この文書の正式な原文は英語版です。法的効力を持つのは英語の本文です。 このページを英語で見る
Privacy Policy
Last updated: 19 September 2026
시행일 및 최종 업데이트: 2026년 9월 19일
1. Scope
This policy describes how 주식회사 SAIR (SAIR Co., Ltd.) (“we”), operator of the Tido Kang website, collects and handles personal data. We collect the minimum we need to run the Service. Data controller: 주식회사 SAIR, 대표자 강희도, 사업자등록번호 368-88-03139, 경기도 안산시 단원구 고잔로 76, 705·706·707호 내 706-33호 (고잔동, 영풍빌딩), Republic of Korea.
2. Data we collect
- Account data — email address, display name, the Tido user ID we assign to your account, and optional profile details you provide.
- Authentication data — a securely hashed password (never the password itself), or your account identifier from a social sign-in provider (such as Apple, Google, Kakao, or Naver) when you choose to sign in that way, together with the verified email address the provider shares with us. Apple and Google sign-in are also offered inside the Airy Neon app; signing in there creates or uses the same Tido account.
- Airy Neon app account data — when you sign in inside the Airy Neon app and use its online features: your in-game nickname (a public display name shown on leaderboards; reserved names are refused, and an administrator may hide a record or clear a nickname that breaks the rules), your gameplay scores and ranking records (best scores per song, stage, and difficulty, shown on leaderboards under your nickname), a minimal set of gameplay statistics used to tune difficulty (for example the point at which a stage was failed, linked to a one-way hashed key rather than to your account), and app sign-in session tokens (see section 9). Game progress such as notes, unlocked songs, energy, missions, and settings stays on your device in the current app version and is not sent to our servers.
- Purchase, order, and subscription data— once checkout opens: what you bought, order amounts and currency, subscription status and billing dates, and refund records. For a subscription bought inside an app through the Apple App Store or Google Play, we receive the store’s transaction or purchase identifiers, the product, and the subscription status and period; for App Store purchases the app also passes Apple an account reference (a UUID our servers derive from your account’s internal identifier) so that the purchase can be attributed to your account. We never store your full card number or card security details — payment credentials are handled by the payment provider.
- Access and usage records — which content your account is entitled to, viewer/print/download activity, and course progress, used to deliver and protect the content you paid for.
- Device, browser, and security logs — IP address, browser or app and device type, and request logs kept for security, abuse prevention (including sign-in attempt and rate-limit counters), and troubleshooting.
Children.Direct sign-up is not offered to children under 14, and the sign-up process does not directly collect a child’s name, email address, date of birth, school, or phone number to create a child account. Users under 14 may use the Service through an account created and managed by a parent or legal guardian. Access and usage records that arise while the Service is used are processed within the scope and purposes described in this policy.
만 14세 미만 아동의 직접 회원가입은 제공하지 않으며, 가입 과정에서 아동 계정 생성을 위한 아동의 이름, 이메일, 생년월일, 학교, 전화번호 등의 개인정보를 직접 수집하지 않습니다. 만 14세 미만 이용자는 부모 또는 법정대리인이 생성·관리하는 계정을 통해 서비스를 이용할 수 있습니다. 서비스 이용 과정에서 발생하는 접속 기록과 이용 기록은 본 개인정보처리방침의 범위와 목적에 따라 처리될 수 있습니다.
3. Cookies
We use cookies that are necessary for the Service to work — above all the session cookie that keeps you signed in. We do not currently use advertising cookies. If analytics or marketing cookies are added later, this policy will be updated first and consent obtained where required.
4. How we use data
To provide the Service: authenticate you, deliver purchased or subscribed content, process and record orders, run the Airy Neon online features (nickname, leaderboards, and rankings), provide support, secure the platform, meet legal obligations, and — only with your separate consent — send marketing messages, which you can withdraw at any time.
5. Service providers
We use a small set of processors to run the Service: website hosting and content delivery, a managed database, and file storage. These providers process data on our instructions. When you sign in with Apple or Google, the provider processes your sign-in under its own privacy policy and shares with us only your account identifier and verified email address. The optional ads shown in the Airy Neon app are described in the Airy Neon app privacy policy.
Payment processing:online checkout is not yet available, and no payment data is currently shared with any payment provider. When Paddle checkout is made available, payments would be processed by Paddle as Merchant of Record — Paddle would then receive the data needed to process your payment (such as your email, country, and payment details you enter on the checkout page) under Paddle’s own privacy policy. If additional payment providers are offered later (for example a Korean payment provider), the same principle applies and this policy will be updated.
6. Retention
Account data is kept while your account exists. Security logs are kept for a limited period. Airy Neon nickname and ranking records are kept while your account exists (an administrator may hide a record from the leaderboards; the record itself is kept until you delete your account); score-submission ledgers are kept for 180 days and gameplay statistics for 30 days; app sign-in sessions expire after 90 days and end earlier when you sign out. Purchase, order, subscription, entitlement, refund, and store transaction records are kept after account deletion for accounting, refund and dispute handling, and to prevent duplicate payments or grants; they currently have no fixed deletion date, and where a law sets a retention period for a record type, that period applies. App Store Server Notification records that could not be matched to a subscription when they arrived are held for reprocessing and removed 30 days after receipt, or 90 days after they were matched; notification records processed on arrival are kept together with the transaction records.
7. Account deletion
You can delete your account yourself: sign in and open tidokang.com/account/delete/. The “Delete account” entry in the Airy Neon app’s account panel and in the Try Piano app’s settings opens the same page. To confirm that it is you, we ask for your password, or — if you signed up with Google or Apple only — for a fresh sign-in with that same Google or Apple account. You can also request deletion by emailing contact@tidokang.com. Deletion takes effect immediately and does not depend on whether you have an active membership: sign-in is blocked on every device and your email address, name, profile image, phone number, password, and social sign-in links are removed from your account record at the same moment, together with your Airy Neon nickname, ranking records, gameplay statistics, learning progress, and activity records. For Sign in with Apple we also ask Apple to revoke the sign-in token as part of the deletion, retrying a few times if Apple is temporarily unreachable; if the request still fails, your account is deleted anyway, the failed revocation is recorded, and the confirmation screen and the deletion notice tell you how to remove the connection yourself in your Apple ID settings. One exception: the deletion notice is sent to your email address through our mail-sending log. While that notice is queued or being retried, the log entry keeps your address and the data needed to render it (such as your display name); the message text itself is not stored. When the entry is closed — sent, given up after retries, or cancelled — that rendering data is removed, and for deletion notices sent after this policy takes effect the address is also replaced by a fixed, non-personal value once the notice has been delivered. Entries closed before this policy took effect, and notices that could not be delivered, keep the address. Kept after deletion, linked to your account’s internal identifier: the account record itself (identifier, deletion time, status); subscription records (provider, the provider’s subscription or purchase identifier — the App Store original transaction identifier, the Google Play purchase token, or the Paddle subscription identifier — plan, status, period, amount, and currency); entitlement and print-credit records; App Store transaction records (environment, transaction and original transaction identifiers, product, outcome, dates); Google Play purchase records; orders, payments, and refund records; revoked app sign-in token hashes; and audit entries. These records identify your account by that identifier and are not anonymised. Deleting your account does not cancel an App Store or Google Play subscription — cancel it with Apple or Google, otherwise they keep billing it — and does not cancel a Tido Kang membership billed through Paddle: cancel it from Manage Membership first if you do not want to be charged again. A deleted account cannot sign in or regain access. Payments or store notifications received after deletion (App Store, Google Play, or Paddle) are recorded but never restore the account or grant it anything; expirations, cancellations, and refunds are still applied to the stored records, and those records are kept as described above. A new account created later with the same email starts empty; past purchases are not attached to it automatically.
8. International processing
Our hosting and storage providers may process data in data centers outside your country, including outside the Republic of Korea. Where that happens we rely on the providers’ contractual data protection commitments and applicable transfer safeguards.
9. Security
We protect data with industry-standard measures: encrypted connections (HTTPS), hashed passwords, access-controlled infrastructure, audit logging of sensitive administrative actions (including changes to app nicknames and ranking records), and the principle of storing only what we need. App sign-in sessions use short-lived access tokens and rotating refresh tokens that the app keeps in the device’s secure storage (Keychain or Keystore); our servers store refresh tokens only as one-way hashes, signing out revokes them, and a revoked token that is presented again ends every session of that account in the app. No full card data is ever stored on our systems.
10. Your rights
You may request access to, correction of, or deletion of your personal data, restrict or object to certain processing, and withdraw consent (such as marketing consent) at any time. Contact contact@tidokang.com or 070-7954-6469; we respond within the period required by applicable law. You also have the right to complain to your data-protection authority.
11. Changes
We will update this policy as the Service evolves — for example when checkout launches — and announce material changes on the Service before they take effect.
12. Contact
Privacy questions and requests: email contact@tidokang.com or call 070-7954-6469 (주식회사 SAIR customer support, Republic of Korea).