Poff

Privacy policy

Poff · Effective October 10, 2026 (Korea Standard Time)

Connecting also shares your information with the plaza. Other participants can see your nickname, task, activity status, and appearance. This continues while you are in a friend room. The setting for filling empty places with plaza people only controls who appears on your screen.

To remove your server account and local data, see account deletion. Removing the app file does not delete your server account.

1. Operator and scope

This policy covers DayPixel’s Poff apps for Mac and Windows and the official download website. Other DayPixel apps have separate notices.

Operator: DayPixel · Representative and privacy contact: Ha-eun Lee
Location: Seongbuk-gu, Seoul, Republic of Korea
Privacy inquiries: eunhafactory@daypixel.kr

2. Information and purposes

Poff starts without an email address or password, but creates a persistent anonymous authentication account with Supabase. The profile identifier is separate from the authentication account identifier. Anonymous sign-in does not mean that no personal data is processed.

InformationPurpose and location
Authentication account identifier and sessionServer connections and your room access. Retained by the authentication service and on your device.
Profile identifier, nickname, task, activity status, and appearanceDisplay people working together. Profile settings are local; current presence is shared through realtime channels.
Room code, name, creation/name-change times, and account-linked membership/recent-use timesInvitations, room lists, and access control. Stored in the server database. Current room details are sent to its participants.
Short messages; sender/recipient identifiers and types for waves and reactionsRealtime interaction through Supabase. The app does not create server chat history. Short messages go to your current friend room.
Window position/size/identifiers and related properties, cursor position, mouse-button state, and time since inputCharacter positioning/movement and activity detection on Mac and Windows. Raw information is processed locally; the resulting activity status may be shared.
On Mac: frontmost app name and identifier, and battery statusAutomatic task detection, focus features, and selected reminders. Raw information is processed locally. The resulting task may be shared. Enabling app-name sharing includes the app name in your task.
On Mac: daily time together and other participants’ nicknames; profile, language, appearance, focus, and reminder settingsLocal work records and preferences. The app does not upload time-together records.
IP addresses and other technical request informationSupabase authentication/realtime connections; GitHub website, downloads, and updates; provider security and operational logs.
Inquiry email address and contentRespond to inquiries, handle rights requests and disputes. Processed in the support mailbox.

Connections, rooms, and realtime sharing are processed to provide the service you request. Security, abuse prevention, and inquiries are handled as necessary for those purposes. Processing requiring separate consent under applicable law is explained separately. Reading this policy or acknowledging the connection notice is not blanket consent to every processing activity.

Windows 0.2.5/0.2.6 lacks some Mac features, including automatic task detection, work statistics, lifestyle reminders, and reactions. Actual processing depends on your platform and features.

3. Information visible to participants

While connected, your profile identifier, nickname, task, activity status, and appearance are shared with plaza participants and your current friend-room participants. Room codes and names are excluded from the plaza profile. Room names are shared within the friend room.

On Mac, automatic task detection is on by default and app-name sharing is off by default. You can disable automatic detection or set your task manually. Avoid adding real names, contact details, confidential work information, or other private content to your nickname, task, room name, or messages.

The app has no feature collecting keystroke contents, other apps’ window titles or screen images, microphone/camera recordings, precise location, or contacts. Activity status inferred from time since input may be shared.

Participants may take screenshots or retain your nickname in their Mac time-together records. Deleting a DayPixel account does not delete records held by other people.

4. Retention and deletion rules

5. Providers and international processing

We use external providers to deliver the service. Poff has no advertising SDK or feature for selling user data for advertising.

ProviderPurpose, information, and locations
Supabase Pte. Ltd.Processes authentication identifiers, room/membership information, realtime information, and technical data over HTTPS/WSS during app connections, authentication, room use, and interactions. The operational database’s primary region is Seoul, Republic of Korea. Support, operations, and subprocessors may use international infrastructure, including Singapore and the United States. DPA and contact · Subprocessors
GitHub, Inc.Processes IP and other technical request information over HTTPS for website visits, update checks, and downloads, using US and global service infrastructure. Privacy statement and contact
Google Gmail/Google WorkspaceProcesses inquiry email addresses and content through email services. Processing may use Google’s global infrastructure, including the United States. Privacy policy and contact · Data processing terms

Provider retention follows the rules above and applicable provider policies and contracts. The database’s primary region does not describe every support, transmission, log, or backup location. Provider policies and subprocessor materials give further information about global processing.

International processing/storage is used as necessary for the requested service and under applicable legal grounds. Transfers requiring separate consent are explained separately. You can avoid online connections, downloads, or email inquiries, or request account deletion if you do not want that processing. Because those features depend on external providers, stopping processing prevents use of connections, sharing, or inquiries.

6. Rights and account/data deletion

Send privacy inquiries and applicable access, correction, deletion, restriction, and other rights requests to eunhafactory@daypixel.kr. Scope and methods may depend on processing purposes, legal obligations, other participants’ rights, and secure identity verification. We explain the outcome or reasons for refusal. Where EU/UK rules apply, applicable portability, objection, consent-withdrawal rights and the right to complain to your supervisory authority are also available.

  1. Poff 0.2.6 or later: choose “Delete account and my data…” in the Mac menu bar or Windows tray menu.
  2. Review the warning and confirm deletion. The server verifies your own account using the app’s authenticated session. Your account, memberships, and this device’s profile, session, settings, and Mac time-together records are removed, and the app closes.
  3. Rooms used by other participants and records they retain remain. Deletion cannot be undone. Starting the app again starts with a new profile and account. If an error appears, do not assume deletion succeeded; retry or contact us.

Version 0.2.5 and earlier have no account-deletion menu. Update to the latest version first. Portable Windows ZIP users must install the new version manually. Contact us first if updating is not possible. An email address or nickname alone does not authorize deletion of someone else’s anonymous account. Do not email authentication tokens, session files, or passwords.

Manual local cleanup: after closing Poff, you can remove Mac authentication session files under ~/Library/Application Support/Ghost/ and Poff preferences (com.daypixel.ghost), or Windows profile/current-server session files under %LOCALAPPDATA%\Ghost\. This alone does not delete the server account, and removing files loses saved profiles, rooms, and preferences. Contact us before removing files shared with other versions or servers.

Korean complaint channels: Personal Information Infringement Report Center (118) and Personal Information Dispute Mediation Committee.

7. Safeguards, website, and changes

The app uses HTTPS/WSS, authentication, and room-membership access checks. Mac sessions are protected by file permissions; Windows sessions are encrypted using the current user’s DPAPI protection. Communications are not end-to-end encrypted.

Poff apps and website have no first-party advertising, usage analytics, or automatic crash-report uploads. The website code sets no advertising/analytics cookies, but providers’ own processing is covered by their policies. Mac updates disable Sparkle system profiling.

Poff is not designed or marketed for children and does not collect birth dates. If use by a child requiring parental consent or processing of their information becomes known, stop using the service and contact us with a parent or guardian. Identified information is handled or deleted under applicable law.

Policy and significant processing changes are reflected here and in app notices where needed. New purposes or changes requiring separate consent are explained before they apply. The connection notice explains sharing; it is not blanket consent to all processing.

History: October 10, 2026 — first publication of the Poff-specific Korean and English policy.