DUPAMO Baby Sleep White Noise Privacy Policy
Last Updated: September 11, 2026
Effective Date: September 1, 2026
SGTHL (the “Operator”) establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea and other applicable laws and regulations in order to protect users’ personal information and process such information safely.
This Privacy Policy applies to the “DUPAMO Baby Sleep White Noise” mobile application (the “App”) and related services provided by the Operator.
The App is intended for use by parents, legal guardians, and other adult caregivers to create a comfortable rest and sleep environment for infants and young children.
The App is not designed on the assumption that infants or young children will directly use the App. The Operator does not operate the App for the purpose of directly collecting personal information from infants or children under the age of 14.
Article 1 (Purposes of Processing Personal Information)
The Operator processes only the minimum amount of personal information necessary for the following purposes:
Providing App features such as lullabies, white noise, nature sounds, classical music, recommended sounds, sound mixing, timers, and related functions
Providing DUPAMO character customization and completed-image saving features
Verifying premium subscription status and restoring purchases
Analyzing App usage, improving features and UI, and enhancing service quality
Analyzing App errors and crashes and improving service stability
Preventing fraudulent use and security threats
Handling user inquiries, complaints, refunds, and disputes
Complying with obligations under applicable laws and regulations
The Operator will not use personal information for purposes incompatible with those stated above. If the purposes of processing change, the Operator will take measures required under applicable laws and regulations.
Article 2 (Categories of Personal Information Processed)
1. Account Registration
The App does not require account registration.
Users are not required to provide personal information such as their name, telephone number, email address, or resident registration number in order to use the basic functions of the App.
2. Google Analytics for Firebase
The Operator uses Google Analytics for Firebase to analyze App usage and improve the service.
The following information may be processed:
Firebase installation identifiers
App instance-related identifiers
Device model
Operating system and version
App version
Language and country
App launch and session information
Screen usage information
Feature usage events
Events relating to use of sounds, presets, and other App features
The Operator does not directly register users’ actual names, telephone numbers, email addresses, or personal information of infants or children as user identifiers in Firebase Analytics.
The retention period for user-level and event-level data is configured to 14 months.
3. Firebase Crashlytics
The Operator uses Firebase Crashlytics to analyze App errors and crashes and improve service stability.
The following information may be processed:
Crashlytics Installation UUID
Firebase installation identifiers
Firebase session identifiers
App crash and error logs
Time of crash occurrence
Stack traces
App bundle or package identifiers
App version
Device model
Operating system and version
Technical device status
Other technical information necessary for error diagnosis
In accordance with Google’s policies, Crashlytics crash-related data and associated identifiers are retained for 90 days, after which the deletion process begins.
4. App Marketplace Subscriptions and Payments
When a user makes a subscription or payment through the Apple App Store or Google Play, the following information may be processed:
Product identifier
Transaction identifier
Purchase token
Purchase status
Subscription start date
Renewal status
Expiration date
Cancellation or termination status
The Operator uses only the minimum transaction-status information necessary to verify subscription entitlements and restore purchases.
Actual payment method information, such as credit or debit card numbers, bank account information, and payment passwords, is processed directly by Apple or Google, and the Operator does not directly collect or store such information.
5. Customer Support Inquiries
When a user contacts customer support by email or other available channels, the following information may be processed:
Email address
Name or nickname voluntarily provided by the user
Contents of the inquiry
Attachments
Device model
Operating system
App version
Purchase or subscription verification information voluntarily submitted by the user
Such information is used only for handling inquiries, complaints, refunds, and disputes.
Article 3 (DUPAMO Customization and Completed Images)
DUPAMO customization is a feature that allows users to customize the DUPAMO character by selecting clothing and decorative elements.
Completed DUPAMO images created by users are stored only on the user’s device. In the current version of the App, such images are not transmitted to or stored on the Operator’s servers, Firebase, or any other external server.
The completed-image saving feature does not photograph the user, an infant or child, or the surrounding environment.
The Operator does not collect photographs of users, infants, or children through the DUPAMO customization feature.
Depending on the operating system, permission to access the device’s photo library or media storage may be required to save a completed image.
Such permission is used only to the extent necessary to save the completed image selected by the user to the device.
If a user shares a completed image with a social media service, messaging service, or other external service using the device’s sharing function, the privacy policy of the relevant external service will apply.
Article 4 (App Settings Information)
The following App settings are, in principle, processed locally on the user’s device:
Sound selections
Sound volume
Preset selections
Timer settings
Playback-related settings
DUPAMO customization status
Other user settings
The Operator does not store users’ personal settings on a separate Operator-controlled server unless such storage is necessary to provide the service.
However, non-identifying or pseudonymous usage events indicating that a particular feature was used may be processed through Firebase Analytics for analytical purposes.
Article 5 (Personal Information of Infants and Children Under 14)
The App is an application for which adult caregivers are the direct users.
Infants and young children are recipients of audio content such as lullabies, white noise, and nature sounds played by adult caregivers and are not intended to be direct users of the App.
DUPAMO customization and completed-image saving features are also intended to be operated directly by adult users.
The Operator currently does not provide functions that collect the following personal information of infants or children under the age of 14:
Name
Date of birth
Email address
Telephone number
Facial photograph
Voice
Precise location information
Sleep records
Health information
Developmental information
Other information that can directly identify a child
If the Operator becomes aware that personal information of a child under the age of 14 has been unintentionally collected without appropriate authorization, the Operator will promptly delete the information or take other protective measures as required by applicable law.
If the Operator introduces features in the future that process an infant’s or child’s name, date of birth, photograph, voice, sleep records, health information, or other personal information, the Operator will revise this Privacy Policy before such features are implemented and, where required by applicable law, obtain the consent of the child’s legal guardian.
If the App’s intended direct users change in the future to include children, the Operator will implement all necessary measures required under applicable laws and applicable App Marketplace child-protection policies before making such changes.
Article 6 (Retention and Use Period of Personal Information)
The Operator will promptly destroy personal information when the purpose of processing has been fulfilled or the applicable retention period has expired.
The main retention periods are as follows:
Google Analytics for Firebase
User-level and event-level data: 14 months
Firebase Crashlytics
Crash-related data and associated identifiers: Deletion process begins after 90 days
Customer Support
General inquiries: 1 year after completion of handling
However, records relating to consumer complaints or disputes may be retained for 3 years where required by applicable laws.
Records Required to Be Retained Under Applicable Laws
Records relating to contracts or withdrawal of offers: 5 years
Records relating to payment and supply of goods or services: 5 years
Records relating to consumer complaints or dispute resolution: 3 years
Records relating to labeling and advertising: 6 months
Information not directly retained by the Operator is not included within the Operator’s retention obligations.
Article 7 (Provision of Personal Information to Third Parties)
The Operator processes personal information within the scope of the purposes specified in this Privacy Policy and, in principle, does not arbitrarily provide personal information to third parties.
Personal information may be provided within the scope permitted by applicable law in the following circumstances:
Where the user has given prior consent
Where specifically permitted or required by applicable law
Where an investigative or administrative authority makes a lawful request in accordance with applicable procedures
Where necessary under applicable law to protect a person from an imminent threat to life or physical safety
Personal information processed by Google analytics and error-diagnosis services and by Apple or Google App Marketplaces is governed by this Policy and by the privacy policies of those providers.
Article 8 (Outsourcing of Personal Information Processing and International Transfers)
The Operator uses external services for usage analytics and error diagnosis. In connection with these services, certain information may be transferred outside the Republic of Korea for processing.
Recipient
Google LLC
Services Used
Google Analytics for Firebase
Firebase Crashlytics
Personal Information Transferred
The information described in Article 2 of this Privacy Policy in connection with each applicable Google service.
Purposes of Transfer
Analysis of App usage
Improvement of App functions and UI
Error and crash analysis
Maintenance of service stability
Countries of Transfer
The United States and other countries in which Google or its service providers operate data-processing facilities.
The actual country in which information is processed may vary depending on Google’s global service infrastructure.
Timing and Method of Transfer
Information may be automatically transmitted through encrypted communications when the App is launched or used, or when an error or crash occurs.
Retention and Use Period
Google Analytics for Firebase: User-level and event-level data — 14 months
Firebase Crashlytics: Deletion process for crash-related data begins after 90 days
Legal Basis for International Transfer
The Operator may process personal information outside the Republic of Korea where such overseas processing, outsourcing, or storage is permitted under applicable laws or based on the user’s consent.
Where separate consent is required by applicable law for an international transfer of personal information, the Operator will provide the required notice and obtain such consent.
Article 9 (Advertising and Advertising Identifiers)
The App does not display advertisements and does not embed any advertising SDK.
The Operator does not collect or use mobile advertising identifiers such as IDFA or AAID, and does not track users across apps or websites owned by other companies.
Installation identifiers used by the analytics and crash-diagnosis services described in Article 2 are not advertising identifiers and are not used for advertising purposes.
Article 10 (Destruction of Personal Information)
The Operator will promptly destroy personal information once the purpose of processing has been fulfilled or the applicable retention period has expired.
Electronic files are deleted using methods designed to make recovery or restoration difficult.
If paper documents containing personal information exist, they will be destroyed by shredding, incineration, or another secure method.
Deleting the App may terminate processing of settings and other App data stored locally on the device.
DUPAMO completed images saved by the user to the device’s photo library or other storage may remain after the App is deleted and may be deleted directly by the user.
Deleting the App does not automatically cancel a subscription through the Apple App Store or Google Play. Subscriptions must be separately cancelled through the relevant App Marketplace subscription-management feature.
Article 11 (Rights of Data Subjects and How to Exercise Them)
Users may exercise the following rights regarding their personal information in accordance with applicable laws:
Request access to information regarding whether and how personal information is processed
Request correction of personal information
Request deletion of personal information
Request suspension of processing
Withdraw consent to processing
Requests to exercise privacy rights may be submitted through the customer support email address specified in Article 14.
The Operator may verify the identity of the requesting person or the authority of a lawful representative and will process the request in accordance with applicable law.
Certain requests may be restricted where applicable laws require retention of the relevant information or where another lawful exception applies.
Where personal information is independently processed by third parties such as Google or Apple, users may be required to exercise their rights through the privacy procedures provided by those third parties.
Article 12 (Measures to Ensure the Security of Personal Information)
The Operator implements technical and administrative safeguards required under applicable laws to prevent personal information from being lost, stolen, leaked, forged, altered, or damaged.
Such measures include:
Minimizing the amount of personal information processed
Limiting access rights to personal information
Managing personnel responsible for personal information processing
Using encryption and secure communication methods for data transmission
Applying security updates and managing vulnerabilities
Monitoring errors and abnormal access
Securely destroying personal information after expiration of the applicable retention period
Reviewing privacy and security practices of external service providers
If a personal information breach or similar incident occurs and notification is required under applicable law, the Operator will notify affected users and the relevant authorities in accordance with legally required procedures.
Article 13 (External Services)
The App uses the following external services:
Google Analytics for Firebase
Firebase Crashlytics
Apple App Store
Google Play
Where an external provider independently processes personal information, the privacy policy and data-protection practices of that provider may apply.
Article 14 (Privacy and Customer Support Contact)
Requests concerning privacy protection, exercise of privacy rights, complaints, and remedies may be submitted using the contact information below.
Business Name: SGTHL
Representatives: Sang Gul Lee, Tae Hoon Yoo
Department: SGTHL Customer Support
Customer Support Email: sgthl20@gmail.com
Customer Support Telephone: 0502-1918-0106
Address: 101, 1 Nongol-ro 63beon-gil, Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
Telephone consultation is not provided. Service and privacy inquiries should be submitted by email.
Article 15 (Remedies for Personal Information Infringement)
Users may contact the following institutions in the Republic of Korea for consultation or remedies relating to personal information infringement:
Personal Information Infringement Report Center: 118
Personal Information Dispute Mediation Committee: 1833-6972
Supreme Prosecutors’ Office: 1301
Korean National Police Agency: 182
These organizations are independent of the Operator. Users may first submit privacy-related inquiries and requests to the Operator through the customer support email address.
Article 16 (Changes to this Privacy Policy)
The Operator may amend this Privacy Policy as a result of changes to applicable laws, App functions, personal information processing practices, or external services.
If this Privacy Policy is amended, the Operator will provide notice of the changes and their effective date through the App, a publicly accessible webpage, or another appropriate method.
Where a change materially affects users’ rights or requires separate consent under applicable law, the Operator will provide prior notice or obtain consent in accordance with applicable legal requirements.
This Privacy Policy will be revised before any of the following features are introduced:
Account registration
Storage of an infant’s or child’s name or date of birth
Uploading photographs or voice recordings of infants or children
Storage of sleep records
Processing of health or developmental information
Collection of precise location information
Server storage or synchronization of completed DUPAMO images
Introduction of new advertising, analytics, or artificial intelligence SDKs
Any other new functionality involving personal information processing
Business Information
Business Name: SGTHL
Representatives: Sang Gul Lee, Tae Hoon Yoo
Business Registration Number: 293-01-01743
Mail-Order Sales Registration: No. 2026-Seongnam Sujeong-0522
Address: 101, 1 Nongol-ro 63beon-gil, Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
Customer Support Telephone: 0502-1918-0106
Customer Support Email: sgthl20@gmail.com
Supplementary Provision
This Privacy Policy shall take effect on September 1, 2026.