Romantic Rider Privacy Policy
This is an English translation provided for convenience. In case of any discrepancy, the Korean version prevails.
Romantic Rider (the "Operator") values the privacy of users of the apps it distributes — Spacetime Diary (nationwide edition) and Namhae: Spacetime Diary (Namhae edition) (together, the "Service") — and complies with the Personal Information Protection Act, the Act on the Protection and Use of Location Information, and other applicable Korean laws. This Policy applies commonly to both apps; items that differ by app are marked with an applicable app badge in each section and listed in Appendix A.
At a glance
- The Service can be used without signing in. Photos, locations, memos and other records you create are stored only on your device by default.
- You sign in with a Google or Kakao account only if you want to use photo sharing. In that case minimal account information such as your email address and nickname is stored on the Operator's server. (Currently offered in the Namhae edition — see Appendix A.)
- Only photos you explicitly choose to publish are uploaded to the Operator's server and shown to other users. Metadata (EXIF), including location, is stripped from uploaded photos.
- Coordinates are transmitted temporarily to external APIs or the Operator's server to display addresses and look up tourism information, but the Operator does not store the coordinates used for these lookups.
- When the app crashes, a crash log with device and app information is sent to Google (Firebase Crashlytics). Photos, locations and memos are not included.
- Spacetime Diary (nationwide edition) displays banner ads, and the advertising identifier (Ad ID) is sent to Google (AdMob) to serve them. Namhae: Spacetime Diary has no ads and does not collect the Ad ID.
- To deliver news about new features, a per-device notification token is sent to Google (Firebase). Notifications appear only if you allow them, and you can turn them off at any time in device settings.
- We do not use analytics or tracking tools that profile user behavior.
1. Information processed and purposes
The core features of the Service (capture, map diary, tourism information) process the information below only on your device, and the Operator does not collect it. Only if you choose to do so are account information and shared photos stored on the Operator's server (Sections 1-3 and 1-4); crash logs for error diagnosis (Section 1-1) and advertising-related information (Section 1-5, nationwide edition only) are sent to Google.
| Information | Purpose | Storage location · period |
|---|---|---|
| Camera image (captured photo) | Taking photos and compositing the timestamp/location overlay | On device · until you delete it |
| Location information (GPS coordinates) | Recording coordinates at capture time, showing photos on the map, address conversion, nearby tourism lookups, landmark visit confirmation (commemorative stamps — Namhae edition) | On device · until you delete it |
| Photo library (gallery) access | Importing existing photos that contain location information into the map diary (only when you run it) | On device · until you delete it |
| Account information (if you sign in for photo sharing) email address, nickname, profile image (optional), user identifier from the social login provider |
Providing photo sharing (verifying your right to manage and delete your own photos), preventing abuse, responding to inquiries | Operator's server (Supabase, Seoul region, Republic of Korea) · until account deletion |
| Shared photos and accompanying information (only photos you mark as "public") image with metadata (EXIF) removed, capture time, linked landmark, the nickname displayed |
Providing the per-place shared album (making photos viewable by other users) | Operator's server (images = Cloudflare R2, records = Supabase) · until you delete it or it is pushed out of the per-place limit (50 photos per place, newest first) |
| Report and block records (if you use those features) | Reviewing and acting on inappropriate content; hiding photos from a poster you do not want to see | Operator's server (Supabase) · destroyed upon account deletion or after handling, per internal standards |
| Crash logs and device/app information (on abnormal termination) |
Diagnosing the cause of crashes and improving app stability | Google (Firebase Crashlytics) servers · 90 days |
| Advertising identifier (Ad ID) and ad request information (nationwide edition only) | Serving banner ads, frequency capping, invalid-click prevention | Google (AdMob) servers · per Google's advertising data policy |
| Notification token (Firebase registration token) | Delivering push notifications about new features and service news | Google (Firebase Cloud Messaging) servers · until the app is uninstalled |
Each permission (camera, location, photos, notifications) is enabled with your consent when the relevant feature is first used, and can be withdrawn at any time in device settings. If you decline a permission, you can still use the rest of the Service.
In the Namhae edition, the determination and recording of the commemorative "treasure" stamps shown when you take a photo at a landmark happen entirely on your device. Which landmarks you visited is never transmitted externally.
1-1. Details on crash logs
The Operator uses Google's Firebase Crashlytics to diagnose app errors. When the app terminates abnormally, the following information is collected automatically and sent to Google.
- Stack trace at the point of failure, error type and time of occurrence
- Device information: model name, CPU architecture, RAM and storage capacity, operating system name and version
- App information: package name (app identifier), app version
- Device and installation identifiers: Crashlytics installation UUID, Firebase installation ID, app run session identifier (values used to avoid counting the same error twice)
Photos, location information (GPS coordinates), memos and other data you create are not included in crash logs. Nor do we collect information that directly identifies you, such as your name, contact details or email address. Crash logs do not contain the advertising identifier.
Crash log collection happens automatically while the app runs, for stability purposes, and the app currently provides no separate opt-out setting. If you do not want it, uninstalling the app stops further transmission; logs already sent are deleted after the period stated in Section 4.
1-2. Details on push notifications
The Operator sends push notifications about new features and service news through Google's Firebase Cloud Messaging. For this purpose a notification token (registration token) is issued per device when the app is installed and sent to Google.
- The notification token points to "this app on this device." It is not linked to information identifying you, such as your name, contact details or email address, and becomes invalid if you uninstall the app or reset the device.
- Only if you consent to receiving notifications does the app subscribe to a single topic for that app. The Operator sends only at the topic level and never targets an individual user. If you withdraw consent, the subscription is removed and you are excluded from delivery.
- Whether you consented, and when, is stored only on your device and never transmitted externally.
- Photos, location information and memos have nothing to do with notifications. Notification content is written by the Operator as an announcement and is not personalized based on your data.
- Displaying notifications requires the notification permission (Android 13 and later). If you do not allow it, all other app features remain available, and you can change your choice at any time in device settings (see Section 5).
The Operator does not send advertising or promotional messages through this channel — only service news and update notices. If promotional messages are ever sent, separate prior consent will be obtained as required by the Act on Promotion of Information and Communications Network Utilization and Information Protection.
1-3. Details on accounts (social login) currently Namhae edition
Using photo sharing requires signing in with a Google or Kakao account. Signing in is optional; without an account you can still use every other feature, including viewing and reporting shared photos.
- What we receive: from the social login provider (Google LLC or Kakao Corp.) we receive your email address, nickname, profile image (if you consented to provide it), and the provider's user identifier. We never receive or store your password. Note that the nickname displayed on shared photos is separate: you choose it yourself in the app (and if you do not, the Service generates one) — your social account nickname is not made public.
- Purpose: granting you the ability to view, manage and delete "photos I uploaded"; preventing abuse such as exceeding upload limits; handling reports and blocks; responding to inquiries.
- Storage location: the Operator's server (Supabase, Seoul region, Republic of Korea). Retained until account deletion.
- Account deletion: you can delete your account at any time from Settings → Account → Delete account in the app. Deletion removes your account information together with the photos you shared from that account. If you cannot access the app, see the Account Deletion Guide.
- For Kakao accounts, an email address may not be provided depending on your Kakao settings. Sign-in and photo sharing still work in that case.
1-4. Details on photo sharing currently Namhae edition
Photo sharing applies only to photos you explicitly mark as "public" right after capture. Photos you do not select never leave your device under any circumstances.
- What is uploaded: the image with metadata (EXIF) removed, including location coordinates; the capture time; the landmark (place) you linked it to; and the displayed nickname described below. The GPS coordinates in the original file are not uploaded; which landmark a photo belongs to is expressed solely by the place link you chose.
- Who can see it: a shared photo can be viewed in that landmark's album by all users of the Service, including users who are not signed in.
- The nickname that is made public: a shared photo is displayed together with the nickname you choose. If you have not chosen one, a nickname generated automatically by the Service (for example, "붕장어338") is displayed. You can change it at any time in Settings → Profile; after you change it, the new nickname is also shown on photos you shared earlier. Your email address, profile image and account identifier are not made public. The block list shows the nickname as it was at the time of blocking.
- Retention: up to the 50 most recent photos are kept per place; as new photos arrive, the oldest are pushed off the list and deleted. You can delete your own photos at any time.
- Reports and action: anyone (even without signing in) can report an inappropriate photo. The Operator reviews reported photos and may hide or delete them; a reported photo may be retained for review for a limited period (up to 30 days).
- Blocking: signed-in users can block a specific poster so that their photos are hidden. Block relationships are stored on the server solely to provide the blocking feature.
1-5. Details on advertising and the advertising identifier nationwide edition only
To cover operating costs, the Operator displays a banner ad at the bottom of the diary list screen in Spacetime Diary (nationwide edition). Ads are served through Google's AdMob (Google LLC), and the following information is sent from your device to Google when an ad is requested and displayed. Namhae: Spacetime Diary contains no ads, and this section does not apply to it.
- Advertising identifier (Android Advertising ID, AAID) — a resettable, per-device identifier
- Device and app information: device model, OS version, app identifier and version, screen size, language and country settings
- IP address and the approximate location inferred from it (city level)
- Records of interaction with ads, such as impressions and clicks
For this purpose the nationwide edition includes the advertising ID permission (com.google.android.gms.permission.AD_ID).
Photos, precise GPS coordinates, memos and other data you create in the app are not included in ad requests. The Operator does not use the location information recorded by the app for advertising purposes and does not pass it to the ad provider. What the Operator receives from Google is aggregated statistics such as impressions and clicks — never information that identifies an individual user.
Google's processing of data for advertising purposes follows How Google uses information from sites or apps that use our services and the Google advertising policies. You can reset or delete the Ad ID and opt out of personalized ads in your device settings (see Section 5).
2. Transmission to external APIs and the Operator's server
When you use the features below, the information needed to provide the feature is sent from your device to each recipient. Transmitted information is used only to generate the response for that feature.
| Recipient | Feature | Items transmitted |
|---|---|---|
| NAVER Cloud Corp. — NAVER Maps API (both apps) | Displaying the map; converting coordinates to an address (reverse geocoding) | Map viewport and photo capture coordinates |
| Korea Tourism Organization — TourAPI (nationwide edition) | Looking up tourist attractions near your current location | Current location coordinates |
| Operator's server (Supabase) (Namhae edition) | Looking up Namhae tourism information such as attractions, Baraegil trails and festivals | Current location coordinates or map viewport — used only to generate the response; not stored |
| Nangman Namhae (Namhae County tourism platform) (Namhae edition) | Checking whether an attraction, restaurant or lodging is listed on Nangman Namhae and linking to its detail page | Place name (search term) only — no personal or location information is transmitted |
When you open an external web page inside the app — Nangman Namhae, Namhae Cultural Center, the Namhae Baraegil guide and the like — connection information such as your IP address is passed to that site, as with ordinary web browsing. Each recipient's handling of personal information follows that organization's or site's own privacy policy.
As features are added and improved, external APIs and data sources of the same nature (tourism and regional information) may be added or changed. This Policy continues to apply so long as no new personal or location information is collected; where new processing of personal information arises, this Policy will be amended and separate consent obtained where required.
3. Provision to third parties, entrustment of processing, and overseas transfer
The Operator does not sell or provide your personal information to third parties. To operate the Service, processing is entrusted as set out below; some processors' servers are located outside Korea, so the relevant information is transferred overseas.
3-1. Storage of accounts and shared-photo records (Supabase — domestic) currently Namhae edition
| Item | Detail |
|---|---|
| Processor | Supabase, Inc. · supabase.com/privacy |
| Entrusted work | Storing and managing account information, shared-photo records, and report/block records (database and authentication infrastructure) |
| Storage location | Seoul region, Republic of Korea (AWS ap-northeast-2) |
| Retention period | Until account deletion (per the periods in Section 1) |
3-2. Storage of shared photo images (Cloudflare — overseas transfer) currently Namhae edition
| Item | Detail |
|---|---|
| Processor (transferee) | Cloudflare, Inc. (R2 object storage) Contact: 101 Townsend Street, San Francisco, CA 94107, USA · legal@cloudflare.com cloudflare.com/privacypolicy |
| Entrusted work | Storing and delivering shared photo image files |
| Items transferred | The shared photo images described in Section 1-4 (metadata removed — no name, contact details or location coordinates) |
| Destination countries | Countries hosting Cloudflare data centers in the Asia-Pacific region (the bucket's storage location setting is APAC). For R2, Cloudflare offers only continent- or region-level settings and does not support country-level designation, and even that setting is best effort rather than a guarantee. We therefore cannot name a specific country. |
| Time and method of transfer | At the moment you choose to publish a photo, over HTTPS-encrypted communication |
| Purpose | Serving images for the per-place shared album |
| Retention period | Until you delete the photo or it is pushed out of the per-place limit (destroyed from storage upon deletion) |
3-3. Crash logs (Google — overseas transfer) both apps
| Item | Detail |
|---|---|
| Processor (transferee) | Google LLC (Firebase Crashlytics) Contact: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · dpo-google@google.com firebase.google.com/support/privacy |
| Entrusted work | Collecting, storing and analyzing crash logs and providing error reports |
| Items transferred | The crash logs, device/app information and device/installation identifiers described in Section 1-1 (excluding photos, locations and memos) |
| Destination countries | The United States and other countries hosting Google data centers |
| Time and method of transfer | When the app terminates abnormally, from your device over HTTPS-encrypted communication |
| Purpose | Diagnosing app errors and improving stability |
| Retention period | 90 days after transmission (then destroyed per Google's deletion process) |
3-4. Banner ads (Google — overseas transfer) nationwide edition only
| Item | Detail |
|---|---|
| Processor (transferee) | Google LLC (Google AdMob) Contact: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · dpo-google@google.com policies.google.com/technologies/partner-sites |
| Entrusted work | Selecting and serving banner ads, measuring ad performance, preventing invalid clicks |
| Items transferred | The advertising identifier (Ad ID), device/app information, IP address and approximate location, and ad interaction records described in Section 1-5 (excluding photos, precise GPS coordinates and memos) |
| Destination countries | The United States and other countries hosting Google data centers |
| Time and method of transfer | When the app requests an ad, from your device over HTTPS-encrypted communication |
| Purpose | Covering operating costs through advertising |
| Retention period | Per Google's advertising data retention policy (policies.google.com/technologies/ads) |
3-5. Push notifications (Google — overseas transfer) both apps
| Item | Detail |
|---|---|
| Processor (transferee) | Google LLC (Firebase Cloud Messaging) Contact: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · dpo-google@google.com firebase.google.com/support/privacy |
| Entrusted work | Issuing and managing notification tokens and delivering push notification messages |
| Items transferred | The notification token and device/app information described in Section 1-2 (excluding photos, locations and memos) |
| Destination countries | The United States and other countries hosting Google data centers |
| Time and method of transfer | When the token is issued on install/launch and when a notification is sent, over HTTPS-encrypted communication |
| Purpose | Announcing new features and service news |
| Retention period | Until the app is uninstalled or the token is refreshed or expires |
3-6. Social login authentication (Google · Kakao) currently Namhae edition
During sign-in you authenticate directly on the authentication screen of Google LLC or Kakao Corp.; the processing of personal information in that step follows each company's privacy policy (Google · Kakao). The information the Operator receives after authentication is as described in Section 1-3.
Transmissions for map display, address conversion, tourism lookups and the Nangman Namhae link are transient communications used only to generate a response; the Operator does not collect or retain that information (see Section 2).
3-7. How to refuse an overseas transfer, the procedure, and its effect
You may refuse the overseas transfers described in 3-2 through 3-5. You refuse by not using the feature that causes the transfer; this takes effect immediately and requires no application procedure. For questions, use the contact in section 8.
| Transfer | How to refuse | Effect of refusing |
|---|---|---|
| 3-2. Shared photo images (Cloudflare) | If you do not use photo sharing, no transfer occurs. Photos you have already shared are destroyed in the storage when you delete them in the app. | Only per-place photo sharing becomes unavailable. Capture, overlay, map display and the other features continue to work. |
| 3-3. Crash logs (Google) | Deleting the app stops crash logs from being sent. There is no separate opt-out setting inside the app. | Because this means deleting the app, the whole Service becomes unavailable. Crash logs are used only for error diagnosis and contain no information that identifies you. |
| 3-4. Banner advertising (Google, nationwide edition only) | On your device, go to Settings → Privacy → Ads and delete the advertising ID; it will no longer be sent with ad requests (see section 5). To stop ad requests entirely you must delete the app. | Deleting the advertising ID means you see non-personalized ads instead of personalized ones, with no effect on other features. Advertising funds the free service, so there is no setting that turns ads off. |
| 3-5. Push notifications (Google) | Turn off Settings → Notifications in the app to unsubscribe from the topic, and no further notifications are sent. Deleting the app also stops delivery (see section 5). | You will not receive news about new features or the Service. No other feature is affected. |
Even after you refuse, information already transferred and held by a processor is destroyed according to the retention period stated for each item. To remove your account and shared photos immediately, use the account deletion procedure in section 5.
4. Retention period and destruction
- On-device user data such as photos, locations, memos and commemorative stamps: stored only on your device, so deleting a photo or record in the app, or uninstalling the app, destroys it immediately. The Operator holds no separate copy.
- Account information: destroyed without delay upon account deletion.
- Shared photos: when you delete a photo or it is pushed out of the per-place limit (50 photos), the image file itself is destroyed from storage. Deleting your account also destroys the photos shared from it. However, a photo under review following a report may be retained for review purposes for up to 30 days and is destroyed after that period.
- Crash logs and device/app information: retained for 90 days after transmission per Google's Firebase Crashlytics policy, then destroyed from live and backup systems per Google's deletion process.
- Advertising identifier and ad request information (nationwide edition): retained and destroyed by Google per its advertising data retention policy. The Operator holds no separate copy, and if you delete the Ad ID in device settings, that identifier is no longer sent with subsequent requests.
- Notification token: uninstalling the app invalidates the token so that no further notifications are sent. Copies held by Google are cleared through token expiry and refresh processes.
5. Your rights
- You can grant or withdraw the camera, location and photo permissions at any time in device settings.
- You can delete individual photos and records directly in the app.
- You can delete a shared photo at any time in the app; it immediately stops being visible to other users and is destroyed from storage.
- You can delete your account at any time from Settings → Account → Delete account in the app. If you cannot access the app, you may request deletion by email following the Account Deletion Guide.
- Uninstalling the app deletes all data the app stored on your device, and no further crash logs are sent. However, account information and shared photos remaining on the server are not removed by uninstalling alone, so delete your account before uninstalling if you want your shared photos removed. (Shared photos are also removed over time by the per-place retention limit.)
- Requests to access, correct, delete or suspend processing of personal information can be submitted to the contact in Section 8. Because crash logs contain no information identifying a specific user, it may be impossible to single out an individual user's records; in such cases we will explain why.
- You can withdraw consent to notifications at any time. Turning off Settings → Notifications in the app unsubscribes you from the topic so that no further notifications are sent (you are removed from delivery, not merely from display). Turning them off in Settings → Apps → (app name) → Notifications on the device also stops display, and uninstalling the app stops delivery.
- You can reset or delete the advertising identifier (nationwide edition). On Android, use Settings → Privacy → Ads (or Settings → Google → Ads, depending on device and version) to reset the Ad ID or select Delete advertising ID. After deletion, the Ad ID is no longer sent with ad requests from the app, and non-personalized ads are shown instead.
6. Security measures
- The Service is designed on-device-first, keeping records and diary data off the Operator's servers; only the minimum information you choose to share is stored on the server.
- Shared photos have metadata (EXIF), including location coordinates, stripped on the device before upload.
- Server data is protected by per-account access control (row-level security); no one can access another user's information without authentication.
- All communication (external APIs, servers, crash logs) takes place only over HTTPS-encrypted channels.
- Crash logs contain no user data or directly identifying information — only the minimum items needed for error diagnosis.
7. Children's personal information · advertising and analytics tools
The Service is not directed to children under the age of 14 and does not knowingly collect their personal information. Any account confirmed to belong to a child under 14 is deleted without delay.
Spacetime Diary (nationwide edition) displays Google AdMob banner ads, and the advertising identifier and related information are sent to Google in the process (see Sections 1-5 and 3-4). Ads are shown in an area clearly separated from content and are never placed so as to obstruct interaction or to be mistaken for content. Namhae: Spacetime Diary displays no ads and does not collect the advertising identifier.
Neither app uses analytics tools that track or profile user behavior (for example, Firebase Analytics). The Firebase Crashlytics described in Section 1-1 is a stability tool used solely for diagnosing app errors. If a behavioral analytics tool is introduced, or the form or scope of advertising is expanded, this Policy will be amended and notice given in advance.
8. Privacy officer
- Privacy officer: Representative, Romantic Rider
- Contact: romanticrider.app@gmail.com
Please send privacy-related inquiries, complaints and remedy requests to the address above. We will respond and act without delay.
9. Remedies for infringement of rights
If you need to report, seek advice on, or mediate a dispute over a privacy infringement, the following Korean bodies can help.
- Personal Information Dispute Mediation Committee: kopico.go.kr · 1833-6972
- Privacy Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr · 118 (no area code)
- Supreme Prosecutors' Office: spo.go.kr · 1301 (no area code)
- National Police Agency, Cyber Investigation Bureau: ecrm.police.go.kr · 182 (no area code)
Appendix A — Per-App Applicability
| Item | Spacetime Diary (nationwide) | Namhae: Spacetime Diary |
|---|---|---|
| Banner ads · Ad ID (Sections 1-5, 3-4) | Applies | Does not apply (no ads) |
| Accounts · photo sharing · reports/blocks (Sections 1-3, 1-4, 3-1, 3-2, 3-6) | Planned — this Appendix will be updated upon launch | Applies (from 2026-09-10) |
| Tourism lookup path (Section 2) | Sent directly to KTO TourAPI | Sent to the Operator's server (Supabase) — lookup coordinates not stored |
| Commemorative stamps · Nangman Namhae link (Sections 1, 2) | Not applicable | Applies (stamp determination = on device) |
| Crash logs · push notifications (Sections 1-1, 1-2, 3-3, 3-5) | Applies commonly to both apps | |
10. Changes to this Policy
This Policy may be amended in line with changes in law or the Service. Where a feature that changes the processing of personal information is introduced, this Policy will be amended before that feature launches, and separate consent will be obtained for items requiring consent by law. Amendments are announced in the app or on this page at least 7 days before they take effect (30 days for material changes).
- 2026-09-02 relationship between the Unified Edition and per-app documents settled — per-app documents are each app's authoritative text; the Unified Edition is a synchronized compendium. Because the paths each app links are fixed, the "replacement" concept was dropped and the relationship stated as it is (no change to which document applies to users)
- 2026-09-02 public nickname reflected — the section 1 table and section 1-4 now state that a shared photo is displayed together with the nickname you choose, and section 1-3 clarifies that the displayed nickname is separate from your social account nickname and is chosen by you (this also applies to photos shared earlier; Personal Information Protection Act, Article 30(1)(i)-(ii))
- 2026-08-28 overseas-transfer disclosure expanded — added the transferee's contact details and how to refuse a transfer, the procedure and its effect, and corrected the description of Cloudflare's destination countries to match what was measured (Personal Information Protection Act, Article 28-8(1)3(a) and 28-8(2); no change adverse to users)
- Unified Edition v1.0 (effective 2026-09-10) — enacted as a single policy covering both apps. At enactment it was intended to replace the per-app policies on the effective date; following the relationship settled on 2026-09-02 it does not (each app's per-app policy is that app's authoritative text; this Unified Edition is a synchronized compendium — see the 2026-09-02 entry below). Reflects the introduction of photo sharing and social login: new processing of account information (Section 1-3) and shared photos (Section 1-4); the Namhae edition's tourism information now served via the Operator's server (Section 2 — lookup coordinates are not stored); Supabase (domestic) and Cloudflare (overseas transfer) added as processors (Section 3); account deletion procedure added (Section 5); per-app differences consolidated in Appendix A.
- Earlier revision history — nationwide edition: v1.0 (enacted 2026-07-07) · v2.0 (2026-07-30, Crashlytics) · v3.0/v3.1 (2026-08-14, AdMob ads and push notifications) / Namhae edition: v1.0 (2026-08-09, enacted separately)