Privacy policy
This document is a translation provided for convenience. If there is any discrepancy between this translation and the Korean original, the Korean original prevails.
Daldagury Co., Ltd. (the "Company") operates the Dear Place service and processes users' personal information as follows.
1. Purposes of Processing
- Identifying Members (email ID), keeping you signed in, sending email verification and password reset emails, and linking multiple sign-in methods that use a verified email address to a single account
- Providing the Note service (including viewing your own Notes and limiting how many Notes you can write)
- Notifying you when a reply arrives (only on signed-in devices that have allowed notification permission; post content is not included in notifications)
- Pre-publication review, handling reports and appeals, preventing fraudulent use, usage restrictions, and restricting re-registration after account deletion or usage restrictions, post hiding and author blocking records (post IDs and internal user identifiers)
- Sending events and offers notifications (only to Members who have consented)
- Fulfilling legal obligations such as retaining access logs
2. Items Processed and Collection Methods
- Required: email address (entered and verified directly or received through social login; the relay address if Apple's "Hide My Email" is used), the account identifier for social login, a password hash for email login (entered directly and converted with a one-way hash; the original is not stored), nickname, sign-up date and time, and terms consent records
- Email verification and security: the email address being verified, hashes of one-time verification codes and sign-up proofs, expiry times, number of failed attempts, and irreversible hashes of email addresses and IP addresses used for rate limiting
- Optional: saved signatures, profile photo URL, and whether and when you consented to receive events and offers notifications
- When a reply arrives: the receiving Member, identifiers of the original Note and the reply, the notification date and time, and the time it was read. Retained in the in-app notification inbox for up to 30 days regardless of device notification permission, and deleted upon account deletion. Post content and signatures are not copied to the notification inbox.
- If notification permission is allowed: push token, the linked login session, operating system type, notification language, registration renewal time, reply notification identifiers and delivery status, and the name of the neighborhood where the original Note was left. Note and reply content, signatures, and precise coordinates are not included in push notifications
- Information generated while using the Service: Notes you leave and their spots, the signature, whether to show the date, and the date format chosen at the time of posting, review results of submitted posts and the original text of rejected posts (including the author's Member ID and writing location), report reasons and outcomes (including the reporter's Member ID), review appeal reasons and responses, and usage restriction records
- Automatically generated information: access date and time, access IP address, app version, operating system version, device model name, app attestation results (the device's app attestation key; not linked to Members or locations), and records confirming the use and provision of location information (Member ID, date and time, and purpose; no coordinates)
- Location: the device's location while you are using the app. It is processed in accordance with the Location-Based Service Terms. For reply notifications, the neighborhood name determined on the device when the Note was written is used. Neighborhood names of your own Notes that were previously stored only on the device are synced to the server while you use the app. The server does not call any separate map API to obtain neighborhood names. The region (administrative district) to which the spot of a Note belongs is determined within the Company's servers using public administrative boundary data stored on the Company's servers, and no location is sent outside the Company for this purpose.
Nicknames are used to distinguish Members and for administrators' review and report handling, and are not displayed on public Notes. The signature text chosen by the author is made public as part of the post. The list of saved signatures is shown only to you. Email addresses are used as IDs and for sending verification and password reset emails, and are not made public. The Company does not store the real name or phone number of social accounts. Locations received for finding, reading, and report checks of nearby Notes, and movement paths, are not stored.
3. Retention Period
Personal information is destroyed immediately upon account deletion. However, the information below is retained for the period stated and then destroyed.
| Information | Retention period | Basis |
|---|---|---|
| Post hiding and author blocking records | Deleted when the blocking Member deletes their account. When the blocked author deletes their account, their identifier is removed and only blocked post IDs are retained | Personal content visibility and safety |
| Temporary email verification data | Verification code 10 minutes; sign-up proof issued after verification an additional 10 minutes. Deleted once used; cleaned up on a 1-hour cycle after expiry | Email verification and password reset |
| Push token | Deleted when revocation of notification permission is confirmed, when the token is confirmed to have expired, or upon account deletion. On logout or session expiry, delivery stops and the token is deleted at the next daily cleanup | Reply arrival notifications |
| Reply notification identifiers and delivery status | Up to 30 days (deleted immediately upon account deletion). Retries for up to 1 day | Confirming delivery and retrying failures |
| Email and IP hashes for rate limiting | Valid for up to 1 hour; cleaned up on a 1-hour cycle after expiry | Preventing abuse of verification requests |
| Public landing page visit statistics (including IP, browser, and referring site) | Automatically deleted after up to 90 days | Analyzing visits and traffic sources |
| Access logs (access date and time, IP address, device information) | 3 months | Protection of Communications Secrets Act |
| Records confirming the use and provision of location information | 6 months (destroyed immediately upon account deletion) | Location Information Act |
| Locations received while writing | Destroyed immediately once the Note is left; otherwise within 30 minutes at the latest | Location-Based Service Terms |
| Review records (including the original text of rejected posts) | 1 year (the author and writing location are destroyed immediately upon account deletion) | Responding to appeals, checking for repeated violations |
| Report and appeal handling records | 1 year from the date handling is completed | Responding to disputes |
| Re-registration restriction values (irreversibly transformed values of the deleted account's email address and social account identifiers; the originals are destroyed immediately upon account deletion) | 30 days after account deletion. If the account was deleted during a usage restriction, until the restriction ends; for a permanent usage restriction, indefinitely | Preventing fraudulent use (Terms of Service, Article 4) |
| App attestation records | 1 year | Preventing fraudulent use |
| Notes left | Erased over one week or kept without an author, according to the choice made when deleting the account | Member's choice |
4. Destruction Procedures and Methods
When the retention period ends or the purpose of processing has been achieved, the information is automatically destroyed daily. Electronic files are deleted using methods that make them unrecoverable. Database backups are kept on the server for 7 days and in backup storage for 30 days before being deleted, so destroyed information may remain in backups for up to 30 days. Notes for which "Erase all" was chosen upon account deletion are gradually erased over one week and then deleted.
5. Provision to Third Parties
The Company does not provide users' personal information to third parties. An exception is made where an investigative agency or other authority requests it in accordance with law.
6. Outsourcing of Processing
| Recipient | Task entrusted | Location |
|---|---|---|
| Amazon Web Services | Operating servers, databases, and backups, and sending verification emails (Amazon SES) | Republic of Korea (Seoul Region) |
| 650 Industries, Inc. (Expo) | App updates and push notification delivery (using Apple APNs and Google FCM) | United States |
7. Overseas Transfer
The Company transfers personal information overseas as follows in order to perform the contract for providing the Service (Article 28-8, Paragraph 1, Subparagraph 3 of the Personal Information Protection Act).
| Recipient (contact) | Country | Items transferred | Time and method of transfer | Purpose of use | Recipient's retention period |
|---|---|---|---|---|---|
| OpenAI, L.L.C. (dsar@openai.com) | United States | Post text and the chosen signature text; for replies, also the text and signature text of the original Note read together with them (excluding author and location) | Each time a post or reply is left, via encrypted communication (HTTPS) | Pre-publication AI review | Up to 30 days (abuse monitoring logs; response storage is turned off) |
| Google LLC (domestic representative: Google Korea LLC, 02-722-7778, data-access-requests@google.com) | United States | Same as above | Same as above (when the higher-priority provider does not respond) | Pre-publication AI review | Up to 55 days (policy violation monitoring logs) |
| Anthropic, PBC (privacy@anthropic.com, domestic representative: anthropic_privacy@kimchang.com) | United States | Same as above | Same as above (when the higher-priority provider does not respond) | Pre-publication AI review | Up to 30 days (up to 2 years for posts determined to violate policies) |
| 650 Industries, Inc. (Expo, contact form at expo.dev/privacy) | United States | A random identifier generated for each app installation, access IP address, operating system and app version. If notifications are allowed: push token, the name of the neighborhood where the original Note was left, fixed notification text, and notification identifiers | Via encrypted communication when checking for updates or when registering for or sending notifications | Distributing app updates and delivering push notifications | Period set out in Expo's privacy policy |
The AI review providers do not use the posts they receive for AI training. If you do not want your information transferred overseas, you may choose not to leave posts, but in that case you cannot use the feature for leaving Notes. Checking for app updates is necessary for using the app and cannot be refused separately. You can refuse reply push notifications by turning off notification permission in your device settings, and you can still read and leave Notes with notifications turned off.
Note and reply translation: when a reader taps Translate, the body and target language are sent over HTTPS to an AI provider configured from those listed above. Author information, location, signatures and drawings are not sent. A saved translation in the same language is reused without another AI call. Translations have the same access rules as the original. A body’s translations are erased when the body is deleted or starts fading. Other people’s replies and their translations are preserved independently. Provider retention periods are those in the table above.
8. Users' Rights and How to Exercise Them
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information, and may withdraw consent by deleting their account. If you make a request through the contact details below, it will be processed within 10 days and you will be notified of the result. Records confirming the use and provision of location information can be viewed directly in the app under My page > App settings > Location use records, and you can delete your account directly under My page > App settings > Delete account. When making a request through a representative, please also send a power of attorney. Consent to receive events and offers notifications can be changed directly in My page > Notifications.
9. Devices That Automatically Collect Personal Information
Public web pages do not install cookies for advertising or behavioral analysis, and the app does not use advertising identifiers for ad tracking.
The map and login SDKs included in the app may process information to provide their features, prevent fraudulent use, diagnose stability, and improve quality. Even though the Company has not installed any separate analytics tools, automatic collection by the SDKs below may occur.
- Google Maps: processes approximate location inferred from the access IP address, device, operating system, and app information, installation identifiers, interactions such as moving and zooming the map, and error and performance diagnostic information. If you allow location permission, location information is also used to show your current location.
- Google Sign-In: uses user identifiers, the access IP address and the approximate location derived from it, and similar information for sign-in and preventing fraudulent use. The privacy declarations of the iOS SDK also include account, device, and usage information for sign-in functionality and analytics.
- Naver Map and Naver, Kakao, and Apple sign-in: the app communicates with the relevant provider when requesting maps or during the sign-in process the user chooses. Each provider's privacy policy and the user's account settings also apply.
You can find Google's privacy policy at https://policies.google.com/privacy and the Maps SDK's data collection disclosures at https://developers.google.com/maps/documentation/android-sdk/play-data-disclosure and https://developers.google.com/maps/documentation/ios-sdk/apple-privacy-policy.
10. Automated Decisions
Before a post is published, the Company has AI automatically assess it against the criteria in Article 7, Paragraph 2 of the Terms of Service; if the post does not meet the criteria, it is not published and the reason is given. Only the post text and signature text (for replies, also the text and signature text of the original Note) are used for the assessment; author information and location are not used. Users may file an appeal against the decision to have it reviewed by an administrator, and may request an explanation of the decision. Usage restrictions are not imposed on the basis of AI decisions alone, but only after an administrator has reviewed the case.
11. Security Measures
- All communications are encrypted (HTTPS).
- Keys for external services and administrators' two-factor authentication secrets are stored encrypted (AES-256-GCM), and tokens that keep users signed in are stored as hashes rather than in their original form.
- Administrators are granted only the permissions they need. Super administrators and general administrators who handle personal information and location must use two-factor authentication. Whenever an administrator opens a list or detail screen that shows personal information, a log is kept together with the date and time and the access IP address.
- Servers cannot be accessed from outside except through the web (HTTPS), and server administration access and cloud account activity are logged and retained. An intrusion detection service and automatic operating system security updates are in operation.
- Databases and backups are kept in encrypted storage.
- Movement paths and locations used for location checks are not accumulated. Records confirming the use and provision of location information also do not contain coordinates. Access permissions are managed and regular self-inspections are carried out in accordance with the guidelines for handling and managing location information.
12. Personal Information of Children Under 14
Persons under 18 years of age cannot sign up, so the Company does not collect children's personal information.
13. Chief Privacy Officer and Location Information Management Officer
- Name: Dukwon Kim
- Phone: 010-4934-0626
- Email: c31sky@daldagury.com
14. Remedies for Infringement of Rights
You may seek counseling or file reports regarding personal information infringement with the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Korean National Police Agency Cybercrime Reporting System: 182 (ecrm.police.go.kr)
15. Changes to This Privacy Policy
If this Privacy Policy is changed, notice will be given in the app and on this page starting 7 days before the effective date. Changes that materially affect users' rights will be notified starting 30 days before the effective date.
Effective date: October 10, 2026