Data handling policy
What your service promises to do with the user data it receives from 놀아 Account.
A service that adds 놀아 Account sign-in receives its users' personal information. This is our promise about how you must handle that information. By registering a service, you are deemed to have agreed to this policy.
1. Information you receive
| Information | Condition |
|---|---|
Per-service identifier (sub) and nickname | profile.basic |
| Email address | profile.basic + email sharing is turned on for the service |
| Profile picture URL | profile.avatar |
| The list of services the user has registered | service.domain.read (granted by an administrator) |
2. No use beyond the stated purpose
You may not use it for anything other than the purpose disclosed to the user on the consent screen — that is, sign-in and account identification for your service.
- You will not use the email you receive to send marketing the user has not consented to
- You will not sell, transfer or share the information you receive with third parties
- You will not use it to build advertising-targeting profiles or supply it to data brokers
- To use it as AI training data, you must notify the user separately and obtain their consent
3. Retention and deletion
- Store only the minimum needed to run your service. If
subalone is enough, don't store the email - When a user leaves your service, delete their data without delay
- If a user has disconnected from 놀아 Account, you must stop using that information from then on
- Do not keep tokens after they expire or are revoked
4. Store it safely
- Keep personal information such as email encrypted or behind access controls
- Do not send access tokens or refresh tokens down to the browser
- Do not write tokens or emails to your logs in plain text
- For details, see the Security checklist
5. About sub
sub is issued as a different value for each service (pairwise).
The same user gets a different sub in a different service.
This is a design to stop services from colluding to track users.
Matching sub against another service, or trying to trace it back, violates this policy.6. What to tell your users
Your service's privacy policy must include the following.
- What information you receive through 놀아 Account sign-in
- What purpose you use it for
- How long you keep it
- How to disconnect and how to leave the service
7. Brand use
Use the 놀아 Account mark and name only to let people know “this service supports sign-in with 놀아 Account.” You may not use them in a way that suggests 놀아 endorses, recommends or is affiliated with your service. The detailed rules are in the Brand guide.
8. If you violate this policy
If a violation of this policy is confirmed, your service's OAuth integration may be blocked without prior notice.
Once blocked, authorization requests from that service are rejected with access_denied.
9. Contact
If the meaning of the policy is unclear, please ask before deciding on your own. This is especially true if you want to use the information you received for a new purpose.