FilmDevMate

Privacy Policy — FilmDevMate

Effective Date 2026-08-05
Last Updated 2026-09-18

OBJECTYE ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use FilmDevMate (the "Service"), and addresses the requirements of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) for users in those regions.

1. Controller and Contact

OperatorOBJECTYE (individually registered business, South Korea, registration no. 160-67-00737)
Contactdevelop@yeji-hong.com

FilmDevMate is built and operated by a single independent developer. We do not publish a physical business address; all inquiries are handled by email.

Data Protection Officer (DPO): Not appointed. Given the limited scale and nature of our processing (no large-scale monitoring or special category data), a DPO is not required under GDPR Art. 37.

EU Representative (Art. 27): Not appointed. We rely on the derogation in Art. 27(2)(a) — our processing is occasional, does not involve large-scale processing of special categories of data, and is unlikely to result in a risk to individuals' rights and freedoms. EU/EEA users can contact us directly at the email above.

2. Personal Data We Collect

CategoryItemsSource
Account dataEmail address, display name, sign-in provider identifier (Google, Apple, or email/password)Directly from you
Usage dataApp interaction logs, saved recipes and development records you createAutomatic / directly from you
Analytics & diagnosticsFirebase Analytics usage events, Firebase Crashlytics crash reports, Firebase installation identifierAutomatic, via Firebase SDK
Device & advertising dataIP address, device model/OS, advertising identifier (GAID/IDFA)Automatic, via AdMob SDK
Photos (optional)A photo of your developed film negative, submitted through the in-app "Exposure Feedback" feature, together with your ISO setting and exposure verdict (under/correct/over)Directly from you, only if you tap the capture button

Camera access is requested only when you use the optional "Exposure Feedback" feature; the camera is never activated and no photo is collected unless you tap the capture button yourself. We do not request location permissions and do not collect real-world location data. The in-app "development map" ranking feature uses a virtual coordinate system unrelated to your actual location.

Special category data (Art. 9 GDPR) / Sensitive Personal Information (CPRA): None. We do not collect health, biometric, racial/ethnic, religious, or similar data.

3. Purposes and Legal Bases (Art. 6 GDPR)

PurposeLegal basis
Account creation, authentication, providing the ServiceContract (Art. 6(1)(b))
Fraud prevention, service securityLegitimate interests (Art. 6(1)(f))
Service analytics and stability improvementsLegitimate interests (Art. 6(1)(f))
Displaying personalized banner adsConsent, collected via the Google User Messaging Platform (UMP) consent flow / iOS App Tracking Transparency prompt
Improving exposure-judgment accuracy using submitted photos (AI model training)Consent (Art. 6(1)(a)) — applies only if you submit a photo

Development timer alerts are local notifications generated on your device. We do not operate a push notification server and do not collect push notification tokens. We do not currently send marketing emails or push notifications. If this changes, we will request separate opt-in consent before doing so.

4. Recipients and Data Sharing

We do not sell your personal data. We share data with the following service providers acting as processors on our behalf:

ProviderPurposeLocation
Supabase, Inc.Authentication and database hosting (recipes, development records)Singapore (server region)
Google LLC (Firebase Authentication)Social sign-in authenticationUnited States
Google LLC (Firebase Analytics, Crashlytics, Remote Config)Usage analytics, crash reporting, remote feature configurationUnited States
Google LLC (AdMob / User Messaging Platform)Banner ad serving, ad consent managementUnited States
Apple Inc.Sign in with Apple (iOS)United States

Photos submitted through the Exposure Feedback feature are stored on our own self-hosted server infrastructure in South Korea, not with any third-party processor listed above, and are used solely to train our exposure-judgment model.

5. International Transfers (Chapter V GDPR)

Your data is transferred outside the EEA/UK to Singapore (Supabase) and the United States (Google, Apple) as listed above. These providers rely on their own standard contractual safeguards (e.g., Google and Apple both publish Standard Contractual Clauses for their processor relationships). Copies of applicable transfer safeguards are available on request at develop@yeji-hong.com.

Exposure Feedback photos are stored on our own server in the Republic of Korea. Korea is covered by a European Commission adequacy decision (Commission Implementing Decision (EU) 2022/254 of 17 December 2021), and the UK has adopted equivalent adequacy regulations for Korea, so no additional transfer safeguard is required for that data.

6. Retention

Account and usage dataUntil account deletion; deleted promptly on request
Withdrawn-account identifiers (email, display name, sign-up date, withdrawal date)5 years after account deletion, then purged automatically — kept to prevent abuse such as repeated delete-and-re-register (legitimate interests, Art. 6(1)(f))
Support correspondence3 years after resolution
Exposure Feedback photos and verdict dataUntil the model-training purpose is fulfilled, or until you request deletion

7. Your Rights Under GDPR

To exercise any right, contact us at develop@yeji-hong.com. We respond within one month. You also have the right to lodge a complaint with your local supervisory authority (list: edpb.europa.eu).

8. California / US State Privacy Rights (CCPA/CPRA)

OBJECTYE is a single-developer indie project. Based on our size and revenue, we do not believe we meet the CCPA/CPRA statutory threshold to be a "business" (California Civil Code §1798.140(d)) — we do not have $25.625M+ in annual gross revenue, do not process 100,000+ California consumers' data annually, and do not derive revenue primarily from selling or sharing personal information. We nonetheless voluntarily extend the rights below to California and other US residents as a matter of transparency and good practice.

Categories of personal information collected (CCPA §1798.140(v)): Identifiers (email, sign-in ID), internet/device activity (usage logs, advertising identifiers), and user-generated content (recipes, development records) — see Section 2 above.

Sale or sharing: We do not sell personal information for monetary consideration. Personalized advertising through Google AdMob may constitute "sharing" for cross-context behavioral advertising under CPRA §1798.140(ah). We honor the Global Privacy Control (GPC) browser/OS signal and the iOS App Tracking Transparency opt-out as an opt-out of this sharing.

Your rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of Sale/Sharing, Right to Non-Discrimination, Right to Data Portability. Exercise any of these by emailing develop@yeji-hong.com. We aim to respond within 45 calendar days.

Sensitive Personal Information: We do not collect Sensitive Personal Information as defined in CPRA §1798.140(ae).

Minors: The Service is not directed to children under 16, and we do not knowingly collect personal information from them.

Residents of Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws may exercise comparable rights using the same contact method.

9. Advertising Identifiers and Personalized Ads

We use Google AdMob for banner ads. Consent for personalized advertising is collected via the Google User Messaging Platform (UMP) consent flow (all regions) and, on iOS, the App Tracking Transparency (ATT) prompt for IDFA access. Declining consent/tracking still allows the Service to show ads — they will simply be non-personalized.

To reset or limit your advertising identifier directly:

10. Security

We use Supabase Row Level Security (RLS) to scope database access per user, encrypt data in transit (TLS), and limit the number of people with access to personal data (a single-developer operation).

11. Children

The Service is not intended for children under 16 and we do not knowingly collect personal data from them. Apple App Store age ratings for the Service are 15+ in South Korea and 16+ in several other territories, which further limits access by younger users at the store level.

12. Changes to This Notice

We may update this Notice as the Service or applicable law changes. Material changes will be posted on this page at least 7 days before taking effect.

This Privacy Policy takes effect on 2026-08-05.