Back to Nesecu

Nesecu

Nesecu Privacy Policy

How Nesecu on iOS and Apps-in-Toss handles photos, app data, ads, purchases, and your rights.

Effective: 2026-07-27Last revised: 2026-08-24

Your chosen photos and stickers are processed and stored on your device, not uploaded to a Mustardmustache server. Ads, purchases, and platform analytics depend on the platform you use.

This page reflects the service and platform behavior currently available.

1. Scope and controller

This policy covers the iOS app and Apps-in-Toss mini-app versions of Nesecu provided by Mustardmustache. Company website inquiries are covered by the separate Company Privacy Policy.

Nesecu does not operate a separate member account or a Mustardmustache photo or sticker backend. Platform, advertising, and payment providers may process data for their own stated purposes.

2. Photos, names, and local content

Nesecu opens only a photo you actively choose through the platform picker. iOS uses Apple's on-device image technologies; Apps-in-Toss uses a bundled model and browser capabilities for cutout and editing.

Finished stickers, your chosen name, packs, calendar entries, game records, difficulty state, and settings are stored on the device to provide features. The source photo is used transiently while editing and the original file is not stored on or sent to a Mustardmustache server.

You retain rights in your photos and creations. Mustardmustache does not reuse them beyond the on-device processing needed to provide the feature and does not use them as training data.

  • Operator upload of photos, cutouts, sticker pixels, or chosen names: none
  • Separate public feed or account: none
  • Identity or profile inference from photos: none

3. iOS advertising and consent

The iOS version uses Google AdMob and Google's User Messaging Platform. The Google Mobile Ads SDK may process coarse location, device identifiers, advertising data, app and ad interactions, crashes, performance, and other diagnostics for ad delivery, frequency capping, aggregate measurement, security, and fraud prevention.

Nesecu disables ad personalization, requests non-personalized ads, and does not request IDFA or cross-app tracking permission. Non-personalized ads may still use mobile identifiers or network data for frequency capping and aggregate reporting. Where required, Google's consent and privacy-choice form is shown before ads and can be reopened from Settings.

Once Remove Ads has been purchased, Nesecu does not ask the ad SDK to load or show ads. Photos, stickers, and chosen names are never included in ad requests.

4. iOS purchases

Play Without Ads is a non-consumable Apple App Store in-app purchase. Apple processes the price, payment method, purchase history, refund, and payment account.

Nesecu stores only a locally verified entitlement state from StoreKit and does not upload receipts or card information to a Mustardmustache server. Restore uses the Apple account, and a verified refund or revocation may remove the entitlement.

5. Apps-in-Toss platform processing

In Apps-in-Toss, an app-specific Toss user key may be hashed again and used as a pseudonymous local storage namespace. The original key, photos, names, and sticker pixels are not placed in app analytics events.

In the live Toss environment, allowlisted non-photo and non-name events such as screens, button presses, game starts, success or failure, rewards, and ad or purchase states may be recorded through Apps-in-Toss Analytics. Sandbox and QR tests may not collect them, and Toss controls platform-added information and retention.

Apps-in-Toss ads, IAP, and PostHog remain disabled unless the required console and backend configuration is verified. This policy and in-app notice will be updated before they are enabled.

6. Independent analytics, third parties, and transfers

PostHog is disabled in the current release configuration, and Mustardmustache does not send events to PostHog.

For iOS, ad-related information may be processed by Google and advertising partners on servers outside Korea when an ad is requested. Categories, purposes, timing, method, and retention follow section 3 and Google's published policy. Apple processes App Store account and purchase data, and Toss processes mini-app execution, storage, and analytics under its platform policy. Mustardmustache does not directly provide photos, sticker pixels, or chosen names to them.

7. Retention, deletion, and export

Local data may remain until you delete it or remove the app or Toss app. Delete All My Data removes the name, photos and derived stickers, packs, calendar, play records, and difficulty progress, while keeping language, audio and haptic preferences, and verified purchase entitlement.

If a technical error prevents deletion, the app shows the result and lets you retry or contact support. Images separately saved to Photos or shared elsewhere must be deleted there. Purchase, refund, or dispute records required by law or the platform may remain separately.

8. Inspecting or deleting data, and children under 14

You can inspect, change, or delete device data in Settings. Requests concerning support emails held by Mustardmustache may be sent to hello@mmche.studio. Section 10 explains how to exercise each right.

The intended audience is adult pet guardians and parents. A child under 14 must use the service with guardian guidance and consent and should not send personal information requiring consent. Nesecu is not offered in Apple's Kids Category.

Mustardmustache does not knowingly collect personal information from a child under 14 and destroys it without delay if it learns that such information has been collected.

9. Destruction of personal information

Mustardmustache destroys personal information without delay when the retention period has passed, the processing purpose has been fulfilled, or the information is otherwise no longer needed.

Destruction procedure: information that has become eligible for destruction is identified and destroyed after review by the privacy officer. Information that must be preserved under other statutes is moved to separate storage and destroyed when that preservation period ends.

Destruction method: electronic files are permanently deleted so that the records cannot be reproduced, and any printed material is shredded or incinerated.

App data stored on your device is not held by Mustardmustache and cannot be destroyed by Mustardmustache. You must delete it in the app settings or by removing the app.

10. Rights of data subjects and legal representatives, and how to exercise them

You may at any time request access to your personal information, correction of errors, deletion, or suspension of processing.

Under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, these requests may be made in writing, by email, or by fax, and Mustardmustache acts on them without delay. You can send a request to hello@mmche.studio.

The legal representative of a child under 14, or a person you authorize, may exercise these rights on your behalf. In that case a power of attorney in the form prescribed by Annex 11 of the Notice on Personal Information Processing Methods must be submitted.

Mustardmustache asks only for the minimum additional information needed to confirm that the requester is the data subject or a duly authorized representative. A request may be limited where a statute requires the information to be retained, or where granting it would unfairly harm another person's life, body, property, or rights; in that case the reason is explained.

Information stored inside the app can be reviewed and deleted directly in the app settings. The only information held by Mustardmustache that requires a request is the email support record.

Mustardmustache does not make automated decisions that affect your rights or obligations, so there is no processing subject to the refusal or explanation rights under Article 37-2 of the Personal Information Protection Act. Mustardmustache is also not a controller subject to the data portability right under Article 35-2 of that Act.

11. Security measures

Under Article 29 of the Personal Information Protection Act, Mustardmustache applies the following security measures.

  • Administrative — the number of people who handle personal information is limited to the representative alone, and processing procedures are reviewed against privacy legislation and the official drafting guidance.
  • Technical — access to accounts and work devices that handle personal information is restricted and protected by account security measures. Web pages and email are transmitted over encrypted connections.
  • Physical — work devices and storage media are locked and access-controlled.

12. Owner responsibility and breach notification

Under Article 30-3 of the Personal Information Protection Act, 설지환, the owner of Mustardmustache, holds ultimate responsibility for personal information protection and secures the staffing and budget needed to process personal information safely.

If Mustardmustache learns that personal information has been lost, stolen, leaked, forged, altered, or damaged, it notifies the affected users without delay under Article 34 of that Act, together with the items and time of the breach, the steps you can take, and how to claim damages or apply for dispute mediation.

13. Remedies for infringement of rights

If you need counseling or remedies for a privacy infringement, you can contact the following Korean authorities.

A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (access), Article 36 (correction or deletion), or Article 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act.

  • Personal Information Dispute Mediation Committee — +82-1833-6972 — www.kopico.go.kr
  • Privacy Infringement Report Centre (KISA) — +82-118 — privacy.kisa.or.kr
  • Supreme Prosecutors' Office, Cybercrime Investigation Division — +82-1301 — www.spo.go.kr
  • Korean National Police Agency, Cybercrime Report System — +82-182 — ecrm.police.go.kr

14. Changes to this policy and revision history

This policy applies from its effective date. If content is added, removed, or changed because of a change in law or in the service, notice is posted on this page at least seven days before the change takes effect. Changes that are significant and unfavorable to users are announced at least 30 days in advance.

Urgent changes required by law or security may take effect immediately, with the reason explained afterward.

  • v1.0 (effective 27 July 2026) — first issue
  • v1.1 (effective 31 July 2026) — revised
  • v1.2 (effective 24 August 2026) — destruction procedure, how to exercise rights, security measures, owner responsibility and breach notification, remedies, and privacy officer details added to meet Article 30 of the Personal Information Protection Act

15. Privacy officer and access request desk

Data controller
Mustardmustache
Privacy officer
설지환 (Representative)
Grievance and access request desk
Mustardmustache Privacy Team
Business address
2F, Unit 4, 78 Saeun-ro, Giheung-gu, Yongin-si, Gyeonggi-do 17079, Republic of Korea