Yoinky is an iOS app that works on your device, with no accounts and no servers of its own. This policy explains what personal information Yoinky processes — the items, purposes, retention, outsourcing, and cross-border transfers — and your rights.
The anonymous identifier is not an account identifier that tells us who you are, but it can link activities from the same installation. So we do not claim complete anonymity — the sections below explain exactly what is processed.
| Item | Details |
|---|---|
| Operator / Representative | Jin Taewoo (진태우), individual developer |
| Privacy Officer | Jin Taewoo (same as the operator) |
| Contact / rights requests | [email protected] |
Inquiries and requests to exercise your rights are received at the email address above. A physical address will be added only if a separate legal obligation requires it.
cutout_, scrapbook_) use these internal names.The following information is processed and stored on your device for app functionality, and is not sent externally to PostHog or anywhere else.
| Information | Purpose | Storage location |
|---|---|---|
| Photos selected in Photos, or photos taken with the camera | Sticker creation | Processed on your device; the original is not copied into the app. Only the resulting sticker is kept. |
| Sticker images and thumbnails | Collection, copying, and Scrapbook editing | App storage. Removed when the sticker or the app is deleted; iOS may clear cached copies earlier. |
| Capture/creation timestamp and the original photo's asset identifier | Sorting and linking to the source photo | Stored on your device. Removed together with the related sticker or the app. |
| On-device image analysis results (subject and quality score) | Sticker creation and display order | Stored on your device. |
| Folder names | Organizing stickers | Stored on your device. |
| Scrapbook text and edit state | Scrapbook editing and image generation | Processed in memory while the app is running and cleared when the app closes. |
| The finished poster image | Saving to Photos | Saved to Photos when you request a save and grant permission. |
| Copied stickers | Pasting into other apps | Written to the iOS clipboard by your copy action. |
Photos may contain people, so we treat them with particular care; photos and their analysis results are processed only on your device, as described in the table above.
In the release version, which includes product analytics, the following information is sent to PostHog.
| Category | Examples | Purpose |
|---|---|---|
| Install/session identifiers | The anonymous identifier PostHog stores on your device, and a session identifier | Measuring repeat use and usage frequency per session |
| Flow identifiers | A random identifier created fresh for each import, edit, or save | Linking the steps of a single processing, editing, or saving flow and preventing duplicates |
| Usage events | App opened, import started, sticker processing completed, sticker used, Scrapbook opened/edit started, save tapped/finished | Understanding whether core features are used and where users drop off |
| Behavioral attributes | Import path (camera/Photos), how a sticker is used (copy/Scrapbook), the first edit action, canvas aspect ratio | Analyzing usability feature by feature |
| Counts | Number of photos selected, number of items/stickers/text elements, save-attempt sequence number | Analyzing usage frequency (text and image content are not included) |
| Technical outcomes | Success, failure, or cancellation; a predefined failure stage; time elapsed for processing, editing, and saving | Diagnosing technical failures |
| App/device information | Event timestamp, app version/build, production vs. development flag, OS name/version, general device type | Identifying version-specific issues and separating production from development data |
| Network/approximate location | The IP address conveyed to the server when data is sent, and the country derived from that IP | The IP address is a technical byproduct of the connection. PostHog derives only country-level location from it; we have disabled finer location estimation such as city, region, or coordinates. It is used only to understand usage distribution by country, and no other location data is stored |
"Time elapsed" means the duration spent processing, editing, or saving — not the actual time you took the photo or saved it. We do not send actual timestamps of those actions. The product analytics events we send are limited to the following 8:
This data is used only to understand the scale of app usage, the sticker-creation success rate, actual usage, conversion from editing to saving, and save failures. It is not used for ad targeting or linked to activity in other apps or on the web.
The following information, which users are likely to consider especially sensitive, is designed not to be included in analytics events; text, folder names, images, and similar content are stripped again before anything is sent.
Product analytics data is sent over an encrypted (HTTPS) connection through the PostHog SDK at fixed points in app usage. If the connection is interrupted, it is held briefly on your device and sent once the connection is restored.
We do not use broad automatic capture of screens, buttons, or gestures; automatic app-lifecycle capture; session replay; surveys; or error/log collection — only the 8 events above are sent. If you do not want analytics, deleting the app stops any further transmission (the current version does not provide an in-app setting to turn it off).
The flow for saving a poster to Photos shows Google AdMob interstitial ads. To request and show ads, the Google Mobile Ads SDK processes the following information, which is sent to Google's advertising infrastructure.
| Category | Examples | Purpose |
|---|---|---|
| Device/advertising identifiers | The advertising identifier (IDFA, when ATT is allowed) and other device-identifying signals | Ad requests, frequency capping, personalization (when allowed), and conversion measurement |
| Network/approximate location | The IP address and the approximate location derived from it | Processing ad requests and region-appropriate ads |
| Ad interaction/device info | Ad impressions/clicks, app/OS/device type, and SKAdNetwork attribution signals | Ad delivery, performance measurement, and attribution |
If you allow ATT, you see personalized ads using the IDFA; if you don't, you see non-personalized ads. In either case, all features — saving, editing, and so on — work the same. This processing is governed by Google's Privacy Policy and How Google uses information from sites or apps that use our services. Photos, stickers, text, and folder names stay on your device as described in §3.1 — they are never sent for advertising.
| Permission | When requested | Purpose |
|---|---|---|
| Camera | When you choose to take a photo | Creating a sticker after taking a photo |
| Photo selection (Photos picker) | When you choose to import photos | Passing only the photos you select for processing |
| Add-only photo access | When you save a poster to Photos | Adding the finished image to Photos |
Photo selection lets you choose exactly which photos to hand over, and the add-only permission is only for adding the result — it does not read everything in Photos.
Version 1.0 stated that we did not show an ATT prompt, because the app had no advertising. With this revision we have introduced interstitial ads, so we now show an ATT prompt to personalize them.
The ATT (App Tracking Transparency) prompt appears not at launch but after your first successful save, once you have closed the save confirmation, and only once. Depending on network conditions it may be deferred to a later save. If you allow it, you see personalized ads using the IDFA; if you deny or don't respond, you see non-personalized ads. Either way, all app features work the same. You can change your tracking choice at any time in iOS Settings.
For users in the EEA/UK, a Google UMP (User Messaging Platform) consent form appears before the ATT prompt to obtain consent for advertising-purpose processing. Your consent state is stored on the device and reused on the next launch; if you don't consent, you can use the app without personalized ads. You can revisit or withdraw that consent at any time from Change Ad Consent on the Collection screen. Product analytics (PostHog) is sent within the scope of §3.2 regardless of your ATT/UMP choices.
We use PostHog Cloud for product analytics. PostHog is a processor that stores and processes analytics data under the operator's instructions. This policy discloses this as outsourcing and a cross-border transfer.
| Item | Details |
|---|---|
| Processor/recipient | PostHog, Inc. |
| Purpose of outsourcing | Product usage analytics |
| Items transferred | The anonymous identifier, session/flow identifiers, usage events, technical outcomes, app/OS/network information, and approximate country described in section 3.2 |
| Timing/method of transfer | Sent continuously over HTTPS as events occur |
| Country of storage | United States (PostHog US region) |
| Transfer basis/subprocessors | Per PostHog's published subprocessor list (posthog.com/subprocessors); PostHog may process information in the United States and elsewhere to operate and support the service |
| Retention period | 12 months from the date of collection |
| Contract | Governed by the data processing agreement (DPA, posthog.com/dpa) included in PostHog's standard terms |
For advertising, we use Google AdMob, and Google processes the ad-related information in §3.5 on its own infrastructure. This entails a cross-border transfer as described below.
| Item | Details |
|---|---|
| Recipient | Google LLC (and regional Google affiliates) |
| Purpose | Serving interstitial ads, performance measurement, and attribution |
| Items transferred | The device/advertising identifiers, IP/approximate location, and ad-interaction/device information in §3.5 |
| Country of storage | The United States and other countries where Google operates |
| Processing basis/retention | Per Google's Privacy Policy (policies.google.com/privacy) and its advertising data retention policies |
| Consent | UMP consent in the EEA/UK; ATT for iOS tracking (§4.2) |
Yoinky does not sell product analytics information (PostHog), nor does it use that information for advertising or provide it to advertising businesses. The information sent to Google for advertising is limited to what is disclosed in §3.5 and §5 above.
| Information | Retention standard | Deletion method |
|---|---|---|
| Stickers, thumbnails, folders, and other on-device information | Until you delete them or delete the app (iOS may clear cached copies earlier) | The app's delete function, or deleting the app |
| Scrapbook edit state and text | While the app is running | Cleared from memory when the app closes |
| Result images saved to Photos | Until you delete them in Photos | Deleted by you in Photos |
| Analytics data awaiting transmission | Until sent, or until it expires under the SDK's queue policy | Removed on transmission or expiration |
| PostHog analytics events | 12 months from the date of collection | Deleted after the retention period elapses or upon a deletion request |
Where retention is required by law, the relevant information may be stored separately for that period. Deleting the app does not automatically delete images you saved to Photos or moved to another app.
Under applicable law, you may request access to, correction of, deletion of, or suspension of processing of your information, or object to its processing.
Because Yoinky does not create accounts, it does not link a name or email address to an analytics identifier. This can make it difficult to confirm that a particular analytics record belongs to the requester; to identify a specific record, you must provide your own analytics identifier. If a record cannot be safely identified, it will instead be deleted once the retention period (12 months) elapses. We will describe the processing timeline and how you'll be notified of the outcome in our reply.
Access to the PostHog project is managed by the operator.
If you need consultation, dispute mediation, or remedy for a privacy violation, you may contact the agencies below (for users in the Republic of Korea).
If you disagree with a disposition regarding a request for access, correction, deletion, or suspension of processing, or have suffered harm, you may file an administrative appeal under the Administrative Appeals Act.
Yoinky includes Google AdMob interstitial ads. In the flow for saving a poster to Photos, we show an ad after a set number of saves, with a minimum interval between ads; if no ad is ready or an ad fails, the app behaves exactly as before, with no ad. The information processed for advertising and its cross-border transfer are described in §3.5 and §5, and consent (ATT/UMP) in §4.2. If the ad format, items processed, or recipients change in the future, we will reflect the change only after revising this policy under §11.
If we change this policy, we will publish the changes and their effective date on this policy page.
| Item | Details |
|---|---|
| Disclosure location | This policy page (§12 revision history and effective date updated) |
| Previous versions | Available in the repository's change history |