개인정보처리방침Privacy Policy

시행일 2026년 8월 14일Effective 14 August 2026

개인정보처리방침

주식회사 칠로엔(이하 "회사")은 82JIGU(이하 "서비스")를 운영하면서 이용자의 개인정보를 소중하게 다룹니다. 회사는 「개인정보 보호법」과 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」을 지킵니다.

이 방침은 회사가 어떤 정보를 왜 모으고, 어떻게 쓰고, 언제 지우는지 알려 드립니다. 문장은 되도록 쉽게 썼습니다. 궁금한 점은 contact@chilloen.com 으로 물어보세요.

제1조 (목적)

이 방침은 다음을 알리기 위한 것입니다.

  1. 회사가 처리하는 개인정보의 항목
  2. 그 정보를 쓰는 목적
  3. 그 정보를 보관하는 기간과 지우는 방법
  4. 이용자가 가진 권리와 그 권리를 쓰는 방법

제2조 (처리하는 개인정보 항목)

1. 모든 이용자 (게스트 포함)

  • 익명 식별자(회사가 만든 임의의 값), 국가(국적), 사용 언어
  • 기기 정보: 기기 종류(iOS 또는 Android), 알림용 기기 토큰

앱을 처음 켜면 국가와 언어를 고릅니다. 두 가지는 앱을 쓰기 위해 반드시 골라야 합니다.

게스트로 쓰는 동안에도 위 정보는 회사 서버에 저장됩니다. 다만 이 정보는 이름·연락처·소셜 계정과 연결되지 않습니다. 게스트 기록은 기기에 저장된 식별자로만 이어지므로, 앱을 지우거나 기기를 바꾸면 다시 접근할 수 없습니다.

2. 소셜 계정으로 로그인한 회원

이용자가 카카오·구글·Apple 로그인을 하면, 회사는 각 회사로부터 다음 정보를 받습니다.

  • 카카오: 카카오 회원번호, 이메일 주소, 프로필 닉네임, 프로필 사진 주소
  • 구글: 구글 회원번호, 이메일 주소, 이름
  • Apple: Apple 회원번호, 이메일 주소

받은 정보 중 회원번호와 이메일 주소는 계정을 알아보기 위해 저장합니다. 닉네임과 프로필 사진은 서비스 안에서 쓰는 첫 표시 이름과 프로필 사진이 됩니다.

Apple 로그인에서 "이메일 가리기"를 고르면, 회사는 실제 주소 대신 Apple이 만든 전달용 주소를 받습니다.

3. 프로필

  • 닉네임(직접 입력, 2~20자)
  • 프로필 사진(기기의 사진에서 선택)

둘 다 선택 사항입니다. 넣지 않아도 서비스를 쓸 수 있습니다.

4. 대학 소속 인증을 하는 경우

대학 커뮤니티(공지·자유게시판·학교 문의)를 쓰려면 학교 소속 인증이 필요합니다. 인증을 시작하면 다음을 입력받습니다.

  • 대학교·캠퍼스 선택
  • 학교 이메일 주소, 이메일 인증번호(6자리)
  • 성명, 학번
  • 휴대전화번호, 문자 인증번호(6자리)

소속 인증 자체는 선택입니다. 하지만 인증을 시작하면 위 항목은 모두 필요합니다. 하나라도 없으면 신청을 끝낼 수 없습니다.

인증번호는 원래 숫자 그대로 저장하지 않고, 되돌릴 수 없게 바꾼 값만 저장합니다. 유효 시간은 10분이고, 확인 시도는 5회까지 가능합니다.

학과·전공은 받지 않습니다.

5. 서비스를 쓰는 과정에서 만들어지는 정보

  • 장소 리뷰: 별점(1~5), 글(최대 500자), 사진(최대 5장)
  • 자유게시판: 글 제목과 본문, 이미지, 댓글, 좋아요
  • 학교 문의: 문의 종류, 제목, 내용, 첨부파일과 파일 이름
  • 신고 기록: 신고한 사람, 신고당한 글을 쓴 사람, 신고 사유, 신고 일시
  • 글을 쓸 때 쓰던 앱 언어(나중에 번역하기 위해 기록)
  • 공지를 읽었는지 여부와 읽은 시각
  • 가입 일시, 마지막 접속 일시
  • 로그인 상태를 유지하기 위한 세션 기록
  • 알림 수신 동의 여부

리뷰·게시글·댓글에는 이용자의 닉네임과 프로필 사진이 함께 보입니다. 자유게시판과 리뷰에서는 닉네임의 가운데 글자를 가려서 보여 줍니다. 프로필 사진은 가리지 않습니다.

6. 자동으로 만들어지는 정보

  • 접속한 IP 주소, 접속 일시, 이용자가 보낸 요청 내용(주소와 검색어를 포함합니다)

이 기록은 서비스를 안전하게 운영하기 위해 웹서버에 남습니다. 계정 정보와 묶어서 따로 정리하지 않습니다. 주변 시설을 찾을 때 보낸 좌표가 요청 주소에 들어가므로, 그 좌표도 이 기록에 함께 남습니다.

7. 회사가 모으지 않는 정보

  • 주민등록번호, 여권번호 등 고유식별정보
  • 신용카드·계좌 등 결제 정보
  • 나이, 생년월일
  • 광고 식별자, 행동 기록을 모으는 분석 도구(회사는 이런 도구를 앱에 넣지 않았습니다)
  • 이용자의 위치를 계속 쌓아 두는 이동 기록(제9조 참고)

제3조 (개인정보의 처리 목적)

회사는 모은 정보를 아래 목적으로만 씁니다. 목적이 바뀌면 미리 알리고 동의를 받습니다.

  1. 회원 확인과 로그인 유지: 소셜 회원번호, 이메일, 세션 기록, 익명 식별자
  2. 앱 언어와 지역 설정: 국가, 사용 언어
  3. 프로필 표시: 닉네임, 프로필 사진
  4. 대학 소속 확인: 학교 이메일, 성명, 학번, 휴대전화번호, 인증번호
  5. 커뮤니티 운영: 게시글, 댓글, 좋아요, 리뷰, 학교 문의
  6. 신고 처리와 이용 제한: 신고 기록
  7. 알림 발송: 소속 심사 결과, 학교 공지, 문의 답변
  8. 주변 시설 찾기: 지도에서 쓰는 좌표(제9조 참고)
  9. 문의 응대와 분쟁 처리: 문의 내용, 접속 기록
  10. 서비스 보호: 부정 이용과 중복 신청 확인, 서버 보안

제4조 (개인정보의 처리 및 보유 기간)

원칙은 목적을 이루면 지체 없이 지우는 것입니다. 항목별 기준은 다음과 같습니다.

  • 회원 정보(소셜 회원번호, 이메일, 닉네임, 프로필 사진, 국가, 언어): 회원 탈퇴 시까지
  • 게스트 정보(익명 식별자, 국가, 언어, 기기 정보): 삭제를 요청할 때까지
  • 로그인 세션: 만료되거나 로그아웃할 때 폐기하며, 탈퇴하면 모두 삭제합니다. 만료된 기록을 주기적으로 정리하는 절차는 아직 두고 있지 않으며, 탈퇴 시 함께 삭제됩니다.
  • 이메일·문자 인증번호: 만든 뒤 10분까지 유효합니다. 인증 기록은 탈퇴 시 삭제합니다.
  • 알림용 기기 토큰: 알림을 끄거나 탈퇴할 때 삭제
  • 게시글, 댓글, 리뷰, 좋아요, 신고 기록: 이용자가 지울 때까지. 탈퇴하면 제8조에 따라 처리합니다.
  • 학교 문의 내용과 첨부파일: 대학이 처리한 기록으로 남습니다. 탈퇴해도 지워지지 않습니다.
  • 대학 소속 신청 기록: 탈퇴하면 성명과 휴대전화번호는 지웁니다. 학번과 학교 이메일, 심사 결과는 같은 사람이 다시 신청하는지 확인하기 위해 남습니다.
  • 서버 접속 기록: 서버 운영과 보안을 위해 웹서버에 보관합니다. 보관 기간은 서버의 저장 공간이 허용하는 범위이며, 별도의 자동 삭제 주기를 아직 정하지 않았습니다.
  • 데이터베이스 자동 백업: 14일 (백업은 순서대로 지워집니다)
  • 저장소에서 지운 사진·파일: 실수로 지운 경우를 대비해 30일 동안 복구할 수 있는 상태로 남습니다. 저장소에 버전 관리 기능이 켜져 있어 그 이전에 저장된 판본이 30일이 지난 뒤에도 남아 있을 수 있습니다.

법령이 더 오래 보관하도록 정한 경우에는 그 법령을 따릅니다. 법령에 따라 보존하는 경우 그 근거와 보존 항목은 이 조에 적힌 그대로입니다.

제5조 (개인정보의 제3자 제공)

회사는 원칙적으로 이용자의 개인정보를 다른 곳에 주지 않습니다. 다음 한 가지 경우만 예외입니다.

대학교(해당 대학의 담당 부서)

  • 주는 때: 이용자가 그 대학의 소속 인증을 신청했을 때
  • 주는 항목: 성명, 학번, 학교 이메일 주소, 휴대전화번호, 국가, 사용 언어, 닉네임, 가입 일시, 승인 일시, 알림 수신 동의 여부
  • 주는 목적: 재학생인지 확인하고, 학교 커뮤니티와 공지·문의를 운영하기 위해
  • 함께 보는 내용: 이용자가 그 대학에 보낸 학교 문의의 내용과 첨부파일, 그 대학의 공지를 읽었는지 여부와 읽은 시각
  • 받는 곳의 보유 기간: 해당 대학의 개인정보 처리 기준에 따릅니다

이 제공에는 소속 인증을 신청할 때 이용자의 동의를 따로 받습니다. 동의하지 않으면 대학 소속 인증과 대학 커뮤니티를 이용할 수 없지만, 그 밖의 서비스는 그대로 이용할 수 있습니다. 소속 인증을 하지 않으면 위 정보는 대학에 가지 않습니다.

이 밖에는 법령에 정해진 경우이거나 수사기관이 법이 정한 절차에 따라 요구한 경우에만 제공합니다.

제6조 (개인정보 처리의 위탁)

회사는 서비스를 운영하기 위해 아래 회사에 일부 업무를 맡깁니다.

맡기는 곳 맡기는 업무
Microsoft (Azure) 서버 운영, 데이터베이스 보관, 사진·파일 저장, 학교 인증 이메일 발송
네이버클라우드 본인확인 문자(SMS) 발송, 지도 화면 표시
카카오 주변 시설 검색(좌표로 장소 찾기)
Google 푸시 알림 발송(Firebase Cloud Messaging)
OpenAI 회원이 쓴 글을 다른 언어로 번역
  • 위탁 계약에는 개인정보를 안전하게 다루도록 하는 내용을 넣습니다.
  • 데이터베이스와 사진·파일은 대한민국(Azure 한국 리전)에 보관합니다. 학교 인증 이메일 발송도 한국에서 처리합니다.
  • 위탁하는 곳이 바뀌면 이 방침을 고쳐서 알립니다.

제7조 (개인정보의 국외 이전)

푸시 알림, 구글 로그인 확인, 글 번역 과정에서 일부 정보가 국외로 나갑니다.

1. 푸시 알림 발송

  • 받는 곳: Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA / support.google.com 의 문의 창구)
  • 나가는 나라: 미국
  • 나가는 항목: 알림용 기기 토큰, 알림 제목과 내용
  • 나가는 때와 방법: 알림을 보낼 때마다 인터넷으로 전송
  • 목적: 이용자의 기기로 알림을 보내기 위해
  • 보유 기간: 알림 발송에 필요한 기간

2. 구글 로그인 확인

  • 받는 곳: Google LLC (같은 주소·연락처)
  • 나가는 나라: 미국
  • 나가는 항목: 구글이 만든 로그인 토큰(구글 회원번호, 이메일, 이름이 들어 있습니다)
  • 나가는 때와 방법: 구글로 로그인할 때 인터넷으로 전송
  • 목적: 그 로그인이 진짜인지 구글에 확인하기 위해
  • 보유 기간: 확인이 끝나면 회사는 이 토큰을 보관하지 않습니다

3. 글 번역

  • 받는 곳: OpenAI, L.L.C. (1455 3rd Street, San Francisco, CA 94158, USA / privacy@openai.com)
  • 나가는 나라: 미국
  • 나가는 항목: 회원이 올린 글의 내용(게시글 제목·본문, 댓글, 장소 리뷰 본문, 학교 문의 제목·본문, 소속 인증 반려 사유)과 그 글을 쓸 때 쓰던 언어. 닉네임·이메일 같은 계정 정보는 함께 보내지 않습니다
  • 나가는 때와 방법: 글이 올라왔을 때, 또는 다른 언어를 쓰는 이웃이 그 글을 열었을 때 인터넷으로 전송
  • 목적: 한국어를 읽기 어려운 이웃에게 같은 글을 그 사람의 언어로 보여주기 위해
  • 보유 기간: 번역에 필요한 기간. OpenAI는 API로 받은 내용을 모델 학습에 쓰지 않으며, 남용 감시 목적으로 짧은 기간 보관한 뒤 지웁니다. 번역 결과는 회사 서버에 보관합니다

거부 방법: 앱의 [마이] 화면이나 기기 설정에서 알림을 끄면 1번은 일어나지 않습니다. 구글 로그인을 쓰지 않으면 2번은 일어나지 않습니다. 3번은 이용자가 올린 글에만 일어나며, 글을 올리지 않으면 일어나지 않습니다. 알림을 끄거나 다른 로그인 방법을 쓰더라도 서비스는 그대로 이용할 수 있습니다.

Apple 로그인에서는 이용자의 정보가 Apple로 나가지 않습니다. 회사는 Apple의 공개 열쇠만 내려받아 서버 안에서 확인합니다.

제8조 (회원 탈퇴와 개인정보의 파기)

1. 탈퇴 방법

앱에서 [마이] > [계정] > [회원탈퇴]를 누르면 바로 탈퇴됩니다. 탈퇴는 되돌릴 수 없고, 유예 기간도 없습니다.

게스트는 앱 안에서 삭제를 진행할 수 없습니다. 게스트로 이용한 기록의 삭제를 원하면 contact@chilloen.com 으로 요청해 주십시오. 회사는 요청을 받은 날부터 10일 안에 처리합니다.

2. 탈퇴하면 바로 지워지는 것

  • 소셜 계정 연결 정보(제공자 회원번호, 이메일)
  • 로그인 세션과 기기 정보, 알림용 기기 토큰, 알림 동의 기록
  • 학교 이메일 인증 기록, 휴대전화 인증 기록
  • 공지를 읽은 기록, 게시글·리뷰에 누른 좋아요
  • 신고 기록(내가 신고한 것과 내 글에 대한 신고 모두)
  • 프로필 사진과 리뷰 사진(다른 이용자의 글이 같은 사진을 쓰고 있지 않으면 파일도 지웁니다)

3. 탈퇴하면 내용이 비워지거나 보이지 않게 되는 것

  • 닉네임, 프로필 사진, 국가
  • 게시글: 작성자 표시를 지우고, 게시판에서 보이지 않게 됩니다
  • 댓글: 작성자 표시를 지우고 내용을 비웁니다. 글의 흐름이 끊기지 않도록 자리는 남습니다
  • 리뷰: 작성자 표시를 지우고 본문을 비웁니다

4. 탈퇴해도 남는 것

  • 리뷰의 별점: 장소의 평균 점수를 지키기 위해 남습니다. 누가 준 점수인지는 보이지 않습니다.
  • 대학 소속 신청 기록의 학번과 학교 이메일, 심사 결과: 같은 학번으로 다시 신청하는지 확인하기 위해 남습니다. 성명과 휴대전화번호는 지웁니다.
  • 학교 문의의 내용과 첨부파일, 파일 이름: 대학이 처리한 기록이므로 남습니다. 작성자는 "탈퇴한 학생"으로 표시됩니다.
  • 데이터베이스 백업: 탈퇴 전 상태가 최대 14일 동안 백업에 남았다가 순서대로 사라집니다.
  • 저장소에서 지운 사진·파일: 30일 동안 복구할 수 있는 상태로 남습니다. 저장소의 버전 관리 기능 때문에 이전 판본이 그 뒤에도 남아 있을 수 있습니다.

5. 파기 방법

  • 전자 파일: 데이터베이스에서 기록을 지우고, 사진과 파일은 저장소에서 지웁니다. 다시 살릴 수 없는 방법을 씁니다.
  • 종이 문서: 회사는 이용자의 개인정보를 종이로 보관하지 않습니다.

제9조 (위치정보의 처리)

지도에서 "내 위치"를 켜면 앱이 기기의 위치를 읽습니다. 그 좌표는 다음과 같이 쓰입니다.

  1. 지도에 내 위치 점을 그립니다.
  2. 주변 시설을 가까운 순서로 보여 줍니다.
  3. 주변 시설을 찾기 위해 회사 서버로 보내고, 서버는 그 좌표를 카카오의 장소 검색에 전달합니다.

회사는 이용자의 위치를 데이터베이스에 저장하지 않습니다. 검색이 끝나면 좌표는 버려집니다. 다만 좌표가 요청 주소에 담겨 전달되므로, 검색을 요청한 좌표가 웹서버의 접속 기록에 IP 주소·접속 일시와 함께 남습니다.

앱은 이용자가 일정 거리 이상 움직였을 때만 주변을 다시 찾습니다. 이 판단은 기기 안에서 이루어지며, 회사는 이동 경로를 서버에 쌓지 않습니다.

위치 권한을 주지 않아도 지도는 쓸 수 있습니다. 이때는 화면에 보이는 지도의 가운데를 기준으로 주변 시설을 찾습니다.

위치정보의 이용에 관한 자세한 사항은 위치기반서비스 이용약관에서 정합니다.

제10조 (앱 접근권한과 거부 시 불이익)

「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 제22조의2에 따라 알려 드립니다. 서비스는 아래 접근권한을 씁니다. 모두 선택 권한입니다. 반드시 허용해야 하는 권한은 없습니다.

권한 구분 쓰는 이유 허용하지 않으면
위치(앱 사용 중) 선택 지도에 내 위치를 표시하고, 주변 시설을 가까운 순서로 보여 주기 위해 지도와 주변 시설 검색은 그대로 쓸 수 있습니다. 내 위치 표시와 거리순 정렬은 되지 않습니다.
알림 선택 소속 심사 결과, 학교 공지, 문의 답변을 알려 주기 위해 앱은 그대로 쓸 수 있습니다. 알림을 받지 못합니다.
카메라 선택 리뷰에 넣을 사진을 찍기 위해 사진을 찍어서 넣을 수 없습니다. 저장된 사진은 넣을 수 있습니다.
사진·파일 선택 프로필 사진, 리뷰 사진, 게시글 이미지, 문의 첨부파일을 고르기 위해 사진과 파일을 올릴 수 없습니다. 글은 쓸 수 있습니다.

앱 안의 알림 설정은 처음에 켜진 상태입니다. [마이] 화면에서 언제든지 끌 수 있습니다. 회사는 광고나 홍보 목적의 알림을 보내지 않으며, 보내게 되는 경우 따로 동의를 받습니다.

권한을 나중에 바꾸는 방법은 다음과 같습니다.

  • Android: 설정 > 애플리케이션 > 82JIGU > 권한
  • iOS: 설정 > 82JIGU

Android 6.0보다 낮은 버전을 쓰면 권한을 하나씩 고를 수 없습니다. 운영체제를 올리거나 앱을 지워서 권한을 거둘 수 있습니다.

제11조 (개인정보를 자동으로 모으는 장치)

  • 앱은 쿠키를 쓰지 않습니다.
  • 앱은 광고 식별자를 모으지 않고, 이용 행동을 분석하는 도구도 넣지 않았습니다. 맞춤형 광고를 하지 않습니다.
  • 알림을 위한 기기 토큰은 알림을 켜면 자동으로 만들어져 서버에 저장됩니다. [마이] 화면에서 알림을 끄거나 기기 설정에서 알림 권한을 거두면, 저장된 토큰을 지우고 더 이상 쓰지 않습니다.

제12조 (정보주체와 법정대리인의 권리·의무 및 행사 방법)

1. 이용자의 권리

이용자는 언제든지 다음을 요구할 수 있습니다.

  1. 개인정보를 보겠다(열람)
  2. 틀린 내용을 고쳐 달라(정정)
  3. 지워 달라(삭제)
  4. 쓰지 말아 달라(처리정지)

2. 앱에서 바로 할 수 있는 것

  • 닉네임·프로필 사진 바꾸기: [마이] 화면
  • 국가·언어 바꾸기: [마이] 화면
  • 알림·위치 끄기: [마이] 화면
  • 내가 쓴 글·댓글·리뷰 지우기: 각 글의 메뉴
  • 회원 탈퇴: [마이] > [계정] > [회원탈퇴]

3. 회사에 요청하는 방법

contact@chilloen.com 으로 메일을 보내면 됩니다. 회사는 요청을 받은 날부터 10일 안에 처리하고 결과를 알려 드립니다. 본인인지 확인하기 위해 필요한 최소한의 정보를 물어볼 수 있습니다.

법정대리인이나 위임받은 사람도 요청할 수 있습니다. 이때는 위임 사실을 확인할 수 있는 서류가 필요합니다.

법령에 따라 보관해야 하는 정보는 지워 달라는 요청을 받아도 지울 수 없습니다. 이 경우 이유를 알려 드립니다.

4. 만 14세 미만 아동

만 14세 미만 아동은 서비스를 이용할 수 없습니다. 회사는 나이를 따로 확인하지 않으므로, 만 14세 미만 아동이 가입한 사실을 알게 되면 바로 그 정보를 지우고 이용을 멈춥니다.

제13조 (개인정보의 안전성 확보 조치)

회사는 다음과 같이 개인정보를 지킵니다.

  1. 전송 구간 암호화: 앱과 서버 사이의 모든 통신은 HTTPS로 암호화합니다. 서버와 데이터베이스 사이의 연결도 암호화합니다.
  2. 인증번호와 비밀번호의 일방향 암호화: 이메일·문자 인증번호와 관리자 비밀번호는 원래 값을 저장하지 않고, 되돌릴 수 없게 바꾼 값만 저장합니다. 로그인 세션도 원래 값 대신 해시 값만 저장합니다.
  3. 접근 권한 최소화: 대학 담당자 계정은 자기 대학의 자료만 볼 수 있습니다. 대학 담당자는 2단계 인증(OTP)을 반드시 써야 합니다.
  4. 네트워크 분리: 데이터베이스는 외부 인터넷에서 바로 접속할 수 없는 사설 망에 둡니다.
  5. 사진 정보 제거: 올린 사진은 서버가 다시 만들어 저장하므로 촬영 위치 등 붙어 있던 정보(EXIF)가 지워집니다. 다만 사진이 아닌 첨부파일(PDF, 문서 등)은 원본 그대로 저장되므로 파일에 붙은 정보가 남을 수 있습니다.
  6. 작성자를 알기 어렵게 하기: 사진 파일의 주소는 회원 번호가 아니라 사진 내용에서 만든 값으로 정합니다. 게시판과 리뷰에서는 닉네임의 일부를 가려서 보여 줍니다.
  7. 부정 시도 차단: 인증번호 확인은 5회까지만 가능하고, 인증번호는 10분이 지나면 쓸 수 없습니다.
  8. 정기 백업: 데이터베이스를 매일 자동으로 백업합니다.

제14조 (개인정보 보호책임자)

이용자는 개인정보와 관련된 모든 문의, 불만, 피해 구제를 아래로 알려 주시면 됩니다. 회사는 성실하게 답변합니다.

개인정보 보호책임자

  • 성명: 조성인
  • 직위: 대표이사
  • 소속: 주식회사 칠로엔
  • 전화: 02-6952-8716
  • 이메일: contact@chilloen.com
  • 주소: 서울특별시 서초구 서초중앙로 64, 6층

제15조 (권익침해 구제방법)

개인정보가 침해되어 도움이 필요하면 아래 기관에 문의할 수 있습니다. 아래 기관은 회사와 별개인 기관입니다.

  • 개인정보분쟁조정위원회: (국번없이) 1833-6972 / www.kopico.go.kr
  • 개인정보침해신고센터: (국번없이) 118 / privacy.kisa.or.kr
  • 대검찰청 사이버수사과: (국번없이) 1301 / www.spo.go.kr
  • 경찰청 국가수사본부 사이버수사국: (국번없이) 182 / ecrm.police.go.kr

회사가 개인정보 보호법 제35조(열람), 제36조(정정·삭제), 제37조(처리정지)에 따른 요구를 거절하거나 처리하지 않으면, 개인정보 보호법 제35조의2에 따라 행정심판을 청구할 수 있습니다.

제16조 (개인정보처리방침의 변경)

  1. 이 방침은 아래 시행일부터 적용됩니다.
  2. 내용이 바뀌면 바뀌기 최소 7일 전에 앱 안에서 알립니다. 이용자에게 중요한 내용(수집 항목 추가, 이용 목적 변경 등)이 바뀌면 최소 30일 전에 알리고, 필요하면 다시 동의를 받습니다.
  3. 지난 방침은 이용자가 볼 수 있도록 앱 안에 남겨 둡니다.

시행일: 2026년 9월 17일 (이전 방침 시행일: 2026년 8월 14일)

회사 정보

  • 상호: 주식회사 칠로엔
  • 대표: 조성인
  • 주소: 서울특별시 서초구 서초중앙로 64, 6층
  • 사업자등록번호: 110-88-01963
  • 전화: 02-6952-8716
  • 문의: contact@chilloen.com

이 방침은 한국어로 작성되었습니다. 다른 언어로 번역한 문서와 뜻이 다르면 한국어 문서를 기준으로 합니다.

Privacy Policy

This English text is provided to help you understand the policy. The Korean version is the official one, and it governs if the two differ.

Chilloen Inc. (주식회사 칠로엔, the "Company") takes care with your personal data while operating 82JIGU (the "Service"). The Company follows the Personal Information Protection Act (개인정보 보호법) and the Act on Promotion of Information and Communications Network Utilisation and Information Protection (정보통신망법).

This policy tells you what the Company collects and why, how it is used, and when it is deleted. It is written as plainly as possible. Ask anything at contact@chilloen.com.

Article 1 (Purpose)

This policy tells you:

  1. what personal data the Company processes;
  2. what it is used for;
  3. how long it is kept and how it is destroyed;
  4. what rights you have and how to use them.

Article 2 (What personal data is processed)

1. All users, including guests

  • an anonymous identifier generated by the Company, your country (nationality), your language;
  • device information: device type (iOS or Android), notification device token.

You choose a country and a language the first time you open the app. Both are required in order to use it.

This information is stored on the Company's servers while you use the app as a guest, too. It is not linked to a name, contact details or a social account. Guest records are tied only to the identifier stored on your device, so deleting the app or changing device makes them unreachable.

2. Members who sign in with a social account

When you sign in with Kakao, Google or Apple, the Company receives from that provider:

  • Kakao: Kakao member number, email address, profile nickname, profile image URL
  • Google: Google member number, email address, name
  • Apple: Apple member number, email address

The member number and email address are stored to recognise your account. The nickname and photo become your initial display name and profile photo in the Service.

If you choose "Hide My Email" with Apple, the Company receives Apple's relay address rather than your real one.

3. Profile

  • nickname (typed by you, 2–20 characters)
  • profile photo (chosen from your device)

Both are optional. You can use the Service without them.

4. If you verify a university affiliation

Using the university community (notices, open board, school inquiries) requires verification. Starting it collects:

  • your university and campus;
  • your school email address and a 6-digit email code;
  • your name and student number;
  • your mobile number and a 6-digit text code.

Verification itself is optional, but once started every item above is required; the application cannot be completed without them.

Codes are not stored as typed — only an irreversible transformation of them is kept. They are valid for 10 minutes and may be checked up to 5 times.

Department and major are not collected.

5. Data created as you use the Service

  • Place reviews: rating (1–5), text (up to 500 characters), photos (up to 5)
  • Open board: post title and body, images, comments, likes
  • School inquiries: category, title, content, attachments and their file names
  • Reports: who reported, who wrote the reported content, the reason, and when
  • The app language in use when you wrote something (recorded so it can be translated later)
  • Whether and when you read a notice
  • Sign-up time, last access time
  • Session records that keep you signed in
  • Whether you consented to notifications

Your nickname and profile photo appear alongside your reviews, posts and comments. On the open board and in reviews the middle of the nickname is masked. The profile photo is not masked.

6. Data created automatically

  • IP address, time of access, and the content of the request you sent (including its path and query).

These records are kept by the web server so the Service can be operated safely. They are not compiled against account information. Because the coordinates used to search nearby places travel in the request path, those coordinates appear in these records too.

7. What the Company does not collect

  • Resident registration numbers, passport numbers or other unique identifiers
  • Credit card, bank account or other payment details
  • Age or date of birth
  • Advertising identifiers, or behavioural analytics tools (the Company has not put any in the app)
  • A running history of where you have been (see Article 9)

Article 3 (Purposes of processing)

The Company uses what it collects only for the purposes below. If a purpose changes, it will tell you beforehand and obtain consent.

  1. Recognising you and keeping you signed in: social member number, email, session records, anonymous identifier
  2. App language and region: country, language
  3. Showing your profile: nickname, profile photo
  4. Confirming university affiliation: school email, name, student number, mobile number, verification codes
  5. Running the community: posts, comments, likes, reviews, school inquiries
  6. Handling reports and restrictions: report records
  7. Sending notifications: verification outcomes, school notices, replies to inquiries
  8. Finding places nearby: map coordinates (see Article 9)
  9. Answering inquiries and handling disputes: inquiry content, access records
  10. Protecting the Service: detecting misuse and duplicate applications, server security

Article 4 (Retention periods)

The rule is to delete without delay once the purpose is met.

  • Member information (social member number, email, nickname, profile photo, country, language): until you delete your account
  • Guest information (anonymous identifier, country, language, device information): until you ask for it to be deleted
  • Sign-in sessions: discarded on expiry or sign-out, and deleted entirely when you delete your account. There is not yet a routine that clears expired records periodically; they go when the account does.
  • Email and text codes: valid for 10 minutes after being created. Verification records are deleted when you delete your account.
  • Notification device token: deleted when you turn notifications off or delete your account
  • Posts, comments, reviews, likes, reports: until you delete them. On account deletion they are handled under Article 8.
  • School inquiry content and attachments: kept as the university's record. Not deleted when you delete your account.
  • University application records: on account deletion your name and mobile number are erased. Student number, school email and the outcome remain, so that a repeat application by the same person can be recognised.
  • Server access records: kept on the web server for operations and security. They are held for as long as the server's storage allows; an automatic deletion cycle has not yet been set.
  • Automatic database backups: 14 days (backups age out in order)
  • Photos and files deleted from storage: kept recoverable for 30 days in case of accidental deletion. Version history is enabled on the storage account, so earlier versions may remain after those 30 days.

Where the law requires longer retention, the law is followed. Where data is retained under the law, the basis and the items retained are exactly as stated in this Article.

Article 5 (Provision to third parties)

As a rule the Company does not give your personal data to anyone else. There is one exception.

Your university (its administrative office)

  • When: when you apply to verify an affiliation with that university
  • What: name, student number, school email address, mobile number, country, language, nickname, sign-up time, approval time, notification consent
  • Why: to confirm you are enrolled, and to run the school community, notices and inquiries
  • Also visible to them: the content and attachments of the school inquiries you send to that university, and whether and when you read that university's notices
  • Retention by them: under that university's own data-handling rules

Your separate consent is obtained for this when you apply. If you do not consent, you cannot use university verification or the university community, but everything else in the Service remains available. If you never apply, none of this reaches any university.

Otherwise data is provided only where the law requires it, or where an investigative authority demands it through the procedure the law lays down.

Article 6 (Processing entrusted to others)

Entrusted to Work entrusted
Microsoft (Azure) Server operation, database hosting, photo and file storage, sending school verification emails
NAVER Cloud Sending identity-verification text messages (SMS), displaying maps
Kakao Searching for nearby places by coordinates
Google Sending push notifications (Firebase Cloud Messaging)
OpenAI Translating what members write into other languages
  • Each contract requires personal data to be handled securely.
  • The database and stored photos and files are held in the Republic of Korea (Azure Korea region). School verification emails are also sent from Korea.
  • If these arrangements change, this policy will be updated to say so.

Article 7 (Transfer abroad)

Some data leaves Korea in the course of push notifications, Google sign-in and translation.

1. Push notifications

  • Recipient: Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; contact via support.google.com)
  • Country: United States
  • Items: notification device token, notification title and body
  • When and how: over the internet, each time a notification is sent
  • Purpose: to deliver the notification to your device
  • Retention: for as long as delivery requires

2. Google sign-in verification

  • Recipient: Google LLC (same address and contact)
  • Country: United States
  • Items: the sign-in token issued by Google, which contains your Google member number, email and name
  • When and how: over the internet, when you sign in with Google
  • Purpose: to confirm with Google that the sign-in is genuine
  • Retention: the Company does not keep this token once the check is done

3. Translation of what members write

  • Recipient: OpenAI, L.L.C. (1455 3rd Street, San Francisco, CA 94158, USA; privacy@openai.com)
  • Country: United States
  • Items: the text a member posts (board titles and bodies, comments, place review bodies, school inquiry titles and bodies, affiliation rejection reasons) and the language it was written in. Account details such as nickname or email are not sent with it
  • When and how: over the internet, when the text is posted or when a neighbour reading in another language opens it
  • Purpose: to show the same text in the language of a neighbour who cannot read Korean
  • Retention: for as long as the translation takes. OpenAI does not use text received through its API to train models, and deletes it after a short period kept for abuse monitoring. The translation itself is stored on the Company's servers

How to refuse: turning notifications off in [My] or in your device settings prevents (1). Not using Google sign-in prevents (2). Item (3) happens only to text a member posts, and not at all if none is posted. The Service remains fully usable either way.

Sign in with Apple sends none of your data to Apple: the Company only downloads Apple's public keys and performs the check on its own server.

Article 8 (Account deletion and destruction of personal data)

1. How to delete

In the app, [My] > [Account] > [Delete account] takes effect immediately. It cannot be undone and there is no grace period.

Guests cannot delete from within the app. To have guest records deleted, write to contact@chilloen.com; the Company acts within 10 days of the request.

2. Deleted immediately

  • Social account link (provider member number, email)
  • Sign-in sessions, device information, notification device token, notification consent record
  • School email and mobile verification records
  • Notice read records, likes on posts and reviews
  • Report records — both those you filed and those filed about your content
  • Profile photo and review photos (the stored file is removed too, unless another user's content uses the same image)

3. Emptied or hidden on deletion

  • Nickname, profile photo, country
  • Posts: the author is removed and the post no longer appears on the board
  • Comments: the author is removed and the text is cleared; the place in the thread remains so conversations stay readable
  • Reviews: the author is removed and the text is cleared

4. Kept after deletion

  • Review ratings: kept so a place's average is not silently changed. Who gave the rating is not shown.
  • Student number, school email and outcome in the university application record: kept so a repeat application under the same student number can be recognised. Name and mobile number are erased.
  • School inquiry content, attachments and file names: kept as the university's record of the conversation. The author is shown as "탈퇴한 학생" (a student who has left).
  • Database backups: your pre-deletion state remains in backups for up to 14 days, then ages out.
  • Photos and files deleted from storage: recoverable for 30 days. Because version history is enabled, earlier versions may remain after that.

5. How data is destroyed

  • Electronic records: deleted from the database; photos and files deleted from storage, by means that cannot be reversed.
  • Paper: the Company does not hold users' personal data on paper.

Article 9 (Handling of location data)

When you turn on "my location" on the map, the app reads your device's position. The coordinates are used to:

  1. draw your position on the map;
  2. order nearby places by distance;
  3. search for nearby places — the coordinates are sent to the Company's server, which passes them to Kakao's place search.

The Company does not store your location in its database. The coordinates are discarded once the search is done. However, because they travel in the request path, the coordinates of a search appear in the web server's access records alongside your IP address and the time.

The app searches again only after you have moved a certain distance. That judgement is made on your device; the Company does not accumulate a route on its servers.

You can use the map without granting location permission. In that case nearby places are found from the centre of the map on screen.

The Location-Based Services Terms set out the detail of how location data is used.

Article 10 (Device permissions, and what happens if you refuse)

Notice under Article 22-2 of the Network Act (정보통신망법). The Service uses the permissions below. All are optional; none is required.

Permission Type Why If you refuse
Location (while using the app) Optional To show your position on the map and order nearby places by distance The map and nearby search still work. Your position is not shown and distance ordering is unavailable.
Notifications Optional To tell you verification outcomes, school notices and replies to inquiries The app works as before. You will not receive notifications.
Camera Optional To take a photo for a review You cannot take a photo in the app. You can still attach saved photos.
Photos and files Optional To choose a profile photo, review photos, post images and inquiry attachments You cannot upload photos or files. You can still write text.

The in-app notification setting starts switched on. You can turn it off at any time in [My]. The Company does not send advertising or promotional notifications, and would obtain separate consent before doing so.

To change permissions later:

  • Android: Settings > Apps > 82JIGU > Permissions
  • iOS: Settings > 82JIGU

On Android below 6.0 permissions cannot be granted individually; update the operating system or uninstall the app to withdraw them.

Article 11 (Automatic collection devices)

  • The app does not use cookies.
  • The app does not collect advertising identifiers and contains no behavioural analytics tools. There is no personalised advertising.
  • The notification device token is created automatically when notifications are on and stored on the server. Turning notifications off in [My], or withdrawing the permission in your device settings, deletes the stored token and stops its use.

Article 12 (Your rights and how to use them)

1. Your rights

At any time you may ask to:

  1. see your personal data (access);
  2. correct what is wrong (rectification);
  3. have it deleted (erasure);
  4. have its processing stopped (suspension).

2. What you can do in the app

  • Change nickname and profile photo: [My]
  • Change country and language: [My]
  • Turn notifications and location off: [My]
  • Delete your own posts, comments and reviews: each item's menu
  • Delete your account: [My] > [Account] > [Delete account]

3. How to ask the Company

Email contact@chilloen.com. The Company acts within 10 days of the request and tells you the outcome. It may ask for the minimum information needed to confirm you are who you say you are.

A legal representative or an authorised agent may also make a request, with documents showing that authority.

Data the law requires the Company to keep cannot be deleted on request. Where that applies, the Company explains why.

4. Children under 14

Children under 14 may not use the Service. The Company does not verify age separately; on learning that a child under 14 has signed up, it deletes that data and stops the use immediately.

Article 13 (Security measures)

  1. Encryption in transit: all traffic between the app and the server uses HTTPS. The connection between the server and the database is encrypted too.
  2. One-way encryption of codes and passwords: email and text codes, and administrator passwords, are never stored as typed — only an irreversible transformation is kept. Session records are stored as hashes rather than as the original values.
  3. Least privilege: a university administrator account can see only its own university's data, and must use two-factor authentication (OTP).
  4. Network separation: the database sits on a private network not reachable from the public internet.
  5. Stripping photo metadata: uploaded photos are re-encoded by the server, which removes attached information such as the capture location (EXIF). Attachments that are not photos (PDFs, documents) are stored as uploaded, so information embedded in those files may remain.
  6. Making authorship hard to trace: image file paths are derived from the content of the image, not from a member number. Nicknames are partly masked on the board and in reviews.
  7. Blocking abuse: codes may be checked at most 5 times and expire after 10 minutes.
  8. Regular backups: the database is backed up automatically every day.

Article 14 (Data Protection Officer)

Send any question, complaint or request about personal data to the officer below. The Company will answer in good faith.

  • Name: Cho Sungin (조성인)
  • Position: Chief Executive Officer
  • Organisation: Chilloen Inc. (주식회사 칠로엔)
  • Telephone: +82-2-6952-8716
  • Email: contact@chilloen.com
  • Address: 6F, 64 Seochojungang-ro, Seocho-gu, Seoul, Republic of Korea

Article 15 (Remedies)

If your personal data has been infringed, these bodies — independent of the Company — can help:

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • Privacy Infringement Report Centre: 118 / privacy.kisa.or.kr
  • Supreme Prosecutors' Office, Cyber Investigation Division: 1301 / www.spo.go.kr
  • National Police Agency, Cyber Bureau: 182 / ecrm.police.go.kr

If the Company refuses or fails to act on a request under Articles 35 (access), 36 (correction and deletion) or 37 (suspension) of the Personal Information Protection Act, you may seek an administrative appeal under Article 35-2 of that Act.

Article 16 (Changes to this policy)

  1. This policy applies from the effective date below.
  2. Changes are announced in the app at least 7 days beforehand — at least 30 days beforehand for changes that matter to users, such as new items collected or a new purpose — and fresh consent is obtained where needed.
  3. Previous versions remain available in the app.

Effective: 17 September 2026 (previous version effective 14 August 2026)

Company information

  • Name: Chilloen Inc. (주식회사 칠로엔)
  • Representative: Cho Sungin (조성인)
  • Address: 6F, 64 Seochojungang-ro, Seocho-gu, Seoul, Republic of Korea
  • Business registration number: 110-88-01963
  • Telephone: +82-2-6952-8716
  • Email: contact@chilloen.com

This policy was written in Korean. Where a translation differs in meaning, the Korean text governs.