alull 프로덕트의 개인정보처리방침 및 법적 고지
com.alull.maju마주는 같은 장소에 체크인한 사람끼리 서로를 보고, 상호 관심이 있을 때만 매치되는 소개팅 앱입니다. 운영자는 「개인정보 보호법」 등 관련 법령과 Google Play 요건을 준수합니다.
핵심 요약
- 위치 권한을 요구하지 않습니다. 앱이 GPS·좌표를 읽지 않고, 서버는 위도·경도를 저장하지도 전송하지도 않습니다. 남는 것은 “미리 정해진 장소 5곳 중 어디에 체크인했는가”뿐이고, 그 체크인은 2시간 뒤 만료됩니다.
- 이메일·전화번호·이름·사진을 받지 않습니다. 계정은 앱을 처음 켤 때 서버가 발급하는 무작위 식별자이며, 회원가입 절차가 없습니다.
- 광고와 분석 도구가 없습니다. 광고 SDK·분석 SDK·광고 식별자를 사용하지 않으며, 제3자에게 개인정보를 제공하거나 판매하지 않습니다.
- 매치된 상대와의 대화는 서버에 저장되며 90일 뒤 자동 삭제됩니다. 차단하거나 둘 중 한 사람이 계정을 삭제하면 즉시 사라집니다.
- 나이는 이용자가 직접 입력한 값입니다. 만 19세 미만 가입은 서버가 거부하지만, 본인확인 절차는 없습니다. 아래 §7 에 이 한계를 그대로 적었습니다.
| 항목 | 수집 방법 | 목적 |
|---|---|---|
| 무작위 식별자(uid) | 앱 최초 실행 시 서버가 생성 | 내 데이터를 구분하기 위한 식별 |
| 인증 토큰 | 서버가 생성해 기기에 저장 | 로그인 상태 유지 — 복호화 불가능한 해시(SHA-256)로만 서버에 저장 |
| 최종 접속 시각 | 자동 | 기록만 합니다. 현재 다른 목적에 사용하지 않습니다 (프로필링·추천에 쓰지 않음) |
| 항목 | 제한 | 비고 |
|---|---|---|
| 닉네임 | 12자 | 실명일 필요 없음 |
| 나이 | 만 19~99 | 이용자 자기신고 (§7 참조) |
| 성별 | 남성 / 여성 / 기타 | |
| 한 줄 소개 | 60자 | 선택 |
| 항목 | 내용 |
|---|---|
| 메시지 본문 | 텍스트만. 1건당 500자 이내. 사진·파일·음성은 보낼 수 없습니다 |
| 보낸 사람 / 시각 |
| 항목 | 내용 |
|---|---|
| 신고자·대상 식별자 | 무작위 uid |
| 신고 사유 | 미성년자로 보임 / 괴롭힘·폭언 / 성적 불쾌감 / 광고·도배 / 사진·정보가 가짜 / 기타 |
| 설명 | 300자 이내, 선택 |
| 대화 스냅샷 | 신고자가 “함께 보내기”를 선택했을 때만. 담기는 것은 상대가 보낸 메시지 최근 20개이며, 신고자 본인이 쓴 메시지는 담기지 않습니다 |
| 처리 상태·시각 |
위치 좌표 · 주소록 · 사진·카메라 · 마이크 · 통화기록 · 문자 · 캘린더 · 광고 식별자 · 기기 고유번호 · 결제 정보 · 민감정보(건강·성생활·종교·정치 성향 등). 본 앱에는 인앱 결제·구독·광고가 없습니다.
설치 파일(APK)이 선언하는 전체 권한입니다. 이 앱의 권한 목록은 두 개뿐이며, 그것이 이 앱의 설계입니다.
| 권한 | 출처 | 사용 목적 |
|---|---|---|
INTERNET |
앱이 직접 선언 | 서버 통신(프로필·체크인·매치·대화). 이 앱이 요청하는 유일한 기능 권한 |
com.alull.maju.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
AndroidX 라이브러리가 자동 추가 | 앱 내부 브로드캐스트를 다른 앱이 받지 못하게 막는 서명 수준 권한. 외부에 노출되지 않으며 이용자 정보와 무관 |
ACCESS_FINE_LOCATION·ACCESS_COARSE_LOCATION)을 선언하지 않습니다.| 항목 | 보유 기간 |
|---|---|
| 계정 식별자·인증 토큰·프로필 | 계정 삭제 시까지 |
| 체크인 | 2시간 뒤 만료, 만료 24시간 뒤 삭제 |
| 관심·매치 | 계정 삭제 또는 차단 시까지 |
| 대화 | 90일 (차단·계정 삭제 시 즉시) |
| 신고 기록(사유·시각) | 180일 (첫 신고 시각부터) |
| 신고에 첨부된 대화 스냅샷·신고자 설명 | 180일, 단 신고 대상이 계정을 삭제하면 즉시 |
| 처분 이력 | 180일 |
| 프로필을 만들지 않고 방치된 계정 식별자 | 7일 |
com.alull.majumaju lets people who have checked in at the same venue see each other, and creates a match only when interest is mutual.
Summary
- No location permission is requested. The app never reads GPS or coordinates, and the server never stores or transmits latitude/longitude. All that exists is which of five predefined venues you checked into, and that check-in expires after 2 hours.
- No email, phone number, real name, or photo. Your account is a random identifier issued by the server on first launch. There is no sign-up form.
- No ads and no analytics SDKs. No advertising identifier. Nothing is sold or shared with third parties.
- Messages with a match are stored on the server and deleted after 90 days, or immediately if either person blocks the other or deletes their account.
- Age is self-declared. The server rejects registrations under 19, but there is no identity verification. Section 7 states this limitation plainly.
1-1. Account identifiers — a random uid and an auth token, both generated by the
server. The token is stored only as a SHA-256 hash. Last-seen timestamp. We do not
collect email, phone, name, address, photos, contacts, or device identifiers. Accounts are
per-device and do not transfer between devices.
1-2. Profile — nickname (≤12 chars), age (19–99, self-declared), gender, and an optional one-line intro (≤60 chars).
1-3. Check-ins — no coordinates. Only the name of a venue you selected from a fixed list and an expiry timestamp (2 hours). No latitude/longitude, no address, no movement history, no background location. The app does not declare location permissions, so this is not technically possible (see §3). Expired check-ins are deleted after a further 24-hour grace period.
1-4. Interest & matches — who you expressed interest in, and whether a mutual match occurred, with timestamps.
1-5. Messages (with matches only) — text only, ≤500 characters per message; no photos, files, or voice. Retained for 90 days. Blocking deletes the match and the conversation — the rows are actually removed from the server, not merely hidden. If either person deletes their account, the whole conversation is deleted — a 1:1 conversation cannot keep only one side. ⛔ There is no feature that lets the operator read users’ conversations. The only thing an operator can see is the snapshot described below.
1-6. Reports & blocks — reporter/target identifiers, a reason chosen from a fixed list (underage / harassment / sexual / spam / fake / other), an optional ≤300-character note, and — only if the reporter explicitly chooses to attach it — a snapshot of the reported person’s last 20 messages in that conversation. The reporter’s own messages are never attached. Retained for 180 days, counted from the first report about that person; the snapshot and note are deleted immediately if the reported person deletes their account. You may only report someone you actually encountered (same venue, or interest/match/block). Automatic hiding requires reports from at least 3 distinct users, pending operator review.
1-7. Automatically collected — no crash-reporting or analytics SDK. The server application does not store user IP addresses; rate limits are counted per account identifier, except account issuance, which counts requests per IP in memory only, per hour (never stored or logged). Only minimal operational logs are kept — what failed, how many rows the cleanup job removed, when an automatic visibility limit was applied. Those lines may contain a random identifier but never message contents or profile values, and error responses never expose internal details. A last-seen timestamp is recorded but is not currently used for anything else (no profiling, no recommendations).
1-8. Not collected — location coordinates, contacts, photos/camera, microphone, call logs, SMS, calendar, advertising identifiers, device identifiers, payment data, or sensitive categories (health, sexual life, religion, politics). There are no in-app purchases, subscriptions, or ads.
Showing people checked in at the same venue (venue-level, never coordinates); interest and mutual matching; conversations between matches; user safety (reports, automatic visibility limits, blocking, suspension); enforcing the 19+ requirement; abuse prevention.
The APK declares exactly two permissions.
| Permission | Source | Purpose |
|---|---|---|
INTERNET |
declared by the app | Server communication (profile, check-in, matches, messages). The only functional permission this app requests |
com.alull.maju.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
added automatically by AndroidX | A signature-level permission that prevents other apps from receiving this app’s internal broadcasts. Not exposed externally and unrelated to user data |
⛔ Location permissions (ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) are not
declared. Neither are camera, storage, contacts, microphone, or notification permissions.
We do not sell or share personal data with third parties. No ad network, no analytics service, no external authentication provider. The backend runs on a server operated directly by the developer, and the database lives only on that server — there is no separate cloud data store.
⚠️ However, traffic reaching the server from the public internet passes through a third-party relay (tunnel) service. TLS is terminated on the operator’s own server, so the relay cannot read message contents. Whether that leg must be disclosed as a separate processor is a question that still needs to be confirmed; this paragraph will be updated once it is.
Lawful requests from authorities are handled per applicable law.
| Data | Retention |
|---|---|
| Account identifier, token, profile | Until account deletion |
| Check-ins | Expire after 2 hours; deleted 24 hours after expiry |
| Interest & matches | Until account deletion or block |
| Messages | 90 days (immediately on block or account deletion) |
| Reports, attached snapshots, moderation records | 180 days, from the first report |
| Account identifiers abandoned without a profile | 7 days |
A scheduled server job (hourly by default) actually performs these deletions. The retention values live in code; automated tests pin messages 90 days, reports 180 days, check-in 2 hours, and the 500-character message cap. The remaining values (7-day abandoned accounts, 24-hour check-in grace) exist in code but are not yet covered by an assertion.
Access — everything about you is visible inside the app. Correction — edit your profile. Deletion — Settings → Delete account, effective immediately.
Contact: alulltro@gmail.com
This service is for adults 19 and over, and the server rejects registrations under 19. ⚠️ However, there is currently no identity verification. Age is taken as declared, and the operator has no means of confirming it. This document does not hide that. Instead: the app states that age is self-declared; a dedicated “appears to be a minor” report reason is weighted more heavily in the operator’s review queue so those cases surface first; and confirmed minors are suspended.
⚠️ Automatic hiding still requires at least 3 distinct reporters regardless of the reason. An underage report does not hide someone with fewer people. That floor is deliberate — it stops two throwaway accounts from erasing anyone. The weight of a reason does not substitute for the number of people.
If you find a user under 19, email alulltro@gmail.com — the account and its data will be deleted.
Auth tokens are stored only as SHA-256 hashes and returned in plaintext exactly once. Tokens are never placed in URLs, because URLs are recorded in proxy access logs; an automated test verifies the app actually behaves this way. ⚠️ Note, however, that a match partner’s random identifier does appear in the conversation’s request path — that value identifies no one on its own, but this is not a claim that no identifier ever appears in a URL. All personal data is accessible only with the owner’s token — knowing someone else’s identifier grants no access. Traffic is encrypted with HTTPS. Per-account rate limits restrict bulk collection.
Changes are announced in the app or on this page; the last-updated date appears at the top.