pupube Privacy Policy
Last updated and effective: 2026-09-22
Group features are available in app versions and servers that support them. Revising this document does not automatically expand existing space membership or the recipients of stored records. Disclosure of personal information requiring separate consent is limited to the scope of the consent obtained.
pupube provides a service that allows connected users to share selected app notifications, chats, schedules, and albums. This policy explains how pupube processes personal information necessary to provide services.
pupube processes notification data only within the scope of sharing with apps that the user has directly set to share. Notifications from apps not set up by the user will not be sent to the other party.
1. Personal Information We Process and Why
| division | item | Purpose of processing |
|---|---|---|
| Account/Authentication | Firebase UID, Google / Apple /Email Login account email, display name, profile picture URL, authentication provider, FCM token, email authentication number request/verification time and IP address hash. The original text of the authentication number is not stored in the server database. | Login, user identification, device push sending, account restoration |
| Onboarding/Space | Nickname, selected gender and date of birth, invitation code/invitation link, space ID, space name, member, relationship start date | Registration, invitations and group spaces for up to 4 people |
| iOS Apply for release notification | Phone number, invitation code, consent time, IP address hash and browser information to protect the service. | pupube iOS Release and invitation connection guidance, prevention of fraudulent applications. It will not be used for advertising or general marketing purposes. |
| Incoming external installation links | Link identifier, inflow medium/campaign value, Android Google Play hash of the signature token delivered to the Install Referrer, and subscription attribution time. Daily tally by link (Click·Play movement· iOS information·Sign up) | Aggregation of store movement and subscription performance for each externally installed link, prevention of link operation and fraudulent aggregation. The link visitor's IP address, overall browser information, and original referrer value are not stored for inflow performance analysis. |
| Share notifications | Shared app name, package name, app icon, sharing level, filter, notification title/body, sender name, occurrence time, duplicate prevention key, delivery record | Share selected app notifications, display notification center, prevent duplication/mis-sending, respond to failures |
| Contact Recommendations | Display name and phone number for device contacts | Recommend contact candidates when entering text/message sender filters. The original contact information is not sent to the server, but only the name and number selected by the user are saved as sharing conditions. |
| Chat/Schedule/Album | Chat message, image message, voice message, schedule title/date/time/memo/color, album photo, photo description, upload user and time | Provides in-space chat, calendar, and album functions |
| Membership/Payment | Space membership level, product ID, base plan ID, payment cycle, order/transaction ID, purchase token hash and some identification values, subscription status, App Store server notification hash and lifecycle metadata. | Google Play and Apple App Store Payment verification, paid authorization, expiration/downgrade processing, customer support |
| Operations/Security | Service usage events, error logs, API request time, basic network information, administrator processing records, server failure and abnormal usage detection information | Failure response, security, fraud prevention, performance improvement, operational indicator verification |
| Conversion diagnosis before signing up | Server-side key hash of the random installation token generated by the app, app execution/login screen/authentication start/completion/account creation steps, app version and operating system | Check for errors and deviations in the sign-up flow after installation. The original installation token is not stored, and advertising identifier, account, email, IP, conversation, and notification contents are not included. |
| Service analysis and advertising performance measurement (optional) | Firebase App instance identifier, usage events such as app execution/screen view/invitation connection completion/server verification purchase completion, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app version/operating system/device type, advertising consent/ ATT status, advertising identifier if allowed | Analysis of service use by users who have agreed to separate selection and measurement of Google Ads · Meta advertising campaign performance. Conversation/Notification title/text/invitation code/email/nickname/receipt/purchase token/original order/transaction ID are not included in the event. |
| safety report | Reporter/reporter identification value, reason for reporting, description entered by the user, up to 20 recent conversations that the user agreed to send when reporting, and report/blocking processing records | Review and act on safety issues, including harassment, threats, spam, inappropriate content, and prevent reconnection |
iOS Applications for release notifications will only be processed if separate consent to collection and use of phone numbers is obtained. You may refuse consent, but in this case, you will not be able to apply for iOS release notification.
2. Sensitive Permissions and Shared Data
Notification access rights
pupube uses the Android notification access permission. This permission is used to detect notifications from apps that the user has set up for sharing on their device, and only deliver them to the connected space if they match the sharing level and filters the user has selected.
Contact Permissions
pupube can use the Android contact permission to easily set message sender filters. The purpose is to recommend candidates from the device's contacts when the user enters a number or name, and the original contact list is not sent to the server. When a user selects a recommendation, only the selected name and number are saved as sharing conditions.
Photos, files, microphone
Photos/images are only processed when users upload them to chat or albums. Voice messages are only uploaded if you record and send them. The app does not randomly record your voice in the background.
iOS App Tracking Transparency (ATT )
When serving advertisements to free users, we may request permission for iOS system tracking to measure advertisement performance and reduce repeated exposure to the same advertisement. The advertising SDK will not be initialized before you allow, and even if you decline, you will still be able to use non-personalized ads and all app features.
safety report
Only if a user submits a report directly from the chat screen, the reason for the report, any optional description, and up to 20 recent conversations with the person being reported will be sent for operational review. Selecting Report and Block will disconnect your current space and prevent both users from reconnecting. The details of the report will not be disclosed to the person being reported.
3. Service Providers and Third-Party Processing
Up to 4 people use this space. Current and future invited members can see retained alerts, chats, photos, voice messages, events and display names for shared group use. Retention follows the space plan; copies saved by members cannot be recalled. Adding a member pauses alert sharing until each phone owner reviews their settings. Send invite links only to people who agree. You may decline; creating, joining or expanding a group then remains unavailable, but you can continue using your existing space.
pupube does not sell personal information. The external services below may be used to provide services.
| Trustee or Provided Services | Purpose of use | Information processed |
|---|---|---|
| Firebase Authentication | Google login, Apple login, Firebase custom token session issuance and user authentication | Account identification information |
| Resend (Plus Five Five, Inc.) | Email authentication number transaction email sent | Receiving email address, email content including 6-digit authentication number, and sending metadata |
| Firebase Cloud Messaging | Send push notifications | FCM Token, notification sending information |
| Firebase Remote Config | Check, update, apply operational settings | App version and settings request information |
| Firebase Analytics and Google Ads | Analysis of service use by users who have agreed to separate selection and measurement of invitation connection/purchase advertising performance | App instance identifier, usage events such as app launch, screen view, invitation connection completion, server verification purchase completion, purchase product, plan, payment cycle, amount, currency, hash transaction ID, app and device information, advertising consent· ATT status and allowed advertising identifier. Conversation/notification contents/invitation code/email/nickname/receipt/purchase token/original order/transaction ID are not transmitted. |
| Meta App Events | Measuring advertising performance through invitation connection/purchase for users who consent to separate selection | partner_invite_completedand standard Purchase Event, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app/device/network information, advertising consent/ ATT status and allowed advertising identifier. Receipts, purchase tokens, and original order/transaction IDs are not transmitted, and automatic event collection is not used. |
| Shorebird Code Push | Check and download emergency error fixes for Flutter executable code | App ID, operating system/device architecture, app version, patch number, anonymous app-specific device identifier, and IP address of security/operation logs. Conversations, notifications, albums, and account information are not transmitted. |
| Google Play Billing / Google Play Developer API, Apple App Store | Subscription payment and receipt· StoreKit 2 Signature transaction verification | Product ID, order/transaction ID, purchase token or receipt identifier, subscription status. App Store The original text of the server notification is not saved after verification, but only the hash and life cycle metadata are kept. |
| Google AdMob and User Messaging Platform | Non-personalized advertising, opt-in consent display, advertising frequency control and performance measurement | Advertising identifier, consent· ATT status, approximate location, ad exposure·click·performance information. In iOS, after agreeing and selecting ATT, initialize the advertising SDK and disable publisher primary identifier and SDK self-conflict reporting. |
| Cloudflare R2 | Archive images and audio files | Upload files and metadata |
| Oracle Cloud Infrastructure Chuncheon Region, Republic of Korea | API Server operation, database storage, backup, security | Stored data required for service provision and key hash of conversion diagnosis before subscription, stored for 31 days |
| Discord Webhook | Notification of non-identifying operations, such as detecting server failures and abnormal usage, checking the subscription flow of new installations, and connecting new spaces | Minimum operational information excluding user identification information, nickname, email, invitation code, installation token, advertising ID, IP, conversation, and report content, including operating environment, occurrence time, registration stage, operating system, app version, login method, authentication result category, processing stage, space type, number of people, etc. |
Connected space members will see notifications, chats, calendars, and album data shared or created by users to provide service features.
4. International Transfers of Personal Information
Personal information may be processed and stored overseas as follows to provide authentication, push, file storage, advertising/consent management, and store payment functions necessary for concluding and implementing service contracts. Transmission takes place through encrypted network communication when using the service.
| Transfer recipient and contact information | Previous item | previous country | When and how | purpose | Retention/Use Period |
|---|---|---|---|---|---|
| Google LLC Personal information inquiry |
Email, Authentication Provider, Firebase UID, Login Request Information | USA | Encrypted transmission when requesting login/account restoration | Firebase Authentication User Authentication | Until account deletion or authentication information is deleted. After Google period according to policies and laws |
| Plus Five Five, Inc. d/b/a Resend Personal information inquiry |
Transactional email content including receiving email address, 6-digit authentication number, and sending metadata | United States and Resend Service processing countries | Encrypted transmission when sending email authentication number | Send email verification number | Resend Period according to policy and contract |
| Google LLC Personal information inquiry |
FCM token, app version/setting request information, app instance identifier/usage event/purchase product/rate plan/payment cycle/amount/currency/hash upon consent to selection/transaction ID/device/app information/ad consent· ATT status/allowed advertising identifier, ad exposure/click/performance information, product/transaction/subscription information for store payment verification | United States and Google Global Infrastructure Operating Countries | Encrypted transmission when using push, remote setting, analysis, advertising, and payment functions | FCM Push sending, Remote Config operation settings, service usage analysis, invitation connection/purchase ad performance measurement, AdMob non-personalized advertisement, ad frequency control/consent management, Google Play Payment verification | The period required to provide each function and fulfill related legal obligations. Account, token, and service data are organized according to deletion requests and Google policy. |
| Meta Platforms, Inc. Personal information inquiry |
App ID upon consent of selection, partner_invite_completedand standard Purchase Event, purchased product/rate plan/payment cycle/amount/currency/hash transaction ID, app/device/network information, advertising consent· ATT status, advertising identifier if allowed. Receipt, purchase token, or original order/transaction ID are not transmitted. |
United States and Meta Global Infrastructure Operating Countries | Encrypted transmission after confirmation of invitation connection or completion of server verification purchase | Meta Measuring and optimizing invitation connection and purchase performance of advertising campaigns | Sent until consent is withdrawn, and the transmitted information is stored for a period of time according to the Meta policy and advertising account settings. |
| Cloudflare, Inc. Personal information inquiry |
User-uploaded chat and album images, voice files, object keys and file metadata | Cloudflare 's Asia Pacific (APAC) storage and processing region and service processing countries such as the United States. APAC location hints do not guarantee a specific country | Encrypted transmission when users upload, view, or delete files | File storage and transfer | Until the end of the membership storage period at the time of creation and the deletion waiting period of this processing policy. |
| Apple Inc. and Apple Distribution International Ltd. Personal information inquiry |
Apple Login identification, product ID, transaction ID, subscription status, StoreKit signature transaction information | United States, Ireland and Apple Service Processing Countries | Apple Encrypted transmission when logging in, purchasing, restoring, or changing status of a subscription | Apple Login, App Store Verify payment and subscription status | The period required to process accounts/subscriptions and fulfill legal obligations, as well as the period in accordance with the Apple policy. |
| Code Town, Inc. d/b/a Shorebird Personal information inquiry |
App ID, operating system/device architecture, app version, patch number, anonymous app-specific device identifier, IP address of security/operation logs | USA | Encrypted transmission during patch check/download process when starting the app | Provide emergency error fixes for Flutter executable code, monitor security and operations | The period required for patch provision and security operations and the period in accordance with the Shorebird policy |
Users who do not wish to transfer overseas can stop processing by deleting their account within the app or contacting us. However, if you refuse overseas processing required for authentication, push, file storage, or store payment, use of the corresponding function or service may be restricted. Service analysis and advertising performance measurement can be selected upon signing up or More > Settings > Service analysis and advertising performance measurementYou can withdraw at any time. Withdrawal will not limit the functionality of the app and will stop future transmissions of Firebase Analytics and Meta App Events. You can change your consent to advertising on the app's privacy selection screen, and iOS tracking permissions can be changed in your device settings.
5. Retention and Deletion
- We retain your account, onboarding, and space connection information for as long as your account or space remains active.
- A Free space retains notification, chat, image, and voice history for 7 days, and calendar use is limited to the current month.
- A Plus space retains notification, chat, image, voice, and calendar data for 1 year.
- Together and Premium spaces retain notification, chat, image, voice, and calendar data for 3 years.
- Photo uploads are limited to a maximum of 10 per space per day, regardless of membership level.
- The email authentication number challenge only stores the HMAC hash, time, and sending status of the email, authentication number, and IP for up to 1 day after expiration and is automatically deleted. The original authentication number is not stored in the server database.
- iOS Release notification application information is stored for 30 days after sending the release notice or 12 months from the application date, whichever comes first, and then deleted.
- External installation link sign-up token hash for attribution is automatically deleted after up to 45 days. Daily aggregates for each link are stored as operational statistics that do not identify individuals, and inflow sources linked to an account are deleted or anonymized when the account is deleted.
- Random installation token key hashes from pre-registration conversion diagnostics are automatically deleted after up to 31 days. We do not store source tokens, advertising identifiers, accounts, emails or IP addresses.
- A 3-day grace period applies when membership expires or downgrades. At the end of the grace period, apps shared over the limit will not be deleted but will be converted to an inactive state. Notification, chat, image, voice, and schedule data are displayed based on the storage period of the space plan at the time of creation. When the storage period ends, it is hidden from the screen and a 14-day waiting period for deletion is provided. Before physical deletion, we repeatedly notify you based on the following basic criteria: 7 days ago, 3 days ago, 1 day ago, and on the same day. If you upgrade before deletion, the retention period will be extended based on the new plan and may be marked for recovery. Data that has passed the 14-day deletion waiting period will be deleted or anonymized.
- We do not keep the original text and files of deleted data, but we may keep deletion clues such as data type, number, date range, and deletion time for customer inquiries and operational verification.
- Operation logs and delivery attempt records are stored for the period necessary for failure response, security, and prevention of unauthorized use, and are then organized sequentially.
- Information that requires storage by law may be stored separately for the period specified in the law.
6. Deletion Procedures and Methods
Personal information whose retention period has expired or whose processing purpose has been achieved is deleted or anonymized without delay. Electronic files are deleted to make recovery difficult, and printed output is destroyed by shredding or similar methods.
7. Your Rights
Users may request to view, correct, delete, suspend processing, or withdraw consent to their personal information. Account deletion can be initiated directly from the app under More > Account > Delete Account. If you cannot use the app Account deletion instructionsYou can request support via the support request form, email, or phone and will process it after verifying your identity. iOS You can also request cancellation of release notification application and viewing/correction/deletion of phone number by contacting the contact information below.
8. Security Measures
- HTTPS -based communication and authentication token verification
- Check request permissions for each user and restrict administrator access
- Instead of the original text of the purchase token, the server stores the hash and some identification values.
- Prevent duplication of notifications, detect abnormal usage, and monitor operations
- Data display on both servers and apps is restricted, hidden, and organized after the maximum retention period according to membership policy.
9. Users Under 14
This service is for users aged 14 or older. We currently do not provide a parental consent process for users under 14.
10. Changes to This Policy
If the processing policy changes, the last update date on this page will be updated, and any significant changes will be notified through the app or website.
11. Privacy Contact
Service name: pupube / pupube
Personal Information Protection Manager: pupube Administrator
email: [email protected]
phone call: 010-7364-2623
Privacy Policy URL: https://pupube.com/privacy
Terms of Use URL: https://pupube.com/terms