Privacy Policy
The DrawTown team (the “Operator”), which operates DrawTown (the “Service”), complies with the Personal Information Protection Act and other applicable laws. This document explains how we collect, use, and protect users' personal information. The Service is a social drawing game where you decorate a village with friends through drawings. This policy applies to the iOS and Android apps and the websites (drawtown.app and invite.drawtown.app).
At a glance
- You can sign in only with a Google or Apple account. We do not store passwords.
- Drawings, photos, chats, and letters created in a village are visible to residents of the same village. They are not exposed to external search.
- However, drawing, photo, and face image files can be opened by anyone who knows their URLs. Section 12 explains this explicitly.
- Payments (Diamond purchases) are handled by the App Store and Google Play. The Operator does not receive card details.
- You may leave at any time through Settings → Delete Account. Your account and associated data are deleted immediately. Drawing and photo files in storage are deleted next; any files left behind due to connection problems are removed within 30 days.
- Contact: drawtown.team@gmail.com
1. Personal information collected and how it is collected
We do not separately ask for information such as your name, phone number, or address during registration. We process only the minimum information provided by social sign-in providers, information you create while using the Service, and information automatically generated by your device.
A. When registering or signing in
| Category | Information | Notes |
|---|---|---|
| Google sign-in | Unique Google account identifier, email address | Your email is used to show which account you signed in with on the Settings screen. |
| Apple sign-in | Unique Apple account identifier, email address (an Apple relay address if you choose “Hide My Email”) | We do not store the name provided by Apple. |
| Profile (entered by the user) | Nickname, face drawing created by the user, app language | Your nickname and face are visible to other residents. |
| Automatically generated | Internal user ID (UUID), device time zone (e.g. Asia/Seoul), registration time | Your time zone is used to calculate Today's Drawing rounds. |
B. Information you create while using the Service
- Drawings: drawings submitted for today's prompt, exhibition drawings, and drawings placed in villages and their locations
- Photos: photos taken with the camera and posted in villages, descriptions (captions), doodles drawn over photos, and records of “What are you up to?” requests
- Conversations: village chats (text and doodles), comments on drawings and photos, and records of letters and gifts sent to residents
- Village activity: villages you have joined, your last standing position in a village (game coordinates) and its time, placement, construction, fundraising, like, quest, and attendance records, and equipped decorative items
- Currency: ledgers of Acorns and Diamonds earned and spent
- Reports: reasons, details, and a copy of the reported content at the time of reporting
- Notification preferences: on/off settings for each notification type
The camera is used only when taking a photo. We do not access location information (GPS), contacts, the microphone, or the photo library. “Position” above means coordinates on the in-game village map, not your real-world location.
C. Information automatically generated or collected while using the Service
- Push notifications: device push token, platform (iOS/Android), delivery records
- Stability and analytics: app version, OS type and version, device model, error (crash) logs, and screen and feature usage events (Firebase Crashlytics and Analytics)
- Advertising: advertising identifiers and device information collected by the advertising SDK (Google AdMob) when you watch rewarded ads (see Section 7)
- Payments: Store transaction ID, product ID, Store type, payment environment, and payment event time when purchasing Diamonds. Payment method information, such as card numbers, is processed by Apple or Google and is not provided to the Operator.
- Access records: server access times, IP addresses, and request logs (service providers' system logs)
D. When contacting us
The app's “Suggest a Feature” and “Report a Bug” features open your email app to send a message to the Operator. Your email address and the app version, device OS, and internal user ID automatically filled into the message are sent with it. You can remove the diagnostic information before sending.
2. Why we use personal information
| Purpose | Information used |
|---|---|
| Identifying users, keeping users signed in, processing account deletion | Social account identifier, email, internal user ID |
| Providing villages, drawings, photos, chats, letters, and other features; showing village residents in real time | Profile, user-created content, village activity records, game coordinates |
| Calculating daily boundaries for Today's Drawing rounds, village daily rewards, and similar features | Time zone |
| Sending push notifications and applying notification preferences | Push token, notification preferences, app language |
| Crediting paid currency (Diamonds), managing its history, handling payment errors, and checking refunds | Payment events, currency ledgers |
| Issuing rewards for watching rewarded ads | Ad completion events |
| Preventing abuse, handling reports, restricting use | Report records, content copies, access records |
| Maintaining stability, fixing errors, analyzing usage statistics | Crash logs, usage events, device and app information |
| Responding to inquiries | Email address, inquiry details, diagnostic information |
3. Retention and use periods
As a rule, personal information is destroyed without delay when you delete your account. Because account data is linked to your user account, a single account deletion also deletes your profile, drawings, photos, chats, letters, currency ledgers, notification preferences, push tokens, and other associated data. The following exceptions apply.
| Item | Period | Basis |
|---|---|---|
| Payment (Diamond purchase) transaction records | 5 years | Act on the Consumer Protection in Electronic Commerce |
| Consumer complaint and dispute handling records | 3 years | The same Act |
| Server access records (IP and access time) | 3 months | Protection of Communications Secrets Act |
| Report records and copies of content at the time of reporting | 1 year from receipt (deleted immediately if the reporter deletes their account) | Preventing repeated abuse |
| Shared records remaining in villages (structure purchasers, placement removers, village quest claimants, plot unlockers, and prompt assignments) | Until the village is deleted | When an account is deleted, the user identifier is cleared (anonymized) and only the village record remains. |
| Photos | Displayed in the village until midnight on the day posted (in the village's time zone) | After display ends, they remain stored until the user deletes them or their account, but are not shown to other residents. |
4. Information visible to other users
As a village-based social game, the Service displays the following information to residents of the same village as part of its features. This is how the Service operates, rather than disclosure to third parties.
- Nickname, face drawing, equipped decorative items, character position in the village, and online/away status
- Submitted drawings, exhibition drawings, drawings and structures placed in the village, likes, and comments
- Photos and doodles, chat messages, and “What are you up to?” speech bubbles
- Village activity notifications, such as fundraising participation, quest claims, and structure purchases
Letters are visible only to their recipients. Anyone who knows the invite code can join the village and see the information above, so share it only with people you want to join. Content you export outside the app yourself, such as drawing share cards, leaves the Service by your choice.
5. Disclosure to third parties
The Operator does not provide users' personal information to third parties, except in the following cases.
- You have given prior consent
- Disclosure is based on law, or an investigative authority requests it following legally prescribed procedures and methods
6. Outsourced processing and international transfers
The Service uses infrastructure and SDKs from the following providers. They store, transmit, and process information on the Operator's behalf. Some have servers abroad or may access information from abroad, so we provide the following notice under Article 28-8 of the Personal Information Protection Act. Use of the Service depends on these transfers; if you do not want international transfers, you cannot use the Service.
| Recipient | Service provided | Information transferred | Country, timing, and method | Retention period |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage (drawings, photos, faces), and real-time event relay | All account, profile, content, and activity information in Section 1 | Data is stored in the South Korea (Seoul) region. Headquarters are in the United States, with possible access for operations and technical support. Transmitted over the network during use | Until account deletion or the end of the processing arrangement |
| Google LLC (Firebase) | Push notification delivery (Cloud Messaging), error collection (Crashlytics), usage analytics (Analytics), and remote configuration (Remote Config) | Push token, device and app information, crash logs, usage events, internal user ID | Google data centers in the United States and elsewhere. Automatically transmitted during use | Under Google's policies |
| Google LLC (AdMob) | Serving rewarded ads | Advertising identifier, device and app information, approximate location (based on IP) | United States and elsewhere. Automatically transmitted when an ad is requested | Under Google's policies |
| Google LLC (Google sign-in) | Social sign-in | Google account identifier, email | United States and elsewhere. At sign-in | Until account deletion |
| Apple Inc. | Apple sign-in, push notifications (APNs), in-app purchases | Apple account identifier, email, push token, payment information | United States and elsewhere. At sign-in, notification delivery, or payment | Under Apple's policies |
| RevenueCat, Inc. | In-app purchase receipt validation and payment event delivery | Internal user ID, Store transaction ID, product ID, payment environment | United States. Automatically transmitted at payment | Until account deletion or the end of the processing arrangement |
| Fly.io, Inc. | Operating the real-time relay server for character movement and online status in villages | Internal user ID, nickname, face drawing path, decoration information, game coordinates, online status | Japan (Tokyo) region. Transmitted in real time while connected to a village. Relayed only in memory without storage | Deleted within a maximum of 20 seconds after disconnection |
Google Privacy Policy: policies.google.com/privacy · Apple: apple.com/legal/privacy · Supabase: supabase.com/privacy · RevenueCat: revenuecat.com/privacy · Fly.io: fly.io/legal/privacy-policy
7. Advertising and behavioral information
The Service uses Google AdMob for rewarded ads that users choose to watch (watching to the end earns rewards such as Acorns or pen colors). When serving ads, the advertising SDK may collect advertising identifiers (iOS IDFA and Android advertising ID), device information, and approximate location based on IP. Google uses this information for ad delivery, measurement, and fraud prevention.
- On iOS, we may request App Tracking Transparency (ATT) permission for personalized advertising. IDFA can be accessed only if you allow tracking. You can use the game without allowing tracking. You can change this permission in Settings → Privacy & Security → Tracking → DrawTown.
- Google's advertising consent form may appear depending on your region and consent status. Where a privacy options entry point is required, you can review or change your choices under “Ad privacy choices” in the app's Settings. On Android, you can reset or delete your advertising ID under Google → Ads in device settings; the path and available options vary by OS version.
- In addition to ad reward records, the Operator uses Firebase Analytics to collect the screen where an ad was requested and its outcome (reward earned, dismissed, unavailable, or error). Usage analytics may include screen and feature events and an internal user ID, and is used to operate and improve the Service. Advertising identifiers and behavioral information handled by the advertising SDK are processed as described in the entrusted processing section and this section.
September 17, 2026: corrected the descriptions of ATT permission, ad settings, and ad outcome analytics in this section.
8. Destruction of personal information
- Information is destroyed without delay when its retention period ends or its processing purpose has been fulfilled.
- Electronic files are deleted using methods that prevent recovery. When an account is deleted, account and content rows in the database are deleted immediately. The app then deletes drawings, photos, and face files in storage immediately after account deletion. Because this step relies on the user's device network, some files may remain if communications fail. These files are no longer referenced by any account or village, and the Operator deletes them within 30 days. To request earlier deletion, contact us using the details in Section 13.
- Information that must be retained by law is stored separately and destroyed when its required retention period ends.
9. Your rights and how to exercise them
You may access, correct, or delete your personal information and request suspension of its processing at any time. Some actions are available directly in the app; others require contacting us.
| What you want to do | How |
|---|---|
| Change your nickname, face, or language | Settings → My Character / Change Name / Language |
| Delete your photos or comments | Select Delete from the photo or comment's menu |
| Leave a village | Village menu → Leave Village (hosts must first transfer their role to another resident) |
| Turn off notifications | Settings → Notifications, or your device's notification settings |
| Delete your account | Settings → Delete Account. You can proceed after leaving all villages you have joined. Your account and associated data are deleted immediately and cannot be restored (see Section 8 for storage file cleanup). All currency, including purchased Diamonds, expires. |
| Other requests for access, correction, or suspension of processing | Contact drawtown.team@gmail.com. We will process your request within 10 days after verifying your identity. |
Legal representatives may exercise these rights on behalf of children under 14 with respect to their personal information. Exercising these rights may be restricted where permitted by law, in which case we will explain the reason.
10. Children under 14
The Service is intended for people aged 14 or older, and we do not knowingly collect personal information from children under 14. If we learn that a child under 14 has registered, we delete the account and information without delay. Guardians who learn that a child has registered should notify us at drawtown.team@gmail.com.
11. Automatic collection mechanisms
The app does not use cookies. It stores authentication tokens to keep you signed in and app settings (language and sound) on your device, and those values are deleted when you uninstall the app. A copy of your language preference is also sent to the server, and notification preferences are stored on the server, because the server needs them to create push notifications in your language and send only the types you have enabled (Sections 1 and 2). Server-side values are deleted when you delete your account (Section 3). Uninstalling the app alone removes only the values on your device. Device identifiers generated by Firebase and AdMob SDKs are handled as described in Sections 6 and 7. The websites (drawtown.app and invite.drawtown.app) do not set cookies; only the hosting provider's (Google Firebase Hosting) access logs are retained.
12. Security measures
- Access control: Row Level Security (RLS) policies are enabled on every database table. All sensitive writes, including currency and state changes, go through server functions without exception. Village records such as chats, photos, submitted drawings, and placements are accessible only to residents of that village; letters are accessible only to the sender and recipient.
- The following two categories fall outside those boundaries. We disclose this explicitly.
- Profiles: Signed-in users can look up other users' profiles even if they are not in the same village. This access is available because the Service needs to display names and faces outside villages as well. This table contains internal user ID, nickname, face drawing URL, app language, device time zone, registration time, and onboarding completion and guidance times. It does not contain email addresses, push tokens, or currency balances.
- Image files (drawings, photos, and faces): File storage allows public reads, so anyone who knows a file's URL can open it even without being a village resident, and listing files in storage is not blocked. This includes drawings made and photos taken within villages, so please keep this in mind when using the Service. (Drawing share cards exported outside the app are shared by the user's choice; see Section 4.)
- Encryption in transit: All communication between the app and servers is encrypted with TLS (HTTPS and WSS).
- No password storage: We support social sign-in only and do not store passwords.
- Least privilege: The real-time relay server has no database administrator privileges and verifies users only through signed tokens.
- Administrative measures: Access to personal information is limited to the Operator, and management console accounts and access permissions are managed separately.
13. Privacy officer
Privacy officer: DrawTown Operator
Email: drawtown.team@gmail.com
Please send privacy inquiries, complaints, and requests for remedies to the contact above. We will respond within 10 days of receipt.
14. Remedies for privacy violations
You may contact the following organizations to report or seek advice about a privacy violation.
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (no area code in Korea) · privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 · kopico.go.kr
- Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code in Korea) · spo.go.kr
- Cyber Investigation Bureau, Korean National Police Agency: 182 (no area code in Korea) · ecrm.police.go.kr
15. Changes to this policy
If content is added, removed, or amended, we will announce the changes in the app or on this page at least 7 days before they take effect. Material changes, such as changes to collected information or purposes of use that are unfavorable to users, will be announced 30 days in advance.
- September 16, 2026 — First effective date (Version 1.0)
- September 17, 2026 — Corrected Section 7 descriptions of ATT permission, ad settings, and ad outcome analytics