개인정보처리방침
시행일자: 2026-07-07
Keyling(이하 “본 서비스”)는 「개인정보 보호법」 등 관련 법령을 준수하며, 정보주체의 개인정보를 안전하게 보호하기 위해 다음과 같은 처리방침을 두고 있습니다.
1. 처리하는 개인정보의 항목
본 서비스는 다음의 개인정보 항목을 처리합니다.
(1) 회원 가입 및 인증
- 이메일 주소
- 비밀번호 (해시 처리되어 저장됨)
- Supabase 사용자 식별자
(2) 키보드 입력 캡처
- Keyling 키보드의 한국어 입력 모드에서 사용자가 입력한 한글 텍스트 (한글 문자가 1자 이상 포함된 경우에 한함)
- 안전 입력 필드(
isSecureTextEntry가 true인 비밀번호 등), 이름 필드(전체/접두사/접미사/이름/중간이름/성/별칭), 이메일 필드, 전화번호 필드, URL 필드, 사용자명 필드, 신용카드 번호 필드, 일회용 인증번호 필드, 주소 필드(전체 주소/주소 1행/주소 2행/시/도/우편번호/국가), 조직명 필드, 직책 필드, 일시/항공편 번호/배송 추적 번호 필드 등 27개 콘텐츠 유형 및 숫자 키패드/전화 키패드/소수점 키패드/이름·전화 키패드/이메일 키보드/URL 키보드/숫자 키패드(ASCII) 등 7개 키보드 유형은 캡처 대상에서 제외됩니다. - 추가 안전장치: 한글이 포함되어 있더라도 영어(로마자) 문자가 하나라도 들어 있거나, 3자 이상 연속된 숫자(전화번호·인증번호·카드번호 등)가 포함된 메시지는 일반 입력 필드에서도 캡처하지 않습니다. 즉, 순수 한글 메시지만 캡처됩니다.
(3) 학습 데이터
- 캡처된 한글 텍스트로부터 생성된 학습 카드 (한국어 원문, 영문 번역, 중점 항목, 연습 문제 등)
(4) 푸시 알림
- APNs(Apple Push Notification service) 기기 토큰
- 푸시 알림 전송 로그 (전송 상태, 시도 시각 등)
(5) 음성 입력 (말하기 연습)
- 사용자가 말하기 연습 단계에서 영어 문장을 소리 내어 말할 때 마이크로 입력되는 음성. 해당 음성은 기기 운영체제의 음성 인식 기능(iOS의 Apple 음성 인식 프레임워크(Speech), Android의 시스템 음성 인식기 — 대개 Google)을 통해 실시간으로 텍스트로 변환됩니다. 기기에 해당 영어(en-US) 온디바이스 인식 모델이 설치되어 있으면 음성은 전적으로 기기 내에서 처리되어 외부로 전송되지 않습니다. 그러나 한국어 환경의 Android 기기에는 영어 온디바이스 인식 모델이 설치되어 있지 않은 경우가 많아, 이러한 기기에서는 인식을 위해 음성이 시스템 음성 인식기 제공자(대개 Google)의 서버로 전송됩니다(제5조의2 참조). 말하기 연습이 진행되는 동안 마이크는 사용자가 중지하거나 문장 인식이 완료될 때까지 연속으로 음성을 수집합니다.
- 변환된 텍스트는 정답 문장과의 발음 비교(채점) 목적으로만 사용되며, 음성과 변환 텍스트 모두 본 서비스의 서버나 데이터베이스에 저장되지 않고 인식 직후 폐기됩니다.
(6) 사용 분석 및 진단 정보
- 익명 사용 분석(PostHog): 서비스 개선을 위해 수집하는 익명 앱 사용 이벤트(화면 조회, 기능 사용 여부, 동작 횟수 등). 개인을 식별하지 않는 임의의 익명 식별자에만 연결되며, 사용자 계정·이메일·캡처된 한글 텍스트·학습 콘텐츠는 일절 포함되지 않습니다.
- 오류 진단(Sentry): 앱의 오류 및 비정상 종료(크래시) 진단 정보(오류 유형, 발생 위치, 기기 모델·OS 버전·앱 버전 등). 개인정보(PII)나 캡처된 텍스트·학습 콘텐츠는 포함되지 않습니다.
본 서비스는 위 항목 외에 위치 정보, 광고 식별자(IDFA), 연락처, 사진·동영상 등을 수집하지 않으며, 사용자를 교차 앱·교차 사이트로 추적(tracking)하거나 데이터 브로커에 정보를 제공하지 않습니다. 위 (6)항의 사용 분석·진단 정보는 모두 익명으로 처리되어 사용자의 신원에 연결되지 않습니다.
2. 개인정보의 처리 목적
본 서비스는 수집한 개인정보를 다음 목적을 위해 처리하며, 목적 외 용도로는 이용하지 않습니다.
- 계정 인증 및 관리
- 사용자가 자연스럽게 입력한 한국어 텍스트를 분석하여 개인 맞춤형 영어 학습 카드 생성
- 생성된 학습 카드를 푸시 알림 및 앱 내 덱(deck)을 통해 제공
- 학습 카드 텍스트(영문 번역·중점 항목·예문)를 음성으로 합성하여 사용자가 소리로 들을 수 있도록 제공
- 말하기 연습에서 사용자가 말한 영어 문장을 인식·채점하여 학습 피드백 제공
- 서비스 품질 개선을 위한 익명 사용 분석 및 오류 진단
3. 개인정보의 보유 및 이용 기간
- 캡처된 한글 텍스트 및 생성된 학습 카드: 사용자가 개별 학습 카드를 삭제하거나 계정 전체를 삭제할 때까지 보유
- 합성 음성(TTS): 학습 카드 텍스트로부터 생성된 음성은 사용자가 아니라 텍스트의 해시값으로 식별되는 공용 캐시로 저장되어, 동일한 텍스트는 어느 사용자에게나 동일한 음성으로 제공됩니다. 이 음성은 특정 계정에 연결되지 않으며, 계정 삭제 시 해당 음성을 사용자와 연결할 수 있는 유일한 정보인 학습 데이터가 삭제되어 캐시된 음성은 익명 상태로 남습니다.
- 계정 정보 (이메일, 비밀번호 해시, 사용자 식별자): 계정 삭제 시까지 보유. 계정 삭제 시 모든 관련 학습 데이터가 데이터베이스의 ON DELETE CASCADE 제약에 따라 즉시 함께 삭제됩니다.
- APNs 기기 토큰: 사용자가 알림 권한을 해제하거나 계정을 삭제할 때까지 보유
- 푸시 알림 전송 진단 로그: 알림 전송의 성공·실패 상태와 오류 코드 등으로 구성된 기술 진단 기록(알림 내용 미포함)으로, 전송 문제 진단에 필요한 기간 동안만 보관합니다.
- 수업 생성 진단 로그: 수업 생성 요청의 성공·건너뜀·실패 상태와 사유 코드, 소요 시간 등으로 구성된 기술 진단 기록(입력하신 문장 등 메시지 내용 미포함)으로, 생성 문제 진단에 필요한 기간 동안만 보관합니다.
- 요청 횟수 카운터: 과도한 요청을 제한하기 위한 단기 카운터로, 분~일 단위의 유효기간이 지나면 자동 삭제됩니다.
- 익명 사용 분석·진단 정보: 각 수탁업체(PostHog, Sentry)의 보관 정책에 따라 보관되며, 사용자 신원에 연결되지 않습니다.
4. 개인정보의 제3자 제공
본 서비스는 정보주체의 동의 없이는 개인정보를 제3자에게 제공하지 않습니다.
5. 개인정보처리의 위탁
본 서비스는 원활한 서비스 제공을 위해 다음과 같이 개인정보 처리 업무를 외부 사업자에게 위탁하고 있습니다.
| 수탁업체 | 위탁 업무 | 위탁 항목 | 보관 위치 |
|---|---|---|---|
| Vercel Inc. | 학습 카드 생성 API 호스팅 | 캡처된 한글 텍스트, 인증 토큰 (전송·처리 시점에 한함, Vercel 저장소에 영구 저장되지 않음) | 미국 |
| Google LLC (Gemini API) | 한글 텍스트로부터 영어 학습 카드 생성을 위한 자연어 처리; 학습 카드 텍스트의 음성 합성(TTS); 키보드 입력 문장의 실시간 영어 변환(작문 보조) | 캡처된 한글 텍스트; 음성 합성을 위한 학습 카드 텍스트(영문 번역·중점 항목·예문); 키보드로 입력 중인 문장(익명·계정 미연결, 실시간 변환 목적) | 미국 |
| Supabase Inc. | 인증 및 데이터베이스 호스팅 | 이메일, 비밀번호 해시, 사용자 식별자, 학습 카드, APNs 기기 토큰 | 미국 |
| Apple Inc. | 푸시 알림 전송 (APNs) | APNs 기기 토큰, 알림 페이로드(학습 카드 미리보기) | 미국 |
| PostHog, Inc. | 익명 사용 분석 | 익명 앱 사용 이벤트(개인 식별 정보 미포함) | 미국 |
| Functional Software, Inc. (Sentry) | 오류 및 비정상 종료(크래시) 진단 | 오류·크래시 진단 정보(개인 식별 정보 미포함) | 미국 |
| Upstash, Inc. | 요청 횟수 제한(레이트 리미팅) 및 비용 한도 관리 | 가명처리된 사용자 식별자가 포함된 단기 요청 카운터(학습 카드 생성·음성 합성 요청 횟수; 분~일 단위 유효기간 경과 후 자동 삭제) | 미국 |
수탁업체와의 계약 시 「개인정보 보호법」에 따라 개인정보가 안전하게 처리되도록 필요한 사항을 규정하고 있으며, 위탁 처리 사실은 본 처리방침을 통해 공개합니다.
본 서비스는 Google Gemini API를 유료로 이용하고 있으며, Google의 Gemini API 이용약관에 따라 본 서비스에서 Gemini API로 전송된 데이터는 Google의 머신러닝 모델 학습에 사용되지 않습니다. 다만 말하기 연습의 음성 인식은 위 Gemini API가 아닌 기기 운영체제의 음성 인식 기능을 이용하며, 이는 본 서비스의 처리위탁에 해당하지 않으므로 위 표에 포함되지 않습니다. 자세한 내용은 제5조의2를 참조하시기 바랍니다.
키보드 사용 중 표시되는 실시간 영어 변환(작문 보조) 기능은 위 학습 카드 생성과 달리 다음과 같이 처리됩니다: 회원님이 입력 중인 문장이 계정 정보 없이 익명으로 Google Gemini API(미국)로 전송되어 실시간으로 영어로 변환되며, 그 결과만 키보드 위에 표시됩니다. 이 문장은 본 서비스 서버에 저장되지 않고 회원님의 계정·신원과 연결되지 않으며, Google은 이를 머신러닝 학습이나 사람의 검토에 사용하지 않고 오·남용 및 정책 위반 방지 목적으로만 최대 약 55일간 일시 보관한 뒤 삭제합니다. 이 기능은 Keyling 키보드의 ‘전체 접근 허용’이 켜져 있을 때만 동작하며, 회원님이 ‘저장’ 버튼을 눌러 직접 보관한 문장만 회원님의 계정에 연결되어 분석을 거쳐 학습 카드로 만들어집니다.
위 실시간 영어 변환과 학습 카드 생성은 모두 키보드의 ‘학습 모드’가 켜져 있을 때만 이루어집니다. 회원님은 키보드의 학습 모드 버튼을 눌러 언제든지 학습 모드를 끌 수 있으며, 학습 모드가 꺼져 있는 동안에는 실시간 영어 변환과 학습 카드 생성이 모두 중단되어 입력하신 어떠한 문장도 기기 밖으로 전송되지 않습니다.
5-2. 기기 운영체제 음성 인식 서비스에 관한 안내
말하기 연습의 음성 인식은 본 서비스가 처리를 위탁한 것이 아니라, 이용자 기기 운영체제에 내장된 음성 인식 기능(iOS: Apple의 음성 인식 프레임워크(Speech), Android: 기기에 기본으로 설정된 시스템 음성 인식 서비스 — 대개 Google)을 이용합니다.
- 기기가 영어(en-US) 온디바이스 인식을 지원하거나(iOS) 영어(en-US) 온디바이스 인식 모델이 설치되어 있는 경우(Android), 음성은 기기 내에서만 처리되며 외부로 전송되지 않습니다.
- 그렇지 않은 경우 음성은 해당 운영체제·음성 인식 서비스 제공자의 서버(미국 등 국외 소재)로 전송되어 텍스트로 변환됩니다. 이때 해당 제공자(iOS: Apple, Android: 대개 Google)는 본 서비스의 수탁자가 아니라 독립적인 개인정보처리자로서 자신의 개인정보처리방침에 따라 음성을 처리합니다. (Apple: apple.com/kr/legal/privacy, Google: policies.google.com/privacy)
- 본 서비스는 이 과정에서 음성 원본을 수신하거나 저장하지 않으며, 변환된 텍스트도 채점 직후 폐기합니다(제1조 제(5)항 참조).
- Android 이용자는 기기 설정에서 영어(en-US) 온디바이스 인식 모델을 설치하여 음성이 기기 밖으로 전송되지 않도록 하거나(예: 설정 → 시스템 → 언어 및 입력 → 음성 인식; 경로는 기기 제조사에 따라 다를 수 있음), 기기의 기본 음성 인식 서비스를 다른 제공자로 변경할 수 있습니다.
6. 개인정보의 국외 이전
본 서비스의 수탁업체는 모두 미국에 소재하므로 개인정보가 미국으로 이전됩니다.
- 이전되는 항목: 위 제5조 표 참조
- 이전 국가: 미국
- 이전 일시 및 방법: 사용자가 한글 텍스트를 캡처하는 시점 또는 계정 활동 시점에 HTTPS를 통해 실시간으로 이전됨
- 수탁업체 정보: 위 제5조 표 참조
- 이용 목적 및 보유 기간: 본 처리방침 제2조 및 제3조 참조
- 이전 거부 방법: 관련 기능(키보드 캡처, 말하기 연습 등)의 사용 중지, 계정 삭제 또는 개인정보 보호책임자(제9조) 문의를 통해 국외 이전을 거부할 수 있습니다. 다만 이 경우 해당 기능의 이용이 제한될 수 있습니다.
아울러 말하기 연습에서 기기 운영체제의 음성 인식을 이용하는 경우, 음성이 기기에서 해당 음성 인식 서비스 제공자(iOS: Apple, Android: 대개 Google)의 국외(미국 등) 서버로 직접 전송될 수 있습니다. 이는 본 서비스의 위탁에 따른 이전이 아니라 기기 운영체제 기능에 의한 전송이며, 자세한 내용은 제5조의2를 참조하시기 바랍니다.
7. 정보주체와 법정대리인의 권리·의무 및 행사방법
정보주체는 언제든지 다음의 권리를 행사할 수 있습니다.
- 개인정보 열람: 앱 내 덱(deck) 화면에서 본인의 학습 카드 전체 열람
- 개별 학습 카드 삭제: 덱 화면에서 카드를 길게 눌러 삭제
- 계정 및 전체 데이터 삭제: 앱 내 “계정” → “계정 삭제” 메뉴
- 처리 정지: 로그아웃 또는 계정 삭제
- 알림 권한 철회: iOS 설정 → 알림 → Keyling
- 마이크·음성 인식 권한 철회: iOS 설정 → Keyling → 마이크 / 음성 인식; Android 설정 → 애플리케이션 → Keyling → 권한 → 마이크
- 키보드 처리 일시정지 (학습 모드): 키보드의 학습 모드 버튼을 눌러 끄면, 실시간 영어 변환과 학습 카드 생성이 중단되고 입력 문장이 기기 밖으로 전송되지 않습니다
- 키보드 접근 권한 철회: iOS 설정 → 일반 → 키보드 → 키보드 → Keyling → “전체 접근 허용” 해제
위 권리 행사 시 즉시 효력이 발생하며, 별도의 처리 기간을 두지 않습니다. 계정 삭제 시 관련 학습 데이터는 Supabase 데이터베이스의 ON DELETE CASCADE 제약에 따라 즉시 함께 삭제됩니다.
8. 개인정보의 안전성 확보 조치
본 서비스는 「개인정보 보호법」 제29조에 따라 다음의 안전성 확보 조치를 실시하고 있습니다.
(1) 기술적 조치
- 전송 구간 암호화: HTTPS (TLS) 적용
- 비밀번호 암호화: Supabase의 표준 해시 알고리즘 적용
- 인증 토큰 보호: iOS Keychain Services에 저장 (사용 가능한 경우 하드웨어 보안 모듈 활용)
- 접근 제어: Supabase의 행 수준 보안(Row-Level Security)을 통해 정보주체가 본인의 데이터에만 접근 가능하도록 제한
(2) 관리적 조치
- 캡처 최소화: 키보드 단계에서 한국어 입력 모드가 아닌 입력, 안전 입력 필드 입력, 34개 캡처 제외 대상 필드 유형의 입력은 서버로 전송되지 않도록 구조적으로 차단
- 최소 수집 원칙: 위치 정보, 광고 식별자(IDFA), 연락처, 사진 등은 수집하지 않으며, 서비스 개선을 위한 사용 분석·진단 정보는 익명으로만 최소한으로 수집함
9. 개인정보 보호책임자
본 서비스는 정보주체의 개인정보를 보호하고 개인정보와 관련된 불만을 처리하기 위해 다음과 같이 개인정보 보호책임자를 지정합니다.
- 성명: 길윤재 (Yoonjae Kil)
- 연락처: privacy@keyling.app
정보주체는 본 서비스를 이용하면서 발생한 모든 개인정보 보호 관련 문의, 불만 처리, 피해 구제 등에 관한 사항을 위 연락처로 문의하실 수 있으며, 본 서비스는 정보주체의 문의에 대해 지체 없이 답변 및 처리해 드리겠습니다.
10. 만 14세 미만 아동의 개인정보
본 서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 만 14세 미만 아동의 개인정보를 의도적으로 수집하지 않습니다. 만 14세 미만 아동이 본 서비스를 이용한 것이 확인되는 경우, 해당 계정 및 관련 데이터를 즉시 삭제합니다.
11. 개인정보처리방침의 변경
본 처리방침은 법령, 정책 또는 서비스 변경에 따라 개정될 수 있으며, 개정 시 변경 사항을 앱 내 공지 또는 이메일을 통해 사전에 안내합니다. 본 처리방침의 시행일은 상단에 명시되어 있습니다.
12. 권익침해 구제방법
정보주체는 개인정보 침해에 대한 신고 및 상담을 위해 아래 기관에 문의하실 수 있습니다.
- 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
- 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
- 대검찰청 사이버수사과: (국번없이) 1301 (www.spo.go.kr)
- 경찰청 사이버수사국: (국번없이) 182 (cyberbureau.police.go.kr)
Privacy Policy
Effective date: 2026-07-07
Keyling (the “Service”) complies with the Personal Information Protection Act (“PIPA”) of the Republic of Korea and other applicable laws. This Privacy Policy describes how the Service processes its users’ personal information.
1. Categories of personal information processed
The Service processes the following categories of personal information:
(1) Account registration and authentication
- Email address
- Password (stored as a hash)
- Supabase user identifier
(2) Keyboard input capture
- Korean (Hangul) text typed by the user in the Korean input mode of the Keyling keyboard, only when the captured text contains at least one Hangul codepoint.
- The Service silently excludes capture from 34 field types via UIKit content-type and keyboard-type checks: all name variants (full/prefix/suffix/given/middle/family/nickname), email, phone, URL, username, password, newPassword, credit card, one-time code, all address components, organization, job title, dateTime, flight number, shipment tracking, plus phonePad / numberPad / decimalPad / namePhonePad / emailAddress / URL / asciiCapableNumberPad keyboard types.
- Text typed in secure fields (where
isSecureTextEntryis true) is filtered in two independent layers and is never transmitted. - Additional safeguard: even when Hangul is present, any message that contains a single English (Latin) letter, or a run of 3 or more consecutive digits (phone numbers, verification codes, card numbers), is not captured — even in a normal text field. Only pure-Korean messages are ever captured.
(3) Generated learning data
- Lesson cards derived from captured Korean text, including the original Korean source text, English translation, focus item, and exercise content.
(4) Push notifications
- Apple Push Notification service (APNs) device token
- Notification delivery logs (delivery status, attempt timestamps)
(5) Speech input (speaking exercise)
- Microphone audio captured while the user speaks an English sentence aloud during the speaking exercise. The audio is transcribed to text in real time by the device operating system’s speech recognition (Apple’s Speech framework on iOS; the device’s system speech recognizer — typically Google — on Android). When the relevant English (en-US) on-device recognition model is installed on the device, the audio is processed entirely on the device and is not transmitted. However, Korean-locale Android devices often do not have the English on-device model installed, and on such devices the audio is sent to the speech recognizer provider’s servers (typically Google) for recognition (see Section 5-2). While the speaking exercise is active, the microphone captures audio continuously until the user stops it or the sentence is recognized.
- The resulting transcript is used only to phonetically compare the spoken answer against the expected sentence (scoring); neither the audio nor the transcript is stored on the Service’s servers or database, and both are discarded immediately after recognition.
(6) Usage analytics and diagnostics
- Anonymous usage analytics (PostHog): anonymous app-usage events collected to improve the Service (screens viewed, whether a feature was used, action counts). Tied only to a randomly generated anonymous identifier that does not identify the user; it never includes the user’s account, email, captured Korean text, or learning content.
- Crash diagnostics (Sentry): error and crash diagnostics (error type, where it occurred, device model, OS version, app version). It contains no personal information (PII) and no captured text or learning content.
Beyond the items listed above, the Service does not collect location data, advertising identifiers (IDFA), contacts, or photos/videos, and does not track users across apps or websites or share data with data brokers. The usage analytics and diagnostics in (6) above are processed anonymously and are not linked to the user’s identity.
2. Purpose of processing
The Service processes collected personal information for the following purposes only, and does not use personal information for any other purpose:
- Account authentication and management
- Generating personalized English-learning content from Korean text the user has naturally typed
- Delivering generated learning content via push notifications and the in-app deck
- Synthesizing lesson text (the English translation, focus item, and example sentences) into audio so the user can hear it read aloud
- Recognizing and scoring the user’s spoken English in the speaking exercise to provide learning feedback
- Anonymous usage analytics and crash diagnostics to improve the quality of the Service
3. Retention and use period
- Captured Korean text and generated learning cards: retained until the user deletes the individual card or deletes their account.
- Synthesized audio (text-to-speech): audio generated from lesson text is stored as a shared cache, identified by a hash of the text rather than by user, so that identical text yields the same audio for any user. It is not linked to an account; on account deletion, the lesson data — the only information that could associate any audio with the user — is removed, leaving the cached audio anonymous.
- Account information (email, password hash, user identifier): retained until account deletion. When the account is deleted, all related learning data is immediately deleted from the database via the ON DELETE CASCADE constraint.
- APNs device token: retained until the user revokes notification permission or deletes the account.
- Push-delivery diagnostic logs: technical delivery records (success/failure status and error codes; no notification content), retained only as long as needed to diagnose delivery problems.
- Lesson-generation diagnostic logs: technical records of each generation request (success/skip/failure status, reason codes, and processing time; no typed message content), retained only as long as needed to diagnose generation problems.
- Request-rate counters: short-lived counters used to limit excessive requests; they expire automatically within minutes to a day.
- Anonymous usage analytics and diagnostics: retained per the retention policies of the respective processors (PostHog, Sentry); not linked to the user’s identity.
4. Provision to third parties
The Service does not provide personal information to third parties without the user’s consent.
5. Entrustment of processing
The Service entrusts the following processors with limited data processing tasks:
| Processor | Task | Data items | Location |
|---|---|---|---|
| Vercel Inc. | Hosts the lesson-generation API | Captured Korean text and authentication token (in transit and during processing only; not permanently stored on Vercel) | USA |
| Google LLC (Gemini API) | Natural-language processing to generate English lessons from Korean text; text-to-speech synthesis of lesson text into audio; real-time English rendering of text typed on the keyboard (writing assistance) | Captured Korean text; lesson text (English translation, focus item, and example sentences) for audio synthesis; the sentence being typed on the keyboard (anonymous, not linked to an account; for real-time rendering only) | USA |
| Supabase Inc. | Authentication and database hosting | Email, password hash, user identifier, lesson cards, APNs device token | USA |
| Apple Inc. | Push notification delivery (APNs) | APNs device token, notification payload (lesson preview) | USA |
| PostHog, Inc. | Anonymous usage analytics | Anonymous app-usage events (no personally identifying information) | USA |
| Functional Software, Inc. (Sentry) | Error and crash diagnostics | Error/crash diagnostics (no personally identifying information) | USA |
| Upstash, Inc. | Request rate limiting and spend-cap enforcement | Short-lived request counters keyed by a pseudonymous user identifier (lesson-generation and audio-synthesis request counts; expire automatically within minutes to a day) | USA |
Contracts with these processors include the data protection requirements mandated by PIPA, and entrustment is disclosed through this Privacy Policy.
The Service uses a paid Google Gemini API account. Per Google’s Gemini API terms, data transmitted by the Service to the Gemini API is not used to train Google’s machine learning models. Speech recognition in the speaking exercise, however, uses the device operating system’s speech recognition rather than the Gemini API above; it is not an entrustment of processing by the Service and is therefore not listed in the table above. See Section 5-2 for details.
The real-time English rendering (writing assistance) shown while you use the keyboard is handled differently from the lesson generation above: the sentence you are typing is sent — anonymously, with no account information — to the Google Gemini API (USA) and rendered into English in real time, with only the result shown above the keys. This sentence is not stored on the Service’s servers and is not linked to your account or identity; Google does not use it to train machine-learning models or for human review, and retains it only briefly — up to approximately 55 days — solely to prevent abuse and policy violations, after which it is deleted. This feature operates only when ‘Allow Full Access’ is enabled for the Keyling keyboard, and only sentences you explicitly keep with the ‘Save’ button are linked to your account and analyzed into lesson cards.
Both the real-time English rendering and the lesson-card generation described above occur only while the keyboard’s ‘Learning Mode’ is on. You can turn Learning Mode off at any time using the button on the keyboard; while it is off, both real-time rendering and lesson-card generation stop, and no sentence you type is transmitted off your device.
5-2. Device operating-system speech recognition (notice)
Speech recognition in the speaking exercise is not processing entrusted by the Service to a processor. It uses the speech recognition built into the device’s operating system (Apple’s Speech framework on iOS; on Android, the system speech recognition service set as the default on the device — typically Google’s).
- When the device supports English (en-US) on-device recognition (iOS) or has the English (en-US) on-device recognition model installed (Android), the audio is processed entirely on the device and is not transmitted.
- Otherwise, the audio is transmitted to the servers of the operating system’s speech recognition provider (located outside Korea, e.g. in the United States) for transcription. That provider (Apple on iOS; typically Google on Android) is not a processor engaged by the Service; it processes the audio independently, as a separate controller, under its own privacy policy. (Apple: apple.com/legal/privacy, Google: policies.google.com/privacy)
- The Service never receives or stores the raw audio, and the transcript is discarded immediately after scoring (see Section 1(5)).
- On Android, you can install the English (en-US) on-device model so that audio never leaves your device (e.g., Settings → System → Languages & input → Speech recognition; the exact path varies by manufacturer), or change the device’s default speech recognition service to a different provider.
6. Cross-border transfer of personal information
All processors used by the Service are located in the United States, which results in cross-border transfer of personal information.
- Items transferred: see Section 5
- Country: United States
- Time and method of transfer: in real time via HTTPS at the moment the user captures Korean text or performs account activity
- Processor information: see Section 5
- Purpose and retention period: see Sections 2 and 3
- How to refuse the transfer: you may refuse cross-border transfer by not using the relevant features (keyboard capture, the speaking exercise), by deleting your account, or by contacting the privacy officer (Section 9). Doing so may limit your use of the relevant features.
In addition, when the speaking exercise uses the device operating system’s speech recognition, audio may be transmitted directly from the device to the overseas servers (e.g. in the United States) of the operating system’s speech recognition provider (Apple on iOS; typically Google on Android). This is a transmission performed by the device operating system, not a transfer under an entrustment by the Service; see Section 5-2 for details.
7. User rights and how to exercise them
You may exercise the following rights at any time:
- Access your data: view all your lesson cards in the in-app deck
- Delete individual lesson cards: long-press a card in the deck
- Delete your account and all associated data: in-app menu Account → Delete Account
- Stop processing: sign out or delete your account
- Revoke notification permission: iOS Settings → Notifications → Keyling
- Revoke microphone / speech-recognition permission: iOS Settings → Keyling → Microphone / Speech Recognition; Android Settings → Apps → Keyling → Permissions → Microphone
- Pause keyboard processing (Learning Mode): turn off the Learning Mode button on the keyboard; while off, real-time English rendering and lesson-card generation stop and no sentence you type is transmitted off your device
- Revoke keyboard Full Access: iOS Settings → General → Keyboard → Keyboards → Keyling → toggle off “Allow Full Access”
These actions take effect immediately with no processing delay. Account deletion cascades through the Supabase database via the ON DELETE CASCADE constraint, immediately deleting all related learning data.
8. Security measures
In accordance with Article 29 of PIPA, the Service implements the following security measures:
(1) Technical measures
- Encryption in transit: HTTPS (TLS) throughout
- Password encryption: standard hash algorithm via Supabase
- Authentication token protection: stored in iOS Keychain Services (with hardware security module where available)
- Access control: Supabase Row-Level Security ensures users can only access their own data
(2) Administrative measures
- Capture minimization: at the keyboard layer, input outside Korean input mode, input in secure fields, and input in 34 non-target field types is structurally blocked from being transmitted
- Data minimization: the Service does not collect location, advertising identifiers, contacts, or photos; usage analytics and diagnostics collected to improve the Service are limited to anonymous data only.
9. Privacy Officer
The Service designates the following privacy officer to protect users’ personal information and to handle related inquiries and complaints:
- Name: Yoonjae Kil (길윤재)
- Contact: privacy@keyling.app
Users may contact the privacy officer at the address above for any inquiries, complaints, or remedies related to personal information arising from use of the Service. The Service will respond to all such inquiries without undue delay.
10. Children under 14
The Service is not intended for children under 14 and does not intentionally collect personal information from children under 14. If it is discovered that a child under 14 has used the Service, the account and all related data will be deleted immediately.
11. Changes to this Privacy Policy
This Privacy Policy may change due to changes in law, Service policies, or Service features. When changes are made, the Service will notify users in advance through in-app announcements or email. The effective date of this Privacy Policy is shown at the top of this document.
12. Remedies for rights infringement
For reports and consultation regarding personal information infringement, you may contact the following Korean agencies:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Reporting Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office Cyber Investigation Division: 1301 (www.spo.go.kr)
- National Police Agency Cyber Investigation Bureau: 182 (cyberbureau.police.go.kr)