우후스튜디오(이하 "회사")는 「개인정보 보호법」에 따라 이용자의 개인정보를 보호하고 이와 관련한 고충을 신속하게 처리할 수 있도록 다음과 같이 개인정보처리방침을 수립·공개합니다.
1. 개인정보의 수집 및 이용 목적
회사는 다음의 목적을 위하여 개인정보를 처리합니다.
- 회원 관리: 회원제 서비스 이용에 따른 본인 확인, 회원 식별, 가입 의사 확인, 불량 회원의 부정 이용 방지
- 서비스 제공: 모임 생성 · 관리(초대 코드, 호스트 양도, 멤버 역할), 투표, 체크리스트, 실시간 채팅, 정산(지출 · 회비 · 송금 · 환급), 일정 조율, AI 여행 일정 생성, 영수증 OCR, 미디어 업로드 · 공유, 가게 리뷰 등 핵심 기능 제공
- 알림 발송: 모임 활동 관련 인앱 알림 및 푸시 알림 발송. 이용자는 모임별 · 카테고리별로 알림을 끌 수 있습니다.
- 결제 및 환불 처리: AI 크레딧 팩 · 사진 저장 팩 등 일회성 인앱 결제 처리, 결제 영수증 검증, 모임 단위 잔량 · 사용 이력 관리, 스토어 환불 정책에 따른 분쟁 대응
- 서비스 개선: 서비스 이용 통계 분석, 신규 기능 개발, 가게 리뷰 · 모임 만족도를 활용한 추천 인프라 운영(이용자가 모임 단위로 공유 옵션을 켠 경우에 한함)
- 안전한 이용 환경 구축: 부정 이용 탐지 및 방지, 계정 보안 유지, 디버그 로그 기반 오류 진단(이용자가 명시적으로 동의한 경우에만)
2. 수집하는 개인정보 항목
필수 항목
- 이메일 주소, 닉네임
- 소셜 로그인(Google · Apple · Kakao) 이용 시: 제공자가 전달하는 사용자 식별자 및 이메일
선택 항목 (이용자가 입력한 경우에만)
- 프로필 사진, 전화번호
- 정산을 위한 은행명·계좌번호 (개인 프로필 또는 모임별 멤버 프로필에 저장)
- 모임별 멤버 커스텀 프로필: 모임 내에서만 사용하는 닉네임 · 아바타 · 연락처 · 계좌번호
- 여행 스타일 태그, 사용 언어, 테마, 폰트 배율 등 앱 환경 설정 (지역은 앱 스토어 국가로 자동 판정되며 별도 저장하지 않음)
권한 기반 수집 항목 (이용자가 OS 권한을 허용한 경우에만)
- 위치 정보: 모임/투표 장소 검색, 지도에서 현재 위치 표시, 장소 검색 시 현재 위치(국내/해외)에 맞는 지도 제공자 보정 목적
- 디바이스 캘린더 이벤트(읽기 전용): 일정 조율 시 본인의 불가 시간대를 추천받기 위해 OS 캘린더에 접근합니다(iOS/Android에 연결된 Google · Outlook · Apple 등 모든 캘린더 포함). 읽어온 이벤트는 본인 기기 메모리에서만 사용되며, 회사 서버에 전송 · 저장되지 않고 다른 멤버에게도 노출되지 않습니다.
- 사진 라이브러리: 미디어 업로드 시점에 사용자가 선택한 사진에 한해 접근
- 알림: 푸시 알림 전송을 위한 디바이스 토큰 발급
자동 수집 항목
- 기기 이름, 푸시 알림 토큰, 서비스 이용 기록, 앱 버전 · 빌드 번호 (기기 모델 · OS 버전은 이용자가 디버그 로그 수집에 동의한 경우 오류 진단 목적으로 함께 수집)
- 로그인 및 토큰 갱신 이력 (인증 처리 과정에서 생성되어 인증 제공자인 Supabase Auth가 보유)
- 디버그 로그(앱 오류 · 이벤트 로그): 이용자가 가입(온보딩) 동의 화면 또는 설정 → 개인정보 → "디버그 로그"에서 명시적으로 동의한 경우에만 수집되며, 동의를 철회하면 본인의 디버그 로그가 즉시 서버에서 삭제됩니다. 수집되더라도 30일 후 자동 삭제됩니다.
결제 정보
- 모든 결제는 Apple App Store 또는 Google Play의 인앱 결제(IAP)로만 처리되며, 회사는 카드 번호 · 계좌 정보 등 결제 수단 정보를 직접 수집 · 저장하지 않습니다.
- 회사가 보관하는 정보: 인앱 결제 거래 식별자(transaction_id), 구매 상품 ID, 구매 시각, 결제 금액, 결제자(모임 멤버 식별자)
- RevenueCat을 통해 거래 식별자 검증 및 구매 이력 동기화가 이루어집니다.
- 환불은 App Store · Google Play를 통해 처리되며, 환불 내역은 각 스토어가 보관합니다. 다만 회사는 환불 시 모임에 충전된 크레딧 · 저장 공간을 회수하고 반복 환불 등 부정 이용을 방지하기 위하여, 해당 거래의 환불 상태(환불 시각)와 회수 내역을 기록합니다.
서비스 이용 시 생성 · 저장되는 정보
- 모임 정보: 모임명, 설명, 카테고리, 확정 날짜, 기간, 국내/해외 구분, 통화, 기본 이미지 품질, 멤버 관계 정보, 반복 모임 회차
- 초대 · 멤버십: 초대 코드, 가입/탈퇴 시각, 멤버 역할(host · co_host · treasurer · photographer · member), 탈퇴 사유(self · kicked · account_deleted)
- 투표 및 응답(날짜 · 장소 · 출석 · 일반 투표), 체크리스트 항목 및 완료 상태
- 채팅 메시지(텍스트 · 이미지 · 멘션 · 답장 · 이모지 리액션 · 읽음 표시)
- 정산 내역: 지출 · 회비 · 송금 · 환급 · 회비납부 항목, 멤버별 분담 · 정산 완료 여부, 모임 공금 계좌(은행명 · 계좌번호 · 초기 잔액), 영수증 이미지 및 OCR 인식 결과(상점명 · 금액 · 품목 · 태그)
- 일정 조율: 후보 날짜 범위, 본인이 등록한 불가 시간대(blockers), 참석 의사(가능 · 불가 · 미정), 사유 메모
- 개인 가용성: 본인이 앱 내 캘린더에 직접 입력한 일정. 디바이스 OS 캘린더에서 읽어온 외부 일정(Google · Outlook · Apple 등)은 서버에 저장되지 않으며 본인 기기에서만 표시됩니다.
- 여행 일정: 슬롯(일차 · 시각 · 장소 · 설명), A/B 플랜 그룹, 슬롯 역할 배정, 슬롯 댓글 · 좋아요 · 첨부 사진, AI 여행 일정 생성 세션 및 사용자 프롬프트. 슬롯에 저장되는 장소 정보는 사용자가 입력한 장소명 · 모모 자체 카테고리 · 사용자가 지도에서 확정한 핀 좌표 · 장소 식별자(place_id/URL)에 한합니다.
- 가게 리뷰: 별점 · 텍스트 · 사진, 모임 만족도 응답
- 업로드한 미디어 파일(원본 · 썸네일) 및 메타데이터: 카테고리(gallery · chat · slot · checklist · receipt), 파일 크기, 너비/높이, 동영상 길이, 캡션. EXIF 메타데이터는 이용자 설정(기본값: 삭제)에 따라 제거됩니다.
- 알림 데이터: 인앱 알림 로그, 모임별 알림 음소거 · 카테고리별 on/off 설정
- 무료 크레딧 지급 이력: 지급 · 사용 · 만료 정보
3. 개인정보의 보유 및 이용 기간
회사는 개인정보 수집·이용 목적이 달성된 후에는 해당 정보를 지체 없이 파기합니다. 회원 탈퇴 시 본인 계정·프로필·인증 토큰은 즉시 파기되며, 이용자가 작성한 채팅 메시지·사진·정산 내역 등 다른 멤버의 모임 활동에 영향을 주는 기록은 "탈퇴한 사용자" 등으로 익명 처리되어 보존됩니다. 본인이 호스트였던 모임은 다른 멤버가 있으면 자동으로 호스트가 위임되어 유지되고, 본인만 있던 모임은 함께 삭제됩니다.
호스트가 모임을 삭제하면 30일간 휴지통에서 복구할 수 있으며, 30일 경과 시 모임 데이터가 완전 삭제됩니다. 호스트가 휴지통에서 직접 영구 삭제를 선택하거나 회원 탈퇴로 더 이상 멤버가 없게 된 모임은 즉시 삭제됩니다. 사진 등 미디어 파일(원본은 Cloudflare R2, 썸네일은 Supabase 비공개 저장소)도 같은 시점에 영구 삭제됩니다.
단, 다음의 정보는 관련 법령에 따라 아래 기간 동안 보관합니다.
| 보관 항목 |
보관 근거 |
보관 기간 |
| 계약 또는 청약철회 등에 관한 기록 |
전자상거래 등에서의 소비자보호에 관한 법률 |
5년 |
| 대금결제 및 재화 등의 공급에 관한 기록 |
전자상거래 등에서의 소비자보호에 관한 법률 |
5년 |
| 소비자 불만 또는 분쟁처리에 관한 기록 |
전자상거래 등에서의 소비자보호에 관한 법률 |
3년 |
| 로그인 기록 |
통신비밀보호법 |
3개월 |
| 디버그 로그(동의한 이용자만) |
오류 진단 및 서비스 품질 개선 |
30일(자동 삭제) 또는 동의 철회 시 즉시 |
4. 개인정보 처리 위탁 및 국외 이전
회사는 이용자의 개인정보를 원칙적으로 외부에 제공하지 않습니다. 다만, 원활한 서비스 제공을 위하여 아래와 같이 개인정보 처리를 위탁하고 있으며, 위탁 업체 중 일부는 국외에 소재합니다.
| 수탁 업체 |
위탁 목적 |
위탁 항목 |
| Supabase Inc. (미국) |
데이터베이스(Postgres), 인증, 실시간 동기화, 파일 저장(미디어 썸네일 등 비공개 버킷, signed URL 기반 접근), Edge Functions 운영 |
서비스 이용에 필요한 데이터 전반(프로필, 모임, 메시지, 정산, 미디어 등) |
| Cloudflare, Inc. (미국) |
미디어 파일(사진 · 영수증 이미지 등)의 원본 · 표시본 객체 저장(Cloudflare R2) 및 임시 서명 URL(signed URL) 기반 접근 제공 |
이용자가 업로드한 미디어 파일(사진, 영수증 이미지 등) |
| Google LLC (미국) |
Google OAuth 소셜 인증, Google Maps(해외 지역 지도), Firebase Hosting(딥링크 및 본 처리방침 페이지 호스팅) |
제공자가 전달하는 사용자 식별자 · 이메일, 위치 검색 질의 |
| Apple Inc. (미국) |
Apple Sign In 소셜 인증, App Store 인앱 결제 처리 |
제공자가 전달하는 사용자 식별자 · 이메일, 결제 영수증 식별자(transaction_id) |
| Kakao Corp. (대한민국) |
Kakao 소셜 인증, 카카오맵(국내 지역 지도) |
제공자가 전달하는 사용자 식별자 · 이메일, 위치 검색 질의 |
| Anthropic, PBC · OpenAI, L.L.C. · Google LLC (미국) |
영수증 OCR · AI 여행 일정 생성 · 채팅 요약 등 AI 기능 처리 — 회사가 서비스 품질 및 비용에 따라 Claude · Gemini 등을 선택하여 사용하며, 향후 GPT 등 다른 제공자로 확장될 수 있습니다 |
모임 컨텍스트, 영수증 이미지, 사용자 프롬프트 |
| RevenueCat, Inc. (미국) |
App Store · Google Play 인앱 결제 영수증 검증 및 구매 이력 동기화 |
결제 영수증 식별자(transaction_id), 구매 상품 ID, 사용자 식별자 |
| Expo, Inc. (미국) |
Expo Push Service를 통한 푸시 알림 발송 |
Expo 푸시 토큰, 알림 제목 · 본문(이용자가 잠금화면 미리보기를 끈 경우 제목 · 본문이 일반 문구로 대체) |
| Functional Software, Inc. (Sentry, 미국) |
앱 오류 진단(크래시 · 예외 수집) — 이용자가 "디버그 로그" 수집에 동의한 경우에만 동작 |
오류 스택, 기기/OS 메타데이터, 앱 버전, 익명 사용자 ID(UUID). 이메일 · 이름 · IP · 화면 캡처는 전송되지 않습니다. |
이 외에 환율 정보 조회(Frankfurter, EU), 날씨 예보(국내: 기상청 KMA, 해외: WeatherAPI) 등 부수적인 외부 서비스에는 개인 식별 정보를 포함하지 않는 데이터(통화 코드, 좌표 등)만 전송됩니다.
회사는 위 수탁 업체와 위탁 계약 또는 서비스 약관에 따라 개인정보 보호 관련 법규의 준수, 개인정보에 관한 비밀 유지, 제3자 제공 금지, 사고 시 책임 등을 규정하고 있습니다.
지도 서비스와 관련하여 각 제공자의 개인정보처리방침은 다음에서 확인하실 수 있습니다: Google — policies.google.com/privacy, Kakao — kakao.com/policy/privacy.
5. 광고성 정보 · 마케팅 · 추천 시스템 운영
광고성 정보 및 마케팅 활용
회사는 이용자의 개인정보를 광고성 정보 발송 또는 외부 마케팅 목적으로 이용하지 않습니다. 푸시 알림은 모임 활동(투표, 채팅, 정산 등) 알림 목적으로만 발송됩니다.
추천 시스템 운영을 위한 모임 단위 활용
회사는 더 나은 일정 · 장소 · 가게 추천을 제공하기 위해, 호스트가 명시적으로 공유 옵션을 켠 모임의 데이터를 익명화 · 집계 형태로 활용합니다.
- 활용 대상: 모임 만족도 응답, 가게 리뷰, 여행 일정 동선 등 — 모임 호스트가 모임 설정에서 공유 옵션을 켠 경우에 한합니다.
- 익명화: 활용 시 모임명, 멤버 닉네임, 작성자 식별자 등 개인 식별 정보는 제거되며, 추천 결과에는 작성자 정보가 표시되지 않습니다.
- 철회 방법: 모임 호스트는 언제든지 모임 설정에서 공유 옵션을 끌 수 있으며, 변경 즉시 해당 모임의 데이터는 추천 활용에서 제외됩니다.
- 법적 근거: 「개인정보 보호법」 제17조에 따른 이용자 동의 (모임 호스트의 공유 옵션 설정).
6. 이용자의 권리와 행사 방법
이용자는 언제든지 다음의 권리를 행사할 수 있습니다.
- 개인정보 열람 요구
- 오류 등이 있을 경우 정정 요구
- 삭제 요구
- 처리 정지 요구
- 디버그 로그 수집 동의 철회(앱 내 설정 → 개인정보 → 디버그 로그 토글)
- 회원 탈퇴(앱 내 설정 → 계정 → 회원 탈퇴)
위 권리 행사는 앱 내 설정 메뉴 또는 아래 이메일을 통해 가능하며, 회사는 이에 대해 지체 없이 조치하겠습니다.
- 이메일: woohoo.studio.official@gmail.com
7. 개인정보의 파기
회사는 개인정보 보유 기간의 경과, 처리 목적 달성 등 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
- 전자적 파일: 복구 및 재생이 불가능하도록 안전하게 삭제(Supabase Postgres 행 삭제, Cloudflare R2 · Supabase Storage 객체 영구 삭제)
- 기록물, 인쇄물: 분쇄하거나 소각하여 파기
8. 개인정보의 안전성 확보 조치
회사는 개인정보의 안전성 확보를 위하여 다음과 같은 조치를 취하고 있습니다.
- 접근 통제: 데이터베이스 Row-Level Security(RLS) 정책으로 본인 또는 해당 모임의 멤버만 데이터에 접근 가능하도록 제한
- 전송 구간 암호화: 앱과 서버 간 모든 통신은 HTTPS(TLS)로 암호화
- 저장 데이터 보호: 클라우드 제공자의 저장 시 암호화(at-rest) 적용
- 미디어 비공개 저장: 업로드된 사진 · 영수증 이미지의 원본은 Cloudflare R2, 썸네일은 Supabase의 비공개 저장소에 보관되며, 제한된 유효시간의 임시 서명 URL(signed URL)을 통해서만 접근이 가능합니다.
- 인증 토큰 보호: 인증 토큰은 디바이스의 보안 저장소(iOS Keychain / Android Keystore)에 안전하게 보관되며, PKCE 인증 플로우를 강제해 인증 코드 가로채기를 차단
- 채팅 로컬 캐시 암호화: 빠른 재진입을 위해 디바이스에 보관되는 최근 채팅 캐시는 강력한 표준 암호화로 보호되며, 암호화 키는 디바이스 보안 저장소에 별도 보관됩니다.
- 최소 권한 원칙: 운영자는 업무 수행에 필요한 최소 범위의 데이터에만 접근
9. 만 14세 미만 아동의 개인정보
회사는 만 14세 미만 아동의 회원가입을 받지 않습니다. 만약 만 14세 미만 아동의 개인정보가 수집된 사실이 확인되면 즉시 해당 정보를 삭제하고 계정을 차단합니다.
10. 위치정보의 처리에 관한 사항
회사는 「위치정보의 보호 및 이용 등에 관한 법률」을 준수하며, 이용자의 위치정보를 다음과 같이 최소한으로 처리합니다.
수집 항목 및 방법
- 수집 항목: 단말기에서 일시적으로 측정된 GPS 좌표(위도 · 경도)
- 수집 방법: 이용자가 OS 위치 권한(앱 사용 중 허용)을 명시적으로 허용한 경우에만, 위치 기능을 사용하는 시점에 단말기 SDK(expo-location)를 통해 수집
- 수집 시점: ① 지도 화면(여행 일정 지도 포함)에서 "내 위치로 이동" 사용 시 ② 모임/투표 장소 검색에서 "내 주변 검색" 사용 시 ③ 장소 검색 화면 진입 시 현재 위치가 국내/해외인지에 따라 지도 제공자를 보정하기 위해 — 위 경우 외에는 위치정보를 수집하지 않습니다. (모임의 국내/해외 지역 기본값은 앱 스토어 국가를 기준으로 정해지며, 장소 검색 화면의 지도 제공자는 위 GPS 보정에 따라 달라질 수 있습니다)
이용 목적
- 지도 화면에서 현재 위치 표시 및 주변 장소 검색 결과 정렬
보유 및 이용 기간 (중요)
- 회사는 이용자의 위치정보를 자체 서버에 저장하지 않습니다. 수집된 GPS 좌표는 위 이용 목적에 사용된 후 단말기 메모리에서 즉시 폐기되며, 회사 데이터베이스(Supabase)에 기록되지 않습니다.
- 이용자가 직접 지도/검색에서 선택한 장소(POI)의 좌표는 모임 일정·투표 항목으로 저장될 수 있으나, 이는 이용자가 선택한 장소의 위치이며 이용자 본인의 위치정보가 아닙니다.
제3자 제공 (일회성 처리 위탁)
위치정보는 회사가 별도로 보관·이용하지 않으며, 다음의 검색 API 제공자에게 검색 결과를 받기 위해 일회성으로 전달됩니다. 전달된 좌표는 회사가 다시 수신·저장하지 않습니다.
| 제공받는 자 |
제공 목적 |
제공 항목 |
| Kakao Corp. (대한민국) |
국내 지역 지도 표시 및 주변 장소 검색 처리 |
일회성 GPS 좌표(위도·경도) |
| Google LLC (미국) |
해외 지역 지도 표시 및 주변 장소 검색 처리 |
일회성 GPS 좌표(위도·경도) |
이용자의 권리
- 이용자는 OS 설정에서 언제든지 위치 권한을 거부 또는 철회할 수 있습니다(설정 → 모모 → 위치).
- 위치 권한을 거부하더라도 모임 생성·투표·정산·채팅 등 핵심 기능은 정상 이용할 수 있으며, 일부 위치 기반 기능("내 주변 검색", "내 위치로 이동")만 제한됩니다.
11. 개인정보 보호책임자
회사는 개인정보 처리에 관한 업무를 총괄하여 책임지고, 이용자의 불만 처리 및 피해 구제를 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
| 구분 |
내용 |
| 상호 |
우후스튜디오 |
| 대표자 · 개인정보 보호책임자 |
김준혁 |
| 사업자등록번호 |
278-05-03740 |
| 전화번호 |
010-8069-4304 |
| 이메일 |
woohoo.studio.official@gmail.com |
기타 개인정보 침해에 대한 신고나 상담이 필요한 경우 아래 기관에 문의하실 수 있습니다.
- 개인정보침해신고센터 (privacy.kisa.or.kr / 118)
- 대검찰청 사이버수사과 (spo.go.kr / 1301)
- 경찰청 사이버수사국 (ecrm.police.go.kr / 182)
12. 개인정보처리방침 변경
이 개인정보처리방침은 시행일로부터 적용되며, 관련 법령 및 방침에 따른 변경 내용의 추가, 삭제 및 정정이 있는 경우에는 변경 사항의 시행 7일 전부터 앱 내 공지사항을 통하여 고지할 것입니다.
Woohoo Studio (the "Company") establishes and discloses the following Privacy Policy to protect users' personal information in accordance with the Korean Personal Information Protection Act and to promptly address related grievances.
1. Purposes of Collection and Use of Personal Information
The Company processes personal information for the following purposes:
- Member Management: Identity verification, member identification, confirmation of intent to subscribe, and prevention of fraudulent use by unauthorized members.
- Service Provision: Core features including Gathering creation/management (invite codes, host transfer, member roles), votes, checklists, real-time chat, ledger (expenses, dues, transfers, reimbursements), schedule coordination, AI travel itinerary generation, receipt OCR, media upload/sharing, and place reviews.
- Notifications: In-app and push notifications for Gathering activities. Users can disable notifications per Gathering or per category.
- Payments and Refunds: Processing one-time in-app purchases (AI credit packs, photo storage packs), validating receipts, managing per-Gathering balances and usage history, and handling disputes per store refund policies.
- Service Improvement: Service usage analytics, new feature development, and operating recommendation infrastructure using place reviews and Gathering satisfaction (only when the user has enabled sharing at the Gathering level).
- Safety: Detecting and preventing fraudulent use, maintaining account security, and diagnosing errors via debug logs (only when the user has explicitly consented).
2. Personal Information Collected
Required Items
- Email address, nickname.
- For social login (Google · Apple · Kakao): user identifier and email provided by the provider.
Optional Items (only if entered by the user)
- Profile photo, phone number.
- Bank name and account number for settlement (stored in personal profile or per-Gathering member profile).
- Per-Gathering custom member profile: nickname, avatar, contact, and account number used only within that Gathering.
- App preferences such as travel style tags, language, theme, and font scale. (Region is automatically determined by the App Store country and is not stored separately.)
Permission-Based Items (only when OS permission is granted)
- Location: for Gathering/vote place search, showing your current position on the map, and adjusting the domestic/overseas map provider based on your current location during place search.
- Device calendar events (read-only): the app accesses OS calendars (including Google · Outlook · Apple and any other calendars linked to iOS/Android) to recommend the user's busy times during schedule coordination. Events read this way are kept only in device memory; they are never transmitted to or stored on the Company's servers and are not visible to other members.
- Photo library: access only to photos selected by the user at the moment of upload.
- Notifications: issuing a device token for push notifications.
Automatically Collected Items
- Device name, push notification token, service usage records, app version and build number (device model and OS version are also collected for error diagnosis only when the user consents to debug log collection).
- Login and token refresh history (generated during the authentication process and retained by the authentication provider, Supabase Auth).
- Debug logs (app errors and event logs): collected only when the user explicitly consents on the sign-up (onboarding) consent screen or in Settings → Privacy → "Debug Logs". Withdrawal of consent immediately deletes the user's debug logs from the server. Even when collected, logs are auto-deleted after 30 days.
Payment Information
- All payments are processed exclusively through Apple App Store or Google Play in-app purchase (IAP). The Company does not directly collect or store payment instrument information such as card numbers or account details.
- Information stored by the Company: in-app purchase transaction identifier (transaction_id), purchased product ID, time of purchase, payment amount, payer (Gathering member identifier).
- Transaction identifier validation and purchase history synchronization is performed via RevenueCat.
- Refunds are processed through the App Store / Google Play, and refund records are retained by each store. However, to reclaim credits and storage charged to the Gathering and to prevent abuse such as repeated refunds, the Company records the refund status (time of refund) and reclamation details for that transaction.
Information Created or Stored During Service Use
- Gathering information: name, description, category, confirmed date, duration, domestic/overseas designation, currency, default image quality, member relationship info, recurring sessions.
- Invitations and membership: invite codes, join/leave times, member roles (host, co_host, treasurer, photographer, member), leave reason (self, kicked, account_deleted).
- Votes and responses (date, location, attendance, general), checklist items and completion status.
- Chat messages (text, image, mentions, replies, emoji reactions, read receipts).
- Ledger entries: expenses, dues, transfers, reimbursements, dues payments, per-member shares and settlement completion, Gathering wallet account (bank name, account number, initial balance), receipt images and OCR results (store name, amount, items, tags).
- Schedule coordination: candidate date ranges, your own blockers, attendance intent (available / unavailable / undecided), reason memos.
- Personal availability: events you directly entered in the app's in-app calendar. External events read from device OS calendars (Google · Outlook · Apple, etc.) are not stored on the Company's servers and are visible only on your own device.
- Itinerary: slots (day, time, place, description), A/B plan groups, slot role assignments, slot comments, likes, attached photos, AI itinerary generation sessions and user prompts. Place data stored in a slot is limited to the place name entered by the user, Momo's own category, the pin coordinates the user confirmed on the map, and a place identifier (place_id/URL).
- Place reviews: ratings, text, photos, and Gathering satisfaction responses.
- Uploaded media files (originals and thumbnails) and metadata: category (gallery, chat, slot, checklist, receipt), file size, width/height, video length, captions. EXIF metadata is removed depending on user settings (default: removed).
- Notification data: in-app notification logs, per-Gathering mute settings, per-category on/off settings.
- Free credit grant history: grant, use, and expiration information.
3. Retention and Use Period
The Company destroys personal information without delay once the purposes of collection and use have been achieved. Upon membership withdrawal, your account, profile, and authentication tokens are immediately destroyed, while records that affect other members' Gathering activity (such as chat messages, photos, and ledger entries) are anonymized (e.g., as "Withdrawn User") and retained. For a Gathering you hosted, host rights are automatically transferred to another member if one exists and the Gathering is retained; a Gathering with no other members is deleted together with your withdrawal.
When a host deletes a Gathering, it can be restored from the trash for 30 days, after which the Gathering data is completely deleted. A Gathering that the host permanently deletes from the trash, or that has no remaining members due to membership withdrawal, is deleted immediately. Media files such as photos (originals in Cloudflare R2, thumbnails in private Supabase storage) are permanently deleted at the same time.
However, the following information is retained for the periods specified by applicable laws:
| Retained Items |
Basis |
Retention Period |
| Records of contracts or withdrawal of subscription |
Act on Consumer Protection in Electronic Commerce, Etc. |
5 years |
| Records of payment and supply of goods |
Act on Consumer Protection in Electronic Commerce, Etc. |
5 years |
| Records of consumer complaints or dispute handling |
Act on Consumer Protection in Electronic Commerce, Etc. |
3 years |
| Login records |
Protection of Communications Secrets Act |
3 months |
| Debug logs (consenting users only) |
Error diagnosis and service quality improvement |
30 days (auto-delete) or immediately upon withdrawal of consent |
4. Entrustment of Processing and Overseas Transfers
The Company does not, in principle, provide users' personal information to external parties. However, for smooth service operation, the Company entrusts processing as follows. Some entrusted parties are located overseas.
| Entrustee |
Purpose |
Items |
| Supabase Inc. (USA) |
Database (Postgres), authentication, real-time sync, file storage (private buckets for media thumbnails, etc., accessed via signed URLs), Edge Functions. |
All data necessary to operate the Service (profiles, Gatherings, messages, ledger, media, etc.). |
| Cloudflare, Inc. (USA) |
Object storage (Cloudflare R2) of media file originals and display versions (photos, receipt images, etc.) and access via temporary signed URLs. |
Media files uploaded by the user (photos, receipt images, etc.). |
| Google LLC (USA) |
Google OAuth, Google Maps (overseas regions), Firebase Hosting (deep links and this policy page). |
User identifier and email provided by the provider, location search queries. |
| Apple Inc. (USA) |
Apple Sign In, App Store in-app purchase processing. |
User identifier and email provided by the provider, receipt identifier (transaction_id). |
| Kakao Corp. (Republic of Korea) |
Kakao social login, Kakao Map (domestic regions). |
User identifier and email provided by the provider, location search queries. |
| Anthropic, PBC · OpenAI, L.L.C. · Google LLC (USA) |
Receipt OCR, AI itinerary generation, chat summaries, and other AI features — the Company selects and uses providers such as Claude and Gemini depending on service quality and cost, and may expand to other providers such as GPT in the future. |
Gathering context, receipt images, user prompts. |
| RevenueCat, Inc. (USA) |
Validation of App Store / Google Play receipts and purchase history synchronization. |
Receipt identifier (transaction_id), purchased product ID, user identifier. |
| Expo, Inc. (USA) |
Sending push notifications via Expo Push Service. |
Expo push token, notification title and body (both the title and body are replaced with a generic message when the user disables lock-screen previews). |
| Functional Software, Inc. (Sentry, USA) |
App error diagnostics (crash and exception collection) — active only when the user has consented to "Debug Logs" collection. |
Error stack traces, device/OS metadata, app version, and an anonymous user ID (UUID). Email, name, IP address, and screen captures are not transmitted. |
For incidental external services such as exchange rate lookup (Frankfurter, EU) and weather forecasts (KMA for domestic Korea, WeatherAPI for overseas), only data not containing personally identifiable information (currency codes, coordinates, etc.) is transmitted.
The Company's entrustment contracts or service terms with the above parties require compliance with applicable privacy laws, confidentiality, prohibition of third-party provision, and liability for incidents.
For the map services, each provider's privacy policy is available here: Google — policies.google.com/privacy, Kakao — kakao.com/policy/privacy.
5. Advertising, Marketing, and Recommendation System
Advertising and Marketing
The Company does not use users' personal information to send advertising materials or for external marketing. Push notifications are sent only for Gathering activities (votes, chat, ledger, etc.).
Use for Recommendation System (Per-Gathering Opt-In)
To provide better recommendations for schedules, places, and shops, the Company uses data from Gatherings whose hosts have explicitly enabled the sharing option, in an anonymized and aggregated form.
- Scope: Gathering satisfaction responses, place reviews, and itinerary flow patterns — only when the Gathering host has enabled the sharing option in Gathering settings.
- Anonymization: Personally identifiable information such as Gathering name, member nicknames, and author identifiers is removed. Recommendation results do not display author information.
- Withdrawal: The Gathering host may turn off the sharing option at any time in Gathering settings. The Gathering's data is excluded from recommendation use immediately upon the change.
- Legal basis: User consent under Article 17 of the Personal Information Protection Act (Gathering host's sharing option setting).
6. Users' Rights and How to Exercise Them
Users may exercise the following rights at any time:
- Request access to personal information.
- Request correction in case of errors.
- Request deletion.
- Request suspension of processing.
- Withdraw consent to debug log collection (Settings → Privacy → Debug Logs toggle in the app).
- Delete account (Settings → Account → Delete Account in the app).
Rights may be exercised through the in-app Settings menu or via the email below. The Company will act on requests without delay.
- Email: woohoo.studio.official@gmail.com
7. Destruction of Personal Information
When personal information is no longer needed because the retention period has elapsed or the processing purposes have been achieved, the Company destroys it without delay.
- Electronic files: Securely deleted to prevent recovery or reproduction (row deletion in Supabase Postgres, permanent deletion of Cloudflare R2 and Supabase Storage objects).
- Documents and printouts: Shredded or incinerated.
8. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information:
- Access control: Database Row-Level Security (RLS) policies restrict access to data so that only the user or members of the relevant Gathering can access it.
- Encryption in transit: All communication between the app and the server is encrypted via HTTPS (TLS).
- Data at rest protection: Encryption at rest is applied by the cloud providers.
- Private media storage: Originals of uploaded photos and receipt images are kept in Cloudflare R2 and thumbnails in Supabase, both in private storage accessible only through temporary signed URLs with a limited validity period.
- Auth token protection: Authentication tokens are stored securely in the device secure storage (iOS Keychain / Android Keystore), and the PKCE flow is enforced to prevent authorization code interception.
- Local chat cache encryption: The recent chat cache kept on device for fast re-entry is protected with strong standard encryption, and the encryption key is stored separately in the device secure storage.
- Principle of least privilege: Operators access only the minimum data necessary for their work.
9. Personal Information of Children Under 14
The Company does not accept sign-ups from children under 14 years of age. If personal information of a child under 14 is found to have been collected, the Company immediately deletes such information and blocks the account.
10. Handling of Location Information
The Company complies with the Korean Act on the Protection, Use, Etc. of Location Information and processes users' location data minimally as follows.
Items and Method of Collection
- Items collected: GPS coordinates (latitude, longitude) temporarily measured on the device.
- Method: Only when the user explicitly grants OS location permission (while-in-use), collected via the device SDK (expo-location) at the moment the location feature is invoked.
- When collected: ① when using "Move to My Location" on a map screen (including the itinerary map), ② when using "Search Nearby" in Gathering/vote location search, ③ when entering a place search screen, to adjust the map provider based on whether your current location is domestic or overseas. Location data is not collected outside these cases. (A Gathering's domestic/overseas region default is determined by the App Store country, while the map provider on the place search screen may vary based on the GPS adjustment above.)
Purposes of Use
- Displaying the current location on the map and sorting nearby place search results.
Retention and Use Period (Important)
- The Company does not store users' location information on its own servers. Collected GPS coordinates are discarded from device memory immediately after being used for the purposes above and are not recorded in the Company database (Supabase).
- Coordinates of POIs you yourself select from the map/search may be saved as Gathering schedules or vote options, but these are coordinates of places you selected, not your own location.
Third-Party Provision (One-Time Processing Entrustment)
Location information is not separately stored or used by the Company; it is provided once to the following search API providers to receive search results. Provided coordinates are not received back or stored by the Company.
| Recipient |
Purpose |
Items |
| Kakao Corp. (Republic of Korea) |
Domestic map display and nearby place search. |
One-time GPS coordinates (lat/long). |
| Google LLC (USA) |
Overseas map display and nearby place search. |
One-time GPS coordinates (lat/long). |
Users' Rights
- Users can deny or withdraw location permission at any time in OS settings (Settings → Momo → Location).
- Even if location permission is denied, core features (Gathering creation, voting, ledger, chat, etc.) still work normally; only location-based features ("Search Nearby", "Move to My Location") are limited.
11. Personal Information Protection Officer
The Company designates the following Personal Information Protection Officer to oversee personal information processing and to handle user complaints and remedies.
| Field |
Detail |
| Business Name |
Woohoo Studio |
| Representative · Data Protection Officer |
Junhyuk Kim |
| Business Registration Number |
278-05-03740 |
| Phone |
+82-10-8069-4304 |
| Email |
woohoo.studio.official@gmail.com |
For reporting or consultation on personal information infringement, you may contact the following organizations:
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- Supreme Prosecutors' Office Cybercrime Investigation Division (spo.go.kr / 1301)
- Korean National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
12. Changes to This Privacy Policy
This Privacy Policy applies from its effective date. In the event of additions, deletions, or amendments based on changes in applicable laws and Company policy, the Company will provide notice via in-app announcements at least 7 days before the changes take effect.
In case of any discrepancy between the Korean and English versions of this Privacy Policy, the Korean version shall prevail.