minivlog Privacy Policy
2026-09-04
This Privacy Policy applies to your use of minivlog (the "App" or the "Service"), a mobile application provided by Hobbyist (the "Operator").
Last updated: September 4, 2026
At a glance
• There is no sign-up. We do not ask for your name, email address, or phone number. • Photos and videos you record or import, vlogs in progress, caption templates, and settings are stored only on your device. The Operator cannot see this material. • Only when you create a finished video are your chosen photos, videos, music, captions, and edit values sent over an encrypted connection to a rendering server located in the Republic of Korea, and they are deleted as soon as the job ends. • We use advertising (Google AdMob) and usage analytics and error diagnostics (Firebase). Photo, video, and music files and caption text are never sent to analytics or advertising services. • We do not perform face recognition or voice recognition, collect location data, or train AI on your media. • The Operator does not sell personal information to third parties.
1. Purpose of this Policy
This Policy explains how minivlog collects, uses, stores, and protects your information. The Operator complies with the Personal Information Protection Act and other laws of the Republic of Korea, and for users in the European Economic Area (EEA) also complies with applicable law including the General Data Protection Regulation (GDPR).
minivlog is designed around collecting as little personal information as possible. Content you create stays on your device by default and passes through a server only while a video you requested is being produced.
2. Information we collect
A. Device permissions used to provide App features
The App may use the following permissions for its core features. If you decline a permission, everything except that feature remains available.
• Camera: needed to record photos and videos. • Microphone: needed to capture sound with your video. • Photo library: needed to import photos and videos from your gallery and to save finished videos. • App tracking (iOS): only with your permission, the advertising identifier (IDFA) is used for personalized ads. All App features remain available if you decline.
Photos and videos you record or select (including audio), capture times, file size, resolution and duration, trim ranges, brightness, filters and placement, caption text, typeface, color and position, project structure, chosen music files and file names, favorites, caption templates, and language, theme, camera, and export settings are stored on your device. They are deleted when you delete them in the App, clear the App's data, or uninstall the App. Depending on your operating system's backup settings, they may be included in a device backup held in your Apple or Google account.
B. Information sent to the server when a video is created
When you tap "Create video," the following is sent to a rendering server located in the Republic of Korea.
• The photos and videos (including audio) and music files selected for the export • Caption text and edit values such as filters, brightness, aspect ratio, playback ranges, placement, and volume
Uploaded material is deleted immediately after rendering succeeds or fails. Finished videos, and any files left behind by a network fault, are deleted automatically within 24 hours of creation. The Operator does not open this material or use it for any other purpose.
C. Anonymous account information
The first time you export a video, a random anonymous user ID is created so that uploaded files can be kept separate and secure per user. Alongside it, authentication and access records are processed, including access and refresh tokens, session creation and refresh times, IP address, and user agent. This information does not identify you personally and is deleted one year after your last use.
D. Usage analytics and error diagnostics
To improve service quality and resolve errors, we use Google Analytics for Firebase, Firebase Crashlytics, and our own error logs. For users in the EEA, analytics data is collected only after consent where required by applicable law.
Information that may be collected: • App instance identifier, Crashlytics installation UUID, Firebase installation ID and session ID, anonymous user ID (where one has been created) • Device model, operating system and version, language, App version, and approximate country-level location (based on IP) • Screen navigation, App launch and feature-use events, the type, aspect ratio, and length of recorded media, editing choices, export success or failure, and clip and caption counts • Crash and error times, error messages and stack traces, screen paths, App state, and CPU, memory, and disk state. Error contents may incidentally include a file name you chose or an internal device path.
Photo, video, and music files and caption text are not transmitted.
Retention: Analytics user and event data 2 months, Crashlytics 90 days, our own error logs 90 days
E. Advertising information
The Service displays Google AdMob advertising so that it can be offered free of charge. The following may be processed to serve and measure ads.
• IP address and the approximate location derived from it • Advertising ID (Android) or, with your permission, the IDFA (iOS), and app-scoped and developer-scoped device identifiers • Ad interactions such as App launches, taps, impressions, and views, ad data, and SDK performance and diagnostic information
You can reset or delete your advertising ID or limit personalized advertising in your device settings. Ads may still appear if you opt out of personalization, but they may be less relevant to your interests. Retention follows Google's policies, your advertising settings, and applicable law.
F. Inquiry information
If you contact us through the KakaoTalk channel, your KakaoTalk profile information, the content of your inquiry, any material you attach, and the reply history are processed. This is kept for one year after the inquiry is closed, or until the end of any longer period required by a pending dispute or by law.
G. Server access logs
For security and fault investigation, the rendering server automatically records IP address, request time, request method and path, response status, user agent, and processing time, and deletes them after 90 days.
Information we do not collect
The Service does not collect your name, email address, phone number, payment information, or precise location, and does not offer sign-up. We do not perform face or voice recognition, train AI on your media, or carry out profiling.
Photos, videos, and music may contain personal information such as the face, voice, or location of you or of others. The Operator does not separately recognize or classify this and uses it only to produce the video you requested. Please obtain any necessary consent before using material that includes other people.
3. Legal bases for processing
For users in the Republic of Korea, processing is carried out under Article 15 of the Personal Information Protection Act on the bases of performance of the service contract (device data processing, video rendering, anonymous authentication, responding to inquiries), the Operator's legitimate interests (security and stability through error logs and access logs), and your consent (personalized advertising, app tracking).
For users in the EEA, the bases under Article 6 of the GDPR are as follows. • Performance of a contract (Art. 6(1)(b)): video production, anonymous authentication, responding to inquiries • Legitimate interests (Art. 6(1)(f)): security, prevention of misuse, error diagnosis • Consent (Art. 6(1)(a)): usage analytics, personalized advertising. Consent may be withdrawn at any time.
4. Purposes of use
Information collected is used only for the following purposes. • Providing Service features such as recording, storage, editing, and video production • Separating uploaded files per user and controlling access • Improving App stability, resolving errors, and improving features and usability • Serving, personalizing, and measuring advertising, and preventing ad fraud • Receiving and answering inquiries and handling disputes • Responding to security incidents and preventing misuse
5. Where information is stored and processed
• Your device: photos, videos, vlog material, and settings are stored only on your device. • Republic of Korea (Seoul): the rendering server runs on cloud infrastructure located in the Republic of Korea, and the anonymous authentication and error log database runs in a Seoul region in the Republic of Korea. • United States and elsewhere: Google's analytics, diagnostic, and advertising information is processed in countries where Google operates facilities. See Section 7 for details.
6. Third-party services
The Operator entrusts processing to, or provides personal information to, the following service providers. Each provider processes information under its own privacy policy.
[Entrusted processing] • Authentication and database provider and its sub-processors: anonymous authentication, database operation, delivery of legal documents and app version information, storage of our error logs • Google LLC (Firebase): app usage analytics, crash and error analysis • Infrastructure hosting provider and its sub-processors: hosting for the rendering server located in the Republic of Korea • Kakao Corp.: delivery of inquiries and support through the KakaoTalk channel
[Provision to third parties] • Google LLC (AdMob) and participants in the advertising ecosystem: IP address, approximate location, advertising, app instance, and device identifiers, ad interactions and diagnostic information. For serving, personalizing, and measuring advertising and preventing fraud. Retention follows the policies of Google and each participant and your advertising settings.
Through its processing agreements, the Operator prohibits use beyond the stated purpose and sets out security measures, sub-processor management, and liability for incidents, and supervises its processors. Otherwise, personal information is provided only where you have consented in advance or where a law specifically permits it, and only to the extent necessary.
7. International transfers
[Google LLC] • Countries: the United States and other countries where Google or its processors operate facilities • Items transferred: the analytics, diagnostic, and advertising information described in Sections 2.D and 2.E • Purpose: usage analytics, error analysis, serving, personalizing, and measuring advertising, security and fraud prevention • Timing and method: transmitted over an encrypted network when the App is launched or used and when errors or ad requests occur • Retention: Analytics 2 months, Crashlytics 90 days, advertising data per Google's policies • Contact: https://support.google.com/policies/
[Authentication and database provider and its sub-processors] • Countries: Singapore (support), the United States (certain infrastructure and security vendors). The primary database is stored in a Seoul region in the Republic of Korea. • Items transferred: anonymous user ID, session, authentication and access records, our error logs • Purpose: authentication and access control, database operation, security and incident response • Timing and method: transferred over an encrypted network, or accessed from outside the country, when anonymous sessions are created or refreshed, when data is read or written, and during technical support • Retention: anonymous identifiers one year from last use, our error logs 90 days • Contact: contact the Operator using the details in Section 12 and you will be directed to the provider's contact point.
If you do not want your information transferred abroad, you may request that it stop using the contact details in Section 12, or stop using the Service. If you stop overseas access for anonymous authentication, video export becomes unavailable; if you stop Google analytics and advertising processing, advertising or some diagnostic features may be limited. Where the law requires consent for an international transfer, the Operator obtains that consent separately before transferring.
8. Your rights
You and your legal representative may request access to, correction or deletion of, suspension of the processing of, and withdrawal of consent for your personal information. Users in the EEA additionally have the rights to data portability, restriction of processing, objection to automated decision-making, and lodging a complaint with a supervisory authority under the GDPR.
• Device data: delete it directly using the App's individual delete functions or under Settings › Manage storage. • Camera, microphone, photo, and app tracking permissions: change these at any time in your device settings. • Personalized advertising: on iOS under Settings › Privacy & Security › Tracking, and on Android under Settings › Privacy › Ads, you can delete or reset your advertising ID or limit personalized advertising. • Anonymous account, error logs, and analytics and advertising data: request deletion or suspension of processing using the contact details in Section 12. Minimal additional verification, such as app installation identifiers, may be required to confirm your identity.
The Operator handles requests within the period set by applicable law and informs you of the outcome. Where the law permits, the exercise of a right may be restricted, and the reason will be explained. For requests made through an agent, documents confirming authority, such as a power of attorney, may be required.
9. Security measures
The Operator takes the following measures to prevent loss, theft, leakage, forgery, alteration, or damage of personal information. • Encryption in transit (HTTPS/TLS) • Randomized file names and storage separated by anonymous user ID, access token validation, and file ownership checks • Row-level access control in the database and the principle of least privilege • Deletion of rendering material immediately after the job, and automatic cleanup of leftover files within 24 hours • Restricted administrator access, retention of access logs, and regular review • Review of App and server vulnerabilities and of processor management
10. Children's personal information
The Service is not directed at children under 14 (under 16 in the EEA), and we do not knowingly collect children's personal information. If we learn that a child's personal information has been processed without valid consent from a legal representative, we delete it without delay. Please tell us using the contact details in Section 12.
11. Retention and destruction
The Operator destroys personal information without delay once the retention period ends or the purpose of processing is achieved. • Rendering material: deleted immediately after the job succeeds or fails. Leftover files and finished videos are deleted automatically within 24 hours of creation • Anonymous account and authentication records: one year from last use • Our error logs and server access logs: 90 days • Analytics user and event data: 2 months; Crashlytics: 90 days • Inquiry information: one year after the inquiry is closed • Device data: until you delete it or uninstall the App. Copies included in an operating system backup may need to be managed separately in your Apple or Google account settings.
Electronic files are deleted by a method that makes recovery difficult. Information that must be preserved under other laws is kept separately from other information and only for the statutory period.
12. Contact
• Data controller: Hobbyist • Privacy officer: Kim Yongil • Email: kyi910705@gmail.com • KakaoTalk channel: https://pf.kakao.com/_zYVxaX/chat
If you need advice about, or wish to report, an infringement of your personal information, you may contact the following Korean authorities. • Privacy Infringement Report Center: 118 (within Korea), https://privacy.kisa.or.kr • Personal Information Dispute Mediation Committee: +82-1833-6972, https://www.kopico.go.kr • Supreme Prosecutors' Office: 1301 (within Korea), https://www.spo.go.kr • Korean National Police Agency: 182 (within Korea), https://ecrm.police.go.kr
13. Changes to this Policy
If this Policy is amended because the law or the Service changes, we will give notice in the App or on the Operator's website beginning at least 7 days before the effective date. Changes that materially affect your rights will be notified separately by the method and within the period required by applicable law, and consent will be obtained where necessary. You can always read the current Policy under Settings › Privacy Policy in the App.
Language: This document is an English translation of the Korean original. If the two differ, the Korean version prevails.
Notice date: September 4, 2026 Effective date: September 4, 2026