Privacy Policy
What information Bzzdex handles, and how long it keeps it.
This is a translation. If it differs from the Korean original, the Korean text governs.
1. First, what we do not handle
Stated first to avoid misunderstanding. Bzzdex does not collect any of the following.
- Passwords. Google handles sign-in; the service neither receives nor stores a password.
- Payment details. The service is free, so there is no payment at all.
- Location, contacts, or device identifiers.
- Member accounts for the apps you build. The service has no end-user account feature.
- Who opened which app. View counts are kept only as anonymous totals.
2. What we handle, and why
When you create an account, we handle the following.
- Google account identifier, email address, display name — to identify you, keep you signed in, and answer your enquiries
- Display language — to show the interface in your language
- Time of consent and the version of the terms you accepted — to record the age-14 confirmation, as the law requires
- The IP address you signed up from — to prevent mass account creation and abuse
- Account status, deletion request time, and a session invalidation number — for account management and signing out everywhere
When you upload an app we store the code files along with its title, description, category, and version history. If you publish it to the Hive, the title and dex number appear in the public list.
When you like an app we record who liked what, so the same app is not counted twice.
When you report an app we record the reason and anything you wrote. You can report without signing in, and in that case no reporter information is kept.
If we confirm a rule violation we record a warning: the reason, the time, and who issued it. You can read your own warnings on your settings page.
We keep daily counters — such as how many apps you published today — against your account or IP address, to enforce daily limits.
3. Legal bases
- Creating an account and providing the service — performance of the user agreement
- Confirming you are 14 or older and recording consent — your consent, and a legal obligation
- Preventing abuse and protecting the service — the operator’s legitimate interests
4. How long we keep it
- Account information — 30 days from the day you request deletion. Signing in again within that window cancels it; after it passes, deletion happens automatically.
- App code files — deleted automatically 30 days after you delete the app.
- Daily usage counters — 60 days.
- Reports — kept as an operational record. If the person who reported deletes their account, the reporter identifier is removed.
- Warnings — kept as an operational record, and deleted together with your account.
An app address stays retired after deletion. The address itself is not personal information; it is kept retired so that an old link can never lead to someone else’s app.
5. Sharing and international transfers
We do not sell personal information. We rely only on what the service needs to run.
- Cloudflare, Inc. (United States) — hosting and storage. Account information, app files, and access records are stored and processed on its servers worldwide.
- Google LLC (United States) — Google sign-in. At sign-in we receive your account identifier, email address, and name from Google.
We send only our own domain names to Google Safe Browsing, to check whether they have been flagged. No user information is sent.
The title and the visible text of a published app are sent to the Google Gemini API to check automatically for inappropriate content. We do not send the full code or any account information, and we use the paid tier, so what we send is not used to train Google models.
Display names are checked the same way once a day. Only the name itself is sent, never your email or your app content. If a name cannot be used here, it is replaced with a temporary one and you are told so on your account page. The time and outcome of the check are kept with your account and deleted when you close it.
We may disclose information where law enforcement or another authority requires it through lawful process.
If advertising is added to the service’s pages in future, we will name the advertising provider here and announce the change beforehand. No advertising is served at present.
6. Processing on behalf of others
There is no arrangement under which we hold a third party’s personal information on their behalf. The service has no end-user accounts and no database feature, so there is no way for an app you build to store another person’s personal information here.
7. Cookies and browser storage
- Sign-in cookie — keeps you signed in. It survives closing the browser and is removed when you sign out.
- Sign-in flow cookie — checks that the request did not change while you were at Google. It expires after 10 minutes.
- Theme cookie — remembers whether you chose the light or dark screen.
Code you paste before signing in is stored only inside your browser (IndexedDB) so it can be restored when you come back. That draft is never sent to the server and is removed once you publish.
We use no advertising or analytics tracking cookies.
8. Your rights
You may exercise these rights at any time.
- Access — your account page shows the information we hold.
- Correction — you can change your display name and language on the account page. Your email comes from Google, so change it there and it follows at your next sign-in.
- Deletion — request deletion on the account page and everything is removed after 30 days. Individual apps can be deleted from the app management page.
- Restriction and objection — write to the contact address below.
People under 14 may not use the service.
9. Disposal
Information is deleted automatically once its retention period passes. Electronic records are deleted in a way that cannot be reversed.
10. Security measures
- All traffic is encrypted (HTTPS).
- We handle no passwords, so there is no password to leak.
- The sign-in cookie is closed to browser scripts and travels only over an encrypted connection.
- Uploaded code is scanned automatically for impersonation and credential-harvesting attempts.
- Operational screens are reachable only by designated operator accounts.
11. For users in Europe
If you use the service from the European Economic Area, then in addition to the bases set out above you have the rights of access, rectification, erasure, restriction, objection, and data portability.
Your information is also processed on servers outside Korea. If you wish to exercise a right, write to the address below.
You also have the right to lodge a complaint with a supervisory authority.
12. Privacy contact
- Operator — 코딩티딩
- Name — 코딩티딩
- Title — 없음
- Contact — codingteading@gmail.com
Send any question, complaint, or request about personal information to the address above.
13. Redress in Korea
Users in Korea may also approach the following bodies.
- Personal Information Dispute Mediation Committee — 1833-6972
- Privacy Infringement Report Centre — 118
- Supreme Prosecutors’ Office, Cybercrime — 1301
- Korean National Police Agency, Cybercrime — 182
14. Changes to this policy
We will announce changes on the service beforehand. The date of the last substantive change appears below.