Privacy Policy
This policy describes, app by app, the information processed by SnackPlay (mini-games) and PaletteWeather (weather), Android and iOS apps provided by independent developer Glenn Yu (the "operator"). Both apps use the same operator server (gwangy.com) but process different information, so please read the section for the app you use.
Summary: SnackPlay stores a guest account (nickname and device identifier) and game records on the operator server; you can delete them in the app under Settings → Delete account or as described on the account deletion page. PaletteWeather has no accounts; to look up weather it sends coordinates rounded to a grid of about 1 km and city search text to the server without any user identifier. Both apps use Google AdMob ads and Google Firebase (analytics and crash reporting).
1. Common to both apps
1-1. Third-party services (SDKs)
| Service | Information it may process | Purpose |
|---|---|---|
| Google AdMob · User Messaging Platform (UMP) | Advertising identifiers (Android advertising ID and app set ID, iOS IDFA when tracking is allowed), approximate location estimated from the IP address, ad impressions, clicks and other interactions, device, app and diagnostic information, consent status | Serving and measuring ads, frequency capping, invalid-traffic prevention, regional ad consent |
| Unity Ads (Android apps only) | The Android apps include the Unity Ads SDK for AdMob mediation, and it initializes when the app starts. It may process advertising identifiers, approximate location, ad interactions, and device and diagnostic information | Serving ads and preventing fraud |
| Firebase Analytics | App instance ID, events such as screen views, feature use and ad impressions, device model, OS, app version and language, approximate region estimated from the IP address. On iOS, the IDFA may also be processed if you allow tracking | Understanding feature use and improving quality |
| Firebase Crashlytics | Stack traces when a crash or error occurs, device state (memory, storage, etc.), device model, OS and app version, installation identifier | Finding and fixing errors |
| Firebase Remote Config | Country, language, time zone, OS and app version, installation identifier | Changing app settings remotely, feature experiments |
- Firebase Analytics and Crashlytics are on by default in both apps, cannot be turned off inside the apps, and run regardless of your ad consent (UMP) choice.
- The ad SDK (AdMob) starts only after the UMP consent flow has finished and ad requests are allowed. In regions where consent is required (EEA, UK, etc.) you can change your choice from the privacy options in the app's settings.
- iOS App Tracking Transparency (ATT): both iOS apps ask whether you allow tracking for ads. If you do not allow it, the IDFA is not used for ads or analytics; you can change this any time under Settings → Privacy & Security → Tracking.
- Android advertising ID: you can reset or delete it under Settings → Privacy → Ads.
1-2. Server logs
The operator server (gwangy.com) may keep access and error logs for operation and security (IP address, requested URL, time, platform and app version sent by the app, etc.). These logs are not linked to user accounts, and no specific retention period has been set for them.
2. SnackPlay
2-1. Information processed
| Category | Items | Purpose |
|---|---|---|
| Guest account | Nickname (entered by you, or generated automatically if you skip), server account number, device identifier for guest sign-in (Android ANDROID_ID / iOS identifierForVendor), platform, device model, OS and app version | Creating the account and signing in, device compatibility |
| Profile image (optional) | An image file made on your device from the photo you choose, downscaled to at most 1024 px on the long side and re-encoded, and its URL | Showing your profile in friend lists and search results |
| Game records | Game, score, wrong answers, difficulty, play time, game seed, record checksum. The Android app also sends tap timing and input logs for score verification (the iOS app does not send them by default; they can be switched on by remote configuration) | Rankings and statistics, detecting score tampering and macros |
| Activity records | Attendance, missions, event participation and rewards, seasons, daily challenges, snack history | Game progress and rewards, preventing duplicate rewards |
| Social features | Friends added and removed, guild name and description (entered by you), guild membership, contributions and invitations. Nickname and guild search terms are used only to return results and are not stored in the service database | Friends and guild features |
| Feedback and reports (optional) | Feedback or report text you write, category, and a device model, OS and app version string. No contact details are collected | Responding to inquiries, improving the service, checking inappropriate use |
| Crash reports | Firebase Crashlytics reports (linked to the server account number). The Android app also sends crash records stored on the device (stack trace, thread, device information) to the operator server on the next launch, masking authentication tokens, email addresses and UUID-like values | Finding and fixing errors |
| Push notifications | Android: Firebase Cloud Messaging token (stored on the server). iOS: the app does not currently register for push notifications, so no token is issued | Game notifications such as attendance, missions and friends |
| Analytics and performance | Firebase Analytics events (game start and finish, score, accuracy, play time, ad impressions, account deletion reason, etc.) and Firebase Performance measurements (app start time, network response time, etc.). Analytics and Crashlytics use the server account number, not the nickname, as the user ID | Game balance and quality improvement |
| Advertising | The AdMob and UMP items in section 1-1 (both platforms) and Unity Ads (Android) | Showing ads to keep the game free, confirming rewarded ads |
SnackPlay does not collect email addresses, phone numbers, real names, precise location, contacts, or microphone or camera data, and currently has no paid purchases.
2-2. Information visible to other players
- Rankings: nickname, score, difficulty, time of the record
- Friend lists and nickname search: nickname, profile image, best score
- Guilds: guild name, description and member nicknames
2-3. Information kept only on your device
Your blocked-player list, the profanity dictionary, local ranking records, settings such as notifications and sound, and the profile photo downscaling are processed and stored on the device only. Android device backups exclude sign-in tokens, the game database and user preferences.
2-4. Retention and deletion
| Item | Retention |
|---|---|
| Account, game and activity records, feedback, crash reports (operator server) | Kept until you delete your account (anti-cheat verification records may be removed earlier by a server cleanup job). Inactive accounts are not deleted automatically after any period |
| Nickname, current profile image file and URL, device identifier, push token, sign-in link identifier | Deleted from the server immediately when you request account deletion |
| The rest of the account record (without nickname), game and activity records, friend and guild records, feedback and reports, crash reports sent to the server, refresh tokens | Permanently deleted by a daily cleanup job once 30 days have passed since the deletion request. Accounts that own a guild are not deleted automatically until the guild is resolved |
| Profile image files uploaded before a later change | Not recorded against your account on the server, so not removed automatically when the account is deleted |
| Firebase Crashlytics crash reports | Kept by Google for 90 days, then deleted |
| Firebase Analytics user- and event-level data | According to the Google Analytics data retention setting (at most 14 months); aggregated statistics that do not identify individuals may remain |
| Advertising data | According to Google's and Unity's policies |
For how to delete and what is not deleted, see SnackPlay Account Deletion.
2-5. Your rights
- Correction: change your nickname and profile image in the app's settings.
- Deletion: delete immediately under Settings → Delete account, or without the app by emailing your nickname to gwangy.claw@gmail.com.
- Access and other requests: you can request access to the information stored about you, or exercise other rights, at the same email address. After confirming the account, we reply based on the items stored on the server.
- Notifications: you can turn notifications off in the app and in device settings. On Android, a refreshed token may still be stored on the server while notifications are off.
3. PaletteWeather
3-1. Information processed
| Category | Items | Purpose |
|---|---|---|
| Location (optional) | If you grant location permission, the app uses your device's current coordinates (Android requests precise and approximate location together; iOS requests while-in-use location). Background location permission is not requested | Weather, air quality and forecasts for your current location |
| Coordinates for weather lookups | Coordinates sent to the operator server (gwangy.com) are rounded to two decimal places (a grid of about 1 km). When the server is unavailable, the app requests weather directly from Open-Meteo, which also receives the coordinates needed for the lookup. The current Android app sends unrounded coordinates in its fallback forecast and air-quality requests (the iOS app rounds coordinates in every request) | Retrieving weather data |
| Place names | To turn coordinates into a place name, unrounded coordinates are sent to the operating system's geocoding service (Android: Google Play services, iOS: Apple) | Showing the name of your current location |
| City search text (optional) | The city name you type and the language. It is sent to both the operator server and Open-Meteo geocoding, and the operator server may also query OpenStreetMap Nominatim | Searching for and adding cities |
| Request information | Request headers with platform, app version and app name, and the IP address | Compatibility management, protecting requests |
| Analytics and crashes | Firebase Analytics events (weather screen views, theme selection, weather lookup result and response time, ad impression, click and revenue events). The Android app sends the reverse-geocoded place name (usually city or district level) with weather screen views; the iOS app does not send coordinates or the name of your current location, and sends the city name when you delete a saved city. Firebase Crashlytics crash reports. No user ID is set | Understanding feature use, fixing errors |
| Advertising | The AdMob and UMP items in section 1-1 (both platforms) and Unity Ads (Android). The app does not pass coordinates to ad SDKs | Showing ads |
PaletteWeather has no accounts or sign-in and does not collect names, email addresses, contacts, photos or microphone data. To check for updates, the iOS app queries the Apple App Store with the app's bundle ID only.
3-2. Information stored on the operator server
- The server stores the coordinates it receives (about 1 km grid) and the weather and air-quality values it looked up in lookup history and caches. These records contain no user or device identifier.
- City search text is stored in a search log with the number of results and the language, also without any user or device identifier.
- The server passes coordinates and search text to weather providers but does not pass on your IP address.
3-3. Information kept only on your device
Saved cities, palette history, widget data, forecast notification schedules, recent searches and the last location used (for widgets and forecast notifications) are stored only on your device. Widgets and forecast notifications refresh weather using that stored location, and notifications are local notifications created on the device.
3-4. Weather data providers
| Provider | Information received | Route |
|---|---|---|
| Open-Meteo (open-meteo.com) | Coordinates for weather, air quality, marine, flood and ensemble lookups, city search text, IP address (when the app requests directly) | Via the operator server and directly from the app |
| Norwegian Meteorological Institute, MET Norway (api.met.no) | Coordinates for weather lookups | Via the operator server |
| OpenStreetMap Nominatim | City search text | Via the operator server |
3-5. Retention and deletion
- Weather and air-quality lookup history and city search logs on the server are deleted by a server cleanup job after 90 days, and caches are deleted when they expire.
- Because server records contain no user identifier, records belonging to a particular user cannot be found or deleted individually.
- Cities, history and settings stored on your device can be removed with the in-app delete and reset functions or by uninstalling the app.
- Retention for Firebase and advertising data is the same as the Firebase and advertising rows in section 2-4.
- You can turn off location access in device settings at any time; you can still see weather by searching for and adding a city.
4. Sharing and international processing
The operator does not sell personal information and does not provide information it holds to third parties except where required by law. The services listed above process information under their own policies, and their servers may be outside Korea (Google LLC and Unity Technologies in the United States and elsewhere, MET Norway in Norway, Open-Meteo and OpenStreetMap Nominatim abroad).
- Google Privacy Policy · Firebase privacy and security · Google advertising
- Unity Privacy Policy · Open-Meteo terms · OpenStreetMap Foundation Privacy Policy
5. Security
- Communication between the apps and the operator server is encrypted with HTTPS.
- SnackPlay checks record checksums and signatures to prevent score tampering, and masks authentication tokens, email addresses and UUID-like values in crash records sent to the server.
6. Children
Neither app is directed primarily at children under 14, and there is no age verification. If you tell us that a SnackPlay account of a child under 14 was created without a legal guardian's consent, we will delete that account.
7. Changes and contact
This revision (September 14, 2026) corrects the descriptions to match the information both apps actually process. If the information processed changes in the future, we will post a notice on this page before the change takes effect.
- Privacy officer: Glenn Yu, independent developer
- Contact: gwangy.claw@gmail.com