SweetPulse (“we”, “us”) operates the mobile application HolyQ(the “Service”). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have.
1. Information we collect
| Category | Items |
|---|---|
| Account | Email (Google/Apple OAuth), nickname, year of birth |
| Automatically collected | Country code (estimated from IP), device language, OS, app version |
| Service usage | Level, XP, ELO rating, win/loss record, titles, talents/coins balance, achievements, friend relationships, chat messages, wrong-answer notes, chapter progress, daily challenge scores |
| Advertising identifier | AAID/IDFA — only when you grant consent (e.g., App Tracking Transparency). If you decline, only non-personalized ads are served. |
| Push token | Expo push token — only if you allow notifications |
| Purchase data | Apple App Store / Google Play transaction ID and subscription state. Payment instrument details are handled by Apple/Google directly and not stored by us. |
2. How we use information
- Account creation, authentication, and account management
- Providing core features: 1-on-1 battles, group battles, rankings, friends
- Processing in-app purchases (HolyQ Plus subscription, talent packs, season pass) and refunds
- Serving personalized or non-personalized advertising
- Sending push notifications (daily challenge, daily bread, friend activity)
- Preventing abuse, handling reports, and maintaining service integrity
- Complying with legal obligations and handling disputes
3. Children
We verify age at sign-up and block accounts for users under 13 years old. Users aged 13–17 do not see full-screen interstitial ads, and certain social features (such as chat) are restricted or disabled. We do not knowingly collect personal information from children under 13. This Service is designed to comply with COPPA, GDPR-K, and the Korean Personal Information Protection Act.
4. Retention
| Data | Retention period |
|---|---|
| Account information | Until account deletion. All personal data is destroyed within 30 days after a deletion request. |
| Chat messages | Automatically deleted 90 days after sending. |
| E-commerce records | 5 years, as required by the Korean Act on Consumer Protection in Electronic Commerce (records of payment and supply of goods, complaint/dispute records). |
| Abuse-prevention logs | Up to 1 year for fraud-prevention purposes. |
5. Sub-processors & international transfers
We rely on the following service providers to operate the Service. They process personal data only to the extent necessary to perform their services for us.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, storage, realtime | United States |
| Upstash, Inc. | Matchmaking queue and ranking cache (Redis) | United States |
| Google LLC (AdMob) | Ad serving and measurement | United States |
| RevenueCat, Inc. | Subscription / IAP entitlement management | United States |
| Apple Inc., Google LLC | In-app purchase processing | United States |
| Expo / 686, Inc. | Push notification delivery | United States |
| Google LLC (Cloud Translation) | Chat auto-translation (planned post-launch) | United States |
For users in the EEA/UK, transfers are made under appropriate safeguards including the European Commission’s Standard Contractual Clauses where applicable. The categories of data transferred are listed in Section 1.
6. Your rights
Subject to local law (GDPR, CCPA, the Korean PIPA, etc.) you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Restrict or object to processing
- Receive your data in a portable format (data portability)
- Withdraw consent at any time, where processing is based on consent
You can delete your account directly in the app at Settings → Privacy → Delete account. For any other request, contact us at developer@sweetpulsegames.com. We will respond within 30 days.
7. Security
- TLS/HTTPS encryption in transit
- Row-level security (RLS) at the database layer
- Least-privilege access and separated admin accounts
- Server-side validation of sensitive game logic (e.g., answer correctness)
- Regular security reviews and dependency patching
8. Advertising identifiers
We display ads via Google AdMob. On iOS we use the IDFA for personalized advertising only if you grant App Tracking Transparency consent; otherwise non-personalized ads are shown. On Android you can reset or opt out of the advertising ID in your device settings. HolyQ Plus subscribers are not shown interstitial ads.
9. Cookies & similar technologies
As a mobile application, the Service does not use traditional web cookies. We do store authentication tokens in the device’s secure storage (AsyncStorage / Keychain) to maintain your session.
10. Contact
| Company | SweetPulse |
| Privacy Officer | Representative, SweetPulse |
| developer@sweetpulsegames.com |
11. Changes to this Policy
If we make material changes to this Policy, we will notify you in the app or on this page at least 7 days before the changes take effect (30 days for changes that materially affect your rights).