유키(U-KEY) 개인정보 처리방침
버전 1.0 · 시행일: 2026년 7월 18일
1. 개인정보처리자의 정보
- 상호: 포포랩스(popolabs)
- 대표자: 김도현
- 사업자등록번호: 105-33-51914
- 통신판매업 신고번호: 제2026-강원속초-0079호
- 통신판매업 신고기관: 속초시청
- 일반 문의: contact@popolabs.app
- 개인정보·법률 문의: popolabs0511@gmail.com
2. 처리하는 개인정보
회사는 서비스 제공에 필요한 범위에서 다음 정보를 처리합니다.
2.1 계정 및 프로필 정보
- 이메일 가입: 이메일 주소, 암호화된 인증정보, 인증 식별자
- 소셜 로그인: Apple·Google·Kakao가 제공하는 계정 식별자, 이메일 주소, 인증 토큰 및 제공 범위의 프로필 정보
- 프로필: 사용자 핸들, 표시 이름, 프로필 사진, 자기소개, 생년월일, 사용자가 정한 AI 이름
- 동의 기록: AI·OCR 기능의 국외이전 동의 여부와 동의 시각
회사는 이용자의 평문 비밀번호를 직접 열람하거나 보관하지 않습니다.
2.2 서비스 이용 정보
- 방 정보: 방 이름, 설명, 과목, 공개 여부, 표지 이미지, 생성자, 구성원, 역할, 가입·초대 정보
- 메시지 및 학습 콘텐츠: 메시지, 질문, 풀이, 답글, 공지, 일정, 사진·첨부파일, 채택·좋아요·고정·읽음 상태
- 학습 기록: 객관식 선택과 정오 기록, 저장한 문제·풀이의 스냅샷, 개인 메모, 오답 기록
- AI 기능 정보: AI에 입력한 질문·이미지, 최근 대화 맥락, AI 답변, 방 지식 요약·임베딩, AI 사용량, AI 답변 신고 시 신고된 답변의 스냅샷
- 안전 및 운영 정보: 신고 내용, 신고 대상, 차단 관계, 문의 내용, 운영 조치 내역
- 공유 기능 정보: 공유 링크 식별자, 생성자, 생성·만료·회수 시각, 공유 대상 질문
저장한 문제·풀이의 스냅샷에는 다른 이용자가 작성한 질문·풀이와 이미지가 복제될 수 있으며, 원본이 수정되거나 삭제되어도 저장한 이용자가 직접 저장본을 삭제하거나 계정을 탈퇴해 저장본이 삭제되기 전까지 별도로 유지될 수 있습니다.
2.3 구독 및 결제 정보
- 앱 사용자 식별자
- 이용 스토어, 상품 식별자, 구독 상태, 만료일
- 구매·복원·갱신·취소 이벤트 및 영수증 검증 결과
결제수단과 카드번호는 Apple App Store 또는 Google Play가 처리하며, 회사는 전체 카드번호를 수집하거나 보관하지 않습니다.
2.4 자동으로 생성·수집되는 정보
- 기기·앱 정보: 기기 유형, 운영체제, 앱 버전, 언어, 플랫폼
- 인증·보안 정보: IP 주소, 접속 일시, 세션·설치 식별자, 오류 및 보안 로그
- 서비스 이용 이벤트: 가입·로그인 방식, 방 생성, 질문 생성, 풀이 채택, 구매 화면 조회, 구독 성공, 공유 링크 생성 등의 이벤트
- 장애 진단 정보: 충돌 시각, 스택 트레이스, 앱 상태 및 기술 진단정보
- 푸시 정보: 기기 푸시 토큰, 플랫폼, 알림 설정 및 갱신 시각
- 공개 공유 페이지 접속 시 일반적인 웹 요청 정보
Firebase Analytics 이벤트에는 메시지 본문, 질문·풀이 내용 또는 표시 이름을 의도적으로 포함하지 않습니다. Android에서는 광고 식별자 수집을 비활성화하며, 회사는 맞춤형 광고나 앱 간 추적 목적으로 개인정보를 이용하지 않습니다.
앱이 글꼴을 실행 중 Google Fonts에서 불러오는 경우 Google에 IP 주소와 일반적인 네트워크 요청 정보가 전달될 수 있습니다.
2.5 기기 권한
- 카메라: 문제·풀이 사진을 촬영할 때만 사용
- 사진 보관함: 이용자가 선택한 사진을 첨부할 때만 사용
- 알림: 메시지와 풀이 알림을 전송할 때 사용
권한을 거부해도 해당 권한이 필요하지 않은 기능은 이용할 수 있습니다. 회사는 연락처, 정확한 위치 또는 마이크 정보를 서비스 기능상 요구하지 않습니다.
3. 처리 목적 및 법적 근거
회사는 다음 목적으로 개인정보를 처리합니다.
| 목적 | 주요 정보 | 처리 근거 |
|---|---|---|
| 회원 가입, 인증, 계정 보호 | 이메일, 소셜 계정 식별자, 인증정보, 생년월일 | 서비스 계약의 체결·이행, 법적 의무 |
| 프로필·방·메시지·학습 기능 제공 | 프로필, 방 정보, 메시지, 첨부파일, 학습 기록 | 서비스 계약의 이행 |
| AI 답변·OCR·방 지식 기능 제공 | 질문, 풀이, 이미지, 대화 맥락, 지식 요약 | 별도 동의 및 기능 제공에 관한 계약 이행 |
| 구독 구매·검증·복원 | 상품·거래·구독 정보 | 계약 이행, 전자상거래 관련 법적 의무 |
| 푸시 알림 | 푸시 토큰, 방 이름, 발신자 표시 이름, 메시지 미리보기 | 이용자의 알림 허용, 서비스 제공 |
| 오류 분석·품질 개선 | 앱 이벤트, 기기·오류·진단정보 | 서비스 안정성과 보안을 위한 정당한 이익 |
| 신고·차단·분쟁 처리 | 신고, 차단, 관련 콘텐츠 및 운영 기록 | 이용자 보호, 법적 의무, 정당한 이익 |
| 법령 준수와 권리 보호 | 거래·접속·분쟁 관련 기록 | 법적 의무 및 법적 청구의 제기·방어 |
시행일 현재 서비스는 대한민국, 미국 및 일본에서 제공됩니다. 회사는 각 국가에서 적용되는 법적 근거와 요건에 따라 개인정보를 처리합니다. 동의가 처리 근거인 경우 이용자는 동의를 철회할 수 있으며, 철회는 그 전에 이루어진 적법한 처리의 효력에 영향을 주지 않습니다.
4. 서비스 안에서 공개되거나 다른 이용자에게 표시되는 정보
4.1 공개 프로필
사용자 핸들, 표시 이름 및 프로필 사진은 로그인한 다른 이용자가 발신자를 식별하고 상호작용할 수 있도록 공개 프로필로 표시될 수 있습니다. 생년월일, 이메일 주소, 자기소개 및 AI 동의 기록은 공개 프로필에 포함하지 않습니다.
4.2 방과 대화
- 비공개방의 대화와 첨부파일은 원칙적으로 해당 방 구성원만 볼 수 있습니다.
- 공개방의 이름, 설명, 과목, 구성원 수, 질문 수 등은 로그인한 이용자의 탐색 화면에 표시됩니다.
- 공개방에 직접 입장한 이용자는 그 방의 대화와 첨부파일을 볼 수 있습니다.
- 방에서 작성한 메시지와 풀이에는 표시 이름과 프로필 사진이 함께 표시될 수 있습니다.
이용자는 방의 공개 여부와 참가자를 확인하고, 민감정보나 타인의 개인정보를 게시하지 않아야 합니다.
4.3 공개 공유 링크
질문 작성자 또는 권한 있는 방 관리자가 공유 링크를 만들면, 인증하지 않은 사람도 링크를 통해 다음 내용을 볼 수 있습니다.
- 방 이름
- 질문 본문의 최대 200자
- 현재 채택된 풀이 본문의 최대 200자
공유 페이지에는 프로필 이름, 프로필 사진, 첨부 이미지 또는 방 초대코드를 표시하지 않습니다. 링크는 생성 후 30일 이내 만료되며 권한 있는 이용자가 그 전에 회수할 수 있습니다. 다만 회수 상태가 공개 페이지 캐시에 반영되기까지 최대 약 5분이 걸릴 수 있고, 메신저·검색엔진·소셜 플랫폼이 이미 만든 미리보기는 해당 외부 서비스의 정책에 따라 더 오래 남을 수 있습니다.
회사는 건강정보 등 민감정보의 입력을 요구하지 않습니다. 이용자가 민감정보를 공개방이나 공개 공유 대상 콘텐츠에 직접 포함하면 다른 사람에게 공개될 수 있습니다. 공개를 원하지 않는 이용자는 비공개방을 이용하고 공유 링크를 생성하지 않아야 하며, 이미 공개한 경우 게시물을 삭제하거나 공유 링크를 회수할 수 있습니다.
4.4 방 간 AI 지식 공유
양쪽 방의 관리자가 요청과 승인을 완료한 경우, 각 방의 채택 풀이 등을 바탕으로 생성된 지식 요약과 임베딩이 상대 방의 AI 답변 근거로 검색될 수 있습니다. 일반 이용자가 원문 전체를 직접 열람하는 기능은 아니지만, 요약 내용이 AI 답변에 반영될 수 있습니다. 관리자는 공유를 해제할 수 있습니다.
4.5 푸시 알림
푸시 알림에는 방 이름, 발신자의 표시 이름, 메시지 본문 최대 80자 또는 “사진” 표시가 포함될 수 있습니다. 기기 설정에 따라 잠금화면에 이 내용이 노출될 수 있으므로, 공용 기기를 사용하거나 알림 내용을 숨기려는 이용자는 앱 또는 운영체제의 알림 설정을 변경해야 합니다.
5. 개인정보의 보유 및 이용기간
회사는 처리 목적 달성 시 개인정보를 지체 없이 삭제하거나 익명화합니다. 다만 서비스 구조상 공동 콘텐츠로 유지되는 정보와 법령상 보존이 필요한 정보는 다음 기준에 따릅니다.
| 정보 | 보유기간 |
|---|---|
| 계정·인증·프로필 정보 | 회원 탈퇴 시까지 |
| 방 구성원·알림 설정·기기 토큰 | 탈퇴, 로그아웃, 방 탈퇴 또는 토큰 무효화 시까지 |
| 방 | 방이 삭제될 때까지 |
| 메시지·질문·풀이 | 방이 삭제될 때까지. 이용자의 개별 삭제 요청은 화면에서 즉시 숨기지만 원문은 아래 정책에 따라 방 삭제 또는 추가 삭제 처리 전까지 보관될 수 있음 |
| 사진·첨부파일 | 이용자가 삭제하거나 방이 삭제될 때까지 |
| 저장한 문제·풀이 스냅샷, 개인 메모, 오답 기록 | 이용자가 직접 삭제하거나 탈퇴할 때까지 |
| AI·OCR 국외이전 동의 기록 | 회원 탈퇴 시까지 |
| 객관식 시도 기록 | 탈퇴 또는 해당 방 삭제 시까지 |
| 방 AI 제안·지식 요약·임베딩 | 관련 메시지 또는 방이 삭제될 때까지 |
| 개인 AI 채팅 | 회사 데이터베이스에는 대화 전체를 저장하지 않음. 요청 시 최근 최대 6턴이 일시 처리되며, 신고 시 신고된 답변 스냅샷은 신고 기록으로 저장 |
| AI 사용량 기록 | 최대 30일 |
| 회사 OCR 캐시 | 최대 30일 |
| 공개 공유 페이지 | 생성 후 최대 30일 또는 회수 시까지. 링크 감사기록은 방 삭제 시까지 |
| Firebase Analytics 이용자·이벤트 데이터 | 14개월 |
| Firebase Crashlytics 진단정보 | 90일 |
| FCM 푸시 토큰 | 로그아웃·탈퇴·무효화 시까지. 삭제 처리 후 공급자 백업에서 제거되기까지 최대 180일이 걸릴 수 있음 |
| 전송되지 않은 FCM 메시지 | 통상 최대 4주 |
| 신고·차단·안전조치 기록 | 처리 목적 달성 시까지. 분쟁 또는 법적 청구에 필요한 경우 처리 완료 후 최대 3년 |
| 계약·청약철회·대금결제·서비스 공급 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 5년 |
| 소비자 불만 또는 분쟁처리 기록 | 같은 법에 따라 3년 |
| 표시·광고 기록 | 같은 법에 따라 6개월 |
부정 이용, 보안 사고, 법적 청구, 수사기관의 적법한 요구 또는 다른 법령상 의무가 있는 경우 해당 사유가 해소될 때까지 필요한 범위에서 보관할 수 있습니다. 통계·서비스 개선 목적으로 개인을 식별할 수 없게 집계하거나 익명화한 정보는 개인정보에 해당하지 않는 범위에서 더 오래 이용할 수 있습니다.
5.1 메시지 삭제와 회원 탈퇴 시의 처리
유키는 그룹 학습방의 공동 대화 맥락을 유지하기 위해 다음과 같이 처리합니다.
- 개별 메시지의 “삭제”는 다른 이용자 화면에서 숨기는 소프트 삭제 방식이며, 메시지 본문은 방 삭제 또는 운영상 삭제 처리 전까지 데이터베이스에 남을 수 있습니다.
- 회원 탈퇴 시 인증 계정, 프로필, 방 구성원 관계, 개인 저장 항목과 업로드한 사진은 삭제 대상으로 처리합니다.
- 탈퇴자가 작성한 질문·풀이·일반 메시지의 텍스트와 그가 만든 방은 그룹 공동 기록을 유지하기 위해 삭제하지 않을 수 있습니다. 이 경우 발신자 계정 식별자를 제거하고 “탈퇴한 사용자”로 표시합니다.
- 탈퇴한 이용자가 방장이었던 경우 공동 방의 연속성을 위해 다른 구성원에게 관리 권한이 승계될 수 있습니다.
- 텍스트 본문 자체에 이름, 연락처 등 개인정보가 작성된 경우 계정 식별자를 제거해도 완전한 익명정보가 되지 않을 수 있습니다. 추가 삭제가 필요한 이용자는 개인정보 문의 이메일로 요청할 수 있습니다.
회원 탈퇴는 Apple App Store 또는 Google Play 구독을 자동으로 취소하지 않습니다. 이용자는 해당 스토어의 구독 관리 화면에서 별도로 구독을 취소해야 합니다.
6. 개인정보 처리업무 수탁자·외부 기술사업자·독립 제공자
6.1 개인정보 처리업무 수탁자와 외부 기술사업자
회사는 지시에 따라 개인정보를 처리하거나 서비스에 필요한 기술 기능을 제공하는 다음 사업자를 이용합니다.
| 사업자 | 처리업무 |
|---|---|
| Supabase, Inc. | 회원 인증, 데이터베이스, 파일 저장, 실시간 동기화, 서버 함수 및 보안 로그 |
| Google LLC — Firebase 서비스 | Firebase Analytics, Crashlytics 및 Cloud Messaging |
| OpenAI, L.L.C. | AI 답변 생성, 임베딩 생성 및 이미지 이해 |
| Mathpix, Inc. | 문제 이미지의 문자·수식 인식 |
| RevenueCat, Inc. | 인앱 구독 상태 확인, 구매 검증·복원 및 권한 관리 |
회사는 적용되는 계약과 공급자 설정을 통해 처리 목적 외 이용 제한, 접근 통제, 기술적·관리적 보호조치 및 삭제·반환 의무를 관리합니다. 공급자는 적용 법률과 공개된 정책이 허용하는 범위에서 보안, 법적 의무 또는 서비스 무결성을 위해 제한된 정보를 별도로 처리할 수 있습니다.
현재 Mathpix의 품질개선 제외 설정이 적용되지 않아 Mathpix는 자체 정책에 따라 보관된 입력 이미지를 품질 검토 또는 인식 품질 개선에 이용할 수 있습니다.
Mathpix는 회사의 지시에 따른 OCR 처리 범위에서는 수탁자로 처리됩니다. 다만 보관된 입력 이미지를 자체 품질 검토 또는 인식 품질 개선에 이용하는 범위에서는 처리 목적과 방법을 독립적으로 결정할 수 있으며, 그 범위는 제7조와 제8조의 적용 대상으로 취급합니다.
6.2 독립된 플랫폼·계정 제공자
이용자가 각 사업자의 계정, 로그인, 결제, 스토어 또는 네트워크 서비스를 직접 이용하는 경우 다음 사업자는 자체 약관과 개인정보처리방침에 따라 일부 처리의 목적과 방법을 독립적으로 결정할 수 있습니다.
| 사업자 | 독립적으로 제공하는 서비스 |
|---|---|
| Apple Inc. | Apple 로그인, App Store 결제·구독 처리 |
| Google LLC | Google 로그인, Google Play 결제·구독 처리 및 Google Fonts 네트워크 제공 |
| Kakao Corp. | Kakao 로그인 |
Google LLC는 앱 운영을 위한 Firebase 서비스와 자체 플랫폼 약관이 적용되는 Google 로그인·Google Play·일부 Google Fonts 처리를 각각 제공하므로 두 역할에 모두 해당합니다. 구체적인 역할은 이용하는 서비스와 처리 활동에 따라 달라집니다.
7. 개인정보의 국외 이전
서비스의 핵심 인프라와 일부 기능은 국외 사업자가 처리합니다. 개인정보는 기능 이용 또는 서비스 운영 시 암호화된 네트워크를 통해 이전됩니다.
| 이전받는 자·문의처 | 국가·처리 위치 | 이전 항목 | 목적 | 이전 시점·방법 | 보유기간 |
|---|---|---|---|---|---|
| Supabase, Inc. | 일본 도쿄 리전, 운영·지원 과정에서 미국 등 공급자 처리 국가 | 계정, 프로필, 방, 메시지, 첨부파일, 학습·AI·신고·구독 상태 정보 | 인증, 데이터·파일 저장, 실시간 기능, 서버 처리 | 가입 및 서비스 이용 시 TLS 전송 | 본 방침의 항목별 보유기간 및 공급자 백업 주기 |
| Google LLC — Firebase | 미국 및 Google의 글로벌 처리시설 | 설치·기기 식별자, 이용 이벤트, 오류 진단정보, 푸시 토큰, 방 이름·표시 이름·메시지 미리보기 | 분석, 장애 진단 및 푸시 전송 | 앱 이벤트·오류·알림 발생 시 암호화 전송 | Analytics 14개월, Crashlytics 90일, 미전송 푸시 최대 4주, 토큰은 삭제 처리 시까지 및 백업 제거 최대 180일 |
| OpenAI, L.L.C. | 미국 | AI 입력 질문·풀이·요약·최근 대화 맥락, 첨부 이미지, 생성 요청에 필요한 기술정보 | AI 답변, 임베딩, 이미지 이해 | 이용자가 AI 기능을 요청할 때 TLS 전송 | API 오남용 모니터링 로그에 최대 30일. 회사는 별도의 Zero Data Retention 승인을 적용받고 있지 않음 |
| Mathpix, Inc. | 미국 | 이용자가 OCR을 요청한 문제 이미지와 인식 결과 | 문자·수식 인식 | 이용자가 OCR 기능을 요청할 때 TLS 전송 | 현재 품질개선 제외 설정이 적용되지 않아 입력 이미지는 최대 90일, OCR 결과 캐시는 최대 30일 보관될 수 있음 |
| RevenueCat, Inc. | 미국 | 앱 사용자 식별자, 상품·구독·구매·권한 정보 | 구독 구매 검증, 복원 및 권한 관리 | 앱 시작, 로그인, 구매·갱신·복원 시 암호화 전송 | 고객 기록 삭제 요청 및 계약·법정 보존기간까지. 공급자는 필요한 법적 의무·분쟁 기록을 별도 보유할 수 있음 |
| Apple Inc. | 미국 등 Apple 처리 국가 | Apple 계정 식별자, 로그인 토큰, 상품·구독·거래 정보 | Apple 로그인, App Store 결제·구독 | 로그인·구매·복원 시 암호화 전송 | Apple 정책과 법정 보존기간 |
| Google LLC — Google 로그인·Google Play·Google Fonts | 미국 및 Google의 글로벌 처리시설 | Google 계정 식별자·인증 토큰, 상품·구독·거래 정보, IP 주소·일반적인 글꼴 요청 정보 | Google 로그인, Google Play 결제·구독 및 글꼴 제공 | 로그인·구매·복원·글꼴 요청 시 암호화 전송 | Google의 공개된 보유기간 및 적용되는 법정 보존기간 |
| Kakao Corp. | 대한민국 및 Kakao가 고지한 처리 위치 | Kakao 계정 식별자, 이메일, 인증 토큰 | Kakao 로그인 | 로그인 시 암호화 전송 | 연동 해제 또는 계정 삭제 시까지 및 Kakao 정책상 기간 |
OpenAI API에 전송된 데이터는 기본적으로 OpenAI 모델 학습에 사용되지 않지만, 회사는 특별 승인이 필요한 Zero Data Retention 설정을 적용받고 있지 않아 오남용 방지 로그가 최대 30일 보관될 수 있습니다.
Mathpix에는 현재 `improve_mathpix: false` 설정이 적용되지 않아 입력 이미지가 품질 검토 또는 인식 품질 개선에 이용될 수 있습니다.
이용자는 AI·OCR 국외이전에 동의하지 않거나 기존 동의를 철회할 수 있습니다. 이 경우 AI 답변, 임베딩 및 이미지 OCR 기능은 이용할 수 없지만 기본 메시지·방·Q&A 기능은 계속 이용할 수 있습니다. 핵심 인증·데이터 저장에 필요한 국외 이전을 거부하는 경우 서비스 제공이 어려울 수 있으며, 이용자는 회원 탈퇴를 요청할 수 있습니다.
8. 제3자 제공과 독립된 외부 서비스
회사는 원칙적으로 이용자의 개인정보를 판매하지 않으며, 맞춤형 광고나 교차 맥락 행동광고 목적으로 공유하지 않습니다.
다만 다음 경우 필요한 범위에서 정보를 제공하거나 공개할 수 있습니다.
- 이용자가 공개방에 참여하거나 공개 공유 링크를 만든 경우
- 이용자가 다른 방 구성원과 메시지·프로필·학습 콘텐츠를 공유한 경우
- 이용자가 양쪽 관리자 승인에 따른 방 간 AI 지식 공유에 참여한 경우
- 이용자가 Apple·Google·Kakao 로그인 또는 스토어 결제를 선택한 경우
- 법령, 법원 명령 또는 권한 있는 기관의 적법한 요구가 있는 경우
- 생명·신체의 급박한 위험, 아동 성착취물 등 중대한 안전사고를 방지하기 위해 필요한 경우
- 회사의 합병·영업양도 등이 이루어지고 법령상 절차와 이용자 보호조치가 적용되는 경우
Apple, Google, Kakao 및 앱스토어는 일부 처리에 관해 독립된 개인정보처리자로서 각자의 개인정보처리방침을 적용할 수 있습니다.
현재 Mathpix의 품질개선 제외 설정이 적용되지 않은 상태에서 OCR을 이용하면 다음과 같은 별도 처리가 발생할 수 있습니다.
| 제공받는 자 | 제공 항목 | 별도 처리 목적 | 보유기간 | 거부 시 영향 |
|---|---|---|---|---|
| Mathpix, Inc. | OCR을 요청한 문제 이미지와 인식 결과 | 품질 검토 및 문자·수식 인식 품질 개선 | 입력 이미지 최대 90일, OCR 결과 캐시 최대 30일 | OCR 기능 이용 불가, 기본 메시지·방·Q&A 기능은 이용 가능 |
9. AI 기능에 관한 특별 고지
- AI 답변은 OpenAI 모델을 사용하며 부정확하거나 부적절한 내용을 생성할 수 있습니다.
- AI 기능은 질문·풀이·채택된 지식, 공개 지식 및 최근 대화 맥락을 처리할 수 있습니다.
- 개인 AI 채팅 답변은 회사 데이터베이스에 일반 대화 기록으로 저장하지 않지만, 오류 로그 또는 OpenAI의 오남용 모니터링 로그에 제한적으로 남을 수 있습니다.
- AI 답변을 신고하면 신고 시점의 답변 원문, 신고 사유와 관련 정보가 운영 검토를 위해 저장됩니다.
- 의료·법률·재정·안전 등 중대한 결정을 AI 답변에만 의존해서는 안 됩니다.
- 이용자는 AI 입력에 주민등록번호, 금융정보, 건강정보, 타인의 개인정보 등 민감한 정보를 입력하지 않아야 합니다.
10. 아동과 미성년자
대한민국 및 미국에서는 만 14세 미만, 일본에서는 만 16세 미만인 사람에게 서비스를 제공하지 않습니다. 회사는 최소 이용 연령 미만인 사람을 위한 법정대리인 동의 가입 절차를 제공하지 않습니다. 회사가 최소 이용 연령 미만 이용자의 가입을 확인하면 즉시 서비스 이용을 제한하고, 법령상 보존 의무가 있는 경우를 제외하고 해당 계정과 개인정보를 지체 없이 파기합니다.
일본의 만 18세 미만 이용자가 유료계약을 체결하려면 법정대리인의 동의를 받아야 합니다. 이용자의 거주 국가에서 더 높은 연령이나 추가 동의 요건을 정한 경우 해당 요건이 우선합니다. 회사는 지역별 법적 요건을 충족하기 어려운 국가 또는 연령대에 서비스 제공을 제한할 수 있습니다.
보호자는 아동의 개인정보가 부적절하게 처리되고 있다고 판단하면 개인정보 문의 이메일로 삭제 또는 이용 제한을 요청할 수 있습니다.
11. 개인정보의 파기
회사는 보유기간이 끝나거나 처리 목적이 달성된 개인정보를 지체 없이 파기합니다.
- 전자적 파일: 복구 또는 재생되지 않도록 영구 삭제
- 데이터베이스 기록: 복구 또는 재생되지 않도록 삭제하거나, 다른 정보와 합리적으로 결합하더라도 특정 개인을 알아볼 수 없도록 익명 처리
- 법령에 따라 보존하는 정보: 다른 개인정보와 분리하여 법정기간 동안 보관한 후 파기
- 종이 문서: 분쇄 또는 소각
백업본과 공급자 시스템에는 장애 복구와 보안 목적의 정기 백업 주기 동안 정보가 제한적으로 남을 수 있으며, 해당 기간에는 일반 서비스 이용에 복원하거나 다른 목적으로 사용하지 않습니다. 공개 공유 링크나 푸시 미리보기를 외부 플랫폼이 자체적으로 저장한 경우 회사가 해당 외부 복사본을 직접 삭제할 수 없습니다.
12. 이용자의 권리와 행사 방법
이용자는 적용되는 법률이 허용하는 범위에서 다음 권리를 행사할 수 있습니다.
- 개인정보 처리 여부와 보유 정보의 확인·열람
- 부정확한 정보의 정정
- 개인정보 삭제와 계정 삭제
- 처리 정지, 제한 또는 반대
- 동의 철회
- 제공한 정보의 사본 또는 이동 가능한 형태로의 제공
- 자동화된 처리에 관한 설명 또는 재검토 요청
- 감독기관에 민원 제기
프로필 정보는 앱 설정에서 수정할 수 있으며, 계정은 앱의 회원 탈퇴 기능으로 삭제할 수 있습니다. 그 밖의 요청은 popolabs0511@gmail.com으로 보낼 수 있습니다. 회사는 본인 확인 후 적용 법령의 기간과 절차에 따라 처리합니다.
이용자는 법정대리인 또는 적법하게 위임받은 사람을 통해 권리를 행사할 수 있으며, 회사는 권리 보호를 위해 본인과 대리인의 신원 및 대리권을 확인할 수 있습니다.
다른 사람의 권리, 법적 의무, 서비스 보안, 분쟁 대응 또는 표현의 자유를 보호하기 위해 일부 요청이 제한될 수 있습니다. 공동 방 메시지를 계정 식별정보와 분리하여 보존하는 방식과 개별 메시지 소프트 삭제는 제5조의 기준을 따릅니다.
대한민국 이용자는 「개인정보 보호법」에 따른 권리를 행사할 수 있습니다. 미국 이용자는 적용되는 연방·주 법률에 따라 개인정보의 열람·정정·삭제 및 판매·공유에 관한 권리를 행사할 수 있습니다. 회사는 개인정보를 판매하거나 교차 맥락 행동광고 목적으로 공유하지 않습니다. 일본 이용자는 일본 개인정보보호법에 따라 보유개인정보의 공개·정정·이용정지 등을 요청할 수 있습니다.
13. 개인정보 보호조치
회사는 개인정보 보호를 위해 다음 조치를 적용합니다.
- 전송 구간 TLS 암호화
- 데이터베이스 행 단위 접근통제(RLS)와 방 구성원 권한 확인
- 관리자 권한과 서버 비밀키의 앱 외부 보관
- 인증 토큰과 세션의 접근 제한
- 비공개방, 공개방, 공개 공유 페이지의 접근 경로 분리
- AI·OCR 요청 전 회원·방 권한 및 동의 여부의 서버 검증
- 사용량 제한, 비정상 요청 차단 및 보안 로그
- 신고·차단 기능과 운영 검토 절차
- 개발·운영 접근권한 최소화 및 공급자 보안조치 점검
인터넷 전송과 전자적 저장의 절대적인 안전을 보장할 수는 없습니다. 개인정보 침해가 확인되면 회사는 적용 법령에 따라 이용자와 관계기관에 통지하고 피해 최소화 조치를 시행합니다.
14. 자동 수집 기술과 추적 거부
서비스는 인증 세션, 설치 식별자, Firebase SDK, 푸시 토큰 및 일반적인 서버 로그를 사용합니다. 이는 로그인 유지, 서비스 안정화, 이용 흐름 분석과 알림 제공을 위한 것입니다.
회사는 제3자 광고 SDK를 사용하지 않고, 개인정보를 광고 사업자에게 판매하지 않으며, 맞춤형 광고를 위한 앱 간 추적을 하지 않습니다.
서비스는 서로 관계없는 웹사이트나 앱에 걸쳐 맞춤형 광고를 위한 추적을 하지 않으므로 현재 브라우저의 `Do Not Track` 신호에 따라 별도의 동작을 수행하지 않습니다. 법률상 인정되는 옵트아웃 신호가 회사에 적용되는 경우에는 해당 법률에 따라 처리합니다. 제6조부터 제8조까지의 독립된 외부 서비스는 각자의 정책에 따라 표준 기술정보를 수집할 수 있습니다.
이용자는 다음 방법으로 일부 처리를 제한할 수 있습니다.
- 앱 또는 운영체제 설정에서 푸시 알림 끄기
- 카메라·사진 권한 철회
- 앱 설정에서 AI 국외이전 동의 철회
- 소셜 로그인 제공자에서 유키 연결 해제
- 개인정보 문의 이메일로 분석정보 처리에 대한 이의 제기
기술적으로 필요한 인증 세션과 보안 로그를 차단하면 로그인이 필요한 기능이 정상 작동하지 않을 수 있습니다.
15. 개인정보 보호책임자와 문의
- 개인정보 보호책임자: 김도현 대표
- 개인정보·법률 문의: popolabs0511@gmail.com
- 일반 서비스 문의: contact@popolabs.app
개인정보 침해에 관한 상담이 필요한 경우 대한민국 개인정보보호위원회, 개인정보침해신고센터 등 관할 기관에 문의할 수 있습니다.
16. 국가별 적용과 서비스 제공 범위
시행일 현재 서비스 제공 대상 국가는 대한민국, 미국 및 일본입니다. 이용자의 거주지에 강행되는 개인정보 보호법이 이 방침보다 우선하는 경우 해당 법률이 적용됩니다. 회사는 스토어 배포 설정과 법적·운영상 사유에 따라 다른 국가의 신규 가입이나 특정 기능 제공을 제한할 수 있으며, 출시국을 확대하기 전 해당 국가의 요건을 별도로 검토합니다.
17. 개인정보 처리방침의 변경
회사는 법령, 서비스 기능 또는 개인정보 처리 방식이 변경되면 이 방침을 개정할 수 있습니다. 중요한 변경은 시행 전에 앱, 웹페이지 또는 이메일 등 합리적인 방법으로 알립니다.
- 최초 시행일: 2026년 7월 18일
- 현재 버전: 1.0
일반 문의: contact@popolabs.app
개인정보·법률 문의: popolabs0511@gmail.com
시행일: 2026년 7월 18일
U-KEY Privacy Policy
Version 1.0 · Effective Date: July 18, 2026
1. Information About the Data Controller
- Legal name: popolabs (포포랩스)
- Representative: 김도현
- Business Registration No.: 105-33-51914
- Mail-Order Business Report No.: 제2026-강원속초-0079호
- Filing authority: Sokcho City Hall
- General inquiries: contact@popolabs.app
- Privacy and legal inquiries: popolabs0511@gmail.com
2. Personal Data We Process
The Company processes the following data only to the extent necessary to provide the Service.
2.1 Account and Profile Data
- Email registration: email address, encrypted authentication data, and authentication identifier
- Social login: account identifier, email address, authentication token, and profile data made available by Apple, Google, or Kakao
- Profile: user handle, display name, profile image, bio, date of birth, and the name assigned by the User to the AI assistant
- Consent records: whether and when the User consented to overseas transfer for AI and OCR features
The Company does not directly view or retain a User’s password in plain text.
2.2 Service Usage Data
- Room data: Room name, description, subject, public or private status, cover image, creator, members, roles, and join or invitation data
- Messages and learning content: messages, questions, solutions, replies, notices, schedules, photos and attachments, accepted-solution status, reactions, pins, and read status
- Learning records: multiple-choice selections and correctness records, saved question and solution snapshots, personal notes, and incorrect-answer records
- AI feature data: questions and images submitted to AI, recent conversation context, AI responses, Room knowledge summaries and embeddings, AI usage counts, and snapshots of reported AI responses
- Safety and operations data: report details, report targets, block relationships, inquiries, and moderation actions
- Sharing data: Share Link identifier, creator, creation, expiration and revocation times, and the question to which the link relates
A saved solution snapshot may include a copy of a question, solution, or image posted by another User. Because the snapshot is stored independently from the original content, it may remain in the saving User’s account even if the original content is later edited or deleted, until the saving User deletes the snapshot or closes the Account.
2.3 Subscription and Purchase Data
- App User identifier
- Store platform, product identifier, subscription status, and expiration date
- Purchase, restoration, renewal and cancellation events, and receipt-verification results
Payment methods and full card numbers are processed by the Apple App Store or Google Play. The Company does not collect or retain full card numbers.
2.4 Automatically Generated or Collected Data
- Device and app data: device type, operating system, app version, language, and platform
- Authentication and security data: IP address, access time, session or installation identifier, error logs, and security logs
- Service usage events: registration or login method, Room creation, question creation, solution acceptance, purchase-screen view, successful subscription, and Share Link creation
- Diagnostic data: crash time, stack trace, app state, and technical diagnostic information
- Push data: device push token, platform, notification settings, and token update time
- Standard web-request data generated when a public sharing page is accessed
Firebase Analytics events are not intentionally configured to include message bodies, question or solution content, or display names. Collection of the Android advertising identifier is disabled, and the Company does not use personal data for personalized advertising or cross-app tracking.
If the app retrieves fonts from Google Fonts at runtime, Google may receive the User’s IP address and standard network-request information.
2.5 Device Permissions
- Camera: used only when the User takes a photo of a question or solution
- Photo library: used only when the User selects a photo to attach
- Notifications: used to deliver message and solution notifications
If a User denies a permission, features that do not require that permission remain available. The Service does not require access to contacts, precise location, or the microphone.
3. Purposes and Legal Bases for Processing
The Company processes personal data for the following purposes.
| Purpose | Main Data | Legal Basis |
|---|---|---|
| Registration, authentication, and Account security | Email, social-account identifier, authentication data, date of birth | Entering into and performing the service agreement; legal obligations |
| Profile, Room, messaging, and learning features | Profile, Room data, messages, attachments, learning records | Performance of the service agreement |
| AI responses, OCR, and Room knowledge features | Questions, solutions, images, conversation context, knowledge summaries | Separate consent; performance of the agreement for the requested feature |
| Subscription purchase, verification, and restoration | Product, transaction, and subscription data | Performance of a contract; e-commerce legal obligations |
| Push notifications | Push token, Room name, sender display name, message preview | User’s notification authorization; provision of the Service |
| Error analysis and quality improvement | App events, device, error, and diagnostic data | Legitimate interests in Service reliability and security |
| Reports, blocks, and dispute handling | Reports, blocks, related content, and moderation records | User safety; legal obligations; legitimate interests |
| Legal compliance and protection of rights | Transaction, access, and dispute records | Legal obligations; establishment, exercise, or defense of legal claims |
As of the Effective Date, the Service is offered in the Republic of Korea, the United States, and Japan. The Company processes personal data in accordance with the legal bases and requirements applicable in each country. Where processing is based on consent, consent may be withdrawn without affecting processing lawfully carried out before withdrawal.
4. Data Made Visible Within the Service or to Other Users
4.1 Public Profiles
A User’s handle, display name, and profile image may be shown as public profile fields to signed-in Users so that they can identify and interact with the sender. Date of birth, email address, bio, and AI-consent records are not included in the public profile.
4.2 Rooms and Conversations
- Conversations and attachments in private Rooms are generally visible only to members of that Room.
- The name, description, subject, member count, and question count of a public Room may be displayed in the discovery screen to signed-in Users.
- A User who directly joins a public Room may view conversations and attachments in that Room.
- Messages and solutions may be displayed with the author’s display name and profile image.
Users should check whether a Room is public or private and who its members are, and should not post sensitive data or another person’s personal data without a lawful basis.
4.3 Public Share Links
When a question author or an authorized Room administrator creates a Share Link, anyone who receives the link may access the following without authentication:
- Room name
- Up to 200 characters of the question
- Up to 200 characters of the currently accepted solution
The public page does not display profile names, profile images, attached images, or Room invitation codes. A link expires within 30 days after creation and may be revoked earlier by an authorized User. It may take up to approximately five minutes for revocation to be reflected in the public-page cache. Preview copies already generated by messaging, search, or social platforms may remain longer under the policies of those external services.
The Company does not ask Users to post health data or other sensitive personal data. If a User directly includes sensitive data in a Public Room or content selected for a public Share Link, it may become visible to other people. A User who does not want that information disclosed should use a Private Room and should not create a Share Link, and may delete the post or revoke the Share Link after publication.
4.4 Cross-Room AI Knowledge Sharing
If administrators of both Rooms complete the request and approval process, knowledge summaries and embeddings generated from accepted solutions and other eligible content in each Room may be searched as supporting context for AI responses in the other Room. Users do not receive direct access to the full original content solely through this feature, but information from a summary may be reflected in an AI response. An administrator may terminate the sharing arrangement.
4.5 Push Notifications
A push notification may include the Room name, sender’s display name, and up to 80 characters of a message, or an indication that the message contains a photo. Depending on device settings, this information may appear on the lock screen. Users who share a device or wish to hide notification content should adjust notification settings in the app or operating system.
5. Retention Periods
The Company deletes or de-identifies personal data without undue delay when the processing purpose has been fulfilled. Shared content and data subject to legal retention requirements are handled as follows.
| Data | Retention Period |
|---|---|
| Account, authentication, and profile data | Until Account closure |
| Room membership, notification settings, and device tokens | Until Account closure, logout, leaving the Room, or token invalidation |
| Rooms | Until the Room is deleted |
| Messages, questions, and solutions | Until the Room is deleted. A User’s individual deletion action hides the content immediately, but the original may remain until Room deletion or additional deletion processing under the rules below |
| Photos and attachments | Until deleted by the User or the Room is deleted |
| Saved question and solution snapshots, personal notes, and incorrect-answer records | Until deleted by the User or the Account is closed |
| AI and OCR overseas-transfer consent records | Until the Account is closed |
| Multiple-choice attempt records | Until the Account or relevant Room is deleted |
| Room AI suggestions, knowledge summaries, and embeddings | Until the related message or Room is deleted |
| Personal AI chat | The full conversation is not stored in the Company database. Up to the six most recent turns are processed temporarily for a request. If a response is reported, a snapshot of that response is stored as part of the report |
| AI usage records | Up to 30 days |
| Company OCR cache | Up to 30 days |
| Public sharing page | Up to 30 days after creation or until revocation; link audit records remain until the Room is deleted |
| Firebase Analytics User and event data | 14 months |
| Firebase Crashlytics diagnostic data | 90 days |
| FCM push token | Until logout, Account closure, or invalidation; removal from provider backups may take up to 180 days after deletion processing |
| Undelivered FCM message | Generally up to four weeks |
| Report, block, and safety-action records | Until the processing purpose is fulfilled; up to three years after completion where needed for a dispute or legal claim |
| Records of contracts, withdrawal from purchase, payment, and supply of the Service | Five years under the Act on the Consumer Protection in Electronic Commerce |
| Records of consumer complaints or dispute resolution | Three years under the same Act |
| Records of labeling and advertising | Six months under the same Act |
Where necessary to address fraud, a security incident, a legal claim, a lawful request from an authority, or another statutory obligation, relevant data may be retained until that reason ends. Aggregated or anonymized data that no longer identifies an individual may be used for statistics and Service improvement for a longer period.
5.1 Message Deletion and Account Closure
U-KEY handles shared group-learning records as follows.
- Deleting an individual message is a soft-delete action that hides the message from other Users. The underlying message body may remain in the database until the Room is deleted or an operational deletion is completed.
- When an Account is closed, the authentication Account, profile, Room-membership relationships, private saved items, and uploaded photos are designated for deletion.
- Text in questions, solutions, and ordinary messages created by the departing User, as well as Rooms created by that User, may remain to preserve the shared group record. The Account identifier is removed and the author is shown as a “Deleted user.”
- If the departing User was a Room owner, administrative control may be transferred to another member to preserve continuity of the shared Room.
- If a message body itself contains a name, contact detail, or other personal data, removing the Account identifier may not make the text fully anonymous. A User may request additional deletion through the privacy contact email where necessary.
Closing a U-KEY Account does not automatically cancel an Apple App Store or Google Play subscription. The User must cancel the subscription separately through the relevant store’s subscription settings.
6. Processors, Technical Service Providers, and Independent Providers
6.1 Processors and Technical Service Providers
The Company uses the following providers to process data on its instructions or to provide technical functions necessary for the Service.
| Provider | Role |
|---|---|
| Supabase, Inc. | Authentication, database, file storage, real-time synchronization, server functions, and security logs |
| Google LLC — Firebase services | Firebase Analytics, Crashlytics, and Cloud Messaging |
| OpenAI, L.L.C. | AI response generation, embedding generation, and image understanding |
| Mathpix, Inc. | Recognition of text and mathematical expressions in question images |
| RevenueCat, Inc. | In-app subscription status, purchase verification, restoration, and entitlement management |
The Company manages purpose limitations, access controls, security safeguards, and deletion or return obligations through provider agreements and Service configurations. A provider may separately process limited data for security, legal compliance, or Service integrity where permitted by applicable law and its published terms.
Because the current Mathpix quality-improvement opt-out is not enabled, Mathpix may process retained input images for quality review or recognition improvement as described in its own policy.
Mathpix acts as a processor for OCR performed on the Company’s instructions. To the extent it uses retained input images for its own quality review or recognition improvement, it may independently determine the purposes and means of that processing, which is addressed in Sections 7 and 8.
6.2 Independent Platform and Account Providers
The following providers may independently determine the purposes and means of some processing under their own terms and privacy policies because Users directly use their account, login, payment, store, or network services.
| Provider | Independently Provided Service |
|---|---|
| Apple Inc. | Sign in with Apple, App Store payment and subscription processing |
| Google LLC | Google Sign-In, Google Play payment and subscription processing, and Google Fonts network delivery |
| Kakao Corp. | Kakao Login |
Google LLC is listed in both subsections because Firebase services are used by the Company for app operations, while Google Sign-In, Google Play, and certain Google Fonts processing are provided under Google’s own platform terms. The applicable role depends on the specific service and processing activity.
7. International Transfers
The Service’s core infrastructure and certain features are operated by providers outside the User’s country. Data is transferred over encrypted network connections when the relevant feature is used or the Service is operated.
| Recipient and Contact | Country or Processing Location | Data Transferred | Purpose | Timing and Method | Retention |
|---|---|---|---|---|---|
| Supabase, Inc. | Tokyo region, Japan; the United States or other provider locations where required for operations and support | Account, profile, Room, message, attachment, learning, AI, report, and subscription-status data | Authentication, database and file storage, real-time functions, and server processing | TLS transfer upon registration and use of the Service | Retention periods in this Policy and provider backup cycles |
| Google LLC — Firebase | United States and Google’s global processing facilities | Installation and device identifiers, usage events, diagnostics, push token, Room name, display name, and message preview | Analytics, crash diagnostics, and push delivery | Encrypted transfer upon app events, crashes, and notifications | Analytics 14 months; Crashlytics 90 days; undelivered push up to four weeks; token until deletion processing and up to 180 days for backup removal |
| OpenAI, L.L.C. | United States | AI prompts, questions, solutions, summaries, recent conversation context, attached images, and necessary technical data | AI responses, embeddings, and image understanding | TLS transfer when the User invokes an AI feature | Up to 30 days in API abuse-monitoring logs; the Company has not received approval for Zero Data Retention |
| Mathpix, Inc. | United States | Question image submitted for OCR and recognition result | Text and mathematical-expression recognition | TLS transfer when the User invokes OCR | Because the quality-improvement opt-out is not enabled, input images may be retained for up to 90 days and OCR result caches for up to 30 days |
| RevenueCat, Inc. | United States | App User identifier, product, subscription, purchase, and entitlement data | Subscription verification, restoration, and entitlement management | Encrypted transfer upon app start, login, purchase, renewal, and restoration | Until customer-record deletion and the applicable contractual or statutory retention period; the provider may retain limited records for legal obligations and disputes |
| Apple Inc. | United States and other Apple processing locations | Apple Account identifier, login token, product, subscription, and transaction data | Apple login and App Store payment or subscription processing | Encrypted transfer upon login, purchase, or restoration | Apple’s published retention periods and applicable statutory periods |
| Google LLC — Google Sign-In, Google Play, and Google Fonts | United States and Google’s global processing facilities | Google Account identifier and authentication token; product, subscription, and transaction data; IP address and standard font-request data | Google login, Google Play payment or subscription processing, and font delivery | Encrypted transfer upon login, purchase, restoration, or font request | Google’s published retention periods and applicable statutory periods |
| Kakao Corp. | Republic of Korea and other locations disclosed by Kakao | Kakao Account identifier, email address, and authentication token | Kakao login | Encrypted transfer upon login | Until disconnection or Account closure, subject to Kakao’s published retention periods |
Data submitted through the OpenAI API is not used to train OpenAI models by default. However, because the Company has not been approved for the separate Zero Data Retention program, abuse-monitoring logs may be retained for up to 30 days.
Because the Mathpix `improve_mathpix: false` opt-out is not currently enabled, input images may be used for quality review or recognition improvement.
A User may refuse consent to, or withdraw prior consent for, overseas transfers related to AI and OCR. If consent is refused or withdrawn, AI responses, embeddings, and image OCR will not be available, but the basic messaging, Room, and Q&A functions remain available. If a User refuses an overseas transfer necessary for core authentication or data storage, the Company may be unable to provide the Service, and the User may close the Account.
8. Disclosures to Third Parties and External Services
The Company does not sell personal data and does not share it for personalized advertising or cross-context behavioral advertising.
Data may nevertheless be disclosed or made available to the extent necessary in the following circumstances:
- When a User joins a public Room or creates a public Share Link
- When a User shares a message, profile, or learning content with Room members
- When a User participates in cross-Room AI knowledge sharing approved by administrators of both Rooms
- When a User chooses Apple, Google, or Kakao login, or an app-store purchase
- When required by law, a court order, or a lawful request from a competent authority
- When necessary to address an imminent risk to life or physical safety, child sexual abuse material, or another serious safety incident
- In connection with a merger, business transfer, or similar transaction, subject to legally required procedures and safeguards
Apple, Google, Kakao, and the app stores may act as independent controllers for some processing and apply their own privacy policies.
When OCR is used while the Mathpix quality-improvement opt-out remains disabled, the following separate processing may occur.
| Recipient | Data | Separate Purpose | Retention | Effect of Refusal |
|---|---|---|---|---|
| Mathpix, Inc. | Question image submitted for OCR and recognition result | Quality review and improvement of text and mathematical-expression recognition | Input image up to 90 days; OCR result cache up to 30 days | OCR will be unavailable; basic messaging, Room, and Q&A functions remain available |
9. Special Notice Regarding AI Features
- AI responses are generated using OpenAI models and may be inaccurate or inappropriate.
- AI features may process questions, solutions, accepted knowledge, public knowledge, and recent conversation context.
- Personal AI chat responses are not stored as ordinary conversation records in the Company database, but limited data may remain in error logs or OpenAI abuse-monitoring logs.
- If a User reports an AI response, the response text, report reason, and related information are stored for moderation review.
- Users should not rely solely on AI responses for medical, legal, financial, safety, or other high-impact decisions.
- Users should not submit resident registration numbers, financial data, health data, another person’s personal data, or other sensitive information to an AI feature.
10. Children and Minors
U-KEY is not directed to children under 13. The Service is not offered to anyone under 14 in the Republic of Korea or the United States, or to anyone under 16 in Japan. The Company does not offer a parental-consent registration program for a person below the applicable minimum age. If the Company learns that such a person provided personal data, it will restrict the Account, stop further collection, and delete the Account and related personal data without undue delay, except where retention is legally required.
A User under 18 in Japan must obtain a legal guardian’s consent before entering into a paid contract. If the User’s country requires a higher minimum age or additional consent, that requirement prevails. The Company may restrict access or certain features in a region or age group where regional age-verification or guardian-consent requirements have not been implemented.
A parent or guardian may request deletion or restriction by contacting the privacy email address if the child’s data appears to have been processed improperly.
11. Deletion and Disposal
The Company deletes personal data without undue delay when the retention period ends or the processing purpose is fulfilled.
- Electronic files: permanently deleted so that they cannot be recovered or reproduced
- Database records: deleted so that they cannot be recovered or reproduced, or anonymized so that an individual cannot reasonably be identified even when combined with other information
- Information retained by law: separated from other personal data, retained for the statutory period, and then deleted
- Paper records: shredded or incinerated
Data may remain for a limited period in disaster-recovery backups and provider systems according to regular backup cycles. During that period, the data is not restored for ordinary use or used for a new purpose. The Company cannot directly delete preview copies of public Share Links or push content independently retained by an external platform.
12. User Rights and How to Exercise Them
Subject to applicable law, a User may have the following rights:
- Confirmation of processing and access to personal data
- Correction of inaccurate data
- Deletion of personal data and Account closure
- Restriction of or objection to processing
- Withdrawal of consent
- A copy of data provided by the User, or data portability
- Information about or review of automated processing
- A complaint to a competent supervisory authority
Profile data may be updated in the app, and the Account may be closed through the in-app Account-deletion feature. Other requests may be sent to popolabs0511@gmail.com. The Company will verify the requester’s identity and respond within the period and procedure required by applicable law.
A User may exercise rights through a legal guardian or duly authorized agent. The Company may verify the identity and authority of the User and agent to protect the User’s rights.
A request may be limited where necessary to protect another person’s rights, comply with a legal obligation, maintain Service security, respond to a dispute, or protect freedom of expression. Retention of shared-Room messages after separation from Account identifiers and soft deletion of individual messages are governed by Section 5.
Users in the Republic of Korea may exercise rights under the Personal Information Protection Act. U.S. Users may exercise rights concerning access, correction, deletion, sale, or sharing where provided by applicable federal or state law. The Company does not sell personal data or share it for cross-context behavioral advertising. Users in Japan may request disclosure, correction, suspension of use, or other measures concerning retained personal data under Japan’s Act on the Protection of Personal Information.
13. Security Measures
The Company applies the following safeguards:
- TLS encryption in transit
- Row-level security and Room-membership authorization checks
- Storage of administrative privileges and server secrets outside the app
- Restricted access to authentication tokens and sessions
- Separation of access paths for private Rooms, public Rooms, and public sharing pages
- Server-side verification of membership, Room authorization, and consent before AI or OCR requests
- Usage limits, abnormal-request controls, and security logging
- Reporting, blocking, and moderation-review mechanisms
- Least-privilege access for development and operations, and review of provider safeguards
No internet transmission or electronic storage method can guarantee absolute security. If the Company confirms a personal-data breach, it will notify affected Users and competent authorities and take mitigation measures as required by applicable law.
14. Automatic Collection Technologies and Choices
The Service uses authentication sessions, installation identifiers, Firebase SDKs, push tokens, and standard server logs for login continuity, Service stability, usage analysis, and notifications.
The Company does not use a third-party advertising SDK, sell personal data to advertising companies, or conduct cross-app tracking for personalized advertising.
U-KEY does not track Users across unaffiliated websites or services for targeted advertising and therefore does not currently take separate action in response to browser `Do Not Track` signals. If a legally recognized opt-out signal applies to the Company, it will be handled as required by that law. Independent providers described in Sections 6–8 may collect standard technical information under their own policies.
Users may limit certain processing by:
- Turning off push notifications in the app or operating-system settings
- Revoking camera or photo-library permission
- Withdrawing AI overseas-transfer consent in the app settings
- Disconnecting U-KEY through the relevant social-login provider
- Objecting to analytics processing by contacting the privacy email address
Blocking technically necessary authentication sessions or security logs may prevent login-required features from functioning properly.
15. Privacy Officer and Contact
- Privacy Officer: 김도현, Representative
- Privacy and legal inquiries: popolabs0511@gmail.com
- General Service inquiries: contact@popolabs.app
Users may also contact the Personal Information Protection Commission of the Republic of Korea, the Personal Information Infringement Report Center, or another competent authority regarding a privacy concern.
16. Regional Requirements and Availability
As of the Effective Date, the Service is offered in the Republic of Korea, the United States, and Japan. Mandatory privacy law in a User’s place of residence applies where it provides non-waivable protections. The Company may restrict new registration or certain features in another country through app-market distribution settings or for legal or operational reasons, and will review local requirements before expanding availability.
17. Changes to This Privacy Policy
The Company may amend this Privacy Policy when laws, Service features, or data-processing practices change. A material change will be announced before it takes effect through the app, a web page, email, or another reasonable method.
- Initial effective date: July 18, 2026
- Current version: 1.0
General inquiries: contact@popolabs.app
Privacy and legal inquiries: popolabs0511@gmail.com
Effective Date: July 18, 2026
U-KEY プライバシーポリシー(個人情報保護方針)
バージョン1.0 · 施行日:2026年7月18日
1. 個人情報取扱事業者に関する情報
- 商号:popolabs(포포랩스)
- 代表者:김도현
- 事業者登録番号:105-33-51914
- 通信販売業届出番号:제2026-강원속초-0079호
- 届出機関:束草市庁(속초시청)
- 一般お問い合わせ:contact@popolabs.app
- 個人情報・法務お問い合わせ:popolabs0511@gmail.com
日本の個人情報保護法第32条に基づき本人の知り得る状態に置くべき当社の住所その他の事項は、個人情報・法務お問い合わせ先に請求いただければ遅滞なく回答します。
2. 取り扱う個人情報
当社は、本サービスの提供に必要な範囲で、次の情報を取り扱います。
2.1 アカウントおよびプロフィール情報
- メールアドレスによる登録:メールアドレス、暗号化された認証情報、認証識別子
- ソーシャルログイン:Apple、GoogleまたはKakaoから提供されるアカウント識別子、メールアドレス、認証トークンおよび提供範囲内のプロフィール情報
- プロフィール:ユーザーハンドル、表示名、プロフィール画像、自己紹介、生年月日、利用者が設定したAIアシスタント名
- 同意記録:AI・OCR機能に関する国外移転への同意の有無および同意日時
当社は、利用者の平文パスワードを直接閲覧または保存しません。
2.2 本サービスの利用情報
- ルーム情報:ルーム名、説明、科目、公開・非公開の設定、カバー画像、作成者、メンバー、権限、参加・招待情報
- メッセージおよび学習コンテンツ:メッセージ、質問、解答・解説、返信、お知らせ、予定、写真・添付ファイル、採択状況、リアクション、固定、既読状況
- 学習記録:選択式問題の選択内容および正誤記録、保存した質問・解答のスナップショット、個人メモ、誤答記録
- AI機能情報:AIに入力した質問・画像、直近の会話履歴、AI回答、ルーム知識の要約・埋め込み、AI利用回数、AI回答を通報した場合の回答スナップショット
- 安全管理・運営情報:通報内容、通報対象、ブロック関係、お問い合わせ内容、運営上の措置記録
- 共有機能情報:共有リンク識別子、作成者、作成・有効期限・取消日時、共有対象となる質問
保存した解答・解説のスナップショットには、他の利用者が投稿した質問、解答・解説または画像のコピーが含まれる場合があります。スナップショットは元のコンテンツとは独立して保存されるため、元のコンテンツが後に編集または削除された場合でも、保存した利用者が当該スナップショットを削除するか退会するまで、その利用者のアカウントに残ることがあります。
2.3 サブスクリプションおよび決済情報
- アプリ利用者識別子
- 利用ストア、商品識別子、サブスクリプション状態、有効期限
- 購入、復元、更新、解約イベントおよびレシート検証結果
決済手段および完全なカード番号はApple App StoreまたはGoogle Playが処理します。当社は完全なカード番号を収集または保存しません。
2.4 自動的に生成・収集される情報
- 端末・アプリ情報:端末の種類、OS、アプリバージョン、言語、プラットフォーム
- 認証・セキュリティ情報:IPアドレス、アクセス日時、セッション・インストール識別子、エラーログ、セキュリティログ
- 本サービスの利用イベント:登録・ログイン方法、ルーム作成、質問作成、解答採択、購入画面表示、サブスクリプション完了、共有リンク作成
- 障害診断情報:クラッシュ日時、スタックトレース、アプリ状態、技術的診断情報
- プッシュ情報:端末のプッシュトークン、プラットフォーム、通知設定、更新日時
- 公開共有ページへのアクセス時に生成される一般的なウェブリクエスト情報
Firebase Analyticsのイベントには、メッセージ本文、質問・解答の内容または表示名を意図的に含めない設定としています。Androidの広告識別子の収集は無効化しており、当社は個人情報をパーソナライズ広告またはアプリ横断トラッキングの目的で利用しません。
アプリが実行時にGoogle Fontsからフォントを取得する場合、GoogleにIPアドレスおよび一般的なネットワークリクエスト情報が送信されることがあります。
2.5 端末権限
- カメラ:利用者が質問または解答・解説の写真を撮影する場合に限り使用
- 写真ライブラリ:利用者が添付する写真を選択する場合に限り使用
- 通知:メッセージおよび解答・解説に関する通知を配信するために使用
権限を拒否しても、その権限を必要としない機能は利用できます。本サービスは、連絡先、正確な位置情報またはマイクへのアクセスを必要としません。
3. 取扱目的および法的根拠
当社は、次の目的で個人情報を取り扱います。
| 目的 | 主な情報 | 法的根拠 |
|---|---|---|
| 会員登録、認証およびアカウント保護 | メールアドレス、ソーシャルアカウント識別子、認証情報、生年月日 | サービス契約の締結・履行、法的義務 |
| プロフィール、ルーム、メッセージおよび学習機能の提供 | プロフィール、ルーム情報、メッセージ、添付ファイル、学習記録 | サービス契約の履行 |
| AI回答、OCRおよびルーム知識機能の提供 | 質問、解答・解説、画像、会話履歴、知識要約 | 個別の同意、要求された機能に関する契約の履行 |
| サブスクリプションの購入、検証および復元 | 商品、取引、サブスクリプション情報 | 契約の履行、電子商取引に関する法的義務 |
| プッシュ通知 | プッシュトークン、ルーム名、送信者の表示名、メッセージプレビュー | 利用者による通知の許可、本サービスの提供 |
| エラー分析および品質改善 | アプリイベント、端末、エラー、診断情報 | 本サービスの安定性およびセキュリティに関する正当な利益 |
| 通報、ブロックおよび紛争対応 | 通報、ブロック、関連コンテンツ、運営記録 | 利用者保護、法的義務、正当な利益 |
| 法令遵守および権利保護 | 取引、アクセス、紛争関連記録 | 法的義務、法的請求の確立・行使・防御 |
施行日現在、本サービスの提供対象国は大韓民国、米国および日本です。当社は、各国で適用される法的根拠および要件に従って個人情報を取り扱います。同意を取扱いの根拠とする場合、利用者は同意を撤回できますが、撤回前に行われた適法な取扱いの効力には影響しません。
4. 本サービス内または他の利用者に表示される情報
4.1 公開プロフィール
利用者を識別し相互にやり取りできるよう、ユーザーハンドル、表示名およびプロフィール画像が、ログイン済みの他の利用者に公開プロフィール情報として表示される場合があります。生年月日、メールアドレス、自己紹介およびAI同意記録は公開プロフィールに含まれません。
4.2 ルームおよび会話
- 非公開ルームの会話と添付ファイルは、原則として当該ルームのメンバーのみが閲覧できます。
- 公開ルームの名称、説明、科目、メンバー数および質問数などは、ログイン済み利用者の検索・閲覧画面に表示されます。
- 公開ルームに直接参加した利用者は、そのルームの会話と添付ファイルを閲覧できます。
- メッセージおよび解答・解説には、投稿者の表示名とプロフィール画像が表示される場合があります。
利用者は、ルームの公開設定と参加者を確認し、適法な根拠なく機微な情報または他人の個人情報を投稿してはなりません。
4.3 公開共有リンク
質問の投稿者または権限を有するルーム管理者が共有リンクを作成した場合、リンクを受け取った者は認証なしで次の情報を閲覧できます。
- ルーム名
- 質問本文の最大200文字
- 現在採択されている解答・解説本文の最大200文字
公開ページには、プロフィール名、プロフィール画像、添付画像またはルーム招待コードを表示しません。リンクは作成後30日以内に期限切れとなり、権限を有する利用者はそれ以前に取り消すことができます。取消状態が公開ページのキャッシュに反映されるまで最大約5分を要する場合があります。また、メッセージングサービス、検索エンジンまたはソーシャルプラットフォームが既に生成したプレビューは、各外部サービスの方針に従ってより長く残る場合があります。
当社は、健康情報その他の要配慮個人情報の投稿を求めません。利用者が要配慮個人情報を公開ルームまたは公開共有の対象となるコンテンツに直接含めた場合、第三者に公開されることがあります。公開を望まない場合は非公開ルームを利用し、共有リンクを作成しないでください。公開後は、投稿を削除し、または共有リンクを取り消すことができます。
4.4 ルーム間AI知識共有
双方のルーム管理者が申請および承認を完了した場合、それぞれのルームで採択された解答・解説その他の対象コンテンツから生成された知識要約および埋め込みが、相手方ルームのAI回答の根拠として検索される場合があります。本機能のみを理由として利用者が元のコンテンツ全文を直接閲覧できるようになるものではありませんが、要約情報がAI回答に反映される場合があります。管理者は共有を解除できます。
4.5 プッシュ通知
プッシュ通知には、ルーム名、送信者の表示名、メッセージ本文の最大80文字、または写真が含まれている旨が表示される場合があります。端末の設定によっては、これらの情報がロック画面に表示されます。共用端末を利用する場合、または通知内容を非表示にしたい場合は、アプリまたはOSの通知設定を変更してください。
5. 保有期間
当社は、取扱目的を達成した個人情報を遅滞なく削除または個人を識別できない状態にします。ただし、共同コンテンツおよび法令上の保存義務がある情報は、次の基準に従って取り扱います。
| 情報 | 保有期間 |
|---|---|
| アカウント、認証およびプロフィール情報 | 退会時まで |
| ルームメンバー情報、通知設定および端末トークン | 退会、ログアウト、ルーム退出またはトークン無効化時まで |
| ルーム | ルームが削除されるまで |
| メッセージ、質問および解答・解説 | ルームが削除されるまで。利用者による個別削除は画面上直ちに非表示となるが、原文は下記方針に従い、ルーム削除または追加の削除処理まで残る場合がある |
| 写真および添付ファイル | 利用者による削除またはルーム削除時まで |
| 保存した質問・解答のスナップショット、個人メモおよび誤答記録 | 利用者による削除または退会時まで |
| AI・OCRに関する国外移転の同意記録 | 退会時まで |
| 選択式問題の回答履歴 | 退会または該当ルーム削除時まで |
| ルームAI提案、知識要約および埋め込み | 関連メッセージまたはルーム削除時まで |
| 個人AIチャット | 会話全体は当社データベースに保存しない。リクエスト処理時に直近最大6ターンを一時的に処理し、回答が通報された場合はその回答のスナップショットを通報記録として保存 |
| AI利用量記録 | 最大30日 |
| 当社のOCRキャッシュ | 最大30日 |
| 公開共有ページ | 作成後最大30日または取消時まで。リンク監査記録はルーム削除時まで |
| Firebase Analyticsの利用者・イベントデータ | 14か月 |
| Firebase Crashlyticsの診断情報 | 90日 |
| FCMプッシュトークン | ログアウト、退会または無効化時まで。削除処理後、提供者のバックアップからの除去に最大180日を要する場合がある |
| 未配信のFCMメッセージ | 通常最大4週間 |
| 通報、ブロックおよび安全措置記録 | 取扱目的の達成時まで。紛争または法的請求に必要な場合は処理完了後最大3年 |
| 契約、申込みの撤回、代金決済および役務提供に関する記録 | 大韓民国の電子商取引等における消費者保護に関する法律に基づき5年 |
| 消費者の苦情または紛争処理に関する記録 | 同法に基づき3年 |
| 表示・広告に関する記録 | 同法に基づき6か月 |
不正利用、セキュリティ事故、法的請求、権限を有する機関からの適法な要請その他の法定義務に対応するため必要な場合、当該事由が終了するまで関連情報を保有することがあります。個人を識別できないよう集計または匿名化された情報は、統計および本サービスの改善のため、より長期間利用することがあります。
5.1 メッセージ削除および退会時の取扱い
U-KEYは、グループ学習における共同記録を次のように取り扱います。
- 個別メッセージの削除は、他の利用者の画面から非表示にするソフトデリート方式です。メッセージ本文は、ルームが削除されるか運営上の削除処理が完了するまで、データベースに残る場合があります。
- 退会時には、認証アカウント、プロフィール、ルームメンバー関係、個人の保存項目およびアップロードした写真が削除対象となります。
- 退会した利用者が作成した質問、解答・解説および通常メッセージのテキストならびに当該利用者が作成したルームは、グループの共同記録を維持するために残る場合があります。この場合、アカウント識別子を削除し、投稿者を「退会した利用者」と表示します。
- 退会した利用者がルーム所有者であった場合、共同ルームの継続性を確保するため、管理権限が他のメンバーに移転される場合があります。
- メッセージ本文自体に氏名、連絡先その他の個人情報が含まれている場合、アカウント識別子を削除しても当該テキストが完全な匿名情報にならないことがあります。追加削除が必要な利用者は、個人情報お問い合わせメールから請求できます。
U-KEYを退会しても、Apple App StoreまたはGoogle Playのサブスクリプションは自動的に解約されません。利用者は、該当ストアのサブスクリプション管理画面から別途解約する必要があります。
6. 委託先・技術提供者および独立したサービス提供者
6.1 取扱委託先および技術提供者
当社は、当社の指示に基づく個人情報の取扱いまたは本サービスに必要な技術機能の提供のため、次の事業者を利用します。
| 事業者 | 役割 |
|---|---|
| Supabase, Inc. | 認証、データベース、ファイル保存、リアルタイム同期、サーバー機能およびセキュリティログ |
| Google LLC — Firebaseサービス | Firebase Analytics、CrashlyticsおよびCloud Messaging |
| OpenAI, L.L.C. | AI回答生成、埋め込み生成および画像理解 |
| Mathpix, Inc. | 問題画像に含まれる文字・数式の認識 |
| RevenueCat, Inc. | アプリ内サブスクリプション状態、購入検証・復元および利用権限管理 |
当社は、提供者との契約およびサービス設定を通じて、目的外利用の制限、アクセス制御、安全管理措置ならびに削除・返還義務を管理します。提供者は、適用法令および公表された条件に従い、セキュリティ、法令遵守またはサービスの完全性のため、限定的な情報を別途取り扱う場合があります。
現在、Mathpixの品質改善に関するオプトアウトが有効になっていないため、Mathpixは、その方針に従い、保存された入力画像を品質確認または認識精度の改善のために取り扱う場合があります。
Mathpixは、当社の指示に基づくOCR処理については委託先として取り扱います。ただし、保存された入力画像を自らの品質確認または認識精度の改善に利用する範囲では、取扱いの目的および方法を独自に決定する場合があり、その範囲については第7条および第8条の対象として取り扱います。
6.2 独立したプラットフォーム・アカウント提供者
次の事業者は、利用者がそのアカウント、ログイン、決済、ストアまたはネットワークサービスを直接利用することから、各社の利用条件およびプライバシーポリシーに基づき、一部の取扱目的および方法を独自に決定する場合があります。
| 事業者 | 独立して提供するサービス |
|---|---|
| Apple Inc. | Sign in with Apple、App Storeの決済およびサブスクリプション処理 |
| Google LLC | Googleログイン、Google Playの決済およびサブスクリプション処理、Google Fontsのネットワーク配信 |
| Kakao Corp. | Kakaoログイン |
Google LLCは、Firebaseサービスについては当社がアプリ運営のために利用する技術提供者として、Googleログイン、Google Playおよび一部のGoogle Fonts処理についてはGoogle独自のプラットフォーム条件に基づく提供者として、それぞれ異なる立場で関与します。適用される立場は、個別のサービスおよび取扱行為によって異なります。
7. 個人情報の国外移転
本サービスの基盤および一部機能は、利用者の所在国以外にある事業者によって運営されます。個人情報は、該当機能の利用時または本サービスの運営時に、暗号化されたネットワークを通じて移転されます。
| 移転先・お問い合わせ先 | 国・処理場所 | 移転項目 | 目的 | 時期・方法 | 保有期間 |
|---|---|---|---|---|---|
| Supabase, Inc. | 日本・東京リージョン。運営・サポートに必要な場合、米国その他の提供者の処理拠点 | アカウント、プロフィール、ルーム、メッセージ、添付ファイル、学習、AI、通報およびサブスクリプション状態情報 | 認証、データ・ファイル保存、リアルタイム機能およびサーバー処理 | 登録および本サービス利用時にTLSで移転 | 本ポリシーの各保有期間および提供者のバックアップ周期 |
| Google LLC — Firebase | 米国およびGoogleのグローバル処理施設 | インストール・端末識別子、利用イベント、診断情報、プッシュトークン、ルーム名、表示名、メッセージプレビュー | 分析、障害診断およびプッシュ配信 | アプリイベント、障害および通知発生時に暗号化して移転 | Analytics 14か月、Crashlytics 90日、未配信プッシュ最大4週間、トークンは削除処理時までおよびバックアップ除去に最大180日 |
| OpenAI, L.L.C. | 米国 | AIプロンプト、質問、解答・解説、要約、直近の会話履歴、添付画像および必要な技術情報 | AI回答、埋め込みおよび画像理解 | 利用者がAI機能を実行した際にTLSで移転 | API不正利用監視ログに最大30日。当社はZero Data Retentionの承認を受けていない |
| Mathpix, Inc. | 米国 | OCRを要求した問題画像および認識結果 | 文字・数式認識 | 利用者がOCR機能を実行した際にTLSで移転 | 品質改善オプトアウトが有効でないため、入力画像は最大90日、OCR結果キャッシュは最大30日保有される場合がある |
| RevenueCat, Inc. | 米国 | アプリ利用者識別子、商品、サブスクリプション、購入および利用権限情報 | サブスクリプション検証、復元および利用権限管理 | アプリ起動、ログイン、購入、更新および復元時に暗号化して移転 | 顧客記録の削除および適用される契約・法定保有期間まで。法的義務・紛争のため限定的な記録を保有する場合がある |
| Apple Inc. | 米国その他Appleの処理拠点 | Appleアカウント識別子、ログイントークン、商品、サブスクリプションおよび取引情報 | Appleログイン、App Storeの決済・サブスクリプション処理 | ログイン、購入または復元時に暗号化して移転 | Appleが公表する保有期間および適用される法定期間 |
| Google LLC — Googleログイン、Google Play、Google Fonts | 米国およびGoogleのグローバル処理施設 | Googleアカウント識別子・認証トークン、商品・サブスクリプション・取引情報、IPアドレスおよび一般的なフォントリクエスト情報 | Googleログイン、Google Playの決済・サブスクリプション処理、フォント配信 | ログイン、購入、復元またはフォント要求時に暗号化して移転 | Googleが公表する保有期間および適用される法定期間 |
| Kakao Corp. | 大韓民国およびKakaoが開示するその他の処理場所 | Kakaoアカウント識別子、メールアドレス、認証トークン | Kakaoログイン | ログイン時に暗号化して移転 | 連携解除または退会時まで。ただしKakaoが公表する保有期間に従う |
OpenAI APIに送信されたデータは、原則としてOpenAIモデルの学習には使用されません。ただし、当社は別途承認が必要なZero Data Retention制度の適用を受けていないため、不正利用監視ログが最大30日間保有される場合があります。
現在、Mathpixの`improve_mathpix: false`オプトアウトが有効になっていないため、入力画像が品質確認または認識精度の改善に使用される場合があります。
利用者は、AI・OCRに関する国外移転への同意を拒否し、または従前の同意を撤回できます。この場合、AI回答、埋め込みおよび画像OCRは利用できませんが、基本的なメッセージ、ルームおよびQ&A機能は引き続き利用できます。中核的な認証またはデータ保存に必要な国外移転を拒否した場合、当社は本サービスを提供できないことがあり、利用者は退会できます。
日本の利用者の個人データを外国にある第三者へ提供する場合、当社は個人情報保護法第28条に従い、本人の同意を取得する前に、外国名、当該外国の制度および提供先の保護措置に関する情報を提供し、または提供先との契約等により基準適合体制を確保します。基準適合体制に基づく場合、当社は相当措置の実施状況および当該外国の制度を定期的に確認し、本人の求めに応じて必要な情報を遅滞なく提供します。
8. 第三者提供および外部サービス
当社は、個人情報を販売せず、パーソナライズ広告またはクロスコンテキスト行動広告のために共有しません。
ただし、次の場合には、必要な範囲で情報が提供または公開されることがあります。
- 利用者が公開ルームに参加し、または公開共有リンクを作成した場合
- 利用者がルームメンバーとメッセージ、プロフィールまたは学習コンテンツを共有した場合
- 利用者が双方の管理者によって承認されたルーム間AI知識共有に参加した場合
- 利用者がApple、GoogleまたはKakaoログイン、またはアプリストア決済を選択した場合
- 法令、裁判所命令または権限を有する機関の適法な要請に従う場合
- 生命・身体への差し迫った危険、児童性的虐待コンテンツその他重大な安全事故に対応するため必要な場合
- 合併、事業譲渡その他これに類する取引に伴い、法令上必要な手続および保護措置を講じる場合
Apple、Google、Kakaoおよび各アプリストアは、一部の取扱いについて独立した個人情報取扱主体となり、各社のプライバシーポリシーを適用する場合があります。
Mathpixの品質改善に関するオプトアウトが無効の状態でOCRを利用すると、次の別個の取扱いが行われる場合があります。
| 提供先 | 提供項目 | 別個の利用目的 | 保存期間 | 拒否した場合の影響 |
|---|---|---|---|---|
| Mathpix, Inc. | OCRを要求した問題画像および認識結果 | 品質確認ならびに文字・数式認識精度の改善 | 入力画像は最大90日、OCR結果キャッシュは最大30日 | OCR機能は利用不可。基本的なメッセージ、ルームおよびQ&A機能は利用可能 |
9. AI機能に関する特別な通知
- AI回答はOpenAIのモデルを用いて生成され、不正確または不適切な内容を含む場合があります。
- AI機能は、質問、解答・解説、採択された知識、公開知識および直近の会話履歴を処理する場合があります。
- 個人AIチャットの回答は、通常の会話記録として当社データベースに保存されませんが、限定的な情報がエラーログまたはOpenAIの不正利用監視ログに残る場合があります。
- AI回答を通報した場合、当該回答の本文、通報理由および関連情報が運営上の確認のために保存されます。
- 医療、法務、金融、安全その他重大な判断について、AI回答のみに依拠してはなりません。
- 住民登録番号、金融情報、健康情報、他人の個人情報その他の機微な情報をAI機能に入力しないでください。
10. 未成年者
日本国内の利用者は16歳以上に限ります。16歳未満の方は本サービスを利用できず、当社は法定代理人の同意による別途の登録手続を提供しません。16歳未満の利用を確認した場合、当社は直ちに利用を制限し、法令上の保存義務がある場合を除き、当該アカウントおよび関連する個人情報を遅滞なく削除します。18歳未満の方が有料契約を締結する場合は、法定代理人の同意を得てください。
韓国および米国では14歳未満の方に本サービスを提供しません。利用者の所在国でより高い年齢要件が適用される場合は、その要件に従います。当社は、地域別の年齢確認または法定代理人同意の仕組みが整備されていない地域もしくは年齢層について、利用または一部機能を制限することがあります。
保護者または法定代理人は、児童の情報が不適切に取り扱われていると判断した場合、個人情報お問い合わせメールを通じて削除または取扱制限を請求できます。
11. 削除および廃棄
当社は、保有期間が終了し、または取扱目的を達成した個人情報を遅滞なく削除します。
- 電子的ファイル:復元または再生できない方法で恒久的に削除
- データベース記録:復元または再生できない方法で削除し、または他の情報と合理的に照合しても特定の個人を識別できないよう匿名化
- 法令に基づき保存する情報:他の個人情報と分離して法定期間保存した後に削除
- 紙媒体:裁断または焼却
災害復旧用バックアップおよび提供者のシステムには、通常のバックアップ周期に従って情報が限定的な期間残る場合があります。その期間中、当該情報を通常利用のために復元したり、新たな目的で利用したりしません。外部プラットフォームが独自に保存した公開共有リンクのプレビューまたはプッシュ内容のコピーについては、当社が直接削除できません。
12. 利用者の権利および行使方法
利用者は、適用法令に従い、次の権利を有する場合があります。
- 個人情報の取扱いの有無の確認および開示
- 不正確な情報の訂正
- 個人情報の削除および退会
- 取扱いの停止、制限または異議申立て
- 同意の撤回
- 利用者が提供した情報の写しまたはデータポータビリティ
- 自動化された取扱いに関する説明または再審査
- 権限を有する監督機関への苦情申立て
プロフィール情報はアプリ内で修正でき、アプリ内のアカウント削除機能から退会できます。その他の請求はpopolabs0511@gmail.comに送付できます。当社は、請求者の本人確認を行い、適用法令が定める期間および手続に従って対応します。
利用者は、法定代理人または適法に委任された代理人を通じて権利を行使できます。当社は、利用者の権利を保護するため、本人および代理人の身元ならびに代理権を確認する場合があります。
他人の権利、法的義務、本サービスのセキュリティ、紛争対応または表現の自由を保護するため、一部の請求が制限される場合があります。共同ルームのメッセージをアカウント識別情報から分離して保有する方法および個別メッセージのソフトデリートについては、第5条に従います。
韓国の利用者は大韓民国の個人情報保護法に基づく権利を行使できます。米国の利用者は、適用される連邦法または州法に基づき、開示、訂正、削除ならびに販売・共有に関する権利を行使できます。当社は、個人情報を販売せず、クロスコンテキスト行動広告のために共有しません。日本の利用者は、個人情報保護法に基づき、保有個人データの開示、訂正、利用停止その他の措置を請求できます。
13. 安全管理措置
当社は、次の安全管理措置を講じます。
- 通信時のTLS暗号化
- 行単位アクセス制御(RLS)およびルームメンバー権限の確認
- 管理者権限およびサーバー秘密情報のアプリ外での保管
- 認証トークンおよびセッションへのアクセス制限
- 非公開ルーム、公開ルームおよび公開共有ページのアクセス経路の分離
- AI・OCRリクエスト前のメンバー資格、ルーム権限および同意のサーバー側検証
- 利用量制限、異常リクエストの制御およびセキュリティログ
- 通報、ブロックおよび運営確認の仕組み
- 開発・運営上の最小権限アクセスおよび提供者の安全管理措置の確認
インターネット通信または電子的保存について絶対的な安全を保証することはできません。個人情報の侵害を確認した場合、当社は適用法令に従い、影響を受ける利用者および権限を有する機関に通知し、被害軽減措置を講じます。
14. 自動収集技術および選択肢
本サービスは、ログイン状態の維持、本サービスの安定化、利用状況の分析および通知のため、認証セッション、インストール識別子、Firebase SDK、プッシュトークンおよび一般的なサーバーログを使用します。
当社は、第三者広告SDKを使用せず、個人情報を広告事業者に販売せず、パーソナライズ広告のためのアプリ横断トラッキングを行いません。
本サービスは、関係のないウェブサイトまたはサービスを横断してターゲティング広告のために利用者を追跡しないため、現在、ブラウザの`Do Not Track`信号に応じた個別の動作を行いません。法令上認められるオプトアウト信号が当社に適用される場合は、当該法令に従って処理します。第6条から第8条までに記載する独立した提供者は、各社の方針に基づき標準的な技術情報を収集する場合があります。
利用者は、次の方法で一部の取扱いを制限できます。
- アプリまたはOS設定でプッシュ通知を無効にする
- カメラまたは写真ライブラリの権限を撤回する
- アプリ設定でAIに関する国外移転への同意を撤回する
- ソーシャルログイン提供者の設定からU-KEYとの連携を解除する
- 個人情報お問い合わせメールを通じて分析情報の取扱いに異議を申し立てる
技術的に必要な認証セッションまたはセキュリティログを遮断した場合、ログインを必要とする機能が正常に動作しないことがあります。
15. 個人情報保護責任者およびお問い合わせ先
- 個人情報保護責任者:김도현(代表)
- 個人情報・法務お問い合わせ:popolabs0511@gmail.com
- 一般サービスお問い合わせ:contact@popolabs.app
個人情報に関する相談については、大韓民国個人情報保護委員会、個人情報侵害申告センターまたはその他権限を有する機関に問い合わせることもできます。
16. 地域別要件および利用制限
施行日現在、本サービスの提供対象国は大韓民国、米国および日本です。利用者の居住地における強行的な個人情報保護法令が、本ポリシーより強い保護を定める場合、当該法令が適用されます。当社は、アプリストアの配信設定または法的・運営上の理由により、その他の国からの新規登録もしくは一部機能の提供を制限し、提供国を拡大する前に当該国の要件を別途確認します。
17. 本ポリシーの変更
当社は、法令、本サービスの機能または個人情報の取扱方法が変更された場合、本ポリシーを改定することがあります。重要な変更については、施行前にアプリ、ウェブページ、メールその他合理的な方法で通知します。
- 初回施行日:2026年7月18日
- 現行バージョン:1.0
一般お問い合わせ: contact@popolabs.app
個人情報・法務お問い合わせ: popolabs0511@gmail.com
施行日: 2026年7月18日