Before Launching an App Built With Vibe Coding, Check Business Registration, E-Commerce Notification, Privacy Policy, and Refund Terms

Hello, this is Jean from Ethos Administrative Office.
The way apps are built has changed dramatically.
In the past, many people thought that building an app required a planner, developer, designer, backend engineer, and server specialist.
But with AI coding tools and what people now call vibe coding, it has become much easier for individuals to turn small ideas into working apps quickly.
Many apps begin with small features, such as wish journals, fortune apps, routine trackers, diaries, quote apps, simple AI consultation apps, or community apps.
That naturally leads to questions like:
“Can I make a simple app and publish it on the App Store or Google Play?”
“If I only add ads to a free app, do I need business registration?”
“If I add in-app purchases or subscriptions, do I need e-commerce notification?”
“Does even a small app need a privacy policy?”
Here is the key distinction.
Building an app and selling an app are different matters.
Building an app is a technical issue.
But once you sell or monetize the app, it may connect to business registration, e-commerce notification, app marketplace review, in-app purchase rules, privacy policy, terms of use, refund policy, consumer notices, user content moderation, and AI-related responsibilities.
This is especially important for apps built quickly through vibe coding, because it is easy to think, “We can fix the legal and administrative parts after launch.”
However, if the app marketplace requests corrections, if payment or refund disputes arise, or if the privacy policy does not match the actual app structure, the launch schedule and user trust can be affected immediately.
This article summarizes what individual developers, solo founders, and side-project builders should check before selling or monetizing an app on the App Store or Google Play.
Bottom Line: More Important Than an “App Sales Permit” Is the App’s Revenue Model
An individual developer does not always need a separate permit called an “app sales permit” just because they sell an app.
But that does not mean the app can be launched without preparation.
The important question is:
“Based on my app’s revenue model and functions, what registrations, notifications, reviews, terms, and privacy documents are needed?”
The review differs depending on whether the app is free, paid download, in-app purchase-based, subscription-based, ad-supported, user-content-based, or AI-powered.
A safer preparation order is:
- Confirm app functions and revenue model
- Decide the seller: individual, sole proprietor, or corporation
- Review whether business registration is needed
- Review whether e-commerce notification is needed
- Check personal data collection and processing structure
- Prepare privacy policy
- Prepare terms of use, refund policy, and subscription policy
- Check app marketplace review rules and in-app purchase policies
- If there is user content, prepare moderation rules and reporting/blocking standards
- If there is AI functionality, review AI notices and risk factors
- Prepare App Store and Google Play launch materials
The key point is simple.
Before launching an app, organize the sales structure and responsibility structure before focusing only on code.
Building an App and Selling an App Are Different
At the app-building stage, vibe coding usually raises questions like:
- What functions should be built?
- What screens are needed?
- How should login work?
- Where should data be stored?
- How should payment be added?
- How do I upload it to the app stores?
At the app-selling or monetization stage, the questions change:
- Is the seller an individual, business operator, or corporation?
- Who sells the paid features?
- What transaction terms must be shown to users?
- How will refunds be handled?
- Is personal information collected?
- Do advertising SDKs or analytics tools collect data?
- How will responsibility for user posts or images be managed?
- What notices are needed for AI-generated answers or content?
- Do marketplace review rules and Korean legal obligations conflict?
In other words, the developer perspective alone is not enough at launch.
An app is both a technical product and a digital service provided to consumers.
First Decide the App’s Revenue Model
Even for the same app, the required preparation differs depending on the monetization method.
| Revenue Model | Examples | What to Check First | |---|---|---| | Free distribution | Free wish journal, free diary app | App marketplace review, whether privacy policy is needed | | Paid download | Selling the app itself for a fixed price | Business registration, e-commerce notification, seller information | | In-app purchase | Basic features free, premium features paid | In-app purchase policy, paid feature display, refund policy | | Subscription | Monthly or annual access to features | Auto-payment notice, cancellation method, refund terms, terms of use | | Ad-supported | Free app with ads | Advertising ID, third-party SDKs, privacy policy | | User-content-based | Users post text, comments, images, wishes | Reporting/blocking features, operating policy, content management | | AI-powered | AI consultation, fortune, writing, recommendation | AI-use notice, output responsibility, personal data and input data management |
For example, a free calculator that works only on the device and an app where users record wishes and pay for premium features require very different reviews.
If ads are inserted, data processing through advertising identifiers or third-party SDKs may become an issue even if the user does not pay directly.
If users can write posts or share content with other users, reporting/blocking functions and an operating policy may be needed.
If the app includes AI consultation, fortune, or advice functions, users may enter sensitive personal information.
Therefore, the revenue model is not just a business plan.
The revenue model determines the required registrations and documents.
When Should Business Registration Be Reviewed?
The key issue is whether app sales are a simple experiment or a continuous and repeated profit-making business activity.
A person building an app for study or testing purposes may be different from a person selling an app, earning in-app purchase revenue, subscriptions, or advertising revenue continuously.
Business registration should be reviewed in advance if:
- The app will be sold as a paid app
- In-app purchases will be included
- Monthly or annual subscriptions will be operated
- Advertising revenue will be earned continuously
- Multiple apps will be released
- Customer inquiries and refunds will be handled directly
- The app will be operated as a long-term brand
- Outsourced development, marketing, or design costs are incurred
- Future incorporation or investment is being considered
For a first app by an individual developer, incorporation may not be necessary from the beginning.
However, if the app is structured to generate recurring revenue, it is realistic to review whether to start as a sole proprietor, remain at an experimental stage, or consider later incorporation.
Whether an app is a hobby or a business depends on revenue structure and repetition.
E-Commerce Notification May Also Need Review
If paid apps, paid features, digital content, or subscription rights are sold online to consumers, e-commerce notification may need to be reviewed.
Many people think:
“If I sell through the App Store or Google Play, doesn’t Apple or Google handle everything?”
But sales through app marketplaces and notification obligations under Korean law should be reviewed separately.
The Apple App Store and Google Play Store are private platforms.
Passing app marketplace review generally means passing that platform’s internal review standards.
It does not automatically mean that Korean business registration, e-commerce notification, consumer disclosure obligations, refund policy, or terms issues are all resolved.
Conversely, business registration or e-commerce notification does not guarantee app marketplace approval.
If you are preparing a paid app or in-app purchase app, check:
- Whether the seller is an individual, business operator, or corporation
- What seller information appears in the app marketplace
- Who the consumer perceives as the contracting party
- Whether payment and refund are handled through the app marketplace
- Whether external payment exists
- Whether subscription cancellation and refund notices are sufficient
- Whether transaction terms must be disclosed under the E-Commerce Act
- Whether an e-commerce notification exemption applies
App marketplace approval and completion of Korean administrative procedures are not the same thing.
Even a Small App May Need a Privacy Policy
“Does a small app made by an individual really need a privacy policy?”
The answer depends on the app’s functions.
If the app collects no personal information and works only on the device without server communication, the situation may be simpler.
But a privacy policy should be reviewed if the app includes:
- Email address collection
- Name or nickname collection
- Membership signup or login
- Payment functions
- Contact form
- Push notifications
- Advertising SDKs
- Analytics tools
- App usage log collection
- Location data use
- Contacts, photos, microphone, or camera access
- Storage of user-entered text, images, voice, or comments
- Free-text input for AI consultation or fortune functions
Extra caution is needed if users may enter personal details such as birth date, worries, health condition, emotional state, family relationships, romantic issues, or workplace problems.
Review items include:
- What personal information is collected
- Whether it is stored on a server or only on the device
- Whether it is transmitted to third-party services
- What data advertising or analytics SDKs process
- Whether user input is sent to an AI API
- Whether users can request deletion
- How long data is retained
- Whether users under age 14 may use the app
- Whether the privacy policy is easy to access inside the app
Article 30 of Korea’s Personal Information Protection Act is connected to preparing and disclosing a privacy policy.
Before launch, the actual app functions and privacy policy should match.
A privacy policy is not a copied template. It is a document explaining the app’s data flow.
AI Features Require Extra Care With Input Data and Notices
Many apps built through vibe coding include AI features.
Examples include:
- AI consultation apps
- AI fortune apps
- AI diary analysis apps
- AI routine recommendation apps
- AI quote generation apps
- AI writing apps
- AI resume or cover letter helpers
- AI relationship or personal concern consultation apps
- AI image generation apps
These apps may require more review than simple utility apps.
Users may enter highly personal information into AI functions.
For example, in a concern consultation app, users may enter health, family, work, relationship, mental health, or financial information.
In that case, it should be clear where the information is sent and how it is stored.
If the app includes AI features, check at least:
- Whether users are informed that AI is used
- Whether users are told AI answers are not professional advice
- Whether user input is sent to external AI APIs
- Whether input is used for training
- Whether sensitive information input is limited or warned against
- Whether inaccurate answers are disclosed as a possibility
- Whether the app touches high-risk fields such as medical, legal, financial, hiring, or education decisions
- Whether generative AI or high-impact AI obligations may become relevant
An AI app is not finished simply by connecting an API.
Especially after 2026, with AI-related law and service responsibility discussions becoming more concrete, AI apps should organize data processing and user notices before launch.
Subscription Apps Should Prepare Auto-Payment, Cancellation, and Refund Terms Early
Subscription apps are especially prone to disputes.
Monthly payment, annual payment, free trials, auto-renewal, price changes, cancellation, and refund all directly affect consumers.
In a digital music subscription price increase case, the Seoul High Court found that simply notifying existing users of a price increase, without providing a process for consumers to directly choose whether to agree, violated the E-Commerce Act’s requirement to confirm the consumer’s subscription intent.
This does not mean that the case applies identically to every app subscription.
But it clearly shows that in subscription-based digital services, price, auto-payment, changes to terms, consumer consent, cancellation, and refund notices are very important.
Before launching a subscription app, organize:
- Price
- Whether there is a free trial
- When payment begins after the free trial
- Monthly or annual billing cycle
- Auto-renewal status
- How to cancel the subscription
- Refund standard for already paid amounts
- Scope of paid features
- Notice and consent process for price changes
- How service discontinuation will be handled
- Customer support email
- Possibility of minors making payments
- Relationship between app marketplace refund policy and your own refund policy
You should decide what the user sees before payment, where cancellation can be done after payment, and how refund requests will be handled.
For subscription apps, payment, cancellation, and refund screens can become bigger dispute points than features.
Apps With User Content Need Operating Policies
Even if an app is made by an individual developer, the situation changes if users can post text, images, comments, wishes, concerns, or reviews.
The app becomes a service where user content accumulates.
If the app includes the following functions, an operating policy should be prepared:
- User post writing
- Visibility of posts to other users
- Comments or replies
- Image upload
- Anonymous posting
- Community features
- Reporting function
- Blocking function
- Admin deletion function
- Profiles or nicknames
Apps with anonymous posting, concern sharing, wish sharing, or comments can face issues such as:
- Profanity
- Defamation
- Copyright infringement
- Illegal information
- Youth-harmful content
- Exposure of personal information
- Advertising posts
- Impersonation accounts
- Harassment or stalking comments
The Korean Supreme Court has held that an online service provider may incur tort liability if it knew or could have known that defamatory content was posted in its space, deletion or blocking was technically and economically possible, and the illegality of the post was clear.
Therefore, user-content apps should prepare:
- Prohibited content standards
- Report handling procedure
- Blocking function
- Post deletion standards
- Account suspension standards
- Copyright infringement report process
- Personal information exposure handling standards
- Minor protection standards
- Administrator contact
- Relationship between terms of use and operating policy
For apps where users can post content, the operating policy is a safety device for the service.
App Marketplace Review Is Not Legal Review
It is easy to think that passing App Store or Google Play review means the app is safe.
But app marketplace review follows platform rules.
It does not replace review of Korean business registration, e-commerce notification, privacy policy, E-Commerce Act disclosures, or consumer dispute handling.
Separately from app marketplace review, check:
- Whether app description matches actual functions
- Whether paid features are clearly described
- Whether a privacy policy URL is prepared
- Whether privacy policy is accessible inside the app
- Whether payment, subscription, and cancellation methods are clear to users
- Whether refund inquiry route exists
- Whether user content reporting function exists
- Whether AI-use notice exists for AI features
- Whether customer support email works
- Whether business or seller information is consistent
App marketplaces are launch channels.
But responsibility for lawful sales and operation in Korea remains with the app operator.
Pre-Launch Checklist
If three or more of the following are unclear, review is recommended before launch:
- You have not decided whether the app is free, paid download, in-app purchase, or subscription.
- You have not decided whether the seller is an individual, sole proprietor, or corporation.
- You do not know whether business registration is needed.
- You do not know whether e-commerce notification is needed.
- You do not know how App Store or Google Play seller information will appear.
- There is no privacy policy.
- You have not organized what personal data the app collects.
- You do not know what data advertising SDKs or analytics tools process.
- You have not checked whether user input is sent to an AI API.
- There are no terms of use.
- There is no refund policy.
- Subscription cancellation method is not explained inside the app.
- Free trial to auto-payment notice is insufficient.
- Users can post text, images, or comments, but there is no operating policy.
- There are no reporting, blocking, or deletion standards.
- There is no customer inquiry or dispute response channel.
Even a small app benefits from organizing the structure before launch.
It can reduce app marketplace correction requests, refund disputes, privacy complaints, and user content problems.
Frequently Asked Questions
Q. Does an app made by an individual need business registration?
Not always.
However, if the app is sold for payment or generates continuous revenue through in-app purchases, subscriptions, or ads, business registration should be reviewed.
The key is whether it is a simple test or continuous and repeated revenue activity.
Q. If I sell through the App Store, can I skip e-commerce notification?
Not necessarily.
App marketplace sales and Korean e-commerce notification requirements should be reviewed separately.
The answer may depend on the seller, payment structure, information shown to consumers, and paid feature model.
Q. Does a free app need a privacy policy?
It may.
Even a free app may need a privacy policy if it includes signup, login, advertising SDKs, analytics tools, contact forms, push notifications, or user input storage.
Q. Does an ad-supported free app need review?
Yes.
Advertising SDKs may involve advertising identifiers, device information, or usage records.
Ad-supported apps should review privacy policy and third-party SDK notices.
Q. Does an app using an AI API need special notices?
It may.
It is advisable to notify users about AI use, whether input is sent externally, limits of AI answers, warnings against entering sensitive information, and use of external APIs.
Q. What should subscription apps be most careful about?
Price, billing cycle, auto-renewal, free trial end time, cancellation method, and refund standard.
Users should clearly understand transaction terms before payment.
Q. Does a user-posting app need an operating policy?
Strongly recommended.
Profanity, defamation, copyright infringement, personal information exposure, illegal information, and youth-harmful content may arise.
Reporting, blocking, and deletion standards should be prepared in advance.
When a Pre-Launch First Review Is Needed
Ethos Administrative Office does not review app launch procedures simply as “just register a business.”
Based on the app structure and revenue model, we review:
- Whether the app is free, paid, in-app purchase, subscription, or ad-supported
- Whether the seller should be an individual, sole proprietor, or corporation
- Whether business registration is needed
- Whether e-commerce notification is needed
- Relationship between marketplace seller information and Korean notification information
- Whether a privacy policy is needed
- Whether terms of use and refund policy are needed
- Auto-payment, cancellation, and refund notice structure for subscription apps
- Privacy issues from advertising SDKs and analytics tools
- Operating policy and reporting/blocking standards for user-content apps
- AI notice wording and input-data processing structure for AI apps
- In what order to contact or file with the relevant authorities
Apps can be built quickly, but the sales structure becomes more complex if handled late.
If you have an app ready to launch, check the required notifications and documents before marketplace submission, paid features, or advertising SDK integration.
For consultation, please contact us through the consultation channel.
How Ethos Administrative Office Can Help
Ethos Administrative Office helps individual developers, solo founders, and startups review administrative procedures and document structures before app launch.
We can assist with matters such as:
- Administrative review by app revenue model
- Business registration necessity review
- E-commerce notification necessity review
- Privacy policy direction review
- Terms of use and refund policy structure review
- Auto-payment, cancellation, and refund notices for subscription apps
- Privacy issues related to advertising SDKs and analytics tools
- Operating policy review for user-content apps
- Privacy, notice wording, and service responsibility structure for AI apps
- Document preparation before App Store or Google Play launch
- Administrative procedure review for foreign developers or overseas companies offering app services in Korea
Vibe coding lowered the barrier to building apps.
But once an app is sold and operated, business structure and user protection documents are needed in addition to technology.
Ethos Administrative Office can help organize business registration, e-commerce notification, privacy policy, terms of use, and refund policy before app launch.
For consultation, please contact us through the consultation channel.
References
- Korea Law Information Center: Act on Consumer Protection in Electronic Commerce
- Korea Law Information Center: Personal Information Protection Act
- Seoul High Court Decision 2014Nu66856: Digital Music Monthly Subscription Price Increase Case
- Korea Law Information Center: Framework Act on the Development of Artificial Intelligence and Establishment of Trust Foundation