Privacy Policy
Last updated: August 18, 2026
1. Service Provider
Ttolong ("ttolong.app") is a community-based Jeju travel planner service. This policy describes how we collect, use, and protect your personal information.
2. Information We Collect
- Account info: Name, email, profile photo (via Google/Kakao OAuth)
- Profile info: Nickname, bio, avatar (user-provided)
- Usage data: Travel plans created, community posts, comments, chat messages
- Community safety data: Reports you submit, report reasons and details, hidden posts, and blocked-user relationships
- Device info: Browser type, OS, screen size (via standard web analytics)
- Push notification token: If push notifications are enabled by the user
3. How We Use Your Information
- Provide and operate the travel planning service
- Display your profile in the community
- Send push notifications you opted into (comments, chat, etc.)
- Improve service quality through usage analytics
- Generate AI-powered travel plans based on your preferences
- Review reports, prevent abuse, enforce community rules, and hide content from blocked users
4. Data Sharing
We do not sell your personal data. We share information only with:
- Supabase — Authentication & database hosting
- Cloudflare — CDN, edge computing, D1 database
- OpenAI / Anthropic — AI plan generation (anonymized travel preferences only)
5. Data Retention
Your data is retained while your account is active. Reports may be retained while they are under review and as reasonably necessary to prevent repeated abuse. You may request deletion at any time by contacting us. Upon account deletion, personal data is removed within 30 days unless retention is legally required.
6. Your Rights
- Access, correct, or delete your personal data
- Withdraw consent for data processing
- Export your data in a portable format
- Opt out of push notifications at any time
- Review and remove users from your blocked-user list in Settings
For Korean users: You have rights under the Personal Information Protection Act (PIPA). For EU users: You have rights under GDPR. For California users: You have rights under CCPA.
7. Cookies & Local Storage
We use cookies for locale preference and authentication session. Local storage is used to cache your profile for faster loading. No third-party tracking cookies are used.
8. Data Security
All data is transmitted over HTTPS. Passwords are managed by OAuth providers (Google/Kakao) — we do not store passwords. Database access is restricted to authorized services only.
9. Children's Privacy
Our service is not intended for children under 14. We do not knowingly collect personal information from children under 14.
10. Night-time Push Notifications
In compliance with Korean telecommunications regulations, push notifications are not sent between 9:00 PM and 8:00 AM KST unless you explicitly opt in to night-time notifications in Settings.
11. Contact
For privacy-related inquiries, please contact: privacy@ttolong.app