먹고마실(이하 "회사")은 이용자의 개인정보를 중요하게 생각하며, 「개인정보 보호법」 등 관련 법령을 준수합니다. 본 방침은 회사가 어떤 개인정보를 수집하고, 어떻게 이용·보관·파기하는지 안내합니다.
1. 수집하는 개인정보 항목
1-1. 회원가입 시 수집
| 항목 | 수집 방법 |
| 이메일 (Apple 계정 식별값) | Sign in with Apple |
| 닉네임 | 이용자 직접 입력 |
| 국가 | 온보딩 시 이용자 선택 |
| 사용 언어 | 기기 설정 또는 이용자 선택 |
1-2. 서비스 이용 중 수집
- 게시물 사진, 음식 이름, 캡션, 태그(해먹은/사 먹은 구분), 식사 날짜·시간대(아침/점심/저녁/야식 등, 선택 입력)
- "사 먹은" 태그 선택 시 입력하는 가게 이름
- 댓글, 원탭 질문 응답, 댓글 수정 이력
- 한 줄 소개, 프로필 사진(선택)
- 좋아요, 위시리스트(찜) 저장 기록, 신고, 차단 기록
- 밥스타일(자기 선언형 식사 정체성 라벨, 선택), 관심 카테고리(해외 이용자 온보딩 시 선택)
- 알림 수신을 위한 기기 푸시 토큰(APNs)
1-3. 자동으로 수집되는 정보
- 접속 로그, 기기 정보(OS 버전, 기기 모델)
- 서비스 이용 기록(이벤트 로그 — 게시물 열람, 원탭 질문 클릭 등 통계 목적)
- 게시물을 열람한 이용자의 국가 정보(도달 국가 표시 기능을 위함, 개인 식별 없이 국가 단위로만 집계)
- 앱 사용 패턴 및 통계 정보(화면 조회, 이벤트 발생 빈도 등) — Firebase Analytics(Google)를 통해 수집. 서비스 개선 목적으로만 사용되며, 광고 목적으로 이용되거나 타사 데이터와 결합되지 않습니다.
2. 개인정보 수집·이용 목적
- 회원 식별 및 서비스 제공 (게시물 작성, 댓글, 알림 등)
- 부적절한 콘텐츠 및 이용자 필터링·제재 (신고 처리, 계정 정지)
- 서비스 개선을 위한 통계 분석 (개인을 식별하지 않는 형태로 집계)
- 고객 문의 응대
3. 개인정보의 제3자 제공 및 처리위탁
회사는 원칙적으로 이용자의 개인정보를 외부에 제공하지 않습니다. 다만 서비스 운영을 위해 아래와 같이 외부 업체에 처리를 위탁하고 있습니다.
| 수탁업체 | 위탁 업무 | 위탁 정보 |
| 인공지능 이미지 분석 서비스 제공업체 | 게시물 사진의 음식 인식·설명·번역 생성, 업로드되는 모든 사진(게시물·프로필)의 부적절한 콘텐츠 자동 판별 | 업로드된 사진(게시물·프로필 사진 포함) |
| Oracle Cloud Infrastructure (오사카 리전) | 서버 인프라 운영 | 이용자 계정 정보, 게시물 데이터 전반 |
| Cloudflare, Inc. | 이미지·동영상 저장, 콘텐츠 전송, 도메인 관리 | 업로드된 사진·동영상 |
| Apple Inc. | 로그인 인증 | 이메일(또는 Apple이 제공하는 중계 이메일) |
| Google LLC (Firebase Analytics) | 서비스 이용 통계 분석 | 앱 사용 패턴, 기기 정보(광고 목적 이용 및 타사 결합 없음) |
위 수탁업체는 해외에 서버를 두고 있어, 개인정보가 국외로 이전될 수 있습니다. 회사는 위탁 계약을 통해 개인정보가 안전하게 처리되도록 관리·감독합니다.
4. 개인정보의 보유 및 이용 기간
- 회원 탈퇴 시까지 보유하며, 탈퇴 신청 즉시 서비스 화면에서 삭제 처리됩니다.
- 부정 이용 방지 및 분쟁 대응을 위해, 탈퇴 후 30일간 데이터를 보관한 뒤 복구 불가능한 방식으로 완전히 파기합니다.
- 관계 법령에 따라 별도 보관이 필요한 정보(예: 전자상거래법상 소비자 불만 처리 기록 등)는 해당 법령이 정한 기간 동안 보관합니다.
5. 개인정보의 파기 절차 및 방법
- 전자적 파일 형태의 정보는 복구 및 재생이 불가능한 기술적 방법을 사용하여 삭제합니다.
- 종이에 출력된 개인정보는 파쇄기로 분쇄하거나 소각합니다.
6. 이용자의 권리와 행사 방법
이용자는 언제든지 아래 권리를 행사할 수 있습니다.
- 자신의 개인정보 열람·정정 요청
- 회원 탈퇴 및 개인정보 삭제 요청 (앱 내 설정 화면에서 직접 처리 가능)
- 개인정보 처리 정지 요청
문의는 아래 연락처로 접수해 주시면 지체 없이 조치합니다.
7. 개인정보의 안전성 확보 조치
- 비밀번호를 별도로 저장하지 않는 Sign in with Apple 방식을 채택하여 인증 관련 위험을 최소화합니다.
- 전송 구간 암호화(HTTPS)를 전 구간에 적용합니다.
- 업로드된 사진은 부적절한 콘텐츠 및 인물 중심 사진을 자동으로 판별하여 게시를 제한합니다.
8. 개인정보 보호책임자
이용자는 서비스 이용 중 발생한 모든 개인정보 관련 문의를 위 연락처로 하실 수 있으며, 회사는 지체 없이 답변 및 처리해 드립니다.
9. 고지의 의무
본 방침이 개정되는 경우, 변경 사항은 본 문서 하단 "변경 이력"에 개정일과 함께 기록됩니다. 이용자의 권리에 중대한 영향을 미치는 변경이 있는 경우, 회사는 시행일 이전에 서비스 내 안내 또는 그 밖의 합리적인 방법으로 이용자에게 고지합니다.
10. 변경 이력
| 시행일 | 변경 내용 |
| 2026-08-19 | 최초 시행 |
| 2026-08-24 | 개인정보 보호책임자 성명 기재, 푸시토큰 수집 고지 문구 정정(APNs 원격 푸시 실제 구현 반영) |
| 2026-09-01 | 서비스 개선을 위한 분석 도구(Firebase Analytics, Google LLC) 도입에 따라 자동 수집 정보(§1-3) 및 제3자 처리위탁(§3) 항목 추가, 광고 목적 미이용·타사 결합 없음을 명시. 전체 수집 항목(§1-2)을 실제 서비스 현황과 대조해 갱신 — 태그 명칭 정정(집밥/외식/음료 → 해먹은/사 먹은), 식사 날짜·시간대, 밥스타일, 관심 카테고리, 위시리스트, 댓글 수정 이력 항목 신규 반영. AI 이미지 분석 위탁 범위(§3)에 프로필 사진 포함 명시. §9 고지 방식을 "앱 내 공지사항"에서 "본 문서 변경 이력"으로 정정(실제 운영 방식 반영) |
Mukgomasil (the "Company") values users' personal information and complies with applicable laws, including the Personal Information Protection Act of Korea. This policy explains what personal information the Company collects and how it is used, stored, and destroyed.
1. Personal Information We Collect
1-1. Information Collected at Registration
| Item | Collection Method |
| Email address (Apple account identifier) | Sign in with Apple |
| Nickname | Entered directly by the user |
| Country | Selected by the user during onboarding |
| Language | Based on device settings or selected by the user |
1-2. Information Collected While Using the Service
- Post photos, food names, captions, tags (indicating whether the food was home-cooked or purchased), and meal date/time-of-day (breakfast, lunch, dinner, late-night snack, etc. — optional)
- Store name entered when the "purchased" tag is selected
- Comments, responses to one-tap questions, and comment edit history
- Bio and profile photo (optional)
- Likes, wishlist (saved posts), reports, and block records
- "Meal style" (a self-declared identity label, optional) and interest categories (selected by international users during onboarding)
- Device push token for receiving notifications (APNs)
1-3. Information Collected Automatically
- Access logs and device information (OS version and device model)
- Service usage records (event logs, used for statistical purposes such as post views and one-tap question clicks)
- Country information of users who view a post (used for the "reach" display feature, aggregated only at the country level without personal identification)
- App usage patterns and statistics (screen views, event frequency, etc.) collected via Firebase Analytics (Google). Used solely to improve the Service; not used for advertising purposes and not combined with third-party data.
2. Purposes of Collecting and Using Personal Information
- Identifying users and providing the Service (posting, comments, notifications, etc.)
- Filtering and enforcing restrictions against inappropriate content and users (handling reports, account suspension)
- Statistical analysis to improve the Service (aggregated in a form that does not identify individuals)
- Responding to customer inquiries
3. Third-Party Disclosure and Processing
As a rule, the Company does not provide users' personal information to external parties. The Company uses the following external service providers to operate the Service:
| Service Provider | Delegated Task | Information Shared |
| AI image analysis service provider | Food recognition and generation of descriptions/translations for post photos; automated detection of inappropriate content for all uploaded photos (posts and profile photos) | Uploaded photos (including profile photos) |
| Oracle Cloud Infrastructure (Osaka region) | Server infrastructure operations | User account information, post data |
| Cloudflare, Inc. | Image/video storage, content delivery, domain management | Uploaded photos/videos |
| Apple Inc. | Login authentication | Email (or Apple's relay email) |
| Google LLC (Firebase Analytics) | Service usage statistics analysis | App usage patterns, device information (not used for advertising, not combined with third parties) |
The above service providers operate servers located outside Korea, so personal information may be transferred internationally. The Company manages and supervises these providers through service agreements to ensure personal information is processed securely.
4. Retention and Use Period
- Personal information is retained until account deletion and is removed from the service screens immediately upon a deletion request.
- To prevent fraudulent use and to address disputes, data is retained for 30 days after deletion and then permanently destroyed in a manner that prevents recovery.
- Information that must be retained separately under applicable law (e.g., consumer complaint records under e-commerce law) is retained for the period required by that law.
5. Destruction Procedures and Methods
- Information stored electronically is deleted using technical methods that prevent its recovery or reproduction.
- Personal information printed on paper is shredded or incinerated.
6. User Rights and How to Exercise Them
Users may exercise the following rights at any time:
- Request to access or correct their personal information
- Request account deletion and deletion of personal information (available directly through the app's Settings screen)
- Request suspension of processing of their personal information
Please contact us using the information below, and we will respond and take action without delay.
7. Measures to Safeguard Personal Information
- Adopting Sign in with Apple, which does not store passwords separately, to minimize authentication-related risk
- Applying transport encryption (HTTPS) across all connections
- Automatically screening uploaded photos for inappropriate content and for posts primarily featuring a person, and restricting posting accordingly
8. Privacy Officer
Users may direct any personal-information-related inquiries arising from their use of the Service to the contact above, and the Company will respond and take action without delay.
9. Notification Obligations
If this policy is amended, the changes will be recorded, together with the effective date, in the "Change History" section below. For amendments that materially affect users' rights, the Company will notify users before the effective date through in-service notice or other reasonable means.
10. Change History
| Effective Date | Changes |
| 2026-08-19 | Initial version took effect |
| 2026-08-24 | Added privacy officer name; corrected push token collection notice to reflect the actual APNs remote push implementation |
| 2026-09-01 | Added Firebase Analytics (Google LLC) as a data collection and processing entry (§1-3, §3) for service improvement, clarifying it is not used for advertising and not combined with third parties. Reviewed and updated all collection items (§1-2) against actual service behavior — corrected tag terminology (home-cooked/dining-out/drinks → home-cooked/purchased), and added meal date/time-of-day, meal style, interest categories, wishlist, and comment edit history. Clarified that the AI image analysis provider's scope (§3) includes profile photos. Revised §9's notice method from "in-app notice board" to "this document's change history" to reflect actual practice |
최종 수정일 · Last updated: 2026-09-01