Privacy Policy
Article 1 (Purpose)
This Privacy Policy is established in accordance with the Personal Information Protection Act to protect users' personal information and to inform users of the purposes and methods of using the personal information they provide, and of the measures taken to protect that information. This Policy takes effect from its date of announcement, and where any content is added, deleted, or amended, notice will be given through an announcement at least 7 days before the amendment takes effect.
Article 2 (Items of Personal Information Collected and Purposes of Collection)
The Company collects the minimum personal information necessary to provide the Service. The purposes, items, retention periods, and legal basis for collection and use are as follows.
| Category | Processing Purpose | Items Collected | Retention/Use Period | Legal Basis |
|---|---|---|---|---|
| Membership registration | Member identification/management, prevention of fraudulent use | (Required) name, email (ID), password, date of birth / (Optional) profile photo, school and department information, member type, phone number, consent to receive marketing information (email/app push) | Until withdrawal is completed (14 days after request) | Article 15 of the Personal Information Protection Act (performance of a contract) |
| Email ownership verification | Verification of email ownership at registration | Until withdrawal is completed (14 days after request) | Article 15 of the Personal Information Protection Act | |
| Payment/refund | Processing payment and refunds | Payment history; bank name, account number, and account holder for refunds | Retention period under applicable law | Article 15 of the Personal Information Protection Act |
| Service use | Verifying usage records, preventing fraudulent use, statistics | Service usage records, access logs, cookies, access IP, device information (OS, app version, device ID) | Destroyed after 1 year | Article 15 of the Personal Information Protection Act, Protection of Communications Secrets Act |
| Learning/usage data | Personalized service, statistics | Areas of interest, usage time and history, etc. | Until termination of service use | Article 15 of the Personal Information Protection Act |
Items Collected upon Registration via Social Login (SSO)
Users who register via social login are also registered as individual members, and the following information is collected depending on the provider. Items marked "optional" are collected only where the user has consented.
| Provider | Items Collected |
|---|---|
| Naver | (Required) contact email address, nickname |
| Kakao | (Required consent) Kakao account (email) / (Optional consent) nickname, profile photo |
| (Required) email / (Optional) profile scope (name, profile image, etc.) | |
| Apple | (Required) email (the user may choose whether to use their actual email address) · fullName (name) is collected only if provided at the time of first authentication |
The Company does not accept membership registration from, and does not collect the personal information of, children under the age of 14. Consent to receive marketing information is optional; use of the Service is not restricted where consent is withheld, and a member may withdraw such consent at any time.
Based on the personal information collected, the Company may analyze a user's areas of interest and usage history to provide (recommend) personalized content, services, and information to the user.
Method of Collection
Information is collected through membership registration and use of the Service, customer center consultations, participation in events, app installation and use, and cookies, among other means.
Where a user does not complete the membership registration process and abandons it midway, the information entered during registration is not stored.
Article 3 (Provision of Personal Information to Third Parties)
The Company does not provide personal information to third parties without the user's consent. Exceptions apply, however, where the user has consented in advance, where required by law, or where information is provided in a form that does not identify a specific individual for statistical, academic, or market-research purposes; in such cases, the Company notifies the recipient, purpose, items, and retention period before obtaining consent.
Article 4 (Entrustment of Personal Information Processing)
To provide the Service smoothly, the Company entrusts personal information processing tasks to the following external specialized providers, and specifies and manages/supervises the matters necessary to ensure personal information is processed securely under the entrustment contract.
| Trustee | Entrusted Task | Retention/Use Period |
|---|---|---|
| Toss Payments Corp. | Online payment processing | Until termination of the entrustment contract |
| Firebase | Sending Kakao notifications, text messages, and emails | Until termination of the entrustment contract |
| AWS | Server operation and data storage | Until termination of the entrustment contract |
| Laputa Co., Ltd. | Handling customer inquiries and consultation | Until termination of the entrustment contract |
Article 5 (Retention and Use Period of Personal Information)
The Company destroys personal information without delay once the purpose of its collection and use has been achieved, except that the following information is retained for the period below as required by applicable law.
| Item Retained | Basis for Retention | Retention Period |
|---|---|---|
| Records concerning contracts or withdrawal of subscription | Act on Consumer Protection in Electronic Commerce | 5 years |
| Records concerning payment and supply of goods, etc. | Act on Consumer Protection in Electronic Commerce | 5 years |
| Records concerning consumer complaints or dispute resolution | Act on Consumer Protection in Electronic Commerce | 3 years |
| Records concerning labeling and advertising | Act on Consumer Protection in Electronic Commerce | 6 months |
| Records concerning identity verification | Act on Promotion of Information and Communications Network Utilization and Information Protection | 6 months |
| Access (visit) records | Protection of Communications Secrets Act | 3 months |
Article 6 (Procedure and Method of Destroying Personal Information)
Information entered for membership registration and similar purposes is stored for a certain period, in accordance with internal policy and applicable law, after its purpose has been achieved, and is then destroyed. Electronic files are deleted by a method that prevents their recovery or reproduction, and paper documents are shredded or incinerated.
Where a member applies for withdrawal (termination of membership), the Company destroys the member's personal information after a 14-day grace period (excluding information that must be retained under applicable law). If the member logs in again during the grace period, the withdrawal request is deemed withdrawn and the account is maintained. Once the grace period has elapsed, the account and related data cannot be restored.
Article 7 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to prevent personal information from being lost, stolen, leaked, altered, or damaged.
- Technical measures: encryption of passwords and important information, encryption during transmission, operation of access-control systems, installation and updating of security/antivirus software, and operation of intrusion detection/prevention systems
- Administrative measures: minimizing and managing the authority of personnel who handle personal information, establishing and implementing an internal management plan, and conducting regular training and self-inspection
- Physical measures: controlling access to computer rooms and data storage rooms, and storing documents and storage media under lock
Article 8 (Cookies and Advertising Identifiers)
The Company uses cookies to provide personalized services, and a user may refuse the storage of cookies through the user's web browser settings; however, refusing cookies may restrict certain services, including login.
The Company may collect and use advertising identifiers (ADID/IDFA) in its mobile app to provide personalized advertising, and a user may block or reset these through the device's settings (Android: Settings › Privacy › Ads; iOS: Settings › Privacy & Security › Tracking).
Article 9 (Processing of Pseudonymized Information)
The Company may process personal information into pseudonymized form for use in statistics compilation, scientific research, and preservation of records for the public interest, and takes administrative, technical, and physical measures, such as access-authority management, access control, and prevention of re-identification, to securely manage pseudonymized information.
Article 10 (Rights of Users and Legal Representatives and Methods of Exercise)
A user may, at any time, request to access, correct, delete, or suspend the processing of the user's personal information, or withdraw consent (withdraw membership), and the Company will take action without delay. Where a correction is requested, the Company does not use or provide the relevant personal information until the correction is completed.
Article 11 (Personal Information Protection Officer and Responsible Department)
The Company has designated a Personal Information Protection Officer who oversees personal information processing and handles user complaints and remedies for harm arising from such processing.
Personal Information Protection Officer
- Name: Youngchae Yoon
- Position: Manager
- Phone: 010-3084-4001
- Email: youngshines@sapyoung.com
Personal Information Protection Department (Customer Support)
- Phone: 070-7549-8227
- Email: unibook_cs@laputa.im
- Hours: Weekdays 09:00–18:00 (excluding public holidays)
Article 12 (Remedies for Infringement of Rights)
A user who requires a report or consultation regarding an infringement of personal information may contact the following agencies.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Investigation Division: 1301 (no area code)
- Korean National Police Agency Cyber Investigation Bureau: 182 (no area code)
Mediation of a consumer dispute may be requested through the Korea Consumer Agency (1372, no area code) or the Fair Trade Commission's Electronic Commerce Dispute Mediation Committee.
Article 13 (Amendment of the Privacy Policy)
This Privacy Policy takes effect from its date of announcement. Where there is a change in applicable law, policy, or internal policy, notice will be given through an announcement at least 7 days before the amendment takes effect.
Date of announcement: August 1, 2026 / Effective date: August 1, 2026
Addendum
This Privacy Policy takes effect on August 1, 2026.