Privacy Policy — FilmDevMate
OBJECTYE ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use FilmDevMate (the "Service"), and addresses the requirements of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) for users in those regions.
1. Controller and Contact
| Operator | OBJECTYE (individually registered business, South Korea, registration no. 160-67-00737) |
|---|---|
| Contact | develop@yeji-hong.com |
FilmDevMate is built and operated by a single independent developer. We do not publish a physical business address; all inquiries are handled by email.
Data Protection Officer (DPO): Not appointed. Given the limited scale and nature of our processing (no large-scale monitoring or special category data), a DPO is not required under GDPR Art. 37.
EU Representative (Art. 27): Not appointed. We rely on the derogation in Art. 27(2)(a) — our processing is occasional, does not involve large-scale processing of special categories of data, and is unlikely to result in a risk to individuals' rights and freedoms. EU/EEA users can contact us directly at the email above.
2. Personal Data We Collect
| Category | Items | Source |
|---|---|---|
| Account data | Email address, display name, sign-in provider identifier (Google, Apple, or email/password) | Directly from you |
| Usage data | App interaction logs, saved recipes and development records you create | Automatic / directly from you |
| Analytics & diagnostics | Firebase Analytics usage events, Firebase Crashlytics crash reports, Firebase installation identifier | Automatic, via Firebase SDK |
| Device & advertising data | IP address, device model/OS, advertising identifier (GAID/IDFA) | Automatic, via AdMob SDK |
| Photos (optional) | A photo of your developed film negative, submitted through the in-app "Exposure Feedback" feature, together with your ISO setting and exposure verdict (under/correct/over) | Directly from you, only if you tap the capture button |
Camera access is requested only when you use the optional "Exposure Feedback" feature; the camera is never activated and no photo is collected unless you tap the capture button yourself. We do not request location permissions and do not collect real-world location data. The in-app "development map" ranking feature uses a virtual coordinate system unrelated to your actual location.
Special category data (Art. 9 GDPR) / Sensitive Personal Information (CPRA): None. We do not collect health, biometric, racial/ethnic, religious, or similar data.
3. Purposes and Legal Bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Account creation, authentication, providing the Service | Contract (Art. 6(1)(b)) |
| Fraud prevention, service security | Legitimate interests (Art. 6(1)(f)) |
| Service analytics and stability improvements | Legitimate interests (Art. 6(1)(f)) |
| Displaying personalized banner ads | Consent, collected via the Google User Messaging Platform (UMP) consent flow / iOS App Tracking Transparency prompt |
| Improving exposure-judgment accuracy using submitted photos (AI model training) | Consent (Art. 6(1)(a)) — applies only if you submit a photo |
Development timer alerts are local notifications generated on your device. We do not operate a push notification server and do not collect push notification tokens. We do not currently send marketing emails or push notifications. If this changes, we will request separate opt-in consent before doing so.
4. Recipients and Data Sharing
We do not sell your personal data. We share data with the following service providers acting as processors on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Authentication and database hosting (recipes, development records) | Singapore (server region) |
| Google LLC (Firebase Authentication) | Social sign-in authentication | United States |
| Google LLC (Firebase Analytics, Crashlytics, Remote Config) | Usage analytics, crash reporting, remote feature configuration | United States |
| Google LLC (AdMob / User Messaging Platform) | Banner ad serving, ad consent management | United States |
| Apple Inc. | Sign in with Apple (iOS) | United States |
Photos submitted through the Exposure Feedback feature are stored on our own self-hosted server infrastructure in South Korea, not with any third-party processor listed above, and are used solely to train our exposure-judgment model.
5. International Transfers (Chapter V GDPR)
Your data is transferred outside the EEA/UK to Singapore (Supabase) and the United States (Google, Apple) as listed above. These providers rely on their own standard contractual safeguards (e.g., Google and Apple both publish Standard Contractual Clauses for their processor relationships). Copies of applicable transfer safeguards are available on request at develop@yeji-hong.com.
Exposure Feedback photos are stored on our own server in the Republic of Korea. Korea is covered by a European Commission adequacy decision (Commission Implementing Decision (EU) 2022/254 of 17 December 2021), and the UK has adopted equivalent adequacy regulations for Korea, so no additional transfer safeguard is required for that data.
6. Retention
| Account and usage data | Until account deletion; deleted promptly on request |
| Withdrawn-account identifiers (email, display name, sign-up date, withdrawal date) | 5 years after account deletion, then purged automatically — kept to prevent abuse such as repeated delete-and-re-register (legitimate interests, Art. 6(1)(f)) |
| Support correspondence | 3 years after resolution |
| Exposure Feedback photos and verdict data | Until the model-training purpose is fulfilled, or until you request deletion |
7. Your Rights Under GDPR
- Right of Access (Art. 15) — obtain a copy of your data
- Right to Rectification (Art. 16) — correct inaccurate data
- Right to Erasure (Art. 17) — request deletion
- Right to Restriction (Art. 18)
- Right to Data Portability (Art. 20)
- Right to Object (Art. 21) — including to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7(3)) — at any time, where consent is the basis (e.g. personalized ads)
To exercise any right, contact us at develop@yeji-hong.com. We respond within one month. You also have the right to lodge a complaint with your local supervisory authority (list: edpb.europa.eu).
8. California / US State Privacy Rights (CCPA/CPRA)
Categories of personal information collected (CCPA §1798.140(v)): Identifiers (email, sign-in ID), internet/device activity (usage logs, advertising identifiers), and user-generated content (recipes, development records) — see Section 2 above.
Sale or sharing: We do not sell personal information for monetary consideration. Personalized advertising through Google AdMob may constitute "sharing" for cross-context behavioral advertising under CPRA §1798.140(ah). We honor the Global Privacy Control (GPC) browser/OS signal and the iOS App Tracking Transparency opt-out as an opt-out of this sharing.
Your rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of Sale/Sharing, Right to Non-Discrimination, Right to Data Portability. Exercise any of these by emailing develop@yeji-hong.com. We aim to respond within 45 calendar days.
Sensitive Personal Information: We do not collect Sensitive Personal Information as defined in CPRA §1798.140(ae).
Minors: The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
Residents of Virginia, Colorado, Connecticut, Utah, and other US states with comprehensive privacy laws may exercise comparable rights using the same contact method.
9. Advertising Identifiers and Personalized Ads
We use Google AdMob for banner ads. Consent for personalized advertising is collected via the Google User Messaging Platform (UMP) consent flow (all regions) and, on iOS, the App Tracking Transparency (ATT) prompt for IDFA access. Declining consent/tracking still allows the Service to show ads — they will simply be non-personalized.
To reset or limit your advertising identifier directly:
- iOS: Settings > Privacy & Security > Tracking > disable "Allow Apps to Request to Track"
- Android: Settings > Privacy > Ads > Delete advertising ID / opt out of ads personalization
10. Security
We use Supabase Row Level Security (RLS) to scope database access per user, encrypt data in transit (TLS), and limit the number of people with access to personal data (a single-developer operation).
11. Children
The Service is not intended for children under 16 and we do not knowingly collect personal data from them. Apple App Store age ratings for the Service are 15+ in South Korea and 16+ in several other territories, which further limits access by younger users at the store level.
12. Changes to This Notice
We may update this Notice as the Service or applicable law changes. Material changes will be posted on this page at least 7 days before taking effect.
This Privacy Policy takes effect on 2026-08-05.