PUBLIC DOCUMENT · 2026-09-15
Privacy Policy
How ONEPIX processes information, what becomes public, and which external services are used.
GOOGLEBusiness Data Responsibility →1. Controller and scope
ONEPIX is operated under the service name 플레이컨티뉴 (PlayContinue) in the Republic of Korea, with the representative display name 캡틴맨. Customer-support, privacy, and rights requests may be sent to playcontinue00@gmail.com.
2. Information processed
- Sign-in: Apple or Google provider identifier, email and account metadata such as a provider-supplied name, authentication tokens, and session information. When Google Sign-In is selected, Google's iOS sign-in SDK may also process a phone number associated with the Google account and SDK/environment usage data as declared in its privacy manifest. ONEPIX does not ask users to enter a phone number as a separate profile field or use it for address-book access, advertising, or tracking.
- Profile: internal actor ID, nickname, selected country badge, app language, account status, and change timestamps
- Social connections: friend requests and accepted friendships, blocks, likes, My World character invitations and connections, the participating actor IDs, status, and related timestamps
- Pixels: canvas ID, coordinate, color, placement time, pixel source, request ID, nickname and country snapshots, and founder/current signatures
- Community and My World content: community posts and comments; My World feed text, mood and background choice; guestbook entries and replies; character speech; linked Studio artwork; source language, attached canvas or coordinate, creation/deletion times, and author snapshots
- My World customization: catalog and wardrobe items owned; room placement, layer, size, direction and functional state; wallpaper; representative character, skin tone, expression, hair, clothing and accessories; selected music track; and connected guest-character placement
- Virtual acorns: wallet balance, grants and spending, amount and reason, request or reference ID, transaction time, displayed item price, item purchase, and resulting entitlement. Acorns are in-service virtual currency; ONEPIX does not collect a payment-card or bank-account number for this ledger.
- Reports: reporting actor, target content, reason, optional details, review state, and resolution
- Translation: requested content and target language, source and translated text, detected language, provider/model, character counts, and request records
- In-app purchases are disabled in version 1. Although a store-purchase adapter remains packaged, ONEPIX does not query products, start purchases or restores, transmit receipts, or grant paid entitlements while the release gate is off.
- Advertising is disabled in version 1. No advertising SDK is included or initialized, no ad request is made, and ONEPIX does not process advertising identifiers or ad interactions.
- Rewarded-ad verification is inactive in version 1. ONEPIX does not create ad reward sessions, accept advertising callbacks, or grant ad-based benefits.
- Service logs: standard network data that infrastructure may generate, such as IP address, request time, User-Agent, app/device environment, and error information
- Optional app measurement: only after the user opts in, Firebase Analytics may process device and app information, operating-system version, locale, screen name, plan category, and feature-use results. In My World, this includes the fixed catalog item ID shared by all users, item subcategory, functional or decorative category, entry surface, ownership state, displayed acorn price, selection, preview, purchase result, feature use, and the types and aggregate counts of placement changes after a room save. These events do not include an owned-item or placement identifier, room-owner or visitor identifier, exact position or coordinates, acorn balance, nickname, dialogue, artwork title, search term, other free text, or purchase receipt. Firebase Crashlytics may process crash diagnostics and stack traces.
- Installation identifiers: Firebase Installations automatically creates and processes a Firebase Installation ID (FID) when the included Firebase services initialize. ONEPIX also creates a random ONEPIX installation UUID and associates it with the signed-in account in Supabase to read and secure installation-specific in-app-alert status. These identifiers are not advertising IDs or phone-push delivery tokens.
- Phone push notifications are disabled in version 1. ONEPIX does not request notification permission or register an FCM registration token; it disables messaging auto-initialization and removes a legacy token when possible. This does not prevent the Firebase Installation ID or ONEPIX installation UUID described above from being processed. Authenticated in-app alerts are fetched directly from Supabase.
3. Purposes
- Authentication, account creation, session continuity, and abuse prevention
- Profiles, pixel balances, canvas placement, signatures, archives, and timelapses
- Friend relationships, invitations, likes, community and My World posts, comments, guestbook entries, character speech, reports, translation, moderation, and safety
- My World inventory, room layout, character appearance, selected music, virtual-acorn accounting, item entitlements, and abuse-resistant transactions
- Service eligibility, account safety, abuse prevention, and customer support
- Error analysis, security, service improvement, and legal compliance
- Aggregate analysis of item selection, preview, purchase, placement, and feature use to improve catalog composition, decorating usability, and feature quality
- Installation recognition, delivery, display, preference control, and abuse prevention for authenticated in-app alerts
4. Information visible to others
Nicknames, country badges, pixel coordinates, colors and times, founder/current signatures, community and My World feed posts and comments, guestbook entries and replies, character speech, linked Studio artwork, likes and attached coordinates may be public by design. A visited My World may also show its wallpaper, room items and layout, functional states, selected background music, and the appearance and placement of displayed characters. Archives retain not only final colors but also public pixel events and historical nickname/country snapshots for signatures and timelapses.
Friend requests, the private friend graph, blocks and pending invitation states are limited to the relevant users. Inventory entitlements, virtual-acorn balances and ledger entries, Firebase Installation IDs, and ONEPIX installation UUIDs are not shown publicly.
Changing a nickname does not update past snapshots in pixels, archives, posts, or comments. Account deletion is different: nickname, country, signature, and account links are removed from those records, and archived contributors are shown as ‘Deleted User.’
5. Processors and international processing
ONEPIX uses the providers listed below. The production Supabase project is hosted in Seoul, Republic of Korea. A provider may process information outside Korea under its published terms and privacy policy.
- Supabase: authentication, PostgreSQL database, Realtime, Edge Functions, server logs, and the account-linked random ONEPIX installation UUID used for installation-specific in-app-alert status and security
- OpenFreeMap: when World Canvas is opened, ONEPIX requests vector tiles and fonts from the public OpenFreeMap instance operated by Hyperknot Software Kft. in Hungary. Normal network requests expose the IP address and requested tile coordinates; OpenFreeMap states that its anonymized server logs include browser type, referrer, date/time, and operating system, that IP addresses are not logged by default, and that an IP may be logged temporarily during a security incident for up to 30 days. Cloudflare may also process request data. ONEPIX does not send an account ID, nickname, pixel content, posts, comments, or signatures. If loading fails, the bundled Natural Earth fallback is used without another map-provider request.
- Google Firebase Analytics and Crashlytics: optional product measurement and crash diagnosis after opt-in. The catalog item ID is a common product ID, not an identifier for a user's owned copy. ONEPIX does not set a ONEPIX account ID as the Firebase user ID or send nicknames, email addresses, artwork, messages, comments, signatures, placement identifiers, dialogue, artwork titles, receipts, or pixel, canvas, or room coordinates to Firebase. Analytics advertising-ID collection and ad personalization are disabled, and collection can be turned off at any time in Profile. Supabase remains the service backend; Firebase is not used for authentication, canvases, pixel or acorn balances, community content, or account storage.
- Google Firebase Installations: automatically creates and processes a Firebase Installation ID (FID) to identify the installed app instance and support included Firebase services. The FID is distinct from an advertising ID, a ONEPIX account ID, the ONEPIX installation UUID, and an FCM registration token; it may be processed even when optional Analytics and Crashlytics collection is off.
- Google Firebase Cloud Messaging: phone push is disabled in version 1. No notification permission or FCM registration-token registration is requested; this does not remove the separately processed FID. Authenticated in-app alerts use Supabase.
- Apple: social sign-in and account authentication. Google Sign-In: when selected, account authentication and provider metadata; its bundled iOS privacy manifest declares linked Phone Number for App Functionality and linked Other Usage Data for Analytics, with Tracking set to No for both.
- Google Cloud Translation: only when a user selects Translate, ONEPIX sends the requested text content and target language to Google for translation. This can include posts, comments, guestbook entries, and character dialogue. ONEPIX account IDs and email addresses are not sent. The translation may be cached in Supabase to avoid repeat requests.
- Google User Messaging Platform (UMP): no UMP or advertising consent SDK is included or initialized in version 1 because advertising is not offered.
- Advertising providers: no advertising SDK is included or used in version 1.
- Apple App Store and Google Play purchase services: in-app purchases are disabled in version 1. ONEPIX does not query products, purchase or restore, transmit receipts, or verify transactions while the release gate is off.
6. Retention, deletion, and disposal
When account deletion is approved, ONEPIX deletes the sign-in account, private profile, pixel balances, and active sessions, and removes the user's current pixels and signatures from active canvases. Posts and comments retain only structural tombstones; their text, author snapshots, and other personal information are scrubbed.
Service records are kept while an account is active and as needed to operate, secure, and meet legal duties for the service. On deletion, the rules above apply. The ordinary operational target for moderation evidence is up to 180 days after a case closes, subject to longer retention for law, security, or an unresolved dispute. A non-identifying Apple-revocation outcome is retained for 30 days. Irreversibly anonymized collective-work records may remain. External-provider logs follow the providers’ published policies.
7. Your rights
Users can request access, correction, deletion, restriction, withdrawal of consent, and account deletion, with final authorization and scope enforcement on the server. Google and other accounts without an Apple identity can be deleted from Profile or the public web page. An Apple-linked account must reauthenticate in the ONEPIX iOS app with a fresh Apple authorization code. The server does not delete Auth or ONEPIX data until upstream Apple revocation succeeds or a valid prior revocation receipt is verified. Because web OAuth does not provide the one-time code, the web flow blocks Apple-linked deletion and directs the user to the native iOS path. Invalid or missing proof requires reauthentication; configuration, Apple service, or receipt-store outages fail safely and can be retried later.
The country badge is designed to be permanent, but correction of a mistake or a legally required correction may be requested at playcontinue00@gmail.com. Access, correction, deletion, restriction, withdrawal, and appeal requests may also be sent there.
Version 1 has no advertising or advertising-consent controls because it makes no ad request and includes no advertising SDK.
Phone push is unavailable in version 1. Authenticated in-app alert categories can be controlled separately in ONEPIX. Firebase Analytics and Crashlytics consent is independent.
Turning off app-improvement data in Profile stops future optional Analytics events and Crashlytics collection, and deletes unsent crash reports remaining on the device. Information already sent remains subject to the published retention and deletion practices, and users may exercise their rights through the official contact.
8. Security, children, and changes
ONEPIX uses measures such as separated server privileges, row-level access controls, server-authoritative validation, encrypted transport, rate limits, and audit records. No system can guarantee absolute security.
ONEPIX is for people age 16 or older. The service is not offered to anyone under 16, and version 1 does not provide a parental-consent path. Policy updates show their revision and effective dates, and material changes will be announced by an appropriate method.