๐Ÿ‡บ๐Ÿ‡ธ English

Dripbook Privacy Policy

Publication Date 2026-05-11 ยท Effective Date 2026-05-11 ยท v1.0

Bublica ("the Company") respects the privacy of its users and is committed to protecting personal information in accordance with applicable laws, including the Korean Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile application Dripbook (Bundle ID: com.bublica.dripbook).

1. Information We Collect

1-1. Automatically Collected (on app install and use)

CategoryDataNotes
IdentifierAdvertising Identifier (IDFA)Only with your ATT consent
IdentifierVendor Identifier (IDFV)iOS standard, reset on app deletion
Device InfoiOS version, device model, screen resolution, language/region
Usage LogsApp launch/exit time, navigation events, ad impression and click logs
DiagnosticsCrash logs, performance metrics
NetworkIP address, access timestampFor ad delivery and abuse prevention
Server operation logsLogged-in user email, AI scan call timestamp, response result (success/failure), recognition metadata (roastery, bean name, origin, roast level)Collected on our backend for monitoring, usage limits, and abuse prevention

1-2. User-Provided Information

CategoryDataCollection Trigger
Account credentialsEmail address, passwordOn sign-up / sign-in (stored in device localStorage only; never transmitted to our servers)
Recipe dataUser-entered coffee recipes, notes, ratings, favorites listStored locally in-app (device localStorage, not sent to server)
App preferencesLanguage setting, "remember me" flagStored locally in-app (device localStorage)
InquiryEmail address, message bodyWhen you contact support
Bean bag imagePhotos of coffee bean packaging you uploadWhen using AI analysis (see ยง 15)

1-3. Device Permissions (used only with your explicit consent)

Dripbook uses the following iOS permissions, all of which trigger a system permission dialog on first use.

PermissionPurposeHow We Handle It
Camera (NSCameraUsageDescription)Take a photo of your coffee bag for AI recognitionThe captured image stays in memory and is sent off-device only when you trigger AI analysis (see ยง 15)
Photo Library โ€” Read (NSPhotoLibraryUsageDescription)Select an existing bean-bag photo from your galleryOnly the photo you actively select is processed
Photo Library โ€” Add (NSPhotoLibraryAddUsageDescription)Save a recipe card image to your gallery (optional feature)Triggered only by your explicit save action

Denying any permission still allows full use of the manual entry flow and other core features. You can change permissions anytime in iOS Settings โ†’ Dripbook.

1-4. Automatic Collection via Advertising SDK

The app integrates the following advertising SDK. Some data is collected and processed directly by the third party (Google LLC) on our behalf.

SDKGoogle Mobile Ads SDK for iOS (Capacitor wrapper: @capacitor-community/admob v8.x)
AdMob App IDca-app-pub-7332080403904454~5549308360
SKAdNetwork38 SKAdNetwork identifiers registered (Apple's privacy-preserving ad attribution standard)
Data collectedAdvertising identifier (IDFA, only with ATT consent), device info, ad impression / click data, approximate IP-based location (country / city level)
Content rating filterMaximum Ad Content Rating is enforced so that ads inconsistent with our app's age rating are filtered out

For more detail, see the Google Privacy Policy:
๐Ÿ‘‰ https://policies.google.com/privacy

2. How Long We Keep Your Data

ItemRetentionBasis
Account credentials (email, password)Until account deletion or app uninstall (stored in device localStorage; not sent to server)User consent
Auto-collected (IDFA, device info, usage)12 months from collection, or until deletion requestUser consent
Recipe data, favorites, app preferences (local)Until app is deleted (device localStorage, not sent to server)โ€”
Server operation logs (email, call time, recognition meta)Up to 30 days (Railway log retention policy)Operations / abuse prevention
Monthly AI scan usage counterAuto-resets on the 1st of every month (UTC); held in server memoryUsage management
Inquiry email records3 years after resolutione-Commerce Act ยง 6 (KR)
Ad-related logs (AdMob)14 monthsGoogle AdMob policy
Crash / diagnostic logs90 daysOperations
Uploaded images for AI analysisNot stored on our server (passes through memory and is discarded immediately). Anthropic side: up to 30 daysAnthropic data policy

3. Sharing With Third Parties

We share your information only to the extent necessary for the purposes described in ยงยง 4 and 5, and only with your consent or as required by law.

RecipientPurposeData SharedRetention
Google LLC (AdMob)Ad delivery, performance measurement, personalized advertisingIDFA (with consent), device info, ad identifiers, IPPer Google policy (~14 months)
Apple Inc.App distribution, in-app diagnostics, attribution (App Store Connect, TestFlight, SKAdNetwork)Device info, crash logs, in-app purchase info (if introduced)Per Apple policy
Anthropic, PBCAI image analysis of coffee bean bags (Claude Sonnet model)Image uploaded by user (Base64), analysis promptUp to 30 days (Anthropic policy)

We do not sell your personal information.

4. Processing on Our Behalf (Sub-processors)

ProcessorServiceCountry
Railway Corp.Backend hosting, server operation logs (infrastructure)United States
Google LLCAd serving and analytics (Google AdMob, Google Mobile Ads SDK)United States
Apple Inc.App distribution, in-app diagnostics, ad attribution (App Store Connect, TestFlight, SKAdNetwork)United States
Anthropic, PBCAI-based bean bag image analysis (Claude Sonnet)United States

5. International Data Transfers

Because Dripbook integrates Google AdMob, Apple App Store, Anthropic AI, and is hosted on Railway, certain data is transferred outside Korea.

RecipientCountryWhen & HowDataPurposeRetention
Railway Corp.USAOn API call, HTTPSEmail, IP, call timestamp, recognition metaBackend hosting / logsUp to 30 days
Google LLCUSAOn ad call, networkIDFA, device info, IPAd delivery14 months
Apple Inc.USAOn app install/launch, networkDevice info, crash logs, SKAdNetwork attribution dataApp distribution / diagnostics / ad attributionPer Apple policy
Anthropic, PBCUSAOn AI analysis use, HTTPSUploaded image (Base64), analysis promptImage AI analysisUp to 30 days

You may refuse international transfers under ยง 7 below; some features (such as personalized ads) may then be limited.

6. App Tracking Transparency (ATT)

  1. Per Apple's App Tracking Transparency framework, Dripbook requests your explicit consent before using the IDFA.
  2. You can grant or deny tracking when the system permission prompt appears on first launch.
  3. Denying tracking does not affect any core feature; you will only see non-personalized ads.
  4. Even when you deny tracking, Apple's SKAdNetwork may still perform privacy-preserving attribution; this uses only anonymized data and cannot identify you individually.
  5. You may revoke or grant consent anytime in iOS Settings โ†’ Privacy & Security โ†’ Tracking.

7. Your Rights

You may exercise the following rights at any time:

  1. Access your personal information
  2. Request correction or deletion
  3. Request restriction of processing
  4. Withdraw consent
  5. Account deletion (see ยง 16)
  6. Under GDPR (EEA users): Right to data portability, right to lodge a complaint with your supervisory authority
  7. Under CCPA (California users): Right to know what we collect, right to delete, right to opt-out of sale (we do not sell personal information)

How to exercise:

8. Data Destruction

When personal data is no longer needed, we destroy it without delay.

9. Security Measures

10. Automatic Collection Tools and Opt-Out

  1. Dripbook uses IDFA, IDFV, and device localStorage for advertising and service improvement.
  2. localStorage usage: login session, favorites list (max 10), language setting, "remember me" flag โ€” stored only on your device, never sent to our server.
  3. You may block tracking and clear local storage at any time:
    • iOS Settings โ†’ Privacy & Security โ†’ Tracking โ†’ "Allow Apps to Request to Track" OFF
    • iOS Settings โ†’ Privacy & Security โ†’ Apple Advertising โ†’ "Personalized Ads" OFF
    • Delete the app: removes all locally stored data on the device.
  4. If you block tracking, you'll see only non-personalized ads.

11. Children's Privacy

  1. Dripbook's App Store age rating is 12+. However, in compliance with the Korean Personal Information Protection Act (Article 22-2), we do not collect personal information from children under 14 in Korea without verifiable consent from a legal guardian.
  2. During sign-up, the user confirms they are 14 or older. If we discover that an account was created by someone under 14 without legal-guardian consent, we delete the account and all related data immediately.
  3. Parents or legal guardians who suspect their child under 14 is using this app may notify us at bublica@naver.com; we will erase the relevant data without delay.
  4. Ad content is filtered via Maximum Ad Content Rating to ensure only ads compatible with the 12+ rating are served.

12. Data Protection Officer (DPO)

13. Complaints & Remedies (Korea)

AuthorityPhoneWebsite
Personal Info Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Info Infringement Center (KISA)118privacy.kisa.or.kr
Cybercrime Investigation Unit1301www.spo.go.kr
National Police Cyber Bureau182cyberbureau.police.go.kr

14. AI Image Analysis

Dripbook uses Anthropic Claude Sonnet (claude-sonnet-4-6 or successors) for automatic bean bag image recognition.

14-1. Purpose

14-2. Model & Processor

ModelAnthropic Claude Sonnet (claude-sonnet-4-6)
ProcessorAnthropic, PBC
Processing LocationUnited States
TransportHTTPS / TLS encryption

14-3. Data Flow

  1. You take or upload a coffee bean bag photo in-app.
  2. Our backend (Dripbook server, Railway hosting) Base64-encodes the image and sends it to the Anthropic API (https://api.anthropic.com/v1/messages).
  3. Anthropic's API returns analysis results in JSON.
  4. Our server forwards only the JSON results to the app; the original image is never persisted on our servers (passes through memory and is immediately discarded).
  5. For monitoring and abuse prevention, only the call metadata (email, timestamp, recognition summary: roastery, bean name, origin, roast level) is recorded in our server logs and retained for up to 30 days (see ยง 1-1).

14-4. Anthropic Data Policy

14-5. Usage Limits

To protect against abuse and runaway costs, AI scan calls are limited to 30 per account per month. The counter resets automatically on the 1st of every month (UTC). The Manual Entry flow is unlimited and unaffected by this cap.

14-6. Your Rights and Cautions

15. Changes to This Policy

  1. This Privacy Policy applies from the effective date. We will notify users of any changes at least 7 days before they take effect via in-app notice or this page.
  2. For material changes affecting user rights, notice will be given at least 30 days in advance.

16. Account Deletion

  1. You may delete your account and associated data at any time.
  2. In-app deletion (recommended): Tap [Account โ†’ Delete account] in the top-right of the app. The following data is deleted immediately and automatically:
    • Device localStorage: account credentials (email, password), favorites, review & auto-tune data, app preferences
    • Server in-memory monthly AI scan usage counter
  3. Server operation logs (email, call timestamps, recognition metadata) are automatically discarded according to our retention policy โ€” up to 30 days from collection (see ยง 2). No separate manual deletion request is required.
  4. Email request (fallback): If you cannot use the app, you may email bublica@naver.com; we will process the request within 7 days.
  5. Data legally required to be preserved (e.g. inquiry records for 3 years under the e-Commerce Act) will be held in isolated storage for the prescribed period and then destroyed.

17. Governing Law and Disputes

  1. This Privacy Policy is governed by the laws of the Republic of Korea.
  2. Any disputes shall be brought in the competent courts of Korea under the Civil Procedure Act.

Appendix

Publication2026-05-11
Effective2026-05-11
Current Versionv1.0
OperatorBublica
RepresentativeHyunmin Park
Business Reg. No.656-79-00658
Mail-Order Reg. No.N/A
Address48-8 Hotan-gil, Geumnam-myeon, Sejong, Republic of Korea (2nd floor)
Emailbublica@naver.com
App NameDripbook
Bundle IDcom.bublica.dripbook
Policy URLhttps://dripbook.bublica.com/privacy/en

Revision History

VersionDateChanges
v1.02026-05-11Initial publication