Privacy Policy

Insight Town (the "Service") values users' personal information and discloses its personal information processing standards in accordance with applicable laws, including the Personal Information Protection Act.

Effective date: July 14, 2026

1. Purposes of Processing Personal Information

The Service processes personal information for the following purposes. Personal information processed for these purposes will not be used for other purposes unless the required procedure is followed.

2. Personal Information Processed

Category Items Processed
Member/account Email address or login ID, encrypted/hashed password, member number, display name/nickname, role and administrator status, registration date, Terms consent date, Privacy Policy consent date, and account status
Social login Provider information for Google, Apple, Kakao, or Naver accounts, unique identifier, email address, email verification status, and last login time. The Service does not collect original passwords for social login accounts.
Authentication/security Account identifiers required to issue JWTs, refresh token hash and expiration information, token version, email verification code hash, password reset request information, login failure count, request IP, and rate limit information
Profile/images Profile image, original/thumbnail file keys, file type, size, upload history, and deletion history
World/game data Character appearance and state, in-world coordinates, entry/exit/session records, items/currency/inventory, paid and free crystal possession/consumption records, fatigue, life skill, buffs, titles, achievements, pets, plants, gathering, fishing, cooking, research, buildings, yards, furniture, interior templates, safes, personal stores, trades, NPC trade and refund records, wandering shop use records, mail, mini-game participation and results, weekly/previous-week ranking scores, and rewards
Invite/settlement rewards Invite code, identifiers of the inviting member and joining member, invite code entry and acceptance time, hashes of IP/device/account identity information, reward grant status, reward block reason, reward date, and monthly aggregation information
Communication/content World chat, speech bubbles, guestbooks, furniture album/frame images, memos, comments, likes, reports, inquiries, error reports, suggestions, report/feedback attached images, attachment file keys, operator processing status, and information required for replies
Paid payments Platform (Android/iOS), product ID, purchase ID, order ID, transaction ID, purchase time, product price, purchase verification request hash, payment server purchase identifier, purchase/verification/grant/failure/refund status, paid product mail ID, receipt time, refund request reason, administrator memo, payment audit logs, subscription product status, auto-renewal flag, subscription expiration/cancellation/grace/last-checked time, subscription status reason, internal VIP/purchase grade based on cumulative payment amount, and operator override history
Device/notifications FCM token, notification settings, OS and platform, app version, target server, data patch target, and notification delivery result
Voice features Voice state, WebRTC connection signals, participant identifiers, and microphone permission status for some mini-games such as Beat Party, Drawing Quiz, Omok, and One Card. The Service server does not record or store voice conversation content.
Automatically generated information IP address, access time, request path, response status, error type, processing time, server/client performance metrics, crash logs, stack traces, OS and app version, security/operations logs, administrator action logs, and use restriction records

The Service does not directly collect resident registration numbers, passport numbers, driver's license numbers, or payment card numbers. Payment method information is processed by Google Play or Apple App Store according to their respective policies. If users voluntarily enter personal information in chat, images, inquiries, reports, or similar features, that content may be processed, so please enter only what is necessary.

3. Methods of Collecting Personal Information

4. Retention and Use Period

In principle, the Service destroys personal information without delay when the purpose of processing is achieved. However, information may be retained for the following periods when necessary for service operation, dispute response, prevention of abnormal use, payment inquiry handling, or compliance with applicable laws.

Item Retention Period
Member account information Access is blocked immediately upon withdrawal, and account status information required for one-time restoration within 7 days is retained. When the recovery period ends, account-identifying information and directly linked data, including login information, social sign-in connections, email verification information, and profile image assets, are permanently deleted or irreversibly anonymized. Records required for legal compliance, payment/refund, dispute response, and abuse prevention are retained for the separate periods below.
Verification codes and password reset records Destroyed after the authentication purpose is achieved or the validity period expires. They may be retained for the minimum period required for security and retry limits.
Refresh token Retained until logout, password change, withdrawal, security action, or expiration. The current default expiration period for refresh tokens is 30 days.
World/game progress data Retained while the member uses the Service. Upon withdrawal, access is blocked immediately, and when the 7-day recovery period ends, the data is permanently deleted or irreversibly anonymized. Payment/refund, dispute, sanction, and report records that require separate retention are stored separately for defined periods with member identifiers minimized.
NPC trade refund records The refundable period is 7 days from the transaction time, and internal transaction records are retained for up to 30 days and then deleted. Expired trades are not displayed on service screens.
Mail When a user deletes mail, it is hidden immediately and actually deleted 30 days later. Mail without attachments may be deleted 30 days after creation, and mail with attachments may be deleted 90 days after creation if claimed or if it is not paid product mail. Unclaimed paid product mail is retained while the account is active for delivery or refund handling. Upon withdrawal, the mail is deleted with account data, while payment and delivery evidence is stored separately for 5 years.
In-app notifications Read notifications may be retained for up to 7 days, and unread notifications for up to 30 days, then deleted. Chat and mail push notifications may be excluded from in-app notification list storage.
Trade/personal store/wandering shop records Completed or canceled trade sessions may be retained for up to 7 days, settled personal store sale records for up to 90 days, and wandering shop records for up to 30 days before deletion.
Invite code and settlement reward records Invite codes are retained while active, and pending settlement reward records may be retained until the reward decision is completed. Completed or blocked reward records and hashes of IP, device, and account identifiers are retained for 1 year from the last action. Records directly related to a consumer dispute may be retained for 3 years.
Paid payment, subscription, product grant, refund, and payment inquiry records For an active account, payment records needed to calculate cumulative purchase-based VIP or purchase grades and provide payment support may be retained while the member uses the Service. After permanent account deletion or the end of that processing purpose, records of contracts or purchase cancellation, payment, and supply of goods are retained for 5 years; consumer complaint or dispute records for 3 years; and display or advertising records for 6 months. Ongoing refunds, missing grants, active subscriptions, abnormal payment investigations, or disputes are retained until resolved and then destroyed under the applicable period. Raw purchase tokens are kept only for the minimum period needed for normal processing and potential disputes, after which only a hash remains.
Furniture album/frame images and comments Retained while the content is posted in the Service. Content may be deleted due to user deletion, furniture recovery, withdrawal, operational measures, or regular cleanup. Operational backups are separated from the live Service, retained for up to 30 days, and then deleted sequentially. Previously processed deletion states are reapplied after a backup restore.
Operations/access/security logs Retained for up to 6 months for abuse prevention, incident analysis, and security monitoring. If legally required or directly related to an ongoing security incident or dispute, the relevant records may be stored separately until the matter is resolved.
Reports, sanctions, and abuse response records Retained for 1 year after report processing or the end of a sanction. Records directly related to a consumer complaint or dispute may be retained for 3 years.
Customer inquiries, reports, error reports, and suggestions General inquiries, error reports, and suggestions are retained for up to 1 year after completion, then permanently deleted or irreversibly anonymized. When an account is permanently deleted, they are deleted with the account data unless retention is required for dispute response or by law. Payment inquiries and consumer dispute records are retained for 3 years.

5. Provision of Personal Information to Third Parties

The Service does not provide users' personal information to third parties in principle. However, information may be provided within the necessary scope in the following cases.

6. Entrustment of Processing and External Services

The Service may use the following external services to provide the Service. Each service is used only within the scope necessary for service provision.

Processor/External Service Purpose Information That May Be Processed
Amazon Web Services (AWS) Server infrastructure, data storage, image and file storage, and data patch file storage Service data, uploaded images, file keys, access logs, and operation logs
Google Firebase Cloud Messaging Push notification delivery FCM token, platform, notification title/body, and notification data
Google Firebase Crashlytics App crash and error diagnosis, and service stability improvement Diagnostic information such as crash logs, stack traces, error types, OS and app version, device state, and occurrence time. Sensitive information such as passwords, JWTs, refresh tokens, and raw payment verification data is managed so it is not included.
Google, Apple Social login, app distribution, Android/iOS in-app purchases, purchase verification, store refunds, and policy handling Social login identifiers and emails, app install/update information, product ID, purchase ID, order ID, transaction ID, receipt or verification token, and other information processed by each platform
Kakao Kakao login, Kakao account authentication, and social account identification Kakao member number, email address and verification status, Kakao login token verification result, and other information provided by Kakao
Naver Naver login, Naver account authentication, and social account identification Naver member identifier, email address, Naver login token verification result, and other information provided by Naver
Google Play Developer API, Apple App Store Server API Paid product purchase verification, payment status confirmation, refund handling, and missing-grant inquiry response Platform, product ID, purchase token, transaction ID, order ID, purchase time, and verification result
Email delivery service (SMTP) Sending email verification codes for registration and password reset Recipient email address, verification email subject, and verification email body
Telegram Operator incident alerts, important server status alerts, error report/suggestion alerts, and incident response alerts Minimum operational information required for troubleshooting, such as server status, error type, request path, internal member number, or payment identifier, excluding sensitive information such as passwords, tokens, and private keys
OpenAI API Generation and review of quiz candidates for service operation Operational data such as quiz topics, difficulty, and candidate questions. It is not used to transmit users' personal information.
WebRTC connection support service Connection support for mini-game voice conversation Network metadata and connection signals required for voice connection. The Service server does not record or store voice content.

External service infrastructure may be located in or outside Korea. The Service transfers information only within the necessary scope and manages operations alerts so that sensitive information such as original passwords, original refresh tokens, FCM tokens, and private keys is not included.

7. Destruction Procedure and Method

8. User Rights and How to Exercise Them

9. App Permissions

Permission Purpose of Use
Notifications Sending push notifications for mail, chat, world state, buildings, fatigue, rankings, events, incidents, notices, and similar information
Photos/images Uploading and storing profile images and furniture album/frame images
Camera Providing image capture and upload features
Microphone Providing mini-game voice conversation features
Network state Server connection, data patches, payment verification, push notifications, and connection stability checks

Even if optional permissions are not granted, the Service can be used except for features that require those permissions. The Service does not currently use users' real GPS location as a required collection item, and in-world coordinates are virtual location information for game progress.

10. Measures to Protect Personal Information

11. Behavioral Information and Personalized Advertising

The Service does not currently collect users' behavioral information or provide it to third-party advertising providers for personalized advertising.

12. Children's Personal Information

The Service is generally not directed to children under 14 years of age. If processing of personal information of a user under 14 is confirmed, the Service may take necessary measures such as confirming legal guardian consent or restricting use.

13. Privacy Officer and Contact

If you need to report or consult about privacy infringement, you may contact relevant institutions such as the Personal Information Protection Commission or the Personal Information Infringement Report Center.

14. Changes to This Privacy Policy

This Policy may be revised due to changes in laws, service features, payment policies, or operations policies. For material changes, the Service will provide notice through the app or in-service notices, or another appropriate method.

Effective date: July 14, 2026