한국어
1. 개요
KIIP Study는 대한민국 사회통합프로그램(KIIP) 시험 대비 학습 앱으로, iOS와 Android에서 제공됩니다. 본 개인정보 처리방침은 앱이 사용자 데이터를 어떻게 다루는지 설명합니다. 사용자의 학습 기록은 기기에 저장됩니다. KIIP Study는 자체 학습 서버를 운영하지 않고 계정을 만들지 않으며, 광고를 넣지 않고 광고 SDK도 사용하지 않으며 광고 식별자를 수집하지 않습니다. 앱이 사용자에 관해 스스로 수집해 보내는 것은 두 가지입니다 — 앱 안정성 개선을 위한 진단 정보(아래 5항 참조)와, 어떤 기능이 얼마나 쓰이는지 파악하기 위한 사용 통계(6항 참조)입니다 — 사용 통계는 Android 앱과 iOS 2.2.3 이상에서 전송됩니다. 어느 쪽에도 사용자가 무엇을 공부했는지, 즉 어떤 문항·단어를 보았고 무엇이라 답했는지는 담기지 않습니다. 이와 별도로 앱은 기능 수행에 필요한 통신을 합니다 — 학습 콘텐츠와 음성·이미지 파일 내려받기, 인앱결제, 업데이트 확인, 리뷰 요청이며 7항에서 설명합니다. 사용자가 직접 보내기로 선택한 문의·문항 신고 메일은 13항, 문제 공유 링크는 7항에서 설명합니다. 1항부터 13항까지는 앱에 관한 설명입니다. 웹사이트(kiipstudy.com)를 방문할 때 수집되는 정보 — 방문 통계(Google Analytics), 오류 진단(Sentry), 저장되는 쿠키와 그 거부 방법 — 은 14항에서 따로 설명합니다.
2. 앱이 저장하는 정보
KIIP Study가 사용자에 관해 디바이스에 저장하는 항목은 모두 학습 활동에서 생기는 데이터입니다:
- 학습 진도(레벨, 회차)
- 문제별 정답·오답 기록 및 SRS(간격 반복) 상태
- 즐겨찾기/북마크한 단어
- 앱 설정값(인터페이스 언어, 활성 학습 레벨, 활성 문제 유형 등)
위 학습 정보 자체는 디바이스에 저장되며, 앱이 그 기록을 KIIP Study 또는 제3자에게 업로드하지 않습니다. 즉 어떤 문항·단어를 보았고 무엇이라 답했는지는 기기 밖으로 나가지 않습니다. 다만 6항의 사용 통계에는 이 활동에서 파생된 집계 수치(한 번에 몇 문제를 풀었는지, 그중 몇 개가 정답이었는지, 몇 초 걸렸는지, 현재 학습 단계와 앱 언어 설정 등 6항에 적은 항목)가 포함됩니다. 또한 사용자가 직접 선택했을 때 다음 두 가지가 함께 나갑니다 — 앱 내 문의·문항 신고 메일에는 진단 목적으로 앱 언어 설정이 미리 채워지고(13항 참조), 문제 공유 링크에는 해당 문항과 정답 여부가 담깁니다(7항 참조).
3. 권한
KIIP Study가 요청하는 시스템 권한은 학습 알림을 보내기 위한 알림 권한 하나뿐이며, 거부해도 알림만 오지 않을 뿐 나머지 기능은 그대로 동작합니다. 마이크, 카메라, 위치, 사진 라이브러리, 연락처, 캘린더, 건강 데이터에 대한 접근은 요청하지 않습니다. 광고 식별자(iOS의 IDFA, Android의 광고 ID)도 요청하지 않고 수집하지 않습니다 — iOS에서는 광고 식별자를 읽는 기능이 앱에서 동작하지 않아 App Tracking Transparency(ATT) 프롬프트를 표시하지 않으며, Android에서는 광고 ID 관련 권한을 앱에서 제거하고 수집 기능을 껐습니다. 다만 위치 권한을 쓰지 않더라도, 5항·6항에 적은 대로 접속 IP 주소에서 유추되는 대략적인 위치는 기록에 남습니다.
4. 데이터 저장 위치
모든 학습 데이터는 기기 내 로컬 저장소에 저장됩니다(iOS는 SwiftData와 UserDefaults, Android는 기기 내 로컬 데이터베이스와 환경설정 저장소). 앱이 학습 데이터 자체를 서버로 업로드하지 않습니다. KIIP Study는 광고나 원격 구성을 위한 제3자 SDK를 사용하지 않습니다. 앱이 사용자에 관해 스스로 수집해 전송하는 것은 앱 안정성 개선을 위한 진단 정보(5항)와 사용 통계(6항) 두 가지이며, 다음 두 항목에서 설명합니다. 이와 별도로 앱은 학습 콘텐츠·음성·이미지 내려받기, 인앱결제, 업데이트 확인, 리뷰 요청을 위해 외부와 통신하며 7항에서 설명합니다. 이와 별개로, 사용자가 직접 보내기로 선택한 문의·문항 신고 메일은 13항에서 설명합니다.
5. 크래시 및 오류 진단 (Sentry)
앱 안정성과 성능을 개선하기 위해, KIIP Study는 iOS와 Android 양쪽에서 이름·계정에 연결되지 않은 진단 정보만 Sentry(제3자 오류 모니터링 서비스 제공업체)로 전송합니다. 여기에는 비정상 종료(크래시)·오류 보고가 포함됩니다. iOS에서는 추가로 앱이 실행·종료된 횟수를 집계하는 세션 정보와, 정상 사용 중 일부만 샘플링되는 성능 트레이스가 전송됩니다. Android에서는 이 둘을 보내지 않습니다.
- 전송되는 정보는 기술적 진단에 한정되며, 다음을 포함합니다 — 오류 메시지, 스택 트레이스, 오류가 난 시각과 그 직전의 앱 동작 기록, 기기·OS 종류와 기기의 상태 값(화면 크기·방향, 배터리 잔량과 충전 여부, 사용 가능한 메모리, Android에서는 네트워크 연결 종류), 기기의 언어·시간대 설정, 앱 버전과 빌드 번호, 실행 환경 표시, IP 주소에서 유추한 대략적인 위치(도시 수준까지), 그리고 iOS의 세션 정보와 일부 성능 트레이스입니다.
- 앱은 이름, 이메일, 계정 정보를 진단 보고에 붙이지 않으며, 접속에 사용된 IP 주소는 저장되지 않습니다(앱의
sendDefaultPii=false 설정과 Sentry 프로젝트의 IP 주소 미저장 설정). 다만 수집 시점에 그 IP에서 유도된 위 대략적인 위치는 보고에 남습니다. 광고 식별자나 6항의 사용 통계는 함께 보내지 않습니다(6항의 통계는 다른 서비스로 전송되며 이 진단 정보와 연결되지 않습니다). 또한 진단 정보에는 앱 설치를 서로 구분하기 위한 무작위 식별자가 포함됩니다. 이 값은 광고 식별자가 아니며 다른 앱과 연결되지 않고, 앱을 삭제하면 사라집니다. 이 값 역시 같은 설치의 보고를 이어서 볼 수 있게 하므로 완전히 익명은 아닙니다. - 사용자의 학습 진도, 정답·오답 기록, 즐겨찾기와 앱 안에서 고른 학습 설정은 이 진단에 포함되지 않으며 계속 기기에만 저장됩니다.
- 진단 정보는 전송 중 암호화(HTTPS)되며, 미국에 위치한 Sentry 서버에 보관됩니다. 보관 기간은 Sentry의 데이터 보존 정책에 따라 제한되며(일정 기간 경과 후 삭제), 자세한 사항은 Sentry의 개인정보 처리방침을 따릅니다.
6. 앱 사용 통계 (Google Analytics for Firebase)
어떤 기능이 실제로 쓰이는지, 학습 블록이 어디에서 끝나는지, 구독 안내가 어디에서 열리는지를 파악해 앱을 개선하기 위해, KIIP Study는 이름·계정에 연결되지 않은 사용 통계를 Google Analytics for Firebase(Google이 제공하는 분석 서비스)로 전송합니다. Android 앱과 iOS 앱 2.2.3 이상에서 전송되며, 그보다 낮은 iOS 버전에서는 전송되지 않습니다. 계정이 없으므로 이 통계는 사람이 아니라 앱 설치 단위로 집계됩니다.
전송되는 정보는 다음과 같습니다:
- 화면 이동 — 홈·시험·어휘·설정 중 어느 탭을 보았는지.
- 학습 사용량 — 한 번에 몇 문제를 풀었는지, 그중 몇 개가 정답이었는지, 몇 초 걸렸는지, 시험과 어휘 중 무엇이었는지, 어느 단계였는지, 그리고 하루 무료 한도를 다 썼는지.
- 구독 관련 — 구독 안내 화면을 앱의 어느 지점에서 열었는지와 그때까지 푼 문제의 누적 개수, 결제를 시작했는지, 구매가 완료됐는지(상품 종류, 금액과 통화, 거래 번호, 신규 구매인지 요금제 변경인지).
- 앱 설정 상태 — 첫 설정(온보딩)을 마쳤는지와 그때 고른 언어, 그리고 현재의 앱 언어·학습 단계·구독 여부.
- Google이 자동으로 수집하는 항목 — 앱 첫 실행과 실행 시작 시점, 앱에 머문 시간, 앱 업데이트, Android에서는 앱 삭제, 기기 모델과 OS 버전, 기기의 언어 설정, 앱 버전, IP 주소에서 유추한 대략적인 위치(도시 수준까지), Android에서는 Google Play를 통한 설치 유입 경로 등이 포함됩니다. 기기 언어는 앱 안에서 고른 언어와 별개로 수집됩니다.
여기에 담기지 않는 것은 다음과 같습니다. 이름이나 이메일 같은 신원 정보(계정 자체가 없습니다), 사용자가 무엇을 공부했는지 — 즉 어떤 문항·단어였는지, 무엇이라 답했는지, 입력한 문구 — 그리고 광고 식별자입니다. 위 숫자는 얼마나 사용했는지를 말할 뿐무엇을 공부했는지는 말하지 않습니다.
- 이 통계에는 앱 설치마다 무작위로 부여되는 식별자(앱 인스턴스 ID)가 함께 전송되며, iOS(2.2.3 이상)에서는 같은 개발자의 앱을 구분하는 데 쓰이는 기기 식별자(IDFV)도 포함될 수 있습니다. 이 값들은 광고 식별자가 아니고 다른 회사의 앱과 연결되지 않으며, 앱을 삭제하면 사라집니다(IDFV는 같은 개발자의 다른 앱이 기기에 남아 있지 않은 경우). 다만 같은 설치의 활동을 이어서 볼 수 있게 하는 값이므로 완전히 익명인 정보는 아닙니다. iOS에서는 광고 개인화 목적의 신호 전송을 꺼 두었고, Android에서는 광고 ID 자체를 수집하지 않습니다.
- 정보는 전송 중 암호화(HTTPS)되며 미국에 위치한 Google 서버에 보관됩니다. Google Analytics 안의 이벤트 데이터는 보관 기간이 14개월로 설정되어 있어 그 이후 자동 삭제됩니다. 이와 별도로 원본 이벤트가 매일 개발자가 관리하는 Google BigQuery(미국)로 복사되는데, 이 사본도 앱 개선이라는 같은 목적에만 사용하며 같은 14개월이 지나면 삭제됩니다.
- 현재 앱에는 이 통계 수집을 끄는 설정이 없습니다. 앱을 삭제하면 수집이 중단되고 위 식별자도 함께 사라집니다 — 다만 Android에서는 삭제했다는 사실 자체가 마지막으로 한 번 기록될 수 있습니다. 자세한 사항은 Google의 개인정보처리방침과 Firebase 개인정보 및 보안 안내를 따릅니다.
7. KIIP Study가 이용하는 외부 서비스
5항의 진단 정보와 6항의 사용 통계 외에, KIIP Study는 다음 다섯 기능에서 기기 밖 서버와 통신합니다. 아래 어느 요청에도 이름·계정 등 사용자를 식별할 수 있는 정보를 앱이 담지 않습니다. 다만 인터넷 요청의 특성상 IP 주소 등 표준 연결 정보는 함께 전달됩니다.
- 인앱결제 — KIIP Study Pro 구매를 처리합니다. iOS는 StoreKit 2, Android는 Google Play 결제를 사용하며, 결제 정보는 Apple 또는 Google이 처리하고 앱은 거래 영수증만 확인합니다. 해당 정보에 대한 Apple 또는 Google의 사용은 각 사의 개인정보 처리방침의 적용을 받습니다.
- 학습 콘텐츠 내려받기 — 어휘 정의와 시험 문항은 KIIP Study의 콘텐츠 서버(Firebase Storage)에서 내려받습니다. 앱을 실행하거나 학습 언어를 바꿀 때 최신본인지 확인하며, 이미 받아 둔 내용이 최신이면 목록만 확인하고 끝냅니다. 뜻풀이는 지원하는 모든 언어가 아니라 현재 설정한 언어 하나만 받습니다.
- 음성·이미지 자산 — 어휘 전량에 원어민 음성 파일(mp3)이 있고, 일부 문항에는 삽화가 있습니다. 재생 버튼을 누르거나 삽화가 있는 문항이 나오면 그 파일만 콘텐츠 서버에서 내려받아 기기에 캐시하며, 같은 것을 다시 볼 때는 다시 받지 않습니다. 이 요청에 앱이 담아 보내는 정보는 어떤 파일이 필요한지뿐입니다. 발음 파일을 받지 못한 경우(오프라인 등)에만 iOS의 AVSpeechSynthesizer 또는 Android의 시스템 음성합성(TTS)이 대신 소리를 냅니다.
- 앱 업데이트 확인 — 새 버전이 나왔는지 확인합니다. iOS는 App Store에 앱 ID로 조회하고, Android는 Google Play의 업데이트 확인 기능을 사용합니다.
- 스토어 리뷰 요청 — 앱을 어느 정도 쓴 뒤 별점 리뷰를 남길지 묻는 창을 띄웁니다. 이 창은 운영체제가 그리며 (iOS는 StoreKit, Android는 Google Play의 인앱 리뷰), 앱은 리뷰를 남겼는지 여부조차 알지 못합니다.
이와 별도로, 사용자가 문제를 공유하기로 선택하면 그 문제를 여는 웹 주소가 만들어집니다. 이 주소에는 어떤 단어·문항인지, 학습 모드와 레벨, 그리고 공유한 사람이 그 문제를 맞혔는지 여부가 담깁니다. 앱이 이 주소를 서버로 보내지는 않으며, 사용자가 선택한 상대에게 전달됩니다. 받은 사람이 주소를 열면 다른 방문과 마찬가지로 kiipstudy.com 방문 기록이 남으며, 그 기록에는 위 정보가 담긴 주소가 그대로 포함됩니다.
8. 데이터 보관 및 삭제
KIIP Study의 학습 데이터는 사용자가 삭제할 때까지 디바이스에 보관됩니다. 앱 내에서 학습 기록을 초기화하거나, KIIP Study를 삭제(앱 제거)하여 앱이 저장한 모든 학습 데이터·즐겨찾기·설정을 한번에 제거할 수 있습니다. 학습 데이터에는 클라우드 컴포넌트가 없으므로 개발자 측에 학습 데이터의 사본은 존재하지 않습니다. 앞서 설명한 진단 정보(5항)에는 이름·계정이 붙어 있지 않으며 Sentry의 보존 정책에 따라 보관되고, 사용 통계(6항)는 Google Analytics 와 6항에 적은 BigQuery 사본 모두 14개월이 지나면 삭제됩니다. 두 기록에 붙는 식별자는 사람이 아니라 앱 설치에 붙어 있고 앱에는 사용자가 자신의 식별자를 확인하거나 알려줄 수 있는 기능이 없어, 이메일 주소만으로는 요청하신 분과 기록을 연결할 방법이 없습니다 — 앱을 삭제하면 이후의 수집이 중단되고 기존 기록과의 연결도 끊어집니다. 사용자가 직접 보낸 문의·문항 신고 메일은 예외로, 해당 메일과 거기 담긴 정보는 수신함에 남습니다 — 보관과 삭제는 13항에서 설명합니다.
9. 개인정보의 국외 이전
앞에서 설명한 전송 가운데 5항의 진단 정보와 6항의 사용 통계, 7항의 인앱결제·업데이트 확인·리뷰 요청은 국외에 있는 서버로 이루어집니다. 7항의 학습 콘텐츠·음성·이미지는 대한민국(서울 리전)에 있는 저장소에서 받지만, 그 저장소를 운영하는 자가 국외 사업자(Google LLC)이므로 함께 적습니다. 항목별로 정리하면 다음과 같습니다.
- 이전받는 자 — Google LLC(Google Analytics for Firebase, Firebase Storage, Google BigQuery, Google Play), Sentry, Inc., Apple Inc.(App Store·StoreKit). 각 사의 문의처는 해당 회사의 개인정보 처리방침에 안내되어 있습니다.
- 이전되는 국가와 확인된 보관 위치 — 5항의 진단 정보와 6항의 사용 통계(BigQuery 사본 포함)는 미국에 보관됩니다. 7항의 인앱결제·업데이트 확인·리뷰 요청은 Apple 또는 Google이 국외에서 처리합니다. 7항의 학습 콘텐츠·음성·이미지 파일은 대한민국 서울 리전의 저장소에 보관됩니다. 이 밖에 각 요청에 수반되는 연결 정보와 서비스 운영상의 기록은 Google 또는 Apple의 국외 인프라에서도 처리될 수 있으며, 그 처리 국가는 각 사의 개인정보 처리방침을 따릅니다.
- 이전되는 항목 — 5항의 진단 정보, 6항의 사용 통계, 7항의 각 요청에 담기는 정보(구매 영수증 확인, 내려받을 파일의 이름, 앱 버전 조회). 인터넷 요청의 특성상 IP 주소 등 표준 연결 정보가 함께 전달됩니다.
- 이전 시기 및 방법 — 앱 사용 중 해당 상황이 발생한 시점에 암호화된 연결(HTTPS)로 전송합니다. 사용 통계의 원본 이벤트는 이와 별도로 하루 한 번 BigQuery로 복사됩니다.
- 이전받는 자의 이용 목적 — 오류 진단과 앱 안정성 개선(Sentry), 기능 사용 현황 파악(Google Analytics), 학습 콘텐츠 제공·결제 처리·업데이트 확인·리뷰 요청(Google, Apple).
- 보유 및 이용 기간 — 5항과 8항에 적은 기간을 따릅니다. 결제 관련 정보와, 7항의 콘텐츠 내려받기·업데이트 확인·리뷰 요청에 수반되는 연결 정보 및 서비스 운영 기록의 보유 기간은 Apple 또는 Google의 정책에 따릅니다.
- 거부 방법과 그 효과 — 현재 앱에는 5항의 진단 정보나 6항의 사용 통계 전송을 개별적으로 끄는 설정이 없습니다. 앱을 삭제하면 이후 전송이 모두 중단되지만, 그때부터 앱을 이용할 수 없습니다. 7항 가운데 결제와 콘텐츠·음성·이미지 내려받기는 그 기능을 사용하지 않으면 전송도 일어나지 않습니다. 다만 업데이트 확인은 앱을 실행할 때 자동으로 이루어지고, 리뷰 요청은 일정 사용 조건을 충족하면 자동으로 뜨므로 이 둘을 개별적으로 끄는 설정은 없습니다.
위 국외 이전은 「개인정보 보호법」 제28조의8제1항제3호(정보주체와의 계약의 체결 및 이행을 위하여 개인정보의 처리위탁·보관이 필요한 경우)에 근거합니다. 같은 호 가목에 따라, 같은 조 제2항 각 호의 사항 — 이전되는 개인정보 항목, 이전되는 국가·시기 및 방법, 이전받는 자, 이전받는 자의 이용 목적 및 보유·이용 기간, 이전을 거부하는 방법·절차와 거부의 효과 — 을 법 제30조에 따른 이 개인정보 처리방침에 위와 같이 공개하며, 이에 따라 별도의 동의를 받지 않고 이전합니다. 14항의 웹사이트 방문 기록에 대한 국외 이전도 같은 근거에 따릅니다.
10. 기기 백업
KIIP Study는 동기화를 위해 iCloud, CloudKit, Google 계정 동기화 등을 사용하지 않습니다. 다만 시스템 설정에서 기기 백업(iOS의 iCloud 백업 또는 Android의 백업)이 활성화되어 있을 경우, 운영체제가 KIIP Study의 로컬 데이터를 표준 기기 백업에 포함할 수 있습니다. 이 설정은 사용자가 기기에서 직접 제어합니다.
11. 아동의 개인정보
KIIP Study는 만 14세 미만 아동을 대상으로 직접 마케팅하지 않으며, 아동으로부터 어떠한 정보도 고의로 수집하지 않습니다.
12. 정책 변경
본 개인정보 처리방침이 변경되는 경우 상단의 “최종 갱신” 날짜를 갱신합니다. 중요한 변경 사항은 App Store 및 Google Play의 릴리즈 노트에도 반영됩니다.
13. 연락처 및 앱 내 문의·문항 신고
KIIP Study를 제공하고 개인정보를 처리하는 자는 상호: Darak / 대표: 강상권입니다. 본 개인정보 처리방침에 대한 문의, 앱 내 “문의하기”와 문항 신고는 모두 다음 이메일로 접수됩니다: wer2774@gmail.com. 전화: 010-7302-2884.
iOS의 앱 내 문의·문항 신고는 사용자의 메일 앱을 열어 본문을 미리 채워줄 뿐이며, 앱이 스스로 전송하는 내용은 없습니다. 내용을 확인·수정한 뒤 사용자 본인의 메일 계정에서 직접 발송하며, 보낼지 여부는 전적으로 사용자의 선택입니다.
메일 본문에 미리 채워지는 정보는 다음과 같습니다:
- 앱 버전·빌드 번호, iOS 버전, 기기 모델 식별자(예: “iPhone15,4”), 앱 내 언어 및 시스템 언어 설정
- 문항 신고인 경우, 신고 대상 문항을 찾기 위한 식별자 한 줄(예: “word L3-먹다 / cloze”)
학습 기록과 구독 상태는 포함되지 않습니다. 메일을 보내면 사용자의 메일 계정 정보(발신 주소 등)가 메일 자체에 담겨 전달됩니다.
기기에 메일 앱이 설정되어 있지 않아 메일 화면을 열지 못한 경우, 앱은 보내려던 내용(수신 주소·제목·위 정보)을 기기의 클립보드에 복사하고 그 사실을 알려드립니다. 이때도 전송은 일어나지 않으며, 복사된 내용은 기기 안에만 있습니다.
접수된 메일은 문의 응대와 문항 오류 수정에만 사용하며, 마케팅이나 프로파일링에 사용하지 않습니다. 문의 처리에 필요한 기간 동안만 보관하고, 삭제를 요청하시면 당사 수신함에서 해당 메일을 삭제합니다. 보내주신 메일은 사용자의 메일 서비스와 당사 메일 서비스 제공업체를 거쳐 전달되며, 각 서비스의 개인정보 처리방침이 함께 적용됩니다.
14. 웹사이트(kiipstudy.com) 방문 시 수집되는 정보
1항부터 13항까지는 앱에 관한 설명입니다. 이 항은 웹사이트 kiipstudy.com — 소개 페이지, 블로그, 시험 일정, 그리고 앱에서 만든 공유 링크를 여는 /q·/eq 페이지 — 를 방문할 때 무엇이 수집되는지 설명합니다. 웹사이트에는 계정과 로그인이 없고, 광고와 광고 SDK도 없습니다.
가. 수집하는 항목
- 방문 통계(Google Analytics 4) — 방문한 페이지의 주소, 페이지 제목, 어디에서 들어왔는지(유입 경로), 방문 시각과 머문 시간, 브라우저·운영체제·기기 종류와 화면 크기, 브라우저의 언어 설정, 그리고 IP 주소에서 유추한 대략적인 위치(도시 수준까지)입니다. 공유 링크로 들어온 경우, 주소에 담긴 정보(어떤 단어·문항인지, 학습 모드와 레벨, 공유한 사람이 맞혔는지 여부)가 그 주소의 일부로 함께 기록됩니다. 이와 함께 사이트에서 한 일부 동작이 기록됩니다 — 앱 스토어 배지를 눌렀는지(어느 스토어인지, 페이지의 어느 위치에서 눌렀는지), 공유 버튼을 눌렀는지와 어떤 방식으로(기기의 공유 시트 또는 주소 복사) 공유를 마쳤는지 취소했는지, 공유 링크로 열린 문제에서 힌트를 열었는지와 그 단계, 그리고 그 문제를 풀었을 때 맞혔는지와 그 학습 모드·레벨입니다.
- 오류 진단(Sentry) — 오류 보고는 페이지에서 오류가 발생한 경우에만 전송됩니다. 오류 메시지와 스택 트레이스, 오류 직전의 동작 기록, 오류가 난 페이지 주소, 브라우저·운영체제 정보가 담깁니다. 이와 별도로, 오류가 없더라도 페이지를 열거나 사이트 안에서 이동할 때마다 배포 버전별 안정성을 집계하기 위한 세션 정보(무작위 세션 식별자, 시작 시각, 그 세션에서 오류가 났는지 여부)가 전송됩니다. 성능 추적과 세션 리플레이(화면 녹화)는 사용하지 않습니다. 접속에 사용된 IP 주소는 저장되지 않으며(웹사이트 Sentry 프로젝트의 IP 주소 미저장 설정), 다만 수집 시점에 그 IP에서 유도된 대략적인 위치는 보고에 남을 수 있습니다.
- 쿠키 — 위 방문 통계를 위해 Google Analytics 쿠키 (
_ga, _ga_로 시작하는 쿠키, 유효기간 각 2년)가 저장됩니다. 이 쿠키에 담긴 무작위 식별자로 같은 브라우저의 방문이 이어서 집계되며, 이름·계정과는 연결되지 않습니다. 이와 별도로 표시 언어 선택을 기억하기 위한 NEXT_LOCALE 쿠키가 저장됩니다 — 사이트 동작에 필요한 기능 쿠키이며 통계·광고에 쓰이지 않습니다. - 호스팅 기록 — 웹사이트는 Vercel Inc.의 호스팅에서 제공됩니다. 인터넷 통신의 특성상 모든 요청에 IP 주소·브라우저 정보 등 표준 연결 정보가 함께 전달되며, 서비스 운영 기록(로그)으로 일정 기간 보관될 수 있습니다.
이름·이메일 등 신원 정보는 수집하지 않습니다(웹사이트에 계정 자체가 없습니다). 광고 식별자도 수집하지 않습니다. 웹사이트는 기기에 저장된 앱의 학습 기록에 접근하지 않습니다.
나. 이용 목적 — 방문 통계는 어느 페이지가 얼마나 읽히는지 파악해 콘텐츠와 안내를 개선하는 데, 오류 진단은 웹사이트의 오류를 찾아 고치는 데만 사용합니다. 광고나 프로파일링에 사용하지 않으며 제3자에게 판매하지 않습니다.
다. 보유 및 이용 기간 — 방문 통계는 6항의 앱 사용 통계와 같은 Google Analytics 속성에서 처리되므로 같은 기간이 적용됩니다. Google Analytics 안의 이벤트 데이터는 14개월이 지나면 자동 삭제되고, 매일 Google BigQuery(미국)로 복사되는 사본도 같은 14개월이 지나면 삭제됩니다. 오류 진단 기록은 Sentry의 데이터 보존 정책에 따라 일정 기간이 지나면 삭제됩니다. 호스팅 운영 기록의 보관 기간은 Vercel의 정책에 따릅니다. 위 쿠키는 각 쿠키의 유효기간이 지나거나 사용자가 브라우저에서 삭제하면 사라집니다.
라. 국외 이전 — 위 정보는 Google LLC(Google Analytics·BigQuery), Sentry, Inc., Vercel Inc.가 미국에서 처리합니다. 각 사의 문의처는 해당 회사의 개인정보 처리방침에 안내되어 있습니다. 전송은 웹사이트를 방문한 시점에 암호화된 연결(HTTPS)로 이루어지며, BigQuery로의 복사는 하루 한 번입니다. 이전되는 항목·이용 목적·보유 기간은 위 가·나·다항과 같고, 거부 방법과 그 효과는 아래 마항과 같습니다. 이전의 근거는 9항 끝에 적은 것과 같습니다.
마. 거부 방법과 그 효과
- 방문 통계 — Google이 제공하는 Google Analytics 옵트아웃 브라우저 부가기능을 설치하거나, 브라우저의 확장 프로그램 등으로 Google Analytics 스크립트를 차단하면 전송되지 않습니다. 다만 쿠키만 차단하거나 삭제하는 것으로는 전송이 멈추지 않습니다 — 그 방문이 같은 브라우저의 이전 방문과 이어져 집계되지 않게 될 뿐입니다. 거부해도 웹사이트의 모든 내용과 기능은 그대로 이용할 수 있습니다.
- 오류 진단 — 사이트에 이를 개별적으로 끄는 설정은 없습니다. 브라우저 확장 프로그램 등으로 해당 요청을 차단해도 웹사이트 이용에는 영향이 없습니다.
- 언어 설정 쿠키와 호스팅 기록 — 사이트를 제공하는 데 필요해 개별적으로 끌 수 없습니다. 언어 쿠키는 브라우저에서 삭제할 수 있으며, 삭제하면 다음 방문 때 브라우저의 언어 설정으로 다시 판단합니다.
웹사이트 방문 기록에 대한 열람·삭제 등의 요청과 이 항에 대한 문의는 13항의 이메일로 접수합니다. 다만 위 기록에는 이름·계정이 붙어 있지 않고 브라우저 쿠키의 무작위 식별자로만 구분되므로, 이메일 주소만으로는 요청하신 분과 기록을 연결할 방법이 없습니다 — 브라우저에서 쿠키를 삭제하면 이후 수집이 새 식별자로 이루어지고 기존 기록과의 연결도 끊어집니다.
15. 시행일자
시행일자: 2026년 8월 10일
English
1. Overview
KIIP Study is a study app for iOS and Android that helps foreign residents in Korea prepare for the Korean Immigration and Integration Program (KIIP) exam. This policy explains what the app does with the information you generate while using it. Your learning history is stored on your device. KIIP Study does not run any learning servers and has no accounts; it carries no ads, no advertising SDK, and collects no advertising identifier. Two kinds of information about you are collected and sent by the app itself: diagnostic information used to improve app stability (see section 5), and usage analytics used to understand which features get used (see section 6) — the analytics are sent from the Android app and from iOS 2.2.3 or later. Neither one carries what you studied — which questions or words you saw, or how you answered them. Separately, the app communicates with outside servers to do its job — study content and audio/image downloads, in-app purchases, update checks, and review prompts — as described in section 7. Inquiry and question-report emails, which you choose to send yourself, are described in section 13, and question share links in section 7. Sections 1 through 13 describe the app. What is collected when you visit the website (kiipstudy.com) — visitor analytics (Google Analytics), error diagnostics (Sentry), the cookies it stores, and how to refuse them — is described separately in section 14.
2. Information Stored in the App
Everything KIIP Study stores about you on your device is learning data you generate by using the app:
- Study progress (level, session count)
- Per-question right/wrong history and SRS (spaced repetition) state
- Words you favorite or bookmark
- App preferences (interface language, active study levels, active question types)
This learning information itself is stored locally on your device, and the app never uploads that record to KIIP Study or any third party — which questions or words you saw and how you answered them does not leave your device. The usage analytics in section 6 do, however, include aggregate numbers derived from that activity: how many questions you answered in one sitting, how many of them were correct, how long it took, and your current stage and app language, among the items listed in section 6. Two further things travel only when you choose to send them: an in-app inquiry or question report carries the app language setting pre-filled into that email as diagnostic information (see section 13), and a question share link carries that question and whether you answered it correctly (see section 7).
3. Permissions
The only system permission KIIP Study requests is permission to send study reminders; declining it means you get no reminders, while everything else keeps working. The app does not request access to the microphone, camera, location, photo library, contacts, calendar, or health data. It also does not request or collect advertising identifiers (IDFA on iOS, Advertising ID on Android): on iOS the advertising-identifier capability is inert in the app, so it never presents an App Tracking Transparency (ATT) prompt, and on Android the advertising-ID permissions are removed from the app and the collection feature is turned off. Note that even without location permission, the coarse location inferred from your IP address is recorded as described in sections 5 and 6.
4. Where Your Data Lives
All learning data is stored in your device's local storage (SwiftData and UserDefaults on iOS; an on-device local database and preference store on Android). The app never uploads your learning data itself to any server. KIIP Study does not use any third-party SDKs for advertising or remote configuration. What the app itself collects and sends about you is diagnostic information used to improve app stability (section 5) and usage analytics (section 6), described in the next two sections. Separately, the app communicates with outside servers for study content, audio and image downloads, in-app purchases, update checks, and review prompts, described in section 7. Inquiry and question-report emails that you choose to send yourself are described in section 13.
5. Crash and Error Diagnostics (Sentry)
To improve app stability and performance, KIIP Study sends only diagnostic information that is not tied to your name or account to Sentry (a third-party error-monitoring service provider) on both iOS and Android. This includes crash and error reports. On iOS it also sends session information — a count of when the app is opened and closed — and a sampled subset of performance traces captured during normal use. Android sends neither of those.
- The information sent is limited to technical diagnostics, and includes the error message, a stack trace, when the error happened and a record of what the app was doing just before it, your device and OS type along with device state (screen size and orientation, battery level and charging status, available memory, and on Android the network connection type), your device's language and time-zone settings, the app version and build number, a build-environment label, a coarse location (up to city level) inferred from your IP address, and — on iOS — session information and some performance traces.
- The app does not attach your name, email, or account details to a diagnostic report, and the IP address used for the connection is not stored (the app's
sendDefaultPii=falsesetting plus the IP-address storage prevention setting on our Sentry project). The coarse location derived from that IP at collection time does, however, remain in the report. No advertising identifiers and none of the usage analytics described in section 6 are sent with it (those go to a different service and are not linked to these diagnostics). Diagnostics also include a random identifier that distinguishes one app installation from another. It is not an advertising identifier, is not linked to other apps, and disappears when you uninstall the app. That identifier also lets one installation's reports be followed over time, so these are not fully anonymous either. - Your study progress, right/wrong history, favorites, and the study preferences you set inside the app are not included in these diagnostics and continue to be stored only on your device.
- Diagnostics are encrypted in transit (HTTPS) and stored on Sentry servers located in the United States. They are retained for a limited period under Sentry's data-retention policy (deleted after a set period) and are otherwise governed by Sentry's privacy policy.
6. Usage Analytics (Google Analytics for Firebase)
To learn which features actually get used, where a study block ends, and where the subscription screen gets opened — and to improve the app accordingly — KIIP Study sends usage analytics that are not tied to your name or account to Google Analytics for Firebase (an analytics service provided by Google). This happens on Android and on iOS 2.2.3 or later; earlier iOS versions send nothing of the kind. Because there are no accounts, these statistics are counted per app installation rather than per person.
What is sent:
- Screen navigation — which of the Home, Exam, Vocabulary, and Settings tabs you viewed.
- Study usage — how many questions you answered in one sitting, how many were correct, how many seconds it took, whether it was exam or vocabulary practice, which stage, and whether you used up the free daily limit.
- Subscription activity — where in the app the subscription screen was opened from and how many questions you had answered in total by then, whether checkout was started, and whether a purchase completed (product, amount and currency, transaction ID, and whether it was a new purchase or a plan change).
- App settings state — whether you finished first-run setup and the language you chose there, plus your current app language, study stage, and subscription status.
- Collected automatically by Google — first launch and app-open events, time spent in the app, app updates, app removal on Android, device model, OS version, your device's language setting, app version, a coarse location (up to city level) inferred from your IP address, and on Android the install source reported by Google Play, among others. Your device language is collected separately from the language you pick inside the app.
What is not included: identity details such as your name or email (there are no accounts); what you studied — which question or word it was, how you answered, or anything you typed; and advertising identifiers. The numbers above describe how much you used the app, not what you studied.
- A random identifier assigned per app installation (the app instance ID) is sent along with these statistics, and on iOS 2.2.3 or later a device identifier that distinguishes apps from the same developer (IDFV) may be included as well. These are not advertising identifiers, are not linked to other companies' apps, and disappear when you uninstall the app (for the IDFV, once no other app from the same developer remains on the device). They do let one installation's activity be followed over time, so this information is not fully anonymous. On iOS, signals for ad personalization are turned off; on Android, no advertising ID is collected at all.
- The data is encrypted in transit (HTTPS) and stored on Google servers located in the United States. Inside Google Analytics, event data retention is set to 14 months, after which it is deleted automatically. Separately, raw events are copied daily into a Google BigQuery dataset we control (also in the United States); that copy is used only for the same purpose of improving the app and is deleted after the same 14 months.
- The app currently has no setting to turn this collection off. Uninstalling the app stops the collection and retires the identifier above — although on Android the fact that you uninstalled may be recorded once, as a last event. Google's handling is governed by Google's privacy policy and the Firebase privacy and security notice.
7. External Services KIIP Study Uses
Besides the diagnostics in section 5 and the usage analytics in section 6, KIIP Study communicates with servers outside your device for five features. The app does not put your name, account, or other identifying information into any of these requests. That said, as with any internet request, standard connection details such as your IP address are transmitted as part of how the network works.
- In-app purchases — handle the purchase of KIIP Study Pro. iOS uses StoreKit 2 and Android uses Google Play Billing; payment information is processed by Apple or Google, and the app only sees the transaction receipt. Apple's or Google's use of this information is governed by their respective privacy policies.
- Study content downloads — word definitions and exam questions are downloaded from KIIP Study's own content server (Firebase Storage). The app checks for the current version when you open it or change your study language; if what you already have is current, it only checks the listing and stops there. Definitions are downloaded for the one language you have set, not for every language offered.
- Audio and image files — every word has a native-speaker audio file (mp3), and some questions have illustrations. Tapping play, or reaching a question that has one, downloads just that file from the content server and caches it on your device, so the same one isn't downloaded again. The only information the app puts into that request is which file is needed. Only if a pronunciation file can't be fetched (e.g., you're offline) does the system voice — AVSpeechSynthesizer on iOS or the system text-to-speech engine on Android — speak the word instead.
- App update checks — the app checks whether a newer version is available. iOS queries the App Store by app ID; Android uses Google Play's update check.
- Store review prompts — after you have used the app for a while, it asks whether you would like to leave a rating. The prompt is drawn by the operating system (StoreKit on iOS, Google Play In-App Review on Android), and the app does not even learn whether you left a review.
Separately, if you choose to share a question, the app builds a web address that opens it. That address carries which word or question it is, the study mode and level, and whether you answered it correctly. The app does not send this address to any server — it goes to whomever you choose. When the recipient opens it, that visit is recorded on kiipstudy.com like any other visit, and that record includes the address itself with the details above in it.
8. Data Retention and Deletion
Your KIIP Study learning data stays on your device until you delete it. You can reset your study history from within the app, or you can uninstall KIIP Study to delete every piece of learning data, favorite, and preference the app has stored. Because your learning data has no cloud component, there is no copy of it on our side. The diagnostics described above (section 5) carry no name or account and are retained according to Sentry's retention policy; the usage analytics (section 6) are deleted after 14 months, both in Google Analytics and in the BigQuery copy described in section 6. The identifiers attached to both belong to an app installation rather than to a person, and the app gives you no way to see or share your own identifier, so an email address alone cannot connect you to those records — uninstalling the app stops any further collection and breaks the link to what was already collected. Inquiry and question-report emails you send yourself are the exception: those messages and the information in them stay in our inbox — see section 13 for how we retain and delete them.
9. International Transfers of Personal Data
Of the transfers described above, the diagnostics in section 5, the analytics in section 6, and the in-app purchases, update checks, and review prompts in section 7 go to servers outside Korea. The study content, audio, and images in section 7 are served from storage inside Korea (the Seoul region), but the operator of that storage is a company outside Korea (Google LLC), so it is listed here as well. Item by item:
- Recipients — Google LLC (Google Analytics for Firebase, Firebase Storage, Google BigQuery, Google Play), Sentry, Inc., and Apple Inc. (App Store and StoreKit). Contact details for each are given in that company's own privacy policy.
- Destination countries and confirmed storage locations — the diagnostics in section 5 and the analytics in section 6 (including the BigQuery copy) are held in the United States. The in-app purchases, update checks, and review prompts in section 7 are handled by Apple or Google outside Korea. The study content, audio, and image files in section 7 are held in storage in the Seoul region of the Republic of Korea. Beyond that, connection details accompanying each request and operational records of the service may also be processed on Google's or Apple's infrastructure outside Korea, in the countries set out in their own privacy policies.
- Data transferred — the diagnostics in section 5, the usage analytics in section 6, and whatever each request in section 7 carries (verifying a purchase receipt, the name of a file to download, an app-version lookup). As with any internet request, standard connection details such as your IP address travel along with it.
- When and how — at the moment the relevant event occurs while you use the app, over an encrypted connection (HTTPS). Separately, raw analytics events are copied to BigQuery once a day.
- Why the recipients process it — error diagnostics and app stability (Sentry); understanding feature usage (Google Analytics); delivering study content, processing payments, checking for updates, and review prompts (Google, Apple).
- Retention — as stated in sections 5 and 8. Payment-related information, and the connection details and operational records that accompany the content downloads, update checks, and review prompts in section 7, are retained under Apple's or Google's own policies.
- How to refuse, and what happens if you do — the app currently has no setting that turns off the section 5 diagnostics or the section 6 analytics individually. Uninstalling the app stops all of it, but you can no longer use the app. Of the communications in section 7, payments and the content, audio, and image downloads only happen when you use those features. Update checks, however, run automatically when you open the app, and a review prompt can appear automatically once you have used the app enough, so there is no separate setting to turn those two off.
These transfers are made under Article 28-8(1)3 of Korea's Personal Information Protection Act (consignment of processing or storage that is necessary to enter into and perform a contract with the data subject). As item (a) of that subparagraph allows, we disclose the matters listed in Article 28-8(2) — the categories of personal data transferred; the destination country, timing, and method; the recipients; each recipient's purpose and retention period; and how to refuse a transfer, the procedure, and the effect of refusing — in this privacy policy, published under Article 30 of that Act, as set out above; on that basis the transfers are made without separate consent. The transfers involved in visits to the website (section 14) rest on the same basis.
10. Device Backups
KIIP Study does not use iCloud, CloudKit, or Google account sync for syncing. However, your operating system may include KIIP Study's local data in standard device backups if you have device backups (iCloud Backup on iOS or backups on Android) enabled in your system settings. You control that setting on your device.
11. Children's Privacy
KIIP Study is not directed at children under 14 and does not knowingly collect any information from children.
12. Changes to This Policy
If we change this policy, we will update the “Last updated” date at the top of this page. Material changes will also be reflected in the app's release notes on the App Store and Google Play.
13. Contact, In-App Inquiries, and Question Reports
KIIP Study is provided by Darak (sole proprietorship), represented by Sangkwun Kang, which is responsible for the personal data described here. Questions about this policy, the in-app “Contact us” option, and question reports all reach us at the same address: wer2774@gmail.com. Phone: +82 10-7302-2884.
On iOS, the in-app inquiry and question report features open your own mail app with a pre-filled message. The app itself sends nothing. You review and edit the message and send it from your own mail account, and whether to send it at all is entirely your choice.
The pre-filled message contains:
- App version and build number, iOS version, device model identifier (e.g. “iPhone15,4”), and your in-app and system language settings
- For a question report, one line identifying the question being reported (e.g. “word L3-먹다 / cloze”)
Your study history and subscription status are not included. When you send the message, your mail account details (such as your sending address) travel with the email itself.
If no mail app is set up on your device and the compose screen cannot open, the app copies what it would have sent (the recipient address, subject, and the information above) to your device's clipboard and tells you it did. Nothing is transmitted in this case either — the copied text stays on your device.
We use the mail we receive only to answer your inquiry and to fix reported content errors — never for marketing or profiling. We keep it only as long as handling your inquiry requires, and we delete it from our inbox if you ask us to. Mail you send passes through your own email service and our email provider, and each of their privacy policies applies to it as well.
14. What the Website (kiipstudy.com) Collects
Sections 1 through 13 describe the app. This section describes what is collected when you visit the website kiipstudy.com — the landing pages, the blog, the exam schedule, and the /q and /eq pages that open a share link made in the app. The website has no accounts and no sign-in, and it carries no ads and no advertising SDK.
a. What is collected
- Visitor analytics (Google Analytics 4) — the address of the page you visited, the page title, where you came from (the referrer), when you visited and how long you stayed, your browser, operating system, device type and screen size, your browser's language setting, and an approximate location inferred from your IP address (to city level). If you arrived through a share link, whatever that address carries — which word or question it is, the study mode and level, and whether the sharer answered it correctly — is recorded as part of the address. A few actions on the site are recorded as well: whether you clicked an app-store badge (which store, and where on the page you clicked it); whether you pressed the share button, by which method (your device's share sheet or copying the address), and whether you completed or cancelled the share; whether you opened a hint on a question from a share link and how far; and, when you answer that question, whether you got it right along with its study mode and level.
- Error diagnostics (Sentry) — an error report is sent only when a page hits an error. It carries the error message and stack trace, a record of what happened just before it, the address of the page where it occurred, and your browser and operating system. Separately, and even when nothing goes wrong, opening a page or navigating within the site sends session information used to track the stability of each release: a random session identifier, when it started, and whether that session hit an error. We do not use performance tracing or session replay. The IP address used to connect is not stored (the website's Sentry project has IP-address storage turned off), though the approximate location derived from that IP at collection time may remain in the report.
- Cookies — the analytics above store Google Analytics cookies in your browser (
_ga and cookies beginning with _ga_, each lasting two years). The random identifier they hold is what lets repeat visits from the same browser be counted together; it is not tied to a name or account. Separately, a NEXT_LOCALE cookie remembers the display language you chose — a functional cookie the site needs, not used for analytics or advertising. - Hosting records — the website is served from hosting operated by Vercel Inc. As with any internet request, every request carries standard connection details such as your IP address and browser information, which may be kept for a period as operational logs.
We collect no identifying information such as a name or email address (the website has no accounts at all), and no advertising identifier. The website does not have access to the study history the app keeps on your device.
b. Why — we use the visitor analytics only to see which pages get read and how much, so we can improve the content and the guidance, and the error diagnostics only to find and fix errors on the website. We do not use either for advertising or profiling, and we do not sell them to anyone.
c. How long it is kept— the visitor analytics are processed in the same Google Analytics property as the app usage analytics in section 6, so the same periods apply: event data inside Google Analytics is deleted automatically after 14 months, and the copy exported daily to Google BigQuery (United States) is deleted after the same 14 months. Error diagnostics are deleted after a limited period under Sentry's data-retention policy. Hosting operational records are retained under Vercel's own policy. The cookies above disappear when they expire or when you delete them in your browser.
d. International transfers— the information above is processed in the United States by Google LLC (Google Analytics and BigQuery), Sentry, Inc., and Vercel Inc. Contact details for each are given in that company's own privacy policy. It is transmitted over an encrypted connection (HTTPS) at the moment you visit, and the BigQuery copy is made once a day. What is transferred, why, and for how long are as set out in a, b, and c above; how to refuse and what happens if you do are in e below. The legal basis is the one stated at the end of section 9.
e. How to refuse, and what happens if you do
- Visitor analytics — installing Google's Google Analytics opt-out browser add-on, or blocking the Google Analytics script with a browser extension, stops them. Blocking or deleting cookies alone does not stop them — it only means the visit is no longer counted together with earlier visits from the same browser. Refusing costs you nothing: every part of the website keeps working.
- Error diagnostics — the site has no setting that turns these off on their own. Blocking those requests with a browser extension has no effect on your use of the website.
- The language cookie and hosting records — these are needed to serve the site and cannot be turned off individually. You can delete the language cookie in your browser; if you do, your next visit falls back to your browser's language setting.
Requests to access or delete website visit records, and questions about this section, reach us at the email address in section 13. Note, however, that these records carry no name or account and are distinguished only by the random identifier in a browser cookie, so an email address alone cannot connect you to them — deleting the cookies in your browser means later visits are collected under a new identifier and the link to what was already collected is broken.
15. Effective Date
Effective: August 10, 2026