← Back

Privacy Policy

Effective: July 12, 2026

Data Controller

The data controller for this service is Funston (Junsung Park), who also serves as the Privacy Officer. MoaVoca ("the App") is operated by Funston, a sole proprietorship registered in the Republic of Korea. This Privacy Policy explains what information we collect, how we use it, and the rights you have over it, in line with Korean PIPA, EU/UK GDPR, and the California CCPA.

Privacy inquiries: support@moavoca.com

1. Information We Collect

MoaVoca ("the App") collects the following information to provide its services.

2. Information We Do Not Collect

3. Where Data Is Stored

Wordlists and vocabulary data are stored locally on your device (SQLite). Language settings are kept in on-device storage (AsyncStorage).

Wordlist data is securely transmitted to and stored on our server (Supabase) for cloud backup and cross-device sync.

When you look up a word, the request is processed through our server (Supabase) for AI processing. Results may be stored in an anonymous cache to improve service quality.

4. Third-Party Services and Processing Entrustment

The App uses the following external services to provide its functionality. These providers act as processors (수탁자) under Korean PIPA Article 26: under a data-processing agreement with the Provider, they process personal data only within the scope of the entrusted work and do not use it for their own purposes.

Beyond the above, we do not share data with third-party analytics tools, social media platforms, or data brokers. Our usage analytics (§1) use no third-party tools and are processed only on our own server (Supabase).

Transfer of personal data on business succession (Korean PIPA Article 27): If personal data is transferred due to a merger, business transfer, or conversion of the Provider from a sole proprietorship to a corporation, the Provider will, before the transfer, notify you through in-app notice and email of (i) the fact of transfer, (ii) the name and contact details of the party receiving the data, and (iii) how to withdraw consent or object if you do not want your data transferred. The receiving party will use the personal data only within the scope of the purposes existing at the time of transfer.

Where the receiving party is located outside Korea (for example, the establishment of an overseas corporation or an acquisition by a foreign operator), the Provider will, in addition to the above notice, comply with the cross-border transfer requirements of PIPA Article 28-8 (disclosing the receiving country, the time and method of transfer, and the categories of data, and obtaining consent or another lawful transfer basis where required). For EU/UK data subjects, transfers outside the European Economic Area (EEA) are protected by appropriate safeguards required under the GDPR, such as Standard Contractual Clauses (SCCs).

5. Text-to-Speech (TTS)

The pronunciation feature uses Microsoft Azure Neural TTS for all languages except Chinese (zh-CN), and Google Cloud Text-to-Speech for Chinese. The word or example sentence text is routed through our Supabase server to the relevant synthesis service, and the synthesized audio file is stored in an anonymous cache on Supabase storage so that subsequent requests for the same text reuse the cached audio. No user identification is included in TTS synthesis requests.

6. Speech Recognition

The microphone button on the word lookup screen lets you dictate a word instead of typing. Audio is processed by your operating system's speech recognition service (iOS Speech, Google Speech) and the corresponding privacy policies of Apple/Google may apply. Our app receives only the transcribed text and uses it for lookup; raw audio is not stored or transmitted by us.

7. Push Notifications

Daily learning reminders, weekly recaps, per-wordlist notifications, and — when you have been inactive for a while — re-engagement and streak-recovery reminders are all scheduled locally on your device. These notifications are scheduled based on your on-device learning state (last study date, streak status, days inactive); that state is not sent to or tracked by external servers. For per-wordlist notifications, you can pick the days of the week and time. All notifications can be disabled at any time from Settings.

8. Wordlist Export

All users can export wordlists as CSV files for free (no premium subscription required). Files are generated on-device and shared via your operating system's share sheet (email, messaging, cloud drives, etc.) to a destination you choose. No additional data is sent to our servers during export. A printable PDF study-sheet export format is additionally offered as a premium feature.

9. Public Content and Wordlist Sharing

When you share a wordlist publicly, the wordlist's name, description, word selection, and the posting user's display name and avatar become visible to all other users. Shared wordlists are treated as public information and are subject to discovery, viewing, and download by other users.

You may unshare or delete content at any time. However, copies that other users have already downloaded or copied into their own wordlists may not be automatically deleted from those copies.

The Provider may, without prior notice, hide or remove inappropriate public content. Users can flag inappropriate content through the in-app reporting system, and we act on credible reports promptly (EU DSA Art. 16). See the Terms of Service for the full content policy.

10. Friend System

Users you have added as friends may see your display name, avatar, learning statistics (study days, total words, etc.), and shared wordlists. The exact scope of visibility is shown and adjustable in the in-app settings.

Friend relationships are formed by mutual consent and may be removed or blocked at any time. After blocking, the blocked user can no longer see your content.

Friend relationship data is stored encrypted on the server and is not disclosed to third parties other than the friends themselves.

11. Profile and Avatar

Profile avatars may only be set from a Provider-supplied predefined set or as auto-generated initials. Custom photo or image upload is not supported (to prevent the risk of inappropriate content).

Display names and avatars are public information visible to other users in friend, sharing, and community feature areas.

12. Advertising Identifiers (iOS ATT / Android GAID)

On iOS, the system may show a tracking permission prompt (IDFA) the first time you launch the App. On Android, the Google Advertising ID (GAID) is used; you can limit ad personalization or reset the GAID in your device settings. Your decision affects only ad personalization — declining does not restrict the app's core functionality. Users in the EU (GDPR) and California (CCPA) will see a separate ad consent screen.

Joint controllership with Google (GDPR Art. 26): For the limited purposes of (i) collecting and presenting end-user consent for ad personalization and (ii) the joint processing carried out by AdMob/AdSense for personalized ad delivery, Funston and Google Ireland Ltd. (or its applicable Google entity) act as joint controllers within the meaning of GDPR Art. 26. Allocation of responsibilities: (a) Funston presents the consent prompt, surfaces this Privacy Policy, and forwards tracking/consent signals; (b) Google handles ad serving, measurement, security, and aggregate reporting back to Funston; (c) the parties cooperate on data-subject requests, but data subjects may exercise their GDPR rights against either Funston or Google directly. The full Google-side terms are at privacy.google.com/businesses/jointcontroller. For matters outside the joint-controllership scope (e.g., Google's own service improvement), Google acts as an independent controller under its own privacy policy.

13. Retention by Processing Purpose

We process personal data only for the purposes and retention periods set out below (Korean PIPA Article 15; GDPR Article 13(2)(a)). Our legal bases under GDPR Article 6 are, by purpose: performance of a contract (Art. 6(1)(b)) for learning, account, and subscription features, including the overseas processing by our subprocessors that is necessary to provide those online features; consent (Art. 6(1)(a)) for marketing and ad personalization; legitimate interests (Art. 6(1)(f)) for abuse prevention, security, and product-improvement usage analytics; and legal obligation (Art. 6(1)(c)) for tax and billing records.

14. Data Storage and Deletion

Locally stored wordlist data is deleted when you uninstall the app. You can also delete all on-device data at any time using the "Reset" option in Settings.

If you have registered an account, you can request account deletion from the Settings screen or by email. After verifying your identity, we will permanently delete all server-stored data (email, OAuth identifiers, wordlist data, learning progress, display name, friend graph, shared wordlists, push tokens, notification settings) within 30 days. In most cases the deletion completes immediately or within minutes; technical reasons such as backup-rotation cycles may take up to 30 days.

However, to prevent repeated use of the free trial, a one-way hash of the email used at signup is retained for 2 years from the last use even after account deletion, and is then destroyed (see §13). The original email cannot be recovered from this hash. In addition, administrator access/audit logs kept as a security safeguard may be retained for the separate period described in §13.

Server data is retained after subscription cancellation until you request account deletion. Payment- and settlement-related transaction records are retained separately under §13.

If the Provider permanently discontinues the Service, we will give notice at least 30 days before the planned termination date through in-app notice and email, during which you may export your wordlists as CSV or JSON to keep your data. After termination, personal data stored on our servers is securely destroyed in accordance with applicable law; transaction records whose retention is legally mandated are pseudonymized or de-identified and retained for the required period before destruction.

Method of destruction: electronic personal data is permanently erased by technical means that prevent recovery; any personal data printed on paper is shredded or incinerated.

15. International Data Transfers

Some processors listed in §4 process personal data outside the Republic of Korea (Korean PIPA Article 28-8 disclosure).

The Service (web, iOS, and Android) requires sign-in to use, and the overseas transfers to the external services listed in §4 are necessary to provide the Service. If you do not want your data transferred overseas, you may choose not to sign up for or use the Service; if you have already created an account, you can request account deletion or withdraw consent through the process described in §16.

Note: the Republic of Korea is the subject of a 2021 EU Commission adequacy decision, so transfers between Korea and the EU are recognized as providing an adequate level of protection. Transfers to other countries (e.g., the United States) rely on lawful transfer mechanisms such as data-processing agreements and Standard Contractual Clauses (SCCs).

16. Your Rights

Regardless of where you live, you have the following rights over your personal data (Korean PIPA Articles 35–37; GDPR Articles 15–22; CCPA §§1798.100 et seq.).

How to exercise: where available, use the in-app controls; otherwise email support@moavoca.com with sufficient information to verify your identity. We respond within 30 days. If we decline, we will explain why and how to appeal.

You may also lodge a complaint with your data-protection authority: the Personal Information Protection Commission of Korea (privacy.go.kr) and KISA (privacy.kisa.or.kr, ☎ 118) for Korea; your national supervisory authority for the EU; the ICO for the UK; or exercise CCPA rights as a California resident.

17. Security Measures and Breach Notification

We implement the following technical and organizational safeguards.

In the event of a personal-data breach, we will notify affected users and the relevant supervisory authority without undue delay, and within 72 hours where required by applicable law (Korean PIPA Article 34; GDPR Articles 33–34; CCPA §1798.82).

18. Accounts and Authentication

Using the App requires signing in with email + password, Apple Sign In, or Google Sign-In (on web, iOS, and Android alike). After signing in, you can use cloud sync, friends/community, and premium features.

Email verification is required during email registration. Passwords are stored only as one-way salted hashes on Supabase Auth and cannot be viewed by the Provider.

When signing in with Google, your Google account email address and profile information (name) are collected. Your Google password is not processed by the App.

When signing in with Apple, the email address and name linked to your Apple ID are collected. If you choose "Hide My Email", Apple generates an anonymous relay address that is provided to us instead of your real email — we cannot see your real email address. Apple handles password and authentication.

19. EU / UK Representative

The Provider has not currently designated a GDPR Article 27 representative in the EU or UK and will consider appointing one if and when required. EU and UK data subjects may exercise their GDPR rights by contacting us directly at the email below.

20. Children's Privacy

The App is rated 12+ on the App Store and Teen on Google Play and is not directed at children. The Service is not available to children under 14 (per Korean PIPA / 정보통신망법), under 13 (per US COPPA), or under the higher minimum age of digital consent required by the user's country of residence (for example, 16 in Germany and the Netherlands, 20 in Thailand). If we become aware of personal information collected from a child below the applicable age, we will delete it promptly. Please contact us at support@moavoca.com if you believe a child has provided personal data.

21. Changes to This Policy

If this Privacy Policy is updated, we will notify you through an in-app notice prior to the changes taking effect.

This policy was last updated on July 12, 2026.

22. Contact Us

For privacy-related inquiries, please reach out by email.

Email: support@moavoca.com

개인정보처리방침

시행일: 2026-07-12

개인정보처리자

본 서비스의 개인정보처리자는 펀스턴 (박준성)이며, 개인정보 보호책임자도 동일합니다. MoaVoca(이하 "앱")는 대한민국에 등록된 개인사업자 펀스턴이 운영합니다. 본 개인정보처리방침은 개인정보보호법(PIPA), EU/영국 GDPR, 캘리포니아 CCPA에 따라 수집하는 정보, 이용 방법 및 정보주체의 권리를 설명합니다.

개인정보 관련 문의: support@moavoca.com

1. 수집하는 정보

MoaVoca(이하 "앱")는 서비스 제공을 위해 아래 정보를 수집합니다.

2. 수집하지 않는 정보

3. 정보의 저장 위치

단어장과 단어 데이터는 기기 내부(SQLite)에 저장됩니다. 언어 설정은 기기 내부 저장소(AsyncStorage)에 보관됩니다.

클라우드 백업 및 동기화를 위해 단어장 데이터가 서버(Supabase)에 암호화 전송 후 저장됩니다.

단어 검색 시 AI 처리를 위해 서버(Supabase)를 경유하며, 검색 결과는 서비스 품질 향상을 위해 익명 캐시로 저장될 수 있습니다.

4. 제3자 제공 및 처리위탁

앱은 서비스 제공을 위해 아래 외부 서비스를 이용합니다. 아래 업체는 개인정보보호법 제26조에 따른 수탁자로서, 운영자와의 위탁계약에 따라 명시된 위탁업무 범위 내에서만 개인정보를 처리하며 자체 목적으로 이용하지 않습니다.

위 외에 제3자 분석 도구, 소셜 미디어, 데이터 브로커 등에 데이터를 공유하지 않습니다. 서비스 이용 통계(§1)는 제3자 도구를 사용하지 않고 운영자 자체 서버(Supabase)에서만 처리됩니다.

영업양도 등에 따른 개인정보 이전(개인정보보호법 제27조): 운영자의 합병·영업양도, 또는 개인사업자에서 법인으로의 전환 등으로 개인정보가 이전되는 경우, 운영자는 이전 전에 (i) 이전 사실, (ii) 개인정보를 이전받는 자의 명칭·연락처, (iii) 정보주체가 동의를 철회하거나 이전을 원하지 않을 경우의 조치 방법을 앱 내 공지 및 이메일을 통해 사전에 통지합니다. 개인정보를 이전받는 자는 이전 당시의 이용 목적 범위 내에서만 개인정보를 이용합니다.

개인정보를 이전받는 자가 국외에 있는 경우(예: 해외 법인 설립 또는 해외 사업자에 의한 인수·합병), 운영자는 위 통지에 더하여 개인정보의 국외이전에 관한 개인정보보호법 제28조의8의 요건(이전받는 국가, 이전 일시·방법, 이전 항목의 고지 및 필요한 경우 동의 또는 그 밖의 적법한 이전 근거 확보)을 준수합니다. EU·영국 정보주체의 개인정보를 유럽경제지역(EEA) 밖으로 이전하는 경우에는 표준계약조항(SCC) 등 GDPR이 요구하는 적절한 보호조치를 적용합니다.

5. 음성 합성(TTS)

발음 듣기 기능은 중국어(zh-CN)를 제외한 언어에 대해 Microsoft Azure Neural TTS를, 중국어에 대해서는 Google Cloud Text-to-Speech를 사용하여 음성을 합성합니다. 단어 또는 예문 텍스트가 Supabase 서버를 경유하여 해당 합성 서비스로 전달되며, 합성된 음성 파일은 Supabase 저장소에 익명 캐시로 보관되어 동일한 단어를 다시 요청할 때 재사용됩니다. 사용자 식별 정보는 음성 합성 요청에 포함되지 않습니다.

6. 음성 인식

단어 검색 화면에서 마이크 버튼으로 음성 입력을 사용할 수 있습니다. 음성은 운영체제가 제공하는 음성 인식 서비스(iOS Speech, Google Speech)에서 처리되며, Apple/Google의 개인정보처리방침이 적용될 수 있습니다. 앱은 인식 결과 텍스트만 받아 검색에 사용하고, 음성 데이터를 별도로 저장하거나 외부로 전송하지 않습니다.

7. 푸시 알림

일일 학습 리마인더, 주간 학습 요약, 단어장별 알림, 그리고 한동안 학습하지 않은 경우의 재참여 알림·연속 학습(스트릭) 복귀 알림 등은 모두 기기에 로컬로 예약되어 표시되는 알림입니다. 이러한 알림은 기기 내 로컬 학습 상태(마지막 학습일·스트릭 상태·휴면 일수)에 따라 예약되며, 해당 상태 정보는 외부 서버로 전송되거나 추적되지 않습니다. 단어장별 알림은 사용자가 직접 요일과 시각을 선택할 수 있고, 모든 알림은 설정에서 언제든 비활성화할 수 있습니다.

8. 단어장 내보내기

모든 사용자는 단어장을 CSV 파일로 무료로 내보낼 수 있습니다(프리미엄 가입이 필요하지 않습니다). 파일은 기기 내에서 생성되어 운영체제의 공유 시트(이메일, 메시지, 클라우드 드라이브 등)를 통해 사용자가 직접 선택한 곳으로 전달됩니다. 내보내기 과정에서 앱 서버로 추가 데이터가 전송되지 않습니다. 인쇄용 PDF 학습지 형식의 내보내기는 프리미엄 혜택으로 추가 제공됩니다.

9. 공개 콘텐츠 및 단어장 공유

이용자가 단어장을 공유 기능을 통해 공개하면, 해당 단어장의 이름·설명·단어 구성과 게시한 사용자의 표시 이름·아바타가 다른 모든 이용자에게 표시됩니다. 공유 단어장은 공개 정보로 취급되며, 검색·열람·다운로드의 대상이 됩니다.

사용자는 언제든 공유를 해제하거나 콘텐츠를 삭제할 수 있습니다. 다만 다른 이용자가 이미 다운로드하거나 자신의 단어장에 복사한 콘텐츠는 그 이용자의 사본에서 자동 삭제되지 않을 수 있습니다.

운영자는 부적절한 공개 콘텐츠를 사전 통지 없이 비공개·삭제할 수 있으며, 신고 시스템을 통해 사용자가 부적절한 콘텐츠를 알릴 수 있습니다. 신뢰할 만한 신고에 대해서는 신속히 조치합니다(EU 디지털 서비스법 제16조). 자세한 콘텐츠 정책은 이용약관을 참고하세요.

10. 친구 시스템

친구로 등록된 다른 이용자에게는 사용자의 표시 이름, 아바타, 학습 통계(학습 일수, 누적 단어 수 등), 공유 단어장이 표시될 수 있습니다. 구체적 공개 범위는 앱 내 설정에서 확인하고 조정할 수 있습니다.

친구 추가는 양방향 동의로 성립하며, 친구 관계는 언제든 해제하거나 차단할 수 있습니다. 차단한 사용자에게는 사용자의 콘텐츠가 더 이상 표시되지 않습니다.

친구 관계 정보는 서버에 암호화 저장되며, 친구 본인이 아닌 제3자에게는 공개되지 않습니다.

11. 프로필 및 아바타

이용자의 프로필 아바타는 운영자가 제공하는 미리 만들어진 세트 또는 자동 생성된 이니셜로만 설정할 수 있습니다. 사용자가 임의로 사진·이미지를 업로드하는 기능은 제공하지 않습니다(부적절한 콘텐츠 위험 방지 목적).

표시 이름과 아바타는 다른 사용자가 볼 수 있는 공개 정보입니다. 친구·공유·게시판 등 사회적 기능 영역에서 노출됩니다.

12. 광고 식별자 (iOS ATT / Android GAID)

iOS에서는 처음 앱 실행 시 광고 식별자(IDFA) 사용 동의를 묻는 시스템 팝업이 표시될 수 있습니다. Android에서는 Google 광고 ID(GAID)가 사용되며, 기기 설정에서 광고 개인화를 제한하거나 광고 ID를 재설정할 수 있습니다. 동의/허용 여부는 광고 개인화 정도에만 영향을 미치며, 거부하더라도 앱의 기본 기능 사용에는 제한이 없습니다. 유럽(GDPR) 및 캘리포니아(CCPA) 지역 사용자에게는 별도의 광고 개인정보 동의 화면이 표시됩니다.

Google과의 공동관리자 관계(GDPR 제26조): (i) 광고 개인화에 대한 최종 이용자 동의의 수집·표시, (ii) AdMob/AdSense의 개인 맞춤형 광고 전달을 위한 공동 처리에 한하여, 펀스턴(Funston)과 Google Ireland Ltd.(또는 해당 Google 법인)는 GDPR 제26조상 공동관리자(joint controllers)에 해당합니다. 역할 분담: (a) 펀스턴은 동의 화면 표시, 본 처리방침 안내, 추적/동의 신호 전달을 담당하고, (b) Google은 광고 게재·측정·보안 및 집계 리포트 제공을 담당하며, (c) 정보주체 요청에 양사가 협력하되, 정보주체는 펀스턴 또는 Google 중 어느 쪽에든 직접 GDPR 권리를 행사할 수 있습니다. Google 측 약정 전문은 privacy.google.com/businesses/jointcontroller에서 확인할 수 있습니다. 공동관리 범위를 벗어난 처리(예: Google 자체 서비스 개선)에 대해서는 Google이 자체 처리방침에 따른 독립 관리자로 행위합니다.

13. 처리 목적별 보관 기간

운영자는 개인정보보호법 제15조에 따라 수집한 개인정보를 아래 목적·기간 내에서만 처리합니다. 처리의 법적 근거(GDPR 제6조)는 항목별로 다음과 같습니다: 학습·계정·구독 등 서비스 제공과 이를 위해 필요한 위탁업체의 국외 처리는 계약 이행(제6조 (1)(b)), 마케팅·광고 개인화는 동의(제6조 (1)(a)), 부정 이용 방지·보안·서비스 개선을 위한 이용 통계는 정당한 이익(제6조 (1)(f)), 세금·결제 기록 보관은 법적 의무(제6조 (1)(c))에 근거합니다.

14. 데이터 보관 및 삭제

기기에 저장된 단어장 데이터는 앱 삭제 시 함께 삭제됩니다. 설정 화면의 "초기화" 기능을 통해 언제든 기기 내 모든 데이터를 삭제할 수 있습니다.

계정을 등록한 사용자는 설정 화면에서 계정 삭제를 요청할 수 있으며, 운영자는 본인 확인 후 30일 이내에 서버에 저장된 이메일, OAuth 식별자, 단어장 데이터, 학습 진도, 표시 이름, 친구 관계, 공유 단어장, 푸시 토큰, 알림 설정 등 모든 정보를 영구 삭제합니다. 통상 즉시 또는 수 분 내 처리되나 백업·복구 사이클 등 기술적 사유로 최대 30일이 소요될 수 있습니다.

다만 무료 체험의 중복 사용을 방지하기 위해, 가입 시 사용한 이메일의 일방향 해시값은 계정 삭제 후에도 최종 이용일로부터 2년간 보관되며 이후 파기됩니다(§13 참조). 이 해시값으로는 원문 이메일을 복원할 수 없습니다. 또한 개인정보 안전성 확보조치를 위한 관리자 접근·감사 기록은 §13에 따라 별도 기간 동안 보존될 수 있습니다.

구독 해지 후에도 서버 데이터는 계정 삭제를 요청할 때까지 보관됩니다. 결제·정산 관련 거래 기록은 위 §13에 따라 별도 보관됩니다.

운영자가 서비스를 영구적으로 종료하는 경우, 종료 예정일 최소 30일 전에 앱 내 공지와 이메일을 통해 안내하며, 이용자는 그 기간 동안 단어장을 CSV 또는 JSON으로 내보내어 데이터를 보관할 수 있습니다. 종료 후 서버에 저장된 개인정보는 관련 법령에 따라 안전하게 파기되며, 법령상 보관이 의무화된 거래 기록은 가명·비식별 처리하여 해당 기간 동안 보관 후 파기합니다.

파기 방법: 전자적 파일 형태로 저장된 개인정보는 복구·재생이 불가능한 기술적 방법(영구 삭제)으로 파기하며, 종이에 출력·기록된 개인정보가 있는 경우 분쇄하거나 소각하여 파기합니다(개인정보보호법 시행령 제16조).

15. 개인정보의 국외이전

본 서비스는 §4에 열거된 외부 서비스를 이용하는 과정에서 사용자의 개인정보를 대한민국 외 국가로 이전합니다(개인정보보호법 제28조의8 고지 사항).

본 서비스(웹·iOS·Android)는 이용에 로그인이 필요하며, §4에 열거된 외부 서비스로의 국외이전은 서비스 제공을 위해 불가피합니다. 국외이전을 원하지 않으시는 경우 서비스에 가입·이용하지 않으실 수 있으며, 이미 가입한 사용자는 §16의 절차에 따라 계정 삭제 또는 동의 철회를 요청할 수 있습니다.

참고: 대한민국은 2021년 EU 집행위원회의 적정성 결정(adequacy decision) 대상국으로, 한국과 EU 간 개인정보 이전에 대해 적절한 보호 수준이 인정됩니다. 미국 등 그 외 국가로의 이전은 위탁계약 및 표준계약조항(SCC) 등 적법한 이전 수단에 따릅니다.

16. 정보주체의 권리

거주 지역에 관계없이 사용자는 자신의 개인정보에 대해 아래 권리를 행사할 수 있습니다(개인정보보호법 제35조 이하, GDPR 제15-22조, CCPA §1798.100 이하).

권리 행사 방법: 앱 내 설정에서 가능한 경우 직접 처리하거나, support@moavoca.com로 본인 확인이 가능한 정보와 함께 이메일을 보내주시면 통상 30일 이내에 답변드립니다. 행사 거부 시 그 사유와 이의 제기 방법을 함께 통지합니다.

개인정보 처리에 관한 불만은 개인정보보호위원회(privacy.go.kr) 및 한국인터넷진흥원(KISA) 개인정보침해신고센터(privacy.kisa.or.kr · ☎ 118)에 신고할 수 있습니다. 개인정보 분쟁의 조정이 필요한 경우 개인정보분쟁조정위원회(kopico.go.kr · ☎ 1833-6972)에 조정을 신청할 수 있으며, 개인정보 침해는 경찰청 사이버수사국(ecrm.police.go.kr · ☎ 182) 또는 대검찰청 사이버수사과(☎ 1301)에도 신고할 수 있습니다. EU 거주자는 거주국 감독기관에, 영국 거주자는 ICO에, 캘리포니아 거주자는 CCPA 권리를 행사할 수 있습니다.

17. 보안 조치 및 침해 통지

운영자는 개인정보 보호를 위해 다음과 같은 기술적·관리적 보호 조치를 시행합니다.

중대한 개인정보 침해 사고가 발생한 경우, 운영자는 관련 법령(개인정보보호법 제34조, GDPR 제33-34조, CCPA §1798.82)에 따라 인지 후 부당한 지체 없이 사용자 및 감독기관에 통지하며, 법령상 요구되는 경우 72시간 이내에 통지합니다.

18. 계정 및 인증

본 서비스 이용에는 이메일·Google·Apple 계정으로 로그인이 필요합니다(웹·iOS·Android 공통). 로그인 후 클라우드 동기화, 친구·커뮤니티, 프리미엄 기능을 이용할 수 있습니다.

이메일 계정 등록 시 이메일 인증을 통해 본인 확인을 진행합니다. 비밀번호는 Supabase Auth에 단방향 솔티드 해시(salted hash)로만 저장되며, 운영자가 원문을 확인할 수 없습니다.

Google 로그인 시 Google 계정의 이메일 주소와 프로필 정보(이름)가 수집됩니다. Google 계정의 비밀번호는 앱에서 처리하지 않습니다.

Apple 로그인 시 Apple ID에 연결된 이메일 주소와 이름이 수집됩니다. "Hide My Email"을 선택하면 Apple이 익명 릴레이 주소를 생성하여 전달하며, 운영자는 사용자의 실제 이메일을 알 수 없습니다. Apple 계정의 비밀번호 및 인증 절차는 Apple이 처리하며 앱에서 직접 다루지 않습니다.

19. EU/UK 대리인

현재 운영자는 GDPR 제27조에 따른 EU/UK 대리인을 지정하고 있지 않으며, 향후 필요 시 지정을 검토합니다. EU·영국 거주 정보주체는 아래 이메일로 운영자에게 직접 연락하여 GDPR상 권리를 행사하실 수 있습니다.

20. 아동 개인정보 보호

본 앱은 App Store 12+, Google Play Teen 등급으로 아동을 대상으로 하지 않습니다. 운영자는 만 14세 미만(개인정보보호법·정보통신망법 기준), 만 13세 미만(미국 COPPA 기준), 또는 이용자의 거주 국가가 정한 디지털 동의 최소 연령(예: 독일·네덜란드 16세, 태국 20세 등) 미만의 가입·이용을 허용하지 않으며, 해당 사실이 확인되는 경우 관련 개인정보를 즉시 삭제합니다. 아동의 개인정보가 수집된 사실을 알게 된 경우 즉시 support@moavoca.com로 연락해 주시기 바랍니다.

21. 변경 사항 고지

개인정보처리방침이 변경될 경우, 앱 내 공지를 통해 사전에 안내합니다.

본 방침은 2026년 7월 12일자로 개정되었습니다.

22. 문의

개인정보와 관련한 문의는 이메일로 보내주시면 답변드리겠습니다.

이메일: support@moavoca.com