Privacy Policy지도 열기

Privacy Policy

시행일자: Effective 2026-09-27

This is an English translation provided for convenience only. The Korean-language version is the legally authoritative text; in the event of any conflict between the two, the Korean version controls. 한국어판(법적 우선 언어): 개인정보처리방침 (한국어)

In plain language first: Woori-Yeojido is a service that shows your photos as pins on a map. To do that, we read and store the GPS coordinates and capture time already embedded in your photos. A history of GPS coordinates can become sensitive information that can identify a person — home, workplace, frequently visited places, and travel routes. That is why there is no default; you must choose every time you register a Graffiti Album. Photos and locations you upload are visible only to you and to friends you have added, unless you explicitly choose to make them public. What becomes visible to whom for each choice is fully explained in §4 Scope of Disclosure.

1. Terms used in this policy

TermMeaning
Graffiti AlbumA single graffiti post placed at one spot on the map. Up to 10 photos can be attached, and at registration you choose one visibility scope — Public, Friends-only, or Only me (there is no default; if you choose none, it is not registered). In this policy, every "container that holds photos and location" refers to this.
PinA single photo placed on the map. It has a location (latitude/longitude) and a capture time.

2. Personal information items collected

ItemCollection method / timingNotes
Email addressEntered directly at sign-upUsed as the login identifier. Ownership is confirmed via a verification link sent to the sign-up email
PasswordEntered directly at sign-upStored as a hash; the plaintext is never stored anywhere
NicknameEntered directly at sign-upDisplayed in Graffiti Albums and the friends list. Must be unique among users
Uploaded photo filesWhen the user uploads a photoOnly image files up to 5MB each are allowed. The original file is stored as-is (see §4-2)
Photo GPS coordinates (latitude/longitude)Automatically extracted from the photo file's EXIF metadataPhotos without GPS information are not placed on the map
Photo capture timeAutomatically extracted from the photo file's EXIF metadataThe displayed time is converted to the viewer's device time zone
Graffiti Album name / theme (tags) / visibility scopeEntered/selected by the user at registration or editIf registered as Public, the name and theme become public items (§4-2)
Account profile photo (avatar)When the user registers or changes a profile photoOnly one is stored per account, managed separately from photos posted on the map
Reactions left on photos (👍)When the user leaves a reaction on a photoStored per user identifier (uid)
Map graffiti (text) and its coordinatesWhen the user leaves graffiti on the mapVisible to other users within the same radius
Direct message (DM) content and the other partyWhen the user exchanges direct messagesKept permanently and visible only to the two parties in that conversation
Friend relationships / request historyWhen the user requests, accepts, declines, or cancels a friend requestThe counterpart and status (pending/accepted/declined/cancelled) are stored per user identifier (uid)
Blocked usersWhen the user blocks another userThe blocking and blocked users are stored as a pair of user identifiers (uid)
Photo analysis results (object tags, person count, capture spot)Automatically generated by the server when a photo with location information is uploadedDoes not include the original photo or facial-recognition information (embeddings). May be aggregated in a form that cannot identify an individual and used to improve place information quality (§3, §5)
Report content, target, and reasonWhen the user reports graffiti, a photo, etc.Used only to process the report; the reported person is not told who filed it
Feedback (bug/opinion) content and diagnostic informationWhen the user sends feedback via "Send Feedback" in the appDirectly entered: description of the situation (the server auto-fills a title from the first line). Automatically collected: app version, device model, OS (SDK) version, screen size/density, language setting, network type, available memory, the current screen (route) and map zoom level at report time, and a one-time anonymous reporter ID not retained on the device. Not collected: precise GPS location, sign-up email/phone number, account identifiers/auth tokens, original photo files/graffiti text, or network request/response bodies. App usage log (last 1 hour, at report time): screen navigation, named button taps, dialog open/close, network call path/result/duration (not content), error occurrences, foreground/background switches, and permission results are sent by default (can be turned off in app settings); included location is rounded to two decimal places. Sub-processor: an internal issue tracker (Notion), used only to diagnose the bug and discarded once the report is closed (§9)
Advertising identifier (Ad ID), device identifier, IP address, ad interaction and diagnostic informationAutomatically collected by the Google AdMob SDK while using the app (personalized ads only with consent)For ad serving and performance measurement (§3, §5). Item basis: Google's official documentation (developers.google.com/admob/android/privacy/play-data-disclosure). The Ad ID can be reset or deleted under Android Settings > Privacy > Ads
Support (in-app purchase) product ID and purchase token (receipt)Issued by Google Play Billing when the user completes a support purchaseSent to the company server for payment verification (§5, §6). Card and other payment details are handled directly by Google Play; the company does not collect them

We do not collect carrier information, contacts, or real-time (background GPS) location tracking. The app does include the Google AdMob advertising SDK, and automatically collects the advertising identifier (Ad ID), device identifier, IP address, and ad interaction information for ad serving and performance measurement (see the row above, and §5 Third-Party Sharing). The device model name is not collected on an ongoing basis — it is collected only as diagnostic information when you send feedback via "Send Feedback".

Your "Hide" list is never sent to the server. When you hide a piece of graffiti or a photo, that list is stored only on your device. Signing in on another device does not apply it, and the company's server cannot see what you hid.

2-1. How the Android app accesses your photo library

Before you pick a photo, the Android app reads and indexes the capture location and capture time metadata of your entire on-device photo library, on the device only (this index itself never leaves the device). This is required for the core feature of grouping many photos onto a map at once — a picker that strips location data and lets you choose photos one at a time cannot build a map. What is uploaded and stored on the server is only the photo(s) you directly choose on the list screen, and their location/time. Separately, photo analysis is already in effect. The first time you launch the app, an onboarding scan automatically goes through your photo library even without you choosing any photo, groups photos with location data into visited spots (automatically clustered by place/time), and sends only an analysis-sized thumbnail of one representative photo per spot, chosen by the app, to the server API. Your whole photo library is not sent, but which photo is sent is chosen by the app, not by you. The thumbnail sent is used for analysis and then discarded immediately — it is not kept on the server, regardless of whether the spot is later registered as Public or not. Full-resolution photos, facial-recognition information, and the original EXIF at import time are never transmitted. The permissions the app requests and their purposes are as follows.

PermissionPurpose
Photos and videos access (READ_MEDIA_IMAGES) or access to selected photos only (READ_MEDIA_VISUAL_USER_SELECTED, partial access)Reads the capture location/time of the whole library or of photos you chose, on the device
Location in photos (ACCESS_MEDIA_LOCATION)Reads the EXIF GPS coordinates of a photo file (without this permission the coordinates are stripped when read)
Precise / approximate location (ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION)Used to show your current location on the map
Camera (CAMERA)Used to take and upload a photo directly within the app
Internet (INTERNET)Uploads and syncs photos and their location/time you chose to the server

Photos near your home are excluded from the start. The app determines "near home" on-device from repeated capture locations, and photos in that cluster are shown with the upload checkbox off by default. You can turn it on yourself. This determination happens only on the device and never tells the server where "home" is.

3. Purposes of collection and use

  • Identity verification at sign-up (email verification link) and member identification
  • Providing the core feature of showing photos as map pins at their capture location
  • Sharing Friends-only photos/reactions between friends and showing who posted them
  • Operating the friend request/accept process
  • Showing a Graffiti Album registered as Public to other users — limited to the scope in §4-2
  • Posting map graffiti (text) and receiving/processing reports
  • Receiving and processing feedback (bugs/opinions) — including device/screen diagnostic information to identify causes
  • Ad serving and performance measurement (Google AdMob) — personalized ads and Ad ID use only with the user's consent
  • Processing support (in-app purchases) and payment verification (Google Play Billing)
  • Storing and aggregating photo analysis results (object tags, person count, capture spot) — used, in a form that cannot identify an individual, to improve place identification accuracy

4-1. Three visibility scopes and the default

When you register a Graffiti Album, you choose one visibility scope. The default is "Only me"; if you choose nothing, it is not made public.

Visibility scopeWho can see itWhat is shown
"Only me" (default)Only youThe photo, location, and capture time in full. Other users cannot see that it exists at all.
"Friends-only"Friends who have mutually accepted each otherThe original photo, location, and capture time in full (§4-4). Does not appear in search or on the map of anyone who is not a friend.
"Public"Anyone, including people who are not signed inOnly what is listed as "what is shown" in §4-2. Does not include the original photo or the capture time.

4-1. Three visibility scopes and the default

When you register a Graffiti Album, you choose one visibility scope. The default is "Only me"; if you choose nothing, it is not made public.

Visibility scopeWho can see itWhat is shown
"Only me" (default)Only youThe photo, location, and capture time in full. Other users cannot see that it exists at all.
"Friends-only"Friends who have mutually accepted each otherThe original photo, location, and capture time in full (§4-4). Does not appear in search or on the map of anyone who is not a friend.
"Public"Anyone, including people who are not signed inOnly what is listed as "what is shown" in §4-2. Does not include the original photo or the capture time.

4-3. Making something Public cannot be undone

The visibility scope is set at registration and never changes afterward. There is no path in either direction.

  • Private → Public: none. A Graffiti Album made "Only me" or "Friends-only" will never later change to Public. If you want to make it public, you choose the photo again on the map and register a new Graffiti Album as Public.
  • Public → Private: none. We do not provide a way to revert a Graffiti Album once registered as Public back to private. The only way to stop it from being public is to delete that Graffiti Album (§5).

This is why making something Public is a one-time, irreversible choice. The registration screen defaults to "Only me", and choosing "Public" shows this notice again before asking for confirmation.

4-4. "Friends-only" — what is visible to friends

Once you send and accept friend requests with each other and become mutual friends, everything that friend chose as "Friends-only" becomes visible as follows.

  • The original file of every Friends-only photo, including ones posted before you became friends, along with its location, capture time, description, and hashtags. It is not limited to only what was posted after you became friends.
  • That friend's nickname and profile photo, and reactions (👍) left on photos

About friend relationships: a friendship is only formed when both sides accept; while only one side has requested, nothing is visible. Visibility scope is chosen per Graffiti Album by whoever posted it, so even between friends, an album the poster chose as "Only me" stays hidden. Only the poster can edit or delete their own Graffiti Album — no one has a role equivalent to the old "owner" who could delete someone else's. Ending a friendship means you can no longer see each other's Friends-only photos.

5. Retention/use period and deletion

We retain data until you withdraw or request deletion. The units you can delete are as follows.

Unit deletedWho can delete itWhat is deleted with it
A single photo (pin)The person who posted itThe photo file and its location/capture time
The entire accountThe account holder (in-app account deletion or an email request)Account information (email, password hash, nickname), map graffiti, uploaded photo files (including analysis thumbnails) and their location/capture time, friend relationship records, report records, and consent records. Reactions and friend records linked to other people may not be deleted immediately.
⚠️ Photo analysis results (object tags, person count, capture spot) made from those photos are not deleted together with the photos. Because we paid to produce this analysis, we anonymize it (removing the account identifier, rounding location to roughly 1 km, rounding capture time to month, and removing captions/descriptions) and may keep it for statistics and service-improvement purposes.

How to delete your account: you can delete your account yourself by tapping "Delete account" on the profile screen in the app.

Requesting account deletion by email: for cases such as having already uninstalled the app, an email request path is also available. See the account deletion request page for the procedure. Email [email protected] with your sign-up email address, and after identity verification we delete the account within 7 business days.

6. Third-party sharing and sub-processing

We do not sell personal information to third parties or provide it for marketing purposes.

If you register a Graffiti Album as "Public", it becomes visible to an unspecified number of people, limited to the "what is shown" scope in §4-2. This is not third-party sharing of personal information but disclosure by your own choice, and nothing outside that scope is ever shared.

The service runs on cloud infrastructure. The server that processes account information, map graffiti, coordinates, etc. runs on Amazon Web Services (AWS) EC2(Seoul region); photo files, graffiti media, and analysis thumbnails are stored on Cloudflare R2 (object storage). Both vendors are overseas. Below is the list of vendors otherwise unavoidably involved in providing the service.

Sub-processors

VendorWork entrustedStorage location
CARTO (basemaps.cartocdn.com)Provides map background tiles for the web service — the visible map area is sent to display the mapCDN based on OpenStreetMap data, overseas
OpenFreeMap (tiles.openfreemap.org)Provides map background tiles for the Android app — the visible map area is sentCDN based on OpenStreetMap data, overseas
CloudflareRelays DNS/TLS traffic for the domain (wooriyeojido.com), and forwards inbound email for the contact address ([email protected]) via Email Routing — this leg only passes traffic through and does not store it separately. Separately, Cloudflare R2 (object storage) stores photo files and graffiti mediaPhoto/media file storage (R2), otherwise traffic relay/mail forwarding only, overseas
Amazon Web Services (EC2, Amazon SES)EC2 — hosts the server that processes account information, map graffiti, coordinates, etc. (operated in the Seoul region). SES — sends sign-up confirmation/notice emails; only the recipient's email address and the message body are shared, and it is not used for anything beyond sendingServer hosting (EC2, Seoul region), email delivery, overseas vendor
Google LLCAdMob — ad serving and performance measurement (personalized ads and Ad ID use only with consent); items shared: Ad ID, device identifier, IP address, ad interaction. Google Play Billing — processing and verifying support (in-app purchases); items shared: product ID, purchase token. Card and other payment details are handled directly by Google Play; the company does not collect themAdMob and Google Play Billing processing, overseas (US) vendor
Photo-analysis API vendor (Google LLC — Vertex AI Gemini)Processes an analysis-sized thumbnail of one representative photo per visited spot chosen by the app — the app, not the user, chooses which photo is sent, and the whole photo library is never sent. The full-resolution photo and facial-recognition embeddings are never shared, and it is not used for anything beyond analysis. The same vendor (Vertex AI) is also used to translate map graffiti (guestbook) text, in which case only the graffiti text itself is shared and no photo is sharedDiscarded right after analysis — not stored on the server (R2), regardless of whether the album is Public or private (as of the 2026-09-20 decision, ISSUE-1476), overseas
Notion (Notion Labs, Inc.)Processes feedback (bugs/opinions) sent via "Send Feedback" — shares the feedback text (free text), the last 1 hour of app usage log (screen navigation, button taps, error events, etc.), diagnostic information (app version, device model, OS/SDK version, screen size, etc.), and a one-time anonymous reporter ID. Precise GPS location, account identifiers, auth tokens, photo files, and graffiti text are not shared. Used only to diagnose the bug and discarded once the report is closed (§9)Kept while the report is being processed, overseas

The server (Amazon Web Services EC2) runs in the Seoul region, but because AWS is an overseas vendor, the account information, map graffiti, and coordinates it processes constitute a cross-border transfer. Photo files and graffiti media are likewise stored on Cloudflare R2, also an overseas vendor. Map background tiles (CARTO, OpenFreeMap), domain connection and inbound email forwarding (Cloudflare), sign-up confirmation email delivery (Amazon SES), photo-analysis thumbnail transmission (the photo-analysis API vendor), and feedback processing (Notion) also go through overseas vendors; this leg carries the visible map-area data, email addresses, analysis thumbnails, feedback text and diagnostic information, and encrypted communication traffic. Analysis thumbnails are discarded right after analysis and are not stored on the server, regardless of whether the album is registered as Public or not. The full-resolution photo, raw coordinates, and facial embeddings are never shared with the photo-analysis API vendor.

7. Measures to secure personal information

Data that includes personal location information, such as photos and GPS coordinates, is stored on cloud infrastructure (server: Amazon Web Services EC2; photo/media files: Cloudflare R2), with the following security measures applied.

  • Encryption in transit — all communication between your device and the server is encrypted via HTTPS (TLS). The service cannot be accessed over an unencrypted (HTTP) connection.
  • Database access control (row-level permission checks) — photo, coordinate, and Graffiti Album data is protected by row-level access-control policies, so only the signed-in owner, or, for a "Friends-only" album, mutually accepted friends of the poster, can view it. The server does not return a response to anyone else at all. The only exception is the §4-2 scope of a Graffiti Album registered as Public, and even that scope is served as data built separately for public display, not by opening up the original data.
  • Login session protection — login sessions are managed via httpOnly cookies that browser scripts cannot read directly, reducing the risk of session hijacking by malicious scripts.
  • Restricted edit/delete permissions — only the person who uploaded a photo or coordinate can edit or delete it.

Backup disclosure: the server (EC2) and photo storage (R2) run on top of cloud-vendor infrastructure, but the service itself does not have a separate, dedicated backup regime. Backup procedures and breach-notification procedures will be reflected in this policy once finalized, and announced within the service.

8. Data subject rights and how to exercise them

You may request access to, correction of, deletion of, or suspension of processing of your personal information at any time. You can delete individual photos and change your nickname/profile photo directly in the app. For full account deletion, access/correction requests, or a request to delete a Graffiti Album registered as Public, please contact us at the address below and we will process it.

Additional rights available to users in the EEA (European Economic Area) or the UK, and the paths to withdraw consent, are collected in the "Additional notice for EU/EEA and UK residents" section below.

Contact: [email protected]

9. Destruction of personal information

We destroy personal information without delay once its retention purpose has been achieved or a deletion request is received. Deleting a photo removes the file and its location/capture-time metadata together, and it cannot be recovered. However, analysis results made from that photo (object tags, person count, capture spot) may be anonymized so that no one can be identified from them and then kept for statistics and service-improvement purposes (see §5).

Additional notice for EU/EEA and UK residents

If you reside in the European Economic Area (EEA) or the United Kingdom, the following applies in addition to the sections above. This notice supplements those sections and does not replace them.

Legal basis by processing purpose

Consent — personalized ad serving and use of the Ad ID (advertising identifier) are processed only if you have consented (see the Google LLC row in §6). Performance of a contract — sign-up/login and providing core services such as the map and Graffiti Albums are processed to perform our contract with you under the Terms of Service. Legitimate interests — security safeguards (§7), error/abuse response, and feedback processing (the Notion row in §6) are based on our legitimate interest in operating the service safely.

Basis for cross-border transfer

The Republic of Korea has held an adequacy decision from the European Commission since December 17, 2021, allowing personal information to be transferred from the EEA to Korea without additional safeguards. The US vendors the service uses (Google LLC, Amazon Web Services, Cloudflare) are each certified under the EU-US Data Privacy Framework and/or incorporate the European Commission's Standard Contractual Clauses (SCCs) into their processing agreements — see the official-document URLs in the header comment of the Korean source file (`PrivacyEea.tsx`) for the vendor-specific basis.

Rights of data subjects (EEA/UK addition)

In addition to the access, correction, deletion, and processing-suspension rights in §8, you may exercise the right to request restriction of processing, the right to receive the personal information you provided in a structured format or have it transferred to another controller (data portability), the right to withdraw consent at any time, the right to objectto processing, and, if you believe processing is unlawful, the right to lodge a complaint with the data-protection supervisory authority of your country of residence (or your habitual workplace, or where the alleged infringement occurred).

How to withdraw consent

In the app, you can reset your personalized-ad consent via the "Privacy options" button in the account (avatar) sheet (shown only to EEA/UK users). On the device, go to Android Settings → Privacy → Ads to reset or delete your Ad ID (the exact location may vary by device and OS version).

Contact for the above rights and consent withdrawal: [email protected]

10. Personal information protection officer

NameThe operator (sole proprietor)
Contact[email protected]

11. Operator information

Service nameWoori-Yeojido
OperatorAn individual (business registration in progress)
Contact[email protected]

12. Duty to notify

This policy may be amended in response to changes in law or in the service; when it is amended, we announce it within the service starting 7 days before the effective date (30 days before, for material changes). In particular, the day the Public feature (§4-1 through §4-3) is turned on is treated as a material change and announced 30 days before its effective date.

Amendment history
2026-09-27 — Enacted (initial version).