gokoreamate

Privacy Policy

Effective date: 2026-09-29

This Privacy Policy explains what information gokoreamate collects, how it is used, and the choices you have. gokoreamate is a travel planning service for exploring Korea, building day-by-day itineraries, and keeping travel memories.

1. Who operates this service

gokoreamate is operated by 케이이엔지, a sole proprietorship in the Republic of Korea (shown by its registered Korean trade name). Address: 부산시 남구 유엔로 96번길 26-31 (대연동), Busan, Republic of Korea.

Privacy contact: 케이이엔지 privacy team (개인정보보호 담당) · [email protected]

2. Information we collect

We collect only what is needed to run the service:

  • Google sign-in (optional): when you choose to sign in with Google, we receive your Google account identifier, name, email address, and profile image link through our authentication provider (Supabase Auth). We never receive or store your Google password.
  • Travel content you create: itineraries (city, dates, places, titles), saved places, your own places with the name, notes, location, and photos you add, trip photos and memos, stories, and your sharing settings.
  • Contact form: email address, message, optional name, and the page or place the inquiry is about, plus your browser language.
  • Reports (optional): the report reason, any note you type (up to 500 characters), and a key computed from your browser's device identifier and the reported item, used to prevent duplicate reports from the same device. Please do not include personal information in the note.
  • Device identifier: a random value created in your browser (not derived from hardware and not linked to your name). It is stored with the content and reactions you create so the service can recognise them as yours; for some records we store a value converted from it instead. If you sign in, this device is linked to your account.
  • Likes, dislikes, 'helpful' marks, reactions, saves, and place suggestions you send.
  • Collected automatically: basic technical logs kept by our hosting providers (such as IP address and request details) and usage statistics (Section 8).

3. Information we do not collect

  • Passwords — Google sign-in never shares your password with us.
  • Date of birth, gender, phone number, postal address, or your contact list.
  • Payment or card details — the service currently has no paid features.
  • Background or continuous location tracking. When you use 'near me', your browser's location is used on your device to sort nearby places and is not sent to our servers.
  • Google Drive, Calendar, or any Google data beyond basic sign-in identity.

4. How we use your information

  • Sign-in information: to keep you signed in and to associate optional AI usage allowances safely with your account.
  • Travel content: to provide the service itself — showing your trips, places, photos, and stories back to you and, only when you choose, to people you share them with.
  • Contact form entries: to read and respond to your inquiry.
  • Reports: to review and act on the reported item and to recognize repeated reports from the same device.
  • Usage statistics: to understand which features are used and improve the service.

5. Google sign-in details

Sign-in uses Google OAuth with the minimum identity scope (OpenID, email, profile). We do not request access to any other Google data, do not request offline access, and do not store Google access or refresh tokens in our own database. Your Google name, email, and profile information are not used for advertising and are not sold.

6. AI features and data sent to AI providers

AI-assisted features (such as itinerary personalization and writing suggestions) are currently disabled in production. Basic itinerary creation works without any AI and sends nothing to AI providers.

If AI features are enabled in the future, they will work as follows, and this policy will be updated before launch: requests are sent to Google's Gemini API. What is sent is limited to the travel context needed for the feature — city, travel dates, travel preferences, and the identifiers, names, and categories of places you selected. The names and precise coordinates of your private personal places are not sent. The writing assistant sends the place name, city, and the note you are editing; the photo caption feature sends the single photo you chose, only when you use it. AI requests never include your email address.

7. Where your data is stored and processed

Your account, travel content, and photos are stored with Supabase on servers located in Seoul, South Korea (AWS ap-northeast-2). Photos are kept in private storage and served through expiring signed links, not public URLs.

The website is delivered through Cloudflare's global network, which processes standard technical logs at edge locations worldwide. Google processes sign-in requests and analytics, and would process AI requests if AI features are enabled; Google may process data outside your country under its own policies.

Service providers that process personal data for us, and where it is processed:

  • Supabase (database, sign-in authentication, photo storage) — stores your account, travel content, and photos in the Seoul region, South Korea (AWS ap-northeast-2). Operator named in its privacy policy: Supabase Pte. Ltd. (Singapore); contact [email protected]. Kept until you delete the content or your account.
  • Cloudflare (website delivery, running the server API, and cookie-free visit statistics) — Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; contact [email protected]. Each time you use the service, request data (such as IP address and the request itself) may be processed at a nearby Cloudflare location outside Korea.
  • Google (Google sign-in and usage analytics) — Google LLC (USA); contact https://support.google.com/policies. At sign-in we receive your Google account identifier, name, email address, and profile image link; usage statistics are sent to Google Analytics only if you give both optional consents (Section 8).
  • Resend (sending notification emails to the operator) — Plus Five Five, Inc.; its privacy policy states data is processed in the United States; contact [email protected]. Notifications to the operator do not contain your name, email, or message.
  • How, when, and how long: information needed for these tasks is sent over encrypted connections (HTTPS) each time you use the service. Retention: Supabase keeps it until you delete the content or your account; Resend keeps delivery logs for 30 days on our current plan; Google Analytics keeps event data for 2 months and user data for 14 months (user- and event-level data; see Section 8); Cloudflare does not store execution logs of our server functions (each provider may keep its own logs under its own policies).
  • How to refuse and what happens: Google Analytics is used only if, in the notice shown on your first visit, you give both consents (collection and use, and transfer outside Korea). If you don't, choose "Reject all", or later turn either off under More › Usage statistics, nothing is sent to Google Analytics from then on, its cookies on this site are deleted, and every feature still works. Supabase and Cloudflare are needed to provide the service, so to refuse them you would stop using it (and can ask us to delete what is already stored). Google sign-in is optional — if you do not sign in, no Google account information is sent to us, but account features are not available.
  • Legal basis: of the processing outside Korea above, Supabase and Cloudflare are entrusted processing and storage needed to perform our service agreement with you, and we disclose these details in this policy under Article 28-8(1)(3)(a) of the Personal Information Protection Act. Google Analytics is used only if you allow it (Section 8).

8. Analytics, cookies, and browser storage

We use Google Analytics 4 for usage statistics only with your consent. We ask for two consents separately — consent to collection and use of personal information (Personal Information Protection Act Article 15(1)(1)) and consent to its transfer outside Korea (Article 28-8(1)(1)) — and load Google Analytics only if you give both. Before you choose, if you choose "Decide later", or if you give only one of them, the Google Analytics script is not loaded, nothing is sent to Google, and no Google Analytics cookie is set. With both consents, information about your visit (a cookie identifier, screens viewed and features used, device and browser information, and your IP address, which Google uses to estimate a rough region) is sent to Google LLC in the USA each time you use the service. Analytics events contain feature and place-level information (for example, a city name or a public place identifier) and never contain your email, name, sign-in tokens, or account identifier. You can change or withdraw your consent at any time under More › Usage statistics; from then on nothing more is sent and this site's Google Analytics cookies are deleted. Withdrawing does not immediately delete information already sent to Google: user- and event-level data already sent remain subject to the Google Analytics retention settings below, and those settings do not apply to Google Analytics' standard aggregated reports. If what we tell you in the notice changes, we do not apply your earlier choice and ask again. The notice asks people under 14 not to consent, but we do not verify age. In our Google Analytics settings, event data is kept for 2 months and user data for 14 months, and the user-data period restarts when a user is active again. These retention settings apply to user- and event-level data, not to standard aggregated reports.

Cloudflare Web Analytics counts visits using browser performance data without cookies; Cloudflare states that it does not collect or use visitors' personal data.

Maps are displayed with NAVER Maps. When a map is shown, your browser connects directly to NAVER's servers, which receive standard connection information such as your IP address. Some images are loaded directly from official tourism websites, which likewise receive connection information.

The only cookie the service itself sets is a temporary one used to confirm your consent while you sign in; it is removed when sign-in finishes, or expires after 10 minutes if it does not. Your browser's local storage keeps: the device identifier, your trip in progress, saved places, tutorial state, language choice, and — if you sign in — your session managed by our authentication provider. Clearing your browser storage removes these from your device.

9. Affiliate links and external services

Some pages contain affiliate links to travel partners (currently Agoda, Trip.com, Klook, and KKday). If you follow one and make a booking, we may earn a commission at no extra cost to you. Clicking such a link takes you to the partner's site with an affiliate identifier; we do not send them your name, email, or travel content. The partner's own terms and privacy policy apply on their site.

10. Public sharing

Trips and stories are private by default. If you set a trip public or share a link, the shared view shows the itinerary content you chose to publish — it does not include your email, your device identifier, or your accommodation arrival time. Other users may copy a public itinerary to their own device (or account, if signed in); copies do not carry your title or travel dates. Photos attached to a memory appear publicly only after you explicitly mark that memory public.

11. Retention

Content you delete in the app is deleted immediately, including the stored photo files. Content you keep remains stored until you delete it or request deletion; the service does not currently auto-expire your travel data.

Inquiry records (kept to answer you and track handling) are kept for 6 months from the date received, and report records (kept to handle reports and judge repeated reports) for 6 months from the date handling is completed; they are then destroyed without delay. Reports still being handled are kept until handling ends and are reviewed regularly. An inquiry that is still open may be kept past 6 months only when a reason and a review date are recorded, and only until that review date. This period is the service's own operating standard, and records are deleted earlier when their purpose ends or a lawful deletion request is received. Inquiry and report records are stored separately from your account and are not deleted automatically when you delete your account. Inquiry notification emails contain only the inquiry number and type, not your name, email, or message; delivery logs kept by the email delivery service (Resend) are retained for 30 days under that service's policy for our current plan. Inquiry notification emails in the operator's mailbox are deleted together with the inquiry. Long-inactive accounts are not currently cleaned up automatically.

How records are destroyed: records whose retention period has ended are deleted from the database (by an automatic job or directly by the operator), and photo files you delete are deleted from storage.

Technical logs at our infrastructure providers: execution logs of the website's server functions (Cloudflare Pages Functions) are not stored, and the database provider (Supabase) keeps API and database logs for 1 day on our current plan. Automatic database backups are not currently used, so deleted information is not restored from backups. Each provider may also keep its own logs under its own policies.

12. Your rights and deletion

You can view, edit, and delete your itineraries, saved places, personal places, photos, and memos directly in the app at any time. Signing out does not delete anything.

You can permanently delete your account yourself in the app (More → Delete account permanently). Deletion proceeds only in the current browser session confirmed by a recent (within 5 minutes) Google sign-in; otherwise you are asked to sign in with Google again first. Deleted: your trips (including photos, memos, and AI-generated text made from them), saved places, personal places (including photos), likes and dislikes on places and trips, 'helpful' marks on trips, event reactions, trip view records, place suggestions still under review, This Trip sync data, device links, consent records, and the sign-in account itself. Kept: copies of your public trips that other users already made (only the link to the original is removed), anonymized aggregate statistics that cannot identify you (such as helpful and usage counts), place suggestions already adopted as public places, and inquiry and report records, which are not part of account deletion and are handled under a separate retention standard.

If deletion is interrupted, no partial success is reported — retrying the same action resumes from what remains. Deletion cannot be undone. Requests that cannot be handled in the app — including access to, correction of, or deletion of inquiry and report records — are accepted through the contact channel below. We review and act on a request without delay and notify you of the result within 10 days of receiving it. The result is sent to the email address you used for the request, and we may ask for additional confirmation to verify that you are the requester.

13. Children

Signing in (account features) is available only to people aged 14 or older. Before signing in you confirm that you are 14 or older; without this confirmation the account is not activated. The service does not verify age with a date of birth or ID and does not offer a parent or guardian consent process. Browsing and creating trips on this device without signing in do not require an age check, and in that case we do not collect your name or email address.

If we learn that an account was created by someone under 14, we delete that account and the information linked to it without delay.

14. Security

Connections are encrypted (HTTPS). Changes to your trips, photos, and places go through server functions that check ownership (the device or the signed-in account). Sign-in sessions are verified server-side on every protected request. Photos are private by default and served only through short-lived signed links.

15. Changes to this policy

If this policy changes, the updated version will be posted on this page with a new revision date. For significant changes we will provide notice within the service.

History: first posted 2026-09-29. Revised 2026-09-29 — Google Analytics is used only if you give both optional consents. This version — adds Google sign-in and account features (effective date shown above).

16. Contact

For privacy questions or requests, contact us at:

Email: [email protected], or the in-app Contact form.