Dripbook Privacy Policy
Bublica ("the Company") respects the privacy of its users and is committed to protecting personal information in accordance with applicable laws, including the Korean Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile application Dripbook (Bundle ID: com.bublica.dripbook).
1. Information We Collect
1-1. Automatically Collected (on app install and use)
| Category | Data | Notes |
|---|---|---|
| Identifier | Vendor Identifier (IDFV) | iOS standard, reset on app deletion |
| Device Info | iOS version, device model, screen resolution, language/region | |
| Usage Logs | App launch/exit time, navigation events | |
| Service Data (server) | Check-in history, bean (in-app point) balance and transactions, weekly mission progress | Stored per account on our backend while you are signed in |
| Diagnostics | Crash logs, performance metrics | |
| Network | IP address, access timestamp | For abuse prevention |
| Server operation logs | Logged-in user email, AI scan call timestamp, response result (success/failure), recognition metadata (roastery, bean name, origin, roast level) | Collected on our backend for monitoring, usage limits, and abuse prevention |
1-2. User-Provided Information
| Category | Data | Collection Trigger |
|---|---|---|
| Account info | Email address and profile name received from your social login provider (or an internal identifier for Kakao) | On social sign-in (see § 6 — we never collect passwords) |
| Nickname | The nickname you choose in-app | On first sign-in (stored in device localStorage only) |
| Recipe data | User-entered coffee recipes, notes, ratings, favorites list | Stored locally in-app (device localStorage, not sent to server) |
| App preferences | Language setting, "remember me" flag | Stored locally in-app (device localStorage) |
| Inquiry | Email address, message body | When you contact support |
| Bean bag image | Photos of coffee bean packaging you upload | When using AI analysis (see § 15) |
1-3. Device Permissions (used only with your explicit consent)
Dripbook uses the following iOS permissions, all of which trigger a system permission dialog on first use.
| Permission | Purpose | How We Handle It |
|---|---|---|
Camera (NSCameraUsageDescription) | Take a photo of your coffee bag for AI recognition | The captured image stays in memory and is sent off-device only when you trigger AI analysis (see § 15) |
Photo Library — Read (NSPhotoLibraryUsageDescription) | Select an existing bean-bag photo from your gallery | Only the photo you actively select is processed |
Photo Library — Add (NSPhotoLibraryAddUsageDescription) | Save a recipe card image to your gallery (optional feature) | Triggered only by your explicit save action |
Denying any permission still allows full use of the manual entry flow and other core features. You can change permissions anytime in iOS Settings → Dripbook.
1-4. Advertising SDK
Dripbook serves no ads and includes no advertising SDK (Google AdMob was removed in v1.1). We do not collect advertising identifiers (IDFA/ADID).
2. How Long We Keep Your Data
| Item | Retention | Basis |
|---|---|---|
| Account info (social login email or internal identifier) | Until account deletion | User consent |
| Check-in / bean / mission data | Until account deletion | Service provision |
| Session tokens | 90 days from issuance (re-login required after expiry) | Authentication |
| Auto-collected (device info, usage) | 12 months from collection, or until deletion request | User consent |
| Recipe data, favorites, app preferences (local) | Until app is deleted (device localStorage, not sent to server) | — |
| Server operation logs (email, call time, recognition meta) | Up to 30 days (Railway log retention policy) | Operations / abuse prevention |
| Monthly AI scan usage counter | Auto-resets on the 1st of every month (UTC); held in server memory | Usage management |
| Inquiry email records | 3 years after resolution | e-Commerce Act § 6 (KR) |
| Crash / diagnostic logs | 90 days | Operations |
| Uploaded images for AI analysis | Not stored on our server (passes through memory and is discarded immediately). Anthropic side: up to 30 days | Anthropic data policy |
3. Sharing With Third Parties
We share your information only to the extent necessary for the purposes described in §§ 4 and 5, and only with your consent or as required by law.
| Recipient | Purpose | Data Shared | Retention |
|---|---|---|---|
| Google LLC | Google social sign-in authentication | Authentication request (in return we receive your email, profile name, and account ID) | Per Google policy |
| Apple Inc. | App distribution, in-app diagnostics, Sign in with Apple | Device info, crash logs, Apple sign-in authentication data | Per Apple policy |
| Kakao Corp. | Kakao social sign-in authentication | Authentication request (in return we receive only a unique member identifier — no email or profile data) | Per Kakao policy |
| Anthropic, PBC | AI image analysis of coffee bean bags (Claude Sonnet model) | Image uploaded by user (Base64), analysis prompt | Up to 30 days (Anthropic policy) |
We do not sell your personal information.
4. Processing on Our Behalf (Sub-processors)
| Processor | Service | Country |
|---|---|---|
| Railway Corp. | Backend hosting, server operation logs (infrastructure) | United States |
| Apple Inc. | App distribution, in-app diagnostics (App Store Connect, TestFlight) | United States |
| Anthropic, PBC | AI-based bean bag image analysis (Claude Sonnet) | United States |
5. International Data Transfers
Because Dripbook uses the Apple App Store and Google Play, social sign-in (Google and Apple), Anthropic AI, and Railway hosting, certain data is transferred outside Korea. (Kakao sign-in is processed in Korea.)
| Recipient | Country | When & How | Data | Purpose | Retention |
|---|---|---|---|---|---|
| Railway Corp. | USA | On API call, HTTPS | Email, IP, call timestamp, recognition meta | Backend hosting / logs | Up to 30 days |
| Google LLC | USA | On Google sign-in, HTTPS | Authentication data (email, profile name, account ID) | Social sign-in | Per Google policy |
| Apple Inc. | USA | On app install/launch and Apple sign-in, network | Device info, crash logs, Apple sign-in authentication data | App distribution / diagnostics / sign-in | Per Apple policy |
| Anthropic, PBC | USA | On AI analysis use, HTTPS | Uploaded image (Base64), analysis prompt | Image AI analysis | Up to 30 days |
You may refuse international transfers under § 7 below; some features (such as social sign-in and AI analysis) may then be limited.
6. Social Sign-In
- Dripbook has no password-based accounts. Sign-in is available only through the social providers below, and we never collect or store passwords.
- What we receive from each provider:
Provider Data we receive Notes Google (Google LLC) Email address, profile name, account ID Email is used as your account key Apple (Apple Inc.) Email address (or a private relay address if you choose "Hide My Email"), name, account ID Hide My Email is supported Kakao (Kakao Corp.) A unique member identifier only We collect no email or profile data from Kakao; an internal account key is derived from the identifier - On successful sign-in, our server issues a self-signed session token (valid for 90 days) used to authenticate member features (check-in, beans, missions).
- You can disconnect Dripbook from your social account at any time in the provider's settings: Google [Account → Security → Third-party access], Apple [Settings → Apple Account → Sign-In & Security → Sign in with Apple], Kakao [KakaoTalk → Settings → Kakao Account → Connected services].
7. Your Rights
You may exercise the following rights at any time:
- Access your personal information
- Request correction or deletion
- Request restriction of processing
- Withdraw consent
- Account deletion (see § 16)
- Under GDPR (EEA users): Right to data portability, right to lodge a complaint with your supervisory authority
- Under CCPA (California users): Right to know what we collect, right to delete, right to opt-out of sale (we do not sell personal information)
How to exercise:
- 📧 Email: bublica@naver.com
- 📮 Postal: 48-8 Hotan-gil, Geumnam-myeon, Sejong, Republic of Korea (2nd floor)
8. Data Destruction
When personal data is no longer needed, we destroy it without delay.
- Electronic files: securely deleted (logical + physical destruction)
- Paper documents: shredded or incinerated
9. Security Measures
- Password-free social sign-in — we never hold passwords, so a server-side compromise cannot expose them
- All traffic encrypted with HTTPS / TLS 1.2+ (including our custom domain
dripbook.bublica.com) - Member APIs are authenticated with HMAC-signed session tokens (Authorization header) — tampered requests are rejected automatically
- AI scan calls debit beans (in-app points) server-side, blocking abnormal call patterns
- Least-privilege access controls
- Intrusion detection and prevention
- Regular security patching and vulnerability checks
- Designated Data Protection Officer (see § 12)
10. Automatic Collection Tools and Opt-Out
- Dripbook uses device
localStorageto provide the service. No advertising identifiers are used. - localStorage usage: login session and session token, nickname, favorites, scanned-bean library, Kongi growth data, language setting — stored on your device.
- Deleting the app removes all locally stored data on the device.
11. Children's Privacy
- Dripbook's App Store age rating is 12+. However, in compliance with the Korean Personal Information Protection Act (Article 22-2), we do not collect personal information from children under 14 in Korea without verifiable consent from a legal guardian.
- During sign-in, the user confirms they are 14 or older. If we discover that an account was created by someone under 14 without legal-guardian consent, we delete the account and all related data immediately.
- Parents or legal guardians who suspect their child under 14 is using this app may notify us at bublica@naver.com; we will erase the relevant data without delay.
12. Data Protection Officer (DPO)
- Name: Hyunmin Park
- Role: Representative
- Email: bublica@naver.com
- Phone: +82 10-6404-8155
13. Complaints & Remedies (Korea)
| Authority | Phone | Website |
|---|---|---|
| Personal Info Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Info Infringement Center (KISA) | 118 | privacy.kisa.or.kr |
| Cybercrime Investigation Unit | 1301 | www.spo.go.kr |
| National Police Cyber Bureau | 182 | cyberbureau.police.go.kr |
14. AI Image Analysis
Dripbook uses Anthropic Claude Sonnet (claude-sonnet-4-6 or successors) for automatic bean bag image recognition.
14-1. Purpose
- To extract roastery, bean name, origin, process method, roast level, and flavor notes from a user-uploaded coffee bean bag image.
14-2. Model & Processor
| Model | Anthropic Claude Sonnet (claude-sonnet-4-6) |
|---|---|
| Processor | Anthropic, PBC |
| Processing Location | United States |
| Transport | HTTPS / TLS encryption |
14-3. Data Flow
- You take or upload a coffee bean bag photo in-app.
- Our backend (Dripbook server, Railway hosting) Base64-encodes the image and sends it to the Anthropic API (
https://api.anthropic.com/v1/messages). - Anthropic's API returns analysis results in JSON.
- Our server forwards only the JSON results to the app; the original image is never persisted on our servers (passes through memory and is immediately discarded).
- For monitoring and abuse prevention, only the call metadata (email, timestamp, recognition summary: roastery, bean name, origin, roast level) is recorded in our server logs and retained for up to 30 days (see § 1-1).
14-4. Anthropic Data Policy
- Anthropic does not use API data for model training (default policy).
- Anthropic retains received data for up to 30 days for operational and safety review, then deletes it.
- More: Anthropic Privacy Policy
14-5. Usage Limits
To protect against abuse and runaway costs, each AI scan debits 10 beans (in-app points). Beans are earned through daily check-ins and weekly missions. The Manual Entry flow is unlimited and unaffected.
14-6. Your Rights and Cautions
- You may decline to use the AI analysis feature; doing so only restricts that specific feature and does not affect other Dripbook functionality.
- Please do not include identifying information (ID cards, business cards, faces, etc.) in your uploaded images. We are not liable for personal information exposure caused by your own carelessness.
15. Changes to This Policy
- This Privacy Policy applies from the effective date. We will notify users of any changes at least 7 days before they take effect via in-app notice or this page.
- For material changes affecting user rights, notice will be given at least 30 days in advance.
16. Account Deletion
- You may delete your account and associated data at any time.
- In-app deletion (recommended): Tap [Profile → Account → Delete account] in the app. The following data is deleted immediately and automatically:
- Device localStorage: account info (email, nickname), favorites, bean library, review & auto-tune data, app preferences
- Server-side check-in / bean / mission data and sessions
- Server operation logs (email, call timestamps, recognition metadata) are automatically discarded according to our retention policy — up to 30 days from collection (see § 2). No separate manual deletion request is required.
- Email request (fallback): If you cannot use the app, you may email bublica@naver.com; we will process the request within 7 days.
- Data legally required to be preserved (e.g. inquiry records for 3 years under the e-Commerce Act) will be held in isolated storage for the prescribed period and then destroyed.
17. Governing Law and Disputes
- This Privacy Policy is governed by the laws of the Republic of Korea.
- Any disputes shall be brought in the competent courts of Korea under the Civil Procedure Act.
Appendix
| Publication | 2026-07-21 |
|---|---|
| Effective | 2026-07-21 |
| Current Version | v1.1 |
| Operator | Bublica |
| Representative | Hyunmin Park |
| Business Reg. No. | 656-79-00658 |
| Mail-Order Reg. No. | N/A |
| Address | 48-8 Hotan-gil, Geumnam-myeon, Sejong, Republic of Korea (2nd floor) |
| bublica@naver.com | |
| App Name | Dripbook |
| Bundle ID | com.bublica.dripbook |
| Policy URL | https://dripbook.bublica.com/privacy/en |
Revision History
| Version | Date | Changes |
|---|---|---|
| v1.0 | 2026-05-11 | Initial publication |
| v1.1 | 2026-07-21 | Removed all advertising (Google AdMob) and ad-identifier (IDFA/ATT) provisions — the app serves no ads; added social sign-in (Google · Apple · Kakao, § 6); reflected session-token authentication, the bean (point) system, server-side check-in data, and the updated in-app account-deletion path |