한국어
PassVoca는 TOPIK 학습 앱입니다. 이번 출시의 앱 표시 언어는 English와 日本語이며, 앱에는 광고가 없습니다. 로그인과 동기화는 선택 사항입니다.
1. 기기와 Archive v2
로그인하지 않아도 학습 진도, 복습 상태, 세션 기록, 오답 표시, 사용자 목록과 앱 설정은 기기에 저장됩니다. 설정의 데이터 내보내기는 전체 학습 상태를 담은 Archive v2 JSON을 만듭니다. 설정, 코스 참조, 보관함, 사용자 단어·뜻·예문·입력형, 학습 프로그램, 종료된 세션, 복습 카드·기준선·이벤트, 오답 표시, 사용자 목록과 항목이 포함됩니다. 진행 중인 세션은 포함되지 않습니다.
로그인 토큰·계정 정보, 구매 권한·스토어 거래 자료, 설치된 코스 데이터베이스, 이미지·오디오 캐시, 동기화 큐·충돌 기록·서버 버전, 기기 전용 앱 언어는 Archive v2에서 제외됩니다. 파일은 자동 업로드되지 않으며, 가져오기 전에 형식과 무결성을 검사합니다.
2. 선택적 계정과 동기화
Apple 또는 Google로 로그인하면 제공자와 앱별 회원 식별자, 제공된 경우 이메일과 Apple 비공개 이메일 릴레이 사용 여부, 계정·세션·기기 시각과 토큰 해시를 서버에 저장합니다. 이름, 프로필 사진, 전화번호는 받거나 저장하지 않습니다. 동기화를 켜면 학습 진도, 학습 프로그램, 종료된 세션, 복습 상태, 오답·목록과 설정이 Cloudflare 인프라의 서버에 저장될 수 있습니다. 충돌 해결에 필요한 양쪽 데이터와 충돌 기록도 저장될 수 있습니다.
3. 구매와 구매 검증
결제는 Apple App Store 또는 Google Play가 처리합니다. 유료 코스 구매·복원에는 로그인이 필요하며, 서버가 스토어 거래를 검증한 뒤에만 권한을 부여합니다. 서버에는 스토어 SKU, 서비스 상품 ID, Apple 거래 ID 또는 Google 토큰의 해시, 원거래 참조(해당 시), 구매·검증 시각, 환경, 확인·권한·환불 상태가 저장될 수 있습니다.
Google 확인이 끝나지 않으면 원문 구매 토큰이 재시도 목적으로 일시 보관될 수 있으며, 확인 후에는 저장하지 않습니다. 로그인만으로 거래가 새 계정에 자동 귀속되지 않으며, 이미 귀속되었거나 삭제된 계정의 거래는 다시 귀속되지 않습니다.
4. 계정 삭제와 보관
설정 → 계정 및 동기화 → 계정 삭제에서 다시 로그인해 본인 확인 후 삭제할 수 있습니다. 보관할 학습 상태가 있으면 삭제 전에 Archive v2 JSON을 먼저 내보내세요. 이 파일에는 로그인·계정 정보와 구매 권한·스토어 거래 자료가 포함되지 않습니다. 서버는 계정·로그인 연결·기기 등록·동기화 데이터·구매 검증 원장을 삭제하고, 서버 삭제가 성공하면 이 기기의 account-owned 학습 데이터도 삭제합니다. 로그아웃만 하면 기기 학습 데이터는 유지됩니다.
삭제된 거래의 재귀속을 막기 위해 플랫폼·거래 참조·원거래 참조·귀속 시각만 담은 최소 ownership 표식이 남을 수 있습니다. 계정 ID, 이메일, 원문 구매 토큰은 포함하지 않습니다. 표식은 분쟁·재귀속 방지에 합리적으로 필요한 기간에만 보관하고 목적이 끝나면 삭제합니다.
5. 네트워크, 제3자와 수집하지 않는 정보
업데이트, TOPIK 코스·이미지 다운로드, 로그인·동기화, 구매 검증에 네트워크를 사용합니다. 요청의 IP 주소와 시각은 Cloudflare의 글로벌 인프라 로그에 포함될 수 있습니다. 앱은 이를 학습 기록과 연결하지 않습니다. 광고·분석·크래시 SDK, 광고 식별자, 추적 권한, 위치·연락처· 사진·카메라·마이크 녹음은 사용하지 않습니다. Apple과 Google은 로그인·결제를, Cloudflare는 계정 서버·동기화·저장소·CDN을 제공합니다.
Apple·Google 로그인·인앱결제와 Cloudflare의 글로벌 Workers·D1·R2·CDN을 이용하므로, 이 흐름의 정보와 요청 메타데이터는 대한민국 밖에서 전송·저장 또는 원격 조회·처리될 수 있습니다. 제공자별 계약 주체·수령자 연락처, 실제 처리 국가·리전, 이전 시점·방법, 서비스별 보관기간은 해당 계정의 계약과 콘솔 설정을 확인하기 전에는 확정하지 않습니다. 따라서 확인 전 특정 국가·리전이나 고정 보관기간을 단정하지 않으며, 한국 대상 공개 유료 출시 전에는 적용 법령에 따라 필요한 이전 항목·수령자·국가·시점·방법·목적·보관기간· 거부 방법과 효과를 이 방침과 필요한 별도 고지에 반영합니다. 로그인·동기화를 사용하지 않으면 기기 간 동기화를 사용할 수 없고, 로그인하지 않으면 유료 코스 구매·복원을 사용할 수 없습니다. 업데이트와 코스·이미지 다운로드에는 CDN 요청이 필요합니다.
6. 아동, 권리와 문의
PassVoca는 일반 이용자 대상이며 특정 아동을 대상으로 하지 않습니다. 초기 출시에는 생년월일·연령을 묻거나 저장하는 연령 게이트를 두지 않고, 관할 지역의 동의 연령 미만 이용자의 개인정보를 알면서 수집하지 않습니다. 보호자·이용자 신고 또는 신뢰할 수 있는 다른 경로로 실제 만 14세 미만 이용자(또는 해당 관할의 동의 연령 미만)임을 알게 되면, 필요한 법정대리인 동의를 확인할 때까지 계정·동기화와 구매 검증을 제한하는 절차를 시작합니다. 동의를 확인할 수 없거나 동의하지 않으면 관련 법령에 따라 계정·동기화 데이터를 제한 또는 삭제합니다. 신고를 위해 이메일로 주민등록번호·신분증 사본을 보내지 마세요. 기기 데이터는 내보내기·불러오기와 기기 데이터 지우기로 관리하고, 서버 데이터는 계정 삭제로 삭제할 수 있습니다.
- 상호: Kohana
- 사업자등록번호: 609-32-66080
- 주소: 경기도 수원시 영통구 도청로 10 B동 612호
- 개인정보 보호책임자: 현병익
- kohana.manage@gmail.com
처리 내용이 바뀌면 이 페이지와 시행일을 함께 갱신합니다.
English
PassVoca is a TOPIK study app. For this launch, the interface languages are English and Japanese, and the app shows no ads. Sign-in and sync are optional.
1. Device data and Archive v2
Without signing in, study progress, review state, session records, flags, custom lists, and app settings stay on your device. Export data creates an Archive v2 JSON file containing the full study state: settings, logical course references, shelves, user words with meanings/examples/typing forms, learning programs, ended sessions, review cards/baselines/events, flags, and custom lists/items. Active or open sessions are excluded.
Archive v2 excludes sign-in tokens and account information, purchase entitlements and store transaction evidence, installed course databases, image/audio caches, sync queues/conflict records/server versions, and the device-only interface language. The file is never uploaded automatically, and its format and integrity are checked before import.
2. Optional account and sync
When you sign in with Apple or Google, we store the provider and app-specific subject ID, an email if supplied and whether Apple Private Email Relay was used, account/session/device times, and a hash of the session token. We do not receive or store your name, profile photo, or phone number. With sync enabled, progress, learning programs, ended sessions, review state, flags, lists, and settings may be stored on account servers on Cloudflare infrastructure. Data needed to resolve device conflicts and a conflict record may also be stored.
3. Purchases and verification
Apple App Store or Google Play processes payment. Sign-in is required to buy or restore a paid course, and the server grants access only after verifying the store transaction. The verification record may contain the store SKU, our product ID, an Apple transaction ID or a hash of the Google token, an original-transaction reference when supplied, purchase/verification times, environment, acknowledgement, entitlement, and refund status.
If Google acknowledgement has not completed, the original purchase token may be held temporarily for retry and is not stored after acknowledgement succeeds. Signing in does not automatically attach a transaction to a new account; a transaction already claimed by another or deleted account is not claimed again.
4. Account deletion and retention
Go to Settings → Account & sync → Delete account and sign in again to confirm your identity. If you want to keep a portable copy of your study state, export an Archive v2 JSON first; it excludes sign-in/account information, purchase entitlements, and store evidence. The server deletes the account, sign-in connections, device registrations, synced data, and purchase-verification records. After server deletion succeeds, account-owned study data on the device is deleted too. Signing out alone keeps device study data.
To prevent a deleted transaction from being claimed again, a minimal ownership marker containing only the platform, transaction reference, any original-transaction reference, and claim time may remain. It contains no account ID, email address, or original purchase token. The marker is kept only for the period reasonably needed to prevent disputes and re-attribution, and is deleted when that purpose ends.
5. Network, providers, and information we do not collect
The app uses the network for updates, TOPIK course/image downloads, sign-in/sync, and purchase verification. Request IP addresses and times may appear in Cloudflare's global infrastructure logs; the app does not connect them to study history. We use no advertising, analytics, or crash-reporting SDKs, advertising identifiers, tracking permission, location, contacts, photos, or camera/microphone recordings. Apple and Google provide sign-in/payment services; Cloudflare provides account, sync, storage, and CDN infrastructure.
Because we use Apple and Google for sign-in and in-app purchase and Cloudflare's global Workers, D1, R2, and CDN services, information and request metadata in these flows may be transmitted, stored, remotely accessed, or otherwise processed outside the Republic of Korea. The contracting entity and contact for each provider, actual processing country or region, transfer time and method, and service-specific retention period are not confirmed until we verify the applicable account contract and console configuration. We therefore do not state a particular country, region, or fixed retention period before that verification. Before a public paid launch for Korea, we will reflect the transfer items, recipient, country, time and method, purpose, retention period, and any required refusal method and consequence in this policy and any required separate notice. Without sign-in and sync, cross-device sync is unavailable; without sign-in, purchasing and restoring paid courses are unavailable. Network features such as updates and course or image downloads need CDN requests.
6. Children, rights, and contact
PassVoca is a general-audience app and is not directed to specific children. At launch, we do not ask for or store a birth date or age and do not use an age gate. We do not knowingly collect personal information from anyone below the consent age in their jurisdiction. If a parent, user, or another reliable source tells us that a user is actually under 14 in Korea (or below the applicable consent age elsewhere), we begin the process of restricting account, sync, and purchase-verification processing while we determine whether legally required parental consent can be verified. If consent cannot be verified or is not given, we restrict or delete the account and synced data as applicable law requires. Do not send government-ID numbers or ID-document copies by email to make a report. You can manage device data with export, import, and erase-device-data features, and delete server data through account deletion.
- Business: Kohana
- Business registration number: 609-32-66080
- Address: B-612, 10 Docheong-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, South Korea
- Privacy contact: Byungik Hyun
- kohana.manage@gmail.com
If our processing changes, we will update this page and its effective date.