Privacy Policy
Insight Town (the "Service") values users' personal information and discloses its personal information processing standards in accordance with applicable laws, including the Personal Information Protection Act.
Effective date: July 14, 2026
1. Purposes of Processing Personal Information
The Service processes personal information for the following purposes. Personal information processed for these purposes will not be used for other purposes unless the required procedure is followed.
- Account registration, email verification, login, social login, identity confirmation, account management, password reset, and management of consent history for the Terms of Use and Privacy Policy
- Provision of game features such as characters, world entry, movement, chat, pets, plants, buildings, furniture, interiors, safes, personal stores, NPC trades, exchanges, mail, rankings, and mini-games
- Management of game data such as items, currency, free crystals, paid crystals, rewards, refundable trades, trade cancellation, system mail, and receipt status
- Android/iOS in-app purchase verification, paid product delivery, missing-grant checks, refund processing, payment inquiries, dispute response, and prevention of payment abuse
- Invite code issuance, entry, settlement reward grants, reward limit management, and prevention of reward abuse
- Purchase verification, status synchronization, restoration, extra reward grants, and support for subscription products such as Attendance Pass
- Provision of user content features such as profile images, furniture album/frame images, guestbooks, comments, likes, reports, inquiries, error reports, and suggestions
- Service operation notices such as push notifications, in-app notifications, email verification codes, system mail, operation notices, and incident notices
- Investigation and prevention of abnormal use, abuse, abnormal payments, security breaches, service incidents, and data errors
- Service quality improvement, server performance analysis, customer support, and fulfillment of legal obligations
2. Personal Information Processed
| Category | Items Processed |
|---|---|
| Member/account | Email address or login ID, encrypted/hashed password, member number, display name/nickname, role and administrator status, registration date, Terms consent date, Privacy Policy consent date, and account status |
| Social login | Provider information for Google, Apple, Kakao, or Naver accounts, unique identifier, email address, email verification status, and last login time. The Service does not collect original passwords for social login accounts. |
| Authentication/security | Account identifiers required to issue JWTs, refresh token hash and expiration information, token version, email verification code hash, password reset request information, login failure count, request IP, and rate limit information |
| Profile/images | Profile image, original/thumbnail file keys, file type, size, upload history, and deletion history |
| World/game data | Character appearance and state, in-world coordinates, entry/exit/session records, items/currency/inventory, paid and free crystal possession/consumption records, fatigue, life skill, buffs, titles, achievements, pets, plants, gathering, fishing, cooking, research, buildings, yards, furniture, interior templates, safes, personal stores, trades, NPC trade and refund records, wandering shop use records, mail, mini-game participation and results, weekly/previous-week ranking scores, and rewards |
| Invite/settlement rewards | Invite code, identifiers of the inviting member and joining member, invite code entry and acceptance time, hashes of IP/device/account identity information, reward grant status, reward block reason, reward date, and monthly aggregation information |
| Communication/content | World chat, speech bubbles, guestbooks, furniture album/frame images, memos, comments, likes, reports, inquiries, error reports, suggestions, report/feedback attached images, attachment file keys, operator processing status, and information required for replies |
| Paid payments | Platform (Android/iOS), product ID, purchase ID, order ID, transaction ID, purchase time, product price, purchase verification request hash, payment server purchase identifier, purchase/verification/grant/failure/refund status, paid product mail ID, receipt time, refund request reason, administrator memo, payment audit logs, subscription product status, auto-renewal flag, subscription expiration/cancellation/grace/last-checked time, subscription status reason, internal VIP/purchase grade based on cumulative payment amount, and operator override history |
| Device/notifications | FCM token, notification settings, OS and platform, app version, target server, data patch target, and notification delivery result |
| Voice features | Voice state, WebRTC connection signals, participant identifiers, and microphone permission status for some mini-games such as Beat Party, Drawing Quiz, Omok, and One Card. The Service server does not record or store voice conversation content. |
| Automatically generated information | IP address, access time, request path, response status, error type, processing time, server/client performance metrics, crash logs, stack traces, OS and app version, security/operations logs, administrator action logs, and use restriction records |
The Service does not directly collect resident registration numbers, passport numbers, driver's license numbers, or payment card numbers. Payment method information is processed by Google Play or Apple App Store according to their respective policies. If users voluntarily enter personal information in chat, images, inquiries, reports, or similar features, that content may be processed, so please enter only what is necessary.
3. Methods of Collecting Personal Information
- Information directly entered by users or transmitted during use, such as registration, email verification, login, social login, profile changes, game use, invite code entry, payment verification, subscription purchase/restoration, mail receipt, refund requests, and inquiry/report/feedback submission with optional image attachments
- Information automatically generated during service use, such as server logs, app logs, notification tokens, world state, ranking scores, payment verification results, and item change records
- IP, device, and account identity information converted into hashes, not stored as raw values, for preventing invite reward abuse
- Minimum necessary operation records created by the Operator during incident response, customer support, refund processing, abuse investigation, or security response
4. Retention and Use Period
In principle, the Service destroys personal information without delay when the purpose of processing is achieved. However, information may be retained for the following periods when necessary for service operation, dispute response, prevention of abnormal use, payment inquiry handling, or compliance with applicable laws.
| Item | Retention Period |
|---|---|
| Member account information | Access is blocked immediately upon withdrawal, and account status information required for one-time restoration within 7 days is retained. When the recovery period ends, account-identifying information and directly linked data, including login information, social sign-in connections, email verification information, and profile image assets, are permanently deleted or irreversibly anonymized. Records required for legal compliance, payment/refund, dispute response, and abuse prevention are retained for the separate periods below. |
| Verification codes and password reset records | Destroyed after the authentication purpose is achieved or the validity period expires. They may be retained for the minimum period required for security and retry limits. |
| Refresh token | Retained until logout, password change, withdrawal, security action, or expiration. The current default expiration period for refresh tokens is 30 days. |
| World/game progress data | Retained while the member uses the Service. Upon withdrawal, access is blocked immediately, and when the 7-day recovery period ends, the data is permanently deleted or irreversibly anonymized. Payment/refund, dispute, sanction, and report records that require separate retention are stored separately for defined periods with member identifiers minimized. |
| NPC trade refund records | The refundable period is 7 days from the transaction time, and internal transaction records are retained for up to 30 days and then deleted. Expired trades are not displayed on service screens. |
| When a user deletes mail, it is hidden immediately and actually deleted 30 days later. Mail without attachments may be deleted 30 days after creation, and mail with attachments may be deleted 90 days after creation if claimed or if it is not paid product mail. Unclaimed paid product mail is retained while the account is active for delivery or refund handling. Upon withdrawal, the mail is deleted with account data, while payment and delivery evidence is stored separately for 5 years. | |
| In-app notifications | Read notifications may be retained for up to 7 days, and unread notifications for up to 30 days, then deleted. Chat and mail push notifications may be excluded from in-app notification list storage. |
| Trade/personal store/wandering shop records | Completed or canceled trade sessions may be retained for up to 7 days, settled personal store sale records for up to 90 days, and wandering shop records for up to 30 days before deletion. |
| Invite code and settlement reward records | Invite codes are retained while active, and pending settlement reward records may be retained until the reward decision is completed. Completed or blocked reward records and hashes of IP, device, and account identifiers are retained for 1 year from the last action. Records directly related to a consumer dispute may be retained for 3 years. |
| Paid payment, subscription, product grant, refund, and payment inquiry records | For an active account, payment records needed to calculate cumulative purchase-based VIP or purchase grades and provide payment support may be retained while the member uses the Service. After permanent account deletion or the end of that processing purpose, records of contracts or purchase cancellation, payment, and supply of goods are retained for 5 years; consumer complaint or dispute records for 3 years; and display or advertising records for 6 months. Ongoing refunds, missing grants, active subscriptions, abnormal payment investigations, or disputes are retained until resolved and then destroyed under the applicable period. Raw purchase tokens are kept only for the minimum period needed for normal processing and potential disputes, after which only a hash remains. |
| Furniture album/frame images and comments | Retained while the content is posted in the Service. Content may be deleted due to user deletion, furniture recovery, withdrawal, operational measures, or regular cleanup. Operational backups are separated from the live Service, retained for up to 30 days, and then deleted sequentially. Previously processed deletion states are reapplied after a backup restore. |
| Operations/access/security logs | Retained for up to 6 months for abuse prevention, incident analysis, and security monitoring. If legally required or directly related to an ongoing security incident or dispute, the relevant records may be stored separately until the matter is resolved. |
| Reports, sanctions, and abuse response records | Retained for 1 year after report processing or the end of a sanction. Records directly related to a consumer complaint or dispute may be retained for 3 years. |
| Customer inquiries, reports, error reports, and suggestions | General inquiries, error reports, and suggestions are retained for up to 1 year after completion, then permanently deleted or irreversibly anonymized. When an account is permanently deleted, they are deleted with the account data unless retention is required for dispute response or by law. Payment inquiries and consumer dispute records are retained for 3 years. |
5. Provision of Personal Information to Third Parties
The Service does not provide users' personal information to third parties in principle. However, information may be provided within the necessary scope in the following cases.
- When the user has given prior consent
- When there is a legal basis or a request from an authorized institution such as an investigative agency, court, or administrative agency
- When necessary to prevent imminent danger to the life, body, or property of the user or another person
- When confirmation of necessary information such as transaction identifiers is required by Google Play or Apple App Store for payment, refund, or store policy handling
6. Entrustment of Processing and External Services
The Service may use the following external services to provide the Service. Each service is used only within the scope necessary for service provision.
| Processor/External Service | Purpose | Information That May Be Processed |
|---|---|---|
| Amazon Web Services (AWS) | Server infrastructure, data storage, image and file storage, and data patch file storage | Service data, uploaded images, file keys, access logs, and operation logs |
| Google Firebase Cloud Messaging | Push notification delivery | FCM token, platform, notification title/body, and notification data |
| Google Firebase Crashlytics | App crash and error diagnosis, and service stability improvement | Diagnostic information such as crash logs, stack traces, error types, OS and app version, device state, and occurrence time. Sensitive information such as passwords, JWTs, refresh tokens, and raw payment verification data is managed so it is not included. |
| Google, Apple | Social login, app distribution, Android/iOS in-app purchases, purchase verification, store refunds, and policy handling | Social login identifiers and emails, app install/update information, product ID, purchase ID, order ID, transaction ID, receipt or verification token, and other information processed by each platform |
| Kakao | Kakao login, Kakao account authentication, and social account identification | Kakao member number, email address and verification status, Kakao login token verification result, and other information provided by Kakao |
| Naver | Naver login, Naver account authentication, and social account identification | Naver member identifier, email address, Naver login token verification result, and other information provided by Naver |
| Google Play Developer API, Apple App Store Server API | Paid product purchase verification, payment status confirmation, refund handling, and missing-grant inquiry response | Platform, product ID, purchase token, transaction ID, order ID, purchase time, and verification result |
| Email delivery service (SMTP) | Sending email verification codes for registration and password reset | Recipient email address, verification email subject, and verification email body |
| Telegram | Operator incident alerts, important server status alerts, error report/suggestion alerts, and incident response alerts | Minimum operational information required for troubleshooting, such as server status, error type, request path, internal member number, or payment identifier, excluding sensitive information such as passwords, tokens, and private keys |
| OpenAI API | Generation and review of quiz candidates for service operation | Operational data such as quiz topics, difficulty, and candidate questions. It is not used to transmit users' personal information. |
| WebRTC connection support service | Connection support for mini-game voice conversation | Network metadata and connection signals required for voice connection. The Service server does not record or store voice content. |
External service infrastructure may be located in or outside Korea. The Service transfers information only within the necessary scope and manages operations alerts so that sensitive information such as original passwords, original refresh tokens, FCM tokens, and private keys is not included.
7. Destruction Procedure and Method
- Information in electronic file form is deleted or made inaccessible so that recovery or reproduction is difficult.
- Information stored in databases is permanently deleted or irreversibly anonymized after confirming expiration of retention periods, member withdrawal, or achievement of the processing purpose.
- Mail, images, comments, and similar content deleted by users may first be hidden from service screens and are then deleted sequentially after the backup retention period of up to 30 days. Previously processed deletion states are reapplied after a backup restore.
- Information required to be retained by law is stored separately and destroyed after the retention period ends.
8. User Rights and How to Exercise Them
- Users may request access to, correction of, deletion of, or suspension of processing of their personal information.
- Users may directly modify some information or withdraw through the in-app profile, settings, and account withdrawal menus.
- If the app cannot be used, users can check how to request deletion through the account and data deletion request page.
- For requests that are difficult to process directly, or to request immediate permanent deletion without the 7-day recovery period, please contact the address listed in this Policy. The Service will process the request under applicable laws after identity verification.
- Deletion or suspension of processing may be restricted within the scope required by law or operations when the information is combined with relationships with other users, service operation records, payment/refund records, reports, sanctions, or dispute records.
9. App Permissions
| Permission | Purpose of Use |
|---|---|
| Notifications | Sending push notifications for mail, chat, world state, buildings, fatigue, rankings, events, incidents, notices, and similar information |
| Photos/images | Uploading and storing profile images and furniture album/frame images |
| Camera | Providing image capture and upload features |
| Microphone | Providing mini-game voice conversation features |
| Network state | Server connection, data patches, payment verification, push notifications, and connection stability checks |
Even if optional permissions are not granted, the Service can be used except for features that require those permissions. The Service does not currently use users' real GPS location as a required collection item, and in-world coordinates are virtual location information for game progress.
10. Measures to Protect Personal Information
- Passwords and verification codes are stored in encrypted or hashed form, not as plain text.
- Refresh tokens are stored as hashes, not as plain text, and token expiration, rotation, and revocation are applied.
- Administrator and operations tool access is limited to necessary people and necessary features, and administrator action history is recorded.
- Internal calls between the payment server and game server are verified by a separate internal secret.
- Server logs and operation alerts are managed so that sensitive information such as passwords, JWTs, refresh tokens, FCM tokens, private keys, and raw payment verification data is not retained.
- Uploaded files are checked for extension, size, file type, and other conditions, and when necessary are accessed only for a limited time through presigned URLs.
- Restrictions and monitoring are applied to abnormal use, abnormal requests, excessive authentication attempts, and abnormal payment verification requests.
11. Behavioral Information and Personalized Advertising
The Service does not currently collect users' behavioral information or provide it to third-party advertising providers for personalized advertising.
12. Children's Personal Information
The Service is generally not directed to children under 14 years of age. If processing of personal information of a user under 14 is confirmed, the Service may take necessary measures such as confirming legal guardian consent or restricting use.
13. Privacy Officer and Contact
- Privacy officer: Park Beomjoo
- Email: bjay@kakao.com
If you need to report or consult about privacy infringement, you may contact relevant institutions such as the Personal Information Protection Commission or the Personal Information Infringement Report Center.
14. Changes to This Privacy Policy
This Policy may be revised due to changes in laws, service features, payment policies, or operations policies. For material changes, the Service will provide notice through the app or in-service notices, or another appropriate method.
Effective date: July 14, 2026