개인정보처리방침
시행일: 2026년 8월 28일 · 버전 0.15 (초안)
고리 에이아이(이하 "회사")는 날개 서비스(이하 "서비스")와 관련하여 「개인정보 보호법」 제30조 및 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 등 관련 법령에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.
제1조 [개인정보의 처리 목적]
회사는 다음의 목적을 위하여 개인정보를 처리합니다. 처리하는 개인정보는 다음의 목적 이외의 용도로는 이용되지 않으며, 이용 목적이 변경되는 경우에는 「개인정보 보호법」 제18조에 따라 별도의 동의를 받는 등 필요한 조치를 이행합니다.
- 회원 가입·본인 식별 및 계정 관리
- 운동 세션 기록·저장, 요약·통계 제공, 기기 간 동기화
- 실외 운동 시 경로 지도 표시 및 위치를 활용한 빙상장·콘텐츠 안내
- 팔로우, 공개 설정에 따른 운동 공유, 좋아요·댓글 등 소셜 기능 제공
- 서비스 개선을 위한 설치 단위 이용 통계 분석 및 오류 진단 (이용 통계 도구가 자동 생성한 앱 인스턴스 식별자는 서비스 계정 식별자와 직접 연계하지 않으며, 사용자는 앱 설정에서 사용 통계 공유를 언제든 끌 수 있습니다. 안정성을 위한 크래시 리포트는 항상 수집됩니다)
- 고객 문의 대응 및 공지사항 전달
- 신고된 콘텐츠 검토 및 서비스 안전·무결성 유지, 대회 참가 자격의 부정 이용 방지(빙상장 근접 확인 포함)를 위한 최소 범위의 운영자 검토
- 앱 내 무료 서비스 운영을 위한 광고 게재 — 기본은 비개인화(문맥 기반) 광고로, 앱 카테고리 등 맥락 정보만 이용
- 이용자가 별도로 동의하고 iOS 추적 허용을 선택한 경우에 한하여, 광고 식별자(IDFA)와 광고 반응 기록을 이용한 맞춤형 광고 게재 (제9조의2)
- 이용자가 동의한 경우 프로모션·이벤트 등 광고성 정보 전송(야간 21시~익일 8시 전송은 별도 동의 시에만 — 정보통신망법 제50조제3항)
제2조 [처리하는 개인정보의 항목]
회사는 다음의 개인정보 항목을 처리합니다.
| 구분 | 수집 항목 | 수집 방법 |
|---|---|---|
| 계정 정보 | 이메일 주소, 표시 이름, 자기소개(bio, 선택), 프로필 이미지(선택), Apple/Google 로그인 식별자 | Apple/Google 소셜 로그인 시 자동 수집 |
| 프로필 정보 (선택) | 키, 체중, 출생 연도, 성별, 국가 | 이용자 직접 입력 |
| 운동 기록 | 운동 시작/종료 시각, 거리, 랩 수, 심박수, 소모 칼로리, 경로(GPS 좌표), 자기장/모션 데이터, 메모, 첨부 사진 | 이용자 기기 및 연동 기기의 센서와 건강 데이터 연동을 통해 자동 수집 |
| 기기 정보 | 기기 모델, OS 버전, 앱 버전, 앱 인스턴스 식별자 | 이용 통계·진단 도구를 통해 자동 수집 (이 항목의 수집에는 하드웨어 고유 식별자와 광고 식별자를 사용하지 않습니다. 광고 식별자는 아래 「광고 관련 정보」 행을 참고하십시오) |
| 위치 정보 | GPS 기반 위치 좌표, 이동 경로, 빙상장 근접 확인을 위한 위치 좌표 | 위치 권한이 허용된 경우 이용자 동의 하에 수집 — 실외 운동 중에는 경로 기록을 위해 계속(백그라운드 포함), 그 밖에는 필요한 시점에 1회. 상세는 위치기반서비스 이용약관 제4조 |
| 이용 통계·진단 정보 | 앱 사용 이벤트(운동 시작/완료, 공유, 팔로우 등 기능 상호작용 로그), 크래시·성능 진단 로그 | 이용 통계·진단 도구를 통해 서비스 이용 중 자동 수집 |
| 광고 관련 정보 | 대략적 위치(IP 기반), 기기 정보, 광고 노출·클릭, (마케팅·광고 활용 동의 시) 광고 식별자(IDFA) | 광고 게재 시 광고 제공 과정에서 자동 수집. 광고 식별자는 마케팅·광고 활용에 동의하고 iOS 추적을 허용한 경우에만 수집 (제9조의2) |
제3조 [개인정보의 처리 및 보유 기간]
- 회사는 법령에 따른 개인정보 보유·이용기간 또는 정보주체로부터 동의받은 보유·이용기간 내에서 개인정보를 처리·보유합니다.
- 이용자가 회원 탈퇴를 요청하거나 수집·이용 목적이 달성된 경우 수집된 개인정보는 지체 없이 파기합니다. 다만, 관계 법령에 따라 보존이 필요한 경우 아래와 같이 일정 기간 보관합니다.
- 서비스 이용 관련 접속 로그: 3개월 (통신비밀보호법 제15조의2)
- 이용자 불만 또는 분쟁 처리 기록: 해당 분쟁이 있는 경우 그 처리 종료 시까지
- 신고 기록: 해당 콘텐츠·계정이 삭제되거나 신고 처리 목적이 달성될 때까지
- 운영자 조치 및 관리자 감사 로그: 생성일로부터 24개월
제4조 [개인정보의 파기절차 및 방법]
- 회사는 개인정보 보유기간의 경과, 처리목적 달성 등 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
- 파기절차: 회사는 파기 사유가 발생한 개인정보를 선정하고, 회사의 개인정보 보호책임자의 승인을 받아 개인정보를 파기합니다.
- 파기방법: 전자적 파일 형태로 저장된 개인정보는 복구·재생이 불가능한 방법으로 영구 삭제하며, 종이에 출력된 개인정보는 분쇄기로 분쇄하거나 소각하여 파기합니다.
제5조 [만 16세 미만 아동·청소년의 개인정보 처리]
회사는 회원가입 시 만 16세 이상임에 대한 이용자의 확인을 받으며, 만 16세 미만의 가입을 허용하지 않습니다. 이는 「개인정보 보호법」이 법정대리인의 동의를 요구하는 만 14세 미만 기준보다 높은 회사의 자체 기준이며, 회사는 별도의 법정대리인 동의 절차를 운영하지 않습니다. 만 16세 미만인 이용자는 계정을 생성하거나 서비스 이용을 위해 개인정보를 제공하지 않아야 합니다.
제6조 [개인정보의 제3자 제공]
- 회사는 개인정보를 제1조에서 명시한 범위 내에서만 처리하며, 원칙적으로 정보주체의 개인정보를 제3자에게 제공하지 않습니다.
- 운동 기록·사진·메모는 해당 게시물에 적용된 공개 범위에 따라 다른 이용자에게 표시됩니다. 이용자는 회원가입 시 공개 범위를 선택할 수 있으며, 선택하지 않은 경우 회사가 정한 초기값이 적용됩니다. 이용자는 이를 언제든지 변경할 수 있습니다. 이는 회사가 제3자에게 제공하는 것이 아니라 서비스 내에서의 게시에 해당하며, 공개 시 표시되는 항목과 비공개로 설정하는 방법은 제9조에서 안내합니다.
- 다만, 다음의 경우에는 「개인정보 보호법」 제17조 및 제18조에 따라 개인정보를 제3자에게 제공할 수 있습니다.
- 이용자가 사전에 동의한 경우
- 법령의 규정에 의거하거나, 수사 목적으로 법령에 정해진 절차와 방법에 따라 수사기관의 요구가 있는 경우
제7조 [개인정보 처리의 위탁]
- 회사는 원활한 서비스 제공을 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.
| 수탁자 | 위탁 업무 |
|---|---|
| Google LLC (Firebase) | 계정 인증, 클라우드 데이터베이스, 파일 저장, 푸시 알림 발송·토큰 관리, 이용 통계 분석, 크래시·성능 진단 |
| Google LLC | 광고 게재 및 게재 통계. 미동의 시 비개인화(문맥) 광고 — 광고 식별자 미사용 / 동의 시 맞춤형 광고는 위탁이 아닌 제3자 제공 (제8조·제9조의2) |
| Google LLC (Google Maps) | 웹 「빙상장 찾기」의 빙상장 지도 표시 및 접속 환경 처리(IP 주소·브라우저 정보) |
| Apple Inc. | Apple 로그인, 건강 데이터 연동, 지도 표시, 푸시 알림 발송 |
- 회사는 위탁계약 체결 시 「개인정보 보호법」 제26조에 따라 위탁업무 수행목적 외 개인정보 처리금지, 기술적·관리적 보호조치, 재위탁 제한, 수탁자에 대한 관리·감독, 손해배상 등 책임에 관한 사항을 문서에 명시하고, 수탁자가 개인정보를 안전하게 처리하는지 감독합니다.
- 위탁 업무 중 일부는 국외에서 처리되며, 자세한 내용은 제8조에서 안내합니다.
제8조 [개인정보의 국외 이전]
회사는 원활한 서비스 제공을 위해 「개인정보 보호법」 제28조의8 제1항 제3호(정보주체와 체결한 계약의 이행을 위한 처리위탁·보관)에 따라 아래와 같이 개인정보 처리를 국외에 위탁(이전)하고 있습니다.
국내 저장 안내: 계정·운동 기록 등 주 데이터베이스·파일 저장소·서버 기능은 대한민국(서울) 리전에 저장·처리되어 국외로 이전되지 않습니다. 아래 항목은 해당 사업자의 글로벌 인프라 특성상 국외를 경유할 수 있는 처리에 한합니다.
| 이전받는 자 (연락처) | 이전 국가 | 이전 항목 | 이전 시기 및 방법 | 이용 목적 | 보유·이용 기간 |
|---|---|---|---|---|---|
| Google LLC (googlekrsupport@google.com) | 미국 | 이용 통계·진단 정보(앱 사용 이벤트, 크래시 로그, 앱 인스턴스 식별자), 푸시 알림 토큰 및 알림 내용, 광고 게재 시 광고 관련 정보(대략적 IP 기반 위치, 기기 정보, 광고 노출·클릭) 및 제3자 제공·국외이전에 동의하고 iOS 추적을 허용한 경우 광고 식별자(IDFA)·광고 반응 기록, Google Maps 접속 시 IP 주소·브라우저 정보 | 서비스 이용·알림 발송 시점부터 네트워크를 통한 전송 | 이용 통계 분석, 크래시·성능 진단, 푸시 알림 발송, 광고 게재(기본은 비개인화, 이용자가 동의하고 iOS 추적을 허용한 경우 맞춤형 — 제9조의2), 빙상장 지도 표시 | 이용 통계는 관리 콘솔에서 설정한 보유기간, 크래시 진단 기록은 90일, 푸시 설치 식별자는 삭제 요청 시까지(삭제 후 백업 포함 최대 180일), 광고·지도 요청 정보는 각 Google 서비스 보유정책에 따른 기간 |
| Apple Inc. (개인정보 문의: apple.com/legal/privacy/contact) | 미국 | 푸시 알림 최종 전송을 위한 기기 푸시 토큰 및 알림 내용, 지도 표시 요청(대략적 위치·좌표) | 알림 발송·지도 표시 시점에 네트워크를 통한 전송 | 푸시 알림 발송, 지도 표시 | 처리 목적 달성 또는 위탁계약 종료 시까지 |
다만 맞춤형 광고를 위한 광고 식별자(IDFA)·광고 반응 기록의 Google LLC(미국) 이전은 처리위탁이 아니라 이용자의 별도 동의에 근거한 국외 제3자 제공이며(「개인정보 보호법」 제28조의8 제1항 제1호 및 제17조), 앱 설정에서 해당 동의를 철회하거나 iOS 설정에서 추적 허용을 해제하면 중단됩니다. 자세한 내용은 제9조의2에서 안내합니다.
이용자는 국외 이전을 거부할 수 있으며, 거부를 원하는 경우 앱 내 회원 탈퇴 또는 고객지원 이메일(cs@narrge.com)을 통해 처리를 중단할 수 있습니다. 다만 이 경우 관련 서비스(푸시 알림, 지도 표시, 무료 광고 기반 서비스 등)의 이용이 제한될 수 있습니다.
제9조 [건강(민감)정보의 처리 및 공개·비공개 선택]
Apple 건강 데이터에서 읽어오는 심박수·소모 칼로리 등 건강 관련 데이터(민감정보)는 선택 항목입니다. 앱의 사전 안내 후 표시되는 iOS 건강 권한 요청을 허용한 범위에서만 수집합니다. 허용하지 않아도 운동 기록(거리·랩 수·시간·경로)은 정상적으로 이용할 수 있고, 이 경우 건강 권한으로 읽어오는 항목만 수집되지 않습니다. 수집된 건강 데이터는 운동 기록의 계산·표시에 사용되며, 신고 검토·안전·무결성 확보를 위해 필요한 최소 범위에서 운영자가 열람할 수 있습니다. 어떠한 경우에도 광고·마케팅·제3자 제공에는 사용되지 않습니다. 이 권한은 언제든지 iOS 설정에서 끌 수 있으며, 이 경우 향후 건강 데이터 읽기가 중지됩니다. 이미 저장된 건강 데이터는 해당 운동 기록 삭제, 회원 탈퇴 또는 고객센터 요청으로 삭제할 수 있습니다.
민감정보의 공개 가능성 및 비공개 선택 방법: 운동 기록의 공개 범위가 전체 공개 또는 팔로워 공개인 경우, 해당 운동의 심박수 등 건강 관련 정보가 다른 이용자에게 표시될 수 있습니다. 심박수·건강 정보의 공개 여부는 운동 공유 시 또는 앱 설정에서 직접 선택할 수 있으며, 비공개로 설정하면 다른 이용자에게 표시되지 않습니다.
경로 지도의 공개 범위: 실외 운동을 공개로 공유하면 다른 이용자에게 표시되는 경로 지도에는 해당 운동의 출발 지점과 도착 지점 좌표가 포함됩니다. 경로 지도의 공개 여부는 운동 공유 시 또는 앱 설정에서 언제든지 변경할 수 있습니다.
공개 시 표시되는 항목: 운동 기록을 공개(전체 공개 또는 팔로워 공개)로 공유하면 거리, 운동 시간, 바퀴 수, 랩타임, 날짜 등 운동의 기본 기록과 이용자가 첨부한 메모·사진은 항상 다른 이용자에게 표시되며, 이 중 개별 항목만 따로 가릴 수는 없습니다. 이를 원하지 않는 경우 해당 운동의 공개 범위를 비공개로 설정하십시오.
선택하여 가릴 수 있는 항목: 위 항목과 달리 다음 두 묶음은 이용자가 공개 여부를 직접 선택할 수 있습니다 — 위치 정보와 건강 데이터입니다. 각 묶음에 어떤 항목이 포함되는지는 앱의 해당 설정 화면에 표시됩니다. 가리기로 선택한 항목은 다른 이용자에게 전송되지 않습니다. 설정은 운동을 저장할 때 운동별로, 또는 앱 설정에서 새 운동에 적용될 기본값으로 변경할 수 있습니다.
제9조의2 [마케팅·광고를 위한 개인정보의 수집·이용 및 국외 제3자 제공]
회사는 앱 내 무료 서비스 운영을 위해 광고를 게재합니다. 광고는 기본적으로 비개인화(문맥 기반)로 제공되며, 이용자가 마케팅·광고 활용을 위한 개인정보 수집·이용, 제3자 제공 및 국외이전에 동의하고 iOS 추적을 허용한 경우에만 아래와 같이 광고 식별자를 이용한 맞춤형 광고가 제공됩니다. 건강(민감)정보는 광고 목적으로 이용하지 않습니다(제9조). 만 16세 미만 이용자에게는 맞춤형 광고를 제공하지 않습니다.
본 조의 동의는 두 가지로 구분하여 각각 받습니다(「개인정보 보호법」 제22조 제1항). ① 수집·이용 동의(같은 법 제15조 제1항 제1호)는 회사가 마케팅·광고 목적으로 개인정보를 수집·이용하는 데 대한 것이고, ② 제3자 제공 및 국외이전 동의(같은 법 제17조 및 제28조의8 제1항 제1호)는 아래 표의 정보가 Google LLC(미국)로 이전되어 Google의 광고 네트워크에서 이용되는 데 대한 것입니다. ①에만 동의하고 ②에는 동의하지 않으실 수 있으며, 이 경우 맞춤형 광고는 제공되지 않습니다. 어느 쪽도 선택 사항이며, 동의하지 않아도 서비스의 모든 기능을 제한 없이 이용할 수 있습니다.
광고 식별자를 이용한 맞춤형 광고 (Google 광고 네트워크)
| 구분 | 내용 |
|---|---|
| 수집하는 행태정보 항목 | 광고 식별자(IDFA), 광고 노출·클릭 등 광고 반응 기록, 기기 정보, 대략적 위치(IP 기반) |
| 수집 방법 | 앱 내 광고 제공 과정에서 광고 요청 시 자동 수집 |
| 수집 목적 | 이용자의 관심사에 맞는 광고 제공 및 광고 효과 측정 |
| 요건 | 수집·이용 동의(제15조 제1항 제1호) 및 제3자 제공·국외이전 동의(제17조, 제28조의8 제1항 제1호) 및 iOS 추적 허용(App Tracking Transparency). 어느 하나라도 충족되지 않으면 광고는 계속 표시되지만 비개인화 광고로 제공됩니다. |
| 보유·이용 기간 | 동의 철회 또는 iOS 추적 허용 해제 시까지. 전송된 정보의 보유기간은 Google의 광고 데이터 보유정책에 따릅니다. |
| 제3자 제공 및 국외이전 | Google LLC(미국) — 별도 동의 시(「개인정보 보호법」 제17조 및 제28조의8 제1항 제1호). 광고 요청 시점에 네트워크를 통해 이전되며, Google이 자사 광고 네트워크 목적으로 이용합니다. 보유·이용 기간은 Google의 광고 데이터 보유정책에 따릅니다. 연락처 등 국외이전 고지사항은 제8조 표를 참고하십시오. 수집·이용 동의만 하고 제3자 제공·국외이전 동의는 하지 않을 수 있으며, 이 경우 맞춤형 광고는 제공되지 않습니다. |
| 거부·철회 방법 | (1) 앱 설정에서 마케팅·광고 활용 동의 철회 (2) iOS 설정에서 앱의 추적 허용 해제 |
한편 서비스 개선을 위한 이용 통계는 광고 식별자를 사용하지 않으며 본 조의 동의와 무관합니다(제10조).
제10조 [개인정보 자동 수집 장치(쿠키 등)의 설치·운영 및 거부]
회사는 서비스 개선을 위한 통계 분석 목적으로 이용 통계·진단 도구를 통해 앱 사용 이벤트와 진단 정보를 자동으로 수집합니다. 이 처리는 「개인정보 보호법」 제15조 제1항 제6호(개인정보처리자의 정당한 이익)에 근거하며, 별도의 동의를 받지 않습니다. 이용 통계 도구가 자동 생성한 앱 인스턴스 식별자로 설치 단위를 구분하지만 서비스 계정 식별자와 직접 연계하지 않으며, 광고 식별자(IDFA)도 사용하지 않습니다. 이용자는 앱 설정에서 이를 언제든지 거부(끄기)할 수 있으며, 안정성 확보를 위한 크래시 리포트는 항상 수집됩니다.
또한 회사 웹사이트(narrge.com)는 이용자의 언어 설정을 저장하기 위한 브라우저 로컬 저장소(localStorage)를 사용합니다. 이는 광고·행태정보 수집용 쿠키가 아니며, 브라우저 설정에서 사이트 데이터를 삭제하여 제거할 수 있습니다. 회사 웹사이트는 광고·행태정보 수집용 쿠키를 사용하지 않습니다.
다만 빙상장 위치를 표시하는 「빙상장 찾기」 페이지는 외부 지도 서비스인 Google Maps를 사용하며, 이 과정에서 접속 IP·브라우저 정보가 Google로 전달됩니다. 해당 페이지는 이용자의 위치를 수집하지 않으며, 지도에는 회사가 보유한 빙상장 좌표만 표시됩니다.
제11조 [정보주체와 법정대리인의 권리·의무 및 행사방법]
- 정보주체는 회사에 대해 언제든지 다음과 같은 권리를 행사할 수 있습니다.
- 개인정보 열람, 정정, 삭제, 처리 정지 요구
- 개인정보 전송 요구 — 앱 내 「내 데이터 내보내기」(JSON 다운로드)
- 회원 탈퇴 및 동의 철회
- 특정 데이터(위치, 사진, 건강 데이터)에 대한 개별 권한 철회 (iOS 설정)
- 설치 단위 이용 통계 수집 거부 — 앱 설정에서 언제든 끄기
- 광고성 정보 수신 동의(광고성 정보 수신·야간 수신) 및 마케팅·광고 활용 동의(수집·이용, 제3자 제공 및 국외이전) 철회 — 앱 설정에서 언제든 끄기 (제9조의2)
- 제1항에 따른 권리 행사는 앱 설정 또는 고객지원 이메일(cs@narrge.com)을 통하여 하실 수 있으며, 회사는 요구를 받은 날로부터 10일 이내에 지체 없이 조치합니다.
- 권리 행사는 정보주체의 법정대리인이나 위임을 받은 대리인을 통하여 하실 수 있습니다. 미성년자의 권리는 법정대리인이 행사할 수 있으나, 회사는 제5조에 따라 만 16세 미만의 가입을 제한하므로 만 16세 미만의 개인정보를 수집하지 않습니다.
- 개인정보 열람 및 처리정지 요구는 「개인정보 보호법」 제35조제4항, 제37조제2항에 의하여 제한될 수 있으며, 다른 법령에서 그 개인정보가 수집 대상으로 명시되어 있는 경우에는 그 삭제를 요구할 수 없습니다.
제12조 [개인정보의 안전성 확보조치 및 유출 등의 통지·신고]
회사는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
- 관리적 조치: 내부 관리계획 수립·시행, 개인정보 취급 직원의 최소화 및 교육, 최소 권한 원칙에 따른 접근 권한 관리
- 기술적 조치: 전송 구간 암호화(TLS), 저장 데이터에 대한 접근 권한의 부여·변경·말소를 통한 접근통제, 접속 기록의 보관 및 위·변조 방지
- 물리적 조치: 클라우드 인프라(Google Cloud 대한민국 리전)의 물리적 보안은 수탁자의 데이터센터 보안 정책에 따름
회사는 개인정보의 분실·도난·유출(이하 "유출등") 사실을 인지한 경우 「개인정보 보호법」 제34조 및 같은 법 시행령이 정한 기한 내에 정보주체에게 그 사실을 통지하며, 법령이 정한 신고 요건에 해당하는 경우 개인정보보호위원회 또는 한국인터넷진흥원에 신고합니다.
- 통지 내용: 유출등이 된 개인정보의 항목, 유출등이 된 시점과 그 경위, 유출등으로 인하여 발생할 수 있는 피해를 최소화하기 위하여 정보주체가 할 수 있는 방법에 관한 정보, 회사의 대응조치 및 피해 구제절차, 정보주체에게 피해가 발생한 경우 신고 등을 접수할 수 있는 담당부서 및 연락처
- 통지 방법: 앱 내 수신함·이메일 등 개별 통지를 원칙으로 하되, 연락처를 알 수 없는 등 개별 통지가 곤란한 경우에는 회사 홈페이지(narrge.com) 게시로 갈음할 수 있습니다.
- 접수 창구: 제13조의 개인정보 보호책임자 (cs@narrge.com)
제13조 [개인정보 보호책임자]
회사는 개인정보 처리에 관한 업무를 총괄해서 책임지고, 개인정보 처리와 관련한 정보주체의 불만처리 및 피해구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
- 성명: 김현진
- 직책: 개인정보 보호책임자 (고리 에이아이 대표자)
- 주소: 서울특별시 마포구 어울마당로 130, 3층 3895호(서교동, 기린빌딩)
- 전화: 010-2812-9639
- 이메일: cs@narrge.com
제14조 [정보주체의 권익침해에 대한 구제방법]
정보주체는 개인정보 침해로 인한 구제를 받기 위하여 아래 기관에 분쟁 해결이나 상담 등을 신청할 수 있습니다.
- 개인정보 분쟁조정위원회: (국번 없이) 1833-6972 (www.kopico.go.kr)
- 개인정보침해 신고센터(KISA): (국번 없이) 118 (privacy.kisa.or.kr)
- 대검찰청 사이버수사과: (국번 없이) 1301 (www.spo.go.kr)
- 경찰청 사이버수사국: (국번 없이) 182 (ecrm.police.go.kr)
타인의 게시물이 명예훼손·사생활 침해 등 자신의 권리를 침해하는 경우에는 위 기관과 별개로 회사에 직접 삭제·임시조치를 요청하실 수 있습니다 — 권리침해 신고. 운영자의 이용 제한·차단 조치에 대한 이의제기는 서비스 이용약관 제8조에 따릅니다.
제15조 [개인정보 처리방침의 변경]
본 개인정보처리방침의 내용 추가, 삭제 및 수정이 있을 경우 변경사항 시행 최소 7일 전(이용자에게 불리하거나 중대한 변경의 경우 최소 30일 전)에 본 페이지에 게시하여 고지하며, 앱 내에서도 확인하실 수 있습니다.
제16조 [본 방침의 적용 범위]
- 본 개인정보처리방침은 회사가 제공하는 날개 모바일 애플리케이션과 회사 웹사이트(narrge.com)에 적용됩니다.
-
다음의 경우에는 본 방침이 적용되지 않습니다. 회사는 해당 사이트·서비스에 대한 통제권이 없으므로 각 사업자가 정한 개인정보처리방침을 확인하시기 바랍니다.
- 서비스에 표시된 빙상장의 웹사이트 등 제3자가 운영하는 외부 사이트(서비스 이용약관 제11조 제7항)
- Apple·Google 로그인 이용 시 각 사업자가 자신의 책임으로 처리하는 개인정보
- 앱을 내려받는 앱 마켓 사업자가 처리하는 개인정보
- 회사는 현재 서비스별 개별 개인정보처리방침을 운영하지 않으며, 향후 개별 방침을 두는 경우 해당 서비스 화면에 별도로 안내합니다.
제17조 [가명정보의 처리]
- 회사는 통계작성, 과학적 연구, 공익적 기록보존 등을 위하여 「개인정보 보호법」 제28조의2에 따라 정보주체의 동의 없이 가명정보를 처리할 수 있습니다. 가명정보란 추가 정보를 사용하지 아니하고는 특정 개인을 알아볼 수 없도록 처리한 개인정보를 말합니다.
-
회사가 가명정보를 처리하는 목적은 다음과 같습니다.
- 랩 감지·거리 산출 등 운동 분석 알고리즘의 정확도 개선을 위한 연구
- 서비스 이용 현황에 관한 통계 작성
-
회사가 가명정보를 처리하는 경우 다음의 조치를 취합니다.
- 가명처리에 사용한 추가 정보를 가명정보와 분리하여 별도로 저장·관리하고 접근 권한을 분리합니다
- 특정 개인을 알아보기 위한 목적으로 가명정보를 처리하지 않으며, 처리 과정에서 특정 개인이 식별되는 경우 즉시 처리를 중지하고 회수·파기합니다
- 가명정보의 처리 목적 등 법령이 정한 사항을 기록하여 보관합니다
- 회사는 가명정보를 제3자에게 제공하지 않으며, 제공하는 경우에도 특정 개인을 알아보기 위하여 사용될 수 있는 정보를 포함하지 않습니다.
Privacy Policy
Effective: August 28, 2026 · Version 0.15 (Draft)
Narrge (the "Service") establishes and discloses this Privacy Policy to protect users' personal information and process it safely and lawfully in accordance with Article 30 of the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other applicable laws.
Article 1 [Purpose of Processing]
The Company processes personal information for the following purposes. Processed information is not used beyond these purposes, and if the purpose changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of the Act.
- Member registration, identity verification, and account management
- Recording and storing workout sessions, providing summaries and statistics, syncing across devices
- Displaying route maps during outdoor workouts, and surfacing rinks and content using location
- Follow, workout sharing based on privacy settings, social features (likes, comments, etc.)
- Installation-level usage-statistics analysis and error diagnosis for service improvement (the app-instance identifier generated by the usage-analytics tool is not directly linked to the Service account identifier; you can turn off usage-statistics sharing anytime in app settings, while crash reports for stability are always collected)
- Responding to customer inquiries and delivering notices
- Operator review, limited to the minimum necessary, to handle reported content, maintain service safety and integrity, and prevent fraudulent event-eligibility (including rink-proximity checks)
- Serving ads to operate the free service — contextual (non-personalized) by default, using only context such as app category
- Serving personalized ads using the advertising identifier (IDFA) and ad-interaction history, only where the user has separately consented and allowed iOS tracking (Article 9-2)
- Sending promotional and event (advertising) messages where you have consented — delivery between 9 PM and 8 AM only with a separate opt-in (Network Act Art. 50(3))
Article 2 [Items of Personal Information Processed]
The Company processes the following personal information items.
| Category | Items collected | Collection method |
|---|---|---|
| Account information | Email address, display name, bio (optional), profile photo (optional), Apple/Google sign-in identifier | Collected automatically at Apple/Google social login |
| Profile information (optional) | Height, weight, birth year, gender, country | Entered directly by user |
| Workout records | Workout start/end time, distance, lap count, heart rate, calories burned, route (GPS coordinates), magnetic/motion data, notes, attached photos | Collected automatically from the user's device and connected devices (sensors and health-data integration) |
| Device information | Device model, OS version, app version, app instance identifier | Collected automatically via usage-analytics and diagnostics tooling (this item is collected without any hardware unique identifier or advertising identifier; for the advertising identifier see the “Advertising data” row below) |
| Location information | GPS-based coordinates, movement route, and a location reading used to verify proximity to the rink | Collected with user consent when location permission is granted — continuously during an outdoor workout to record the route (including in the background), and once at the point it is needed otherwise. See Article 4 of the Location-Based Services Terms |
| Usage & diagnostics | App usage events (feature-interaction logs such as workout start/complete, share, follow), crash and performance diagnostics logs | Collected automatically during service use via usage-analytics and diagnostics tooling |
| Advertising data | Approximate location (IP-based), device information, ad impressions/clicks, and (with marketing/ad-use consent) the advertising identifier (IDFA) | Collected automatically when serving ads. The advertising identifier is collected only where the user consented to the use of personal data for marketing and ads and allowed iOS tracking (Article 9-2) |
Article 3 [Retention and Use Period]
- The Company processes and retains personal information within the retention/use period stipulated by law or consented to by the data subject.
- Personal information is destroyed without delay when the user requests withdrawal or the purpose is achieved. However, where retention is required by applicable law, it is retained as follows:
- Service access logs: 3 months (Communications Secrets Protection Act Art. 15-2)
- Records of user complaints or dispute resolution: until the dispute, if any, is resolved
- Report records: until the relevant content/account is deleted or the report-handling purpose is achieved
- Operator actions and administrator audit logs: 24 months from creation
Article 4 [Destruction Procedure and Method]
- When personal information becomes unnecessary due to the expiry of the retention period or achievement of the purpose, the Company destroys it without delay.
- Procedure: The Company selects the personal information for which a destruction ground has arisen and destroys it with the approval of the Privacy Officer.
- Method: Information stored electronically is permanently deleted using a method that prevents recovery or reproduction; information printed on paper is shredded or incinerated.
Article 5 [Processing of Personal Information of Children and Adolescents Under 16]
At registration the Company obtains the user's confirmation that they are 16 or older and does not permit registration by anyone under 16. This is the Company's own threshold, set higher than the under 14 line at which the Personal Information Protection Act requires legal-guardian consent, and the Company therefore does not operate a separate legal-guardian consent process. Anyone under 16 must not create an account or provide personal information to use the Service.
Article 6 [Third-Party Disclosure]
- The Company processes personal information only within the scope specified in Article 1 and, in principle, does not provide it to third parties.
- Workout records, photos, and notes are displayed to other users according to the visibility applied to that post. Users may choose that visibility at sign-up; where they do not, a default visibility set by the Company applies. The user may change it at any time. This is publication within the Service rather than provision by the Company to a third party; the items shown when sharing, and how to keep them private, are set out in Article 9.
- However, the Company may provide personal information to third parties under Articles 17 and 18 of the Act in the following cases:
- When the user has given prior consent
- When required by law or when a law enforcement agency requests it through legally prescribed procedures for investigative purposes
Article 7 [Entrustment of Processing]
- The Company entrusts personal information processing as follows for smooth service delivery.
| Processor | Entrusted work |
|---|---|
| Google LLC (Firebase) | Account authentication, cloud database, file storage, push notification delivery & token management, usage analytics, crash and performance diagnostics |
| Google LLC | Ad delivery and delivery statistics. Without consent: non-personalized (contextual) ads — no advertising identifier / With consent: personalized ads are a third-party provision, not entrustment (Articles 8 and 9-2) |
| Google LLC (Google Maps) | Rink-map display on the web “Find a Rink” page and processing of connection data (IP address and browser information) |
| Apple Inc. | Apple Sign-In, health data integration, map display, push notification delivery |
- When concluding entrustment contracts, the Company specifies in writing — pursuant to Article 26 of the Act — the prohibition of processing beyond the purpose, technical/administrative safeguards, restrictions on re-entrustment, supervision of the processor, and liability for damages, and supervises whether the processor handles personal information safely.
- Some entrusted work is processed overseas; details are provided in Article 8.
Article 8 [Overseas Transfer of Personal Information]
For smooth service delivery, the Company entrusts (transfers) personal information processing overseas as follows, pursuant to Article 28-8(1)(3) of the Personal Information Protection Act (entrustment/storage for performance of a contract with the data subject).
Domestic storage note: The primary database, file storage, and server functions — including accounts and workout records — are stored and processed in the Republic of Korea (Seoul) region and are not transferred overseas. The items below are limited to processing that may transit outside Korea due to the global infrastructure of the respective providers.
| Transferee (contact) | Country | Items transferred | Time & method | Purpose | Retention/use period |
|---|---|---|---|---|---|
| Google LLC (googlekrsupport@google.com) | United States | Usage & diagnostics (app usage events, crash logs, app instance identifier); push notification token and message content; advertising data when serving ads (approximate IP-based location, device info, ad impressions/clicks) and, where you have consented to third-party provision and overseas transfer and allowed iOS tracking, the advertising identifier (IDFA) and ad interaction records; and IP address/browser information when loading Google Maps | Transmitted over the network from the time of service use / notification delivery | Usage analytics, crash/performance diagnostics, push notification delivery, ad delivery (non-personalized by default; personalized only where you have consented and allowed iOS tracking — see Article 9-2), and rink-map display | usage analytics: the retention period configured in the admin console; crash diagnostics: 90 days; push installation identifiers: until deletion is requested (up to 180 days including backups after deletion); ad/map request data: the period in each Google service's retention policy |
| Apple Inc. (privacy contact: apple.com/legal/privacy/contact) | United States | Device push token and message content for final push delivery; map display requests (approximate location/coordinates) | Transmitted over the network at the time of notification delivery / map display | Push notification delivery, map display | Until the purpose is achieved or the entrustment contract terminates |
However, the transfer of the advertising identifier (IDFA) and ad interaction records to Google LLC (United States) for personalized advertising is not entrustment but an overseas third-party provision based on your separate consent (Personal Information Protection Act Article 28-8(1)(1) and Article 17). It stops when you withdraw that consent in the app's settings, or revoke tracking in iOS Settings. See Article 9-2 for details.
You may refuse the overseas transfer; to do so, you may stop the processing via in-app membership withdrawal or the support email (cs@narrge.com). In that case, related services (push notifications, map display, ad-supported free service, etc.) may be limited.
Article 9 [Processing of Health (Sensitive) Data · Disclosure Possibility and How to Keep Private]
Health-related data read from Apple's Health data — heart rate and calories burned (sensitive data) — is optional. It is collected only within the scope you allow in the iOS Health permission prompt shown after the app's prior notice. You can still record workouts (distance, laps, duration, route) without allowing it; in that case only the items read via the health permission are not collected. Collected health data is used to compute and display your workout records, and may be accessed by operators only to the minimum extent necessary for report handling, safety, and integrity. It is never used for advertising, marketing, or third-party provision. You can turn this permission off at any time in iOS Settings, which stops future health data reads. Existing stored health data can be deleted by deleting the workout, deleting the account, or contacting support.
Disclosure possibility of sensitive data and how to keep it private: Where a workout's visibility is public or followers-only, health-related information such as heart rate for that workout may be shown to other users. You can choose whether to disclose heart rate / health information when sharing a workout or in the app's settings; if set to private, it is not shown to other users.
What a shared route map discloses: If you share an outdoor workout, the route map shown to other users includes the start and end coordinates of that workout. You can change whether the route map is disclosed when sharing a workout or in the app's settings at any time.
What is shown when a workout is shared: Where a workout is shared as public or followers-only, the core workout record (distance, duration, laps, lap times, date, and the like) together with any note or photo you attached is always shown to other users and individual items within it cannot be hidden. If you do not want them shown, set that workout's visibility to Private.
What you can choose to hide: Unlike the items above, two groups are yours to disclose or withhold: Location info and Health data. What each group covers is shown next to the corresponding setting in the app. Items you choose to hide are not sent to other users at all. You can change this per workout when you save a workout, or set the default applied to new workouts in the app's settings.
Article 9-2 [Collection and Use of Personal Data for Marketing and Ads, and Overseas Third-Party Provision]
The Company serves ads to operate the free service. Ads are contextual (non-personalized) by default. Personalized ads using the advertising identifier are served as set out below only where the user has consented to the collection and use of personal data for marketing and ads, to third-party provision and overseas transfer, and has allowed iOS tracking. Health (sensitive) data is not used for advertising purposes (Article 9). Personalized ads are not served to users under 16.
Consent under this Article is obtained as two separately distinguished items (Personal Information Protection Act, Article 22(1)). ① Collection and use (Art. 15(1)(1)) covers the Company collecting and using personal data for marketing and advertising purposes; ② third-party provision and overseas transfer (Art. 17 and Art. 28-8(1)(1)) covers the data in the table below being transferred to Google LLC (United States) and used in Google's advertising network. You may consent to ① without consenting to ②, in which case personalized ads are not served. Both are optional, and declining does not restrict any feature of the Service.
Personalized ads using the advertising identifier (Google advertising network)
| Item | Details |
|---|---|
| Behavioural data collected | Advertising identifier (IDFA), ad impressions/clicks, device information, approximate location (IP-based) |
| Collection method | Collected automatically on ad requests in the course of serving ads |
| Purpose | Serving ads matched to the user's interests and measuring ad effectiveness |
| Requirements | Consent to collection and use (Art. 15(1)(1)) AND consent to third-party provision and overseas transfer (Art. 17, Art. 28-8(1)(1)) AND iOS App Tracking Transparency permission. Unless all of these are met, ads are still shown but remain non-personalized. |
| Retention and use period | Until consent is withdrawn or iOS tracking permission is revoked. Retention of transmitted data follows Google's advertising data retention policy. |
| Third-party provision and overseas transfer | Google LLC (United States) — with separate consent (PIPA Art. 17 and Art. 28-8(1)(1)). Transferred over the network at the time an ad is requested, and used by Google for its own advertising network; retention follows Google's advertising data retention policy. For the transferee's contact details and the other overseas-transfer disclosures, see the table in Article 8. The user may consent to collection/use without consenting to third-party provision and overseas transfer, in which case personalized ads are not served. |
| How to refuse or withdraw | (1) Withdraw the marketing/ad-use consent in the app's settings; (2) revoke tracking permission in iOS Settings |
Separately, usage statistics for service improvement do not use the advertising identifier and are unrelated to the consents under this Article (Article 10).
Article 10 [Automatic Data Collection Devices (Cookies, etc.) — Installation, Operation, and Refusal]
For statistical analysis to improve the service, the Company automatically collects app usage events and diagnostic information via usage-analytics and diagnostics tooling. This processing relies on the legitimate interests of the controller under Article 15(1)(6) of the Personal Information Protection Act and is not based on separate consent; Installations are distinguished by an automatically generated app-instance identifier, but it is not directly linked to the Service account identifier and no advertising identifier (IDFA) is used. You can refuse (turn this off) at any time in app settings; crash reports for stability are always collected.
In addition, the Company website (narrge.com) uses browser local storage (localStorage) to save your language preference. This is not an advertising/behavioral cookie and can be removed by clearing site data in your browser settings. The Company website does not use advertising or behavioral-tracking cookies.
The "Find a Rink" page, which shows rink locations, uses Google Maps as an external map service, and in doing so your IP address and browser information are transmitted to Google. That page does not collect your location; the map shows only the rink coordinates held by the Company.
Article 11 [Rights of Users and Legal Representatives, and How to Exercise Them]
- Data subjects may exercise the following rights against the Company at any time:
- Right to access, correct, delete, and request suspension of processing of personal information
- Right to data portability — in-app "Export My Data" (JSON download)
- Membership withdrawal and consent revocation
- Individual permission revocation for specific data (location, photos, health data) via iOS Settings
- Refusal of installation-level usage-statistics collection — can be turned off anytime in the app's settings
- Withdrawal of consent to receive advertising messages (advertising messages and night-time delivery) and of the marketing/ad-use consents (collection and use; third-party provision and overseas transfer) — can be turned off anytime in the app's settings (Article 9-2)
- These rights may be exercised through app settings or the customer support email (cs@narrge.com), and the Company will act without delay within 10 days of receiving the request.
- Rights may be exercised through the data subject's legal representative or an authorized agent. The rights of minors may be exercised by a legal representative; however, because the Company restricts registration by anyone under 16 pursuant to Article 5, it does not collect the personal information of anyone under 16.
- Requests for access and suspension of processing may be limited under Articles 35(4) and 37(2) of the Act, and deletion cannot be requested where the personal information is specified as a collection target under other statutes.
Article 12 [Security Measures and Breach Notification]
The Company takes the following measures to ensure the security of personal information.
- Administrative: establishment and implementation of an internal management plan, minimization and training of staff handling personal information, least-privilege access management
- Technical: encryption of transmission (TLS), access control via grant/change/revocation of access rights to stored data, retention and tamper prevention of access records
- Physical: physical security of the cloud infrastructure (Google Cloud, Republic of Korea region) follows the processor's data-center security policy
Upon becoming aware of the loss, theft, or leakage of personal information (a "breach"), the Company notifies affected data subjects within the period prescribed by Article 34 of the Personal Information Protection Act and its Enforcement Decree, and reports the breach to the Personal Information Protection Commission or the Korea Internet & Security Agency where the statutory reporting conditions are met.
- Contents of the notice: the categories of personal information involved, when the breach occurred and how, what data subjects can do to minimize potential harm, the Company's response measures and remedy procedures, and the contact point for reporting damage.
- Method: individual notice (such as the in-app inbox or email) as a rule; where individual notice is impracticable — for example, when contact details are unknown — the Company may instead post the notice on its website (narrge.com).
- Contact point: the Privacy Officer in Article 13 (cs@narrge.com).
Article 13 [Privacy Officer]
The Company designates a Privacy Officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies.
- Name: Hyunjin Kim
- Title: Privacy Officer (Kori AI · Representative)
- Address: 130 Eoulmadang-ro, 3F, Room 3895, Mapo-gu, Seoul, Republic of Korea (Seogyo-dong, Giraffe Building)
- Phone: 010-2812-9639
- Email: cs@narrge.com
Article 14 [Remedies for Rights Infringement]
To obtain remedies for personal information infringement, users may apply for dispute resolution or consultation to the following agencies (Korea):
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation: 1301 (www.spo.go.kr)
- National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)
Separately from those agencies, if another user's post infringes your rights — defamation, invasion of privacy and the like — you may ask the Company directly to delete it or apply an interim measure: rights infringement report. Appeals against an operator's usage restriction or account suspension follow Article 8 of the Terms of Service.
Article 15 [Changes to This Privacy Policy]
In the event of additions, deletions, or modifications to this Privacy Policy, notice will be posted on this page at least 7 days before the changes take effect (at least 30 days in advance for changes that are unfavorable or material to users); the notice can also be viewed in the app.
Article 16 [Scope of This Policy]
- This Privacy Policy applies to the Narrge mobile application and to the Company's website (narrge.com).
-
It does not apply to the following. The Company has no control over those sites and services, so please review the privacy policy set by each operator.
- External sites operated by third parties, such as the websites of rinks shown in the Service (Terms of Service, Article 11(7))
- Personal information that Apple or Google processes under its own responsibility when you sign in with those accounts
- Personal information processed by the app marketplace from which you download the app
- The Company does not currently operate service-specific privacy policies; if it introduces one, it will be announced separately on that service's screen.
Article 17 [Processing of Pseudonymized Information]
- The Company may process pseudonymized information without the data subject's consent for purposes such as compiling statistics, scientific research, and archiving in the public interest, under Article 28-2 of the Personal Information Protection Act. "Pseudonymized information" means personal information processed so that a specific individual cannot be identified without additional information.
-
The Company's purposes for processing pseudonymized information are:
- research to improve the accuracy of workout-analysis algorithms such as lap detection and distance calculation
- compiling statistics on service usage
-
Where the Company processes pseudonymized information, it takes the following measures:
- stores and manages the additional information used for pseudonymization separately from the pseudonymized information, with segregated access rights
- does not process pseudonymized information for the purpose of identifying a specific individual, and where an individual becomes identifiable during processing, immediately stops processing and retrieves or destroys the data
- keeps records of the processing purposes and other matters prescribed by law
- The Company does not provide pseudonymized information to third parties, and where it does, it does not include information that could be used to identify a specific individual.