Privacy Policy
Effective: July 12, 2026
Data Controller
- Business name: Funston (펀스턴)
- Representative / Privacy Officer: Junsung Park (박준성)
- Business registration number: 774-17-02956
- Mail-order business registration: 제2026-서울구로-0893호
- Address: Opus 1, B36-S77, B1F, 207 Gurojungang-ro, Guro-gu, Seoul 08216, Republic of Korea
- Hosting provider: Cloudflare, Inc. (website) · Supabase Inc. and Amazon Web Services (backend)
- Phone: +82-10-9966-3457
- Email: support@moavoca.com
The data controller for this service is Funston (Junsung Park), who also serves as the Privacy Officer. MoaVoca ("the App") is operated by Funston, a sole proprietorship registered in the Republic of Korea. This Privacy Policy explains what information we collect, how we use it, and the rights you have over it, in line with Korean PIPA, EU/UK GDPR, and the California CCPA.
Privacy inquiries: support@moavoca.com
1. Information We Collect
MoaVoca ("the App") collects the following information to provide its services.
- Email address: collected when you register and sign in. Sign-in is required to use the service (choose one of email, Google, or Apple), and the email tied to your chosen sign-in method is collected.
- Password: collected for email account authentication and stored only as a one-way salted hash on Supabase Auth — we cannot view the plaintext password
- Google profile information: if you choose Google sign-in, your email address and name are passed to us via Google.
- Apple account information: if you choose Apple sign-in, the email address and name linked to your Apple ID are passed to us. If you choose "Hide My Email", only an Apple-generated anonymous relay address is passed to us — we cannot see your real email address.
- Display name (nickname) and username (@handle): the name and handle shown to other users in friend and sharing features. The username is searchable by other users to add you as a friend. Both are set by you.
- Avatar selection: an avatar chosen from a Provider-supplied predefined set or auto-generated initials. Custom photo upload is not supported.
- Language settings: native language, source language, target language
- Wordlist data: list names, saved words, and AI-generated definitions
- Shared wordlists: wordlists you share so other users can view them (name, description, word selection)
- Friend relationships: list of other users you have added, accepted, or blocked
- Device language: checked once for initial UI language (not sent to servers)
- Camera/Photos: When using the image word extraction feature, text is by default extracted on-device (ML Kit) and the image never leaves your device. Only when on-device extraction is not possible is the captured or selected image sent to our server for AI processing (OpenAI, United States); it is deleted immediately after processing and is not stored on our servers.
- Pasted-text extraction: When using the extract-words-from-text feature, the passage you paste (up to 200 characters) is sent to OpenAI (United States) to extract headwords. The passage is not stored on our servers after extraction.
- Microphone/Voice: When using voice search, microphone input is forwarded to your operating system's speech recognition service (Apple/Google) for conversion to text. Only the transcribed text is used for word lookup; the audio itself is not transmitted to or stored on our servers.
- Notifications: Notification permission is used for learning reminders (daily reminders, weekly recap, per-wordlist reminders with day-of-week and time selection, and re-engagement/streak-recovery reminders when you have been inactive). All notifications are scheduled locally on your device — no notification data is sent to external servers. Per-wordlist notification settings are also stored on the server for cloud sync.
- Country/Timezone: The country and matching timezone you select during onboarding are stored. They are used for monthly usage limit calculations, notification timing, and similar features. You can change your region once per month from Settings.
- Learning progress: Per-wordlist review counts, next-review dates, and consecutive learning days (streak) are stored on your device and on the server.
- API usage logs: per-call counts, response times, costs, and error categories, keyed by your user id, for service operations and abuse prevention
- Usage analytics: to improve the service and understand feature usage, we collect screen views, key feature-usage events, a per-launch session identifier, daily in-app usage time (seconds), the app version, and the operating-system type on our own server (Supabase). This never includes word text, search terms, email, or any directly identifying / user-entered content, and is never shared with ad networks or other third parties. The legal basis is legitimate interest (GDPR Art. 6(1)(f)); you can opt out at any time from Settings.
- Age range (optional): a coarse age band you may optionally select during onboarding (e.g., 18–24, 25–34) is collected for statistics and product improvement. We do not collect your date of birth or exact age, and you can skip this. The legal basis is legitimate interest (GDPR Art. 6(1)(f)).
- Connection IP address: processed transiently per request for rate limiting to prevent abuse and excessive requests. Some external services (§4), such as advertising and web hosting, may also process your IP as part of standard access logs.
- Device push token: a device push token is collected and stored on the server to deliver push notifications such as friend requests and learning reminders (see APNs/FCM in §4).
- Login device info: to enforce the per-plan limit on concurrent signed-in devices and prevent abuse, we collect and store a random per-device identifier (generated by the app), device type/model (e.g., iPhone 15 Pro), and access timestamps. We do not collect user-assigned device names. This information is deleted when you sign out of that device.
- Error & diagnostic data: when an error occurs, device information, error logs, and a pseudonymous identifier are sent to Sentry to improve app stability. Directly identifying data such as email is removed before transmission (see §4).
- Subscription status: premium subscription state and related transaction information
- Customer inquiry data: when you contact us through the in-app inquiry form, we collect your contact email address, the inquiry content, and any attached screenshot image (optional), used to handle and respond to your inquiry.
2. Information We Do Not Collect
- Additional personal identifiers such as phone number
- GPS or precise location data
- Contacts, calendar, or health data
- Payment card information (payments are processed through Apple/Google)
3. Where Data Is Stored
Wordlists and vocabulary data are stored locally on your device (SQLite). Language settings are kept in on-device storage (AsyncStorage).
Wordlist data is securely transmitted to and stored on our server (Supabase) for cloud backup and cross-device sync.
When you look up a word, the request is processed through our server (Supabase) for AI processing. Results may be stored in an anonymous cache to improve service quality.
4. Third-Party Services and Processing Entrustment
The App uses the following external services to provide its functionality. These providers act as processors (수탁자) under Korean PIPA Article 26: under a data-processing agreement with the Provider, they process personal data only within the scope of the entrusted work and do not use it for their own purposes.
- OpenAI: The searched word and language pair are sent. When using image word extraction, an image is also transmitted only when on-device extraction is not possible. When using text word extraction, the passage you paste (up to 200 characters) is sent to extract headwords and is not stored after processing. In addition, when you publish a community/shared wordlist, its title, description, and wordlist body (words, definitions, and example sentences) are sent to OpenAI for content moderation. No user identification is transmitted.
- Anthropic (United States): When you submit a customer inquiry, the inquiry body text is sent to generate a draft reply. It is not used for any purpose other than drafting the reply.
- Microsoft Azure (Cognitive Services - Speech): For all languages except Chinese (zh-CN), the word or example sentence text is sent to Azure Neural TTS for speech synthesis. No user identification is transmitted; the synthesized audio is stored in an anonymous cache.
- Google Cloud Text-to-Speech: Chinese (zh-CN) pronunciation is synthesized via Google Cloud TTS instead of Azure. Only the word/sentence text is sent; no user identification is included.
- Supabase: Provides authentication, database, cloud sync, TTS audio caching, and API hosting
- RevenueCat: Manages in-app (iOS/Android) subscription state. Only a pseudonymous user ID and subscription information are shared; no card data.
- Paddle.com Market Limited: Payment processing as Merchant of Record and the subscription management portal, should web (moavoca.com) subscription billing be introduced in the future. Web billing is not currently offered, so no data is shared today; if introduced, the checkout email, transaction amount, country (for VAT), and pseudonymous customer/subscription IDs would be shared, and no card data reaches the operator.
- Free Dictionary API: Fallback dictionary for English lookups (only the word is sent)
- National Institute of Korean Language – Korean Basic Dictionary API (krdict.korean.go.kr, in Korea): when you look up a Korean word, only the searched word is sent. No user identification is included.
- Google Cloud Translation: To cross-check lookup quality, the looked-up word and a candidate definition are sent to Google Cloud Translation. No user identification is included.
- Google AdMob / AdSense: Displays in-app ads (AdMob) and moavoca.com web ads (AdSense) to free-tier users. Per Google's privacy policy, advertising identifiers (IDFA/GAID) or web cookies / pseudonymous identifiers and ad-interaction data may be collected, subject to your tracking/cookie consent. Premium users do not see ads.
- Apple (Sign in with Apple): When you sign in with Apple, Apple handles authentication and only the information you consent to share (email, name) is passed to the App. If you select "Hide My Email", Apple generates an anonymous relay address that is shared with us instead of your real email.
- Google (Google Sign-In): When you sign in with Google, Google handles authentication and your email and profile information are passed to the App.
- Apple Push Notification service (APNs): Delivers iOS push notifications (friend requests, learning reminders, etc.). The device push token and the notification payload (title/body) are transmitted.
- Firebase Cloud Messaging (FCM, Google): Delivers Android push notifications. The device push token and the notification payload are transmitted.
- Amazon Web Services (AWS SES): Delivers transactional email (account deletion confirmation, subscription notices, etc.). The recipient email address and the message body are transmitted.
- Sentry: Error monitoring service. Device information, error logs, and a pseudonymous identifier (your Supabase user ID) may be transmitted when errors occur; directly identifying data such as email is redacted client-side before transmission.
- Cloudflare: Hosting for the moavoca.com website (Cloudflare Pages), CDN, and DDoS protection. Standard HTTP access logs (visitor IP, User-Agent, request path) are processed.
- ImprovMX: Inbound email alias forwarding (support@, admin@). The sender address, subject, and body of incoming mail are forwarded to the operator's inbox.
- jsDelivr: CDN for the Pretendard web font used on legal and web pages. Visitor IP, User-Agent, and Referer are processed.
Beyond the above, we do not share data with third-party analytics tools, social media platforms, or data brokers. Our usage analytics (§1) use no third-party tools and are processed only on our own server (Supabase).
Transfer of personal data on business succession (Korean PIPA Article 27): If personal data is transferred due to a merger, business transfer, or conversion of the Provider from a sole proprietorship to a corporation, the Provider will, before the transfer, notify you through in-app notice and email of (i) the fact of transfer, (ii) the name and contact details of the party receiving the data, and (iii) how to withdraw consent or object if you do not want your data transferred. The receiving party will use the personal data only within the scope of the purposes existing at the time of transfer.
Where the receiving party is located outside Korea (for example, the establishment of an overseas corporation or an acquisition by a foreign operator), the Provider will, in addition to the above notice, comply with the cross-border transfer requirements of PIPA Article 28-8 (disclosing the receiving country, the time and method of transfer, and the categories of data, and obtaining consent or another lawful transfer basis where required). For EU/UK data subjects, transfers outside the European Economic Area (EEA) are protected by appropriate safeguards required under the GDPR, such as Standard Contractual Clauses (SCCs).
5. Text-to-Speech (TTS)
The pronunciation feature uses Microsoft Azure Neural TTS for all languages except Chinese (zh-CN), and Google Cloud Text-to-Speech for Chinese. The word or example sentence text is routed through our Supabase server to the relevant synthesis service, and the synthesized audio file is stored in an anonymous cache on Supabase storage so that subsequent requests for the same text reuse the cached audio. No user identification is included in TTS synthesis requests.
6. Speech Recognition
The microphone button on the word lookup screen lets you dictate a word instead of typing. Audio is processed by your operating system's speech recognition service (iOS Speech, Google Speech) and the corresponding privacy policies of Apple/Google may apply. Our app receives only the transcribed text and uses it for lookup; raw audio is not stored or transmitted by us.
7. Push Notifications
Daily learning reminders, weekly recaps, per-wordlist notifications, and — when you have been inactive for a while — re-engagement and streak-recovery reminders are all scheduled locally on your device. These notifications are scheduled based on your on-device learning state (last study date, streak status, days inactive); that state is not sent to or tracked by external servers. For per-wordlist notifications, you can pick the days of the week and time. All notifications can be disabled at any time from Settings.
8. Wordlist Export
All users can export wordlists as CSV files for free (no premium subscription required). Files are generated on-device and shared via your operating system's share sheet (email, messaging, cloud drives, etc.) to a destination you choose. No additional data is sent to our servers during export. A printable PDF study-sheet export format is additionally offered as a premium feature.
9. Public Content and Wordlist Sharing
When you share a wordlist publicly, the wordlist's name, description, word selection, and the posting user's display name and avatar become visible to all other users. Shared wordlists are treated as public information and are subject to discovery, viewing, and download by other users.
You may unshare or delete content at any time. However, copies that other users have already downloaded or copied into their own wordlists may not be automatically deleted from those copies.
The Provider may, without prior notice, hide or remove inappropriate public content. Users can flag inappropriate content through the in-app reporting system, and we act on credible reports promptly (EU DSA Art. 16). See the Terms of Service for the full content policy.
10. Friend System
Users you have added as friends may see your display name, avatar, learning statistics (study days, total words, etc.), and shared wordlists. The exact scope of visibility is shown and adjustable in the in-app settings.
Friend relationships are formed by mutual consent and may be removed or blocked at any time. After blocking, the blocked user can no longer see your content.
Friend relationship data is stored encrypted on the server and is not disclosed to third parties other than the friends themselves.
11. Profile and Avatar
Profile avatars may only be set from a Provider-supplied predefined set or as auto-generated initials. Custom photo or image upload is not supported (to prevent the risk of inappropriate content).
Display names and avatars are public information visible to other users in friend, sharing, and community feature areas.
12. Advertising Identifiers (iOS ATT / Android GAID)
On iOS, the system may show a tracking permission prompt (IDFA) the first time you launch the App. On Android, the Google Advertising ID (GAID) is used; you can limit ad personalization or reset the GAID in your device settings. Your decision affects only ad personalization — declining does not restrict the app's core functionality. Users in the EU (GDPR) and California (CCPA) will see a separate ad consent screen.
Joint controllership with Google (GDPR Art. 26): For the limited purposes of (i) collecting and presenting end-user consent for ad personalization and (ii) the joint processing carried out by AdMob/AdSense for personalized ad delivery, Funston and Google Ireland Ltd. (or its applicable Google entity) act as joint controllers within the meaning of GDPR Art. 26. Allocation of responsibilities: (a) Funston presents the consent prompt, surfaces this Privacy Policy, and forwards tracking/consent signals; (b) Google handles ad serving, measurement, security, and aggregate reporting back to Funston; (c) the parties cooperate on data-subject requests, but data subjects may exercise their GDPR rights against either Funston or Google directly. The full Google-side terms are at privacy.google.com/businesses/jointcontroller. For matters outside the joint-controllership scope (e.g., Google's own service improvement), Google acts as an independent controller under its own privacy policy.
13. Retention by Processing Purpose
We process personal data only for the purposes and retention periods set out below (Korean PIPA Article 15; GDPR Article 13(2)(a)). Our legal bases under GDPR Article 6 are, by purpose: performance of a contract (Art. 6(1)(b)) for learning, account, and subscription features, including the overseas processing by our subprocessors that is necessary to provide those online features; consent (Art. 6(1)(a)) for marketing and ad personalization; legitimate interests (Art. 6(1)(f)) for abuse prevention, security, and product-improvement usage analytics; and legal obligation (Art. 6(1)(c)) for tax and billing records.
- Provide learning features (wordlists, study progress, language settings): until account deletion
- Account authentication (email, password hash, OAuth identifiers): until account deletion
- Friend & community features (display name, friend graph, public wordlists): until you remove the content or delete the account
- Abuse prevention and API usage logs: 90 days
- Usage analytics: 12 months (legal basis: legitimate interest)
- Age band: until account deletion (legal basis: legitimate interest)
- Subscription billing records: 5 years, per Korean VAT, income-tax, and e-commerce-consumer-protection law; personal identifiers in those records are pseudonymized or de-identified
- Personalized advertising identifiers (IDFA/GAID): per the ad network's policy, up to 2 years from consent
- Crash and diagnostic logs (Sentry): 90 days
- Daily in-app usage time (learning statistics): until account deletion (collection stops if you opt out of usage analytics in Settings; legal basis: legitimate interest)
- Customer inquiry records (contact email, inquiry content, attachments): retained to handle inquiries and respond to consumer disputes, and deleted on account withdrawal; where a record constitutes a consumer complaint/dispute record under the e-Commerce Act, it is retained for 3 years and then destroyed
- One-way email hash for free-trial abuse prevention: retained for 2 years from last use even after account deletion, then destroyed; the original email cannot be recovered from this value
- Administrator access/audit logs: retained to meet security-safeguard (access-log) obligations and may include an email snapshot of the affected member; kept for up to 3 years, then destroyed
14. Data Storage and Deletion
Locally stored wordlist data is deleted when you uninstall the app. You can also delete all on-device data at any time using the "Reset" option in Settings.
If you have registered an account, you can request account deletion from the Settings screen or by email. After verifying your identity, we will permanently delete all server-stored data (email, OAuth identifiers, wordlist data, learning progress, display name, friend graph, shared wordlists, push tokens, notification settings) within 30 days. In most cases the deletion completes immediately or within minutes; technical reasons such as backup-rotation cycles may take up to 30 days.
However, to prevent repeated use of the free trial, a one-way hash of the email used at signup is retained for 2 years from the last use even after account deletion, and is then destroyed (see §13). The original email cannot be recovered from this hash. In addition, administrator access/audit logs kept as a security safeguard may be retained for the separate period described in §13.
Server data is retained after subscription cancellation until you request account deletion. Payment- and settlement-related transaction records are retained separately under §13.
If the Provider permanently discontinues the Service, we will give notice at least 30 days before the planned termination date through in-app notice and email, during which you may export your wordlists as CSV or JSON to keep your data. After termination, personal data stored on our servers is securely destroyed in accordance with applicable law; transaction records whose retention is legally mandated are pseudonymized or de-identified and retained for the required period before destruction.
Method of destruction: electronic personal data is permanently erased by technical means that prevent recovery; any personal data printed on paper is shredded or incinerated.
15. International Data Transfers
Some processors listed in §4 process personal data outside the Republic of Korea (Korean PIPA Article 28-8 disclosure).
- Recipients: the processors listed in §4 (Supabase, OpenAI, Anthropic, Microsoft Azure, Google (Cloud TTS, Cloud Translation, AdMob/AdSense, Sign-In), Apple, RevenueCat, Paddle.com Market Limited, Sentry, AWS, Cloudflare, ImprovMX, jsDelivr, freedictionaryapi.com)
- Recipient country: primarily the United States; Azure uses the United States (East US); Paddle in Ireland/UK (US fallback); ImprovMX in Czech Republic/EU; Cloudflare and jsDelivr at the nearest global edge
- Time and method of transfer: continuously, via encrypted HTTPS/TLS, at the time the relevant feature is used
- Categories of data: as detailed per processor in §4
- Purpose: as detailed per processor in §4
- Retention by recipients: per each processor's own policy; we instruct them to delete on request
The Service (web, iOS, and Android) requires sign-in to use, and the overseas transfers to the external services listed in §4 are necessary to provide the Service. If you do not want your data transferred overseas, you may choose not to sign up for or use the Service; if you have already created an account, you can request account deletion or withdraw consent through the process described in §16.
Note: the Republic of Korea is the subject of a 2021 EU Commission adequacy decision, so transfers between Korea and the EU are recognized as providing an adequate level of protection. Transfers to other countries (e.g., the United States) rely on lawful transfer mechanisms such as data-processing agreements and Standard Contractual Clauses (SCCs).
16. Your Rights
Regardless of where you live, you have the following rights over your personal data (Korean PIPA Articles 35–37; GDPR Articles 15–22; CCPA §§1798.100 et seq.).
- Right of access — request a copy of the personal data we hold about you
- Right to correction / deletion — correct inaccurate data or request erasure. In-app: Settings → Account → Delete Account. By email: a request from your registered address
- Right to restriction of processing
- Right to data portability — receive your data in a machine-readable format. All users can export wordlists as CSV in-app for free; the main account data can be exported instantly as JSON in-app (Settings → Account → Export data). Any remaining items not included in the in-app export (for example, device-session and usage-time records) are provided within 30 days on email request
- Right to withdraw consent at any time, without affecting prior processing
- No solely automated decision-making — we do not make decisions producing legal effects on you based solely on automated processing
- Right to opt out of sale/sharing (California CCPA/CPRA) — we do not "sell" personal information for monetary consideration. Any "sharing" for cross-context behavioral advertising is limited to the consent-based ads described in §12; you may exercise your "Do Not Sell or Share My Personal Information" right by declining ad consent or using your device's ad-tracking limit setting. On our website (moavoca.com) we also honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sharing. You may also request limitation of the use of sensitive personal information by email; additional requests may be sent by email.
How to exercise: where available, use the in-app controls; otherwise email support@moavoca.com with sufficient information to verify your identity. We respond within 30 days. If we decline, we will explain why and how to appeal.
You may also lodge a complaint with your data-protection authority: the Personal Information Protection Commission of Korea (privacy.go.kr) and KISA (privacy.kisa.or.kr, ☎ 118) for Korea; your national supervisory authority for the EU; the ICO for the UK; or exercise CCPA rights as a California resident.
17. Security Measures and Breach Notification
We implement the following technical and organizational safeguards.
- All server connections use TLS 1.2 or higher
- Authentication tokens are stored in iOS Keychain or Android EncryptedSharedPreferences — never plaintext AsyncStorage
- Service-role keys never leave the server
- Periodic security audits and prompt hardening updates (latest audit: June 2026)
In the event of a personal-data breach, we will notify affected users and the relevant supervisory authority without undue delay, and within 72 hours where required by applicable law (Korean PIPA Article 34; GDPR Articles 33–34; CCPA §1798.82).
18. Accounts and Authentication
Using the App requires signing in with email + password, Apple Sign In, or Google Sign-In (on web, iOS, and Android alike). After signing in, you can use cloud sync, friends/community, and premium features.
Email verification is required during email registration. Passwords are stored only as one-way salted hashes on Supabase Auth and cannot be viewed by the Provider.
When signing in with Google, your Google account email address and profile information (name) are collected. Your Google password is not processed by the App.
When signing in with Apple, the email address and name linked to your Apple ID are collected. If you choose "Hide My Email", Apple generates an anonymous relay address that is provided to us instead of your real email — we cannot see your real email address. Apple handles password and authentication.
19. EU / UK Representative
The Provider has not currently designated a GDPR Article 27 representative in the EU or UK and will consider appointing one if and when required. EU and UK data subjects may exercise their GDPR rights by contacting us directly at the email below.
20. Children's Privacy
The App is rated 12+ on the App Store and Teen on Google Play and is not directed at children. The Service is not available to children under 14 (per Korean PIPA / 정보통신망법), under 13 (per US COPPA), or under the higher minimum age of digital consent required by the user's country of residence (for example, 16 in Germany and the Netherlands, 20 in Thailand). If we become aware of personal information collected from a child below the applicable age, we will delete it promptly. Please contact us at support@moavoca.com if you believe a child has provided personal data.
21. Changes to This Policy
If this Privacy Policy is updated, we will notify you through an in-app notice prior to the changes taking effect.
This policy was last updated on July 12, 2026.
22. Contact Us
For privacy-related inquiries, please reach out by email.
Email: support@moavoca.com
개인정보처리방침
시행일: 2026-07-12
개인정보처리자
- 상호: 펀스턴 (Funston)
- 대표자 / 개인정보 보호책임자: 박준성
- 사업자등록번호: 774-17-02956
- 통신판매업 신고: 제2026-서울구로-0893호
- 주소: 서울특별시 구로구 구로중앙로 207, B1층 B36-S77호, 오퍼스1 (우편번호 08216)
- 호스팅 제공자: Cloudflare, Inc.(웹사이트) · Supabase Inc. 및 Amazon Web Services(백엔드)
- 전화: +82-10-9966-3457
- 이메일: support@moavoca.com
본 서비스의 개인정보처리자는 펀스턴 (박준성)이며, 개인정보 보호책임자도 동일합니다. MoaVoca(이하 "앱")는 대한민국에 등록된 개인사업자 펀스턴이 운영합니다. 본 개인정보처리방침은 개인정보보호법(PIPA), EU/영국 GDPR, 캘리포니아 CCPA에 따라 수집하는 정보, 이용 방법 및 정보주체의 권리를 설명합니다.
개인정보 관련 문의: support@moavoca.com
1. 수집하는 정보
MoaVoca(이하 "앱")는 서비스 제공을 위해 아래 정보를 수집합니다.
- 이메일 주소: 계정 등록 및 로그인 시 수집됩니다. 본 서비스 이용에는 로그인이 필요하며(이메일·Google·Apple 중 택1), 선택한 로그인 방식에 해당하는 이메일이 수집됩니다.
- 비밀번호: 이메일 계정 인증 목적으로 수집되며, Supabase Auth에 단방향 솔티드 해시(salted hash) 형태로만 저장되어 운영자도 원문을 확인할 수 없습니다
- Google 프로필 정보: Google 로그인을 선택한 경우 이메일 주소와 이름이 Google을 통해 전달됩니다.
- Apple 계정 정보: Apple 로그인을 선택한 경우 Apple ID에 연결된 이메일 주소와 이름이 전달됩니다. "Hide My Email" 사용 시 Apple이 생성한 익명 릴레이 주소만 전달받으며, 사용자의 실제 이메일 주소는 알 수 없습니다.
- 표시 이름(닉네임) 및 사용자명(@아이디): 친구·공유 기능에서 다른 사용자에게 노출되는 이름과 아이디. 사용자명(@아이디)은 다른 이용자가 검색하여 친구 추가할 수 있습니다. 모두 사용자가 직접 설정합니다.
- 아바타 선택: 운영자가 제공하는 미리 만들어진 아바타 세트 또는 자동 생성된 이니셜 중에서 선택한 정보. 임의 사진 업로드 기능은 제공하지 않습니다.
- 언어 설정: 모국어, 원서 언어, 번역 언어
- 단어장 정보: 단어장 이름, 저장한 단어 및 AI 생성 정의
- 공유 단어장: 사용자가 다른 이용자가 볼 수 있도록 공유한 단어장 (이름, 설명, 단어 구성)
- 친구 관계: 사용자가 추가/수락/차단/친구 요청/콕 찌르기(poke)한 다른 이용자 목록
- 기기 언어: 앱 초기 언어 설정을 위해 1회 확인 (서버 전송 없음)
- 카메라/사진: 이미지 단어 추출 기능 사용 시, 기본적으로 기기 내(온디바이스 ML Kit)에서 텍스트를 추출하며 이미지가 기기를 벗어나지 않습니다. 온디바이스 추출이 어려운 경우에 한해 촬영·선택한 이미지가 AI 처리(OpenAI, 미국)를 위해 서버로 전송되며, 처리 후 즉시 삭제되고 서버에 저장되지 않습니다.
- 붙여넣기 텍스트 추출: 텍스트에서 단어를 추출하는 기능 사용 시, 붙여넣으신 지문(최대 200자)이 표제어 추출을 위해 OpenAI(미국)로 전송됩니다. 추출 처리 후 지문은 서버에 저장되지 않습니다.
- 마이크/음성: 음성 검색 기능 사용 시 마이크 입력이 기기 운영체제(Apple/Google)의 음성 인식 서비스로 전달되어 텍스트로 변환됩니다. 플랫폼 설정에 따라 운영체제가 기기 내에서 처리하거나 음성을 Apple/Google 서버로 전송하여 변환할 수 있으며, 이 경우 Apple/Google의 개인정보처리방침이 적용됩니다. 변환된 텍스트만 단어 검색에 사용되며, 음성 데이터 자체는 앱 서버로 전송·저장되지 않습니다.
- 알림: 학습 리마인더(전체 일일 알림, 주간 요약, 단어장별 요일/시각 알림, 휴면 시 재참여·스트릭 복귀 알림)를 발송하기 위해 알림 권한이 사용됩니다. 모든 알림은 기기에 로컬로 예약되며 외부 서버로 데이터가 전송되지 않습니다. 단어장별 알림 설정(요일/시각)은 클라우드 동기화를 위해 서버에도 저장됩니다.
- 거주 국가/시간대: 온보딩 시 선택한 거주 국가와 그에 대응하는 시간대가 저장됩니다. 월간 사용량 한도 산정 및 알림 시각 등에 사용됩니다. 설정에서 월 1회 변경 가능합니다.
- 학습 진도: 단어장별 복습 횟수, 다음 복습 예정일, 연속 학습 일수(스트릭) 등 학습 데이터가 기기와 서버에 저장됩니다.
- API 사용 기록: 단어 검색 횟수, 응답 시간, 비용 (서비스 운영 목적)
- 서비스 이용내역(사용 통계): 서비스 개선과 기능 사용 현황 분석을 위해 화면 조회·주요 기능 사용 이벤트, 세션 식별자(앱 실행마다 생성), 일별 앱 사용 시간(초), 앱 버전, 운영체제 구분이 운영자 자체 서버(Supabase)에 수집됩니다. 단어 원문·검색어·이메일 등 직접적인 개인 식별 정보나 입력 콘텐츠는 포함되지 않으며, 광고 네트워크 등 제3자와 공유되지 않습니다. 법적 근거는 정당한 이익(GDPR 제6조 (1)(f))이며, 설정 화면에서 언제든 수집을 거부(opt-out)할 수 있습니다.
- API 사용 로그: 호출 횟수, 응답 시간, 비용, 오류 유형이 사용자 ID에 연결되어 서비스 운영 및 악용 방지 목적으로 기록됩니다.
- 연령대(선택): 온보딩에서 사용자가 선택적으로 제공하는 대략적 연령대 구간(예: 18–24, 25–34 등)이 통계 및 서비스 개선 목적으로 수집됩니다. 생년월일이나 정확한 나이는 수집하지 않으며, 선택 사항으로 건너뛸 수 있습니다. 법적 근거는 정당한 이익(GDPR 제6조 (1)(f))입니다.
- 접속 IP 주소: 부정 이용·과도한 요청 방지를 위한 속도 제한(rate limiting) 목적으로 요청 시 일시적으로 처리됩니다. 광고·웹 호스팅 등 일부 외부 서비스(§4)도 표준 접속 로그로 IP를 처리할 수 있습니다.
- 디바이스 푸시 토큰: 친구 요청·학습 리마인더 등 푸시 알림 발송을 위해 기기 푸시 토큰이 수집되어 서버에 저장됩니다(§4의 APNs/FCM 참조).
- 로그인 기기 정보: 요금제별 동시 로그인 기기 수 제한 및 부정 이용 방지를 위해 기기별 임의 식별자(앱이 생성한 무작위 값), 기기 유형·모델(예: iPhone 15 Pro), 접속 일시가 수집·저장됩니다. 이용자가 지정한 기기 이름은 수집하지 않습니다. 해당 기기에서 로그아웃하면 관련 정보는 삭제됩니다.
- 오류·진단 데이터: 앱 안정성 개선을 위해 오류 발생 시 기기 정보·오류 로그와 가명 식별자가 Sentry로 전송됩니다. 이메일 등 직접적인 개인 식별 정보는 전송 전 제거됩니다(§4 참조).
- 구독 상태: 프리미엄 구독 여부 및 관련 거래 정보
- 고객 문의 정보: 인앱 문의 폼으로 문의하실 때 연락용 이메일 주소, 문의 내용, 첨부하신 스크린샷 이미지(선택)를 수집하며, 문의 처리·응대 목적으로 이용합니다.
2. 수집하지 않는 정보
- 전화번호 등 추가 개인 식별 정보
- 위치 정보(GPS) 및 정밀 위치
- 연락처, 캘린더, 건강 데이터
- 결제 카드 정보 (결제는 Apple/Google을 통해 처리됩니다)
3. 정보의 저장 위치
단어장과 단어 데이터는 기기 내부(SQLite)에 저장됩니다. 언어 설정은 기기 내부 저장소(AsyncStorage)에 보관됩니다.
클라우드 백업 및 동기화를 위해 단어장 데이터가 서버(Supabase)에 암호화 전송 후 저장됩니다.
단어 검색 시 AI 처리를 위해 서버(Supabase)를 경유하며, 검색 결과는 서비스 품질 향상을 위해 익명 캐시로 저장될 수 있습니다.
4. 제3자 제공 및 처리위탁
앱은 서비스 제공을 위해 아래 외부 서비스를 이용합니다. 아래 업체는 개인정보보호법 제26조에 따른 수탁자로서, 운영자와의 위탁계약에 따라 명시된 위탁업무 범위 내에서만 개인정보를 처리하며 자체 목적으로 이용하지 않습니다.
- OpenAI: 검색한 단어와 언어쌍 정보가 전달됩니다. 이미지 단어 추출 기능 사용 시 온디바이스 추출이 어려운 경우에 한해 이미지가 함께 전송됩니다. 텍스트 단어 추출 기능 사용 시 붙여넣으신 지문(최대 200자)이 표제어 추출을 위해 전송되며, 처리 후 저장되지 않습니다. 또한 커뮤니티·공유 단어장을 게시할 때 제목·설명 및 단어장 본문(단어·정의·예문)이 유해성 검열(콘텐츠 모더레이션)을 위해 OpenAI로 전송됩니다. 사용자 식별 정보는 전송되지 않습니다.
- Anthropic(미국): 고객 문의 접수 시 AI 회신 초안 생성을 위해 문의 본문 텍스트가 전송됩니다. 회신 초안 작성 외의 목적으로 이용되지 않습니다.
- Microsoft Azure (Cognitive Services - Speech): 발음 듣기(TTS) 기능 사용 시 중국어(zh-CN)를 제외한 언어의 단어·예문 텍스트가 Azure Neural TTS 서비스로 전달되어 음성으로 합성됩니다. 사용자 식별 정보는 전송되지 않으며, 생성된 음성은 익명 캐시로 저장됩니다.
- Google Cloud Text-to-Speech: 중국어(zh-CN) 발음은 Azure 대신 Google Cloud TTS로 합성됩니다. 단어·예문 텍스트만 전달되며 사용자 식별 정보는 포함되지 않습니다.
- Supabase: 인증, 데이터베이스, 클라우드 동기화, TTS 음성 캐시 및 API 호스팅 서비스 제공
- RevenueCat: 앱(iOS/Android) 구독 결제 상태 관리. 가명 사용자 ID와 구독 정보만 전달되며, 카드 정보는 전달되지 않습니다.
- Paddle.com Market Limited: 추후 moavoca.com 웹 구독 결제(판매대행자/Merchant of Record)가 도입되는 경우의 결제 처리 및 구독 관리 포털. 현재 웹 결제는 제공하지 않아 데이터가 전달되지 않으며, 도입 시 결제 시 입력한 이메일, 거래 금액, VAT 산정용 국가, 가명 고객·구독 식별자가 전달되고 카드 정보는 운영자에게 전달되지 않습니다.
- Free Dictionary API: 영어 단어 검색 실패 시 대체 사전 (단어만 전송)
- 국립국어원 한국어기초사전 API(krdict.korean.go.kr, 국내): 한국어 단어를 검색할 때 검색한 단어만 전송됩니다. 사용자 식별 정보는 포함되지 않습니다.
- Google Cloud Translation: 단어 조회 결과의 품질 교차검증을 위해 조회한 단어와 후보 정의문이 Google Cloud Translation으로 전달됩니다. 사용자 식별 정보는 포함되지 않습니다.
- Google AdMob / AdSense: 무료 사용자에게 앱 내 광고(AdMob)와 moavoca.com 웹 광고(AdSense)를 표시합니다. Google 개인정보처리방침에 따라 광고 식별자(IDFA/GAID) 또는 웹 쿠키·가명 식별자, 광고 상호작용 데이터를 수집할 수 있으며, 추적/쿠키 동의 여부에 따릅니다. 프리미엄 사용자에게는 광고가 표시되지 않습니다.
- Apple (Sign in with Apple): Apple 로그인 시 Apple이 인증을 처리하고, 사용자가 동의한 정보(이메일, 이름)만 앱으로 전달됩니다. "Hide My Email" 선택 시 Apple이 익명 릴레이 주소를 생성하여 전달합니다.
- Google (Google Sign-In): Google 로그인 시 Google이 인증을 처리하고, 이메일과 프로필 정보가 전달됩니다.
- Apple Push Notification service (APNs): iOS 푸시 알림(친구 요청, 학습 리마인더 등) 전송을 위해 기기 푸시 토큰과 알림 내용(제목·본문)이 전달됩니다.
- Firebase Cloud Messaging (FCM, Google): Android 푸시 알림 전송을 위해 기기 푸시 토큰과 알림 내용이 전달됩니다.
- Amazon Web Services (AWS SES): 거래성 이메일(계정 삭제 확인, 구독 안내 등) 발송. 수신자 이메일 주소와 메일 본문이 전달됩니다.
- Sentry: 앱 오류 모니터링 서비스. 오류 발생 시 기기 정보, 오류 로그와 가명 식별자(Supabase 사용자 ID)가 전송될 수 있으며, 이메일 등 직접적인 개인 식별 정보는 클라이언트에서 제거 후 전송됩니다.
- Cloudflare: moavoca.com 웹사이트 호스팅(Cloudflare Pages), CDN 및 DDoS 방어. 표준 HTTP 접속 로그(방문 IP, User-Agent, 요청 경로)가 처리됩니다.
- ImprovMX: 수신 이메일(support@·admin@) 별칭 전달 서비스. 발신자 주소·제목·본문이 운영자 메일함으로 전달됩니다.
- jsDelivr: 법적 고지 등 웹 페이지에서 사용하는 Pretendard 웹폰트의 CDN. 방문 IP·User-Agent·Referer가 처리됩니다.
위 외에 제3자 분석 도구, 소셜 미디어, 데이터 브로커 등에 데이터를 공유하지 않습니다. 서비스 이용 통계(§1)는 제3자 도구를 사용하지 않고 운영자 자체 서버(Supabase)에서만 처리됩니다.
영업양도 등에 따른 개인정보 이전(개인정보보호법 제27조): 운영자의 합병·영업양도, 또는 개인사업자에서 법인으로의 전환 등으로 개인정보가 이전되는 경우, 운영자는 이전 전에 (i) 이전 사실, (ii) 개인정보를 이전받는 자의 명칭·연락처, (iii) 정보주체가 동의를 철회하거나 이전을 원하지 않을 경우의 조치 방법을 앱 내 공지 및 이메일을 통해 사전에 통지합니다. 개인정보를 이전받는 자는 이전 당시의 이용 목적 범위 내에서만 개인정보를 이용합니다.
개인정보를 이전받는 자가 국외에 있는 경우(예: 해외 법인 설립 또는 해외 사업자에 의한 인수·합병), 운영자는 위 통지에 더하여 개인정보의 국외이전에 관한 개인정보보호법 제28조의8의 요건(이전받는 국가, 이전 일시·방법, 이전 항목의 고지 및 필요한 경우 동의 또는 그 밖의 적법한 이전 근거 확보)을 준수합니다. EU·영국 정보주체의 개인정보를 유럽경제지역(EEA) 밖으로 이전하는 경우에는 표준계약조항(SCC) 등 GDPR이 요구하는 적절한 보호조치를 적용합니다.
5. 음성 합성(TTS)
발음 듣기 기능은 중국어(zh-CN)를 제외한 언어에 대해 Microsoft Azure Neural TTS를, 중국어에 대해서는 Google Cloud Text-to-Speech를 사용하여 음성을 합성합니다. 단어 또는 예문 텍스트가 Supabase 서버를 경유하여 해당 합성 서비스로 전달되며, 합성된 음성 파일은 Supabase 저장소에 익명 캐시로 보관되어 동일한 단어를 다시 요청할 때 재사용됩니다. 사용자 식별 정보는 음성 합성 요청에 포함되지 않습니다.
6. 음성 인식
단어 검색 화면에서 마이크 버튼으로 음성 입력을 사용할 수 있습니다. 음성은 운영체제가 제공하는 음성 인식 서비스(iOS Speech, Google Speech)에서 처리되며, Apple/Google의 개인정보처리방침이 적용될 수 있습니다. 앱은 인식 결과 텍스트만 받아 검색에 사용하고, 음성 데이터를 별도로 저장하거나 외부로 전송하지 않습니다.
7. 푸시 알림
일일 학습 리마인더, 주간 학습 요약, 단어장별 알림, 그리고 한동안 학습하지 않은 경우의 재참여 알림·연속 학습(스트릭) 복귀 알림 등은 모두 기기에 로컬로 예약되어 표시되는 알림입니다. 이러한 알림은 기기 내 로컬 학습 상태(마지막 학습일·스트릭 상태·휴면 일수)에 따라 예약되며, 해당 상태 정보는 외부 서버로 전송되거나 추적되지 않습니다. 단어장별 알림은 사용자가 직접 요일과 시각을 선택할 수 있고, 모든 알림은 설정에서 언제든 비활성화할 수 있습니다.
8. 단어장 내보내기
모든 사용자는 단어장을 CSV 파일로 무료로 내보낼 수 있습니다(프리미엄 가입이 필요하지 않습니다). 파일은 기기 내에서 생성되어 운영체제의 공유 시트(이메일, 메시지, 클라우드 드라이브 등)를 통해 사용자가 직접 선택한 곳으로 전달됩니다. 내보내기 과정에서 앱 서버로 추가 데이터가 전송되지 않습니다. 인쇄용 PDF 학습지 형식의 내보내기는 프리미엄 혜택으로 추가 제공됩니다.
9. 공개 콘텐츠 및 단어장 공유
이용자가 단어장을 공유 기능을 통해 공개하면, 해당 단어장의 이름·설명·단어 구성과 게시한 사용자의 표시 이름·아바타가 다른 모든 이용자에게 표시됩니다. 공유 단어장은 공개 정보로 취급되며, 검색·열람·다운로드의 대상이 됩니다.
사용자는 언제든 공유를 해제하거나 콘텐츠를 삭제할 수 있습니다. 다만 다른 이용자가 이미 다운로드하거나 자신의 단어장에 복사한 콘텐츠는 그 이용자의 사본에서 자동 삭제되지 않을 수 있습니다.
운영자는 부적절한 공개 콘텐츠를 사전 통지 없이 비공개·삭제할 수 있으며, 신고 시스템을 통해 사용자가 부적절한 콘텐츠를 알릴 수 있습니다. 신뢰할 만한 신고에 대해서는 신속히 조치합니다(EU 디지털 서비스법 제16조). 자세한 콘텐츠 정책은 이용약관을 참고하세요.
10. 친구 시스템
친구로 등록된 다른 이용자에게는 사용자의 표시 이름, 아바타, 학습 통계(학습 일수, 누적 단어 수 등), 공유 단어장이 표시될 수 있습니다. 구체적 공개 범위는 앱 내 설정에서 확인하고 조정할 수 있습니다.
친구 추가는 양방향 동의로 성립하며, 친구 관계는 언제든 해제하거나 차단할 수 있습니다. 차단한 사용자에게는 사용자의 콘텐츠가 더 이상 표시되지 않습니다.
친구 관계 정보는 서버에 암호화 저장되며, 친구 본인이 아닌 제3자에게는 공개되지 않습니다.
11. 프로필 및 아바타
이용자의 프로필 아바타는 운영자가 제공하는 미리 만들어진 세트 또는 자동 생성된 이니셜로만 설정할 수 있습니다. 사용자가 임의로 사진·이미지를 업로드하는 기능은 제공하지 않습니다(부적절한 콘텐츠 위험 방지 목적).
표시 이름과 아바타는 다른 사용자가 볼 수 있는 공개 정보입니다. 친구·공유·게시판 등 사회적 기능 영역에서 노출됩니다.
12. 광고 식별자 (iOS ATT / Android GAID)
iOS에서는 처음 앱 실행 시 광고 식별자(IDFA) 사용 동의를 묻는 시스템 팝업이 표시될 수 있습니다. Android에서는 Google 광고 ID(GAID)가 사용되며, 기기 설정에서 광고 개인화를 제한하거나 광고 ID를 재설정할 수 있습니다. 동의/허용 여부는 광고 개인화 정도에만 영향을 미치며, 거부하더라도 앱의 기본 기능 사용에는 제한이 없습니다. 유럽(GDPR) 및 캘리포니아(CCPA) 지역 사용자에게는 별도의 광고 개인정보 동의 화면이 표시됩니다.
Google과의 공동관리자 관계(GDPR 제26조): (i) 광고 개인화에 대한 최종 이용자 동의의 수집·표시, (ii) AdMob/AdSense의 개인 맞춤형 광고 전달을 위한 공동 처리에 한하여, 펀스턴(Funston)과 Google Ireland Ltd.(또는 해당 Google 법인)는 GDPR 제26조상 공동관리자(joint controllers)에 해당합니다. 역할 분담: (a) 펀스턴은 동의 화면 표시, 본 처리방침 안내, 추적/동의 신호 전달을 담당하고, (b) Google은 광고 게재·측정·보안 및 집계 리포트 제공을 담당하며, (c) 정보주체 요청에 양사가 협력하되, 정보주체는 펀스턴 또는 Google 중 어느 쪽에든 직접 GDPR 권리를 행사할 수 있습니다. Google 측 약정 전문은 privacy.google.com/businesses/jointcontroller에서 확인할 수 있습니다. 공동관리 범위를 벗어난 처리(예: Google 자체 서비스 개선)에 대해서는 Google이 자체 처리방침에 따른 독립 관리자로 행위합니다.
13. 처리 목적별 보관 기간
운영자는 개인정보보호법 제15조에 따라 수집한 개인정보를 아래 목적·기간 내에서만 처리합니다. 처리의 법적 근거(GDPR 제6조)는 항목별로 다음과 같습니다: 학습·계정·구독 등 서비스 제공과 이를 위해 필요한 위탁업체의 국외 처리는 계약 이행(제6조 (1)(b)), 마케팅·광고 개인화는 동의(제6조 (1)(a)), 부정 이용 방지·보안·서비스 개선을 위한 이용 통계는 정당한 이익(제6조 (1)(f)), 세금·결제 기록 보관은 법적 의무(제6조 (1)(c))에 근거합니다.
- 학습 기능 제공(단어장·진도·언어 설정 등): 회원 탈퇴 시까지
- 계정 인증(이메일, 비밀번호 해시, OAuth 식별자): 회원 탈퇴 시까지
- 친구·커뮤니티 기능(표시 이름, 친구 관계, 공유 단어장): 사용자가 삭제하거나 탈퇴 시까지
- 부정 이용 방지·API 사용 기록: 90일
- 서비스 이용내역(사용 통계): 12개월 (법적 근거: 정당한 이익)
- 연령대(age band): 회원 탈퇴 시까지 (법적 근거: 정당한 이익)
- 결제·정산 거래 기록: 부가가치세법·소득세법·전자상거래법 등에 따라 5년 보관 후 파기. 보관 기간 중 개인 식별 정보는 가명·비식별화 처리
- 개인 맞춤형 광고 식별자(IDFA/GAID): 동의 시점부터 광고 네트워크 정책상 최대 2년
- 오류·진단 로그(Sentry): 90일
- 일별 앱 사용 시간(학습 통계): 회원 탈퇴 시까지 (설정에서 사용 통계 수집을 거부하면 함께 중단됩니다. 법적 근거: 정당한 이익)
- 고객 문의 기록(연락용 이메일·문의 내용·첨부 이미지): 문의 처리 및 소비자 분쟁 대응 목적으로 보관하며 회원 탈퇴 시 삭제합니다. 다만 전자상거래법상 소비자의 불만·분쟁 처리에 관한 기록에 해당하는 경우 관련 법령에 따라 3년간 보관 후 파기합니다.
- 무료 체험 중복 방지용 이메일 일방향 해시값: 회원 탈퇴 후에도 최종 이용일로부터 2년간 보관 후 파기합니다. 이 값으로는 원문 이메일을 복원할 수 없습니다.
- 관리자 접근·감사 기록: 개인정보 안전성 확보조치(접근기록 보관) 목적으로 관리자 작업 로그가 보존되며, 여기에는 처리 대상 회원의 이메일 스냅샷이 포함될 수 있습니다. 최대 3년간 보관 후 파기합니다.
14. 데이터 보관 및 삭제
기기에 저장된 단어장 데이터는 앱 삭제 시 함께 삭제됩니다. 설정 화면의 "초기화" 기능을 통해 언제든 기기 내 모든 데이터를 삭제할 수 있습니다.
계정을 등록한 사용자는 설정 화면에서 계정 삭제를 요청할 수 있으며, 운영자는 본인 확인 후 30일 이내에 서버에 저장된 이메일, OAuth 식별자, 단어장 데이터, 학습 진도, 표시 이름, 친구 관계, 공유 단어장, 푸시 토큰, 알림 설정 등 모든 정보를 영구 삭제합니다. 통상 즉시 또는 수 분 내 처리되나 백업·복구 사이클 등 기술적 사유로 최대 30일이 소요될 수 있습니다.
다만 무료 체험의 중복 사용을 방지하기 위해, 가입 시 사용한 이메일의 일방향 해시값은 계정 삭제 후에도 최종 이용일로부터 2년간 보관되며 이후 파기됩니다(§13 참조). 이 해시값으로는 원문 이메일을 복원할 수 없습니다. 또한 개인정보 안전성 확보조치를 위한 관리자 접근·감사 기록은 §13에 따라 별도 기간 동안 보존될 수 있습니다.
구독 해지 후에도 서버 데이터는 계정 삭제를 요청할 때까지 보관됩니다. 결제·정산 관련 거래 기록은 위 §13에 따라 별도 보관됩니다.
운영자가 서비스를 영구적으로 종료하는 경우, 종료 예정일 최소 30일 전에 앱 내 공지와 이메일을 통해 안내하며, 이용자는 그 기간 동안 단어장을 CSV 또는 JSON으로 내보내어 데이터를 보관할 수 있습니다. 종료 후 서버에 저장된 개인정보는 관련 법령에 따라 안전하게 파기되며, 법령상 보관이 의무화된 거래 기록은 가명·비식별 처리하여 해당 기간 동안 보관 후 파기합니다.
파기 방법: 전자적 파일 형태로 저장된 개인정보는 복구·재생이 불가능한 기술적 방법(영구 삭제)으로 파기하며, 종이에 출력·기록된 개인정보가 있는 경우 분쇄하거나 소각하여 파기합니다(개인정보보호법 시행령 제16조).
15. 개인정보의 국외이전
본 서비스는 §4에 열거된 외부 서비스를 이용하는 과정에서 사용자의 개인정보를 대한민국 외 국가로 이전합니다(개인정보보호법 제28조의8 고지 사항).
- 이전받는 자: §4에 명시된 처리 위탁업체(Supabase, OpenAI, Anthropic, Microsoft Azure, Google(Cloud TTS·Cloud Translation·AdMob/AdSense·로그인), Apple, RevenueCat, Paddle.com Market Limited, Sentry, AWS, Cloudflare, ImprovMX, jsDelivr, freedictionaryapi.com)
- 이전되는 국가: 주로 미국. Azure는 미국(East US), Paddle은 아일랜드·영국(미국 보조), ImprovMX는 체코·EU, Cloudflare·jsDelivr는 가장 가까운 글로벌 엣지
- 이전 시점·방법: 사용자가 해당 기능을 이용하는 시점에 HTTPS/TLS 암호화 통신을 통해 지속적으로 이전
- 이전 항목: 위탁업체별로 §4에 기재된 항목 범위 내
- 이전 목적: §4의 각 위탁업체 목적란에 기재
- 이전받는 자의 보관 기간: 각 위탁업체의 자체 보관 정책에 따르며, 운영자는 삭제 요청을 위탁업체에 전달합니다
본 서비스(웹·iOS·Android)는 이용에 로그인이 필요하며, §4에 열거된 외부 서비스로의 국외이전은 서비스 제공을 위해 불가피합니다. 국외이전을 원하지 않으시는 경우 서비스에 가입·이용하지 않으실 수 있으며, 이미 가입한 사용자는 §16의 절차에 따라 계정 삭제 또는 동의 철회를 요청할 수 있습니다.
참고: 대한민국은 2021년 EU 집행위원회의 적정성 결정(adequacy decision) 대상국으로, 한국과 EU 간 개인정보 이전에 대해 적절한 보호 수준이 인정됩니다. 미국 등 그 외 국가로의 이전은 위탁계약 및 표준계약조항(SCC) 등 적법한 이전 수단에 따릅니다.
16. 정보주체의 권리
거주 지역에 관계없이 사용자는 자신의 개인정보에 대해 아래 권리를 행사할 수 있습니다(개인정보보호법 제35조 이하, GDPR 제15-22조, CCPA §1798.100 이하).
- 열람권 — 운영자가 보유한 본인의 개인정보 사본 요청
- 정정·삭제권 — 부정확한 정보의 정정 또는 삭제 요청. 계정 삭제는 설정 → 계정 → 계정 삭제 메뉴 또는 이메일 요청
- 처리정지권 — 처리에 대한 일시적 또는 영구적 정지 요청
- 이동권 — 본인이 제공한 데이터를 기계 판독 가능한 형식으로 받을 권리. 모든 사용자는 앱 내에서 단어장을 CSV로 무료로 내보낼 수 있으며, 주요 계정 데이터는 앱 내(설정 → 계정 → 데이터 내보내기)에서 JSON으로 즉시 내보낼 수 있습니다. 앱 내 내보내기에 포함되지 않는 그 밖의 항목(예: 기기 세션·사용 시간 기록 등)은 이메일 요청 시 30일 이내에 제공합니다
- 동의 철회권 — 이미 처리된 부분에 영향을 주지 않는 범위에서 언제든 동의 철회
- 자동화된 결정 거부권 — 운영자는 사용자에 대해 자동화된 의사결정만으로 법적 효과를 야기하는 처리는 하지 않습니다
- 판매·공유 거부권(캘리포니아 CCPA/CPRA) — 운영자는 개인정보를 금전적 대가를 받고 "판매"하지 않습니다. 교차맥락 행동 광고를 위한 "공유"는 §12의 동의 기반 광고에 한하며, 사용자는 광고 동의를 거부하거나 기기의 광고 추적 제한 설정을 통해 "Do Not Sell or Share My Personal Information" 권리를 행사할 수 있습니다. 또한 웹사이트(moavoca.com)에서는 브라우저의 GPC(Global Privacy Control) 신호를 유효한 판매·공유 거부 의사로 인정하여 처리합니다. 민감정보의 이용 제한 요청을 포함한 추가 요청은 이메일로 접수합니다.
권리 행사 방법: 앱 내 설정에서 가능한 경우 직접 처리하거나, support@moavoca.com로 본인 확인이 가능한 정보와 함께 이메일을 보내주시면 통상 30일 이내에 답변드립니다. 행사 거부 시 그 사유와 이의 제기 방법을 함께 통지합니다.
개인정보 처리에 관한 불만은 개인정보보호위원회(privacy.go.kr) 및 한국인터넷진흥원(KISA) 개인정보침해신고센터(privacy.kisa.or.kr · ☎ 118)에 신고할 수 있습니다. 개인정보 분쟁의 조정이 필요한 경우 개인정보분쟁조정위원회(kopico.go.kr · ☎ 1833-6972)에 조정을 신청할 수 있으며, 개인정보 침해는 경찰청 사이버수사국(ecrm.police.go.kr · ☎ 182) 또는 대검찰청 사이버수사과(☎ 1301)에도 신고할 수 있습니다. EU 거주자는 거주국 감독기관에, 영국 거주자는 ICO에, 캘리포니아 거주자는 CCPA 권리를 행사할 수 있습니다.
17. 보안 조치 및 침해 통지
운영자는 개인정보 보호를 위해 다음과 같은 기술적·관리적 보호 조치를 시행합니다.
- 모든 서버 통신은 TLS 1.2 이상으로 암호화
- 인증 토큰은 iOS Keychain 또는 Android EncryptedSharedPreferences에 저장. 평문 AsyncStorage 저장 금지
- 서비스 권한 키는 서버 외부로 반출 금지
- 정기적인 보안 감사 및 보안 패치 적용(최근 감사: 2026년 6월)
중대한 개인정보 침해 사고가 발생한 경우, 운영자는 관련 법령(개인정보보호법 제34조, GDPR 제33-34조, CCPA §1798.82)에 따라 인지 후 부당한 지체 없이 사용자 및 감독기관에 통지하며, 법령상 요구되는 경우 72시간 이내에 통지합니다.
18. 계정 및 인증
본 서비스 이용에는 이메일·Google·Apple 계정으로 로그인이 필요합니다(웹·iOS·Android 공통). 로그인 후 클라우드 동기화, 친구·커뮤니티, 프리미엄 기능을 이용할 수 있습니다.
이메일 계정 등록 시 이메일 인증을 통해 본인 확인을 진행합니다. 비밀번호는 Supabase Auth에 단방향 솔티드 해시(salted hash)로만 저장되며, 운영자가 원문을 확인할 수 없습니다.
Google 로그인 시 Google 계정의 이메일 주소와 프로필 정보(이름)가 수집됩니다. Google 계정의 비밀번호는 앱에서 처리하지 않습니다.
Apple 로그인 시 Apple ID에 연결된 이메일 주소와 이름이 수집됩니다. "Hide My Email"을 선택하면 Apple이 익명 릴레이 주소를 생성하여 전달하며, 운영자는 사용자의 실제 이메일을 알 수 없습니다. Apple 계정의 비밀번호 및 인증 절차는 Apple이 처리하며 앱에서 직접 다루지 않습니다.
19. EU/UK 대리인
현재 운영자는 GDPR 제27조에 따른 EU/UK 대리인을 지정하고 있지 않으며, 향후 필요 시 지정을 검토합니다. EU·영국 거주 정보주체는 아래 이메일로 운영자에게 직접 연락하여 GDPR상 권리를 행사하실 수 있습니다.
20. 아동 개인정보 보호
본 앱은 App Store 12+, Google Play Teen 등급으로 아동을 대상으로 하지 않습니다. 운영자는 만 14세 미만(개인정보보호법·정보통신망법 기준), 만 13세 미만(미국 COPPA 기준), 또는 이용자의 거주 국가가 정한 디지털 동의 최소 연령(예: 독일·네덜란드 16세, 태국 20세 등) 미만의 가입·이용을 허용하지 않으며, 해당 사실이 확인되는 경우 관련 개인정보를 즉시 삭제합니다. 아동의 개인정보가 수집된 사실을 알게 된 경우 즉시 support@moavoca.com로 연락해 주시기 바랍니다.
21. 변경 사항 고지
개인정보처리방침이 변경될 경우, 앱 내 공지를 통해 사전에 안내합니다.
본 방침은 2026년 7월 12일자로 개정되었습니다.
22. 문의
개인정보와 관련한 문의는 이메일로 보내주시면 답변드리겠습니다.
이메일: support@moavoca.com