BusTable Privacy Policy
# Privacy Policy
**Service Name**: BusTable (버스시간표)
**Effective Date**: July 17, 2026
**Last Updated**: July 17, 2026
This Privacy Policy describes how BusTable (the "App") collects, uses, and stores information. By installing and using the App, you agree to the terms below.
---
## 1. Information Collected
### 1.1 Account Information (Stored on Our Server)
The App offers optional sign-up for features such as favorites, photo uploads, and comments. The following data is stored on the App's server (bustable.reactiveworks.dev):
- **Email sign-up**: email address, password (stored only as an irreversible bcrypt hash — the plain-text password is never stored), nickname
- **Google Sign-In**: Google-verified account identifier, email address, nickname
- **Sign in with Apple**: Apple-verified account identifier, email address (which may be a private relay address at your choice), nickname
- A JWT session token to keep you signed in (kept in your device's secure storage)
Most features — stop search, map, and real-time arrivals — are available without an account.
### 1.2 User-Generated Content (Stored on Our Server, Publicly Displayed)
Content that signed-in users upload is stored on our server and **shown publicly to other users**:
- **Photos** of paper timetables posted at bus stops
- Comments (reports), likes/dislikes, and abuse reports
> ⚠️ Uploaded photos are publicly visible. **Do not upload photos containing personal information such as people's faces, license plates, or contact details.** Please photograph only the posted timetable itself.
### 1.3 Location (Processed On-Device Only, Never Sent to Our Server)
The App uses your device's location to show your current position and nearby stops on the map. Location data is **processed only on your device for map display and is never transmitted to or stored on the App's server.** You can still use the App via search if you deny location permission.
### 1.4 Locally Stored on Your Device (No External Transmission)
The App uses `Hive` (local database) and `flutter_secure_storage` (secure storage) to store the following data **only on your device**:
- Favorite stops, recent searches, and stop/timetable caches
- App settings (theme, language, notification preferences)
- Sign-in session token (secure storage)
This data is deleted when you uninstall the App.
### 1.5 Third-Party Ad Service (Google AdMob)
The App is offered free of charge and displays banner advertisements via the **Google AdMob** SDK. To deliver personalized ads and prevent fraud, AdMob may automatically collect:
- **Advertising ID** (resettable from your device settings)
- IP address (used to approximate region)
- Device information (model, OS version, screen size, etc.)
- Ad impression and click data
This information is **not collected or stored by the App developer**; it is processed by Google in accordance with Google's privacy policies:
- Google Ads Policy: https://policies.google.com/technologies/ads
- AdMob Data Processing: https://support.google.com/admob/answer/6128543
---
## 2. Permissions Used
| Permission | Purpose |
| --- | --- |
| Internet (`INTERNET`) | Fetching stop/arrival data, account & upload communication, loading ads, store update checks |
| Location (`ACCESS_FINE/COARSE_LOCATION`) | Showing your position and nearby stops on the map (on-device only; never sent to our server) |
| Camera (`CAMERA`) | Taking a timetable photo (only when you choose to take one) |
| Photos (`READ_MEDIA_IMAGES`) | Selecting a timetable photo from your gallery (only photos you select are accessed) |
| Notifications (`POST_NOTIFICATIONS`) | Local on-device notifications such as last-bus alerts |
Each permission is requested only when the related feature is used; denying it does not affect other features.
---
## 3. Data Retention
- Account information (§1.1) and user-generated content (§1.2) are **deleted without undue delay when you delete your account.** For Sign in with Apple users, account deletion also revokes the Apple token.
- Locally stored data (§1.4) remains on your device until you uninstall the App.
- Data processed by AdMob is retained according to Google's data retention policies.
---
## 4. Sharing With Third Parties
The App developer **does not sell or otherwise share your personal data with third parties.** The following processing occurs as part of providing the service:
- Ad-related data is processed by Google AdMob for ad delivery as described in §1.5 (standard AdMob SDK behavior)
- Google/Apple sign-in goes through the respective provider's authentication flow (governed by their privacy policies)
---
## 5. Your Rights
You may exercise the following rights at any time:
- **Delete your account**: Use **More → Delete Account** inside the App to delete your account and server-stored data.
- **Delete your posts**: Delete your own uploaded photos and comments inside the App.
- **Uninstall**: Removing the App from your device deletes all locally stored data described in §1.4.
- **Opt out of personalized ads**: Android — Settings → Google → Ads → reset your Advertising ID or opt out of ads personalization; iOS — Settings → Privacy & Security → Tracking.
- **Access, correction, and deletion requests**: Email the address in §7; requests are handled within 7 business days.
---
## 6. Children's Privacy
The App is not directed at children under the age of 14, and we do not knowingly collect personal information from users under 14. In particular, we do not knowingly collect personal information from children under the age of 13 (COPPA). AdMob ads displayed are general-audience. If you believe a child's information has been collected, please contact us via §7 and we will delete it promptly.
---
## 7. Contact
| Field | Detail |
| --- | --- |
| Developer | SiU Ahn (안시우) |
| Email | siwooeo@gmail.com |
For questions, requests for data access or deletion, or any privacy-related concerns, please email the address above. Responses will be sent within 7 business days.
---
## 8. Changes to This Policy
This Policy may be updated to reflect changes in law or service practices. Material changes will be announced in the App or on this page in advance.
---
**Effective Date: July 17, 2026**
**Service Name**: BusTable (버스시간표)
**Effective Date**: July 17, 2026
**Last Updated**: July 17, 2026
This Privacy Policy describes how BusTable (the "App") collects, uses, and stores information. By installing and using the App, you agree to the terms below.
---
## 1. Information Collected
### 1.1 Account Information (Stored on Our Server)
The App offers optional sign-up for features such as favorites, photo uploads, and comments. The following data is stored on the App's server (bustable.reactiveworks.dev):
- **Email sign-up**: email address, password (stored only as an irreversible bcrypt hash — the plain-text password is never stored), nickname
- **Google Sign-In**: Google-verified account identifier, email address, nickname
- **Sign in with Apple**: Apple-verified account identifier, email address (which may be a private relay address at your choice), nickname
- A JWT session token to keep you signed in (kept in your device's secure storage)
Most features — stop search, map, and real-time arrivals — are available without an account.
### 1.2 User-Generated Content (Stored on Our Server, Publicly Displayed)
Content that signed-in users upload is stored on our server and **shown publicly to other users**:
- **Photos** of paper timetables posted at bus stops
- Comments (reports), likes/dislikes, and abuse reports
> ⚠️ Uploaded photos are publicly visible. **Do not upload photos containing personal information such as people's faces, license plates, or contact details.** Please photograph only the posted timetable itself.
### 1.3 Location (Processed On-Device Only, Never Sent to Our Server)
The App uses your device's location to show your current position and nearby stops on the map. Location data is **processed only on your device for map display and is never transmitted to or stored on the App's server.** You can still use the App via search if you deny location permission.
### 1.4 Locally Stored on Your Device (No External Transmission)
The App uses `Hive` (local database) and `flutter_secure_storage` (secure storage) to store the following data **only on your device**:
- Favorite stops, recent searches, and stop/timetable caches
- App settings (theme, language, notification preferences)
- Sign-in session token (secure storage)
This data is deleted when you uninstall the App.
### 1.5 Third-Party Ad Service (Google AdMob)
The App is offered free of charge and displays banner advertisements via the **Google AdMob** SDK. To deliver personalized ads and prevent fraud, AdMob may automatically collect:
- **Advertising ID** (resettable from your device settings)
- IP address (used to approximate region)
- Device information (model, OS version, screen size, etc.)
- Ad impression and click data
This information is **not collected or stored by the App developer**; it is processed by Google in accordance with Google's privacy policies:
- Google Ads Policy: https://policies.google.com/technologies/ads
- AdMob Data Processing: https://support.google.com/admob/answer/6128543
---
## 2. Permissions Used
| Permission | Purpose |
| --- | --- |
| Internet (`INTERNET`) | Fetching stop/arrival data, account & upload communication, loading ads, store update checks |
| Location (`ACCESS_FINE/COARSE_LOCATION`) | Showing your position and nearby stops on the map (on-device only; never sent to our server) |
| Camera (`CAMERA`) | Taking a timetable photo (only when you choose to take one) |
| Photos (`READ_MEDIA_IMAGES`) | Selecting a timetable photo from your gallery (only photos you select are accessed) |
| Notifications (`POST_NOTIFICATIONS`) | Local on-device notifications such as last-bus alerts |
Each permission is requested only when the related feature is used; denying it does not affect other features.
---
## 3. Data Retention
- Account information (§1.1) and user-generated content (§1.2) are **deleted without undue delay when you delete your account.** For Sign in with Apple users, account deletion also revokes the Apple token.
- Locally stored data (§1.4) remains on your device until you uninstall the App.
- Data processed by AdMob is retained according to Google's data retention policies.
---
## 4. Sharing With Third Parties
The App developer **does not sell or otherwise share your personal data with third parties.** The following processing occurs as part of providing the service:
- Ad-related data is processed by Google AdMob for ad delivery as described in §1.5 (standard AdMob SDK behavior)
- Google/Apple sign-in goes through the respective provider's authentication flow (governed by their privacy policies)
---
## 5. Your Rights
You may exercise the following rights at any time:
- **Delete your account**: Use **More → Delete Account** inside the App to delete your account and server-stored data.
- **Delete your posts**: Delete your own uploaded photos and comments inside the App.
- **Uninstall**: Removing the App from your device deletes all locally stored data described in §1.4.
- **Opt out of personalized ads**: Android — Settings → Google → Ads → reset your Advertising ID or opt out of ads personalization; iOS — Settings → Privacy & Security → Tracking.
- **Access, correction, and deletion requests**: Email the address in §7; requests are handled within 7 business days.
---
## 6. Children's Privacy
The App is not directed at children under the age of 14, and we do not knowingly collect personal information from users under 14. In particular, we do not knowingly collect personal information from children under the age of 13 (COPPA). AdMob ads displayed are general-audience. If you believe a child's information has been collected, please contact us via §7 and we will delete it promptly.
---
## 7. Contact
| Field | Detail |
| --- | --- |
| Developer | SiU Ahn (안시우) |
| Email | siwooeo@gmail.com |
For questions, requests for data access or deletion, or any privacy-related concerns, please email the address above. Responses will be sent within 7 business days.
---
## 8. Changes to This Policy
This Policy may be updated to reflect changes in law or service practices. Material changes will be announced in the App or on this page in advance.
---
**Effective Date: July 17, 2026**