Privacy Policy
Effective 7 September 2026 · Last revised 31 August 2026
This policy takes effect on 7 September 2026. Until then, the version dated 11 August 2026 applies. Changes are listed under Notices.
At a glance
- Pushbin keeps notification, schedule, and transaction data encrypted on your device and never sends it anywhere.
- Cyber Merge Chip and Rookie Hacker Cat include advertising, and the ad SDK uses an advertising identifier.
- Signing in, joining leaderboards, and cloud save are optional. Skip them and your progress stays on the device.
- We do not sell personal information.
- This website uses no cookies and no analytics tools.
1. Scope and controller
Eurion ("we", "us") publishes this Privacy Policy to explain how we handle personal data and to comply with applicable law. For the services listed below we determine the purposes and means of processing, which makes us the controller under the GDPR.
This policy applies to:
-
the website
eurion.co.kr - the mobile application Cyber Merge Chip
- the mobile application Pushbin
- the mobile application Rookie Hacker Cat
We apply the Personal Information Protection Act of the Republic of Korea as our baseline, together with the GDPR and UK GDPR for users in the European Economic Area and the United Kingdom, and the CCPA/CPRA for residents of California. Region-specific rights are set out in section 9.
2. Personal data we process
| Category | Data | How it is collected |
|---|---|---|
| Enquiries | Email address and anything you include in your message | Provided by you |
| Website access | IP address, browser and device information, timestamp | Generated automatically in web server logs |
| Advertising | Advertising identifier (Android Advertising ID), device and network information, approximate location derived from IP address, ad impression and interaction records | Collected automatically by the in-app advertising SDK |
| Account (optional) | Google account identifier, email address, display name, session data | Only if you choose to sign in |
| Game progress (optional) | Scores, progress state, leaderboard entries | Only if you use leaderboards or cloud save |
| Notifications (Pushbin) | App name, title, body and timestamp of notifications received on your device, plus schedules and transactions extracted from them | Only if you grant notification access; processed entirely on the device |
We do not collect special categories of personal data under Article 9 of the GDPR — such as data on race, health, sex life, or political opinions — nor sensitive information or unique identifiers as defined by Korean law.
3. How each app handles data
Our apps differ. The table below matches the declarations we make in the Google Play Data safety section.
| App | Ads | Account | Sent off device | Stored on device |
|---|---|---|---|---|
| Cyber Merge Chip | Includes Google AdMob | Google sign-in (optional) |
The ad SDK, and — if you sign in or join leaderboards —
our server at
api.eurion.co.kr
|
High score, current run state |
| Rookie Hacker Cat | Includes Google AdMob | Anonymous auth (optional) | The ad SDK, and — if you use cloud save or leaderboards — Supabase | Game progress |
| Pushbin | None | None | Nothing | Notifications, schedules, transactions (AES-256-GCM encrypted) |
The notification data Pushbin processes never leaves your device. It is not transmitted to us or to anyone else. You can withdraw notification access and delete the stored data from the app settings at any time.
4. Purposes and legal bases
For users in the EEA and the UK, we rely on the following legal bases under Article 6(1) of the GDPR.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service and making features work | Account identifier, game progress | Performance of a contract — Art. 6(1)(b) |
| Answering enquiries | Email address, message content | Contract or legitimate interests — Art. 6(1)(b), (f) |
| Keeping the service stable and fixing faults | Access logs, error records | Legitimate interests — Art. 6(1)(f), secure operation |
| Serving and measuring personalised ads | Advertising identifier, device data | Your consent — Art. 6(1)(a) |
| Serving non-personalised ads | Minimal device and network data | Legitimate interests — Art. 6(1)(f), funding a free service |
| Meeting legal obligations | Relevant records | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you may withdraw it at any time. Withdrawal applies going forward and does not affect the lawfulness of processing carried out before it.
5. Processors and disclosure
We do not sell personal information, and we do not disclose it to third parties except as set out below. We engage the following processors to deliver our services.
| Processor | Service | Data involved |
|---|---|---|
| Google LLC · Google Ireland Limited | Ad serving and measurement (AdMob), account authentication (Google sign-in), app distribution and updates (Google Play), website fonts (Google Fonts) | Advertising identifier, device and network data, IP address, account identifier |
| Supabase, Inc. | Cloud save and leaderboards for Rookie Hacker Cat, only where you use those features | Anonymous identifier, game progress |
| Cloudflare, Inc. | Delivery of website style resources (CDN) | IP address, browser information |
Sign-in sessions and leaderboard entries for Cyber Merge Chip are
handled on our own server
(api.eurion.co.kr). That is processing by us, not by a processor.
If our processors or the scope of their work changes, we will update this policy without undue delay. We may disclose data where a law enforcement authority makes a lawful request under the applicable procedure.
6. International transfers
Our services are available worldwide, and the processors above may handle personal data outside your country of residence.
- Recipients: the processors listed in section 5 (Google, Supabase, Cloudflare)
- Destination countries: the United States and other countries where those providers operate data centres
- When and how: transmitted over an encrypted connection at the moment the relevant feature runs
- Data transferred: as listed in section 5
- Retention: until the purpose is fulfilled or you ask us to delete it
For transfers out of the EEA or the UK to a third country, we work only with providers covered by an adequacy decision of the European Commission or by appropriate safeguards, including Standard Contractual Clauses.
You can avoid these transfers by not using the features that trigger them — personalised advertising, sign-in, cloud save, and leaderboards. Those features will then be unavailable.
7. Retention and deletion
- Enquiries: kept for three years after the enquiry is resolved, then deleted, in line with Korean consumer dispute record-keeping rules
- Website access logs: deleted within six months of collection
- Account and leaderboard data: deleted without undue delay when you ask us to delete your account
- Data stored on your device: deleted the moment you clear it in the app or uninstall the app; we have no access to it
- Advertising identifier: retained under the advertising provider's own policy; you can reset or delete the identifier in your device settings
Electronic records are deleted by a method that prevents recovery. Paper records are shredded or incinerated.
8. Your rights and how to use them
Wherever you live, you may exercise the following rights.
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure of your data
- Restriction of processing
- Portability — receive your data in a structured format or have it sent to another controller
- Objection to processing based on legitimate interests, and to direct marketing
- Withdrawal of consent
Write to manager@eurion.co.kr. We respond without undue delay and in any event within one month of receiving your request. Complex requests may take up to a further two months, and we will tell you why if that happens. We will not treat you differently for exercising these rights.
Some things you can do yourself, without contacting us:
- Opt out of personalised ads and reset your advertising ID — Android Settings → Privacy → Ads
- Clear in-app data or uninstall the app
- Withdraw Pushbin's notification access
9. Region-specific information
European Economic Area, United Kingdom, Switzerland
- Our legal bases are set out in section 4, and our transfer safeguards in section 6.
- Where we serve personalised ads to users in the EEA or the UK, we obtain consent beforehand through a Google-certified consent management platform. Without confirmed consent, we do not serve personalised ads.
- You have the right to lodge a complaint with the supervisory authority where you live or work (Article 77 GDPR). A list of authorities is available from the European Data Protection Board at edpb.europa.eu. In the UK, contact the Information Commissioner's Office at ico.org.uk.
- We have no establishment in the European Union. We are assessing whether we must appoint a representative under Article 27 of the GDPR, based on the scale and risk of our processing, and will publish the contact details here if we appoint one.
California, United States
- Under the CCPA/CPRA, California residents have the right to know what personal information is collected, from where, and why; to request deletion; to request correction; to opt out of the sale or sharing of personal information; and not to be discriminated against for exercising these rights.
- We have not sold personal information in the preceding twelve months. Providing an advertising identifier to an advertising provider for personalised ads may count as "sharing" under the CPRA. You can opt out through your device's personalised-ads setting or by emailing us.
- We do not sell or share the personal information of users we know to be under 16.
Republic of Korea
- Under Articles 35 to 37 of the Personal Information Protection Act, you may request access, correction or deletion, and suspension of processing.
- For reports or advice about privacy infringement, contact the Korea Internet & Security Agency privacy centre (privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), the Supreme Prosecutors' Office cybercrime division (spo.go.kr, 1301), or the National Police Agency cyber bureau (ecrm.police.go.kr, 182).
10. Children
Our services are not directed at children. We do not knowingly collect personal data without verifiable parental consent from children under 14 in Korea, under 16 in the EEA (or the lower age between 13 and 16 set by a member state), or under 13 in the United States.
We do not serve personalised ads to users we recognise as children. If we learn that we hold a child's personal data without the required consent, we delete it without undue delay. Parents and guardians who believe we hold their child's data should contact us using the details below.
11. Cookies, tracking, and automated decisions
- This website uses no cookies, no web analytics, and no tracking pixels. It does load fonts and style resources from third parties (Google Fonts, Cloudflare), so opening a page sends your IP address and browser information to those providers.
- In our apps, the advertising SDK uses an advertising identifier and similar technology. You can reset that identifier or opt out in your device settings.
- We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
12. Security
- Data minimisation — we process only what the service needs
- Least-privilege access and access control
- Encryption in transit (HTTPS/TLS)
- AES-256-GCM on-device encryption of Pushbin notification titles, bodies, and schedules
- On-device by default — we do not add server transmission we do not need
13. Contact
- Controller: Eurion
- Privacy contact: Eurion privacy team
- Email: manager@eurion.co.kr
Send all privacy questions, rights requests, and complaints to the address above.
14. Changes to this policy
If we add to, remove from, or amend this policy, we publish the change under Notices at least seven days before it takes effect. For changes that materially affect your rights, we give thirty days' notice.
Revision history
- Effective 7 September 2026 — added GDPR, UK GDPR, and CCPA/CPRA coverage for worldwide app distribution, and disclosures on advertising, account sign-in, and international transfers.
- Effective 11 August 2026 — first version.
This English text is a translation provided for convenience. Where it differs from the Korean version, the Korean version prevails.