Privacy
Privacy Policy
Last updated: 1 September 2026 · Effective: 1 September 2026
BE-JUMIN ("the Service") connects travelers with local neighborhoods and the small businesses within them. This policy explains what personal data we collect, why, how long we keep it, and the choices you have. It applies to the BE-JUMIN mobile app and becomeajumin.com.
1. Who processes your data
The Service is operated by 이도희 ("we", "us"). For any privacy-related question you can reach us at the contact below.
2. What we collect
| Category | Data | When |
|---|---|---|
| Account | Email address; password authentication credential processed by our self-hosted Keycloak server; name from Sign in with Apple or Google; email-verification status; and the device language used for the verification email | When you sign up |
| Profile | Nickname, profile image, bio, dietary preferences, birth year, nationality, interest keywords, all optional | When you choose to add them |
| Location | Your precise device location (GPS coordinates), used to show nearby content, center the map, record where a visit took place, and attach location to your posts and pins | While you use map or visit features (foreground only), with your permission |
| Activity | How you interact with content and features: searches, likes, saves, and the visit records you create | As you use the app |
| Push notifications | App installation identifier, platform, Expo push token, token validity, notification permission status, whether permission can be requested again, last checked time, device language, and notification-category preferences. The underlying APNs or FCM device token is processed by Expo, Apple, or Google for delivery and is not stored directly by BE-JUMIN. Delivery and milestone-deduplication logs contain internal recipient, event and target identifiers, milestone, send status, and creation time. | When you register the device for notifications or change notification settings |
| Notification center | Notification type and target, internal recipient and actor identifiers, safe localized title and body snapshots, language, creation time, and read time | When an eligible comment, like milestone, store publication, or follow event occurs |
| User content | Photos, moment captions, pins and memos, and comments you create | When you post or comment |
| Diagnostics | Crash reports and performance data, to keep the app stable | Automatically, when errors occur |
| Anonymous browsing | A randomly generated device identifier, used to keep your guest session, before you sign in | When you explore as a guest |
The anonymous identifier is generated on your device and is not linked to your name, email, or Apple/Google account unless and until you create an account. We do not use Apple's advertising identifier (IDFA) or device identifier for vendors (IDFV).
3. Why we use it
- To provide the core service: showing you neighborhoods, stories, and local businesses.
- To attach a verified "local" context to content, based on where and when it was created.
- To personalize what you see and to recommend neighborhoods, places, and stories, based on your interest keywords, your location, and the items you save.
- To understand, in aggregate, how the Service is used and improve it.
- To keep the Service secure and prevent abuse.
- To verify email ownership, send verification and resend messages, and maintain account verification status.
- To deliver push notifications, apply your notification preferences, and provide an in-app notification history and read status.
- To translate place, store, menu, guide, Moment, and comment text so the Service can be used in supported languages.
We do not sell your personal data. We do not serve third-party advertising.
4. Who we share it with
We rely on the following systems and providers to run the Service. They process data for the functions and under the terms described below:
- Microsoft Azure: cloud hosting and database (data stored in Korea Central (대한민국)).
- Google Maps: map display and place search.
- Keycloak: self-hosted account authentication and email-verification status management.
- Expo Push Service, Apple Push Notification service (APNs), and Google Firebase Cloud Messaging (FCM): delivery of push tokens and notification title, body, and routing identifiers to your device.
- Google Workspace SMTP relay (smtp-relay.gmail.com): delivery of verification emails; the recipient address, message content, verification link, and delivery metadata are processed for this purpose.
- DeepL: translation of place and store names, addresses and descriptions, menu and category content, guide content, and Moment captions or comments. The production Service uses DeepL API Growth under a data processing agreement (DPA). Only the text needed for translation is sent, and DeepL does not use that content for model training. Translation results may be stored with the source content or cached by BE-JUMIN.
- Sentry: crash and performance monitoring. Error reports may include device and OS information, app version, and technical log content related to the error, which can in some cases include internal user identifiers.
- Apple / Google: sign-in, when you choose those methods.
International transfers
Some of the providers above process data outside of the Republic of Korea:
- Sentry (Functional Software, Inc., United States): the diagnostic and error data described above is transmitted over the network at the moment an error or performance event occurs and is stored on servers in the United States, for the purpose of crash and performance monitoring. It is retained for up to 90 days and then deleted.
- Expo, Apple, and Google (United States and other regions where their service providers operate): push tokens and notification content are transmitted when a notification is sent. Expo processes notification content transiently for delivery and retains push receipts for a limited period; Apple and Google process delivery data under their respective privacy terms.
- Google Workspace SMTP relay (Google and its subprocessors, including processing regions outside Korea): recipient address, verification-email content and link, and delivery metadata are transmitted when a verification email is sent or resent. Google may retain delivery and security logs under the Workspace service settings and terms.
- DeepL (DeepL SE, Germany and other regions where its subprocessors operate under the DPA): relevant text is transmitted when a translation is requested or prepared. Under DeepL API Growth and the DPA, submitted text and translation output are stored only temporarily as technically necessary to provide the service and are not used for model training. If specified error patterns occur, encrypted text and output may exceptionally be retained for up to 72 hours for debugging, with access limited to authorized employees and logged, and are then automatically deleted. Technical access logs may contain metadata but not the submitted text or translation output.
Moment and comment translation is initiated by the user; public place, store, menu, and guide translations may be prepared automatically. Do not include sensitive personal information in public content. Push delivery, verification email delivery, and Sentry diagnostics are necessary to provide the corresponding features or maintain the Service. You may disable push notifications and avoid optional translation features as described in Section 6.
5. How long we keep it
We keep your personal data while your account is active. When you delete your account, we immediately:
- Remove personal identifiers (email, phone, nickname, profile image, bio, birth year, nationality, location history).
- Delete your sign-in account, so you can no longer log in.
- Revoke the token issued through Sign in with Apple, so the app no longer appears under your Apple ID settings.
- Sever the link between your account and any anonymous browsing records, so those records become genuinely anonymous again.
Aggregated and anonymized records that can no longer identify you, such as neighborhood-level activity statistics, may be retained to operate and improve the Service. Content you posted may remain visible, shown as authored by a "deleted user."
- Push tokens and device-notification settings are kept while the device is registered to your account. They are normally removed when the installation is unregistered and are deleted with the account; invalid tokens are disabled. If unregister synchronization fails, a token record can remain until later invalidation or cleanup.
- In-app notification-center records are retained for up to 90 days and are deleted when the recipient account is deleted.
- Push delivery and milestone-deduplication logs currently have no automatic time-based deletion and may remain under internal identifiers after account deletion.
- Email-verification status and verification-email language are kept with the account. The SMTP provider may retain delivery and security logs according to its service settings and terms.
- Temporary translation cache entries are kept for 7 to 30 days. Translation results stored in the database currently have no general time-based expiration and remain until they are deleted through the applicable content or operational deletion process.
6. Your choices
- Delete your account at any time from within the app (Profile → Delete account). Deletion is immediate and cannot be undone.
- Location can be turned off in your device settings; some map features will be limited.
- Notifications can be denied or disabled in device settings, and notification categories can be managed in the app. In-app notification history is separate and may still be created when operating-system push is disabled.
- Access, correction, objection: contact us using the details below.
7. Children
The Service is intended for users aged 14 and over. We do not knowingly collect personal data from children under 14. If you believe a child has provided us data, contact us and we will delete it.
8. Changes
We may update this policy. Material changes will be announced in the app or on our website before they take effect. The "last updated" date above always reflects the current version.
9. Contact
이도희
Email: hello@becomeajumin.com