개인정보처리방침
시행일자: 2026-08-10
Keyling(이하 “본 서비스”)는 「개인정보 보호법」 등 관련 법령을 준수하며, 정보주체의 개인정보를 안전하게 보호하기 위해 다음과 같은 처리방침을 두고 있습니다.
1. 처리하는 개인정보의 항목
본 서비스는 다음의 개인정보 항목을 처리합니다.
(1) 회원 가입 및 인증
- 이메일 주소
- 비밀번호 (해시 처리되어 저장됨)
- Supabase 사용자 식별자
(2) 키보드 입력 캡처
- 회원님이 키보드 스트립의 ‘저장’ 버튼을 눌러 저장을 직접 요청한 문장 텍스트. 캡처는 항상 회원님의 명시적인 저장 탭으로만 일어나며, 자동으로 수집되지 않습니다. 저장 대상은 키보드 스트립에 번역이 표시된 현재 입력 중인 문장으로, Keyling 키보드로 직접 입력한 문장뿐 아니라 같은 입력창에 다른 방법(다른 키보드, 음성 입력, 붙여넣기)으로 작성된 문장도 포함될 수 있습니다 (한글 또는 영문이 포함된 문장에 한함). 저장 시에는 키보드 스트립에 표시되어 있던 영어 변환 결과가 해당 문장과 함께 전송됩니다(제5조 참조).
- 안전 입력 필드(
isSecureTextEntry가 true인 비밀번호 등), 이름 필드(전체/접두사/접미사/이름/중간이름/성/별칭), 이메일 필드, 전화번호 필드, URL 필드, 사용자명 필드, 신용카드 번호 필드, 일회용 인증번호 필드, 주소 필드(전체 주소/주소 1행/주소 2행/시/도/우편번호/국가), 조직명 필드, 직책 필드, 일시/항공편 번호/배송 추적 번호 필드 등 27개 콘텐츠 유형 및 숫자 키패드/전화 키패드/소수점 키패드/이름·전화 키패드/이메일 키보드/URL 키보드/숫자 키패드(ASCII) 등 7개 키보드 유형은 캡처 대상에서 제외됩니다. - 추가 안전장치: 3자 이상 연속된 숫자(전화번호·인증번호·카드번호 등)가 포함된 메시지와 비밀번호 형태의 문자열(영문자 뒤에 숫자가 이어지는 공백 없는 토큰)이 포함된 메시지는 일반 입력 필드에서도 캡처하지 않습니다. 또한 한글이 포함된 문장은 50자, 영문 전용 문장은 120자를 초과하면 캡처하지 않습니다.
(3) 학습 데이터
- 캡처된 문장 텍스트로부터 생성된 학습 카드 (원문, 영문 번역, 중점 항목, 연습 문제 등)
- 회원님이 학습 카드의 문장을 보관함에 담은 보관 내역과, 문장을 정리하기 위해 회원님이 직접 만들고 이름을 지은 카테고리 (카테고리 이름 포함)
- 회원님이 학습 카드의 단어를 ‘단어장’에 보관한 내역 (단어, 그 문장에서의 한국어 뜻, 품사, 짧은 설명, 그리고 그 단어가 나온 영어 문장). 이 내용은 보관하시는 시점의 상태가 그대로 복사되어 저장되며, 이후 해당 학습 카드가 변경되어도 함께 바뀌지 않습니다.
(4) 푸시 알림
- APNs(Apple Push Notification service) 기기 토큰
- 푸시 알림 전송 로그 (전송 상태, 시도 시각 등)
(5) 음성 입력 (말하기 연습)
- 사용자가 말하기 연습 단계에서 영어 문장을 소리 내어 말할 때 마이크로 입력되는 음성. 해당 음성은 기기 운영체제의 음성 인식 기능(iOS의 Apple 음성 인식 프레임워크(Speech), Android의 시스템 음성 인식기 — 대개 Google)을 통해 실시간으로 텍스트로 변환됩니다. 기기에 해당 영어(en-US) 온디바이스 인식 모델이 설치되어 있으면 음성은 전적으로 기기 내에서 처리되어 외부로 전송되지 않습니다. 그러나 한국어 환경의 Android 기기에는 영어 온디바이스 인식 모델이 설치되어 있지 않은 경우가 많아, 이러한 기기에서는 인식을 위해 음성이 시스템 음성 인식기 제공자(대개 Google)의 서버로 전송됩니다(제5조의2 참조). 말하기 연습이 진행되는 동안 마이크는 사용자가 중지하거나 문장 인식이 완료될 때까지 연속으로 음성을 수집합니다.
- 변환된 텍스트는 정답 문장과의 발음 비교(채점) 목적으로만 사용되며, 음성과 변환 텍스트 모두 본 서비스의 서버나 데이터베이스에 저장되지 않고 인식 직후 폐기됩니다.
(6) 사용 분석 및 진단 정보
- 익명 사용 분석(PostHog): 서비스 개선을 위해 수집하는 익명 앱 사용 이벤트(화면 조회, 기능 사용 여부, 동작 횟수 등). 개인을 식별하지 않는 임의의 익명 식별자에만 연결되며, 사용자 계정·이메일·캡처된 한글 텍스트·학습 콘텐츠는 일절 포함되지 않습니다.
- 오류 진단(Sentry): 앱의 오류 및 비정상 종료(크래시) 진단 정보(오류 유형, 발생 위치, 기기 모델·OS 버전·앱 버전 등). 개인정보(PII)나 캡처된 텍스트·학습 콘텐츠는 포함되지 않습니다.
(7) 피드백 수집 (웹 폼)
- keyling.app 의 피드백 페이지에서 이용자가 직접 작성한 답변 내용 (서술형 답변 및 선택 항목).
- 혜택 지급 대상을 확인하기 위한 가입 이메일 주소 (선택 입력). Apple 로그인으로 가입하신 경우 전체 주소 대신 앞 4글자만 입력하셔도 됩니다.
- 이 항목은 앱이 아니라 웹 페이지에서, 이용자가 직접 제출 버튼을 눌러 보내신 경우에만 수집되며, 제출 화면에서 수집·이용 동의를 받습니다. 동의를 거부하실 수 있으며 이 경우 혜택을 드릴 수 없습니다.
(8) 구독 정보
- 유료 구독 상태(구독 상품, 구독 시작·갱신·만료 시점) 및 무료 이용 혜택 부여 여부.
- 결제는 App Store를 통해 이루어지며, 신용카드 번호 등 결제수단 정보는 Apple이 직접 처리합니다. 본 서비스는 결제수단 정보를 수집하거나 보관하지 않습니다.
본 서비스는 위 항목 외에 위치 정보, 광고 식별자(IDFA), 연락처, 사진·동영상 등을 수집하지 않으며, 사용자를 교차 앱·교차 사이트로 추적(tracking)하거나 데이터 브로커에 정보를 제공하지 않습니다. 위 (6)항의 사용 분석·진단 정보는 모두 익명으로 처리되어 사용자의 신원에 연결되지 않습니다.
2. 개인정보의 처리 목적
본 서비스는 수집한 개인정보를 다음 목적을 위해 처리하며, 목적 외 용도로는 이용하지 않습니다.
- 계정 인증 및 관리
- 사용자가 자연스럽게 입력한 한국어 또는 영어 텍스트를 분석하여 개인 맞춤형 영어 학습 카드 생성. 회원님이 저장 시 키보드에 표시되던 영어 변환 결과가 함께 전송된 경우, 그 결과를 해당 학습 카드의 영문 번역으로 사용
- 키보드 입력 중 문장의 실시간 영어 변환(작문 보조) 제공
- 생성된 학습 카드와 카드 생성 결과(생성 실패 안내 포함)를 푸시 알림 및 앱 내 덱(deck)을 통해 제공
- 학습 카드 텍스트(영문 번역·중점 항목·예문)를 음성으로 합성하여 사용자가 소리로 들을 수 있도록 제공
- 말하기 연습에서 사용자가 말한 영어 문장을 인식·채점하여 학습 피드백 제공
- 서비스 품질 개선을 위한 익명 사용 분석 및 오류 진단
- 피드백 이벤트 참여자 확인 및 혜택 지급, 제출된 피드백을 통한 서비스 개선
- 유료 구독 상태 및 무료 체험 기간 확인
3. 개인정보의 보유 및 이용 기간
- 캡처된 한글 텍스트 및 생성된 학습 카드: 사용자가 개별 학습 카드를 삭제하거나 계정 전체를 삭제할 때까지 보유
- 문장 보관 내역 및 사용자 생성 카테고리: 사용자가 해당 보관 항목이나 카테고리를 삭제하거나 계정을 삭제할 때까지 보유. 보관된 문장의 학습 카드가 삭제되면 그 문장의 보관 내역도 함께 삭제됩니다.
- 단어장 보관 내역: 사용자가 해당 단어를 단어장에서 빼거나 계정을 삭제할 때까지 보유. 문장 보관 내역과 달리, 그 단어가 나온 학습 카드를 삭제하더라도 단어장에 보관한 단어는 삭제되지 않고 그대로 남습니다. 보관 시점에 복사된 내용이므로 카드가 없어도 뜻과 예문을 계속 읽으실 수 있기 때문이며, 이 단어를 지우시려면 단어장에서 직접 빼주셔야 합니다. 계정을 삭제하시면 단어장 내역도 함께 삭제됩니다.
- 합성 음성(TTS): 학습 카드 텍스트로부터 생성된 음성은 사용자가 아니라 텍스트의 해시값으로 식별되는 공용 캐시로 저장되어, 동일한 텍스트는 어느 사용자에게나 동일한 음성으로 제공됩니다. 이 음성은 특정 계정에 연결되지 않으며, 계정 삭제 시 해당 음성을 사용자와 연결할 수 있는 유일한 정보인 학습 데이터가 삭제되어 캐시된 음성은 익명 상태로 남습니다.
- 계정 정보 (이메일, 비밀번호 해시, 사용자 식별자): 계정 삭제 시까지 보유. 계정 삭제 시 모든 관련 학습 데이터가 데이터베이스의 ON DELETE CASCADE 제약에 따라 즉시 함께 삭제됩니다.
- APNs 기기 토큰: 계정 삭제 시까지 보유하며, 앱 삭제 등으로 토큰이 더 이상 유효하지 않다는 사실이 확인되면 삭제합니다.
- 푸시 알림 전송 진단 로그: 알림 전송의 성공·실패 상태와 오류 코드 등으로 구성된 기술 진단 기록(알림 내용 미포함)으로, 전송 문제 진단에 필요한 기간 동안만 보관합니다.
- 수업 생성 진단 로그: 수업 생성 요청의 성공·건너뜀·실패 상태와 사유 코드, 소요 시간 등으로 구성된 기술 진단 기록으로, 생성 문제 진단에 필요한 기간 동안만 보관합니다. 어떤 문장에 대한 요청인지 앱에서 알려드리기 위해, 요청이 접수되는 시점에 저장하신 문장이 함께 기록됩니다. 이 사본은 학습 카드가 만들어지면 곧바로 삭제하며, 카드가 만들어지지 않은 경우를 포함해 어떤 경우에도 최대 24시간 이내에 자동으로 삭제됩니다(카드가 만들어진 경우 문장은 카드의 일부로 위 첫 번째 항목에 따라 보관됩니다).
- 요청 횟수 카운터: 과도한 요청을 제한하기 위한 단기 카운터로, 분~일 단위의 유효기간이 지나면 자동 삭제됩니다.
- 익명 사용 분석·진단 정보: 각 수탁업체(PostHog, Sentry)의 보관 정책에 따라 보관되며, 사용자 신원에 연결되지 않습니다.
- 피드백 답변 및 가입 이메일 (웹 폼): 혜택 지급 확인을 위해 2026년 11월 3일까지 보관한 뒤 이메일 주소를 파기합니다. 답변 내용은 이메일과 분리한 상태로 서비스 개선 목적으로만 보관합니다. 이 기록은 앱 계정에 연결된 데이터가 아니므로 계정을 삭제하셔도 함께 삭제되지 않습니다. privacy@keyling.app 으로 요청하시면 언제든 개별 삭제해 드립니다.
- 구독 정보: 구독 상태 확인을 위해 보관하며, 회원 탈퇴 시 계정과 함께 즉시 파기됩니다. 다만 App Store 구매 내역 자체는 Apple이 보유하며, 이는 본 서비스의 파기 범위에 포함되지 않습니다.
4. 개인정보의 제3자 제공
본 서비스는 정보주체의 동의 없이는 개인정보를 제3자에게 제공하지 않습니다.
5. 개인정보처리의 위탁
본 서비스는 원활한 서비스 제공을 위해 다음과 같이 개인정보 처리 업무를 외부 사업자에게 위탁하고 있습니다.
| 수탁업체 | 위탁 업무 | 위탁 항목 | 보관 위치 |
|---|---|---|---|
| Vercel Inc. | 학습 카드 생성 API, 실시간 영어 변환 API 및 피드백 웹 폼 호스팅 | 캡처된 문장 텍스트와 저장 시 함께 전송되는 영어 변환 결과, 키보드로 입력 중인 문장(실시간 변환용·익명), 인증 토큰, 피드백 답변 및 가입 이메일 (전송·처리 시점에 한함, Vercel 저장소에 영구 저장되지 않음) | 미국 |
| Google LLC (Gemini API) | 한글 텍스트로부터 영어 학습 카드 생성을 위한 자연어 처리; 학습 카드 텍스트의 음성 합성(TTS); 키보드 입력 문장의 실시간 영어 변환(작문 보조); 이용자 피드백 텍스트의 주제 분류 | 캡처된 한글 텍스트; 음성 합성을 위한 학습 카드 텍스트(영문 번역·중점 항목·예문); 키보드로 입력 중인 문장(실시간 변환 요청 자체는 익명이며 계정에 연결되지 않음); 회원님이 저장을 누른 경우 해당 문장과 함께 전송되어 학습 카드 생성에 사용되는 영어 변환 결과(이 요청은 회원님의 계정으로 인증되며, Google에는 계정 식별자가 전달되지 않습니다); 신원 정보(이메일)를 분리한 피드백 답변 텍스트 | 미국 |
| Supabase Inc. | 인증 및 데이터베이스 호스팅 | 이메일, 비밀번호 해시, 사용자 식별자, 학습 카드, APNs 기기 토큰, 수업 생성 진단 로그(최대 24시간 동안 저장하신 문장 포함), 피드백 답변 및 가입 이메일, 구독 상태 | 미국 |
| Resend, Inc. | 인증 관련 이메일 발송(비밀번호 재설정 인증번호 등 서비스 운영에 필요한 메일) | 이메일 주소, 발송 메일 내용(인증번호) — 발송 목적 범위 내에서만 처리 | 미국 |
| Apple Inc. | 푸시 알림 전송 (APNs) | APNs 기기 토큰, 알림 페이로드(학습 카드 미리보기) | 미국 |
| PostHog, Inc. | 익명 사용 분석 | 익명 앱 사용 이벤트(개인 식별 정보 미포함) | 미국 |
| Functional Software, Inc. (Sentry) | 오류 및 비정상 종료(크래시) 진단 | 오류·크래시 진단 정보(개인 식별 정보 미포함) | 미국 |
| Upstash, Inc. | 요청 횟수 제한(레이트 리미팅) 및 비용 한도 관리 | 단기 요청 카운터(학습 카드 생성·실시간 영어 변환·음성 합성·피드백 제출 요청 횟수). 접속 IP 또는 가명처리된 사용자 식별자를 기준으로 하며, 분~일 단위 유효기간이 지나면 자동 삭제됩니다. | 미국 |
| RevenueCat, Inc. | 구독 결제 상태 관리 및 App Store 구매 영수증 검증 | 사용자 식별자, 구독 상품·구매·갱신·만료 내역, App Store 영수증 정보 (신용카드 등 결제수단 정보는 Apple이 직접 처리하며, 본 서비스와 RevenueCat은 이를 전달받거나 처리하지 않습니다) | 미국 |
수탁업체와의 계약 시 「개인정보 보호법」에 따라 개인정보가 안전하게 처리되도록 필요한 사항을 규정하고 있으며, 위탁 처리 사실은 본 처리방침을 통해 공개합니다.
본 서비스는 Google Gemini API를 유료로 이용하고 있으며, Google의 Gemini API 이용약관에 따라 본 서비스에서 Gemini API로 전송된 데이터는 Google의 머신러닝 모델 학습에 사용되지 않습니다. 다만 말하기 연습의 음성 인식은 위 Gemini API가 아닌 기기 운영체제의 음성 인식 기능을 이용하며, 이는 본 서비스의 처리위탁에 해당하지 않으므로 위 표에 포함되지 않습니다. 자세한 내용은 제5조의2를 참조하시기 바랍니다.
키보드 사용 중 표시되는 실시간 영어 변환(작문 보조) 기능은 위 학습 카드 생성과 달리 다음과 같이 처리됩니다: 회원님이 입력 중인 문장이 계정 정보 없이 익명으로 Google Gemini API(미국)로 전송되어(다른 해석을 요청하는 경우 직전에 표시된 변환 결과가 함께 전송됩니다) 실시간으로 영어로 변환되며, 그 결과가 키보드 위에 표시됩니다. 이 실시간 변환 과정에서 해당 문장은 본 서비스 서버에 저장되지 않고 회원님의 계정·신원과 연결되지 않으며, Google은 이를 머신러닝 학습이나 사람의 검토에 사용하지 않고 오·남용 및 정책 위반 방지 목적으로만 최대 약 55일간 일시 보관한 뒤 삭제합니다. 이 기능은 Keyling 키보드의 ‘전체 접근 허용’이 켜져 있을 때만 동작합니다. 회원님이 ‘저장’ 버튼을 눌러 직접 보관한 문장만 회원님의 계정에 연결되며, 이때 키보드 위에 표시되던 영어 변환 결과가 해당 문장과 일치하는 경우에 한해 그 문장과 함께 전송됩니다. 전송된 변환 결과는 학습 카드 생성을 위한 분석 과정에서 Google Gemini API(미국)로 다시 전달되며, 통상 그대로 학습 카드의 영문 번역으로 사용됩니다(일치하지 않는 경우에는 전송되지 않고, 서버가 해당 문장을 직접 번역합니다). 이는 저장 시 새로 번역하는 대신 회원님이 이미 화면에서 보신 문장을 그대로 사용하기 위한 것입니다. 저장하지 않은 문장과 그 변환 결과는 본 서비스의 서버나 데이터베이스에 보관되지 않으며 회원님의 계정·신원과 연결되지 않습니다(위에 안내드린 Google의 오·남용 방지 목적 일시 보관은 제외).
위 실시간 영어 변환과 학습 카드 생성은 모두 키보드의 ‘학습 모드’가 켜져 있을 때만 이루어집니다. 회원님은 키보드의 학습 모드 버튼을 눌러 언제든지 학습 모드를 끌 수 있으며, 학습 모드가 꺼져 있는 동안에는 실시간 영어 변환과 학습 카드 생성이 모두 중단되어 입력하신 어떠한 문장도 기기 밖으로 전송되지 않습니다.
5-2. 기기 운영체제 음성 인식 서비스에 관한 안내
말하기 연습의 음성 인식은 본 서비스가 처리를 위탁한 것이 아니라, 이용자 기기 운영체제에 내장된 음성 인식 기능(iOS: Apple의 음성 인식 프레임워크(Speech), Android: 기기에 기본으로 설정된 시스템 음성 인식 서비스 — 대개 Google)을 이용합니다.
- 기기가 영어(en-US) 온디바이스 인식을 지원하거나(iOS) 영어(en-US) 온디바이스 인식 모델이 설치되어 있는 경우(Android), 음성은 기기 내에서만 처리되며 외부로 전송되지 않습니다.
- 그렇지 않은 경우 음성은 해당 운영체제·음성 인식 서비스 제공자의 서버(미국 등 국외 소재)로 전송되어 텍스트로 변환됩니다. 이때 해당 제공자(iOS: Apple, Android: 대개 Google)는 본 서비스의 수탁자가 아니라 독립적인 개인정보처리자로서 자신의 개인정보처리방침에 따라 음성을 처리합니다. (Apple: apple.com/kr/legal/privacy, Google: policies.google.com/privacy)
- 본 서비스는 이 과정에서 음성 원본을 수신하거나 저장하지 않으며, 변환된 텍스트도 채점 직후 폐기합니다(제1조 제(5)항 참조).
- Android 이용자는 기기 설정에서 영어(en-US) 온디바이스 인식 모델을 설치하여 음성이 기기 밖으로 전송되지 않도록 하거나(예: 설정 → 시스템 → 언어 및 입력 → 음성 인식; 경로는 기기 제조사에 따라 다를 수 있음), 기기의 기본 음성 인식 서비스를 다른 제공자로 변경할 수 있습니다.
6. 개인정보의 국외 이전
본 서비스의 수탁업체는 모두 미국에 소재하므로 개인정보가 미국으로 이전됩니다.
- 이전되는 항목: 위 제5조 표 참조
- 이전 국가: 미국
- 이전 일시 및 방법: 사용자가 키보드로 문장을 입력하는 중(실시간 영어 변환), 문장을 저장하는 시점(해당 문장 및 함께 전송되는 영어 변환 결과), 또는 계정 활동 시점에 HTTPS를 통해 실시간으로 이전됨
- 수탁업체 정보: 위 제5조 표 참조
- 이용 목적 및 보유 기간: 본 처리방침 제2조 및 제3조 참조(실시간 영어 변환에 관하여는 제5조의 설명을 함께 참조)
- 이전 거부 방법: 관련 기능(키보드 캡처, 실시간 영어 변환, 말하기 연습 등)의 사용 중지 — 실시간 영어 변환은 키보드의 학습 모드를 끄면 즉시 중단됩니다 — 계정 삭제 또는 개인정보 보호책임자(제9조) 문의를 통해 국외 이전을 거부할 수 있습니다. 다만 이 경우 해당 기능의 이용이 제한될 수 있습니다.
아울러 말하기 연습에서 기기 운영체제의 음성 인식을 이용하는 경우, 음성이 기기에서 해당 음성 인식 서비스 제공자(iOS: Apple, Android: 대개 Google)의 국외(미국 등) 서버로 직접 전송될 수 있습니다. 이는 본 서비스의 위탁에 따른 이전이 아니라 기기 운영체제 기능에 의한 전송이며, 자세한 내용은 제5조의2를 참조하시기 바랍니다.
7. 정보주체와 법정대리인의 권리·의무 및 행사방법
정보주체는 언제든지 다음의 권리를 행사할 수 있습니다.
- 개인정보 열람: 앱 내 덱(deck) 화면에서 본인의 학습 카드 전체 열람
- 개별 학습 카드 삭제: 덱 화면에서 카드를 길게 눌러 삭제
- 계정 및 전체 데이터 삭제: 앱 내 “계정” → “계정 삭제” 메뉴
- 처리 정지: 로그아웃 또는 계정 삭제
- 알림 권한 철회: iOS 설정 → 알림 → Keyling
- 마이크·음성 인식 권한 철회: iOS 설정 → Keyling → 마이크 / 음성 인식; Android 설정 → 애플리케이션 → Keyling → 권한 → 마이크
- 키보드 처리 일시정지 (학습 모드): 키보드의 학습 모드 버튼을 눌러 끄면, 실시간 영어 변환과 학습 카드 생성이 중단되고 입력 문장이 기기 밖으로 전송되지 않습니다
- 키보드 접근 권한 철회: iOS 설정 → 일반 → 키보드 → 키보드 → Keyling → “전체 접근 허용” 해제
위 권리 행사 시 즉시 효력이 발생하며, 별도의 처리 기간을 두지 않습니다. 계정 삭제 시 관련 학습 데이터는 Supabase 데이터베이스의 ON DELETE CASCADE 제약에 따라 즉시 함께 삭제됩니다.
8. 개인정보의 안전성 확보 조치
본 서비스는 「개인정보 보호법」 제29조에 따라 다음의 안전성 확보 조치를 실시하고 있습니다.
(1) 기술적 조치
- 전송 구간 암호화: HTTPS (TLS) 적용
- 비밀번호 암호화: Supabase의 표준 해시 알고리즘 적용
- 인증 토큰 보호: iOS Keychain Services에 저장 (사용 가능한 경우 하드웨어 보안 모듈 활용)
- 접근 제어: Supabase의 행 수준 보안(Row-Level Security)을 통해 정보주체가 본인의 데이터에만 접근 가능하도록 제한
(2) 관리적 조치
- 캡처 최소화: 키보드 단계에서 숫자·기호 레이어 입력, 안전 입력 필드 입력, 34개 캡처 제외 대상 필드 유형의 입력, 긴 연속 숫자 또는 비밀번호 형태 문자열이 포함된 입력은 서버로 전송되지 않도록 구조적으로 차단
- 최소 수집 원칙: 위치 정보, 광고 식별자(IDFA), 연락처, 사진 등은 수집하지 않으며, 서비스 개선을 위한 사용 분석·진단 정보는 익명으로만 최소한으로 수집함
9. 개인정보 보호책임자
본 서비스는 정보주체의 개인정보를 보호하고 개인정보와 관련된 불만을 처리하기 위해 다음과 같이 개인정보 보호책임자를 지정합니다.
- 성명: 길윤재 (Yoonjae Kil)
- 연락처: privacy@keyling.app
정보주체는 본 서비스를 이용하면서 발생한 모든 개인정보 보호 관련 문의, 불만 처리, 피해 구제 등에 관한 사항을 위 연락처로 문의하실 수 있으며, 본 서비스는 정보주체의 문의에 대해 지체 없이 답변 및 처리해 드리겠습니다.
10. 만 14세 미만 아동의 개인정보
본 서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 만 14세 미만 아동의 개인정보를 의도적으로 수집하지 않습니다. 만 14세 미만 아동이 본 서비스를 이용한 것이 확인되는 경우, 해당 계정 및 관련 데이터를 즉시 삭제합니다.
11. 개인정보처리방침의 변경
본 처리방침은 법령, 정책 또는 서비스 변경에 따라 개정될 수 있으며, 개정 시 변경 사항을 앱 내 공지 또는 이메일을 통해 사전에 안내합니다. 본 처리방침의 시행일은 상단에 명시되어 있습니다.
12. 권익침해 구제방법
정보주체는 개인정보 침해에 대한 신고 및 상담을 위해 아래 기관에 문의하실 수 있습니다.
- 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
- 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
- 대검찰청 사이버수사과: (국번없이) 1301 (www.spo.go.kr)
- 경찰청 사이버수사국: (국번없이) 182 (cyberbureau.police.go.kr)
Privacy Policy
Effective date: 2026-08-10
Keyling (the “Service”) complies with the Personal Information Protection Act (“PIPA”) of the Republic of Korea and other applicable laws. This Privacy Policy describes how the Service processes its users’ personal information.
1. Categories of personal information processed
The Service processes the following categories of personal information:
(1) Account registration and authentication
- Email address
- Password (stored as a hash)
- Supabase user identifier
(2) Keyboard input capture
- The sentence you explicitly ask to save by tapping the keyboard strip’s ‘저장’ (Save) button. Capture only ever happens on that explicit tap — never automatically. The saved sentence is the one whose translation is currently displayed on the keyboard strip: text typed with the Keyling keyboard, and text entered into the same field by other means (another keyboard, dictation, or paste), may both be saved, provided the sentence contains Korean or English letters. When you save, the English rendering that was displayed on the keyboard strip is transmitted together with the sentence (see Section 5).
- The Service silently excludes capture from 34 field types via UIKit content-type and keyboard-type checks: all name variants (full/prefix/suffix/given/middle/family/nickname), email, phone, URL, username, password, newPassword, credit card, one-time code, all address components, organization, job title, dateTime, flight number, shipment tracking, plus phonePad / numberPad / decimalPad / namePhonePad / emailAddress / URL / asciiCapableNumberPad keyboard types.
- Text typed in secure fields (where
isSecureTextEntryis true) is filtered in two independent layers and is never transmitted. - Additional safeguards: any message containing a run of 3 or more consecutive digits (phone numbers, verification codes, card numbers) or a password-shaped token (a whitespace-free token in which a Latin letter is followed by a digit) is not captured — even in a normal text field. Sentences longer than 50 characters (when they contain Hangul) or 120 characters (Latin-only) are not captured either.
(3) Generated learning data
- Lesson cards derived from captured text, including the original source sentence, English translation, focus item, and exercise content.
- Your saved-sentence bookmarks, and the categories you create and name yourself to organize saved sentences (including the category names).
- The words you keep in your word list (“단어장”) — the word, its Korean meaning in that sentence, its part of speech, a short note, and the English sentence it came from. These are stored as a copy taken at the moment you save, and do not change afterwards even if the lesson card itself changes.
(4) Push notifications
- Apple Push Notification service (APNs) device token
- Notification delivery logs (delivery status, attempt timestamps)
(5) Speech input (speaking exercise)
- Microphone audio captured while the user speaks an English sentence aloud during the speaking exercise. The audio is transcribed to text in real time by the device operating system’s speech recognition (Apple’s Speech framework on iOS; the device’s system speech recognizer — typically Google — on Android). When the relevant English (en-US) on-device recognition model is installed on the device, the audio is processed entirely on the device and is not transmitted. However, Korean-locale Android devices often do not have the English on-device model installed, and on such devices the audio is sent to the speech recognizer provider’s servers (typically Google) for recognition (see Section 5-2). While the speaking exercise is active, the microphone captures audio continuously until the user stops it or the sentence is recognized.
- The resulting transcript is used only to phonetically compare the spoken answer against the expected sentence (scoring); neither the audio nor the transcript is stored on the Service’s servers or database, and both are discarded immediately after recognition.
(6) Usage analytics and diagnostics
- Anonymous usage analytics (PostHog): anonymous app-usage events collected to improve the Service (screens viewed, whether a feature was used, action counts). Tied only to a randomly generated anonymous identifier that does not identify the user; it never includes the user’s account, email, captured Korean text, or learning content.
- Crash diagnostics (Sentry): error and crash diagnostics (error type, where it occurred, device model, OS version, app version). It contains no personal information (PII) and no captured text or learning content.
(7) Feedback collection (web form)
- The answers a user writes on the feedback page at keyling.app (free-text responses and multiple-choice selections).
- The signup email address (optional), used to identify who qualifies for the offer. Users who signed up with Apple may enter only the first four characters instead of the full address.
- These items are collected on a web page rather than in the app, and only when the user presses submit themselves. Consent is obtained on the submission screen; users may decline, in which case the offer cannot be granted.
(8) Subscription information
- Paid subscription state (subscription product; start, renewal, and expiration times) and whether complimentary access has been granted.
- Payment is processed through the App Store. Payment-method details such as card numbers are handled by Apple; the Service never collects or stores them.
Beyond the items listed above, the Service does not collect location data, advertising identifiers (IDFA), contacts, or photos/videos, and does not track users across apps or websites or share data with data brokers. The usage analytics and diagnostics in (6) above are processed anonymously and are not linked to the user’s identity.
2. Purpose of processing
The Service processes collected personal information for the following purposes only, and does not use personal information for any other purpose:
- Account authentication and management
- Generating personalized English-learning content from Korean or English text the user has naturally typed. When you save a sentence and the English rendering displayed on the keyboard is sent with it, that rendering is used as the lesson card’s English translation
- Rendering the sentence you are typing into English in real time and displaying it above the keys (writing assistance)
- Delivering generated learning content, and the outcome of a generation request (including notice that it could not be saved), via push notifications and the in-app deck
- Synthesizing lesson text (the English translation, focus item, and example sentences) into audio so the user can hear it read aloud
- Recognizing and scoring the user’s spoken English in the speaking exercise to provide learning feedback
- Anonymous usage analytics and crash diagnostics to improve the quality of the Service
- Identifying participants in the feedback campaign and granting the offer, and improving the Service based on the feedback submitted
- Determining paid subscription status and free-trial eligibility
3. Retention and use period
- Captured Korean text and generated learning cards: retained until the user deletes the individual card or deletes their account.
- Saved-sentence bookmarks and user-created categories: retained until you delete the bookmark or category, or delete your account. When a saved sentence’s lesson card is deleted, its bookmark entries are deleted with it.
- Words kept in your word list (단어장): retained until you remove the word from the list or delete your account. Unlike saved-sentence bookmarks, deleting the lesson card a word came from does NOT delete the kept word. Because it is a copy taken at save time, it stays readable — meaning and example sentence included — without the card; to remove it, take it out of your word list. Deleting your account deletes your word list with it.
- Synthesized audio (text-to-speech): audio generated from lesson text is stored as a shared cache, identified by a hash of the text rather than by user, so that identical text yields the same audio for any user. It is not linked to an account; on account deletion, the lesson data — the only information that could associate any audio with the user — is removed, leaving the cached audio anonymous.
- Account information (email, password hash, user identifier): retained until account deletion. When the account is deleted, all related learning data is immediately deleted from the database via the ON DELETE CASCADE constraint.
- APNs device token: retained until the account is deleted; also removed once the token is found to be no longer valid (for example, after the app is uninstalled).
- Push-delivery diagnostic logs: technical delivery records (success/failure status and error codes; no notification content), retained only as long as needed to diagnose delivery problems.
- Lesson-generation diagnostic logs: technical records of each generation request (success/skip/failure status, reason codes, processing time, and similar technical attributes), retained only as long as needed to diagnose generation problems. So the app can tell you which message a request was about, the sentence you saved is stored alongside the record when the request starts. That copy is deleted as soon as a learning card is created, and in every case — including when no card is created — it is deleted automatically within 24 hours (when a card is created, the sentence itself is then retained as part of the card, under the first item of this section).
- Request-rate counters: short-lived counters used to limit excessive requests; they expire automatically within minutes to a day.
- Anonymous usage analytics and diagnostics: retained per the retention policies of the respective processors (PostHog, Sentry); not linked to the user’s identity.
- Feedback answers and signup email (web form): retained until 3 November 2026 to verify eligibility for the offer, after which the email address is destroyed. The answers are kept separately from the email address and used only to improve the Service. These records are not linked to an app account, so they are not deleted when an account is deleted; write to privacy@keyling.app at any time and they will be deleted individually.
- Subscription information: retained to determine subscription status, and destroyed together with the account immediately upon account deletion. The App Store purchase record itself is held by Apple and is outside the scope of our deletion.
4. Provision to third parties
The Service does not provide personal information to third parties without the user’s consent.
5. Entrustment of processing
The Service entrusts the following processors with limited data processing tasks:
| Processor | Task | Data items | Location |
|---|---|---|---|
| Vercel Inc. | Hosts the lesson-generation API, the real-time English rendering API, and the feedback web form | Captured sentence text and the English rendering sent with it on save, the sentence being typed on the keyboard (for real-time rendering; anonymous), authentication token, and feedback answers and signup email (in transit and during processing only; not permanently stored on Vercel) | USA |
| Google LLC (Gemini API) | Natural-language processing to generate English lessons from Korean text; text-to-speech synthesis of lesson text into audio; real-time English rendering of text typed on the keyboard (writing assistance); thematic classification of user feedback text | Captured Korean text; lesson text (English translation, focus item, and example sentences) for audio synthesis; the sentence being typed on the keyboard (the real-time rendering request itself is anonymous and not linked to an account); where you tap Save, the English rendering sent with that sentence and used to generate the lesson card (that request is authenticated as your account, though no account identifier is passed to Google); feedback answer text with identifying information (email) separated out | USA |
| Supabase Inc. | Authentication and database hosting | Email, password hash, user identifier, lesson cards, APNs device token, lesson-generation diagnostic logs (including the sentence you saved, for up to 24 hours), feedback answers and signup email, subscription status | USA |
| Resend, Inc. | Delivery of authentication-related email (such as password-reset verification codes) | Email address and the message content (verification code), processed only to deliver the email | USA |
| Apple Inc. | Push notification delivery (APNs) | APNs device token, notification payload (lesson preview) | USA |
| PostHog, Inc. | Anonymous usage analytics | Anonymous app-usage events (no personally identifying information) | USA |
| Functional Software, Inc. (Sentry) | Error and crash diagnostics | Error/crash diagnostics (no personally identifying information) | USA |
| Upstash, Inc. | Request rate limiting and spend-cap enforcement | Short-lived request counters (lesson-generation, real-time English rendering, audio-synthesis, and feedback-submission request counts), keyed by client IP address or a pseudonymous user identifier; they expire automatically within minutes to a day | USA |
| RevenueCat, Inc. | Subscription state management and App Store purchase receipt validation | User identifier; subscription product, purchase, renewal, and expiration records; App Store receipt data (payment-method details such as card numbers are handled by Apple and are never received or processed by the Service or RevenueCat) | USA |
Contracts with these processors include the data protection requirements mandated by PIPA, and entrustment is disclosed through this Privacy Policy.
The Service uses a paid Google Gemini API account. Per Google’s Gemini API terms, data transmitted by the Service to the Gemini API is not used to train Google’s machine learning models. Speech recognition in the speaking exercise, however, uses the device operating system’s speech recognition rather than the Gemini API above; it is not an entrustment of processing by the Service and is therefore not listed in the table above. See Section 5-2 for details.
The real-time English rendering (writing assistance) shown while you use the keyboard is handled differently from the lesson generation above: the sentence you are typing is sent — anonymously, with no account information, and together with the rendering you rejected when you ask for other readings — to the Google Gemini API (USA) and rendered into English in real time, and the result is shown above the keys. During this real-time rendering the sentence is not stored on the Service’s servers and is not linked to your account or identity; Google does not use it to train machine-learning models or for human review, and retains it only briefly — up to approximately 55 days — solely to prevent abuse and policy violations, after which it is deleted. This feature operates only when ‘Allow Full Access’ is enabled for the Keyling keyboard. Only sentences you explicitly keep with the ‘Save’ button are linked to your account; when you do, the English rendering shown above the keys is sent together with that sentence — but only when it matches the sentence being saved. A rendering sent this way is passed to the Google Gemini API (USA) again as part of the analysis that builds the lesson, and is normally used as-is for the lesson card’s English translation. When it does not match it is not sent, and the Service translates the sentence itself. The point is to reuse the sentence you already read rather than translate it a second time. Sentences you do not save, and their renderings, are not stored on the Service’s servers or databases and are not linked to your account or identity (apart from Google’s temporary abuse-prevention retention described above).
Both the real-time English rendering and the lesson-card generation described above occur only while the keyboard’s ‘Learning Mode’ is on. You can turn Learning Mode off at any time using the button on the keyboard; while it is off, both real-time rendering and lesson-card generation stop, and no sentence you type is transmitted off your device.
5-2. Device operating-system speech recognition (notice)
Speech recognition in the speaking exercise is not processing entrusted by the Service to a processor. It uses the speech recognition built into the device’s operating system (Apple’s Speech framework on iOS; on Android, the system speech recognition service set as the default on the device — typically Google’s).
- When the device supports English (en-US) on-device recognition (iOS) or has the English (en-US) on-device recognition model installed (Android), the audio is processed entirely on the device and is not transmitted.
- Otherwise, the audio is transmitted to the servers of the operating system’s speech recognition provider (located outside Korea, e.g. in the United States) for transcription. That provider (Apple on iOS; typically Google on Android) is not a processor engaged by the Service; it processes the audio independently, as a separate controller, under its own privacy policy. (Apple: apple.com/legal/privacy, Google: policies.google.com/privacy)
- The Service never receives or stores the raw audio, and the transcript is discarded immediately after scoring (see Section 1(5)).
- On Android, you can install the English (en-US) on-device model so that audio never leaves your device (e.g., Settings → System → Languages & input → Speech recognition; the exact path varies by manufacturer), or change the device’s default speech recognition service to a different provider.
6. Cross-border transfer of personal information
All processors used by the Service are located in the United States, which results in cross-border transfer of personal information.
- Items transferred: see Section 5
- Country: United States
- Time and method of transfer: in real time via HTTPS while the user is typing a sentence (real-time English rendering), at the moment the user saves a sentence (that sentence and the English rendering sent with it), or during account activity
- Processor information: see Section 5
- Purpose and retention period: see Sections 2 and 3 (for the real-time English rendering, see also Section 5)
- How to refuse the transfer: you may refuse cross-border transfer by not using the relevant features (keyboard capture, real-time English rendering, the speaking exercise) — turning off the keyboard’s Learning Mode stops the real-time rendering immediately — by deleting your account, or by contacting the privacy officer (Section 9). Doing so may limit your use of the relevant features.
In addition, when the speaking exercise uses the device operating system’s speech recognition, audio may be transmitted directly from the device to the overseas servers (e.g. in the United States) of the operating system’s speech recognition provider (Apple on iOS; typically Google on Android). This is a transmission performed by the device operating system, not a transfer under an entrustment by the Service; see Section 5-2 for details.
7. User rights and how to exercise them
You may exercise the following rights at any time:
- Access your data: view all your lesson cards in the in-app deck
- Delete individual lesson cards: long-press a card in the deck
- Delete your account and all associated data: in-app menu Account → Delete Account
- Stop processing: sign out or delete your account
- Revoke notification permission: iOS Settings → Notifications → Keyling
- Revoke microphone / speech-recognition permission: iOS Settings → Keyling → Microphone / Speech Recognition; Android Settings → Apps → Keyling → Permissions → Microphone
- Pause keyboard processing (Learning Mode): turn off the Learning Mode button on the keyboard; while off, real-time English rendering and lesson-card generation stop and no sentence you type is transmitted off your device
- Revoke keyboard Full Access: iOS Settings → General → Keyboard → Keyboards → Keyling → toggle off “Allow Full Access”
These actions take effect immediately with no processing delay. Account deletion cascades through the Supabase database via the ON DELETE CASCADE constraint, immediately deleting all related learning data.
8. Security measures
In accordance with Article 29 of PIPA, the Service implements the following security measures:
(1) Technical measures
- Encryption in transit: HTTPS (TLS) throughout
- Password encryption: standard hash algorithm via Supabase
- Authentication token protection: stored in iOS Keychain Services (with hardware security module where available)
- Access control: Supabase Row-Level Security ensures users can only access their own data
(2) Administrative measures
- Capture minimization: at the keyboard layer, input on the number and symbol layers, input in secure fields, input in 34 non-target field types, and input containing long digit runs or password-shaped tokens is structurally blocked from being transmitted
- Data minimization: the Service does not collect location, advertising identifiers, contacts, or photos; usage analytics and diagnostics collected to improve the Service are limited to anonymous data only.
9. Privacy Officer
The Service designates the following privacy officer to protect users’ personal information and to handle related inquiries and complaints:
- Name: Yoonjae Kil (길윤재)
- Contact: privacy@keyling.app
Users may contact the privacy officer at the address above for any inquiries, complaints, or remedies related to personal information arising from use of the Service. The Service will respond to all such inquiries without undue delay.
10. Children under 14
The Service is not intended for children under 14 and does not intentionally collect personal information from children under 14. If it is discovered that a child under 14 has used the Service, the account and all related data will be deleted immediately.
11. Changes to this Privacy Policy
This Privacy Policy may change due to changes in law, Service policies, or Service features. When changes are made, the Service will notify users in advance through in-app announcements or email. The effective date of this Privacy Policy is shown at the top of this document.
12. Remedies for rights infringement
For reports and consultation regarding personal information infringement, you may contact the following Korean agencies:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Reporting Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office Cyber Investigation Division: 1301 (www.spo.go.kr)
- National Police Agency Cyber Investigation Bureau: 182 (cyberbureau.police.go.kr)