Geupddong policies
Privacy Policy
Revised policy · Announced: 10/09/2026, 17:45:00 · Effective: 10/09/2026, 18:00:00 (Korea time)
Previous policy (Korean) 1 September 2026Changes to account deletion and recovery
The revisions below apply from the effective time shown above. The previous policy applies before that time. Publication alone does not activate account features or count as consent to retain recovery data. The account screen explains whether each feature is available.
- Recovery information is retained for 3 months only if you separately opt in when requesting account deletion.
- If you do not consent, request erasure or reach the end of the retention period, your account information becomes subject to erasure. Report and audit work records with personal information removed are retained.
- The purpose and end-of-retention procedure for encrypted records kept in Korea to prevent deleted accounts from reappearing are explained below.
Review feature policy
Review policy · Announced and effective: 12/09/2026, 18:30:00 (Korea time)
- Location, accuracy and measurement time are checked temporarily so that signed-in users can write reviews only when near the restroom.
- Removing author information disconnects the author and changes the displayed name to “Anonymous”. Ratings and free-text comments remain as service information.
- Review availability is controlled by separate server safety settings. Publishing this policy does not automatically activate reviews.
Profile photo storage policy
Profile photo policy · Announced and effective: 15/09/2026, 04:30:00 (Korea time)
- Kakao photos optionally provided at sign-up, or photos uploaded by users, are converted to a small WebP image and stored in private Cloudflare R2 storage in the United States.
- If you agree to provide your Kakao photo or upload a photo yourself, it is shown as your author photo on public reviews. You can turn this off at any time in My page.
- Public photos may be temporarily cached on Cloudflare CDN for up to 5 minutes for faster display. When a photo is made private, replaced or deleted, public access is blocked and CDN cache deletion is requested.
- You can use account features with the default avatar without providing a profile photo. Publishing this policy does not automatically activate the photo feature.
1. Personal information collected
- Social login: provider, hash of the provider’s member identifier, display name, email address and email verification status.
- Profile photo: a converted image from a Kakao profile photo you agreed to provide at new sign-up, or a photo you uploaded; its visibility, collection source, and the version and time of the notice applied. Registered photos are shown as author photos on public reviews, and sharing can be turned off at any time in My page. Original files and original Kakao image URLs are not stored after conversion.
- Service use: roles, policies agreed to and their versions and timestamps, and last login time.
- Reports: target restroom, report content, selected coordinates and road-name address, processing status and administrator notes.
- Reviews: target restroom, satisfaction and cleanliness scores, toilet-paper availability, waiting time, optional comment, creation and modification times, author account link, and a review identifier used to prevent unauthorized changes.
- Review eligibility: current location, location accuracy and measurement time at the time of the request. The server checks that the location is within 150 m of the restroom, accuracy is 50 m or better, and the measurement is no more than 5 minutes old. Exact current-location coordinates are not saved in the review.
- Service usage statistics: page types; visits, views, sessions and engagement time; traffic sources; device, operating system and browser; country- and city-level connection area; search success and result-count ranges; and use of features such as markers, details, reports and reviews. Raw search terms, email addresses and account identifiers, precise locations and coordinates, restroom addresses and free-text input are not included in statistics collection requests.
- Operations and security: access records, audit logs and error records.
2. Purposes of use
Information is used to identify members, provide social login, receive reports and provide processing results, verify review eligibility near the restroom, provide reviews and prevent misuse or duplicate use, respond to failures and improve service quality. Service usage statistics are used to aggregate usage volume and changes in major features, pages, traffic sources and device environments to identify failures and usability problems.
3. Retention periods
- Email address, verification status and ordinary login information: deleted or reset when the account is deleted.
- Account recovery information: 3 calendar months from the account deletion request, only if separately and optionally agreed to when requesting deletion. The social provider and protected unique identifier, nickname, account and report links, and consent, deletion-request and scheduled-erasure times are retained for recovery. Email addresses and social tokens are not retained for recovery.
- No consent to recovery retention, or an erasure request during retention: account and social identification information, per-member consents and notifications, and member links and free-text reasons in reports are erased. Signing up again with the same social login does not reconnect the previous account.
- Refresh tokens: up to 14 days after issuance, or until logout or account deletion.
- Reviews: ratings, cleanliness scores, toilet-paper availability, waiting times and optional comments are retained while the service provides user experiences of the restroom. Selecting “Remove author information” removes the author account link and submission-request link and displays the author as “Anonymous”, but the review content remains. Editing or deletion is reviewed separately in cases such as reports of personal-information exposure or infringement of rights, legal obligations, or service closure.
- Location used for review eligibility: used only while processing the eligibility request and not stored in the review record.
- Reports and processing history: work records with personal information removed are retained without deletion merely because time has passed. When account information is erased, author links and free-text reasons and review notes that may contain personal information are removed. Approved information already applied to public restroom data is retained.
- Operational audit history: records of actions and processing results with personal information removed are retained without deletion merely because time has passed. This does not mean that originals containing personal information are kept permanently. When account information is erased, the identifying links and details for that member are removed.
- General access and system logs: this account-deletion revision does not introduce a new service-wide time-based log deletion policy or storage method. Existing operational log rotation and capacity limits remain. Permanent storage of original logs is not guaranteed.
Consent to recovery retention is optional; you may delete your account without it. During retention, you can sign in with the same social account and request immediate deletion without recovery, or contact the privacy email address. Information whose retention purpose has ended is destroyed using methods that make recovery difficult. Where applicable law requires separate retention, it is kept separately on the relevant basis and for the relevant period. If a failure delays erasure, retries occur while service use and recovery remain blocked.
4. External services
We use Google and Kakao OAuth for login, Kakao Maps for maps and address verification, and Cloudflare for web delivery, security, email forwarding and profile photo storage. Each provider’s policies apply to information it processes during authentication and transmission. Service usage statistics are calculated directly on Geupddong servers rather than sent to a separate external analytics tool.
4-1. Service usage statistics
To check service operation and usability problems, Geupddong servers aggregate page types, traffic-source categories, device environments and use of major features. Google analytics tags and Google Analytics cookies are not used.
- Purpose
- Statistics on visits, views, traffic sources, device environments and major feature use, and service improvement.
- Traffic-source information
- At the start of a session, only the previous website’s domain and the source and medium categories of share or campaign links issued by Geupddong are processed. Full previous-page URLs, search terms and query strings are not stored.
- Minimizing identification
- Part of the connection-network information and device information are converted into period-specific cryptographic hashes to count repeat visits. Original IP addresses are not stored in the analytics tables.
- Browser storage
- A random session value and initial traffic-source categories are kept in sessionStorage for the tab session. localStorage stores only whether a first visit has been recorded; this flag may remain until you clear the browser’s site data. Clearing site data resets session and first-visit counting but does not stop statistics collection.
- Retention
- Individual analytics events are deleted after no more than 35 days. Daily aggregate statistics that do not contain personal information or original input text are retained to track long-term operating trends.
- Excluded data
- Raw search terms, member and social identifiers, precise GPS and restroom coordinates and addresses, and free-text report and review content.
4-2. Overseas profile photo storage and caching
Profile photo policy · Announced and effective: 15/09/2026, 04:30:00 (Korea time)
- Transferred items
- Profile photos converted to WebP, at most 256×256 pixels.
- Country, timing and method
- United States. Transferred online over encrypted communications when you consent to provide a Kakao photo at new sign-up or upload a photo yourself.
- Recipient
- Cloudflare, Inc. · legal@cloudflare.com
- Purpose and period
- Storage in private R2 to display the photo to you and provide it as your author photo on public reviews, until you delete the photo or delete your account.
- Public display and caching
- While sharing on reviews is enabled, the converted image is provided at a dedicated public URL and may be temporarily cached on Cloudflare CDN for up to 5 minutes for faster display. Browsers use ETags to recheck whether a photo has changed. Turning off sharing, replacing or deleting a photo, or deleting your account blocks public access on the server and requests CDN cache deletion. Cache copies already delivered may remain visible temporarily until deletion is complete or the maximum 5-minute cache period expires.
- How to decline and the effects
- You can decline to provide a photo on the Kakao sign-up screen or choose not to upload a profile photo. After registration, you can also turn off review photo sharing in My page. Account features remain available with the default avatar.
4-3. Backups and records that prevent deleted accounts from reappearing
Erasing account information in the service database, optionally retaining recovery information for 3 months, encrypted backups, and records that prevent deleted accounts from reappearing are separate processes. An account-information erasure confirmation does not mean all existing copies were erased simultaneously.
Recovery is blocked after the recovery deadline of 3 calendar months from the account deletion request. Expired information becomes eligible for the regular erasure job after the daily public-data collection ends. Failures are managed as pending or failed, not marked as complete.
Minimal records are kept separately and applied during restoration checks to prevent old accounts in backups from being restored. These records are not assumed to be anonymous merely because they are encrypted.
- Location and operator
- A separate file area on a server in Korea managed by the Geupddong operator. Access is restricted and kept separate from the service database.
- Storage structure
- Per-member records that prevent deleted accounts from reappearing are configured to be stored as encrypted local files. New records of this kind are not stored in Cloudflare R2. Because they are separate files on the same server, they are not an independent backup protecting against loss of the entire server or disk.
- Recorded items
- Minimal processing evidence, such as internal member ID, sign-up time, deletion-request identifier, erasure-due time, database restore generation and format information, and erasure confirmation time. Email addresses, nicknames and social tokens are not included in this ledger.
- Timing and method
- Before final account-information erasure, an encrypted protective record is saved to a local file, and evidence confirming the result is kept. Independent verification criteria are checked against separately retained verification records.
- Conditions for ending retention
- We confirm that the member’s information has been erased from the service database and check whether old copies capable of restoring the member still exist. After confirming that related copies are gone, no restore is in progress, and independent verification criteria are updated, the member’s record is erased through a review and approval process. The current tool’s 32 days after the first confirmation of absence from the database is a minimum waiting threshold to begin review, not a statutory retention period or automatic deletion date. It is also separate from the 3-month recovery retention period.
Separately retained private independent-verification records contain aggregate counts, verification hashes and restore generations rather than member-by-member lists. They do not contain original per-member ledger records or encryption keys. Changing to local storage does not mean all processing by external services used for web delivery, authentication and independent verification is confined to Korea.
Checks cover encrypted database backups, database change logs, old Redis persistence files, previous database volumes, temporary restore copies and remaining copies in previously used external storage. Missing evidence or failed checks are not treated as proof that no copies exist. Reasons for continued retention are reviewed, and personal-information records no longer needed become subject to erasure. You may request deletion or suspension of processing through the contact below.
5. Your rights
You may check the processing status of your reports and view My reviews. Within 7 days of writing a review, you may edit it yourself or remove its author link. You may request account deletion from the account screen. For reviews past the self-service period, or for requests to access, correct, delete or suspend processing of personal information in review text, email the contact with information identifying the review and the relevant part.
6. Security measures
We use HttpOnly secure cookies, short-lived JWTs, Redis-based refresh-token revocation, separate storage for passwords and tokens, access controls and audit logs.
7. Children under 14
Geupddong account features are not intended for children under 14. If a user is confirmed to be under 14, access to account features is stopped and the related account information is deleted.
Contact
Operator: Geupddong (an individually operated service)
Privacy enquiries: privacy@geupddong.com