Somewhere
HomeHome 대한민국 이용약관Korea Terms of Service

대한민국 개인정보처리방침Korea Privacy Policy

시행일: 2026년 9월 28일

문서를 불러오는 중입니다.Loading document.

NP Somewhere(이하 "회사" 또는 "운영자")는 「개인정보 보호법」 제30조에 따라 정보주체(이용자)의 개인정보를 보호하고 관련 고충을 신속하게 처리하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다. 본 방침은 여행 계획 앱 "Somewhere"(이하 "서비스")와 공식 웹사이트에 적용됩니다.

제1조 - 개인정보의 처리 목적

회사는 아래 목적에 필요한 개인정보를 처리해요. 처리 목적이 변경되는 경우 「개인정보 보호법」 제18조에 따라 별도 동의 등 필요한 조치를 이행해요.

  • 회원 가입·계정 관리, 본인 확인, 친구 확인 및 서비스 부정이용 방지
  • 여행 일정·장소·메모·이미지·지출·정산 정보의 생성·저장·공유 및 협업
  • AI 여행 생성, AI 대화·일정 편집, Google Places API를 통한 장소 검색·검증
  • 이용자가 요청한 트리플 공유 일정·지출·첨부 이미지 가져오기
  • Somewhere Pro 구매·복원·구독 관리, AI 크레딧 지급·차감 및 광고 보상 검증
  • 서비스 이용 통계 분석, 서비스 개선, 고객 문의·버그 제보·장애·보안 대응
  • 이용자의 지역·광고 동의·기기 설정에 따른 광고 제공 및 성과 측정

제2조 - 수집하는 개인정보의 항목 및 수집 방법

  • 계정·프로필: 이메일, Firebase UID 또는 게스트 ID, 이름·닉네임, 프로필 이미지, 로그인 제공자 및 제공자 식별자
  • 서비스 콘텐츠: 여행 제목·날짜·도시·국가, 장소 이름·주소·ID·좌표, 메모, 동행자·취향, 여행·장소 이미지, 친구 초대·공유 정보, 지출 금액·통화·결제수단·결제자·정산 대상 및 영수증·첨부 이미지
  • AI 여행 생성·대화·일정 편집: 입력 메시지, 최근 대화 내용, 여행지·날짜·인원·취향·예산·언어, 현재 편집 중인 여행의 제목·날짜·장소·좌표·메모, AI 답변·일정 수정 제안 및 요청·처리 기록
  • 트리플 가져오기: 이용자가 제출한 공유 링크에서 추출한 여행 코드, 언어, 원본 일정·장소·메모·지출·사용자 첨부 이미지, 원본 콘텐츠 해시, 가져오기 상태·결과·오류 기록. 원본 공유 URL 전체는 저장하지 않아요.
  • 구독·크레딧·광고 보상: RevenueCat 앱 사용자 ID, 구독 상품·스토어·구매·복원·만료·갱신 상태, 구독 관리 URL, 거래·영수증 검증 정보, 크레딧 잔액·주간 기준·지급·차감·광고 보상 내역, 보상 거래 ID·광고 네트워크·광고 단위·처리 시각. 카드번호 등 원 결제정보는 앱 마켓 또는 결제사업자가 처리해요.
  • 부정이용 방지: UID, 정규화한 이메일의 해시, 가입 보너스 지급·청구 기록, 탈퇴 시각·사유 및 만료 정보
  • 앱·기기 보안 검증: Firebase App Check 토큰과 Google Play Integrity 또는 Apple App Attest/DeviceCheck의 증명 자료. 앱·기기의 무결성을 확인하고 무단 접근·부정이용을 방지하기 위해 처리해요.
  • 문의·제보(선택): Google Forms 등에 제출한 이메일·문의 내용·첨부 이미지·파일 또는 Instagram 프로필·DM·댓글 내용
  • 위치정보(선택): 기기 위치 권한을 허용한 경우 지도에 표시하는 현재 위치
  • 자동 수집 정보: 기기 종류·OS·앱 버전·세부 기기 정보, 도시 수준 위치, IP 주소, 접속 일시·이용 기록, 오류·진단 정보, 광고 식별자(ADID/IDFA), 앱 화면·기능 이용 통계 및 Google Signals 기반 분석 정보
  • Sentry 오류 진단(프로젝트 DSN이 설정된 경우 로그인 오류 또는 일부 기능의 진단 대상 오류가 보고될 때): 로그인 오류의 인증 제공자, 일부 기능 오류의 기능 구분·작업명·오류 단계·진단 코드, 오류 유형·정제된 스택 추적, 앱 버전·플랫폼·운영체제/기기 진단정보. 오류 메시지는 일반 문구로 바꾸며 계정 ID·이메일·여행·경비 내용·AI 입력·URL·토큰·앱 요청/응답 본문·헤더·탐색 기록은 보고서에 넣지 않아요. 오류 보고에 연결 IP 주소가 자동으로 포함될 수 있으며, Sentry의 IP 저장 여부는 프로젝트 개인정보 설정에 따라 달라요. 로그인과 일부 기능의 오류 해결 및 서비스 안정성 개선에 이용해요.

이용자가 직접 입력·업로드하거나 서비스 이용 중 자동으로 생성되는 정보를 수집해요. 트리플 가져오기는 이용자가 제출한 외부 공유 페이지에서 정보를 읽고, 대상 이미지의 사본을 회사의 저장소에 보관해요.

AI 대화·일정 편집에서는 입력 메시지와 최근 대화, 현재 편집 중인 여행·날짜·장소의 제목·좌표·메모 등을 OpenAI에 전송해요. 편집 요청에 동행자 목록·지출·사진 파일은 포함하지 않으며, 장소 검증에 필요한 장소명·언어·좌표 등은 Google Places API로 전송할 수 있어요.

AI 답변은 여행 계획을 돕는 참고 자료예요. 회사의 AI는 이용자의 권리·의무에 중대한 영향을 미치는 자동화된 결정을 내리지 않으며, 일정 수정 제안을 실제로 적용할지는 이용자가 선택해요.

민감정보·고유식별정보, 다른 사람의 개인정보 또는 비밀번호를 AI 메시지나 메모에 입력하지 않도록 주의해 주세요. 부적절한 AI 답변이나 개인정보 노출이 우려되는 경우 contact@npsomewhere.com로 문의·신고하거나 이의를 제기할 수 있어요.

OpenAI 정책상 API 입력·출력은 회사가 학습용 데이터 공유에 명시적으로 참여하지 않는 한 기본적으로 모델 학습에 사용되지 않아요. 서비스는 응답 저장 기능을 사용하지 않아요. 회사가 학습을 위한 새로운 이용 목적을 추가하는 경우 해당 목적·범위를 안내하고 필요한 동의 등 법적 근거를 먼저 갖춰요. 서비스 보안·악용 방지 로그는 OpenAI의 데이터 처리 정책에 따라 별도로 보관될 수 있어요.

현재 위치는 지도 표시용으로 사용하며 회사의 Firebase 데이터베이스에 저장하지 않아요. 지도 제공자가 위치·기기 정보를 처리할 수 있고, 이용자가 일정에 저장한 장소의 이름·주소·좌표는 여행 데이터로 보관될 수 있어요.

로그인한 회원의 Firebase UID를 Google Analytics for Firebase의 사용자 식별자로 전송하고, 화면 조회·로그인·구독·광고 보상 등 이용 이벤트와 회원 유형을 분석해요. 이메일은 Analytics 사용자 식별자로 전송하지 않아요. Google Signals, 도시 수준 위치·세부 기기 데이터 및 광고 개인화 설정에 따른 데이터 처리도 이루어질 수 있으며, 광고 제공 방식은 지역·광고 동의·기기 설정에 따라 달라져요.

회원·여행·공유 데이터와 업로드 이미지는 Firebase/Google Cloud에 보관해요. 앱 설정·계정/구독 캐시·이미지·가져오기 진행 상태 등은 기기 내 DataStore 또는 로컬 저장소에 저장될 수 있고, 앱 삭제 또는 앱 데이터 삭제로 제거할 수 있어요. Google Forms 제보와 첨부파일은 Google Forms/Drive에서 처리하며, Instagram 문의는 해당 서비스 안에서 처리하고 회사가 별도 시스템에 복사·보관하지 않아요.

수집 항목별 처리 근거

  • 동의 없이 처리하는 정보 — 계정·프로필, 여행·공유 콘텐츠, 이용자가 요청한 AI 입력·일정 편집·가져오기 정보, 구독·크레딧 정보: 서비스 계약의 체결·이행을 위한 처리(개인정보 보호법 제15조 제1항 제4호)
  • 동의 없이 처리하는 정보 — Sentry 로그인·일부 기능 오류 진단 기록을 포함한 오류·보안 기록, 앱·기기 무결성 검증 정보, 탈퇴 및 가입 보너스 중복 수령 방지 기록, 광고 보상 검증 기록: 최소한의 정보로 보안·부정이용을 방지하기 위한 정당한 이익(제15조 제1항 제6호). 회사의 이익이 정보주체의 권리보다 명백히 우선하는 범위에 한해 처리해요.
  • 동의 없이 처리하는 정보 — 서비스 운영·개선을 위한 이용 통계: 정보주체의 권리를 침해하지 않는 범위의 정당한 이익(제15조 제1항 제6호). 광고 개인화에 필요한 처리는 별도 광고 동의·설정 및 적용 법령에 따라 구분해요.
  • 동의를 받아 처리하는 정보 — 동의가 필요한 맞춤형 광고·추적 및 선택적 위치정보: 정보주체의 동의(제15조 제1항 제1호). 위치 권한, 기기 추적 설정 및 표시되는 광고 개인정보 옵션을 통해 선택할 수 있어요.
  • 법령에 따라 보존하는 거래·분쟁 기록: 법적 의무 이행(제15조 제1항 제2호). 실제로 회사가 보유하는 기록에 한해 해당 법정 기간을 적용해요.

미국 법령상 개인정보 범주

위 항목은 미국 법령상 다음 범주에 해당할 수 있어요. 이용자·기기·로그인 및 결제 사업자·이용자가 제출한 외부 공유 페이지에서 정보를 받고, 제1조의 목적에 사용해요. 범주별 보유기간은 제3조, 제공 대상·목적은 제4조부터 제7조를 확인해 주세요.

  • 식별자: 이름·이메일·UID·기기 및 광고 식별자·IP 주소
  • 상업 정보: 구매·구독·거래·크레딧·여행 지출 기록
  • 인터넷·네트워크 활동: 화면·기능 이용, 광고 시청·클릭, 접속·오류 기록
  • 위치 정보: 도시 수준 위치, 여행 장소의 주소·좌표 및 권한 허용 시 현재 위치
  • 시각 정보 및 이용자가 제공한 콘텐츠: 프로필·여행·영수증 이미지, 메모·문의·AI 메시지
  • 선호 정보 및 추론: 이용자가 입력한 여행 취향과 그 입력을 바탕으로 생성한 AI 여행 제안

기기의 정확한 현재 위치는 미국 법령상 민감 개인정보에 해당할 수 있어요. 위치 권한을 허용한 경우 요청한 지도 기능을 위해 사용하며 회사의 Firebase 데이터베이스에 저장하지 않아요. 이용자가 권한을 철회할 수 있고, 허용된 목적을 벗어나는 민감정보 이용·제공의 제한은 제11조에서 안내해요.

제3조 - 개인정보의 처리 및 보유 기간

개인정보는 아래 기간 또는 법령에서 정한 기간 동안 보관해요. 보유기간이 지나거나 처리 목적이 달성되면 파기하며, 탈퇴 후에도 보관하는 부정이용 방지·보상 검증 기록은 해당 목적에 필요한 최소 항목으로 제한해요.

  • 회원·프로필·여행·공유·지출 데이터, 구독 상태 미러 및 크레딧 잔액: 계정 삭제 또는 처리 목적 달성 시까지
  • AI 여행 생성 요청 기록(해시된 사용자 식별자·요청 지문·처리 정보): 생성 또는 실패 시점부터 30일
  • AI 여행 생성 상태: 계정 삭제 시까지
  • AI 대화·일정 편집 요청 및 결과(해시된 식별자·요청 지문·응답·수정 제안·처리 상태): 각 요청의 처리·완료·실패 시점부터 24시간. 기기에서 진행 중인 대화는 해당 대화가 초기화되거나 앱 데이터가 삭제될 때까지 보관될 수 있어요.
  • 트리플 가져오기 작업 기록: 작업 생성·최종 처리 시점부터 30일. 가져온 일정·지출·이미지는 일반 여행 데이터와 동일하게 보관해요.
  • 가입 보너스 중복 수령 방지 기록(UID·이메일 해시·지급/청구 시각): 기록 생성부터 90일. 계정 삭제 시 갱신한 기록은 탈퇴 시점부터 90일 보관해요.
  • 탈퇴 제한 기록(UID·탈퇴 시각): 탈퇴 시점부터 90일
  • 광고 보상 검증 기록(UID·거래 ID·광고 네트워크/단위·지급 결과·처리 시각): 보상 처리일부터 90일. 중복 지급·부정이용 검증을 위해 탈퇴 후에도 해당 기간 내에 보관할 수 있어요.
  • 여행 초대 토큰·상태: 발급 후 24시간에 만료되고 만료 후 정기 정리
  • 운영자 감사 로그(식별자·이메일·변경 사유·변경 전후 설정): 생성일부터 365일
  • Google Analytics for Firebase 사용자·이벤트 수준 데이터: 2개월. 새 이용 활동으로 보유기간을 재설정하지 않아요.
  • 분리된 이미지의 삭제 대기 정보: 24시간 유예 후 정기적으로 실제 파일 삭제
  • Google Forms 고객 문의·버그 제보: 문의·오류 조치 완료 시까지, 처리 완료 후 파기
  • Instagram 문의: 이용자가 삭제하거나 Meta/Instagram 정책에 따른 기간, 회사의 별도 복사본 없음
  • 기기 내 캐시·설정·로컬 알림 정보: 앱 삭제 또는 앱 데이터 삭제 시까지
  • 앱·기기 보안 검증: App Check는 증명 자료를 보관하지 않으며, 재전송 방지 기능에 사용하지 않는 토큰은 Firebase 서비스에 보관하지 않아요. 검증 제공자가 처리하는 증명 자료에는 Google 또는 Apple의 보안 서비스 보유 기준이 적용돼요.
  • Sentry 오류 진단 보고: Sentry 프로젝트의 보유기간 설정에 따라 보관한 뒤 Sentry의 삭제 기준에 따라 삭제해요.

회사가 실제로 보유하는 기록 중 전자상거래법상 보존 대상은 표시·광고 기록 6개월, 계약·청약철회 및 대금결제·공급 기록 5년, 소비자 불만·분쟁 처리 기록 3년 동안 보관해요. 앱 마켓이 독립적으로 보유하는 구매 기록과 외부 사업자 기록은 해당 사업자의 법적 의무·정책에 따른 기간이 적용돼요.

자동 파기 대상은 보유기간이 끝나면 삭제 대상으로 전환되고 시스템의 정기 처리 과정에서 순차적으로 삭제돼요. 법정 보존 대상은 별도로 보관하고 해당 목적으로만 이용해요.

제4조 - 개인정보의 제3자 제공

회사는 개인정보를 데이터 거래 목적으로 구매하거나 판매하지 않아요. 정보주체의 동의 또는 법률상 허용되는 경우에 한해 제3자에게 제공하며, 서비스 위탁·외부 기능·광고 SDK의 데이터 처리는 제5조부터 제7조에서 안내해요.

  • 여행 공유: 이용자가 선택한 초대 대상에게 설정한 일정·지출 권한에 따라 여행 제목·날짜·일정·장소·메모·이미지·지출·정산 정보를 제공해요. 해당 이용자와의 여행 공유를 해제할 수 있어요.
  • 친구·프로필 확인: QR 코드 등으로 정확한 UID를 확인한 로그인 이용자는 해당 회원의 이름·이메일·프로필 이미지를 조회할 수 있어요. 전체 회원 목록의 조회·검색은 허용하지 않으며, 여행 공유 해제만으로 프로필 조회 가능성이 없어지는 것은 아니에요.
  • Google·Apple 로그인·결제, 지도·광고 및 Instagram 문의 등 외부 서비스: 각 사업자가 자신의 서비스 제공과 법적 의무를 위해 개인정보를 독립적으로 처리할 수 있어요. 회사의 위탁 처리와는 구분하며 해당 사업자의 정책도 적용돼요.

맞춤형 광고 과정의 데이터 처리는 금전적 대가를 받는 개인정보 판매와 별개로, 적용되는 법령상 광고 목적의 공유에 해당할 수 있어요. 광고 관련 처리 항목·설정 및 거부 방법은 제7조에서 확인할 수 있어요.

제5조 - 개인정보 처리의 위탁

회사는 아래 사업자에게 서비스 제공에 필요한 개인정보 처리를 위탁해요. 사업자가 독립적으로 처리하는 로그인·결제·광고·문의 데이터는 위탁과 구분해요.

  • Google LLC: Firebase Authentication·Firestore·Storage·Cloud Functions를 통한 인증·저장·클라우드 운영, Firebase App Check 앱·기기 보안 검증, Google Places API 장소 검색·검증, Google Forms/Drive 문의 접수·첨부파일 보관, 적용되는 계약 범위의 이용 통계 처리
  • OpenAI OpCo, LLC: Responses API를 통한 AI 여행 생성, AI 대화·일정 편집
  • RevenueCat, Inc.: 구독·구매 복원·entitlement 확인, 고객 식별자 및 구독 관리 링크 처리
  • Functional Software, Inc. (Sentry): 로그인 및 일부 기능의 선택된 오류 진단 보고 처리. Sentry 데이터 처리계약 및 재수탁자 안내

회사는 수탁자의 업무·보호조치·재위탁·삭제 및 권리 요청 처리 등을 계약에 반영하고 관리·감독해요. Apple의 로그인·App Store 결제·App Attest/DeviceCheck 검증, Google Play 결제·AdMob 광고, Meta/Instagram 문의 등 독립적인 처리에는 각 사업자의 정책이 적용되며, 이를 모두 회사의 수탁업무로 분류하지 않아요.

사업자별 처리 정보와 문의 경로: Firebase 개인정보 안내, Google 개인정보처리방침, OpenAI 데이터 처리계약, RevenueCat 데이터 처리계약, Apple 개인정보 보호정책, Instagram 개인정보처리방침

제6조 - 개인정보의 국외 이전

여행·프로필 등 회사가 직접 관리하는 Firestore 데이터와 서울 리전을 선택한 클라우드 기능은 asia-northeast3(서울)을 사용해요. Firebase Authentication은 미국에서 처리되며, 서울 리전 선택이 인증·분석·광고 등 모든 외부 서비스의 국내 처리까지 보장하는 것은 아니에요.

계약 체결·이행에 필요한 인증·클라우드·AI·장소 검색·구독 관리의 국외 처리위탁·보관은 개인정보 보호법 제28조의8 제1항 제3호에 따라 아래 사항을 공개하여 처리해요. 계약 이행에 필요하지 않은 맞춤형 광고·추적 또는 외부 사업자에게 제공하는 정보는 별도 동의 등 해당 처리에 적용되는 법적 근거가 충족되는 범위에서 이전해요.

Functional Software, Inc. (Sentry)

  • 이전 국가: 미국·독일 등 Sentry가 제공하는 처리 리전. 실제 저장 리전은 프로젝트 설정에 따라 달라요.
  • 이전 시기·방법: DSN이 설정된 앱에서 로그인 오류 또는 일부 기능의 진단 대상 오류가 보고될 때 진단정보를 정보통신망으로 전송해요.
  • 이전 항목·목적: 로그인 오류의 인증 제공자·단계·코드와 일부 기능 오류의 기능 구분·작업명·오류 단계·진단 코드, 오류 유형·정제된 스택 추적, 앱 버전·플랫폼·운영체제/기기 진단정보, 보고서에 자동 포함될 수 있는 연결 IP 주소 / 로그인 및 선택된 기능 오류 해결과 서비스 안정성 개선
  • 보유기간: Sentry 프로젝트의 보유기간 설정에 따라 보관한 뒤 Sentry의 삭제 기준에 따라 삭제해요. 자세한 처리 리전·기간은 Sentry 데이터 처리계약과 프로젝트 설정에서 확인할 수 있어요.

Google LLC

  • 이전 국가: 미국(Firebase Authentication). 기타 Google 서비스는 미국 및 서비스별 글로벌 처리 국가를 이용하며, 처리 국가의 구체적인 범위는 Firebase 저장 위치·보유기간 안내, Google 데이터센터 국가 목록, Google Cloud 재수탁자·처리 국가 목록에서 확인할 수 있어요.
  • 연락처: Google 개인정보 문의
  • 이전 시기·방법: 회원 가입·로그인, 앱·기기 보안 검증, 지도·장소 검색, 분석·광고·광고 보상 검증, Google Play 결제 및 Google Forms 문의 기능 이용 시 정보통신망을 통한 전송
  • 이전 항목·목적: 계정 식별자·이메일·프로필(인증), 증명 자료·App Check 토큰(앱·기기 무결성 검증), 장소 검색어·좌표(지도·장소 검증), UID·이용 이벤트·기기/광고 식별자(분석·광고·보상 검증), 구독/거래 검증 정보(결제), 문의·첨부파일(고객지원)
  • 보유기간: 회사 관리 데이터는 제3조의 기간. Firebase Authentication의 기타 인증 정보는 삭제 요청까지, 요청 후 운영·백업 시스템에서 180일 이내 삭제되며 IP 로그는 수주 동안 보관돼요. 회사의 Analytics 사용자·이벤트 데이터 설정은 2개월이고, Google이 독립적으로 처리하는 광고·결제·보안 기록은 Google 보유기간 기준에 따라 해당 목적 달성·계정/설정 삭제 또는 법정 보존 기간까지 보관돼요.

OpenAI OpCo, LLC

  • 이전 국가: 미국 및 OpenAI 재수탁자 목록에 공개한 처리 국가. API 처리가 미국 내에서만 이루어지는 것으로 제한하지 않아요.
  • 연락처: privacy@openai.com / 개인정보 문의 포털
  • 이전 시기·방법: AI 여행 생성·대화·일정 편집 요청 시 정보통신망을 통한 전송
  • 이전 항목·목적: 제2조의 AI 입력·최근 대화·여행/장소/메모 정보와 해시된 안전성 식별자 등 요청 관련 정보 / AI 답변·일정 생성·편집 제안 및 안전성 확보
  • 보유기간: 응답 저장 기능은 사용하지 않아요. 모델 처리에 필요한 임시 캐시는 최대 24시간, 악용 방지 로그는 기본 최대 30일이며 법적 의무 또는 서비스·제3자의 피해 방지를 위해 필요한 경우 더 보관될 수 있어요. 상세 기준은 OpenAI API 데이터 보유 안내에서 확인할 수 있어요.

RevenueCat, Inc.

  • 이전 국가: 미국(AWS 데이터센터)
  • 연락처: compliance@revenuecat.com
  • 이전 시기·방법: 구매·복원·구독 상태 확인·관리 시 정보통신망을 통한 전송
  • 이전 항목·목적: Firebase UID 기반 고객 식별자, 앱·플랫폼·구독 상품·entitlement·거래/영수증 검증·관리 링크 정보 / 구독 확인·구매 복원·관리
  • 보유기간: 구독·복원 등 위탁 목적 수행 또는 회사의 삭제 요청까지. 계정 삭제 시 회사가 고객 삭제를 요청하며 실패한 요청은 자동 재시도해요. 백업·법정 보존 등 계약상 예외는 RevenueCat 처리계약에 따라 별도로 적용될 수 있어요.

Apple Inc.

  • 이전 국가: 미국 및 Apple 개인정보 보호정책에 공개한 서비스 처리 국가
  • 연락처: Apple 개인정보 문의
  • 이전 시기·방법: Apple 로그인, App Store 구매·구독 또는 App Attest/DeviceCheck 보안 검증 시 정보통신망을 통한 전송
  • 이전 항목·목적: 로그인 식별자·제공되는 이메일, 구매·구독·거래 검증 정보, 앱·기기 증명 자료 / 로그인·App Store 결제·구독 처리 및 앱·기기 무결성 검증
  • 보유기간: 회사 관리 기록은 제3조의 기간, Apple의 독립적인 구매·보안 기록은 거래·서비스 및 법적 보존 목적에 필요한 기간. Apple이 보유하는 기록의 삭제·권리 요청은 위 연락처에서 접수할 수 있어요.

Meta Platforms, Inc. (Instagram)

  • 이전 국가: 미국 및 Instagram 정책의 국제 이전 안내에 공개한 국가
  • 연락처: Instagram 개인정보 문의·권리 요청 안내
  • 이전 시기·방법: 이용자가 Instagram DM·댓글 문의를 보낼 때 해당 서비스의 정보통신망을 통한 전송
  • 이전 항목·목적: Instagram 프로필과 직접 보낸 문의 내용 / 문의 소통
  • 보유기간: 이용자가 메시지·댓글을 삭제하거나 Meta의 서비스·보안·법정 보존 기준에 따른 기간. 회사는 별도 복사본을 보관하지 않으며, Instagram 기록의 삭제 요청은 위 경로에서 할 수 있어요.

국외 이전을 거부하거나 관련 동의를 철회하려면 해당 외부 기능을 이용하지 않거나, 앱·기기의 광고/추적 설정을 변경하거나, contact@npsomewhere.com로 요청해 주세요. 본인 확인 후 요청한 기능·항목에 대한 이전 중단·삭제 가능 여부와 처리 결과를 안내해요. 인증·AI·구독 등 계약 이행에 필요한 이전을 거부하면 해당 기능 이용이 제한될 수 있으며, 선택적 맞춤형 광고를 거부해도 기본 여행 기능은 이용할 수 있어요.

제7조 - 행태정보의 수집·이용 및 거부

광고 보상 확인을 위해 Firebase UID를 AdMob의 서버 검증용 사용자 식별자로 전송해요. Google이 보낸 서명된 거래 정보를 서버에서 확인한 뒤 크레딧을 지급하며, 회사는 제3조의 보유기간 동안 거래 ID·UID·지급 결과 등을 보관해요.

Google AdMob은 기기·광고 식별자, 광고 노출·클릭·시청 기록, 기기·앱 정보 및 도시 수준 위치 등을 처리해 광고를 제공하고 성과를 측정해요. Google Analytics for Firebase는 UID·화면·기능 이벤트 및 Google Signals 등 설정에 따른 분석 정보를 처리해요. 연결된 Google 광고 서비스와 광고 개인화 설정에 따라 이용 통계가 광고에 활용될 수 있어요.

  • 회사 보유기간: Analytics 사용자·이벤트 수준 데이터 2개월, 광고 보상 검증 기록 90일. Google이 독립적으로 보유하는 정보의 기준은 제6조에서 확인할 수 있어요.
  • Android: 설정 → Google → 광고 → 광고 ID 삭제 또는 맞춤형 광고 설정 변경
  • iOS: 설정 → 개인정보 보호 및 보안 → 추적 → 앱 추적 요청 거부
  • 앱: 더보기 → 광고 개인정보 설정(지역·동의 상태에 따라 메뉴가 표시되는 경우) → Google UMP 개인정보 옵션에서 동의 확인·변경

메뉴가 표시되지 않거나 별도 광고 관련 권리 요청이 필요한 경우 contact@npsomewhere.com로 문의해 주세요. 동의 철회·광고 개인화 거부 후에도 비개인화 광고가 표시되거나 광고 요청이 제한될 수 있으며, 기본 여행 기능은 계속 이용할 수 있어요. 보상형 광고를 시청하지 않으면 해당 광고에 따른 추가 크레딧은 지급되지 않아요.

제8조 - 개인정보 자동 수집 장치의 설치·운영 및 거부

회사가 직접 설치한 웹사이트의 광고 추적 쿠키·행태광고 스크립트는 없어요. 웹사이트는 언어·테마 선택을 브라우저의 로컬 저장소에 보관할 수 있으며, 브라우저의 사이트 데이터 삭제로 제거할 수 있어요. 앱의 SDK 기반 분석·광고와 거부 방법은 제2조·제7조에서 안내해요.

현재 웹사이트에서는 브라우저의 GPC(Global Privacy Control) 신호로 거부할 광고 목적의 개인정보 판매·공유가 이루어지지 않아요. 브라우저 신호가 앱의 광고 설정을 변경하지는 않으므로 앱 광고의 선택·권리 요청은 제7조·제11조의 방법을 이용해 주세요.

제9조 - 개인정보의 파기 절차 및 방법

보유기간이 지나거나 목적이 달성된 개인정보를 선정하고 개인정보 보호책임자의 관리 아래 복구·재생되지 않도록 삭제해요. 법정 보존 정보는 일반 서비스 데이터와 분리해 해당 기간 동안 보관하고 이후 파기해요.

앱 내 계정 삭제 또는 contact@npsomewhere.com 요청으로 계정·프로필·소유 여행·지출·구독 상태 미러·크레딧 잔액·AI 요청/상태·가져오기 작업·사용자 Storage 파일을 삭제하고, 다른 사람이 소유한 여행의 참여 정보를 정리해요. 본인 확인을 위한 최근 재로그인이 필요할 수 있어요. 탈퇴 제한·가입 보너스 중복 수령 방지·광고 보상 검증 기록은 제3조의 90일 기준을 적용해요.

앱 삭제만으로 클라우드 계정이나 앱 마켓 구독이 해지되지는 않아요. 계정 삭제 시 회사는 RevenueCat 고객 삭제를 요청하고 실패한 요청은 자동 재시도해요. Google·Apple 구매 기록과 외부 사업자 백업 등은 즉시 함께 삭제되지 않을 수 있으며 각 사업자의 정책·법정 보존 기준이 적용돼요.

제10조 - 개인정보의 안전성 확보 조치

  • 관리적 조치: 내부관리계획 수립·시행, 접근 권한의 차등 부여 및 관리
  • 기술적 조치: 개인정보 처리 시스템 접근통제, 전송 구간 암호화(HTTPS) 등
  • 물리적 조치: 데이터가 저장된 시스템에 대한 접근 통제

제11조 - 정보주체와 법정대리인의 권리·의무 및 행사 방법

언제든지 개인정보 열람·정정·삭제·처리정지·동의 철회를 요청할 수 있어요. 앱의 계정 정보 수정·삭제 기능 또는 contact@npsomewhere.com로 요청해 주세요. 본인 확인 후 법정 기간 내에 처리하고, 거절·제한 또는 추가 시간이 필요한 경우 사유와 이의 제기 방법을 안내해요.

법정대리인이나 위임받은 대리인도 권리를 행사할 수 있어요. 대리인 요청에는 위임장 등 대리 권한과 본인 확인에 필요한 최소한의 자료를 요청할 수 있어요. Instagram DM·댓글은 일반 문의 창구이며 개인정보 권리 요청은 전자우편으로 접수해 주세요.

동의를 철회해도 철회 전 처리는 소급하여 무효가 되지 않으며, 계약 이행 또는 법정 보존 등 다른 적법한 근거로 처리하는 정보에는 해당 근거가 적용돼요. 열람·처리정지는 개인정보 보호법 제35조 제4항·제37조 제2항에 따라 제한될 수 있어요.

해외 이용자의 권리

캘리포니아 소비자 개인정보 보호법(CCPA) 및 캘리포니아 개인정보 권리법(CPRA)이 적용되는 경우에도 아래 방법으로 권리를 행사할 수 있어요. 개인정보 판매·공유 거부 요청은 전자우편으로 접수하고, 적용되는 경우 본인 확인이 필요한 열람·삭제 요청과 구분해 처리해요.

미국 등 해외 이용자에게도 해당 지역에서 적용되는 개인정보 법령에 따른 권리를 보장해요. 적용되는 경우 수집 정보·출처·목적·수신자 확인, 삭제·정정·이동 가능한 사본 제공, 개인정보 판매 또는 광고 목적 공유의 거부, 허용된 목적을 벗어나는 민감정보 이용 제한, 대리인 요청 및 차별받지 않을 권리를 위 전자우편으로 행사할 수 있어요.

CCPA/CPRA가 적용되는 요청은 접수 후 10영업일 이내 확인하고, 열람·삭제·정정 요청에 45일 이내 답변해요. 필요한 경우 사유를 안내하고 추가 45일까지 연장할 수 있으며, 판매·공유 거부 또는 민감정보 이용 제한 요청은 가능한 한 빨리, 최대 15영업일 이내 처리해요. 동의가 필요한 미성년자 정보의 판매·공유는 필요한 동의 없이 하지 않아요.

제12조 - 만 14세 미만 아동의 개인정보

서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 회사는 만 14세 미만 아동의 개인정보를 고의로 수집하지 않습니다. 만 14세 미만 아동의 개인정보가 수집된 사실을 알게 된 경우 지체 없이 파기합니다.

제13조 - 개인정보 보호책임자

회사는 개인정보 처리에 관한 업무를 총괄하여 책임지고, 정보주체의 문의·불만 및 피해 구제를 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.

  • 개인정보 보호책임자: 이세종 (대표자 및 개발자)
  • 연락처: contact@npsomewhere.com

제14조 - 권익침해 구제 방법

정보주체는 개인정보 침해로 인한 구제를 받기 위하여 아래 기관에 분쟁 해결이나 상담을 신청할 수 있습니다.

  • 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
  • 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
  • 대검찰청: (국번없이) 1301 (www.spo.go.kr)
  • 경찰청: (국번없이) 182 (ecrm.cyber.go.kr)

제15조 - 개인정보 처리방침의 변경

이 개인정보처리방침은 2026년 9월 28일부터 적용돼요. 변경 시 시행일·주요 변경사항을 본 페이지 또는 서비스 내에서 안내하고, 권리에 중대한 영향을 미치는 변경은 개정 전 또는 개정 즉시 알리며 별도 동의가 필요한 경우 동의를 받아요. 이전 방침은 위 「지난 개인정보처리방침」에서 확인할 수 있어요.

NP Somewhere ("we", "us", or the "Operator") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) of Korea to protect users' personal information and to handle related concerns promptly. This policy applies to the travel-planning app "Somewhere" (the "Service") and its official website.

1. Purpose of Processing

We process personal information for the purposes below. If a purpose changes, we take the measures required by Article 18 of Korea’s Personal Information Protection Act (PIPA), including separate consent where required.

  • Registration, account management, identity and friend verification, and prevention of misuse
  • Creating, saving, sharing, and collaborating on trips, places, notes, images, expenses, and settlements
  • AI trip generation, AI conversations and itinerary editing, and place search and verification through Google Places API
  • Importing Triple shared itineraries, expenses, and user attachments at your request
  • Somewhere Pro purchases, restoration, and subscription management; AI credit awards, deductions, and ad-reward verification
  • Usage analytics, Service improvement, customer support, bug reports, and reliability and security response
  • Serving and measuring ads according to your region, advertising consent, and device settings

2. Information We Collect and How

  • Account/profile: email, Firebase UID or guest ID, name/nickname, profile image, sign-in provider, and provider identifier
  • Service content: trip titles, dates, cities/countries, place names/addresses/IDs/coordinates, notes, companions/preferences, trip/place images, invitations/sharing, expense amounts/currencies/payment methods/payers/settlement participants, and receipts/attachments
  • AI generation/conversations/itinerary editing: messages, recent conversation, destination/dates/party size/preferences/budget/language, titles/dates/places/coordinates/notes in the current trip draft, AI replies/edit proposals, and request/processing records
  • Triple imports: trip code extracted from your shared link, language, source itinerary/places/notes/expenses/user attachments, source-content hash, and import status/results/errors. We do not persist the full source share URL.
  • Subscriptions/credits/ad rewards: RevenueCat app user ID, product/store/purchase/restoration/expiration/renewal status, management URL, transaction/receipt verification data, credit balance/week/awards/deductions/ad rewards, reward transaction ID/network/ad unit/processing time. Raw payment details such as card numbers are handled by the app marketplace or payment provider.
  • Misuse prevention: UID, hash of normalized email, sign-up bonus awards/claims, and account-deletion time/reason/expiry
  • App/device security verification: Firebase App Check tokens and attestation material from Google Play Integrity or Apple App Attest/DeviceCheck. These help verify app/device integrity and prevent unauthorized access and misuse.
  • Optional support: email, inquiry content, images/files submitted through Google Forms, or Instagram profile/DM/comment content
  • Optional location: current position displayed on the map when device location permission is granted
  • Automatically collected: device type/OS/app version/granular device details, city-level location, IP address, access/usage logs, diagnostics, advertising identifiers (ADID/IDFA), screen/feature statistics, and Google Signals analytics information
  • Selected Sentry error diagnostics (only when a project DSN is configured and a sign-in error or selected operation failure is reported): authentication provider for sign-in errors; feature, operation name, error stage, and diagnostic code for selected operation failures; exception type and sanitized stack trace; app version/platform and operating-system/device diagnostics. Exception messages are replaced with generic text. Reports exclude account IDs, email addresses, trip/expense content, AI prompts, URLs/tokens, request/response bodies or headers, and breadcrumbs. Sentry may automatically associate the connection IP address with a report; whether it stores IP addresses depends on the project's privacy settings. We use reports to diagnose sign-in and selected operation failures and improve service reliability.

Information is provided directly by you or generated during use. A Triple import reads the external shared page you submit and stores copies of eligible images in our storage.

AI conversations and itinerary editing send your message, recent conversation, and titles, coordinates, and notes from the current trip/date/place draft to OpenAI. The edit payload excludes companion lists, expenses, and photo files. Place names, language, and coordinates needed for verification may be sent to Google Places API.

AI replies are reference material to help you plan. The AI does not make automated decisions that significantly affect your rights or obligations, and you choose whether to apply suggested itinerary changes.

Please avoid entering sensitive information, government identifiers, other people’s personal information, or passwords in AI messages or notes. You can report inappropriate AI replies, possible personal-information exposure, or objections to contact@npsomewhere.com.

Under OpenAI’s policy, API inputs and outputs are not used for model training by default unless we explicitly opt into training-data sharing. The Service does not use response storage. Before introducing a new training purpose, we will disclose its purpose and scope and establish the required legal basis, including consent where necessary. OpenAI may separately retain security and abuse-prevention logs under its data-processing policy.

Current location is used to display your position and is not stored in our Firebase database. The map provider may process location/device data, and place names, addresses, and coordinates you save to a trip may be retained as trip content.

We send signed-in members’ Firebase UID to Google Analytics for Firebase as a user identifier and analyze screen views, login, subscription, ad-reward events, and user type. We do not send email as an Analytics user identifier. Processing may also occur under Google Signals, city-level location/granular-device collection, and ads-personalization settings; actual ad delivery depends on region, advertising consent, and device settings.

Account, trip, sharing data, and uploaded images are stored in Firebase/Google Cloud. App preferences, account/subscription caches, images, and import progress may be stored locally through DataStore or device storage and removed by deleting the app or clearing app data. Google Forms reports/attachments are handled in Forms/Drive. Instagram inquiries stay within Instagram and are not copied to a separate company system.

Legal bases by information category

  • Without separate consent — account/profile, trip and sharing content, requested AI inputs and itinerary edits, imports, subscriptions, and credits: processing necessary to enter into or perform the Service contract (PIPA Article 15(1)(4))
  • Without separate consent — error/security logs including Sentry sign-in and selected-operation diagnostics, app/device integrity verification, account-deletion and sign-up bonus claims, and ad-reward verification records: legitimate interests in security and preventing misuse using minimal information (Article 15(1)(6)). We rely on this basis only where our interests clearly outweigh the impact on your rights.
  • Without separate consent — operational usage statistics: legitimate interests in operating and improving the Service without infringing your rights (Article 15(1)(6)). Processing for ads personalization is handled separately under applicable advertising consent, settings, and law.
  • With consent — personalized advertising/tracking and optional location processing where consent is required: your consent (Article 15(1)(1)). You can use location permissions, device tracking settings, and available ad privacy options.
  • Records retained under law — transaction and dispute records: compliance with legal obligations (Article 15(1)(2)). Statutory periods apply only to records we actually hold.

Categories of personal information under US laws

The information above may fall into the categories below. Sources include you, your device, sign-in/payment providers, and external shared pages you submit. We use it for the purposes in Section 1. See Section 3 for category-specific retention and Sections 4–7 for recipients and disclosure purposes.

  • Identifiers: name, email, UID, device/ad identifiers, and IP address
  • Commercial information: purchases, subscriptions, transactions, credits, and trip expenses
  • Internet/network activity: screen/feature use, ad views/clicks, access, and error records
  • Geolocation: city-level location, trip-place addresses/coordinates, and current location with permission
  • Visual information and content you provide: profile/trip/receipt images, notes, inquiries, and AI messages
  • Preferences and inferences: travel preferences you provide and AI trip suggestions based on that input

Precise current device location may be Sensitive Personal Information under US law. With location permission, it is used for the map feature you request and is not stored in our Firebase database. You can revoke permission; Section 11 explains applicable rights to limit use/disclosure beyond permitted purposes.

3. Retention and Deletion

We retain information for the periods below or those required by law. We delete it when its period expires or purpose is fulfilled, and limit post-deletion misuse-prevention and reward-verification records to the minimum information needed for those purposes.

  • Account/profile/trip/sharing/expense data, mirrored subscription status, and credit balance: until account deletion or fulfillment of the purpose
  • AI trip-generation request records (hashed user identifier, request fingerprint, processing information): 30 days after completion or failure
  • AI trip-generation state: until account deletion
  • AI conversation/edit request records and results (hashed identifiers, input fingerprint, replies/edit proposals, processing state): 24 hours from the respective processing/completion/failure time. An ongoing on-device conversation may remain until the conversation is reset or app data is cleared.
  • Triple import job records: 30 days from creation/final processing. Imported itineraries, expenses, and images follow the ordinary trip-data period.
  • Sign-up bonus duplicate-claim records (UID, email hash, award/claim time): 90 days from creation; records renewed at account deletion are retained for 90 days after deletion
  • Account-deletion restriction records (UID, deletion time): 90 days after account deletion
  • Ad-reward verification records (UID, transaction ID, network/unit, award result, processing time): 90 days from reward processing, including after account deletion within that period to prevent duplicate or fraudulent rewards
  • Trip invitation token/state: expires after 24 hours, followed by periodic cleanup
  • Administrator audit logs (identifier/email, reason, before/after settings): 365 days from creation
  • Google Analytics for Firebase user/event-level data: 2 months, without renewal of the period by new activity
  • Detached-image deletion queue: periodic file deletion after a 24-hour grace period
  • Google Forms inquiries/bug reports: until resolution, followed by deletion
  • Instagram inquiries: until user deletion or for the period set by Meta/Instagram; no separate company copy
  • Device caches/preferences/local-notification data: until the app or app data is deleted
  • App/device security verification: App Check does not retain attestation material; Firebase services do not retain tokens unused for replay protection. Attestation material handled by Google or Apple follows that provider’s security-service retention criteria.
  • Sentry error reports: retained for the period configured for the Sentry project, then deleted under Sentry’s retention and deletion terms.

For records we actually hold that fall under Korea’s Electronic Commerce Act, advertising records are kept for 6 months; contract/withdrawal and payment/supply records for 5 years; and consumer complaint/dispute records for 3 years. Purchase records independently held by marketplaces and other providers follow their own legal obligations and retention policies.

Records subject to automatic deletion become eligible at expiry and are removed through scheduled system processing. Records required by law are kept separately and used only for that purpose.

4. Third-Party Provision

We do not buy or sell personal information as a data-trading business. We disclose information to third parties with consent or where legally permitted, and describe processing by service providers, external features, and advertising SDKs in Sections 5–7.

  • Trip sharing: the invitees you select receive trip titles/dates/itineraries/places/notes/images/expenses/settlements according to itinerary and expense permissions. You can remove the trip share.
  • Friend/profile verification: signed-in users who know an exact UID, including through a QR code, can retrieve the member’s name, email, and profile image. Member-directory queries and searches are prohibited; removing a trip share does not itself prevent exact-UID profile retrieval.
  • External services: Google/Apple sign-in and payments, maps, ads, and Instagram support may involve independent processing by those providers for their own services and legal obligations. This is distinct from processing on our behalf and is also governed by their policies.

Personalized-ad processing may constitute advertising-related “sharing” under applicable law even without selling data for money. See Section 7 for advertising data, settings, and opt-out choices.

5. Outsourcing of Processing

We use the following providers for processing needed to deliver the Service. Independent processing of sign-in, payment, advertising, and support information is distinguished from processing on our behalf.

  • Google LLC: authentication, storage, and cloud operations through Firebase Authentication/Firestore/Storage/Cloud Functions; Firebase App Check app/device security verification; Google Places API search/verification; Google Forms/Drive support and attachments; and analytics within the applicable processing agreement
  • OpenAI OpCo, LLC: AI trip generation, conversations, and itinerary editing through the Responses API
  • RevenueCat, Inc.: subscription/purchase restoration/entitlement checks, customer identifiers, and subscription-management links
  • Functional Software, Inc. (Sentry): sign-in and selected-operation error reporting and diagnostics. See Sentry’s Data Processing Addendum and subprocessor list

Our processing agreements address tasks, safeguards, subprocessors, deletion, and assistance with rights requests, and we oversee our providers. Apple sign-in/App Store payments/App Attest/DeviceCheck verification, Google Play payments/AdMob advertising, and Meta/Instagram inquiries also involve independent provider processing under their own policies; these activities are not all classified as our outsourced processing.

Provider information and contacts: Firebase privacy information, Google Privacy Policy, OpenAI DPA, RevenueCat DPA, Apple Privacy Policy, Instagram Privacy Policy

6. Overseas Transfer

Firestore trip/profile data and cloud functions for which we select the Seoul region use asia-northeast3. Firebase Authentication is processed in the United States; selecting Seoul does not locate all authentication, analytics, advertising, and external services in Korea.

Overseas processing/storage needed for authentication, cloud operations, AI, place search, and subscription management relies on the contract-performance disclosure basis in PIPA Article 28-8(1)(3). Personalized advertising/tracking not necessary for the contract and disclosures to independent providers require their own applicable legal basis, including separate consent where required.

Functional Software, Inc. (Sentry)

  • Countries: the United States or Germany and other Sentry service locations; the project’s configured Sentry region determines its storage location.
  • When/how: diagnostic information is sent over the network when a sign-in error or selected operation failure is reported by an app with a configured DSN.
  • Items/purpose: authentication provider/stage/code for sign-in errors; feature/operation name/error stage/diagnostic code for selected operation errors; exception type and sanitized stack trace; app version/platform, operating-system/device diagnostics, and connection IP address that may be automatically associated with a report / diagnose sign-in and selected-operation failures and improve service reliability.
  • Retention: the period configured for the Sentry project, followed by deletion under Sentry’s terms. See the Sentry Data Processing Addendum and project settings for the exact region and period.

Google LLC

  • Countries: United States for Firebase Authentication. Other Google features use the US and service-specific global processing locations; see Firebase locations and retention, Google data-center countries, and Google Cloud subprocessors and processing countries for country details.
  • Contact: Google privacy requests
  • When/how: network transmission during registration/sign-in, app/device security verification, maps/place search, analytics/ads/reward verification, Google Play purchases, and Google Forms support
  • Items/purposes: identifiers/email/profile for authentication; attestation material/App Check tokens for app/device integrity; queries/coordinates for maps and place verification; UID/events/device/ad identifiers for analytics, ads, and reward verification; subscription/transaction data for payments; inquiries/attachments for support
  • Retention: company-managed data follows Section 3. Other Firebase Authentication information is held until deletion is requested and removed from live/backup systems within 180 days afterward; IP logs are kept for a few weeks. Our Analytics user/event setting is 2 months. Google’s independent advertising, payment, and security records follow Google retention criteria until the purpose is fulfilled, account/settings deletion, or the relevant legal period.

OpenAI OpCo, LLC

  • Countries: United States and processing countries disclosed in OpenAI’s subprocessor list. API processing is not restricted to the United States.
  • Contact: privacy@openai.com / privacy request portal
  • When/how: network transmission when you request AI trip generation, conversations, or itinerary editing
  • Items/purposes: AI inputs/recent conversation/trip/place/note data from Section 2, hashed safety identifiers, and request-related information / AI replies, itinerary generation/edit proposals, and safety
  • Retention: response storage is not used. Temporary model-processing caches may last up to 24 hours; default abuse-monitoring logs are kept for up to 30 days, or longer where required by law or necessary to protect the service or third parties from harm. See OpenAI API data retention for details.

RevenueCat, Inc.

  • Country: United States (AWS data centers)
  • Contact: compliance@revenuecat.com
  • When/how: network transmission for purchases, restoration, and subscription status/management
  • Items/purposes: Firebase UID-based customer ID, app/platform/product/entitlement/transaction/receipt/management-link data / subscription checks, restoration, and management
  • Retention: until the subscription/restoration processing purpose is fulfilled or we request deletion. On account deletion, we request customer deletion and automatically retry failed requests. Backup and legal-retention exceptions may apply under the RevenueCat DPA.

Apple Inc.

  • Countries: United States and processing countries disclosed in Apple’s Privacy Policy
  • Contact: Apple privacy requests
  • When/how: network transmission during Apple sign-in, App Store purchases/subscriptions, or App Attest/DeviceCheck security verification
  • Items/purposes: sign-in identifier/email where provided, purchase/subscription/transaction data, and app/device attestation material / authentication, App Store payments/subscriptions, and app/device integrity verification
  • Retention: company-managed records follow Section 3; Apple independently retains transaction/security records for service and legally required purposes. Requests concerning Apple-held records can be submitted through the contact above.

Meta Platforms, Inc. (Instagram)

  • Countries: United States and countries disclosed in the international-transfer information in Instagram’s policy
  • Contact: Instagram privacy contacts and rights requests
  • When/how: transmission through Instagram when you send a DM or comment inquiry
  • Items/purposes: Instagram profile and content you send / support communication
  • Retention: until you delete messages/comments or for Meta’s service, security, or legal-retention periods. We keep no separate copy; requests for Instagram-held records can be made through the contact above.

To refuse an overseas transfer or withdraw related consent, do not use the external feature, change app/device advertising or tracking choices, or contact contact@npsomewhere.com. After identity verification, we explain whether transfers/deletion can be stopped for the relevant feature/data and report the result. Refusing transfers needed for authentication, AI, or subscriptions may limit those features; refusing optional personalized advertising does not prevent basic trip use.

7. Behavioral Information for Ads and Opt-Out

We send your Firebase UID to AdMob as the user identifier for server-side reward verification. After verifying Google’s signed transaction, the server awards credits; we retain transaction IDs, UID, and award results for the period in Section 3.

Google AdMob processes device/ad identifiers, ad impressions/clicks/viewing, app/device information, and city-level location to serve and measure ads. Google Analytics for Firebase processes UID, screen/feature events, and analytics data under Google Signals and related settings. Connected Google ad services and ads-personalization settings may allow usage statistics to be used for advertising.

  • Company retention: Analytics user/event-level data for 2 months; ad-reward verification records for 90 days. See Section 6 for Google’s independent retention criteria.
  • Android: Settings → Google → Ads → delete the advertising ID or change personalized-ad settings
  • iOS: Settings → Privacy & Security → Tracking → reject app tracking requests
  • App: More → Ad privacy settings, where displayed for your region/consent status → Google UMP privacy options to review or change consent

If that menu is unavailable or you need to make another advertising rights request, contact contact@npsomewhere.com. After withdrawing consent or opting out of personalized ads, non-personalized ads may remain or ad requests may be limited, while basic trip features remain available. If you do not watch a rewarded ad, you do not receive its additional credits.

8. Cookies

We do not install advertising-tracking cookies or behavioral-ad scripts on our website. Language/theme preferences may be stored in browser local storage and removed by clearing site data. App SDK-based analytics/advertising and opt-out choices are described in Sections 2 and 7.

This website currently carries out no advertising-related sale or sharing to opt out of through a browser’s Global Privacy Control (GPC) signal. Browser signals do not change native-app ad settings; use the choices and rights-request methods in Sections 7 and 11 for app advertising.

9. Destruction Procedure and Method

Information that has expired or fulfilled its purpose is selected and deleted under the data protection officer’s oversight using methods that prevent recovery. Legally required records are kept separately from ordinary Service data and deleted after the legal period.

Account deletion in the app or a request to contact@npsomewhere.com deletes the account/profile/owned trips/expenses/mirrored subscriptions/credit balance/AI requests and state/import jobs/user Storage files and cleans up participation in other users’ trips. Recent sign-in may be needed for identity verification. Account-deletion restrictions, duplicate sign-up bonus claims, and ad-reward verification records follow the 90-day criteria in Section 3.

Deleting the app alone does not delete the cloud account or cancel marketplace subscriptions. On account deletion, we request deletion of the RevenueCat customer and automatically retry failed requests. Google/Apple purchase records and provider backups may remain under each provider’s policy and legal-retention requirements.

10. Security Measures

  • Administrative: establishing and operating an internal management plan; least-privilege access management
  • Technical: access control for processing systems and encryption of data in transit (HTTPS)
  • Physical: access control to systems where data is stored

11. Your Rights and How to Exercise Them

You may request access, correction, deletion, suspension, or withdrawal of consent at any time through account-edit/deletion features or contact@npsomewhere.com. We verify identity, act within the applicable legal period, and explain any refusal, restriction, extension, or appeal procedure.

A legal representative or authorized agent may make requests. We may ask for a power of attorney and the minimum information needed to verify identity and authority. Instagram DMs/comments are for general support; please submit privacy rights requests by email.

Withdrawal does not invalidate earlier processing; a separate lawful basis, such as contract performance or legal retention, may continue to apply. Access/suspension may be limited under PIPA Articles 35(4) and 37(2).

Rights for users outside Korea

Where the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies, you can exercise your rights through the methods below. Do Not Sell or Share My Personal Information requests are accepted by email and, where applicable, handled separately from access and deletion requests that require identity verification.

Users in the US and other countries receive rights under local privacy laws where those laws apply. Where applicable, you can use the email above to request information about collected data/sources/purposes/recipients, deletion/correction/a portable copy, opt out of sale or advertising-related sharing, limit sensitive-information use beyond permitted purposes, use an authorized agent, and exercise rights without discrimination.

For requests covered by CCPA/CPRA, we acknowledge receipt within 10 business days and respond to access/deletion/correction within 45 days. We may extend by another 45 days with notice of the reason. Opt-outs of sale/sharing and requests to limit sensitive-information use are handled as soon as feasible, within 15 business days. We do not sell/share minors’ information without the consent required by applicable law.

12. Children Under 14

The Service is not directed to children under the age of 14, and we do not knowingly collect their personal information. If we learn that we have collected such information, we will delete it without delay.

13. Data Protection Officer

  • Officer: Sejong Lee (Representative and Developer)
  • Contact: contact@npsomewhere.com

14. Remedies for Rights Infringement

You may contact the following for dispute resolution or counseling:

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • KISA Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • National Police Agency: 182 (ecrm.cyber.go.kr)

15. Changes to This Policy

This Privacy Policy is effective September 28, 2026. We announce the effective date and material changes on this page or in the Service, notify changes that significantly affect your rights before or at amendment, and obtain separate consent where required. Earlier policies remain available in the Previous policy selector.

Somewhere

문의: contact@npsomewhere.com

개인정보처리방침 서비스 이용약관 © 2026 Somewhere
사업자 정보
상호: 엔피(NP)
대표자: 이세종
사업자등록번호: 545-01-04035
통신판매업 신고번호: 제 2026-서울양천-0818 호
사업장 소재지: 서울특별시 양천구 중앙로45길 25-22, 402호(신정동, 신정빌라)
이메일: np@npsomewhere.com

Apple and the Apple logo are trademarks of Apple Inc., registered in the U.S. and other countries. App Store is a service mark of Apple Inc., registered in the U.S. and other countries. Google Play and the Google Play logo are trademarks of Google LLC.