BurnTok Privacy Policy
- Service: BurnTok (the "Service")
- Operator: Hwang Jimin
- Contact:
jimin1286@gmail.com - Effective date: 2026-09-10
Review record. Reviewed by the operator on 2026-09-10. The review covered (1) every factual
statement here against the actual implementation and infrastructure and (2) the disclosure items
required by the Korean Personal Information Protection Act (PIPA) Article 30, the cross-border
transfer notice under Article 28-8, and the policy-URL requirements of the App Store and Google
Play. This is not a lawyer's review — if outside counsel reviews the text, the result will be
published under a new effective date. The canonical source for the collected items, purposes,
processors, retention and deletion wording is
config/apps/burntok/policy.jsonin
control-plane/app-release-hub; this document is the human-readable form of the same content.
1. At a glance
- BurnTok is a community where a sentence becomes a small app that others can run and remix.
- Browsing and running a shared mini app does not require an account. Member features (creating,
reacting, commenting, messaging) require linking a social account.
- You can delete your account inside the app, even before accepting the community rules.
- Members under 14 years of age may not sign up.
- **The production server is located in Canada, and AI generation requests are sent to a processor
in China** (see section 5).
2. Information we collect
- An anonymous identifier generated on the device, and the account identifier and email address of
a Google, Kakao, Naver or Apple account you optionally link
- Nickname, profile image or avatar, and other profile information you enter or generate
- Content you create, AI generation/edit/conversation prompts, generated app specifications and
bundles, mini app data, comments, reactions, follows, messages and reports
- Push notification tokens and notification preferences
- Server and error logs: IP address, request URL and time, user identifier, client error messages
and stack traces
- Sign-in session, language and theme settings stored on the device
We do not collect advertising identifiers or location data, and the app contains no advertising, analytics or crash-reporting SDK. We do not collect national identification numbers or payment card and bank account details. Information received from social sign-in is limited to the minimum items each provider passes on with your consent (identifier, email address).
3. Purposes
- Account identification and sign-in, profile and social features
- AI-based content generation, editing and conversation; storing and sharing content; messaging
between members
- Sending the notifications you chose and managing notification settings
- Preventing abuse, analyzing errors, security and service quality
4. Processors and third parties
We entrust processing of personal information to the following providers to the extent needed to run the Service. Each provider's handling of personal information follows its own policy.
| Processor | Entrusted work | Items entrusted | Policy |
|---|---|---|---|
| OVH SAS | Production server and database hosting | All server-stored information in section 2 | https://www.ovhcloud.com/en/personal-data-protection/ |
| DeepSeek | AI content generation, editing and conversation | Prompts you enter and the generation context | https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html |
| Expo (Expo Application Services) | App update delivery and push notification delivery | Push notification tokens, notification content | https://expo.dev/privacy |
| Apple, Google | App distribution and device push delivery | Push notification tokens, notification content | Each platform's policy |
Social sign-in is not entrusted processing; it is information received from the provider with your consent. The items received are an identifier and an email address, and you choose which provider to use.
| Provider | Items received | Policy |
|---|---|---|
| User identifier, email address | https://policies.google.com/privacy | |
| Kakao | User identifier, email address | https://www.kakao.com/policy/privacy |
| Naver | User identifier, email address | https://policy.naver.com/policy/privacy.html |
| Apple | User identifier, email address | https://www.apple.com/legal/privacy/ |
We do not sell personal information or provide it to third parties for advertising. We may disclose information to the extent the law allows in order to comply with legal obligations, to prevent an imminent danger to life, body or property, or to investigate abuse.
5. Cross-border transfers
As required by PIPA Article 28-8, the transfers (including storage) of personal information outside Korea are disclosed below.
| Recipient | Country | Items | Purpose | When and how | Retention |
|---|---|---|---|---|---|
| OVH SAS | Canada | All server-stored information in section 2 | Server and database hosting | Sent over HTTPS and stored when you use the Service | Same as section 7 |
| DeepSeek | China | Prompts you enter and the generation context | AI mini app generation and editing | Sent by API when a generation is requested | Per the processor's policy |
| Expo | United States | Push notification tokens, notification content | App update and push delivery | Sent by API when a notification is delivered | Per the processor's policy |
| Apple, Google | United States | Push notification tokens, notification content | Device push delivery | Sent when a notification is delivered | Per each platform's policy |
You may refuse these transfers. Because refusing the hosting transfer makes the Service unusable, the way to refuse it is not to create an account, or to delete your account. The AI transfer does not happen if you do not use the generation feature, and the push transfer does not happen if you turn notifications off. Please do not put personal or confidential information into prompts.
6. Cookies and device storage
On the web we use an HttpOnly, SameSite=Lax session cookie (Secure in production, 400-day lifetime) to keep you signed in, and browser local and session storage for language and theme settings and for the account-deletion confirmation notice. In the app we use the device's secure storage (Keychain, Keystore) and app settings storage for the same purposes. We use no advertising or tracking cookies. Blocking cookies or clearing storage signs you out; deleting the app removes the values stored on the device.
7. Retention and destruction
- Account information and content stored on the server are retained while the account exists.
- When you request deletion, related data is deleted except information we must retain by law.
- Server and access logs rotate under the container log settings (10 MB per file, 3 files maximum);
older records are dropped automatically once the limit is passed. We keep no separate long-term access-log store.
- Settings inside the device are removed when you delete the app or reset it.
Procedure and method: personal information whose retention period has passed or whose purpose has been achieved is destroyed without delay. Electronic files are deleted so that they cannot be recovered, and copies remaining in backups disappear as the backup rotation passes. Information we must retain by law is stored separately from other information for that period and then destroyed.
8. Account and data deletion
You can delete your account yourself from the deletion screen in the app or on the web. The deletion screen is reachable even before you accept the community rules.
Deletion removes your user row in the production database together with the related data linked for deletion (mini apps, comments, messages, follows, consent records). This action alone does not guarantee deletion of server logs, backups, or copies held by the AI, OAuth or push providers; the retention and deletion scope of that information follows each provider's policy and operational procedures.
When you delete your account we also ask the linked provider to revoke the grant. Deletion proceeds even if revocation fails; in that case you can disconnect the link yourself in the provider's account settings. The linked Google, Kakao, Naver or Apple account itself is not deleted. If you have trouble deleting an account or specific content, write to the contact address above.
9. Your rights and how to exercise them
You may request access, correction, deletion or suspension of processing of your personal information, and you may withdraw consent. In the app and on the web, editing your profile, deleting content and deleting your account produce the same result immediately; other requests are accepted at the contact address above. Once received, we confirm the minimum information needed to verify you and report the result within 10 days. A legal representative or an authorized agent may also make a request; in that case we ask for material confirming the authorization. Notifications can be turned off at any time in the device settings and the app settings.
10. Children's information
Members under 14 years of age may not sign up. At sign-up, accepting the community rules includes a statement that you are 14 or older; if we find an account belongs to someone under 14, we delete the account and its data.
11. Security measures
Traffic is encrypted with HTTPS. There is a single public edge, and no other service port is exposed. Server access is limited to key-based authentication, and the deploy account is separate from the runtime account. The database and cache are not publicly reachable. Production secrets are injected only through restricted-permission files on the server and are never stored in the repository. We do not store passwords (social sign-in only).
12. Privacy officer
- Privacy officer: Hwang Jimin (the operator)
- Contact:
jimin1286@gmail.com
Questions, grievances and remedies concerning the handling of personal information are accepted at the address above. As a one-person service, the privacy officer and the access-request desk are the same.
13. Remedies for infringement
For counseling or dispute mediation about personal information infringement, you may contact:
- Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
- Korea Internet & Security Agency privacy report center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office cybercrime division: 1301 (www.spo.go.kr)
- National Police Agency cybercrime report system: 182 (ecrm.police.go.kr)
14. Changes
When this policy changes we announce it through an in-service notice or by updating this document. Changes that are materially unfavorable to users are announced 30 days before they take effect.