top of page
eightstudio.png

EIGHT STUDIO Privacy Policy

​

EIGHT STUDIO Inc. (the “Company”) complies with the Personal Information Protection Act and other applicable laws and regulations. The Company establishes and discloses this Privacy Policy to protect users’ personal information and to promptly and effectively address any concerns relating to personal information. This Privacy Policy applies to all game services provided by the Company.

​

Article 1. Purposes of Processing Personal Information

The Company processes personal information to the extent necessary for the following purposes. Personal information processed by the Company will not be used for purposes other than those specified below. If the purposes of use change, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

1. User identification and account management

2. Provision of game services and content

3. Purchases and payments, customer inquiries, and user support

4. Prevention of fraudulent or unauthorized use and maintenance of service stability

5. Analysis of service usage and improvement of service quality

6. Provision of advertisements, measurement of advertising performance, and analysis of marketing effectiveness
 

Article 2. Categories of Personal Information Processed

The Company processes only the minimum amount of personal information necessary for the purposes specified in Article 1.
① In the course of account creation and use of the services, the Company may process the following personal information:

1. Account identifiers from third-party platforms and profile information that the user has consented to provide
2. Game account and character information
3. Service usage records, access logs, and dates and times of access
4. IP address, device model, operating system, and app version
5. Advertising identifiers (ADID/GAID, IDFA)
6. App or installation identifiers
7. In-game activity and event information
8. Purchase and payment records (transaction information available through app marketplaces, such as order number, product name, and date and time of payment; the Company does not directly collect payment method information such as credit card numbers)

9. Error and diagnostic information

10. Ad impression, click, and conversion information

11. Approximate location information at the country or regional level derived from the IP address
12. Account identifiers assigned when using a guest account

② In connection with customer inquiries and the exercise of rights relating to personal information, the Company may process the following personal information:

1. Email address

2. Game account and character information

3. Details of inquiries and customer support records

4. Information necessary to verify the identity of the individual or the authority of a legitimate representative

5. Materials directly submitted by the user in connection with an inquiry or the exercise of rights
 

Article 3. Processing of Personal Information of Children Under 14 Years of Age

① When the Company processes the personal information of a child under 14 years of age, it obtains the consent of the child’s legal representative in accordance with Article 22-2 of the Personal Information Protection Act.
② A legal representative may exercise rights regarding the child’s personal information, including the rights to access, correction or deletion, and suspension of processing, as permitted under applicable laws and regulations. Such rights may be exercised in accordance with Article 11.

 

Article 4. Processing and Retention Period of Personal Information

① The Company retains personal information for the period necessary to fulfill the purposes of processing and destroys it without delay once the purposes of processing have been fulfilled or the applicable retention period has expired.

② The retention periods for personal information processed in connection with the use of the services are as follows:

1. Account and service usage information: Until the user withdraws their membership, deletes their account, or the service is terminated. However, if the user requests termination of the service agreement, a grace period may apply in accordance with the Company’s Terms of Service.
2. If a user does not use the services for one consecutive year, the Company may terminate the service agreement in accordance with its Terms of Service and destroy the relevant personal information or store it separately from other personal information. In such cases, the Company provides notice of the relevant measures at least 30 days before the date of such measures.

3. Records of fraudulent or unauthorized use: One year for the purpose of preventing fraudulent or unauthorized use.

③ Where retention is required by applicable laws and regulations, the Company retains the relevant information for the periods prescribed by such laws and regulations, as follows:

1. Records concerning contracts or withdrawal of offers, etc.: Five years (Act on the Consumer Protection in Electronic Commerce, Etc.)
2. Records concerning payment and supply of goods, etc.: Five years (Act on the Consumer Protection in Electronic Commerce, Etc.)

3. Records concerning consumer complaints or dispute resolution: Three years (Act on the Consumer Protection in Electronic Commerce, Etc.)

4. Records concerning labeling and advertising: Six months (Act on the Consumer Protection in Electronic Commerce, Etc.)
5. Computer communications and internet log records and access location tracking data: Three months (where a retention obligation under the Protection of

Communications Secrets Act applies)

④ Identity verification materials submitted to verify the identity of an individual or the authority of a legitimate representative, such as copies of identification documents, are destroyed without delay once identity verification is complete. However, records concerning the details of a request to exercise rights, whether identity verification was conducted, and the results of processing the request may be retained for the period necessary for dispute resolution or as required by applicable laws and regulations.
⑤ Personal information processed based on separate consent is retained for the period specified in the consent.

 

Article 5. Provision of Personal Information to Third Parties

① The Company uses users’ personal information within the scope of the purposes of processing specified in Article 1. When providing personal information to a third party, the Company obtains the user’s consent or relies on a legal basis permitted under applicable laws and regulations, including Articles 17 and 18 of the Personal Information Protection Act.
② When personal information is provided to a third party, the Company informs users of the matters required by applicable laws and regulations and follows the necessary procedures.

 

Article 6. Entrustment of Personal Information Processing

① The Company entrusts the processing of personal information as follows for the smooth provision and operation of its services.

1. Hidden Monster Co., Ltd.

  • Entrusted tasks: Game service operation support, community management, assistance with store operations, handling of user inquiries and reviews, operation of advertising media, and execution of advertising campaigns

  • Retention and use period: Until the purpose of entrustment is fulfilled or the entrustment contract is terminated

2. Amazon Web Services, Inc. and its affiliates

  • Entrusted tasks: Data storage and server operation for the provision of game services

  • Retention and use period: For the retention period specified in Article 4

  • Matters concerning cross-border transfers are set forth in Article 9.

3. Google LLC and its affiliates (Google Analytics 4 / Firebase)

  • Entrusted tasks: Analysis of service usage and user behavior, compilation of statistics, improvement of service quality, and support for technical functions necessary for the provision and operation of services

  • Retention and use period: For the period determined by the Company’s settings and the applicable service policies

  • Matters concerning cross-border transfers are set forth in Article 9.

4. AppsFlyer Ltd.

  • Entrusted tasks: Analysis of advertising acquisition channels and install attribution, measurement of advertising campaign performance, and detection of fraudulent traffic

  • Retention and use period: For the period determined by the Company’s settings, contractual terms, and the applicable service policies

  • Matters concerning cross-border transfers are set forth in Article 9.

② When the Company entrusts the processing of personal information, it includes in contracts or other documents, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than the entrusted purposes, measures to ensure security, restrictions on sub-entrustment, management and supervision of entrusted processors, and compensation for damages. The Company also supervises entrusted processors to ensure that they process personal information securely.
③ If there are any changes to an entrusted processor or the details of the entrusted tasks, the Company discloses such changes through this Privacy Policy.

 

Article 7. Installation and Operation of Automatic Personal Information Collection Tools and Options for Refusal

① The Company installs and operates third-party SDKs and analytics and advertising tools in its apps for the purposes of analyzing service usage, providing advertisements, measuring advertising performance, and integrating community features. These tools automatically collect information from users’ devices and transmit it when the apps are launched and used.
② The major third-party tools used by the Company are as follows:

1. Google Analytics 4 / Firebase

  • Information that may be processed: App instance identifiers, advertising identifiers, IP address, device and app information, service usage and event information, and diagnostic information

  • Purpose: Analysis of service usage, compilation of statistics, improvement of service quality, and support for technical functions necessary for the provision and operation of services

  • Processing method: Automatic collection and transmission through SDKs when the app is launched and used

  • Matters concerning the entrustment of personal information processing and cross-border transfers are set forth in Articles 6 and 9.

2. AppsFlyer

  • Information that may be processed: Advertising identifiers, AppsFlyer ID, IP address, device information, installation and launch information, and in-app event information

  • Purpose: Analysis of advertising acquisition channels and install attribution, measurement of advertising campaign performance, and detection of fraudulent traffic

  • Processing method: Automatic collection and transmission through SDKs when the app is launched and used

  • Matters concerning the entrustment of personal information processing and cross-border transfers are set forth in Articles 6 and 9.

3. Google AdMob / Google Ads

  • Information that may be processed: Advertising identifiers, IP address, device and app information, ad impression, click, and conversion information, app usage and interaction information, and diagnostic information

  • Purpose: Provision of advertisements, measurement of advertising performance, analysis of marketing effectiveness, and prevention of fraudulent or unauthorized use

  • Processing method: Automatic collection and transmission of relevant information to Google through SDKs when the app is launched and used

  • Matters concerning the processing of behavioral information are set forth in Article 8.

4. Meta Ads (Meta Platforms, Inc.)

  • Information that may be processed: Advertising and device identifiers, IP address, app usage information, ad response and event information, and purchase-related event information

  • Purpose: Measurement of advertising performance, advertising optimization, and analysis of marketing effectiveness

  • Processing method: Automatic collection and transmission of relevant information to Meta through SDKs when the app is launched and used

  • Matters concerning the processing of behavioral information are set forth in Article 8.

5. NAVER Game SDK (NAVER Corporation)

  • Information that may be processed: NAVER account and authentication-related information, Lounge usage information, and information registered by users with NAVER Game services

  • Purpose: Provision of and integration with NAVER Game Official Lounge and community features

  • Processing method: Processing through SDKs provided by NAVER and NAVER services when users use the relevant features·

③ The information actually processed may vary depending on the features used by the user, the operating system, the SDK version, and the settings applied by the Company.
④ Users may restrict the use of or reset their advertising identifiers by changing the settings on their mobile devices.

[How to Restrict Advertising Identifiers]

  • Android: Settings → Security and privacy → Privacy → Other privacy settings → Ads → Reset advertising ID or Delete advertising ID

  • iPhone: Settings → Privacy & Security → Tracking → Turn off “Allow Apps to Request to Track”

※ Menus and procedures may vary depending on the version of the mobile operating system.

⑤ The settings described in paragraph ④ restrict the use of advertising identifiers and personalized advertising, but do not mean that all processing of personal information through the tools specified in paragraph ② or all processing outside Korea is discontinued.
⑥ The NAVER Game SDK specified in paragraph ②, item 5, is used for integration with the NAVER Game Official Lounge and community features provided by NAVER. NAVER may directly process personal information when users use such features. Details of such processing are governed by NAVER’s Privacy Policy and applicable service policies.

 

Article 8. Collection and Use of Behavioral Information and Options for Refusal

① The Company allows behavioral information to be processed through the advertising-related SDKs specified in Article 7, paragraph ②, items 3 and 4, for the purposes of providing personalized advertisements and measuring advertising performance. The Company does not identify users in this process, and the information is processed in a non-identifying manner using advertising identifiers and similar information.
② Details concerning the processing of behavioral information are as follows:

  • Processing method: Processed without identifying users

  • Information collected: Advertising identifiers, IP address, device and app information, app usage and interaction information, ad impression, click, and conversion information, and in-app event information

  • Collection method: Automatic collection and transmission through SDKs when the app is launched and used

  • Purpose of collection: Provision of personalized advertisements, measurement of advertising performance, and analysis of marketing effectiveness

  • Entities processing the information: Google LLC and its affiliates; Meta Platforms, Inc. and its affiliates

  • etention and use period: For the periods specified in each entity’s Privacy Policy and data processing policies

③ The information specified in paragraph ② is automatically transmitted to Google or Meta through the applicable SDK and processed in accordance with each entity’s Privacy Policy and applicable data processing policies, and may be processed at facilities outside Korea.
④ The Company ensures that only the minimum behavioral information necessary for personalized advertising is processed and does not collect sensitive behavioral information that may infringe upon individuals’ rights, interests, or privacy, such as information concerning ideology, beliefs, or medical history.
⑤ Users may block personalized advertisements by restricting the use of or resetting their advertising identifiers using the methods described in Article 7, paragraph ④.
⑥ Users may submit inquiries regarding behavioral information, exercise their right to refuse, or report related harm through the customer support center available within each game or to the Privacy Officer (master@eightstudio.co.kr).

 

Article 9. Cross-Border Transfer of Personal Information

① The Company entrusts certain personal information processing activities to service providers outside Korea and stores personal information with such service providers for the purposes of providing and operating game services, analyzing service usage, improving service quality, and analyzing advertising acquisition and performance.
② The cross-border transfers specified in paragraph ① are based on Article 28-8, paragraph (1), item 3(a) of the Personal Information Protection Act (entrustment and storage for the conclusion and performance of a contract). Accordingly, the Company discloses the matters specified in each item of paragraph (2) of the same Article as follows.
③ Details of cross-border transfers through cloud infrastructure for the operation of game services are as follows:

1. Recipient: Amazon Web Services, Inc. and its affiliates
2. Contact: AWS Korea Privacy (aws-korea-privacy@amazon.com)

3. Countries of transfer: Republic of Korea, Japan, Taiwan, and the United States
※ The countries of transfer may vary depending on the service region from which the user accesses the services and the Company’s infrastructure configuration.
4. Personal information transferred: Personal information specified in Article 2, paragraphs ① and ②

5. Timing and method of transfer: Transmission over a network and storage when the services are used
6. Purpose of transfer: Data storage and server operation for the provision of game services
7. Retention and use period: For the retention period specified in Article 4

④ Details of cross-border transfers through Google Analytics 4 / Firebase are as follows:

1. Recipient: Google LLC and its affiliates and subprocessors involved in providing the applicable services
2. Contact: Google Privacy Help Center
(https://support.google.com/policies/answer/9581826?hl=ko)
3. Countries of transfer: The United States and other countries in which Google and its subprocessors process personal information for the provision of the applicable services
4. Personal information transferred: App instance identifiers, advertising identifiers, IP address, device and app information, service usage and event information, and diagnostic information
5. Timing and method of transfer: Transmission over a network through SDKs when the services are used
6. Purpose of transfer: Analysis of service usage and user behavior, compilation of statistics, improvement of service quality, and support for technical functions necessary for the provision and operation of services
7. Retention and use period: For the period determined by the Company’s settings and Google’s applicable service policies

⑤ Details of cross-border transfers through AppsFlyer are as follows:

1. Recipient: AppsFlyer Ltd. and its affiliates and subprocessors involved in providing the services
2. Contact: dpo@appsflyer.com
3. Countries of transfer: Israel (where AppsFlyer is located), the EU (data hosting), and countries where AppsFlyer’s disclosed affiliates and subprocessors

are located, including the United States, the United Kingdom, Germany, Japan, India, China, and Hong Kong. The latest list is available in the list of subprocessors published by AppsFlyer.
4. Personal information transferred: Advertising identifiers, AppsFlyer ID, IP address, device information, installation and launch information, and in-app event information
5. Timing and method of transfer: Transmission over a network through SDKs when the services are used
6. Purpose of transfer: Analysis of advertising acquisition channels and install attribution, measurement of advertising campaign performance, and detection of fraudulent traffic
7. Retention and use period: For the period determined by the Company’s settings, contractual terms, and AppsFlyer’s applicable service policies

⑥ The methods and procedures for refusing the cross-border transfers specified in paragraphs ③ through ⑤, and the consequences of such refusal, are as follows:

1. The cross-border transfers specified in paragraphs ③ through ⑤ are carried out in connection with the provision and operation of the services. If a user refuses such transfers, the user will not be able to use the applicable game services.
2. Users who do not wish to have their personal information transferred outside Korea may withdraw by using the account deletion (withdrawal) feature available within each game. The location and name of the relevant menu may vary by game and can be found in the in-game settings. Withdrawal is completed after the grace period specified in the Company’s Terms of Service has elapsed. Once withdrawal is complete, the relevant personal information will no longer be transferred outside Korea.
3. During the grace period or before withdrawal is completed, users may also prevent automatic transmission resulting from use of the app by deleting the app.

4. Personal information that has already been transferred is processed in accordance with applicable laws and regulations, the Company’s settings, and the applicable service’s retention policies. The retention and destruction of account and service usage information are handled in accordance with Article 4.
5. The advertising identifier settings described in Article 7, paragraph ④ restrict the use of advertising identifiers and personalized advertising. These settings alone do not stop all of the cross-border transfers specified in paragraphs ③ through ⑤.

⑦ Users may submit inquiries regarding the details of cross-border transfers of personal information, the recipients of such transfers, and the status of processing through the customer support center available within each game or to the Privacy Officer specified in Article 13.
⑧ If there are any changes to the matters concerning the cross-border transfers specified in paragraphs ③ through ⑤, the Company discloses the changes through this Privacy Policy. If separate notice or consent is required under applicable laws and regulations, the Company follows the required procedures.

 

Article 10. Procedures and Methods for Destruction of Personal Information

① The Company destroys personal information without delay when it is no longer necessary, such as when the retention period has expired or the purposes of processing have been fulfilled.
② Where personal information must continue to be retained pursuant to applicable laws and regulations, the Company stores such personal information separately from other personal information and destroys it without delay after the statutory retention period has expired.
③ Personal information separately retained by the Company pursuant to applicable laws and regulations is limited to the extent required by such laws and regulations, including transaction and payment records, consumer complaint and dispute resolution records, and access logs.

④ The methods for destroying personal information are as follows:

1. Electronic files: Deleted using methods that prevent recovery or restoration
2. Paper documents and other storage media: Destroyed by shredding, incineration, or other equivalent methods that prevent recovery

 

Article 11. Rights and Obligations of Data Subjects and Legal Representatives and Methods for Exercising Such Rights

① Users may exercise their rights regarding the protection of their personal information, including the rights to access, correction or deletion, and suspension of processing, in accordance with applicable laws and regulations.
② Such rights may be exercised through any of the following methods, and the Company processes such requests in accordance with the procedures and time periods prescribed by applicable laws and regulations.

1. Customer support center or 1:1 inquiry available within each game
2. Privacy Officer Email: master@eightstudio.co.kr

③ The Company ensures that the methods and procedures for exercising rights regarding personal information are not unreasonably difficult compared with the methods used to collect the personal information.
④ The Company may request identity verification to the extent necessary to verify that the person requesting to exercise such rights is the individual concerned or a legitimate representative.
⑤ If the Company restricts or denies a user’s request to access personal information or otherwise exercise their rights, or delays processing such a request in accordance with applicable laws and regulations, the Company informs the user of the reasons and the methods available for raising an objection.

 

Article 12. Measures to Ensure the Security of Personal Information

The Company implements the following measures to prevent the loss, theft, leakage, forgery, alteration, or damage of personal information.

1. Administrative Measures

  • Establishment, implementation, and review of an internal management plan

  • Minimization of personnel handling personal information and provision of personal information protection training

2. Technical Measures

  • Management of the granting, modification, and revocation of access rights to personal information processing systems, and access control

  • Measures such as encryption for the secure storage and transmission of personal information

  • Storage and review of access logs for personal information processing systems

  • Installation and periodic updating of security software to prevent intrusion by malware and other threats

3. Physical Measures

  • The Company operates its personal information processing systems using cloud services, and measures to protect physical facilities are implemented by the applicable cloud service providers.

  • Access control for work areas used by personnel handling personal information, and secure storage of documents and storage media containing personal information

 

Article 13. Privacy Officer

① The Company’s Privacy Officer is as follows:

1. Name: Jin No (Chief Executive Officer)

2. Email: master@eightstudio.co.kr

② Users may contact the Privacy Officer regarding inquiries related to personal information protection, the exercise of rights, the handling of complaints, and remedies for harm.
 

Article 14. Remedies for Infringement of Rights

Users may contact any of the following organizations for remedies, counseling, or dispute mediation in connection with harm resulting from an infringement of personal information rights.

1. Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972

2. Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (without area code)

3. Supreme Prosecutors’ Office: www.spo.go.kr / 1301 (without area code)
4. Korean National Police Agency Cybercrime Reporting System (ECRM): ecrm.police.go.kr / 182 (without area code)

 

Article 15. Changes to the Privacy Policy

① The announcement date and effective date of this Privacy Policy are as follows:

  • Announcement date: September 17, 2026

  • Effective date: September 17, 2026

② If the Company changes this Privacy Policy, it continuously makes the revised Privacy Policy available on the Company’s website so that users can review it.
③ If changes are made that require separate notice or consent under applicable laws and regulations, including changes concerning the collection and use of personal information, provision to third parties, or cross-border transfers, the Company follows the procedures prescribed by such laws and regulations.
④ The revision history of this Privacy Policy is as follows:

  • September 17, 2026: Revised matters concerning categories of personal information processed, entrustment of personal information processing, third-party SDKs, behavioral information, and cross-border transfers

  • December 3, 2021: Privacy Policy established

⑤ Previous versions of the Privacy Policy may be obtained by contacting the Privacy Officer.

bottom of page