alull-legal

alull 프로덕트의 개인정보처리방침 및 법적 고지

개인정보처리방침 — 마주(maju)

마주는 같은 장소에 체크인한 사람끼리 서로를 보고, 상호 관심이 있을 때만 매치되는 소개팅 앱입니다. 운영자는 「개인정보 보호법」 등 관련 법령과 Google Play 요건을 준수합니다.

핵심 요약

  • 위치 권한을 요구하지 않습니다. 앱이 GPS·좌표를 읽지 않고, 서버는 위도·경도를 저장하지도 전송하지도 않습니다. 남는 것은 “미리 정해진 장소 5곳 중 어디에 체크인했는가”뿐이고, 그 체크인은 2시간 뒤 만료됩니다.
  • 이메일·전화번호·이름·사진을 받지 않습니다. 계정은 앱을 처음 켤 때 서버가 발급하는 무작위 식별자이며, 회원가입 절차가 없습니다.
  • 광고와 분석 도구가 없습니다. 광고 SDK·분석 SDK·광고 식별자를 사용하지 않으며, 제3자에게 개인정보를 제공하거나 판매하지 않습니다.
  • 매치된 상대와의 대화는 서버에 저장되며 90일 뒤 자동 삭제됩니다. 차단하거나 둘 중 한 사람이 계정을 삭제하면 즉시 사라집니다.
  • 나이는 이용자가 직접 입력한 값입니다. 만 19세 미만 가입은 서버가 거부하지만, 본인확인 절차는 없습니다. 아래 §7 에 이 한계를 그대로 적었습니다.

1. 처리하는 개인정보 항목

1-1. 계정 식별자

항목 수집 방법 목적
무작위 식별자(uid) 앱 최초 실행 시 서버가 생성 내 데이터를 구분하기 위한 식별
인증 토큰 서버가 생성해 기기에 저장 로그인 상태 유지 — 복호화 불가능한 해시(SHA-256)로만 서버에 저장
최종 접속 시각 자동 기록만 합니다. 현재 다른 목적에 사용하지 않습니다 (프로필링·추천에 쓰지 않음)

1-2. 프로필 (이용자가 직접 입력)

항목 제한 비고
닉네임 12자 실명일 필요 없음
나이 만 19~99 이용자 자기신고 (§7 참조)
성별 남성 / 여성 / 기타  
한 줄 소개 60자 선택

1-3. 체크인 (⛔ 좌표를 다루지 않습니다)

1-4. 관심·매치

1-5. 대화 (매치된 상대와만)

항목 내용
메시지 본문 텍스트만. 1건당 500자 이내. 사진·파일·음성은 보낼 수 없습니다
보낸 사람 / 시각  

1-6. 신고·차단 (안전 조치)

항목 내용
신고자·대상 식별자 무작위 uid
신고 사유 미성년자로 보임 / 괴롭힘·폭언 / 성적 불쾌감 / 광고·도배 / 사진·정보가 가짜 / 기타
설명 300자 이내, 선택
대화 스냅샷 신고자가 “함께 보내기”를 선택했을 때만. 담기는 것은 상대가 보낸 메시지 최근 20개이며, 신고자 본인이 쓴 메시지는 담기지 않습니다
처리 상태·시각  

1-7. 자동 수집 정보

1-8. 수집하지 않는 것 (명시)

위치 좌표 · 주소록 · 사진·카메라 · 마이크 · 통화기록 · 문자 · 캘린더 · 광고 식별자 · 기기 고유번호 · 결제 정보 · 민감정보(건강·성생활·종교·정치 성향 등). 본 앱에는 인앱 결제·구독·광고가 없습니다.


2. 개인정보의 이용 목적

  1. 같은 장소에 체크인한 이용자 목록 제공 (좌표 없이 장소 단위)
  2. 관심 표현과 상호 매치, 매치된 상대와의 대화
  3. 이용자 안전 — 신고 접수·자동 노출 제한·차단·정지
  4. 만 19세 미만 가입 차단
  5. 남용 방지(과도한 요청 제한)

3. 앱 권한 및 사용 목적

설치 파일(APK)이 선언하는 전체 권한입니다. 이 앱의 권한 목록은 두 개뿐이며, 그것이 이 앱의 설계입니다.

권한 출처 사용 목적
INTERNET 앱이 직접 선언 서버 통신(프로필·체크인·매치·대화). 이 앱이 요청하는 유일한 기능 권한
com.alull.maju.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION AndroidX 라이브러리가 자동 추가 앱 내부 브로드캐스트를 다른 앱이 받지 못하게 막는 서명 수준 권한. 외부에 노출되지 않으며 이용자 정보와 무관

4. 제3자 제공 및 처리위탁


5. 보유 기간 및 파기

항목 보유 기간
계정 식별자·인증 토큰·프로필 계정 삭제 시까지
체크인 2시간 뒤 만료, 만료 24시간 뒤 삭제
관심·매치 계정 삭제 또는 차단 시까지
대화 90일 (차단·계정 삭제 시 즉시)
신고 기록(사유·시각) 180일 (첫 신고 시각부터)
신고에 첨부된 대화 스냅샷·신고자 설명 180일, 단 신고 대상이 계정을 삭제하면 즉시
처분 이력 180일
프로필을 만들지 않고 방치된 계정 식별자 7일

6. 정보주체의 권리와 행사 방법


7. 연령 제한과 그 한계 (⚠️ 솔직한 고지)


8. 안전성 확보 조치


9. 처리방침의 변경


10. 권익침해 구제 방법


Privacy Policy — maju (English)

maju lets people who have checked in at the same venue see each other, and creates a match only when interest is mutual.

Summary

  • No location permission is requested. The app never reads GPS or coordinates, and the server never stores or transmits latitude/longitude. All that exists is which of five predefined venues you checked into, and that check-in expires after 2 hours.
  • No email, phone number, real name, or photo. Your account is a random identifier issued by the server on first launch. There is no sign-up form.
  • No ads and no analytics SDKs. No advertising identifier. Nothing is sold or shared with third parties.
  • Messages with a match are stored on the server and deleted after 90 days, or immediately if either person blocks the other or deletes their account.
  • Age is self-declared. The server rejects registrations under 19, but there is no identity verification. Section 7 states this limitation plainly.

1. Data We Process

1-1. Account identifiers — a random uid and an auth token, both generated by the server. The token is stored only as a SHA-256 hash. Last-seen timestamp. We do not collect email, phone, name, address, photos, contacts, or device identifiers. Accounts are per-device and do not transfer between devices.

1-2. Profile — nickname (≤12 chars), age (19–99, self-declared), gender, and an optional one-line intro (≤60 chars).

1-3. Check-ins — no coordinates. Only the name of a venue you selected from a fixed list and an expiry timestamp (2 hours). No latitude/longitude, no address, no movement history, no background location. The app does not declare location permissions, so this is not technically possible (see §3). Expired check-ins are deleted after a further 24-hour grace period.

1-4. Interest & matches — who you expressed interest in, and whether a mutual match occurred, with timestamps.

1-5. Messages (with matches only) — text only, ≤500 characters per message; no photos, files, or voice. Retained for 90 days. Blocking deletes the match and the conversation — the rows are actually removed from the server, not merely hidden. If either person deletes their account, the whole conversation is deleted — a 1:1 conversation cannot keep only one side. ⛔ There is no feature that lets the operator read users’ conversations. The only thing an operator can see is the snapshot described below.

1-6. Reports & blocks — reporter/target identifiers, a reason chosen from a fixed list (underage / harassment / sexual / spam / fake / other), an optional ≤300-character note, and — only if the reporter explicitly chooses to attach it — a snapshot of the reported person’s last 20 messages in that conversation. The reporter’s own messages are never attached. Retained for 180 days, counted from the first report about that person; the snapshot and note are deleted immediately if the reported person deletes their account. You may only report someone you actually encountered (same venue, or interest/match/block). Automatic hiding requires reports from at least 3 distinct users, pending operator review.

1-7. Automatically collected — no crash-reporting or analytics SDK. The server application does not store user IP addresses; rate limits are counted per account identifier, except account issuance, which counts requests per IP in memory only, per hour (never stored or logged). Only minimal operational logs are kept — what failed, how many rows the cleanup job removed, when an automatic visibility limit was applied. Those lines may contain a random identifier but never message contents or profile values, and error responses never expose internal details. A last-seen timestamp is recorded but is not currently used for anything else (no profiling, no recommendations).

1-8. Not collected — location coordinates, contacts, photos/camera, microphone, call logs, SMS, calendar, advertising identifiers, device identifiers, payment data, or sensitive categories (health, sexual life, religion, politics). There are no in-app purchases, subscriptions, or ads.

2. Purposes

Showing people checked in at the same venue (venue-level, never coordinates); interest and mutual matching; conversations between matches; user safety (reports, automatic visibility limits, blocking, suspension); enforcing the 19+ requirement; abuse prevention.

3. Permissions

The APK declares exactly two permissions.

Permission Source Purpose
INTERNET declared by the app Server communication (profile, check-in, matches, messages). The only functional permission this app requests
com.alull.maju.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION added automatically by AndroidX A signature-level permission that prevents other apps from receiving this app’s internal broadcasts. Not exposed externally and unrelated to user data

⛔ Location permissions (ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) are not declared. Neither are camera, storage, contacts, microphone, or notification permissions.

4. Third-party Sharing & Processors

We do not sell or share personal data with third parties. No ad network, no analytics service, no external authentication provider. The backend runs on a server operated directly by the developer, and the database lives only on that server — there is no separate cloud data store.

⚠️ However, traffic reaching the server from the public internet passes through a third-party relay (tunnel) service. TLS is terminated on the operator’s own server, so the relay cannot read message contents. Whether that leg must be disclosed as a separate processor is a question that still needs to be confirmed; this paragraph will be updated once it is.

Lawful requests from authorities are handled per applicable law.

5. Retention & Deletion

Data Retention
Account identifier, token, profile Until account deletion
Check-ins Expire after 2 hours; deleted 24 hours after expiry
Interest & matches Until account deletion or block
Messages 90 days (immediately on block or account deletion)
Reports, attached snapshots, moderation records 180 days, from the first report
Account identifiers abandoned without a profile 7 days

A scheduled server job (hourly by default) actually performs these deletions. The retention values live in code; automated tests pin messages 90 days, reports 180 days, check-in 2 hours, and the 500-character message cap. The remaining values (7-day abandoned accounts, 24-hour check-in grace) exist in code but are not yet covered by an assertion.

6. Your Rights

Access — everything about you is visible inside the app. Correction — edit your profile. Deletion — Settings → Delete account, effective immediately.

Contact: alulltro@gmail.com

7. Age Limit and Its Limitation (stated plainly)

This service is for adults 19 and over, and the server rejects registrations under 19. ⚠️ However, there is currently no identity verification. Age is taken as declared, and the operator has no means of confirming it. This document does not hide that. Instead: the app states that age is self-declared; a dedicated “appears to be a minor” report reason is weighted more heavily in the operator’s review queue so those cases surface first; and confirmed minors are suspended.

⚠️ Automatic hiding still requires at least 3 distinct reporters regardless of the reason. An underage report does not hide someone with fewer people. That floor is deliberate — it stops two throwaway accounts from erasing anyone. The weight of a reason does not substitute for the number of people.

If you find a user under 19, email alulltro@gmail.com — the account and its data will be deleted.

8. Security

Auth tokens are stored only as SHA-256 hashes and returned in plaintext exactly once. Tokens are never placed in URLs, because URLs are recorded in proxy access logs; an automated test verifies the app actually behaves this way. ⚠️ Note, however, that a match partner’s random identifier does appear in the conversation’s request path — that value identifies no one on its own, but this is not a claim that no identifier ever appears in a URL. All personal data is accessible only with the owner’s token — knowing someone else’s identifier grants no access. Traffic is encrypted with HTTPS. Per-account rate limits restrict bulk collection.

9. Changes

Changes are announced in the app or on this page; the last-updated date appears at the top.

10. Complaints (Korea)