App Store · Google Play 출시 준비 중

Teampler Privacy Policy

Effective date: 2026-08-19 Last updated: 2026-08-19

Teampler (“the App”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (Republic of Korea), to protect personal information of data subjects and to promptly and effectively handle related grievances.

The App is a cloud service used after authentication via social sign-in (OAuth) or an email-and-password account. After sign-in, some data is stored on the operator’s server to enable multi-device sync and real-time collaboration, and some data is also cached on the user’s device for fast restore.

Users may sign out or delete their account at any time to permanently delete server-side data.


1. Personal Information Processed

1.1 Account & service data (stored on the operator’s server)

Depending on the sign-up method (social sign-in or email-and-password), the following items are stored on the operator’s server.

1.2 Data cached on the device

For fast restore and offline display, copies of the team/session data above and app settings are cached on the user’s device in local storage (AsyncStorage), and authentication tokens are stored in secure storage (SecureStore). This data never leaves the device and is removed when the app is deleted or the account is deleted.

1.3 Automatically collected information

The App does NOT use analytics, advertising, or crash-tracking SDKs. No advertising identifiers, cookies, or tracking pixels are used.


2. Purpose of Processing

Stored information is used only for the following purposes.

The App does NOT use personal information for marketing, advertising, profiling, or automated decision-making.


3. Retention and Use Periods

DataStorageRetention
Local cache (AsyncStorage)User deviceUntil app removal or account deletion
JWT / push token (SecureStore)User deviceUntil sign-out or account deletion
Account / team / session (MongoDB Atlas)Operator server (Korea region)Until account deletion
Meeting records (including per-attendee wait and play statistics with names)Operator serverAuto-deleted after 3 months
Cumulative member activity statistics (numbers only, no names)Operator serverUntil account deletion
HTTP access logsOperator serverAuto-deleted within 30 days
Revoked JWTs (Redis blocklist)Operator serverUntil token expiry (max 7 days)
Email verification code (OTP, SHA-256 hashed)Operator server (Redis)Up to 10 minutes after issuance; discarded immediately on verification

Upon account deletion, the user’s account, teams (including teams they host), sessions, and invite codes are permanently deleted.


4. Third-Party Disclosure

The operator does NOT disclose user information to any third party for advertising, marketing, or profiling purposes.

However, the following infrastructure providers process data on the operator’s behalf. The scope and purpose are described in section 5.


5. Outsourcing of Processing

ProcessorDataPurposeRetention
Google LLCOAuth ID token validationSocial sign-inValidated at login only; not stored
Apple Inc.Sign in with Apple token validationSocial sign-inSame
Kakao Corp.Kakao OIDC token validationSocial sign-inSame
Amazon Web Services (ap-northeast-2, Seoul)Server hostingAPI/WebSocket operationUntil account deletion
MongoDB AtlasDatabaseStorage of account/team/session dataUntil account deletion
Amazon SES (ap-northeast-2, Seoul)Sign-up email address / verification codeSending the verification-code (OTP) email for email-and-password sign-upProcessed only at send time; not stored
Expo (650 California St., San Francisco, CA, USA)Push tokens / deliveryPush notification routingUntil sign-out or token refresh
Google LLC (Firebase Cloud Messaging) · Apple Inc. (APNs)Expo push token / notification payloadPush message delivery to devices (Android=FCM, iOS=APNs)Routed only at send time; not stored
Expo (EAS Update, 650 California St., San Francisco, CA, USA)Platform / app build identifier (runtimeVersion) / release channel / installation identifier / connecting IPChecking for and delivering app updates (JavaScript bundles)Processed only at update-check time; not combined with account data

Each processor follows its own privacy policy. The operator applies contractual safeguards to ensure data subject rights are preserved.


6. Deletion Procedures and Methods

Users can delete their data by:

  1. Sign out — Settings → Account → “Sign out” (server data retained; device tokens revoked)
  2. Delete account — Settings → Account → “Delete account” (both server and local data permanently deleted)
  3. Remove the app — Delete the app from the device (only the local cache is deleted; server-side cloud data remains)
  4. Request deletion by email — Even if you cannot access the app (e.g., after uninstalling or unable to sign in), email support@teampler.com with the email you signed up with; after identity verification we will permanently delete your account and related data (within a few business days).

7. Rights of Data Subjects

Under Articles 35-37 of the Personal Information Protection Act, users have the right to access, correct, delete, and suspend processing of their personal information.

For additional inquiries, contact the privacy officer in section 13.


8. Security Measures


9. Automatic Collection (Cookies, etc.)

The App does NOT use cookies, advertising identifiers (IDFA/AAID), or tracking pixels.


10. Children Under 14

The App is not directed at children under 14 and does not knowingly collect personal information from them.


11. App Permissions

The App uses only the following OS permissions, all requiring explicit user consent.

The App does NOT request camera, location, microphone, contacts, or photo permissions.


12. Cross-Border Transfer

The operator’s server is located in the Korea region (Seoul). However, transfers outside Korea may occur in the following cases.

Transfer items, countries, dates, methods, recipients, purposes, and retention periods are disclosed throughout this policy. Users may refuse cross-border transfer by declining (since the App requires sign-in, it then becomes unavailable).


13. Privacy Officer

The app operator is responsible for personal information processing and grievance handling.

Users may direct any inquiries, complaints, or remedy requests related to personal information to the above contact.


14. Remedies

Users may contact the following bodies for dispute resolution and counseling regarding personal information violations.

AuthorityPhoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
KISA Privacy Infringement Report Center118privacy.kisa.or.kr
Cyber Investigation Bureau, Supreme Prosecutors’ Office1301www.spo.go.kr
Cyber Bureau, National Police Agency182ecrm.cyber.go.kr

15. Policy Changes

If this Privacy Policy is added to, deleted from, or amended, the changes will be announced on this page at least 7 days before they take effect. For changes that materially affect user rights, notice will be given at least 30 days in advance.


16. Contact

For inquiries regarding this policy, please contact:

Email: support@teampler.com