PIGAMES

Privacy Policy

My Little Goddess: Idle RPG | PIGAMES Co., Ltd.
Effective date: September 2, 2026

[This English translation is provided for convenience only. In the event of any discrepancy, the Korean original shall prevail.]

PIGAMES Co., Ltd. (the "Company") complies with the Personal Information Protection Act of the Republic of Korea and related laws and regulations, and establishes and discloses this Privacy Policy as follows in accordance with Article 30 of the Personal Information Protection Act, in order to protect users' personal information and to handle related grievances promptly and smoothly. This Policy applies to the mobile game "My Little Goddess: Idle RPG" (the "Service") provided by the Company.

Article 1 (Items of Personal Information Collected and Methods of Collection)

The Company collects the following personal information in order to provide the Service.

1. Upon membership registration and login

CategoryItems CollectedMethod
Google account linkageGoogle account email address, profile name, Google account identifierSocial login
Apple account linkageApple ID email address (or the private relay email provided by Apple), name, Apple account identifierSocial login
Guest playUnique device identifier (Android: unique device identifier; iOS: app installation identifier)Automatic collection

2. Information generated and collected in the course of using the Service

  • Account and game information: user identifier (UID) assigned by the Company, nickname, profile icon, server number, game progress records (stage, account level, combat power, owned heroes, pets, items, and equipment, formation information, currency acquisition and usage history), play time, access dates and times (initial registration date, most recent access date), system language
  • Device information: device model name, OS type and version (including firmware build information), unique device identifier, app version, installation store type, payment currency
  • Advertising identifiers: Google Advertising ID (GAID), Apple Identifier for Advertisers (IDFA, where app tracking has been allowed), Identifier for Vendors (IDFV), App Set ID, install referrer information
  • Network and log information: IP address, country of access, access records, error and crash reports (including the user identifier, nickname, and highest stage at the time of the crash), app system logs (including device model, OS, and app version)
  • Community information: original text of chat messages, emoticons, time of posting, chat block list, (where the guild feature is provided) guild name, guild description, guild flag and emblem, guild application, joining, and withdrawal records, guild contribution, guild chat messages
  • Ranking information: stage, raid, and event records, formation information, most recent update time
  • Ad viewing information: number and type of rewarded ads viewed, ad revenue information

3. Upon in-app purchase

Items CollectedNotes
Payment history (product ID, amount, currency, date and time of payment, store type)Processed through the Google Play, App Store, and ONE store payment systems
Order number, transaction ID, purchase token (Google Play)For receipt verification, prevention of duplicate grants, and refund processing
Cumulative payment amountFor user support and determination of fraudulent use
Card and bank account informationNot collected — processed directly by each app market

4. Upon customer inquiries and coupon use

  • Customer inquiries: email address (sender address), inquiry details, and the user identifier, device model, OS version, and app version automatically included in the inquiry email
  • Coupon use: user identifier, date and time of use, requesting IP address (to prevent brute-force entry)

5. Methods of collection

Automatic collection in the course of running the app and playing the game, social login linkage, app market payment system linkage, email inquiries, coupon entry

Article 2 (Purposes of Collection and Use of Personal Information)

Purpose of UseItems Used
Member identification, account management, and maintaining loginEmail, name, account identifier, unique device identifier, user identifier
Saving game data, synchronization between devices, and account recoveryGame progress records, device information, access dates and times
In-app purchase processing, receipt verification, and refundsPayment history, order number, transaction ID, purchase token
Provision of community features such as rankings, chat, and guilds — nickname, profile icon, records, and guild name are disclosed to other usersNickname, profile icon, ranking records, formation information, chat messages, guild information
Provision of rewarded ads and granting of ad viewing rewardsAdvertising identifiers, device information, user identifier, ad viewing records
Ad performance measurement and install path analysisAdvertising identifiers, install referrer, user identifier, app events, payment information
Sending push notifications for notices and eventsPush notification token, system language
Responding to customer inquiries and handling disputesEmail, inquiry details, user identifier, payment history, game progress records
Detection of and sanctions against fraudulent use (unauthorized programs, account theft, coupon abuse, etc.)User identifier, nickname, device information, IP address, currency and payment records, access logs
Service improvement and usage statistics analysisApp usage logs, game progress records, error and crash reports
Fulfillment of legal obligationsPayment records, access records

Article 3 (Retention and Use Period of Personal Information)

In principle, the Company destroys personal information without delay once the purpose of its collection and use has been achieved. However, in the following cases, the information is retained for the period specified below.

BasisItems RetainedPeriod
Service use agreementAccount information, game dataUntil membership withdrawal. For members linked to a Google or Apple account, the information is deleted after a grace period of 15 days following the withdrawal request (logging in again within the grace period cancels the withdrawal); guest accounts are deleted immediately upon withdrawal.
Prevention of fraudulent useSanctioned account information (user identifier, nickname, device information, reason for sanction), identification information of withdrawn accounts1 year after withdrawal or lifting of the sanction
Community operation and dispute responseChat messages1 year from the date of posting
Prevention of fraudulent coupon useRequesting IP addressUntil the entry restriction period ends
Act on Consumer Protection in Electronic CommerceRecords concerning contracts, withdrawal of offers, payment, and supply of goods5 years
Act on Consumer Protection in Electronic CommerceRecords concerning the handling of consumer complaints and disputes3 years
Act on Consumer Protection in Electronic CommerceRecords concerning labeling and advertising6 months
Protection of Communications Secrets ActAccess records (IP address, etc.)3 months
Service analysisUsage metrics statistically processed so that individuals cannot be identifiedRetained without a separate period

Article 4 (Provision of Personal Information to Third Parties)

The Company processes users' personal information only within the scope specified in Article 2, and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the user's consent or under special provisions of law. In the following cases, personal information is provided to third parties in order to provide the Service.

RecipientPurposeItems ProvidedRetention and Use Period
Google LLC, Apple Inc., ONE store Co., Ltd.In-app purchase processing and receipt verificationProduct ID, order information, device informationIn accordance with each provider's privacy policy
Google LLC (AdMob), Unity Technologies (Unity Ads), Meta Platforms, Inc. (Audience Network)Provision of rewarded ads and personalized advertisingAdvertising identifiers, device information, IP address, ad viewing recordsIn accordance with each provider's privacy policy
Meta Platforms, Inc.Ad performance measurement and ad optimizationAdvertising identifiers, device information, app events (app launch, tutorial completion, stage clear, payment amount and currency)In accordance with each provider's privacy policy

In addition, personal information may be provided where the user has given prior consent, where required by laws and regulations, or where an investigative agency requests it in accordance with the procedures and methods prescribed by law.

Article 5 (Entrustment of Personal Information Processing)

For the smooth provision of the Service, the Company entrusts personal information processing tasks as follows. Trustees do not use personal information for purposes other than performing the entrusted tasks or provide it to third parties, and the Company manages and supervises trustees through entrustment agreements.

TrusteeEntrusted Tasks
Google LLC (Firebase)Member authentication, game data storage and synchronization, execution of server functions, sending of push notifications, usage statistics analysis, collection of error and crash reports, log file storage, app integrity verification, provision of remote configuration
Singular Labs, Inc.Ad performance measurement and install path analysis (advertising identifiers, install referrer, user identifier, app events, payment and ad revenue information)
Unity Technologies (Unity LevelPlay)Rewarded ad mediation (advertising identifiers, user identifier, device information)

If the details of the entrusted tasks or the trustees change, the Company will disclose such changes through this Policy without delay.

Article 6 (Overseas Transfer of Personal Information)

For the entrustment of processing and storage necessary to provide the Service, the Company transfers personal information overseas as follows in accordance with Article 28-8 (1) 3 of the Personal Information Protection Act, and discloses the details in this Policy.

Recipient (Contact)CountryTime and MethodItemsPurposeRetention and Use Period
Google LLC — support.google.com/policiesUnited StatesTransmitted over the network when the Service is usedItems entrusted under Article 5, payment information, advertising identifiersMember authentication, data storage, analytics, payment, advertisingUntil termination of the entrustment agreement or membership withdrawal
Apple Inc. — apple.com/legal/privacyUnited StatesUpon Apple sign-in and App Store paymentApple account identifier, email, payment informationMember authentication, payment processingIn accordance with each provider's policy
Singular Labs, Inc. — privacy@singular.netUnited StatesUpon app launch and when events occurAdvertising identifiers, install referrer, user identifier, app events, payment and ad revenue informationAd performance measurementUntil termination of the entrustment agreement
Meta Platforms, Inc. — facebook.com/privacyUnited StatesUpon app launch, ad impression, and when events occurAdvertising identifiers, device information, app eventsAd provision and performance measurementIn accordance with each provider's policy
Unity Technologies — unity.com/legal/privacy-policyUnited StatesUpon ad requestAdvertising identifiers, user identifier, device informationProvision of rewarded adsIn accordance with each provider's policy

Users may refuse overseas transfer by withdrawing their membership, resetting their advertising identifier, or opting out of app tracking (Article 7). However, refusing transfers necessary for member authentication and data storage may restrict use of the Service.

Article 7 (Collection, Use, Provision, and Refusal of Behavioral Information)

The Company collects and uses behavioral information as follows in order to provide users with personalized advertising and to measure ad performance.

Behavioral information collectedApp installation, launch, and usage records, ad viewing records, in-app purchase records, advertising identifiers
Method of collectionAutomatic collection through the advertising and analytics SDKs included in the app (Google AdMob, Unity Ads, Meta Audience Network, Meta SDK, Singular)
Purpose of collectionProvision of personalized advertising based on users' interests and preferences, ad performance measurement, and install path analysis
Retention and use periodAd viewing records stored directly by the Company: until membership withdrawal; behavioral information collected by advertising providers: in accordance with each provider's policy
Advertising providers processing behavioral informationGoogle LLC (policies.google.com/technologies/ads), Unity Technologies (unity.com/legal/privacy-policy), Meta Platforms, Inc. (facebook.com/privacy/policy), Singular Labs, Inc. (singular.net/privacy-policy)

Users may block or allow the collection of behavioral information for personalized advertising by the following methods.

  • Android: Settings > Privacy > Ads > Delete or reset advertising ID (on some devices, Settings > Google > Ads)
  • iOS: Settings > Privacy & Security > Tracking > turn off Allow Apps to Request to Track, or select "Ask App Not to Track" in the app tracking permission prompt displayed when the Service is first launched
  • Even if the collection of behavioral information is blocked, ads themselves may continue to be displayed, and general, non-personalized ads will be shown.

The Company does not collect behavioral information for personalized advertising purposes from children it knows to be under the age of 14. Inquiries regarding behavioral information may be directed to the Personal Information Protection Officer under Article 13.

Article 8 (Automatic Personal Information Collection Devices and App Access Permissions)

1. The Company's Service is provided as a mobile app and does not use web browser cookies. Automatic collection through advertising and analytics SDKs is governed by Article 7.

2. In accordance with Article 22-2 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Company provides notice of the app access permissions required to provide the Service as follows.

TypePermissionPurpose
OptionalNotifications (Android POST_NOTIFICATIONS / iOS notifications)Sending push notifications for notices and events
OptionalAllow app tracking (iOS App Tracking Transparency)Provision of personalized advertising and ad performance measurement
Normal permissions — no separate consent requiredInternet, network state check, advertising ID, in-app purchase, install referrer lookupService provision, payment processing, ad performance measurement

The basic functions of the Service can be used even without consenting to optional permissions, and these can be changed at any time in the device settings (Settings > Apps > My Little Goddess > Permissions or Notifications).

Article 9 (Rights and Obligations of Users and Legal Representatives, and Methods of Exercise)

  1. Users may exercise their rights against the Company at any time, including requesting access to, correction of, deletion of, or suspension of the processing of their personal information.
  2. Rights may be exercised by the following methods, and the Company will take action and notify the user of the result within 10 days of receiving the request.
    • Direct processing through the in-app [Settings > Account > Delete Account] menu
    • Email inquiry: support@pigames.co.kr
  3. Rights may be exercised through an agent, such as the user's legal representative or an authorized person. In such cases, a power of attorney in the form of Attachment No. 11 of the Public Notice on Methods of Processing Personal Information must be submitted.
  4. Requests for access and suspension of processing may be restricted pursuant to Articles 35 (4) and 37 (2) of the Personal Information Protection Act, and deletion may not be requested for personal information specified as subject to collection under other laws.
  5. The Company verifies whether the person making a request to exercise rights is the user or a legitimate agent.
  6. Users are responsible for keeping their personal information up to date, and must not infringe on the personal information of others or collect or use other users' nicknames, chat content, or the like without authorization.

Article 10 (Procedures and Methods of Destruction of Personal Information)

  1. The Company destroys personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.
  2. Where personal information must continue to be preserved under other laws despite the expiration of the retention period or the achievement of the processing purpose, the Company moves such personal information to a separate database or preserves it in a different storage location, and does not use it for purposes other than those prescribed by law.
  3. Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen, and destroys it with the approval of the Personal Information Protection Officer. Accounts for which withdrawal has been requested are automatically deleted from the server after the grace period has elapsed.
  4. Destruction method: Personal information in electronic file format is permanently deleted in a manner that cannot be recovered, and personal information recorded on paper documents is destroyed by shredding or incineration.

Article 11 (Protection of Children's Personal Information)

The Company's Service is not directed at children under the age of 14 (under the age of 13 outside Korea). Children under the age of 14 may not register for the Service without the consent of their legal representative, and if the Company becomes aware that a child's personal information has been collected, it will delete such information without delay. If you have concerns about the collection of a child's personal information, please contact support@pigames.co.kr.

Article 12 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures in accordance with Article 29 of the Personal Information Protection Act.

Technical measures

  • Application of SSL/TLS encryption when transmitting personal information
  • Prevention of forgery and tampering through encryption of client-stored data and app integrity verification
  • Minimization of database access rights and management of access records
  • Operation of an automatic fraudulent use detection system
  • Regular inspection of security vulnerabilities and application of patches

Administrative measures

  • Minimization of personal information handlers and regular training
  • Regular review and updating of the Privacy Policy
  • Management and supervision of trustees

Article 13 (Personal Information Protection Officer and Department Receiving Access Requests)

The Company designates a Personal Information Protection Officer as follows, who bears overall responsibility for the processing of personal information and handles users' complaints and remedies for damages related to the processing of personal information. Requests for access to personal information under Article 35 of the Personal Information Protection Act are also received at the contact below.

Personal Information Protection OfficerMinchan Kim (CEO)
Emailsupport@pigames.co.kr

Users may contact the Personal Information Protection Officer with respect to all inquiries, complaints, and remedies for damages related to personal information protection arising in the course of using the Service, and the Company will respond to and handle such matters without delay.

Article 14 (Remedies for Infringement of Rights and Interests)

Users may contact the following organizations for remedies for damages, consultation, and other matters relating to personal information infringement.

  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code required, within Korea) (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (no area code required, within Korea) (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office, Cyber Investigation Division: 1301 (no area code required, within Korea) (www.spo.go.kr)
  • National Police Agency, Cyber Investigation Bureau: 182 (no area code required, within Korea) (ecrm.cyber.go.kr)

Article 15 (Criteria for Additional Use and Provision of Personal Information)

In accordance with Articles 15 (3) and 17 (4) of the Personal Information Protection Act, the Company may additionally use or provide personal information without the user's consent, taking into account the matters set forth in Article 14-2 of the Enforcement Decree. In doing so, the Company comprehensively considers whether the additional use or provision is related to the original purpose of collection, whether it is foreseeable in light of the circumstances of collection or processing practices, whether it infringes on the user's interests, and whether measures to ensure security, such as pseudonymization or encryption, have been taken.

Article 16 (Changes to the Privacy Policy)

  1. This Policy takes effect on September 2, 2026.
  2. The contents of this Policy may be added to, deleted, or amended in accordance with changes in laws, policies, or the Service, and any changes will be announced through in-app notices or the store page at least 7 days before they take effect (30 days in the case of significant changes to users' rights).
  3. Previous versions of the Privacy Policy (effective January 25, 2026 and effective April 21, 2026) are available upon request to the customer center (support@pigames.co.kr).

© PIGAMES Corporation. All Rights Reserved. · support@pigames.co.kr