칸데(CANDE)(이하 “회사”)는 정병발사 앱과 Cande 홈페이지의 개인정보
처리에 관하여 이 방침을 적용합니다. 사업자등록번호는
798-35-01563입니다.
개인정보 보호 업무 및 권리행사 접수 부서는
Cande 개인정보 보호 담당입니다.
열람·정정·삭제·처리정지 요청과 개인정보 관련 문의는
푸터의 문의 이메일로 접수합니다.
2. 처리 목적, 항목과 근거
회사는 서비스 제공 계약의 체결·이행에 필요한 범위, 이용자의 동의
또는 관계 법령에 따른 의무를 근거로 개인정보를 처리합니다. 동의가
필요한 처리는 필요한 사항을 별도로 알린 뒤 동의를 받습니다. 이
방침의 게시 자체를 동의로 보지 않습니다.
구분 / 목적
처리 항목
처리 근거
로그인·계정 관리
Google/Apple 계정 식별정보, 서비스 회원 식별자, 로그인
과정에서 제공되는 이메일·이름·프로필 정보, 인증·세션 정보
계약 체결·이행에 필요한 처리
프로필·친구·채팅 제공 및 복원
사용자가 정한 호칭, 선택한 프로필 이미지, AI 친구
닉네임·성향, 채팅방·참여 멤버, 대화 내용·시각·상태 및 응답
생성에 필요한 최근 대화
계약 이행에 필요한 처리. 선택적 사진은 해당 기능을 선택할 때
처리
이용권·구독·구매 확인
회원 식별자, 상품·거래 식별자, 구매·환불·구독 상태, 이용권
잔액·사용 내역, 스토어 및 SDK의 기기·앱 버전 등 기술정보
계약 이행 및 거래기록 보존 의무
문의·권리행사 처리
발신 이메일, 문의 내용, 답변 기록 및 본인 확인에 필요한 최소
정보
요청 처리 및 법령상 의무 이행
서비스 보안·오류 대응
접속 시각, IP 주소, 요청·오류 정보, 기기·운영체제·앱 버전 등
기술정보
서비스 제공에 필요한 처리 및 법령상 보안 의무. 별도 정당한
이익에 의존하는 경우 필요성·권리 침해 여부를 검토
소셜 로그인 정보는 제공자와 이용자가 선택한 공개 범위에 따라
달라집니다. 회사가 소셜 계정 비밀번호나 결제 카드번호를 직접
수집·보관하지는 않습니다. 카메라·사진 접근은 이용자가 해당 기능을
사용할 때 기기 권한을 요청하며, 거부해도 사진 기능 외의 기본 기능은
이용할 수 있습니다.
연락처 목록, 정밀 위치, 학교 계정, 학번 등을 필수로 요구하지
않습니다. 대화에 주민등록번호, 건강정보 등 민감정보나 다른 사람의
개인정보를 입력하지 마세요. 별도의 민감정보 처리가 필요해지는
경우에는 적법한 별도 절차를 마련합니다.
3. 보유기간과 파기
계정·프로필·친구·채팅 정보는 서비스 이용기간 동안 보관하고, 탈퇴
또는 적법한 삭제 요청으로 처리 목적이 끝나면 법령상 보존 대상 외의
정보는 지체 없이 파기합니다. 일반 문의는 처리 완료 후 파기하며,
아래의 소비자 불만·분쟁 기록에 해당하는 부분만 법정기간 보존합니다.
법정 보존 대상
기간
근거
계약 또는 청약철회 기록
5년
전자상거래법 시행령 제6조
대금결제 및 재화·서비스 공급 기록
5년
전자상거래법 시행령 제6조
소비자 불만 또는 분쟁처리 기록
3년
전자상거래법 시행령 제6조
표시·광고 기록
6개월
전자상거래법 시행령 제6조
위 기간은 해당 법률의 적용 대상인 실제 기록에 한해 적용하며, 모든
채팅을 거래기록이라는 이유로 보관하지 않습니다. 보존 대상은 일반
서비스 정보와 분리하고 보존 목적 외에 이용하지 않습니다.
개인정보처리시스템의 관리용 접속기록은 적용되는 안전성 확보조치
기준이 정한 기간 동안 보존합니다.
전자파일은 복구가 어렵도록 삭제하고 종이 문서는 분쇄 또는
소각합니다. 백업·외부 처리자 보관분도 정해진 삭제 절차에 포함하며,
기술적 사유로 즉시 제거가 어려운 경우에는 복구·일반 이용을 제한하고
해당 보관 주기가 끝나면 제거합니다. 정확한 로그·백업 보존 주기는
시행 전 운영 설정과 대조하여 확정합니다.
4. 처리 위탁과 외부 서비스
회사는 다음 서비스를 이용해 필요한 업무를 처리합니다. 위탁계약에는
목적 외 처리 금지, 접근 통제, 재위탁 관리, 삭제 및 사고 대응에 관한
사항을 정하고 관리합니다.
업체
업무 / 정보
Supabase
인증, 데이터베이스, 비공개 이미지 저장 및 서버 기능.
계정·프로필·친구·채팅·이용권 데이터와 서비스 운영 정보
OpenAI
AI 응답 생성. 현재 입력, 응답에 필요한 최근 대화, 선택한 AI
친구의 식별자·닉네임·성향
Google/Apple 로그인과 App Store/Google Play 결제 과정에서 각
사업자가 자신의 계정·결제 서비스를 위해 처리하는 정보에는 해당
사업자의 방침도 적용됩니다. 이는 회사가 대화 내용을 광고 사업자에게
제공한다는 뜻이 아닙니다. 회사는 법령상 근거 또는 별도 동의 없이
개인정보를 독립적인 제3자의 목적을 위해 제공하지 않습니다.
5. 국외 처리 안내
외국 사업자의 인프라를 통해 AI 응답, 구매 검증 및 문의 처리가
이루어집니다. 계약 이행에 필요한 국외 처리위탁·보관은 개인정보
보호법 제28조의8에서 허용하는 요건을 갖추어 안내하며, 별도 동의가
필요한 이전은 사전에 동의를 받습니다.
국외 이메일 처리. 실제 처리 국가·계약 조건은 시행 전 확정 /
문의 이메일 전송 시 서비스 통신
문의 이메일·답변 / 문의 처리 / 일반 문의 처리 완료 시 파기,
해당하는 분쟁 기록은 3년
시행 전 확인 사항: 이 표는 확인된 구현과 제공자의
공개 안내를 바탕으로 작성한 예정 내역입니다. 아직 확인되지 않은 실제
이전 국가·계약 법인·삭제 주기를 확정한 뒤 최종 방침을 게시합니다.
이전을 원하지 않는 경우 해당 기능을 이용하기 전
푸터의 문의 이메일로 문의하거나 동의
철회·계정 삭제를 요청할 수 있습니다. AI 응답, 외부 인증 또는 구매
검증에 필요한 처리를 거부하면 해당 기능의 제공이 어려울 수 있습니다.
홈페이지 열람은 별개입니다.
6. AI 대화의 처리
AI 응답은 사람이 작성하는 실시간 답변이 아닙니다. 회사 서버가 현재
메시지와 필요한 최근 대화, AI 친구 설정을 OpenAI API로 전송합니다.
프로필 사진과 로그인 이메일은 응답 생성을 위한 별도 입력 항목으로
전송하지 않지만, 이용자가 메시지에 직접 쓴 개인정보는 대화 내용에
포함될 수 있습니다.
현재 API 요청은 store:false로 설정되어 있습니다. 이는 외부 업체가
정보를 전혀 보관하지 않는다는 뜻이 아닙니다. OpenAI의 기본 API
정책상 입력·출력은 고객이 별도로 참여하지 않는 한 모델 학습에
사용되지 않으며 보안 목적의 보관이 있을 수 있습니다. 회사는 대화를
광고 타기팅이나 사용자 장기 성향 학습에 이용하지 않습니다.
회사는 AI 대화 결과로 채용·신용평가 등 이용자의 권리·의무에 중대한
영향을 미치는 자동화된 결정을 하지 않습니다. 응답 또는 이용 제한에
관한 이의는 담당 부서에 제기할 수 있습니다.
7. 권리행사와 계정 삭제
이용자 또는 적법한 대리인은
푸터의 문의 이메일로 개인정보 열람,
정정, 삭제, 처리정지, 동의 철회 및 계정 삭제를 요청할 수 있습니다.
회사는 필요한 최소한의 본인·대리인 확인 후 관계 법령의 기한과 절차에
따라 처리합니다. 법률상 제한되는 경우에는 그 사유와 이의제기 방법을
안내합니다.
앱 삭제나 로그아웃만으로 서버 계정·데이터가 삭제되지는 않습니다.
계정 삭제와 스토어 구독 해지는 별개이며, 자동 결제를 중단하려면 해당
스토어에서 구독을 해지해야 합니다. 삭제 요청에는 비밀번호나 결제수단
전체 번호를 보내지 마세요.
8. 아동의 개인정보
정병발사는 만 14세 미만 아동을 대상으로 제공하지 않습니다. 만 14세
미만 아동의 정보가 법정대리인 동의 등 적법한 근거 없이 수집된 사실을
알게 되면 확인 후 필요한 삭제·처리 제한 조치를 취합니다. 아동의
정보가 포함된 경우 담당 부서로 알려주세요.
9. 안전조치와 홈페이지 저장정보
회사는 암호화된 통신, 사용자별 데이터 접근 권한, 비공개 이미지 저장,
인증정보 보호를 적용하고 개인정보 접근자를 필요한 범위로 제한합니다.
개인정보 보호 업무 절차, 접근권한 점검과 사고 대응 절차를
운영합니다.
현재 홈페이지에는 자체 광고·방문자 분석 스크립트가 없으며, 언어
선택값만 브라우저의 로컬 저장소(cande-language)에 저장합니다.
브라우저 사이트 데이터 삭제로 지울 수 있고 저장을 차단해도 한국어
기본 화면을 볼 수 있습니다. 앱에는 로그인 유지와 대화 복원을 위한
로컬 캐시가 별도로 저장됩니다. 공개 호스팅 서비스의 접속기록은 실제
배포 환경에 맞추어 추가 안내합니다.
방침이 변경되면 변경 내용과 적용일을 홈페이지 또는 앱에 알립니다.
동의가 필요한 변경은 별도 절차를 거칩니다. 이 문서의 시행 예정일은
2026년 10월 1일입니다.
1. Scope and contact
This policy covers the Jeongbyeong Balsa app and Cande website
operated by 칸데(CANDE) (“Cande”). Business registration number:
798-35-01563.
The Cande Privacy Team receives privacy questions
and requests to access, correct, delete or restrict processing of
personal data through
the contact email in the footer.
2. Purposes, information and legal grounds
We process data as necessary to enter into or perform the service
contract, with consent, or to meet legal obligations. Where separate
consent is required, we explain the processing and obtain it
separately. Publishing this policy does not constitute consent.
Purpose
Information
Ground
Login and account management
Google/Apple account identifiers, service user ID, email,
name and profile information supplied during login,
authentication and session information
Necessary to enter into or perform the contract
Profiles, friends, chat and restoration
Chosen name and image, AI friend names and personalities,
rooms and members, messages, timestamps, status and recent
context
Service performance; optional photos are processed when that
feature is selected
Credits, subscriptions and purchase verification
User, product and transaction IDs,
purchase/refund/subscription status, credit balance and
usage, device/app and SDK technical data
Contract performance and applicable recordkeeping
obligations
Questions and privacy requests
Sender email, request and reply, minimum identity
verification information
Responding to requests and fulfilling legal duties
Security and error handling
Access time, IP address, request/error information, device,
OS and app version
Necessary service processing and legal security duties; any
separate legitimate-interest basis requires an assessment
Information received from a social login provider depends on the
provider and your sharing choices. We do not directly collect your
social-account password or payment card number. Camera/photo
permissions are requested when you use those features. Declining
does not block other basic features.
Contact lists, precise location and school identifiers are not
required. Do not enter government identifiers, health or other
sensitive data, or another person’s personal information in
messages. Any intended sensitive-data processing requires a separate
lawful procedure.
3. Retention and deletion
Account, profile, friend and chat data are kept during service use,
then erased without undue delay when the purpose ends through
account closure or a valid deletion request, except where retention
is legally required. Ordinary inquiries are deleted when resolved.
Only records qualifying as consumer complaints or disputes are
retained for the statutory period below.
Applicable transaction record
Period
Basis
Contracts or withdrawal
5 years
Article 6, Enforcement Decree of the Korean Electronic
Commerce Consumer Protection Act
Payments and supply of goods/services
5 years
Same provision
Consumer complaints or disputes
3 years
Same provision
Advertisements
6 months
Same provision
These periods apply only to actual records covered by the law, not
to all chat messages. Retained records are separated and used only
for their retention purpose. Administrative access logs for
personal-data systems are retained for the period required by the
applicable security standard.
Electronic files are securely deleted; paper is shredded or
destroyed. Backups and processor copies are included in deletion
procedures. If technical constraints prevent immediate erasure,
ordinary use and restoration are restricted until removal at the end
of the applicable cycle. Exact log and backup periods require
operational verification before the policy takes effect.
4. Processors and external services
We use the following providers for service operations. Processing
agreements address purpose limitations, access controls,
subprocessors, deletion and incident handling.
Provider
Processing
Supabase
Authentication, database, private image storage and server
functions; account, profile, friend, chat, credit and
operational data
OpenAI
AI responses; current input, necessary recent context,
selected AI friend IDs, names and personalities
RevenueCat
In-app purchase verification and subscription/credit
management; user, transaction, product and SDK data
Google (Gmail)
Receiving and storing inquiry emails, sender address and
correspondence
Google/Apple and the App Store/Google Play also process information
for their own account and payment services under their policies.
This does not mean we disclose chat content for advertising. We do
not provide personal data for an independent third party’s purposes
without consent or another legal basis.
5. International processing
External infrastructure supports AI responses, purchase verification
and inquiry handling. Necessary overseas outsourcing/storage must
meet Article 28-8 of Korea’s Personal Information Protection Act;
transfers requiring separate consent are subject to that consent.
International API processing; actual countries and
contracting entity to be confirmed before effectiveness /
encrypted requests when chatting
AI input described above / responses / default
abuse-monitoring retention up to 30 days, subject to legal
exceptions
RevenueCat, Inc. / compliance@revenuecat.com
United States / encrypted communications when connecting to
purchase services or verifying purchases
User, purchase and SDK data / purchase verification / until
the purpose ends or deletion is processed; precise
deletion/backup periods need contractual verification
Supabase / privacy@supabase.io
Database configured for Seoul, Korea; overseas
support/subprocessor locations and scope require contract
verification / encrypted service requests
Account and service data / authentication, storage, server
processing / service period, applicable legal periods and
verified deletion/backup cycles
International email processing; actual locations and
contract terms to be confirmed / email communications
Inquiry correspondence / support / ordinary inquiries
deleted on resolution; qualifying dispute records retained
for 3 years
Before effectiveness: This is a proposed record
based on implementation and public provider documentation. Actual
countries, contracting entities and deletion cycles that remain
unverified will be finalized before publication of the final policy.
You can contact
the contact email in the footer before
using a feature, withdraw applicable consent or request account
deletion. Refusing processing necessary for AI, authentication or
purchase verification may make those features unavailable. Website
reading is separate.
6. AI conversations
AI responses are generated, not live replies from a person. Our
server sends the current message, relevant recent context and AI
friend settings to the OpenAI API. Profile images and login email
are not separate AI input fields, but personal data you type can be
part of your message.
Requests use store:false; this does not guarantee that the provider
retains nothing. Under OpenAI’s default API policy, inputs and
outputs are not used for model training unless the customer opts in,
and security retention may apply. Cande does not use conversations
for advertising targeting or long-term personality learning.
We do not use chat responses to make legally or similarly
significant automated decisions such as hiring or credit decisions.
You can raise concerns about responses or service restrictions with
the Privacy Team.
7. Your rights and account deletion
You or an authorized representative may request access, correction,
deletion, processing restriction, consent withdrawal or account
deletion through
the contact email in the footer. After
proportionate verification, we act within applicable legal
deadlines. If a legal restriction prevents compliance, we explain
the reason and how to challenge it.
Uninstalling or logging out does not delete the server account.
Account deletion does not cancel a store subscription; cancel it in
the relevant store to stop renewal. Do not send passwords or full
payment details in a request.
8. Children
Jeongbyeong Balsa is not offered to children under 14. If we learn
that their data was collected without a lawful basis such as
required guardian consent, we verify the issue and take appropriate
deletion or restriction measures. Please report such cases to the
Privacy Team.
9. Safeguards and website storage
We use encrypted communications, user-specific access controls,
private image storage and authentication protection, with access
limited to necessary personnel. Privacy procedures include access
reviews and incident response.
The current website has no in-house advertising or visitor-analytics
scripts. It stores only the language preference, cande-language, in
browser local storage. You may clear site data or block storage;
Korean remains the default. The app separately stores authentication
and conversation caches. Public hosting access logs require
disclosure based on the actual deployment environment.
Changes and application dates will be announced on the website or in
the app; separate consent will be obtained when required. Scheduled
effective date: October 1, 2026. This English version is provided
for convenience; mandatory applicable law remains unaffected.