텐프레임 · Tenframe

최종 개정일 · Last updated · 最終改定日: 2026-08-04

개인정보처리방침

텐프레임(이하 "서비스")은 볼링 점수판 사진을 판독해 기록으로 남기는 앱입니다. 이 방침은 서비스가 어떤 정보를 다루고, 어디로 보내고, 얼마나 보관하는지 설명합니다.

1. 수집하는 정보

항목수집 시점목적
점수판 사진판독을 요청할 때점수 판독
기기 식별자앱 최초 실행 시일일 판독 횟수 관리
이메일, 이름로그인할 때만계정 식별, 기록 동기화
경기 기록
(선수 이름·보조표기·점수·메모·장소·경기 일시·'나' 표시)
판독·편집할 때기록 보관, 로그인 시 동기화
구독 상태구독할 때만광고 면제 여부 판단
IP 주소서버 요청 시서버 운영·오류 추적. 헤더 누락 시에는 해시한 값으로 임시 식별
광고 거래 번호광고를 볼 때만보상 중복 지급 방지
광고 식별자(IDFA)광고를 볼 때, 추적을 허용한 경우에만맞춤형 광고 게재 (Google AdMob이 처리)
기기·OS 정보, 앱 버전앱 실행 시 업데이트 확인앱 업데이트 배포 (Expo가 처리)

2. 사진 처리 — 중요

판독을 요청하면 사진은 OpenAI로 전송되어 분석됩니다. 분석이 끝나면 결과(점수 데이터)만 돌려받습니다.

사진은 서비스 서버에 저장되지 않습니다. 전송 후 메모리에서 사라지며, 데이터베이스나 파일 저장소 어디에도 기록되지 않습니다. 사진 원본은 사용자 기기 안에만 보관되고, 기록을 삭제하면 함께 지워집니다. 로그인해도 사진은 클라우드로 올라가지 않습니다.

사진에 점수판 외의 사람이나 배경이 찍혀 있을 수 있습니다. 판독에 필요한 범위만 촬영하시길 권합니다.

3. 기기 식별자

일일 무료 판독 횟수를 세기 위해 앱 최초 실행 시 무작위로 생성한 값을 기기에 저장합니다. 광고 식별자(IDFA)나 하드웨어 고유번호가 아닙니다. 맞춤형 광고에 쓰이는 IDFA는 이 값과 별개이며, 추적을 허용한 경우에 한해 광고 제공자(Google AdMob)가 다룹니다(7항).

이 값은 iOS 키체인에 저장되므로 앱을 삭제해도 남아 있으며, 다시 설치하면 같은 값이 복원됩니다. 무료 횟수를 초기화하려고 앱을 지웠다 까는 것을 막기 위한 설계입니다. 키체인을 초기화하면 새 값이 만들어집니다. 기기를 바꾸는 경우, 암호화된 기기 백업에서 복원하면 같은 값이 새 기기로 따라옵니다. 백업 없이 새로 설정하면 새 값이 만들어집니다.

이 식별자와 함께 날짜별 판독 횟수가 서버에 기록됩니다. 요청 헤더가 누락된 비정상 요청에 한해 IP 주소를 되돌릴 수 없게 해시한 값이 임시 식별자로 쓰일 수 있습니다.

로그인 상태에서는 기기 식별자 대신 계정 식별자로 횟수를 셉니다. 광고 보상을 지급할 때는 이 값(로그인 시 계정 식별자, 비로그인 시 기기 식별자)이 광고 제공자에게 전달되었다가 검증 신호로 되돌아옵니다 — 누구에게 보상을 줄지 알아야 하기 때문입니다. 서버 운영 로그에는 이 값을 그대로 남기지 않고 되돌릴 수 없게 축약한 형태로만 기록합니다.

토스 미니앱 버전에서는 토스가 제공하는 이미 해시된 사용자 식별키를 그대로 같은 용도로 씁니다. 이 값은 토스 계정에 연결되어 있어 앱 삭제나 기기 변경에도 유지됩니다.

4. 계정

로그인은 선택입니다. 로그인하지 않아도 모든 판독 기능을 쓸 수 있습니다. 로그인하지 않으면 기록은 기기에만 저장되며, 앱을 삭제하거나 기기를 바꾸면 복구할 수 없습니다.

Apple 또는 Google 계정으로 로그인하면 이메일과 이름을 전달받아 인증 기반(Supabase)에 저장합니다. 비밀번호는 다루지 않습니다.

5. 기록 동기화

로그인 상태에서는 경기 기록이 서버에 저장되어 기기 간에 이어집니다. 저장되는 내용은 선수 이름과 보조표기, 프레임별 점수, 메모, 장소, 경기 일시, 어느 선수가 '나'인지입니다. 사진은 포함되지 않습니다.

선수 이름은 점수판에서 판독된 값이며, 다른 사람의 이름이 포함될 수 있습니다. 원하지 않으면 결과 화면에서 수정하거나 해당 선수를 삭제할 수 있습니다.

6. 공유 링크

기록을 공유하면 선수 이름과 보조표기, 점수, 메모, 장소가 서버에 저장되고, 임의의 주소가 만들어집니다.

링크를 아는 사람은 누구나 볼 수 있습니다. 검색에 노출되지는 않지만 로그인은 필요 없습니다. 메신저 미리보기에 선수 이름이 표시될 수 있습니다. 공유 링크는 생성일로부터 180일이 지나면 열리지 않으며, 저장된 내용도 매일 도는 정리 작업으로 삭제됩니다. 그 전에 삭제가 필요하면 아래 문의처로 링크 주소와 함께 연락해 주세요.

7. 광고

무료 판독 횟수를 다 쓰면 보상형 광고를 보고 판독을 1회 더 받을 수 있습니다. 광고를 보지 않아도 다음 날 무료 횟수가 다시 채워지며, 구독하면 광고가 표시되지 않습니다.

iOS 앱의 광고는 Google AdMob이 제공합니다. AdMob은 광고 게재와 부정 방지를 위해 기기·광고 식별자, 대략적인 위치(IP 기반 국가 수준), 광고 상호작용 기록을 처리합니다. 자세한 내용은 Google 파트너 사이트 정책을 참고하세요.

맞춤형 광고는 사용자가 허용한 경우에만 표시됩니다. iOS의 추적 허용 요청(ATT)은 앱을 처음 실행할 때 한 번 나타납니다(광고를 보기 전에 묻습니다). 허용하지 않으면 앱이 관심사 기반이 아닌 일반 광고만 요청하며, 광고 식별자를 이용한 제3자 제공도 일어나지 않습니다. 허용하지 않아도 앱의 모든 기능을 그대로 쓸 수 있고 광고 보상도 동일하게 받습니다. 설정 → 개인정보 보호 및 보안 → 추적에서 언제든 바꿀 수 있습니다.

보상이 정상적으로 지급되었는지 확인하기 위해, 광고 제공자가 보낸 검증 신호를 서버가 받아 처리합니다. 이때 거래 번호만 따로 저장해 같은 광고로 두 번 보상받는 것을 막습니다. 이 번호는 광고 제공자가 만든 임의의 값이고 누구의 것인지 알 수 있는 정보가 함께 저장되지 않습니다. 보상을 받을 대상 식별자는 판독 횟수 기록에 반영될 뿐 이 표에는 남지 않으며, 서버 로그에도 축약된 형태로만 남습니다.

토스 미니앱 버전에서는 토스가 제공하는 보상형 광고가 표시되며, 이때 광고 노출·보상 정보는 토스가 처리합니다.

8. 결제

구독 결제는 Apple App Store가 처리하며, 서비스는 카드번호 등 결제수단 정보를 받지 않습니다. 구독 상태 확인을 위해 RevenueCat을 사용하며, 서버에는 계정 식별자와 구독 활성 여부, 만료 예정일만 저장합니다.

9. 제3자 제공 및 처리위탁

아래 표의 위탁은 서비스를 대신해 처리만 하는 경우이고, 제3자 제공은 받는 쪽이 자기 목적으로도 쓰는 경우입니다.

구분업체목적전달 정보
위탁OpenAI점수판 판독점수판 사진
위탁Supabase계정·기록·사용량 저장계정 정보, 경기 기록, 기기 식별자
위탁Vercel서버 운영접속 기록(IP 포함)
위탁Expo앱 업데이트 배포IP, 기기·OS 정보, 앱 버전
위탁RevenueCat구독 상태 확인계정 식별자, 구독 상태
제3자 제공Google AdMob
(보상 검증)
광고 보상 서버 검증보상 대상 식별자 (보내면 그대로 되돌아옵니다)
제3자 제공Google AdMob
(맞춤형 광고)
관심사 기반 광고 게재광고 식별자(IDFA), IP(국가 수준), 광고 상호작용 — 추적을 허용한 경우에만
제3자 제공Apple / Google로그인 인증로그인 요청(앱·기기 정보). 이메일·이름은 반대로 이들로부터 받습니다
제공받음토스 (비바리퍼블리카, 국내)미니앱 운영·광고토스가 제공한 익명 식별키를 받아 사용 (토스 버전에 한함)

9-1. 국외 이전

아래 업체는 국외에 서버를 둡니다. 개인정보보호법 제28조의8에 따라 알립니다. 토스는 국내 사업자이므로 이 표에 해당하지 않습니다. 이전 국가는 각 사의 본사 소재지가 아니라 실제 데이터가 처리되는 리전을 기준으로 적었습니다.

이전받는 자연락처이전 국가이전 항목이전 시점·방법목적 / 이전받는 자의 보유·이용 기간
OpenAI, L.L.C.privacy@openai.com미국점수판 사진판독 요청 시 HTTPS 전송점수 판독 / 처리 후 즉시 파기. 다만 OpenAI가 오·남용 점검 목적으로 최대 30일 보관할 수 있습니다
Supabase, Inc.privacy@supabase.io싱가포르
(리전 ap-southeast-1)
계정 정보, 경기 기록, 사용량, 구독 상태, 공유 스냅샷가입·저장 시 HTTPS 전송계정·기록 보관 / 계정 삭제 시까지. 공유 스냅샷은 180일, 비로그인 사용 이력은 90일
Vercel, Inc.privacy@vercel.com미국
(리전 iad1)
접속 기록(IP 포함). 광고 보상 검증 호출에 한해 보상 대상 식별자가 요청 주소에 포함됩니다요청 시 자동 수집서버 운영 / 1시간 (Vercel Hobby 요금제의 런타임 로그 보관 기간). 서비스가 따로 내려받아 쌓지 않습니다
Google LLC (AdMob)Google 개인정보 문의 창구미국보상 대상 식별자(항상). 광고 식별자(IDFA)·IP(국가 수준)·광고 상호작용은 추적을 허용한 경우에만광고 요청 시 전송광고 게재·보상 검증 / 서비스가 AdMob 이용을 종료할 때까지. 서비스는 이 항목들을 저장하지 않습니다
RevenueCat, Inc.support@revenuecat.com미국계정 식별자, 구독 상태구독 시 전송구독 확인 / 계정 삭제 시까지 (계정을 지우면 구독자 기록 삭제를 함께 요청합니다). 다만 RevenueCat이 회계·환불 대응을 위해 거래 기록을 자체 정책에 따라 보관할 수 있습니다
Apple Inc.Apple 개인정보 문의 창구미국로그인 요청(앱 식별자, 기기·접속 정보). 이메일·이름은 Apple이 우리에게 주는 값입니다로그인 시 전송본인 인증 / 서비스가 Apple 로그인 연동을 종료할 때까지
Google LLC (로그인)Google 개인정보 문의 창구미국로그인 요청(앱 식별자, 기기·접속 정보). 이메일·이름은 Google이 우리에게 주는 값입니다로그인 시 전송본인 인증 / 서비스가 Google 로그인 연동을 종료할 때까지
Expo (650 Industries, Inc.)Expo 개인정보 문의 창구미국IP, 기기·OS 정보, 앱 버전앱 실행 시 업데이트 확인앱 업데이트 배포 / 서비스가 Expo 이용을 종료할 때까지

위 연락처로 닿지 않으면 아래 14항의 개인정보 보호책임자에게 알려주세요. 대신 전달해 드립니다.

국외 이전을 원하지 않으시면 서비스 이용을 중단하고 계정을 삭제하실 수 있습니다. 맞춤형 광고를 위한 제3자 제공은 추적을 허용하지 않으면 일어나지 않으며, 이 경우에도 앱의 모든 기능을 쓰실 수 있습니다. 다만 판독 기능은 국외 처리 없이는 제공할 수 없습니다.

10. 보관 기간

10-1. 파기 절차 및 방법

보유기간이 지나거나 처리 목적이 끝난 개인정보는 지체 없이 파기합니다. 전자적 파일은 데이터베이스에서 삭제하며 복구하지 않습니다. 종이 문서는 다루지 않습니다.

기간이 정해진 항목은 매일 자동으로 도는 정리 작업이 지웁니다 — 만료된 공유 스냅샷, 90일이 지난 광고 거래 번호, 90일이 지난 비로그인 사용 이력이 여기에 해당합니다. 계정을 삭제하면 계정에 연결된 기록·사용량·구독 상태가 그 자리에서 지워집니다.

자동 파기 대상이 아닌 항목(아직 만료되지 않은 공유 링크)은 아래 문의처로 요청해 주시면 처리합니다.

10-2. 안전성 확보조치

11. 이용자의 권리

정보주체는 열람, 정정·삭제, 처리정지를 요구하실 수 있습니다. 판독은 사진에서 점수를 읽어내는 자동 처리이지만 그 결과로 이용자에게 불이익한 결정을 내리지는 않으며, 결과는 언제든 화면에서 직접 고치실 수 있습니다.

기록은 앱 안에서 직접 삭제할 수 있고, 로그인 상태면 서버 사본도 함께 지워집니다. 삭제할 때 인터넷이 끊겨 있으면 다음에 연결될 때 서버에서 지워집니다. 지운 기기에서는 다시 나타나지 않고, 다른 기기에서는 서버 삭제가 반영된 뒤에 사라집니다.

계정 삭제는 앱의 설정 화면에서 직접 하실 수 있습니다(설정 → 계정 삭제). 클라우드에 보관된 경기 기록·구독 정보·계정에 연결된 사용 이력이 지워지고, 결제 확인에 쓰는 RevenueCat 구독자 기록도 함께 삭제를 요청합니다. 되돌릴 수 없습니다. 이 기기에 남은 기록은 함께 지워지지 않으며 기록 화면에서 개별 삭제할 수 있습니다.

다음은 계정과 연결되어 있지 않아 함께 지워지지 않습니다: 이미 만든 공유 링크(180일 후 자동 삭제, 그 전에 지우려면 아래로 요청), 로그인 전 게스트로 쌓인 사용 이력(90일 후 자동 삭제), 광고 거래 번호(90일 후 자동 삭제. 누구의 것인지 식별할 수 없어 개별 삭제는 불가능합니다).

보관 정보의 열람·정정, 처리정지, 공유 링크의 조기 삭제는 아래 문의처로 요청해 주세요.

12. 아동

서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 아동의 개인정보를 의도적으로 수집하지 않습니다.

13. 변경

이 방침이 바뀌면 이 페이지에 개정일과 함께 게시합니다.

14. 개인정보 보호책임자 및 문의

개인정보 처리에 관한 문의·열람·정정·삭제·처리정지 요청은 아래로 연락해 주세요. 접수 후 지체 없이 답변드립니다.

구분내용
서비스명텐프레임 (Tenframe)
상호드라카리스
대표자김민석
사업자등록번호584-21-02501
개인정보 보호책임자김민석
이메일minseok1061@gmail.com

15. 권익침해 구제방법

개인정보 침해로 인한 신고·상담이 필요하시면 아래 기관에 문의하실 수 있습니다.


Privacy Policy

Tenframe ("the Service") reads bowling scoreboard photos and keeps them as records. This policy explains what information the Service handles, where it is sent, and how long it is kept.

1. Information we handle

ItemWhenPurpose
Scoreboard photoWhen you request a readingReading the scores
Device identifierFirst launchDaily scan limits
Email, nameOnly if you sign inAccount, sync
Game records
(player names and sub-labels, scores, notes, venue, game date, which player is you)
On reading/editingStorage and sync
Subscription statusOnly if you subscribeAd-free entitlement
IP addressOn server requestsOperations and error tracing; a hashed form serves as a temporary identifier when the expected header is missing
Ad transaction IDOnly when you watch an adPreventing duplicate rewards
Advertising identifier (IDFA)When you watch an ad, only if you allowed trackingPersonalised ads (handled by Google AdMob)
Device/OS info, app versionOn the update check at app launchApp update delivery (handled by Expo)

2. How photos are handled — important

When you request a reading, the photo is sent to OpenAI for analysis. Only the result (score data) is returned.

Photos are not stored on our servers. They are discarded from memory after the request and are never written to any database or file storage. The original photo stays on your device only and is deleted together with the record. Photos are never uploaded to the cloud, even when signed in.

A photo may capture people or surroundings beyond the scoreboard. We recommend framing only what is needed.

3. Device identifier

To count daily free scans, a randomly generated value is stored on your device at first launch. It is not an advertising identifier (IDFA) or a hardware serial. The IDFA used for personalised ads is a separate value, handled by the ad provider (Google AdMob) only if you allowed tracking — see section 7.

The value is kept in the iOS keychain, so it survives deleting the app and is restored on reinstall. This is deliberate — it stops free scans from being reset by reinstalling. Resetting the keychain produces a new value. When you switch devices, restoring from an encrypted device backup carries the same value across; setting up fresh without a backup produces a new one.

Daily scan counts are recorded on the server alongside this identifier. For malformed requests missing the expected header, an irreversibly hashed IP address may be used as a temporary identifier.

When signed in, scans are counted against your account identifier instead. To credit an ad reward, this value (account identifier when signed in, device identifier otherwise) is sent to the ad provider and returned in the verification signal — we must know who to credit. Our operational logs never record it verbatim, only in an irreversibly shortened form.

The Toss mini-app version uses the already-hashed user key that Toss supplies, as-is, for the same purpose. That value is tied to the Toss account and persists across app deletion and device changes.

4. Accounts

Signing in is optional. All reading features work without an account. Without signing in, records stay on your device only and cannot be recovered if you delete the app or change devices.

If you sign in with Apple or Google, your email and name are received and stored in our authentication backend (Supabase). We never handle passwords.

5. Sync

While signed in, game records are stored on the server and follow you across devices. Stored content includes player names and sub-labels, per-frame scores, notes, venue, the game's date and time, and which player is marked as you. Photos are not included.

Player names are read from the scoreboard and may include other people's names. You can edit them or remove a player on the result screen.

6. Share links

Sharing a game stores player names and sub-labels, scores, notes, and venue on the server under a randomly generated address.

Anyone with the link can view it. It is unlisted but requires no sign-in, and player names may appear in messenger link previews. Share links stop working 180 days after creation, and a daily cleanup job then deletes the stored content as well. To have one removed sooner, contact us with the link address.

7. Advertising

When your free scans run out, you can watch a rewarded ad to earn one more. Watching is never required — free scans refill the next day, and subscribers see no ads at all.

Ads in the iOS app are served by Google AdMob, which processes device and advertising identifiers, coarse location (country level, derived from IP), and ad interaction data to deliver ads and prevent fraud. See Google's partner sites policy for details.

Personalised ads are shown only if you allow tracking. iOS asks for permission (ATT) once, on first launch — before any ad is shown. If you decline, the app requests non-personalised ads only, and no advertising-identifier data is shared with third parties. Declining does not limit any feature — you still earn the same rewards. You can change this any time in Settings → Privacy & Security → Tracking.

To confirm that a reward was granted correctly, our server receives and processes a verification signal from the ad provider. We store only the transaction ID from it, so that the same ad cannot be redeemed twice. That ID is a random value generated by the ad provider and is stored with nothing that identifies whose it is. The identifier of the account to credit is applied to your scan counts, is not retained in that table, and appears in server logs only in shortened form.

The Toss mini-app version shows Toss-provided rewarded ads; ad delivery and reward data are handled by Toss.

8. Payments

Subscription payments are processed by the Apple App Store. We never receive card or payment credentials. RevenueCat is used to determine subscription status; our server stores only an account identifier, whether the subscription is active, and its expiry date.

9. Third parties

In the table below, Processor means the provider only handles data on our behalf; Third-party disclosure means the recipient also uses it for its own purposes.

BasisProviderPurposeData shared
ProcessorOpenAIScoreboard readingScoreboard photo
ProcessorSupabaseAccounts, records, usageAccount info, game records, device identifier
ProcessorVercelHostingAccess logs (incl. IP)
ProcessorExpoApp update deliveryIP, device/OS info, app version
ProcessorRevenueCatSubscription statusAccount identifier, status
Third-party disclosureGoogle AdMob
(reward verification)
Server-side verification of ad rewardsIdentifier of the account to credit (sent out and echoed straight back)
Third-party disclosureGoogle AdMob
(personalised ads)
Interest-based ad deliveryAdvertising identifier (IDFA), IP (country level), ad interactions — only if you allowed tracking
Third-party disclosureApple / GoogleSign-in authenticationThe sign-in request (app and device details). Email and name flow the other way — we receive them
Received fromToss (Viva Republica, Korea)Mini-app and adsAn anonymous key provided to us by Toss (Toss version only)

9-1. Transfers abroad

The providers below hold data outside the Republic of Korea, where the Service is operated. We disclose this under Article 28-8 of the Personal Information Protection Act. Toss is a Korean company and is not part of this table. The country listed is the region where data is actually processed, not the provider's headquarters.

RecipientContactCountryData transferredWhen and howPurpose / recipient's retention
OpenAI, L.L.C.privacy@openai.comUnited StatesScoreboard photoSent over HTTPS on each reading requestReading scores / discarded immediately after processing, though OpenAI may retain it for up to 30 days for abuse monitoring
Supabase, Inc.privacy@supabase.ioSingapore
(region ap-southeast-1)
Account info, game records, usage, subscription status, share snapshotsSent over HTTPS on sign-up and saveStoring accounts and records / until the account is deleted. Share snapshots 180 days; signed-out usage history 90 days
Vercel, Inc.privacy@vercel.comUnited States
(region iad1)
Access logs (incl. IP). For ad reward verification calls only, the identifier of the account to credit appears in the request URLCollected automatically per requestHosting / 1 hour (runtime log retention on Vercel's Hobby plan). We do not export or accumulate them
Google LLC (AdMob)Google privacy contactUnited StatesIdentifier of the account to credit (always). Advertising identifier (IDFA), IP (country level), and ad interactions only if you allowed trackingSent on each ad requestAd delivery and reward verification / until we stop using AdMob. We do not store these items ourselves
RevenueCat, Inc.support@revenuecat.comUnited StatesAccount identifier, subscription statusSent on subscribingSubscription verification / until the account is deleted (deleting your account also requests deletion of the RevenueCat subscriber record). RevenueCat may still retain transaction records for accounting and refunds under its own policy
Apple Inc.Apple privacy contactUnited StatesThe sign-in request (app identifier, device and connection details). Email and name are values Apple gives to usSent when you sign inAuthentication / until we stop offering Sign in with Apple
Google LLC (sign-in)Google privacy contactUnited StatesThe sign-in request (app identifier, device and connection details). Email and name are values Google gives to usSent when you sign inAuthentication / until we stop offering Google sign-in
Expo (650 Industries, Inc.)Expo privacy contactUnited StatesIP, device/OS info, app versionSent on the update check at app launchApp update delivery / until we stop using Expo

If a contact above does not reach the recipient, tell the data protection officer in section 14 and we will pass your request on.

If you do not want your data transferred abroad, you may stop using the Service and delete your account. The third-party disclosure for personalised ads does not happen at all unless you allow tracking, and every feature still works if you decline. Note that the reading feature cannot be offered without processing abroad.

10. Retention

10-1. How data is destroyed

Personal information is destroyed without delay once its retention period ends or its purpose is fulfilled. Electronic records are deleted from the database and not recovered. We handle no paper records.

Items with a fixed period are removed by a cleanup job that runs daily — expired share snapshots, ad transaction IDs older than 90 days, and signed-out usage history older than 90 days. Deleting your account immediately removes the records, usage counts, and subscription status linked to it.

The one item outside that automatic sweep — a share link that has not yet expired — is handled on request via the contact below.

10-2. Security measures

11. Your rights

You may request access, correction or deletion, and suspension of processing. Reading a scoreboard is automated, but no decision adverse to you is made from it, and you can correct any result directly on screen.

Records can be deleted in the app, which also removes the server copy while signed in. If you are offline when you delete, the server copy is removed the next time you connect. It never comes back on the device you deleted it from; on your other devices it disappears once the deletion reaches the server.

You can delete your account from within the app (Settings → Delete account). The game records, subscription details, and usage history linked to the account are erased, and we also request deletion of the RevenueCat subscriber record used for payment verification. This cannot be undone. Records stored on this device are not removed and can be deleted individually.

The following are not linked to your account and are not erased with it: share links you already created (deleted automatically after 180 days; contact us to remove one sooner), usage history accumulated as a guest before signing in (deleted automatically after 90 days), and ad transaction IDs (deleted automatically after 90 days; individual deletion is impossible because we cannot tell whose they are).

For access to or correction of stored data, suspension of processing, or early removal of a share link, contact us below.

12. Children

The Service is not directed to children under 14 and does not knowingly collect their personal information.

13. Changes

Changes to this policy will be posted on this page with a revision date.

14. Data protection contact

For questions about how your data is handled, or to request access, correction, deletion, or suspension of processing, contact us below. We respond without undue delay.

ServiceTenframe
Business nameDrakarys (드라카리스)
RepresentativeMinseok Kim
Business registration no.584-21-02501 (Republic of Korea)
Data protection officerMinseok Kim
Emailminseok1061@gmail.com

15. Filing a complaint

The Service is operated from the Republic of Korea. If you believe your privacy rights have been infringed, you may contact any of the following. You may also contact your local supervisory authority.


プライバシーポリシー

テンフレーム(以下「本サービス」)は、ボウリングのスコア表の写真を読み取って記録として残すアプリです。本ポリシーは、本サービスがどの情報を扱い、どこへ送り、どれだけ保管するかを説明します。

1. 取り扱う情報

項目取得のタイミング目的
スコア表の写真読み取りを依頼したときスコアの読み取り
端末識別子初回起動時1日の読み取り回数の管理
メールアドレス・氏名ログインした場合のみアカウント識別、同期
ゲーム記録
(プレイヤー名・補助表記・スコア・メモ・場所・試合日時・「自分」の指定)
読み取り・編集時記録の保管と同期
サブスクリプション状態購入した場合のみ広告免除の判定
IPアドレスサーバーへの要求時サーバー運用・障害追跡。ヘッダー欠落時はハッシュ化した値で一時的に識別
広告の取引番号広告を視聴した場合のみ報酬の二重付与の防止
広告識別子(IDFA)広告視聴時、追跡を許可した場合のみパーソナライズ広告の配信(Google AdMobが処理)
端末・OS情報、アプリバージョン起動時の更新確認アプリ更新の配信(Expoが処理)

2. 写真の取り扱い(重要)

読み取りを依頼すると、写真はOpenAIへ送信され解析されます。返ってくるのは結果(スコアデータ)のみです。

写真は本サービスのサーバーに保存されません。送信後にメモリから破棄され、データベースやファイルストレージには一切記録されません。写真の原本はお使いの端末内にのみ保管され、記録を削除すると一緒に消えます。ログインしても写真がクラウドへ上がることはありません。

写真にはスコア表以外の人物や背景が写る場合があります。必要な範囲のみ撮影されることをおすすめします。

3. 端末識別子

1日の無料読み取り回数を数えるため、初回起動時にランダムに生成した値を端末に保存します。広告識別子(IDFA)や端末固有番号ではありません。パーソナライズ広告に用いるIDFAはこの値とは別のもので、追跡を許可した場合に限り広告提供者(Google AdMob)が扱います(7項)。

この値はiOSのキーチェーンに保存されるため、アプリを削除しても残り、再インストールすると同じ値が復元されます。再インストールで無料回数がリセットされるのを防ぐための設計です。キーチェーンを初期化すると新しい値が作られます。機種変更の際、暗号化された端末バックアップから復元すると同じ値が新しい端末に引き継がれます。バックアップなしで新規設定した場合は新しい値が作られます。

この識別子とともに日別の読み取り回数がサーバーに記録されます。所定のヘッダーを欠く不正な要求に限り、復元できない形にハッシュ化したIPアドレスが一時的な識別子として使われることがあります。

ログイン中は端末識別子ではなくアカウント識別子で回数を数えます。広告報酬を付与する際、この値(ログイン時はアカウント識別子、未ログイン時は端末識別子)は広告提供者に送信され、検証信号として返ってきます—誰に付与するかを知る必要があるためです。運用ログにはこの値をそのまま残さず、復元できない形に短縮して記録します。

Tossミニアプリ版では、Tossが提供するすでにハッシュ化された利用者識別キーをそのまま同じ用途に使います。この値はTossアカウントに紐づくため、アプリ削除や端末変更後も維持されます。

4. アカウント

ログインは任意です。ログインしなくてもすべての読み取り機能を利用できます。ログインしない場合、記録は端末内にのみ保存され、アプリの削除や機種変更では復元できません。

AppleまたはGoogleでログインすると、メールアドレスと氏名を受け取り認証基盤(Supabase)に保存します。パスワードは扱いません。

5. 同期

ログイン中はゲーム記録がサーバーに保存され、端末間で引き継がれます。保存される内容はプレイヤー名と補助表記・フレームごとのスコア・メモ・場所・試合日時・どのプレイヤーが「自分」かです。写真は含まれません。

プレイヤー名はスコア表から読み取った値で、他人の名前が含まれる場合があります。結果画面で修正または削除できます。

6. 共有リンク

記録を共有すると、プレイヤー名と補助表記・スコア・メモ・場所がサーバーに保存され、ランダムなアドレスが発行されます。

リンクを知っている人は誰でも閲覧できます。検索には表示されませんがログインは不要で、メッセンジャーのリンクプレビューにプレイヤー名が表示されることがあります。共有リンクは作成から180日を過ぎると開けなくなり、保存された内容も毎日実行される整理処理で削除されます。それより前に削除が必要な場合は、リンクのアドレスを添えてお問い合わせください。

7. 広告

無料の読み取り回数を使い切ると、リワード広告を視聴して1回追加できます。視聴しなくても翌日に無料回数が回復し、サブスクリプションに加入すると広告は表示されません。

iOSアプリの広告はGoogle AdMobが配信します。AdMobは広告配信と不正防止のため、端末・広告識別子、おおまかな位置(IPに基づく国レベル)、広告の操作履歴を処理します。詳細はGoogleのパートナーサイトポリシーをご覧ください。

パーソナライズ広告は、追跡を許可した場合にのみ表示されます。iOSの追跡許可(ATT)は初回起動時に一度表示されます(広告表示より前に確認します)。許可しない場合、アプリは関心に基づかない広告のみを要求し、広告識別子の第三者提供も行われません。許可しなくてもすべての機能をそのまま利用でき、報酬も同じように受け取れます。設定 → プライバシーとセキュリティ → トラッキング でいつでも変更できます。

報酬が正しく付与されたか確認するため、広告提供者から送られる検証信号をサーバーが受け取り処理します。その際取引番号のみを保存し、同じ広告で二度報酬を受け取れないようにします。この番号は広告提供者が生成したランダムな値で、誰のものか分かる情報は一緒に保存されません。付与対象の識別子は読み取り回数の記録に反映されるだけで、この表には残らず、サーバーログにも短縮した形でしか残りません。

Tossミニアプリ版ではTossが提供するリワード広告が表示され、その配信と報酬の処理はTossが行います。

8. 決済

サブスクリプションの決済はApple App Storeが処理します。カード情報などの決済手段は当方では受け取りません。状態確認にRevenueCatを利用し、サーバーにはアカウント識別子・有効かどうか・有効期限のみを保存します。

9. 第三者提供・委託

下表の委託は本サービスに代わって処理するだけの場合、第三者提供は受け取る側が自らの目的にも用いる場合です。

区分事業者目的提供する情報
委託OpenAIスコア表の読み取りスコア表の写真
委託Supabaseアカウント・記録・利用状況の保存アカウント情報、ゲーム記録、端末識別子
委託Vercelサーバー運用アクセスログ(IPを含む)
委託Expoアプリ更新の配信IP、端末・OS情報、アプリバージョン
委託RevenueCatサブスクリプション状態の確認アカウント識別子、状態
第三者提供Google AdMob
(報酬の検証)
広告報酬のサーバー検証付与対象の識別子(送信し、そのまま返ってきます)
第三者提供Google AdMob
(パーソナライズ広告)
関心に基づく広告配信広告識別子(IDFA)、IP(国レベル)、広告の操作履歴 — 追跡を許可した場合のみ
第三者提供Apple / Googleログイン認証ログイン要求(アプリ・端末の情報)。メールアドレスと氏名は逆に当方が受け取る値です
提供を受けるToss(ビバリパブリカ、韓国国内)ミニアプリ運用・広告Tossから提供を受けた匿名識別キー(Toss版のみ)

9-1. 国外移転

以下の事業者は、本サービスの運営国である大韓民国の国外にデータを保持しています。個人情報保護法第28条の8に基づきお知らせします。Tossは韓国国内の事業者のため、この表には含まれません。記載する国は各社の本社所在地ではなく、実際にデータが処理されるリージョンです。

移転先連絡先移転先の国移転する項目時期・方法目的 / 移転先での保有・利用期間
OpenAI, L.L.C.privacy@openai.com米国スコア表の写真読み取り依頼のたびにHTTPSで送信スコアの読み取り / 処理後ただちに破棄。ただしOpenAIが不正利用の点検のため最大30日保管する場合があります
Supabase, Inc.privacy@supabase.ioシンガポール
(リージョン ap-southeast-1)
アカウント情報、ゲーム記録、利用状況、サブスクリプション状態、共有スナップショット登録・保存時にHTTPSで送信アカウント・記録の保管 / アカウント削除まで。共有スナップショットは180日、未ログインの利用履歴は90日
Vercel, Inc.privacy@vercel.com米国
(リージョン iad1)
アクセスログ(IPを含む)。広告報酬の検証呼び出しに限り、付与対象の識別子が要求URLに含まれます要求ごとに自動取得サーバー運用 / 1時間(VercelのHobbyプランにおけるランタイムログの保管期間)。当方が別途取得・蓄積することはありません
Google LLC (AdMob)Googleの個人情報窓口米国付与対象の識別子(常時)。広告識別子(IDFA)・IP(国レベル)・広告の操作履歴は追跡を許可した場合のみ広告要求時に送信広告配信・報酬検証 / 本サービスがAdMobの利用を終了するまで。当方はこれらの項目を保存しません
RevenueCat, Inc.support@revenuecat.com米国アカウント識別子、サブスクリプション状態購入時に送信購入状態の確認 / アカウント削除まで(アカウント削除時に購読者記録の削除も要請します)。ただしRevenueCatが会計・返金対応のため取引記録を自社方針に従い保管する場合があります
Apple Inc.Appleの個人情報窓口米国ログイン要求(アプリ識別子、端末・接続情報)。メールアドレスと氏名はAppleが当方に渡す値ですログイン時に送信本人認証 / 本サービスがAppleログイン連携を終了するまで
Google LLC(ログイン)Googleの個人情報窓口米国ログイン要求(アプリ識別子、端末・接続情報)。メールアドレスと氏名はGoogleが当方に渡す値ですログイン時に送信本人認証 / 本サービスがGoogleログイン連携を終了するまで
Expo (650 Industries, Inc.)Expoの個人情報窓口米国IP、端末・OS情報、アプリバージョン起動時の更新確認で送信アプリ更新の配信 / 本サービスがExpoの利用を終了するまで

上記の連絡先で連絡がつかない場合は、14項の個人情報保護責任者までお知らせください。代わってお取り次ぎします。

国外移転をお望みでない場合は、本サービスの利用を停止しアカウントを削除いただけます。パーソナライズ広告のための第三者提供は追跡を許可しなければ一切行われず、その場合もすべての機能をご利用いただけます。ただし読み取り機能は国外での処理なしには提供できません。

10. 保管期間

10-1. 破棄の手続および方法

保有期間が経過し、または処理目的が達成された個人情報は遅滞なく破棄します。電子ファイルはデータベースから削除し、復元しません。紙の文書は扱いません。

期間の定めがある項目は毎日実行される整理処理が削除します — 期限切れの共有スナップショット、90日を過ぎた広告の取引番号、90日を過ぎた未ログインの利用履歴が該当します。アカウントを削除すると、それに紐づく記録・利用回数・サブスクリプション状態はその場で消去されます。

自動削除の対象外となる項目(まだ期限切れでない共有リンク)は、下記へご請求いただければ対応します。

10-2. 安全性確保の措置

11. 利用者の権利

利用者は開示・訂正・削除、および処理の停止を請求できます。読み取りは自動処理ですが、その結果によって利用者に不利益な決定を行うことはなく、結果は画面上でいつでもご自身で修正できます。

記録はアプリ内で削除でき、ログイン中であればサーバー上の複製も同時に消えます。削除時にオフラインだった場合は次に接続したときにサーバーから削除されます。削除した端末で再び現れることはなく、他の端末からはサーバーへの削除が反映された後に消えます。

アカウントはアプリの設定画面から削除できます(設定 → アカウントを削除)。アカウントに紐づくゲーム記録・サブスクリプション情報・利用履歴が消去され、決済確認に用いるRevenueCatの購読者記録も併せて削除を要請します。元に戻せません。この端末に残る記録は削除されず、個別に削除できます。

次の項目はアカウントと紐づいていないため同時には消えません:すでに作成した共有リンク(180日後に自動削除。それより前に消す場合は下記へご請求ください)、ログイン前にゲストとして蓄積された利用履歴(90日後に自動削除)、広告の取引番号(90日後に自動削除。誰のものか特定できないため個別削除はできません)。

保管情報の開示・訂正、処理の停止、共有リンクの早期削除は下記までご連絡ください。

12. お子さまについて

本サービスは14歳未満の方を対象としておらず、お子さまの個人情報を意図的に収集することはありません。

13. 変更

本ポリシーを変更した場合は、改定日とともに本ページに掲示します。

14. 個人情報保護責任者・お問い合わせ

個人情報の取り扱いに関するお問い合わせ、開示・訂正・削除・処理停止のご請求は下記までご連絡ください。受付後、遅滞なく回答いたします。

サービス名テンフレーム (Tenframe)
商号ドラカリス(드라카리스)
代表者キム・ミンソク
事業者登録番号584-21-02501(大韓民国)
個人情報保護責任者キム・ミンソク
メールminseok1061@gmail.com

15. 苦情の申し立て

本サービスは大韓民国で運営されています。個人情報の取り扱いについて苦情がある場合は、下記のいずれかにご相談いただけます。お住まいの国の監督機関へのご相談も可能です。