pupube Privacy Policy

Last updated and effective: 2026-09-22

Group features are available in app versions and servers that support them. Revising this document does not automatically expand existing space membership or the recipients of stored records. Disclosure of personal information requiring separate consent is limited to the scope of the consent obtained.

pupube provides a service that allows connected users to share selected app notifications, chats, schedules, and albums. This policy explains how pupube processes personal information necessary to provide services.

pupube processes notification data only within the scope of sharing with apps that the user has directly set to share. Notifications from apps not set up by the user will not be sent to the other party.

1. Personal Information We Process and Why

divisionitemPurpose of processing
Account/Authentication Firebase UID, Google / Apple /Email Login account email, display name, profile picture URL, authentication provider, FCM token, email authentication number request/verification time and IP address hash. The original text of the authentication number is not stored in the server database. Login, user identification, device push sending, account restoration
Onboarding/Space Nickname, selected gender and date of birth, invitation code/invitation link, space ID, space name, member, relationship start date Registration, invitations and group spaces for up to 4 people
iOS Apply for release notification Phone number, invitation code, consent time, IP address hash and browser information to protect the service. pupube iOS Release and invitation connection guidance, prevention of fraudulent applications. It will not be used for advertising or general marketing purposes.
Incoming external installation links Link identifier, inflow medium/campaign value, Android Google Play hash of the signature token delivered to the Install Referrer, and subscription attribution time. Daily tally by link (Click·Play movement· iOS information·Sign up) Aggregation of store movement and subscription performance for each externally installed link, prevention of link operation and fraudulent aggregation. The link visitor's IP address, overall browser information, and original referrer value are not stored for inflow performance analysis.
Share notifications Shared app name, package name, app icon, sharing level, filter, notification title/body, sender name, occurrence time, duplicate prevention key, delivery record Share selected app notifications, display notification center, prevent duplication/mis-sending, respond to failures
Contact Recommendations Display name and phone number for device contacts Recommend contact candidates when entering text/message sender filters. The original contact information is not sent to the server, but only the name and number selected by the user are saved as sharing conditions.
Chat/Schedule/Album Chat message, image message, voice message, schedule title/date/time/memo/color, album photo, photo description, upload user and time Provides in-space chat, calendar, and album functions
Membership/Payment Space membership level, product ID, base plan ID, payment cycle, order/transaction ID, purchase token hash and some identification values, subscription status, App Store server notification hash and lifecycle metadata. Google Play and Apple App Store Payment verification, paid authorization, expiration/downgrade processing, customer support
Operations/Security Service usage events, error logs, API request time, basic network information, administrator processing records, server failure and abnormal usage detection information Failure response, security, fraud prevention, performance improvement, operational indicator verification
Conversion diagnosis before signing up Server-side key hash of the random installation token generated by the app, app execution/login screen/authentication start/completion/account creation steps, app version and operating system Check for errors and deviations in the sign-up flow after installation. The original installation token is not stored, and advertising identifier, account, email, IP, conversation, and notification contents are not included.
Service analysis and advertising performance measurement (optional) Firebase App instance identifier, usage events such as app execution/screen view/invitation connection completion/server verification purchase completion, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app version/operating system/device type, advertising consent/ ATT status, advertising identifier if allowed Analysis of service use by users who have agreed to separate selection and measurement of Google Ads · Meta advertising campaign performance. Conversation/Notification title/text/invitation code/email/nickname/receipt/purchase token/original order/transaction ID are not included in the event.
safety report Reporter/reporter identification value, reason for reporting, description entered by the user, up to 20 recent conversations that the user agreed to send when reporting, and report/blocking processing records Review and act on safety issues, including harassment, threats, spam, inappropriate content, and prevent reconnection

iOS Applications for release notifications will only be processed if separate consent to collection and use of phone numbers is obtained. You may refuse consent, but in this case, you will not be able to apply for iOS release notification.

2. Sensitive Permissions and Shared Data

Notification access rights

pupube uses the Android notification access permission. This permission is used to detect notifications from apps that the user has set up for sharing on their device, and only deliver them to the connected space if they match the sharing level and filters the user has selected.

Contact Permissions

pupube can use the Android contact permission to easily set message sender filters. The purpose is to recommend candidates from the device's contacts when the user enters a number or name, and the original contact list is not sent to the server. When a user selects a recommendation, only the selected name and number are saved as sharing conditions.

Photos, files, microphone

Photos/images are only processed when users upload them to chat or albums. Voice messages are only uploaded if you record and send them. The app does not randomly record your voice in the background.

iOS App Tracking Transparency (ATT )

When serving advertisements to free users, we may request permission for iOS system tracking to measure advertisement performance and reduce repeated exposure to the same advertisement. The advertising SDK will not be initialized before you allow, and even if you decline, you will still be able to use non-personalized ads and all app features.

safety report

Only if a user submits a report directly from the chat screen, the reason for the report, any optional description, and up to 20 recent conversations with the person being reported will be sent for operational review. Selecting Report and Block will disconnect your current space and prevent both users from reconnecting. The details of the report will not be disclosed to the person being reported.

3. Service Providers and Third-Party Processing

Up to 4 people use this space. Current and future invited members can see retained alerts, chats, photos, voice messages, events and display names for shared group use. Retention follows the space plan; copies saved by members cannot be recalled. Adding a member pauses alert sharing until each phone owner reviews their settings. Send invite links only to people who agree. You may decline; creating, joining or expanding a group then remains unavailable, but you can continue using your existing space.

pupube does not sell personal information. The external services below may be used to provide services.

Trustee or Provided ServicesPurpose of useInformation processed
Firebase AuthenticationGoogle login, Apple login, Firebase custom token session issuance and user authenticationAccount identification information
Resend (Plus Five Five, Inc.)Email authentication number transaction email sentReceiving email address, email content including 6-digit authentication number, and sending metadata
Firebase Cloud MessagingSend push notificationsFCM Token, notification sending information
Firebase Remote ConfigCheck, update, apply operational settingsApp version and settings request information
Firebase Analytics and Google AdsAnalysis of service use by users who have agreed to separate selection and measurement of invitation connection/purchase advertising performanceApp instance identifier, usage events such as app launch, screen view, invitation connection completion, server verification purchase completion, purchase product, plan, payment cycle, amount, currency, hash transaction ID, app and device information, advertising consent· ATT status and allowed advertising identifier. Conversation/notification contents/invitation code/email/nickname/receipt/purchase token/original order/transaction ID are not transmitted.
Meta App EventsMeasuring advertising performance through invitation connection/purchase for users who consent to separate selectionpartner_invite_completedand standard Purchase Event, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app/device/network information, advertising consent/ ATT status and allowed advertising identifier. Receipts, purchase tokens, and original order/transaction IDs are not transmitted, and automatic event collection is not used.
Shorebird Code PushCheck and download emergency error fixes for Flutter executable codeApp ID, operating system/device architecture, app version, patch number, anonymous app-specific device identifier, and IP address of security/operation logs. Conversations, notifications, albums, and account information are not transmitted.
Google Play Billing / Google Play Developer API, Apple App StoreSubscription payment and receipt· StoreKit 2 Signature transaction verificationProduct ID, order/transaction ID, purchase token or receipt identifier, subscription status. App Store The original text of the server notification is not saved after verification, but only the hash and life cycle metadata are kept.
Google AdMob and User Messaging PlatformNon-personalized advertising, opt-in consent display, advertising frequency control and performance measurementAdvertising identifier, consent· ATT status, approximate location, ad exposure·click·performance information. In iOS, after agreeing and selecting ATT, initialize the advertising SDK and disable publisher primary identifier and SDK self-conflict reporting.
Cloudflare R2Archive images and audio filesUpload files and metadata
Oracle Cloud Infrastructure Chuncheon Region, Republic of KoreaAPI Server operation, database storage, backup, securityStored data required for service provision and key hash of conversion diagnosis before subscription, stored for 31 days
Discord WebhookNotification of non-identifying operations, such as detecting server failures and abnormal usage, checking the subscription flow of new installations, and connecting new spacesMinimum operational information excluding user identification information, nickname, email, invitation code, installation token, advertising ID, IP, conversation, and report content, including operating environment, occurrence time, registration stage, operating system, app version, login method, authentication result category, processing stage, space type, number of people, etc.

Connected space members will see notifications, chats, calendars, and album data shared or created by users to provide service features.

4. International Transfers of Personal Information

Personal information may be processed and stored overseas as follows to provide authentication, push, file storage, advertising/consent management, and store payment functions necessary for concluding and implementing service contracts. Transmission takes place through encrypted network communication when using the service.

Transfer recipient and contact informationPrevious itemprevious countryWhen and howpurposeRetention/Use Period
Google LLC
Personal information inquiry
Email, Authentication Provider, Firebase UID, Login Request Information USA Encrypted transmission when requesting login/account restoration Firebase Authentication User Authentication Until account deletion or authentication information is deleted. After Google period according to policies and laws
Plus Five Five, Inc. d/b/a Resend
Personal information inquiry
Transactional email content including receiving email address, 6-digit authentication number, and sending metadata United States and Resend Service processing countries Encrypted transmission when sending email authentication number Send email verification number Resend Period according to policy and contract
Google LLC
Personal information inquiry
FCM token, app version/setting request information, app instance identifier/usage event/purchase product/rate plan/payment cycle/amount/currency/hash upon consent to selection/transaction ID/device/app information/ad consent· ATT status/allowed advertising identifier, ad exposure/click/performance information, product/transaction/subscription information for store payment verification United States and Google Global Infrastructure Operating Countries Encrypted transmission when using push, remote setting, analysis, advertising, and payment functions FCM Push sending, Remote Config operation settings, service usage analysis, invitation connection/purchase ad performance measurement, AdMob non-personalized advertisement, ad frequency control/consent management, Google Play Payment verification The period required to provide each function and fulfill related legal obligations. Account, token, and service data are organized according to deletion requests and Google policy.
Meta Platforms, Inc.
Personal information inquiry
App ID upon consent of selection, partner_invite_completedand standard Purchase Event, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app/device/network information, advertising consent· ATT status, advertising identifier if allowed. Receipt, purchase token, or original order/transaction ID are not transmitted. United States and Meta Global Infrastructure Operating Countries Encrypted transmission after confirmation of invitation connection or completion of server verification purchase Meta Measuring and optimizing invitation connection and purchase performance of advertising campaigns Sent until consent is withdrawn, and the transmitted information is stored for a period of time according to the Meta policy and advertising account settings.
Cloudflare, Inc.
Personal information inquiry
User-uploaded chat and album images, voice files, object keys and file metadata Cloudflare 's Asia Pacific (APAC) storage and processing region and service processing countries such as the United States. APAC location hints do not guarantee a specific country Encrypted transmission when users upload, view, or delete files File storage and transfer Until the end of the membership storage period at the time of creation and the deletion waiting period of this processing policy.
Apple Inc. and Apple Distribution International Ltd.
Personal information inquiry
Apple Login identification, product ID, transaction ID, subscription status, StoreKit signature transaction information United States, Ireland and Apple Service Processing Countries Apple Encrypted transmission when logging in, purchasing, restoring, or changing status of a subscription Apple Login, App Store Verify payment and subscription status The period required to process accounts/subscriptions and fulfill legal obligations, as well as the period in accordance with the Apple policy.
Code Town, Inc. d/b/a Shorebird
Personal information inquiry
App ID, operating system/device architecture, app version, patch number, anonymous app-specific device identifier, IP address of security/operation logs USA Encrypted transmission during patch check/download process when starting the app Provide emergency error fixes for Flutter executable code, monitor security and operations The period required for patch provision and security operations and the period in accordance with the Shorebird policy

Users who do not wish to transfer overseas can stop processing by deleting their account within the app or contacting us. However, if you refuse overseas processing required for authentication, push, file storage, or store payment, use of the corresponding function or service may be restricted. Service analysis and advertising performance measurement can be selected upon signing up or More > Settings > Service analysis and advertising performance measurementYou can withdraw at any time. Withdrawal will not limit the functionality of the app and will stop future transmissions of Firebase Analytics and Meta App Events. You can change your consent to advertising on the app's privacy selection screen, and iOS tracking permissions can be changed in your device settings.

5. Retention and Deletion

6. Deletion Procedures and Methods

Personal information whose retention period has expired or whose processing purpose has been achieved is deleted or anonymized without delay. Electronic files are deleted to make recovery difficult, and printed output is destroyed by shredding or similar methods.

7. Your Rights

Users may request to view, correct, delete, suspend processing, or withdraw consent to their personal information. Account deletion can be initiated directly from the app under More > Account > Delete Account. If you cannot use the app Account deletion instructionsYou can request support via the support request form, email, or phone and will process it after verifying your identity. iOS You can also request cancellation of release notification application and viewing/correction/deletion of phone number by contacting the contact information below.

8. Security Measures

9. Users Under 14

This service is for users aged 14 or older. We currently do not provide a parental consent process for users under 14.

10. Changes to This Policy

If the processing policy changes, the last update date on this page will be updated, and any significant changes will be notified through the app or website.

11. Privacy Contact

Service name: pupube / pupube
Personal Information Protection Manager: pupube Administrator
email: [email protected]
phone call: 010-7364-2623
Privacy Policy URL: https://pupube.com/privacy
Terms of Use URL: https://pupube.com/terms