Privacy Policy

Effective: March 27, 2026

Bokbut ("the Service") takes your privacy seriously. This Privacy Policy describes how we handle information in accordance with the Personal Information Protection Act of the Republic of Korea.

1. Information we collect

The Service can be used without signing up. We do not collect direct identifiers such as your name, email, or phone number.

ItemPurposeRetention
Device identifier (UUID)Device authentication and text deliveryUntil the app is uninstalled
Transmitted textPhone ↔ PC text deliveryFree: 24 hours / Pro: 7 days
Push token (FCM)Notifying you that text has arrivedReplaced when the token rotates
Purchase informationManaging your Pro subscriptionCached up to 1 hour after cancellation
Usage records and internal metricsService improvement and acquisition, pairing, transfer and repeat-use countsExisting usage records: 1 year from collection. Internal metrics: see below
Error logsApp stability improvements90 days
Transferred files (images, etc.)Phone ↔ PC file transferFree: 24 hours / Pro: 7 days (auto-deleted after 8 days at most)

Internal service metrics use an approved campaign category, a pseudonymous identifier derived from the device ID using SHA-256, activity times, transfer type and direction, and counts. These metrics exclude transferred content, file names and transferred URLs, and introduce no new external analytics vendor.

The acquisition-category cookie (bokbut_source) lasts 7 days from an install-link click and is renewed by another click. A device’s first recorded acquisition category is retained for up to 90 days from recording; activity records last up to 90 days from the latest accepted new transfer. Deduplication markers and daily device records last 8 days; daily totals last up to 90 days. Using Delete data in the app removes the device’s acquisition, activity and daily records. Deduplication markers and totals without device identifiers remain until their respective retention periods expire.

2. Text encryption

Transferred text is stored encrypted with AES-256-GCM. Text and files sent by QR-paired devices are end-to-end encrypted on the device before transfer. The server and file store retain encrypted content, which approved devices can read. All communication is protected by TLS/HTTPS. Stored files are automatically deleted after their retention period.

3. Sharing with third parties

We use the following processors to operate the Service:

RecipientPurposeItemsCountry
PostHog Inc.Usage analyticsDevice identifier, eventsUnited States
Sentry (Functional Software)Error trackingError logs, device infoUnited States
RevenueCat Inc.Subscription billingDevice identifier, purchase historyUnited States
Google (Firebase)Push notificationsFCM tokenUnited States
Cloudflare, Inc. (R2)Storing transferred filesTransferred files (ciphertext when end-to-end encrypted)United States (stored in the Asia-Pacific region)

4. Data deletion

Select "Delete data" in the app settings to request deletion of stored transfers, device settings and device-level activity records. Text also expires after its retention period. Internal deduplication markers and totals without device identifiers expire after the retention periods described above.

5. Your rights

6. Privacy officer

Name: Yechan Ahn
Contact: support@bokbut.com

7. Children under 14

The Service does not knowingly collect personal information from children under the age of 14.

8. Changes to this policy

If this Policy changes, we will notify you via the app or this page.

Privacy Policy — Bokbut