🇺🇸 English

Dripbook Privacy Policy

Publication Date 2026-07-21 · Effective Date 2026-07-21 · v1.1

Bublica ("the Company") respects the privacy of its users and is committed to protecting personal information in accordance with applicable laws, including the Korean Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile application Dripbook (Bundle ID: com.bublica.dripbook).

1. Information We Collect

1-1. Automatically Collected (on app install and use)

CategoryDataNotes
IdentifierVendor Identifier (IDFV)iOS standard, reset on app deletion
Device InfoiOS version, device model, screen resolution, language/region
Usage LogsApp launch/exit time, navigation events
Service Data (server)Check-in history, bean (in-app point) balance and transactions, weekly mission progressStored per account on our backend while you are signed in
DiagnosticsCrash logs, performance metrics
NetworkIP address, access timestampFor abuse prevention
Server operation logsLogged-in user email, AI scan call timestamp, response result (success/failure), recognition metadata (roastery, bean name, origin, roast level)Collected on our backend for monitoring, usage limits, and abuse prevention

1-2. User-Provided Information

CategoryDataCollection Trigger
Account infoEmail address and profile name received from your social login provider (or an internal identifier for Kakao)On social sign-in (see § 6 — we never collect passwords)
NicknameThe nickname you choose in-appOn first sign-in (stored in device localStorage only)
Recipe dataUser-entered coffee recipes, notes, ratings, favorites listStored locally in-app (device localStorage, not sent to server)
App preferencesLanguage setting, "remember me" flagStored locally in-app (device localStorage)
InquiryEmail address, message bodyWhen you contact support
Bean bag imagePhotos of coffee bean packaging you uploadWhen using AI analysis (see § 15)

1-3. Device Permissions (used only with your explicit consent)

Dripbook uses the following iOS permissions, all of which trigger a system permission dialog on first use.

PermissionPurposeHow We Handle It
Camera (NSCameraUsageDescription)Take a photo of your coffee bag for AI recognitionThe captured image stays in memory and is sent off-device only when you trigger AI analysis (see § 15)
Photo Library — Read (NSPhotoLibraryUsageDescription)Select an existing bean-bag photo from your galleryOnly the photo you actively select is processed
Photo Library — Add (NSPhotoLibraryAddUsageDescription)Save a recipe card image to your gallery (optional feature)Triggered only by your explicit save action

Denying any permission still allows full use of the manual entry flow and other core features. You can change permissions anytime in iOS Settings → Dripbook.

1-4. Advertising SDK

Dripbook serves no ads and includes no advertising SDK (Google AdMob was removed in v1.1). We do not collect advertising identifiers (IDFA/ADID).

2. How Long We Keep Your Data

ItemRetentionBasis
Account info (social login email or internal identifier)Until account deletionUser consent
Check-in / bean / mission dataUntil account deletionService provision
Session tokens90 days from issuance (re-login required after expiry)Authentication
Auto-collected (device info, usage)12 months from collection, or until deletion requestUser consent
Recipe data, favorites, app preferences (local)Until app is deleted (device localStorage, not sent to server)—
Server operation logs (email, call time, recognition meta)Up to 30 days (Railway log retention policy)Operations / abuse prevention
Monthly AI scan usage counterAuto-resets on the 1st of every month (UTC); held in server memoryUsage management
Inquiry email records3 years after resolutione-Commerce Act § 6 (KR)
Crash / diagnostic logs90 daysOperations
Uploaded images for AI analysisNot stored on our server (passes through memory and is discarded immediately). Anthropic side: up to 30 daysAnthropic data policy

3. Sharing With Third Parties

We share your information only to the extent necessary for the purposes described in §§ 4 and 5, and only with your consent or as required by law.

RecipientPurposeData SharedRetention
Google LLCGoogle social sign-in authenticationAuthentication request (in return we receive your email, profile name, and account ID)Per Google policy
Apple Inc.App distribution, in-app diagnostics, Sign in with AppleDevice info, crash logs, Apple sign-in authentication dataPer Apple policy
Kakao Corp.Kakao social sign-in authenticationAuthentication request (in return we receive only a unique member identifier — no email or profile data)Per Kakao policy
Anthropic, PBCAI image analysis of coffee bean bags (Claude Sonnet model)Image uploaded by user (Base64), analysis promptUp to 30 days (Anthropic policy)

We do not sell your personal information.

4. Processing on Our Behalf (Sub-processors)

ProcessorServiceCountry
Railway Corp.Backend hosting, server operation logs (infrastructure)United States
Apple Inc.App distribution, in-app diagnostics (App Store Connect, TestFlight)United States
Anthropic, PBCAI-based bean bag image analysis (Claude Sonnet)United States

5. International Data Transfers

Because Dripbook uses the Apple App Store and Google Play, social sign-in (Google and Apple), Anthropic AI, and Railway hosting, certain data is transferred outside Korea. (Kakao sign-in is processed in Korea.)

RecipientCountryWhen & HowDataPurposeRetention
Railway Corp.USAOn API call, HTTPSEmail, IP, call timestamp, recognition metaBackend hosting / logsUp to 30 days
Google LLCUSAOn Google sign-in, HTTPSAuthentication data (email, profile name, account ID)Social sign-inPer Google policy
Apple Inc.USAOn app install/launch and Apple sign-in, networkDevice info, crash logs, Apple sign-in authentication dataApp distribution / diagnostics / sign-inPer Apple policy
Anthropic, PBCUSAOn AI analysis use, HTTPSUploaded image (Base64), analysis promptImage AI analysisUp to 30 days

You may refuse international transfers under § 7 below; some features (such as social sign-in and AI analysis) may then be limited.

6. Social Sign-In

  1. Dripbook has no password-based accounts. Sign-in is available only through the social providers below, and we never collect or store passwords.
  2. What we receive from each provider:
    ProviderData we receiveNotes
    Google (Google LLC)Email address, profile name, account IDEmail is used as your account key
    Apple (Apple Inc.)Email address (or a private relay address if you choose "Hide My Email"), name, account IDHide My Email is supported
    Kakao (Kakao Corp.)A unique member identifier onlyWe collect no email or profile data from Kakao; an internal account key is derived from the identifier
  3. On successful sign-in, our server issues a self-signed session token (valid for 90 days) used to authenticate member features (check-in, beans, missions).
  4. You can disconnect Dripbook from your social account at any time in the provider's settings: Google [Account → Security → Third-party access], Apple [Settings → Apple Account → Sign-In & Security → Sign in with Apple], Kakao [KakaoTalk → Settings → Kakao Account → Connected services].

7. Your Rights

You may exercise the following rights at any time:

  1. Access your personal information
  2. Request correction or deletion
  3. Request restriction of processing
  4. Withdraw consent
  5. Account deletion (see § 16)
  6. Under GDPR (EEA users): Right to data portability, right to lodge a complaint with your supervisory authority
  7. Under CCPA (California users): Right to know what we collect, right to delete, right to opt-out of sale (we do not sell personal information)

How to exercise:

8. Data Destruction

When personal data is no longer needed, we destroy it without delay.

9. Security Measures

10. Automatic Collection Tools and Opt-Out

  1. Dripbook uses device localStorage to provide the service. No advertising identifiers are used.
  2. localStorage usage: login session and session token, nickname, favorites, scanned-bean library, Kongi growth data, language setting — stored on your device.
  3. Deleting the app removes all locally stored data on the device.

11. Children's Privacy

  1. Dripbook's App Store age rating is 12+. However, in compliance with the Korean Personal Information Protection Act (Article 22-2), we do not collect personal information from children under 14 in Korea without verifiable consent from a legal guardian.
  2. During sign-in, the user confirms they are 14 or older. If we discover that an account was created by someone under 14 without legal-guardian consent, we delete the account and all related data immediately.
  3. Parents or legal guardians who suspect their child under 14 is using this app may notify us at bublica@naver.com; we will erase the relevant data without delay.

12. Data Protection Officer (DPO)

13. Complaints & Remedies (Korea)

AuthorityPhoneWebsite
Personal Info Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Info Infringement Center (KISA)118privacy.kisa.or.kr
Cybercrime Investigation Unit1301www.spo.go.kr
National Police Cyber Bureau182cyberbureau.police.go.kr

14. AI Image Analysis

Dripbook uses Anthropic Claude Sonnet (claude-sonnet-4-6 or successors) for automatic bean bag image recognition.

14-1. Purpose

14-2. Model & Processor

ModelAnthropic Claude Sonnet (claude-sonnet-4-6)
ProcessorAnthropic, PBC
Processing LocationUnited States
TransportHTTPS / TLS encryption

14-3. Data Flow

  1. You take or upload a coffee bean bag photo in-app.
  2. Our backend (Dripbook server, Railway hosting) Base64-encodes the image and sends it to the Anthropic API (https://api.anthropic.com/v1/messages).
  3. Anthropic's API returns analysis results in JSON.
  4. Our server forwards only the JSON results to the app; the original image is never persisted on our servers (passes through memory and is immediately discarded).
  5. For monitoring and abuse prevention, only the call metadata (email, timestamp, recognition summary: roastery, bean name, origin, roast level) is recorded in our server logs and retained for up to 30 days (see § 1-1).

14-4. Anthropic Data Policy

14-5. Usage Limits

To protect against abuse and runaway costs, each AI scan debits 10 beans (in-app points). Beans are earned through daily check-ins and weekly missions. The Manual Entry flow is unlimited and unaffected.

14-6. Your Rights and Cautions

15. Changes to This Policy

  1. This Privacy Policy applies from the effective date. We will notify users of any changes at least 7 days before they take effect via in-app notice or this page.
  2. For material changes affecting user rights, notice will be given at least 30 days in advance.

16. Account Deletion

  1. You may delete your account and associated data at any time.
  2. In-app deletion (recommended): Tap [Profile → Account → Delete account] in the app. The following data is deleted immediately and automatically:
    • Device localStorage: account info (email, nickname), favorites, bean library, review & auto-tune data, app preferences
    • Server-side check-in / bean / mission data and sessions
  3. Server operation logs (email, call timestamps, recognition metadata) are automatically discarded according to our retention policy — up to 30 days from collection (see § 2). No separate manual deletion request is required.
  4. Email request (fallback): If you cannot use the app, you may email bublica@naver.com; we will process the request within 7 days.
  5. Data legally required to be preserved (e.g. inquiry records for 3 years under the e-Commerce Act) will be held in isolated storage for the prescribed period and then destroyed.

17. Governing Law and Disputes

  1. This Privacy Policy is governed by the laws of the Republic of Korea.
  2. Any disputes shall be brought in the competent courts of Korea under the Civil Procedure Act.

Appendix

Publication2026-07-21
Effective2026-07-21
Current Versionv1.1
OperatorBublica
RepresentativeHyunmin Park
Business Reg. No.656-79-00658
Mail-Order Reg. No.N/A
Address48-8 Hotan-gil, Geumnam-myeon, Sejong, Republic of Korea (2nd floor)
Emailbublica@naver.com
App NameDripbook
Bundle IDcom.bublica.dripbook
Policy URLhttps://dripbook.bublica.com/privacy/en

Revision History

VersionDateChanges
v1.02026-05-11Initial publication
v1.12026-07-21Removed all advertising (Google AdMob) and ad-identifier (IDFA/ATT) provisions — the app serves no ads; added social sign-in (Google · Apple · Kakao, § 6); reflected session-token authentication, the bean (point) system, server-side check-in data, and the updated in-app account-deletion path