Back to Nesecu

Nesecu

Nesecu Privacy Policy

How the iOS and Apps-in-Toss versions of Nesecu handle photos, local data, ads, purchases, and your rights.

Effective: 2026-07-27Last revised: 2026-07-27

Selected photos and created stickers are processed and stored on the device and are not uploaded to a Mustardmustache server. Advertising, purchases, and platform analytics are separated by platform and current activation state.

This document reflects the services and platform behavior currently provided.

1. Scope and controller

This policy covers the iOS app and Apps-in-Toss mini-app versions of Nesecu provided by Mustardmustache. Company website enquiries are covered by the separate Company Privacy Policy.

Nesecu does not operate a separate member account or a Mustardmustache photo or sticker backend. Platform, advertising, and payment providers may process data for their own stated purposes.

2. Photos, names, and local content

Nesecu opens only a photo you actively choose through the platform picker. iOS uses Apple's on-device image technologies; Apps-in-Toss uses a bundled model and browser capabilities for cutout and editing.

Finished stickers, your chosen name, packs, calendar entries, game records, difficulty state, and settings are stored on the device to provide features. The source photo is used transiently while editing and the original file is not stored on or sent to a Mustardmustache server.

You retain rights in your photos and creations. Mustardmustache does not reuse them beyond the on-device processing needed to provide the feature and does not use them as training data.

  • Operator upload of photos, cutouts, sticker pixels, or chosen names: none
  • Separate public feed or account: none
  • Identity or profile inference from photos: none

3. iOS advertising and consent

The iOS version uses Google AdMob and Google's User Messaging Platform. The Google Mobile Ads SDK may process coarse location, device identifiers, advertising data, app and ad interactions, crashes, performance, and other diagnostics for ad delivery, frequency capping, aggregate measurement, security, and fraud prevention.

Nesecu disables ad personalization, requests non-personalized ads, and does not request IDFA or cross-app tracking permission. Non-personalized ads may still use mobile identifiers or network data for frequency capping and aggregate reporting. Where required, Google's consent and privacy-choice form is shown before ads and can be reopened from Settings.

After Remove Ads is owned, Nesecu does not ask the ad SDK to load or show ads. Photos, stickers, and chosen names are never included in ad requests.

4. iOS purchases

Play Without Ads is a non-consumable Apple App Store in-app purchase. Apple processes the price, payment method, purchase history, refund, and payment account.

Nesecu stores only a locally verified entitlement state from StoreKit and does not upload receipts or card information to a Mustardmustache server. Restore uses the Apple account, and a verified refund or revocation may remove the entitlement.

5. Apps-in-Toss platform processing

In Apps-in-Toss, an app-specific Toss user key may be hashed again and used as a pseudonymous local storage namespace. The original key, photos, names, and sticker pixels are not placed in app analytics events.

In the live Toss environment, allowlisted non-photo and non-name events such as screens, button presses, game starts, success or failure, rewards, and ad or purchase states may be recorded through Apps-in-Toss Analytics. Sandbox and QR tests may not collect them, and Toss controls platform-added information and retention.

The repository's Apps-in-Toss ads, IAP, and PostHog remain disabled unless required console and backend configuration is verified. This policy and in-app notice will be updated before they are enabled.

6. Independent analytics, third parties, and transfers

PostHog is disabled in the current release configuration, and Mustardmustache does not send events to PostHog.

For iOS, ad-related information may be processed by Google and advertising partners on servers outside Korea when an ad is requested. Categories, purposes, timing, method, and retention follow section 3 and Google's published policy. Apple processes App Store account and purchase data, and Toss processes mini-app execution, storage, and analytics under its platform policy. Mustardmustache does not directly provide photos, sticker pixels, or chosen names to them.

7. Retention, deletion, and export

Local data may remain until you delete it or remove the app or Toss app. Delete All My Data removes the name, photos and derived stickers, packs, calendar, play records, and difficulty progress, while keeping language, audio and haptic preferences, and verified purchase entitlement.

If a technical error prevents completion, the app should report the result and offer retry or support. Images separately saved to Photos or shared elsewhere must be deleted there. Purchase, refund, or dispute records required by law or the platform may remain separately.

8. Rights, children, and changes

You can inspect, change, or delete device data in Settings. Requests concerning support emails held by Mustardmustache may be sent to hello@mmche.studio.

The intended audience is adult pet guardians and parents. A child under 14 must use the service with guardian guidance and consent and should not send personal information requiring consent. Nesecu is not offered in Apple's Kids Category.

Ordinary changes are posted 7 days in advance and materially adverse changes 30 days in advance, except for urgent legal or security changes.

Privacy contact

Data controller
Mustardmustache
Privacy contact
Mustardmustache Privacy Team
Business address
2F, Unit 4, 78 Saeun-ro, Giheung-gu, Yongin-si, Gyeonggi-do 17079, Republic of Korea