PUBLIC DOCUMENT · 2026-09-22
Privacy Policy
How ONEPIX processes information, what becomes public, and which external services are used.
GOOGLEBusiness Data Responsibility →1. Controller and scope
ONEPIX is operated under the service name 플레이컨티뉴 (PlayContinue) in the Republic of Korea, with the representative display name 캡틴맨. Customer-support, privacy, and rights requests may be sent to playcontinue00@gmail.com.
2. Information processed
- Sign-in: Apple or Google provider identifier, email and account metadata such as a provider-supplied name, authentication tokens, and session information. When Google Sign-In is selected, Google's iOS sign-in SDK may also process a phone number associated with the Google account and SDK/environment usage data as declared in its privacy manifest. ONEPIX does not ask users to enter a phone number as a separate profile field or use it for address-book access, advertising, or tracking.
- Profile: internal actor ID, nickname, selected country badge, app language, account status, and change timestamps
- Social connections: friend requests and accepted friendships, blocks, likes, My World character invitations and connections, the participating actor IDs, status, and related timestamps
- Pixels: canvas ID, coordinate, color, placement time, pixel source, request ID, nickname and country snapshots, and founder/current signatures
- Community and My World content: community posts and comments; My World feed text, mood and background choice; guestbook entries and replies; character speech; linked Studio artwork; source language, attached canvas or coordinate, creation/deletion times, and author snapshots
- My World customization: catalog and wardrobe items owned; room placement, layer, size, direction and functional state; wallpaper; representative character, skin tone, expression, hair, clothing and accessories; selected music track; and connected guest-character placement
- Virtual acorns: account-bound wallet balance, grants and spending, amount and reason, request or reference ID, transaction time, displayed item price, item purchase, and resulting entitlement. Acorns are non-transferable virtual currency usable only inside ONEPIX; they are not money or cryptocurrency and cannot be cashed out or exchanged. Purchased acorns do not expire while the account remains active. ONEPIX does not collect a payment-card or bank-account number for this ledger.
- Reports: reporting actor, target content, reason, optional details, review state, and resolution
- Translation: requested content and target language, source and translated text, detected language, provider/model, character counts, and request records
- In-app purchases: store and product, store transaction, order, or reference ID or a one-way hash, opaque receipt or purchase token used for server verification, account-binding identifier, purchase date and environment, verification and consumption status, PIXEL+ subscription period and renewal state, and refund, revocation, provider-notification, and reconciliation records. ONEPIX does not receive or store payment-card or bank-account details. Raw Google purchase tokens are not stored in SQL or logs; a SHA-256 transaction identity is stored.
- Advertising is not enabled in the current review build. No advertising SDK is initialized and no ad request, advertising identifier, or ad interaction is processed. If advertising is later served to FREE accounts, PIXEL+ remains ad-free and the relevant consent and privacy disclosures will apply.
- Rewarded-ad verification is inactive while advertising is unavailable. ONEPIX does not create ad-reward sessions, accept advertising callbacks, or grant ad-based benefits unless that feature is separately enabled.
- Service logs: standard network data that infrastructure may generate, such as IP address, request time, User-Agent, app/device environment, and error information
- Optional app measurement: only after the user opts in, Firebase Analytics may process device and app information, operating-system version, locale, screen name, plan category, and feature-use results. In My World, this includes the fixed catalog item ID shared by all users, item subcategory, functional or decorative category, entry surface, ownership state, displayed acorn price, selection, preview, purchase result, feature use, and the types and aggregate counts of placement changes after a room save. These events do not include an owned-item or placement identifier, room-owner or visitor identifier, exact position or coordinates, acorn balance, nickname, dialogue, artwork title, search term, other free text, or purchase receipt. Firebase Crashlytics may process crash diagnostics and stack traces.
- Installation identifiers: Firebase Installations automatically creates and processes a Firebase Installation ID (FID) when the included Firebase services initialize. ONEPIX also creates a random ONEPIX installation UUID and associates it with the signed-in account in Supabase to read and secure installation-specific in-app-alert status. These identifiers are not advertising IDs or phone-push delivery tokens.
- Phone push notifications are disabled in the current build. ONEPIX does not request notification permission or register an FCM registration token; it disables messaging auto-initialization and removes a legacy token when possible. This does not prevent the Firebase Installation ID or ONEPIX installation UUID described above from being processed. Authenticated in-app alerts are fetched directly from Supabase.
3. Purposes
- Authentication, account creation, session continuity, and abuse prevention
- Profiles, pixel balances, canvas placement, signatures, archives, and timelapses
- Friend relationships, invitations, likes, community and My World posts, comments, guestbook entries, character speech, reports, translation, moderation, and safety
- My World inventory, room layout, character appearance, selected music, virtual-acorn accounting, item entitlements, store-purchase verification, account binding, subscription delivery, refund and revocation handling, reconciliation, and abuse-resistant transactions
- Service eligibility, account safety, abuse prevention, and customer support
- Error analysis, security, service improvement, and legal compliance
- Aggregate analysis of item selection, preview, purchase, placement, and feature use to improve catalog composition, decorating usability, and feature quality
- Installation recognition, delivery, display, preference control, and abuse prevention for authenticated in-app alerts
4. Information visible to others
Nicknames, country badges, pixel coordinates, colors and times, founder/current signatures, community and My World feed posts and comments, guestbook entries and replies, character speech, linked Studio artwork, likes and attached coordinates may be public by design. A visited My World may also show its wallpaper, room items and layout, functional states, selected background music, and the appearance and placement of displayed characters. Archives retain not only final colors but also public pixel events and historical nickname/country snapshots for signatures and timelapses.
Friend requests, the private friend graph, blocks and pending invitation states are limited to the relevant users. Inventory entitlements, virtual-acorn balances and ledger entries, Firebase Installation IDs, and ONEPIX installation UUIDs are not shown publicly.
Changing a nickname does not update past snapshots in pixels, archives, posts, or comments. Account deletion is different: nickname, country, signature, and account links are removed from those records, and archived contributors are shown as ‘Deleted User.’
5. Processors and international processing
ONEPIX uses the providers listed below. The production Supabase project is hosted in Seoul, Republic of Korea. A provider may process information outside Korea under its published terms and privacy policy.
- Supabase: authentication, PostgreSQL database, Realtime, Edge Functions, server logs, and the account-linked random ONEPIX installation UUID used for installation-specific in-app-alert status and security
- OpenFreeMap: when World Canvas is opened, ONEPIX requests vector tiles and fonts from the public OpenFreeMap instance operated by Hyperknot Software Kft. in Hungary. Normal network requests expose the IP address and requested tile coordinates; OpenFreeMap states that its anonymized server logs include browser type, referrer, date/time, and operating system, that IP addresses are not logged by default, and that an IP may be logged temporarily during a security incident for up to 30 days. Cloudflare may also process request data. ONEPIX does not send an account ID, nickname, pixel content, posts, comments, or signatures. If loading fails, the bundled Natural Earth fallback is used without another map-provider request.
- Google Firebase Analytics and Crashlytics: optional product measurement and crash diagnosis after opt-in. The catalog item ID is a common product ID, not an identifier for a user's owned copy. ONEPIX does not set a ONEPIX account ID as the Firebase user ID or send nicknames, email addresses, artwork, messages, comments, signatures, placement identifiers, dialogue, artwork titles, receipts, or pixel, canvas, or room coordinates to Firebase. Analytics advertising-ID collection and ad personalization are disabled, and collection can be turned off at any time in Profile. Supabase remains the service backend; Firebase is not used for authentication, canvases, pixel or acorn balances, community content, or account storage.
- Google Firebase Installations: automatically creates and processes a Firebase Installation ID (FID) to identify the installed app instance and support included Firebase services. The FID is distinct from an advertising ID, a ONEPIX account ID, the ONEPIX installation UUID, and an FCM registration token; it may be processed even when optional Analytics and Crashlytics collection is off.
- Google Firebase Cloud Messaging: phone push is disabled in the current build. No notification permission or FCM registration-token registration is requested; this does not remove the separately processed FID. Authenticated in-app alerts use Supabase.
- Apple: social sign-in and account authentication. Google Sign-In: when selected, account authentication and provider metadata; its bundled iOS privacy manifest declares linked Phone Number for App Functionality and linked Other Usage Data for Analytics, with Tracking set to No for both.
- Google Cloud Translation: only when a user selects Translate, ONEPIX sends the requested text content and target language to Google for translation. This can include posts, comments, guestbook entries, and character dialogue. ONEPIX account IDs and email addresses are not sent. The translation may be cached in Supabase to avoid repeat requests.
- Google User Messaging Platform (UMP): not initialized while advertising is unavailable. It will be used only as required if advertising is enabled for FREE accounts.
- Advertising providers: no advertising SDK is used while advertising is unavailable. PIXEL+ remains ad-free whenever FREE accounts are served ads.
- Apple App Store and Google Play purchase services: display localized products and prices, process charges and subscription management, and provide transaction, receipt or purchase-token, renewal, cancellation, refund, revocation, and consumption status for server verification. ONEPIX sends an account-binding identifier and product or transaction reference as needed, but does not receive payment-card or bank-account details.
6. Retention, deletion, and disposal
When account deletion is approved, ONEPIX deletes the sign-in account, private profile, pixel balances, acorn wallet, inventory, internal subscription state, and active sessions, and removes the user’s current pixels and signatures from active canvases. Posts and comments retain only structural tombstones; their text, author snapshots, and other personal information are scrubbed. Deletion of ONEPIX data does not cancel an App Store or Google Play subscription.
Service records are kept while an account is active and as needed to operate, secure, process purchases and refunds, reconcile store state, prevent duplicate or fraudulent transactions, and meet accounting and legal duties. On deletion, live wallet and subscription state are removed, but non-identifying transaction IDs or hashes, ledger entries, and refund or replay-prevention tombstones may remain for those limited purposes. Raw reconciliation references are scrubbed after a 400-day retention window; attempt details are removed after 90 days, completed provider-delivery records after 400 days, and remaining operational fingerprints after an additional 730 days. Moderation evidence ordinarily remains up to 180 days after case closure, a non-identifying Apple-revocation outcome for 30 days, and irreversibly anonymized collective-work records may remain. External-provider logs follow the providers’ published policies.
7. Your rights
Users can request access, correction, deletion, restriction, withdrawal of consent, and account deletion, with final authorization and scope enforcement on the server. Google and other accounts without an Apple identity can be deleted from Profile or the public web page. An Apple-linked account must reauthenticate in the ONEPIX iOS app with a fresh Apple authorization code. The server does not delete Auth or ONEPIX data until upstream Apple revocation succeeds or a valid prior revocation receipt is verified. Because web OAuth does not provide the one-time code, the web flow blocks Apple-linked deletion and directs the user to the native iOS path. Invalid or missing proof requires reauthentication; configuration, Apple service, or receipt-store outages fail safely and can be retried later.
The country badge is designed to be permanent, but correction of a mistake or a legally required correction may be requested at playcontinue00@gmail.com. Access, correction, deletion, restriction, withdrawal, and appeal requests may also be sent there.
The current review build has no advertising or advertising-consent controls because it makes no ad request. If advertising is enabled for FREE accounts, the applicable consent controls will be provided and PIXEL+ will remain ad-free.
Phone push is unavailable in the current build. Authenticated in-app alert categories can be controlled separately in ONEPIX. Firebase Analytics and Crashlytics consent is independent.
Turning off app-improvement data in Profile stops future optional Analytics events and Crashlytics collection, and deletes unsent crash reports remaining on the device. Information already sent remains subject to the published retention and deletion practices, and users may exercise their rights through the official contact.
8. Security, children, and changes
ONEPIX uses measures such as separated server privileges, row-level access controls, server-authoritative validation, encrypted transport, rate limits, and audit records. No system can guarantee absolute security.
ONEPIX is for people age 16 or older. The service is not offered to anyone under 16, and ONEPIX does not currently provide a parental-consent path. Policy updates show their revision and effective dates, and material changes will be announced by an appropriate method.