laws, including the Republic of Korea's Personal Information Protection Act (PIPA). This Policy explains how the Kokorang mobile and web application (the "Service") collects, uses, stores, and deletes personal information, and the rights available to you.

1. Information We Collect

CategoryDataWhen Collected
RequiredEmail, password (encrypted), nicknameAt sign-up
OptionalProfile image, language preference, marketing opt-inDuring sign-up or settings
Social LoginEmail, identifier (uid), display name (as provided by the social platform)When logging in via Google / Apple / Facebook / X
Service UsageLearning progress, match history, stars/marbles ledger, daily attendanceAutomatically while you use the Service
DeviceOS and app version, FCM push token, sign-in IP (security)On launch and push registration
Under 14Guardian's email and consent recordWhen a user under 14 signs up

2. Purposes of Use

3. Retention and Deletion

4. Third Parties and Processors

We do not sell or share your personal information with third parties for their own purposes without your consent. We use the following service providers to operate the Service:

ProcessorPurposeRegion
Google LLC (Firebase Authentication, Firestore, Hosting, Cloud Functions, Cloud Storage, FCM)Authentication, database, push delivery, static hostingUSA / Global
Google LLC (Cloud Run)Real-time match serverasia-northeast3
Apple Inc.Sign in with AppleUSA
Meta Platforms (Facebook Login)Facebook sign-in (optional)USA
X Corp.X (Twitter) sign-in (optional)USA

All processors are bound by their respective data protection agreements and may only process data within the scope necessary to provide the Service.

5. Children Under 14

Users under the age of 14 must obtain consent from a legal guardian to sign up. During sign-up we collect the guardian's email and send a magic-link consent request. The account remains inactive until the guardian confirms consent. A guardian may withdraw consent at any time, which will result in account deletion in the same manner as a user-initiated deletion.

6. Your Rights

7. Security Measures

8. Automated Collection

We do not use third-party advertising SDKs and do not display advertisements. Operational tools such as Firebase Crashlytics may collect anonymized diagnostic data for reliability and incident response.

9. Privacy Officer

10. Changes to This Policy

We will notify users of material changes at least 7 days before the effective date through in-app notice or this page. For significant changes, we will provide notice at least 30 days in advance.