Privacy Policy
umpire (sole proprietor, operator: EOM MINKYU, the "Operator") values the personal data of users of the mobile application TourJ (the "Service") and publishes this Privacy Policy in accordance with applicable laws, including the Personal Information Protection Act of Korea.
1. Data We Process and How It Is Collected
| Category | Items | When / How |
|---|---|---|
| Account | Email address, display name, Firebase UID, sign-in provider identifier, profile photo URL (if provided by the social login) | Email sign-up, Sign in with Apple, Google Sign-In |
| Profile | Nickname, avatar emoji, friend code, friend relationships, shared-trip membership and role | Entered by the user; when adding friends or sharing trips |
| Location | Current location (latitude/longitude) — processed on the device and by Google Maps/Places SDKs for map and nearby-place features; it is not stored on the Operator's servers or linked to your TourJ account identifier. Names, addresses and coordinates of destinations you deliberately save are trip content, not a current-location history. | When using map/place features (only if you grant the OS permission) |
| User content | Trips, places, notes, flight and accommodation details (including booking references), expenses and budgets, packing lists, wishlist (cities/places you want to visit), globe records | Entered by the user; synced to the cloud when signed in |
| Ticket & document files | Booking confirmations, receipts and ticket images/PDFs — stored only on your device and never uploaded to our servers | When you attach or scan them |
| AI usage data | Trip conditions you enter for AI planning (city, dates, themes, budget, companions, preferences); text extracted from documents by on-device OCR after sensitive data (passport numbers, card numbers, resident registration numbers, emails, phone numbers, dates of birth) is masked on the device; live-search queries; daily AI usage counters | Only when you use AI features, and only after separate explicit consent |
| Purchase history | Apple transaction ID, product ID, transaction environment (Sandbox/Production), quantity, purchase/refund times, server validation/pass-grant/refund-processing times, duplicate-redemption status, refund status, and recovered/adjusted quantities. TourJ does not receive or store payment-card or bank-account details; Apple processes them directly. | When an App Store in-app purchase is validated/granted or an Apple-approved refund/refund-reversal notification is processed |
| Device & log data | Crash logs, performance metrics, app usage events, app version, OS version, device model, app instance identifier, masked (pseudonymized) user identifier | Collected automatically via Firebase Crashlytics / Analytics |
2. Purposes of Processing
- Member identification and authentication; isolating and syncing your data across devices
- Providing core features: trips, places, tickets, budgets
- Friends, trip sharing and read-only share links
- AI itinerary generation, booking/receipt recognition and live search — only at your request and after separate consent
- Rate-limiting to prevent AI abuse
- Validating in-app purchases, granting AI itinerary-generation passes, withdrawing unused refunded passes, adjusting used refunded quantities, restoring entitlements when Apple reverses a refund, preventing duplicate/fraudulent redemption, and handling purchase inquiries
- Service stability, crash diagnosis and improvement; pseudonymized usage statistics
- Compliance with legal obligations and dispute handling
3. Retention Periods
- Account data and user content: kept until account deletion, then erased without delay (see Section 7 for scope and exceptions).
- AI usage counters: recorded per day; all deleted upon account deletion.
- Account-deletion safety lock: to prevent another device or a still-valid session from recreating data while deletion is in progress, we store only the lock state and expiry time. The lock is set to expire 48 hours after creation or retry and is automatically removed after expiry, subject to Firestore TTL processing delay.
- In-app purchase records: while the account exists, retained to validate transactions, grant passes, and prevent duplicate redemption. On account deletion, the member identifier (UID) is removed. A UID-unlinked ledger containing the Apple transaction ID, product, quantity, environment, purchase/grant/refund-processing times, refund status, and recovered/adjusted quantities is retained to prevent the same transaction from being credited twice and to preserve payment integrity. Any mandatory statutory retention is handled separately for the required period.
- Crash logs (Crashlytics): under the Firebase retention notice, Google retains crash stacks and associated identifiers for 90 days before beginning removal from live and backup systems.
- Usage analytics (Analytics): user- and event-level data follows the retention selected in the Analytics property. The Google Analytics retention documentation states that a standard GA4 property allows 2 or 14 months, and that setting might not apply to standard aggregated reports. The Operator records the actual property setting before launch and during quarterly operations reviews. Account deletion resets the identifier and analytics data on the device; records already transmitted follow the configured retention and Google's deletion process.
- AI inputs (Google Gemini): not used to train AI models (paid API); Google may retain them for a limited period for abuse monitoring, then deletes them (see Section 6).
- Data subject to statutory retention: kept separately for the legally required period.
- Dispute/complaint records: kept 3 years after resolution.
4. Provision to Third Parties
We do not sell personal data and, in principle, do not provide it to third parties without consent, except:
- When you consent or request it yourself — e.g., sharing a trip shows your nickname/avatar and trip content to that friend; creating a read-only share link shows a sanitized trip summary (booking references, individual expenses and attachments removed) to anyone with the link.
- Where required by law or by lawful requests of investigative authorities.
5. Processing Delegation (Processors)
| Processor | Delegated work | Items |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions, Crashlytics, Analytics, App Check) |
Authentication, data storage/sync, AI proxy server, crash/usage analytics, app integrity | Account, profile, user content, crash/performance logs, usage events |
| Google LLC (Gemini API) |
AI itinerary generation, booking/receipt text analysis, live search answers | Trip conditions, OCR text masked on-device, search queries. Original images/PDFs are never sent; only after separate consent. |
| Google LLC (Google Maps Platform, Places API, Google Sign-In) |
Maps, place search/autocomplete, Google account login | Map interactions, search terms, place coordinates, account identifier |
| Apple Inc. | Sign in with Apple; App Store in-app purchase/refund processing and transaction validation | Apple ID identifier, email (private relay address if you choose), transaction ID, product ID, quantity, purchase/refund times, transaction environment and refund status. Apple handles payment details directly; TourJ does not receive them. |
| Open-Meteo (non-profit open API) | Weather forecasts for destinations | Destination city coordinates and dates (no account identifiers) |
6. Cross-Border Transfers
| Item | Details |
|---|---|
| Recipients | Google LLC (1600 Amphitheatre Parkway, Mountain View, CA, USA — privacy contact), Apple Inc. (One Apple Park Way, Cupertino, CA, USA) |
| Countries | The United States and other countries where Google/Apple operate data centers. Firestore and the AI proxy (Cloud Functions) run primarily in the Seoul region (asia-northeast3); authentication, analytics and AI processing may occur in the U.S. or elsewhere. |
| Items | The items listed in Sections 1 and 5, including in-app purchase transaction information |
| Timing / method | Transferred over encrypted connections (TLS/HTTPS) whenever you use the Service |
| Purpose | The purposes in Section 2 |
| Retention | Same as Section 3. Gemini API inputs may be temporarily retained by Google for abuse monitoring and then deleted (Gemini data usage policy); paid-tier inputs are not used for model training. |
| How to refuse / consequences | You may refuse or withdraw AI transfers at any time (separate in-app consent; Profile → AI data-transfer consent) and still use every feature via manual entry. Transfers to Firebase are essential to operate the Service; you can refuse them by using the app without an account (browse mode) or by deleting your account, in which case sync/friends/sharing are unavailable. For other requests, contact the officer in Section 14. |
7. Account Deletion and Scope of Erasure
You can delete your account at any time in Profile → Account → Delete Account. Upon deletion we erase without delay:
- Server (Firebase): account and profile; all trips, places and folders; globe backup (wishlist, engrave records); friend relationships (including your entry left in friends' lists); share links you created; invitations sent or received; shared trips you own (deleted for all members); your membership in other members' shared trips; AI usage records; the Firebase auth account (with Apple sign-in token revocation).
- Your device: trip files, ticket/booking/receipt files, wishlist, app settings and AI consent records, scheduled notifications; analytics identifiers and accumulated data are reset.
Exceptions, with reasons and handling:
- Collaborative content of shared trips owned by other members: the trip itself remains for the remaining members; only your membership and identifier links are removed. You may leave such trips or ask their owner to delete them before deleting your account.
- In-app purchase ledger with the member UID removed: your member identifier (UID) is removed on account deletion. The Apple transaction ID, product, quantity, environment, purchase/grant/refund-processing times, refund status and recovered/adjusted quantities remain solely to prevent transaction reuse or duplicate credit and to preserve payment integrity; they are not used to relink the ledger to your profile or deleted trip data.
- Account-deletion safety lock: only the lock state and expiry time remain to prevent deletion races and data recreation through an existing authenticated session. It is set to expire 48 hours after creation or retry and is automatically removed after expiry, subject to Firestore TTL processing delay.
- Processor system logs and backups: automatically purged by Google per their policies (Crashlytics is retained 90 days before removal begins; Analytics user/event-level retention is the property's 2- or 14-month setting, while standard aggregate reports are outside that setting; Gemini abuse-monitoring retention).
- Data under statutory retention: stored separately for the legally required period, then destroyed.
You may re-register with the same email at any time; deleted data cannot be recovered.
8. AI Features (Google Gemini)
- AI itinerary generation, booking/receipt recognition and live search use Google LLC's Gemini API.
- No data is sent until you give explicit consent on a dedicated consent screen that explains what is sent, to whom, and why. The consent version and timestamp are recorded.
- OCR runs on your device; passport numbers, card numbers, resident registration numbers, emails, phone numbers and dates of birth are masked on-device before any text is sent. Original files are never uploaded.
- Requests go through the Operator's proxy (Cloud Functions, Seoul region), which requires Firebase authentication and App Check.
- If you decline or withdraw consent (Profile → AI data-transfer consent), every feature remains available via manual entry.
- Per the Gemini API Terms, AI features are available only to users aged 18 or older, confirmed on the consent screen.
- AI output may be inaccurate; the app always shows a review screen before anything is saved.
9. Destruction of Personal Data
- Procedure: data whose retention period has ended, or subject to a deletion request, is destroyed without delay.
- Method: electronic files are deleted irrecoverably; paper documents are shredded or incinerated.
10. Your Rights
You may at any time request access, correction, deletion, or suspension of processing; withdraw consent (including AI transfers); and request copies of your data. Exercise these rights directly in the app (profile editing, AI consent management, account deletion) or by contacting the officer in Section 14. We respond within 10 days. Rights may also be exercised through a legal representative or an authorized agent.
11. Security Measures
- All network traffic is encrypted with TLS (HTTPS).
- Firestore security rules restrict access to your own data (or trips you are a member of).
- The AI proxy and the account-deletion API require Firebase auth tokens and App Check verification.
- iOS file protection is applied to on-device files such as tickets and booking documents.
- Release-build system logs keep contents private (no place names/coordinates in plain text); identifiers are masked.
- Secret keys are kept out of source code, in build settings and server-side environment variables.
- Sensitive data is automatically masked on-device before any AI transfer.
12. Automatic Collection and Opt-Out
The Service uses no cookies. Firebase Crashlytics/Analytics automatically collect crash logs, usage events, an app instance identifier and a masked (pseudonymized) user identifier for diagnostics and statistics. While you are signed in, crash/performance data and usage events may be linked to that pseudonymous identifier. The app instance identifier is not the advertising identifier (IDFA) and is not used for advertising tracking.
To opt out: deleting your account resets the analytics identifier and accumulated data on your device; deleting the app stops all collection; to request erasure of already-collected data, contact the officer in Section 14.
13. Children Under 14
The Service does not accept sign-ups from children under 14. Sign-up includes a confirmation that the user is 14 or older. If we learn that a child under 14 has registered without legal-guardian consent, we delete the account and its data without delay. Guardians may contact the officer below.
14. Privacy Officer
- Name: EOM MINKYU
- Email: dainomk556@gmail.com
15. Remedies
For dispute mediation or counseling in Korea: Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972), Privacy Report Center (privacy.kisa.or.kr / 118), Supreme Prosecutors' Office (spo.go.kr / 1301), National Police Agency (ecrm.police.go.kr / 182).
16. Changes to This Policy
Changes are announced on this page at least 7 days before they take effect; material changes are additionally announced in-app or by email.
- May 23, 2026: first version.
- August 2, 2026: comprehensive revision — detailed Gemini AI disclosure and separate consent, itemized cross-border transfers, detailed deletion scope, age-14 confirmation, removal of unused items (Cloud Storage, push notifications).
- August 10, 2026: clarified App Store purchase/refund records, refunded-pass adjustments and their retention/deletion treatment, the account-deletion safety lock, pseudonymous linking in Analytics/Crashlytics, and on-device-only handling of original photos/PDFs.