Privacy Policy
Eunhasu, represented by Kyounghwan Jung (the “Service”), complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws to protect the freedoms and rights of data subjects and to process personal information lawfully and securely. This Policy explains the categories, purposes, and periods of processing and how you may exercise your rights.
Privacy at a glance
- You may use the Service with an email address, a device account, Google Sign-In, or Sign in with Apple.
- We do not store plaintext passwords. Passwords are processed using one-way Argon2id hashes.
- Account email addresses, purchase tokens, and customer-support content are encrypted at rest.
- We use Google Play and Apple App Store payments, AdMob, Brevo email, the Cloudflare network, and a Neon PostgreSQL database.
- We process our own usage statistics and error diagnostics but do not use Google Analytics.
- To access content restricted to users aged 15 or 19, users complete NHN KCP mobile identity verification, including PASS. We encrypt and store date of birth, Duplication Information (DI), verification provider, and verification time.
- We distinguish information necessary to perform the membership agreement from optional marketing consent. We do not request broad consent to third-party disclosure merely because payment and identity-verification vendors process data on our behalf.
- We do not ask users to enter a sign-up country code. We store Cloudflare’s country determination for the connection IP address.
1. Purposes, Categories, and Legal Bases for Processing Personal Information
| Category | Purpose | Information processed | Legal basis |
|---|---|---|---|
| Device account | Identify the account, maintain login and access rights, operate the Service by region, and prevent abusive use | App-generated device account identifier, internal user number, sign-up country code | Article 15(1)(4) of the Personal Information Protection Act (“PIPA”) |
| Email registration | Registration and login, email verification, security and recovery, and regional Service operation | Email address, password hash, verification status and time, sign-up country code, optional nickname, optional birth year | PIPA Article 15(1)(4), and Article 15(1)(1) where required |
| Google Sign-In | Social login, account linking, and regional Service operation | Google account identifier (sub), email address, authentication provider, sign-up country code, and nickname when provided | PIPA Article 15(1)(4) |
| Sign in with Apple | Social login, account linking and deletion, email-relay status, and regional Service operation | Apple account identifier (sub), email address or private relay address, name initially provided, authentication and refresh tokens, email-relay status, and sign-up country code | PIPA Article 15(1)(4) |
| Age verification for restricted content | Determine eligibility for content restricted to users aged 15 or 19 and prevent duplicate or fraudulent verification | Date of birth, Duplication Information (DI), verification provider and time. Name, mobile phone number, carrier, sex, domestic/foreign-national status, and Connecting Information (CI) are processed temporarily during verification and are not stored in our database | PIPA Article 15(1)(4), and Article 15(1)(1) where required |
| Consent records | Confirm applicable documents and consent and respond to disputes | Consent item, document version, response, date and time, IP address, User-Agent | PIPA Article 15(1)(4) and (6) |
| Content usage | Reading and synchronization, favorites, ratings, attendance and achievements, and delivery of currency and access rights | User number, work and episode, reading and completion status, reading position, favorites, ratings, attendance, achievements, Gems, transactions, and access rights | PIPA Article 15(1)(4) |
| Copyright protection | Prevent unauthorized copying and investigate leaked copies | Non-visible episode delivery identifier, user number, work and episode, first and most recent delivery time, and delivery count | PIPA Article 15(1)(6) |
| Comments and reports | Publish content, process reports and blocks, operate and moderate the community | Nickname, comment, creation, edit and deletion times, report reason, count and outcome, blocking and enforcement records | PIPA Article 15(1)(4) and (6) |
| Google Play payments | Verify purchases, deliver Gems, process refunds, and prevent abusive use | Product ID, purchase token, order number, status and time, Gems delivered, refund and cancellation records | PIPA Article 15(1)(4) and Article 6 of the Act on Consumer Protection in Electronic Commerce |
| Apple App Store payments | Verify purchases, deliver Gems and access rights, and prevent duplicate payments, refunds, and abusive use | Product ID, transaction ID, signed transaction JWS, payment environment, status and time, Gems and access rights delivered, refund and cancellation records | PIPA Article 15(1)(4) and Article 6 of the Act on Consumer Protection in Electronic Commerce |
| Rewarded advertising | Provide advertisements and rewards, verify views, and prevent abusive use | Advertising identifier, IP address, device and account identifiers, app interactions, view, reward, and diagnostic information | Consent where required, and PIPA Article 15(1)(4) and (6) |
| Optional marketing | Send promotional information about new releases, events, and discounts and manage opt-in and withdrawal | Email address, push token, internal user number, opt-in or withdrawal status and time | PIPA Article 15(1)(1) and Article 50 of the Act on Promotion of Information and Communications Network Utilization and Information Protection |
| Support, analytics, and diagnostics | Handle inquiries and deletion requests, analyze use, and respond to outages and security issues | Email address, inquiries, responses and deletion records, app-generated installation and session identifiers, usage events, app, operating system and device information, error messages, stack and context, and access logs | PIPA Article 15(1)(4) and (6) |
We do not ask users to enter a sign-up country code. Cloudflare supplies an ISO 3166-1 alpha-2 code determined from the IP address used for the registration connection. If no determination is available, we record KR in accordance with the Service’s Korea-only default operating scope. We do not directly collect resident registration numbers, payment-card numbers, or bank-account numbers. Names, mobile phone numbers, CI, and similar information used for identity verification are processed temporarily to validate the result and are not stored. Google Play and the Apple App Store process payment methods directly and provide the Service only with transaction information needed to verify the purchase and deliver the product.
2. Processing and Retention Periods
We process personal information only for as long as necessary to achieve the relevant purpose. When an account is closed, we delete or anonymize direct identifiers. Records that must be retained by law or are needed to respond to disputes or abusive use are separated and destroyed after the periods below.
| Personal information or record | Retention period |
|---|---|
| Account information, Content status, favorites, ratings, and currency balance | Until account closure |
| Age-verification date of birth, DI, provider, and verification time | Until account closure; verification remains valid for one year from the verification date |
| Public comments | Comment, reply and review text is removed when the user deletes it or deletes their account. Empty thread anchors may remain to preserve other readers’ replies |
| Service usage events and app errors and diagnostics | One year from collection |
| Episode delivery identifiers and records linking an account, work, and episode | 180 days from the most recent delivery |
| Consent and withdrawal records | Three years after account closure |
| Email address and push token used for marketing | Until marketing consent is withdrawn or the account is closed |
| Customer support, consumer complaints and disputes, and account-deletion processing | Three years after the matter is completed |
| Contracts and withdrawal, payment, and supply of goods or services | Five years from the transaction |
| Display and advertising records | Six months after publication ends |
E-commerce records are retained under Article 6 of the Act on Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree. If an investigation, inquiry, or lawsuit is pending, necessary records may be retained until that process ends.
3. Disclosure of Personal Information to Third Parties
As a rule, we do not disclose personal information to third parties and do not seek blanket consent at registration merely because payment and identity-verification vendors process data on our behalf. If a user chooses Google Sign-In, a Google Play payment, or AdMob advertising, Google LLC and its affiliates may process the relevant account, purchase, and advertising information. If a user chooses Sign in with Apple or an App Store payment, Apple Inc. and its affiliates may process account identifiers, an email address or private relay address, a provided name, authentication and access information, and payment and transaction information for login, private email relay, payment authorization, refunds, and account-status notifications. Retention follows each company’s privacy policy and service rules.
Google and Apple login are optional. If a user chooses Hide My Email, we store the private relay address and Apple forwards messages to the user’s actual inbox. A user who does not want the relevant login, payment, or advertising processing may choose not to use that feature. Only the corresponding login, purchase, or advertising reward will be unavailable.
4. Service Providers Processing Personal Information on Our Behalf
| Service provider | Service | Information processed | Period |
|---|---|---|---|
| Cloudflare, Inc. | Web and API connections, connection-country determination, CDN, DDoS protection, and security | IP address, country code, URL and headers, access and security logs | Until the agreement ends or the purpose is achieved |
| Neon, LLC (Databricks) | Provision, storage, and backup of the application’s PostgreSQL database | Account, usage, transaction, consent, and operational data processed by the Service | Until the agreement ends, the Member closes the account, or the applicable retention period expires |
| Sendinblue SAS (Brevo) | Registration-verification and Service email | Email address, email content, delivery, receipt, and error records | Until the agreement ends or the sending purpose is achieved |
| NHN KCP Corp. | Mobile identity verification, including PASS, and delivery of the verification result | Name, mobile phone number, date of birth, carrier, sex, domestic/foreign-national status, CI, and DI | Until identity verification is completed and for any period required by applicable law or the processing agreement |
Comments, replies and reviews are filtered on our server before publication. Their text is not sent to external AI services. Reports are checked by internal filters and human operators; urgent content may be temporarily hidden pending review.
We require third parties and service providers that process personal information to provide the same or an equivalent level of protection as stated in this Policy and required by applicable law. We use contractual obligations, reviews of safeguards, and other appropriate oversight to support this requirement.
5. Overseas Transfers of Personal Information
When the global Service is used, personal information may be transmitted abroad or accessed and processed from another country. These transfers are outsourced processing and storage necessary to perform the agreement and are based on Article 28-8(1)(3) of PIPA. Separate consent will be obtained where required.
| Recipient | Country | Information and purpose | Timing and method | Period |
|---|---|---|---|---|
| Google LLC | United States and other countries where Google operates servers | Google-related information / login, payment, advertising, measurement, and prevention of abusive use | Encrypted transmission when the feature is used | Period specified by Google policy |
| Apple Inc. | United States and other countries where Apple operates servers | Apple account identifier, email address or private relay address, provided name, authentication information, and App Store transaction information / login, email relay, payment, refund, and account-status processing | Encrypted transmission during Apple login, payment, or account-status changes | Period specified by Apple policy |
| Cloudflare, Inc. privacyquestions@cloudflare.com | United States and countries where the global network operates | IP address and request, access, and security logs / connection and security | Encrypted transmission during web and app requests | Until the agreement ends or the purpose is achieved |
| Neon, LLC (Databricks) | Singapore (AWS ap-southeast-1) and other countries where the Service operates | Account, usage, transaction, consent, and operational data / PostgreSQL database provision, storage, and backup | Encrypted transmission when the Service is used or data changes | Until the agreement ends, the Member closes the account, or the applicable retention period expires |
| Sendinblue SAS (Brevo) privacy@brevo.com | France, Germany, and Belgium | Email address, email content, and sending records / verification and email delivery | Encrypted transmission when email is sent | Until the agreement ends or the purpose is achieved |
You may refuse a transfer by not using an optional feature or by contacting the Privacy Officer. Cloudflare connections and verification email are necessary to provide the Service, however, so refusing them may limit web and API access or registration by email. Where possible, we will explain alternatives such as a device account.
6. Procedure and Method for Deleting Personal Information
We delete or anonymize personal information without undue delay when its retention period expires or its processing purpose has been achieved. Information retained by law is separated and access-restricted. Electronic records are deleted in a manner designed to prevent recovery. Backups expire according to their rotation cycle and are not used except for recovery. Any paper documents are shredded or incinerated.
7. Rights and Responsibilities of Data Subjects and Legal Representatives
You may request access, correction or deletion, suspension of processing, withdrawal of consent, and account closure. Optional marketing consent may be changed immediately through Account Management in the app profile. Other requests may be submitted through Account Management or deletion in the app, the Account & Data Deletion page, or support.eunhasu@gmail.com. We will verify that the requester is the data subject or a duly authorized representative and respond within the period required by law. If a legal ground limits the request, we will explain the reason and how to object. If information strictly necessary to perform the agreement is not processed, registration or the relevant feature may not be available.
8. Automatic Collection and Advertising Identifiers
The app stores settings such as login state and reading progress on the device. At registration, the country code that Cloudflare determines from the connection IP address is automatically stored with the account. Access to age-restricted content is determined from the server’s KCP verification result, not a local device value. The public website does not use behavioral-analytics cookies.
The Google Mobile Ads SDK may automatically collect and share IP addresses, app interactions, diagnostic information, and device or account identifiers permitted by the operating system to deliver and analyze advertising and prevent abusive use. On Android, users may delete or reset the advertising ID and limit ad personalization in device settings. Starting with iOS version 1.1.6 build 40, the app resolves App Tracking Transparency (ATT) permission before the advertising consent flow and ad requests. If you allow tracking, the advertising provider may use the IDFA for advertising measurement. If you decline or tracking is restricted on your device, the app does not use the IDFA for tracking, and core app features remain available. All ad requests remain non-personalized, with publisher first-party ID and publisher privacy personalization disabled. Google’s regional advertising and device-storage consent is separate from ATT and cannot override an ATT refusal. You can change ATT permission in iOS Settings > Privacy & Security > Tracking. Earlier iOS builds do not request ATT permission or use the IDFA for cross-app tracking.
9. Children Under 14 and Age Verification
The Service is intended for users aged 14 or older and does not knowingly collect personal information from a child under 14 without consent from a legal representative. If we identify such information, we restrict use and delete it without undue delay.
A registered account must complete NHN KCP mobile identity verification to access content restricted to users aged 15 or 19. The Service calculates age from date of birth and encrypts and stores DI, the provider, and verification time. Verification remains valid for one year. Name, mobile phone number, CI, sex, carrier, and domestic/foreign-national status are processed temporarily to validate the result and are not stored, and we do not collect resident registration numbers. Users below the applicable age may not access the restricted Content.
10. Security Measures
- One-way Argon2id password hashing and encryption of key stored data
- HTTPS/TLS encryption in transit
- Least-privilege administration, authentication, and access controls
- Secret-key pseudonymization of episode delivery identifiers, with reverse lookup limited to administrators
- Rate limits and duplicate and tampering checks for verification, payments, and advertising rewards
- Management of access, consent, and operational records, security reviews, and backups
- Minimizing personnel who handle personal information and conducting regular reviews
11. Privacy Officer
Requests for access to personal information, inquiries and complaints, and remedies
support.eunhasu@gmail.com · 070-8064-3041
Room 201, 30 Dorim-ro 20ga-gil, Guro-gu, Seoul, Republic of Korea
12. Remedies for Infringement of Privacy Rights
- Korea Internet & Security Agency Privacy Infringement Report Center: 118, privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972, kopico.go.kr
- Supreme Prosecutors’ Office: 1301, spo.go.kr
- Korean National Police Agency Cybercrime Reporting System: 182, ecrm.police.go.kr
13. Changes to this Privacy Policy
Before a change takes effect, we will publish the change and its effective date through an in-app notice and on the website. As a general rule, a change that materially affects users’ rights will be announced at least 30 days in advance, and we will obtain consent again where required. The previous Policy (Korean, July 20, 2026) and previous Policy (Korean, July 9, 2026) remain available.
Business Information
- Business and service name: Eunhasu
- Representative: Kyounghwan Jung
- Business Registration No.: 414-02-65870
- Mail-order Business Report No.: 2026-Seoul Guro-1242 · Verify business information
- Telephone: 070-8064-3041
- Business address: Room 201, 30 Dorim-ro 20ga-gil, Guro-gu, Seoul, Republic of Korea
- Contact: support.eunhasu@gmail.com