개인정보 처리방침
Privacy Policy
- Effective
- Operator
- Fervorlab (펠보르랩)
Fervorlab (펠보르랩, the “Company”, “we”) establishes and publishes this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related concerns promptly and smoothly.
This Policy applies to the mobile game Tailbound (설화) — the iOS and Android apps and the Toss mini-app edition — the game website (tailbound.xyz), the Company website (fervorlab.com), and related services (collectively, the “Service”).
This English version is provided for convenience. In the event of any inconsistency between the Korean and English versions, the Korean version shall prevail.
Article 1Purposes of processing
We process personal information for the purposes below. Personal information is not used for any purpose other than those stated, and if a purpose changes we will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
- Providing the game service
- Storing, restoring and synchronizing game progress across devices (cloud save)
- Integrating platform game services (Google Play Games, Apple Game Center) such as leaderboards and achievements
- Connecting players and managing sessions for cooperative play (Co-op)
- Delivering in-game information such as notices and patch notes
- Managing purchases of paid content
- Confirming in-app purchases made through app stores (Apple App Store, Google Play, Toss) and delivering content
- Server-side verification and restoration of purchases, fraud prevention, and handling refund inquiries
- Improving quality and stability
- Diagnosing errors and crashes and fixing bugs
- Analyzing gameplay statistics for balancing, feature improvement and planning new content
- Detecting abnormal use (cheats, emulators, etc.) and keeping the Service stable
- Serving advertisements
- Displaying rewarded, interstitial and banner ads and granting rewards for watching ads
- Measuring ad impressions and clicks and preventing click fraud
- Responding to customer inquiries
- Receiving, verifying and responding to support requests, bug reports, refund requests and privacy-related requests
Article 2Personal information we process and how it is collected
We do not operate a membership sign-up process (email/password or social login) and do not collect your name, date of birth, phone number or location. The personal information processed to provide the Service is as follows.
| Category | Items processed | How it is collected |
|---|---|---|
| User identification (required) | Firebase anonymous authentication identifier (UID) and auth tokens | Generated automatically on first launch |
| Platform game services (optional) | Google Play Games player ID and display name, Apple Game Center player ID, submitted scores and achievements | When you choose to sign in with Play Games / Game Center |
| Cloud save (optional) | Game progress (currencies, upgrades, unlocks, run history and scores), last purchase information (product ID, time, platform, receipt identifier), platform player ID | Synchronized automatically during play for users signed in to a platform game service |
| Cooperative play (optional) | Room code, participants’ anonymous UIDs, connection data (WebRTC SDP and ICE candidates — includes IP addresses), presence, selected character, app version | Collected automatically when you create or join a co-op room |
| Purchases of paid content (optional) | Product ID, transaction (order) identifier, purchase token or receipt, purchase time, platform | Received from the app store when a purchase is completed |
| Usage analytics (required) | Analytics ID derived from the anonymous identifier via one-way hash (SHA-256), OS type and version, app version, language setting, gameplay events (stage progress, currency earned/spent, ads watched, purchases, etc.) | Collected automatically during play |
| Error diagnostics (required) | Error message and stack trace, app version, OS and device model, graphics renderer info, breadcrumbs of actions before the error, hashed user ID | Collected automatically when an error or crash occurs (release builds only) |
| Advertising (required) | Advertising identifier (Android Advertising ID / iOS IDFV and other device identifiers collected by the ad SDK), device information, ad impression/click/completion records | Collected automatically by the ad SDK (Google AdMob) |
| Network access logs (required) | IP address, access time, requested URL, device/app information (User-Agent) | Generated automatically when connecting to game servers and the CDN |
| Category | Items processed | How it is collected |
|---|---|---|
| User identification (required) | Game user key (hash) issued by the Toss app, Firebase anonymous UID | Collected automatically when the game runs inside the Toss app |
| Cloud save and leaderboard (required) | Game progress, scores | Synchronized automatically during play |
| Purchases of paid content (optional) | Toss order ID, product ID, payment status | Received from Toss when an in-app purchase is completed |
| Analytics, advertising and error diagnostics (required) | Same items as the iOS/Android apps above. Ads are Google AdMob ads served through the Toss SDK | Collected automatically |
| Category | Items processed | How it is collected |
|---|---|---|
| Visiting tailbound.xyz (required) | Cookies, IP address, browser and device information, pages visited, store-link click events | Collected automatically via Google Analytics |
| Visiting fervorlab.com (required) | IP address, access time, browser information (hosting server access logs) | Generated automatically — no analytics tools or cookies are used |
| Customer inquiries (optional) | Email address, content of the inquiry and any information you attach (screenshots, device info, purchase receipts, etc.) | When you contact us by email (contact@fervorlab.com) |
“Optional” items are processed only when you use the corresponding feature (platform sign-in, cloud save, co-op, purchases, inquiries); basic gameplay is not restricted if you do not use them. We do not directly collect or store payment instrument details such as card or bank account numbers — these are handled by the app store operators under their own policies.
Article 3Retention period
We process and retain personal information within the retention period required by law or agreed to at the time of collection. The retention periods are as follows.
| Category | Retention period | Basis |
|---|---|---|
| Anonymous authentication identifier, cloud save data, platform player ID | Until you request deletion or the game service is terminated | Destroyed once the purpose of providing the Service is fulfilled |
| Co-op room data (including connection data) | Expires 15 minutes after the room is created and is deleted automatically | Destroyed once session management is complete |
| Purchase records (product ID, transaction identifier, receipt identifier, etc.) | 5 years | Article 6 of the Act on Consumer Protection in Electronic Commerce (records on contracts, withdrawal, payment and supply of goods) |
| Customer inquiries and handling records | 3 years | Article 6 of the Act on Consumer Protection in Electronic Commerce (records on handling consumer complaints or disputes) |
| Usage analytics (Google Analytics) | Up to 14 months from collection (Google Analytics data retention setting) | Destroyed once statistical analysis is complete |
| Error diagnostics (Sentry) | 90 days from collection | Destroyed once diagnostics are complete (Sentry event retention) |
| Access logs (IP address, access time, etc.) | 3 months | Article 15-2 of the Protection of Communications Secrets Act |
Game progress is stored on your device by default; game data of users who do not use cloud save is not kept on our servers. Deleting the game deletes the data stored on your device.
Article 4Provision to third parties
We process personal information only within the scope set out in Article 1 and provide it to third parties only where permitted by Articles 17 and 18 of the Personal Information Protection Act, such as with your consent or where a special provision of law applies.
We do not currently provide personal information to third parties. The cases below are instances where platform operators process your personal information under the agreement you have directly entered into with them; we receive only the minimum information needed to provide the Service.
- App installation and in-app purchases through the Apple App Store, Google Play and Toss — each store’s privacy policy applies.
- Google Play Games and Apple Game Center sign-in, leaderboards and achievements — scores and achievements you submit may be visible to other users under the platform’s policies.
- Cooperative play — when connecting directly (peer-to-peer) with another player’s device, network connection information such as your IP address may be transmitted to that player.
Article 5Entrustment of processing
To provide the Service smoothly we entrust certain processing to the service providers below. In accordance with Article 26 of the Personal Information Protection Act, our agreements with these providers prohibit processing beyond the entrusted purpose and set out technical and organizational safeguards, restrictions on sub-processing, supervision, and liability, and we supervise that they process personal information safely.
| Processor | Entrusted work | Items |
|---|---|---|
| Google LLC (Firebase) | Anonymous authentication; storage of cloud save and co-op session data (Cloud Firestore) | Anonymous UID and tokens, cloud save data, co-op room data |
| Google LLC (Google Analytics) | Usage statistics and analysis | Hashed analytics ID, device and app information, gameplay events, website visit records |
| Google LLC (Google AdMob) | Ad serving and measurement | Advertising identifier, device information, ad impression/click/completion records |
| Functional Software, Inc. (Sentry) | Error and crash diagnostics | Error information, device and app information, hashed user ID |
| Cloudflare, Inc. | Co-op connection relay (TURN), purchase verification servers, content delivery (CDN) | IP address, anonymous auth token, purchase verification requests, access logs |
| Vercel Inc. | Website hosting (fervorlab.com, tailbound.xyz) | Website access logs (IP address, access time, browser information) |
| Viva Republica Inc. (Toss) — Toss mini-app edition only | Mini-app runtime, in-app payments and payment status checks, ad mediation, Game Center (leaderboards) | Toss game user key, order ID and payment status, scores |
If the entrusted work or the processor changes, we will disclose the change without delay through this Privacy Policy.
Article 6Cross-border transfer
To provide the Service, personal information is transferred to (entrusted to and stored by) processors located outside the Republic of Korea as set out below. Transfers use encrypted connections (TLS) in accordance with each provider’s security policies. Pursuant to Article 28-8 of the Personal Information Protection Act, we disclose the following.
| Recipient (contact) | Country and timing/method | Items transferred | Purpose and retention |
|---|---|---|---|
| Google LLC — Firebase, Google Analytics, AdMob, Google Play Games (privacy.google.com) | United States and other countries where Google data centers are located / transmitted over the network as the Service is used | Anonymous UID and tokens, cloud save data, co-op room data, analytics ID and usage events, advertising identifier, platform player ID | Authentication, storage, analytics and advertising / retention periods in Article 3 or until the processing agreement ends |
| Apple Inc. — Game Center, App Store (apple.com/legal/privacy) | United States / transmitted as the Service is used | Game Center player ID, scores and achievements, purchase receipts | Platform game services and payments / per Apple’s policies |
| Functional Software, Inc. (Sentry) (sentry.io/privacy) | United States / transmitted when an error occurs | Error information, device and app information, hashed user ID | Error diagnostics / 90 days from collection |
| Cloudflare, Inc. (cloudflare.com/privacypolicy) | United States and Cloudflare’s global edge network (including Korea, Japan, Singapore) / transmitted on co-op, purchase verification and content requests | IP address, anonymous auth token, purchase verification requests | Connection relay, purchase verification, content delivery / until the session ends or the access log retention period |
| Vercel Inc. (vercel.com/legal/privacy-policy) | United States / transmitted when visiting the websites | Website access logs | Website hosting / access log retention period |
You may refuse the cross-border transfer of your personal information. However, because these transfers are essential to running, saving, advertising in and diagnosing the game, refusing may limit the corresponding feature or the Service as a whole. Requests and inquiries regarding cross-border transfers can be made to the Privacy Officer in Article 13.
Article 7Destruction of personal information
- We destroy personal information without delay when it is no longer needed — for example when the retention period has elapsed or the purpose of processing has been achieved.
- Where personal information must continue to be preserved under other laws after the agreed retention period has elapsed or the purpose has been achieved, it is moved to a separate database or storage location.
- Procedure: personal information subject to destruction is identified and destroyed with the approval of the Privacy Officer.
- Method: electronic files are deleted using technical methods that make recovery impossible; paper records are shredded or incinerated.
Article 8Rights of data subjects and legal representatives, and how to exercise them
- You may at any time request access to, correction or deletion of, or suspension of processing of your personal information, and withdraw consent.
- Requests can be made by email (contact@fervorlab.com); we will act without delay (within 10 days of the request). To verify your identity we may ask for additional information such as the identifier shown in the in-game settings screen or a purchase receipt.
- Rights may be exercised through a legal representative or an authorized agent. In that case a power of attorney in the form prescribed by the Korean Personal Information Protection Commission (Form No. 11 of the Notice on Methods of Processing Personal Information) must be submitted.
- Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act, and deletion cannot be requested where other laws designate the information as subject to collection.
- We verify that the person making the request is the data subject or a legitimate representative.
Given the nature of the Service, you can also take the following actions yourself.
- Delete on-device data: uninstalling the game deletes the game data and anonymous authentication information stored on your device.
- Delete cloud save data and the anonymous account: email contact@fervorlab.com and we will delete the cloud save data and anonymous authentication account stored on our servers. Game progress cannot be restored after deletion. See the Account & Data Deletion guide (fervorlab.com/en/delete-account) for the full procedure.
- Platform game service data: profiles, scores and achievements stored in Google Play Games or Apple Game Center can be managed or deleted in the respective platform settings (Google Account settings, Apple ID settings).
- Personalized ads and advertising identifiers: as described in Article 12, you can reset or delete your advertising identifier or limit personalized ads in your device settings.
- Usage analytics: the analytics ID is one-way hashed so we cannot directly identify you from it; nevertheless, if you wish, email contact@fervorlab.com and we will request deletion of analytics data linked to that identifier.
Article 9Children under 14
- We are aware that the consent of a legal representative is required to collect personal information from children under 14, and we do not collect information that directly identifies a child, such as name or contact details, in the course of the Service.
- Children under 14 must use the Service with the consent of a legal representative, and purchases of paid content require the legal representative’s consent through features such as the app store’s parental approval.
- If we learn that personal information of a child under 14 has been collected without the consent of a legal representative, we will destroy it without delay. Legal representatives may request access to, correction or deletion of, or suspension of processing of the child’s personal information using the contact details in Article 13.
Article 10Security measures
In accordance with Article 29 of the Personal Information Protection Act, we take the following measures to keep personal information secure.
- Organizational measures
- Minimizing the number of people handling personal information and designating a Privacy Officer to manage and supervise processing
- Imposing contractual protection obligations on processors and supervising them
- Technical measures
- Encryption (TLS) on all network transmissions
- Access-control rules on the cloud database (Firestore Security Rules) — users can access only their own data
- One-way hashing (SHA-256) of user identifiers used for analytics and error diagnostics, and blocking transmission of directly identifying information such as email addresses and phone numbers
- Server-side verification of paid content purchases and use of short-lived tokens
- Least-privilege access to operational systems and service consoles, with multi-factor authentication
- Physical measures
- Cloud infrastructure holding personal information is operated in data centers with the processors’ access controls and security certifications (ISO 27001, SOC 2, etc.)
Article 12Behavioral information and personalized advertising
To serve in-game ads, we allow an advertising provider to collect and process behavioral information as follows.
| Item | Details |
|---|---|
| Advertising provider collecting behavioral information | Google LLC (Google AdMob) |
| Behavioral information collected | Advertising identifier (e.g. Android Advertising ID), device and OS information, IP address, in-app ad impression/click/completion records |
| How it is collected | Collected and transmitted automatically by the ad SDK included in the game app when an ad is requested |
| Purpose | Serving rewarded, interstitial and banner ads, delivering interest-based personalized ads, measuring ad performance and preventing click fraud |
| Retention | Per the advertising provider’s privacy policy (policies.google.com/technologies/ads) |
We do not provide directly identifying information such as your name or contact details to the advertising provider for personalized advertising, and we do not collect behavioral information for personalized advertising from children we know to be under 14.
You can block or allow personalized ads as follows. If you block personalized ads, non-personalized ads will still be shown.
- Android: Settings › Google › Ads › “Opt out of Ads Personalization” or “Delete advertising ID”
- iOS: Settings › Privacy & Security › Tracking › turn off “Allow Apps to Request to Track”; Settings › Privacy & Security › Apple Advertising › turn off “Personalized Ads”
- Google Account: change your ad personalization settings at myadcenter.google.com
Article 13Privacy Officer and handling of concerns
We have designated the following Privacy Officer, who is responsible for overall personal information processing and for handling complaints and remedying harm related to the processing of personal information.
| Item | Details |
|---|---|
| Privacy Officer | Wontae Hwang (Representative) |
| contact@fervorlab.com | |
| Address | 176-10 Sadang-ro, Dongjak-gu, Seoul, Republic of Korea |
You may direct any inquiries, complaints or requests for remedy regarding personal information arising from your use of the Service to the Privacy Officer. We will respond and act without delay.
Article 14Remedies for infringement of rights
To obtain relief from infringement of personal information, you may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, and other bodies. For other reports or consultations regarding personal information infringement, please contact the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118 / privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division: 1301 / www.spo.go.kr
- Korean National Police Agency, Cyber Bureau: 182 / ecrm.police.go.kr
A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to a request under Articles 35 (access), 36 (correction and deletion) or 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act (Central Administrative Appeals Commission: 110 / www.simpan.go.kr).
Article 15Changes to this Privacy Policy
- This Privacy Policy takes effect on September 1, 2026.
- If the Policy is added to, deleted from or amended due to changes in law, policy or the Service, we will announce the changes on our website (fervorlab.com/privacy) at least 7 days before they take effect. For material changes affecting your rights — such as changes to the items collected or the purposes of use — we will give at least 30 days’ notice.
- Previous versions can be found in the revision history below.
Revision history
- Full revision. Published in Korean and English; detailed cloud save, cooperative play, platform game services, advertising, error diagnostics and cross-border transfers for Tailbound.
- First established.
