Privacy Policy
Effective: March 27, 2026
Bokbut ("the Service") takes your privacy seriously. This Privacy Policy describes how we handle information in accordance with the Personal Information Protection Act of the Republic of Korea.
1. Information we collect
The Service can be used without signing up. We do not collect direct identifiers such as your name, email, or phone number.
| Item | Purpose | Retention |
|---|---|---|
| Device identifier (UUID) | Device authentication and text delivery | Until the app is uninstalled |
| Transmitted text | Phone ↔ PC text delivery | Free: 24 hours / Pro: 7 days |
| Push token (FCM) | Notifying you that text has arrived | Replaced when the token rotates |
| Purchase information | Managing your Pro subscription | Cached up to 1 hour after cancellation |
| Usage records and internal metrics | Service improvement and acquisition, pairing, transfer and repeat-use counts | Existing usage records: 1 year from collection. Internal metrics: see below |
| Error logs | App stability improvements | 90 days |
| Transferred files (images, etc.) | Phone ↔ PC file transfer | Free: 24 hours / Pro: 7 days (auto-deleted after 8 days at most) |
Internal service metrics use an approved campaign category, a pseudonymous identifier derived from the device ID using SHA-256, activity times, transfer type and direction, and counts. These metrics exclude transferred content, file names and transferred URLs, and introduce no new external analytics vendor.
The acquisition-category cookie (bokbut_source) lasts 7 days from an install-link click and is renewed by another click. A device’s first recorded acquisition category is retained for up to 90 days from recording; activity records last up to 90 days from the latest accepted new transfer. Deduplication markers and daily device records last 8 days; daily totals last up to 90 days. Using Delete data in the app removes the device’s acquisition, activity and daily records. Deduplication markers and totals without device identifiers remain until their respective retention periods expire.
2. Text encryption
Transferred text is stored encrypted with AES-256-GCM. Text and files sent by QR-paired devices are end-to-end encrypted on the device before transfer. The server and file store retain encrypted content, which approved devices can read. All communication is protected by TLS/HTTPS. Stored files are automatically deleted after their retention period.
3. Sharing with third parties
We use the following processors to operate the Service:
| Recipient | Purpose | Items | Country |
|---|---|---|---|
| PostHog Inc. | Usage analytics | Device identifier, events | United States |
| Sentry (Functional Software) | Error tracking | Error logs, device info | United States |
| RevenueCat Inc. | Subscription billing | Device identifier, purchase history | United States |
| Google (Firebase) | Push notifications | FCM token | United States |
| Cloudflare, Inc. (R2) | Storing transferred files | Transferred files (ciphertext when end-to-end encrypted) | United States (stored in the Asia-Pacific region) |
4. Data deletion
Select "Delete data" in the app settings to request deletion of stored transfers, device settings and device-level activity records. Text also expires after its retention period. Internal deduplication markers and totals without device identifiers expire after the retention periods described above.
5. Your rights
- Access, deletion, or restriction of processing: app Settings > Delete data
- Contact: support@bokbut.com
6. Privacy officer
Name: Yechan Ahn
Contact: support@bokbut.com
7. Children under 14
The Service does not knowingly collect personal information from children under the age of 14.
8. Changes to this policy
If this Policy changes, we will notify you via the app or this page.