Privacy Policy

[This is an English reference translation of the Korean-language Privacy Policy of Chakeylog. The Korean version is the original, and where the content of the two differs the Korean version is the authoritative text. The Korean version is available on the Privacy Policy screen in the app and on the privacy policy page operated by the Company.]

Chakeylog (the "Company") regards the personal information of its users as important and complies with the Personal Information Protection Act and other applicable statutes.
This Policy applies to the Android app Chakeylog.

1. Items of personal information collected

Of the items below, the account identifier (UID) is indispensable in order to distinguish users and to connect records to the account concerned, and the Service cannot be used without it. Linking a Google account is optional and the Service may be used anonymously without linking one, but where no Google account is linked, records cannot be moved to a new device and the account cannot be restored when the device is changed (item 2). The items under (b) are entered directly by the user when the user chooses to use the function concerned, so they need not be entered; where they are not entered, only that function and the results it produces are not provided (for example, a vehicle name is required in order to register a vehicle, and where the tyre production number is not entered the number of years since manufacture cannot be calculated). The items under (c) are created and stored automatically in the course of using the Service and so cannot be chosen item by item; how to limit the advertising identifier is set out in item 10.

(a) Account information
- Where use began anonymously: the unique identifier (UID) issued by the authentication service, the date and time the account was created, the date and time of the last access
- Where a Google account has been linked: in addition to the above, the email address, the name and the profile photograph address of the Google account
(Linking of an Apple account is not currently provided.)

(b) Information entered directly by the user
- Vehicle information: vehicle nickname, manufacturer, vehicle name, detailed model (generation), model year, fuel type, mileage, consumable items and their replacement cycles, the tyre production number (the last four digits of the DOT code written on the side of the tyre) and the tyre size, and whether the vehicle is one actually owned or a vehicle model of interest (a Wishcar)
- Where a vehicle is registered by AI, the specifications identified by the AI (engine displacement, engine code, transmission, drive type) are created together with it. These specifications are stored in the user's vehicle information and also in the catalogue shared by vehicle model with other users who register the same vehicle model. The shared catalogue remains after withdrawal of membership; details are set out in item 3.
- Refueling records: date, mileage, quantity refueled, unit price, total amount, fuel type, name of the gas station, memo
- Maintenance records: date, mileage, maintenance item, amount, name of the repair shop, payment method, number of instalment months, first billing month, memo
- Expense records: date, category, amount, place, mileage, payment method, number of instalment months, first billing month, memo
- The amounts in the refueling, maintenance and expense records above (unit price, total amount, amount) are stored together with a currency code (for example, KRW for Korean won) indicating the currency in which the amount is expressed. This is not a value separately asked of and received from the user; it records what the amounts the user enters are expressed in. The currency attached to a newly created record is determined by the app on the user's device. Where the user has chosen a currency or a country in the app's settings, the app follows that choice; where the user has not, the app determines it according to the region setting of the device; and where the user enters a record by AI, the app may follow a currency clearly stated in the sentence written by the user. The currency of a record saved by the user can be changed by opening that record. Records for which no currency code is stored (records created with a version of the app from before currency codes were stored together with the amounts) are treated as being in Korean won.
- Symptom records: date, mileage, weather, category, description of the symptom
- The original text of the sentence entered by the user when using an AI function (see items 5 and 6 below)

(c) Information generated or collected automatically in the course of using the Service
- App settings (language, whether notifications are received, the list of vehicles for which notifications have been turned off, the vehicle to be shown first when the app is opened again, the order in which vehicles are arranged in the vehicle list, the input method opened by default when adding a record), the membership level (whether Premium), and whether an actual photograph has been registered for each vehicle (not the photograph itself; see item 11)
- The date on which a tyre production number was entered: when a user enters or corrects the tyre production number under (b) above, the Company's server records that date together with it. This is so that, if a record of a tyre replacement is entered afterwards, it can be determined that the stored production number is that of the previous tyre and that number can be excluded from the calculation of the years since manufacture.
- Premium subscription information: the type of subscription product (weekly or annual) and the identifiers of the base plan and the discount applied within that product, the expiry date of the Premium usage period, the purchase verification token issued by Google Play, the order number issued by Google Play, the date and time on which that purchase was connected to the account, and whether that purchase is a Google Play test purchase. This is everything that the Company keeps in connection with subscriptions, and payment method information is not received (see (d) below). Some of these items are preserved after withdrawal in accordance with the applicable statutes (see item 3).
- Premium granted by the Company: where the Company grants a user the Premium level at no charge to the user by the method set out in item 12, the fact that the level has been granted, the type of the period granted (one week or one year), the expiry date of that period, the date and time of the grant and the account identifier of the administrator who granted it are stored in the user's account. Nothing further is received from the user, and these are stored separately from the "Premium subscription information" above and do not alter the subscription information that the user has paid for.
- The number of times AI functions are used per day and the session identifier of the vehicle registration dialogue
- The country sent by the app when the user requests estimated running costs by vehicle model (the country the user has chosen in the app's settings or, where the user has not chosen one, the country according to the region setting of the device). It is used only to show the estimated running costs in the currency and at the price level of that country, and the Company's server does not store it.
- Information for managing the creation limit for Wishcars (saving a vehicle model of interest): the number created that day, the number added that day by watching rewarded advertisements, the number accrued through friend invitations, and a marker by vehicle model (which vehicle models have already been counted once) that prevents the popularity count from being inflated by saving the same vehicle model repeatedly
- Information created where friend invitation is used: the invitation code issued to the user and, where a user has installed the app through another user's invitation link and signed up, the unique identifier (UID) of that inviting user and the date and time it was applied. The app reads only the invitation code from the value delivered in the installation path and reports it to the server; it does not store any other value. Details are set out in items 2 and 4.
- The IP address and the request records at the time of access to the server. These are used for the operation of the server (including checking whether there is an update file that corrects screens and wording when the app is launched, and downloading it) and for blocking excessive repeated requests (item 12), and they remain in the server operation logs.
- Records of an administrator's viewing or changing of a user's personal information. Where an administrator of the Company views a user's account information, vehicle information, refueling, maintenance, expense or symptom records, or sharing relationship information through the administrator screen, or changes a user's membership level, the following are recorded in respect of that viewing or change: the account identifier of the administrator, the date and time of the processing, the IP address used for it, the unique identifier (UID) of the user concerned, and the work performed (which function was used and on what conditions). This record is not created by the user but within the Company; it is set out here because it contains a value pointing to the user (the UID). Article 30(1)5 of the Enforcement Decree of the Personal Information Protection Act, and Article 8(1) of the public notice of the Personal Information Protection Commission issued under the delegation in Article 30(3) of that Decree, require this record to be created and kept. The retention period is set out in item 3.
- Information collected by the advertising SDK. The items below do not pass through the Company's server; the Google AdMob advertising SDK included in the app collects them directly and sends them to Google. The Company neither receives nor keeps those values. How to refuse and limit this is set out in item 10.
  · The advertising identifier (the Android advertising ID), the app set ID, and other identifiers related to the accounts logged in on the device
  · App usage interaction information: launches of the app, operations on the screen (taps), views of advertising videos
  · Diagnostic information: information about the performance of the app and of the advertising SDK (the time taken for the app to start, the rate at which the app freezes, battery usage and the like). Crash logs of the app are not collected.
  · The IP address of the device. Google can estimate the approximate location of the device from this IP address. Details are set out in (d) below.
- The unique identifier (UID) of the user who left a record. The UID of the user who left the record is stored together with refueling, maintenance, expense and symptom records. This is because several people can leave records for one vehicle where the vehicle is shared, so it is necessary to tell whose record it is.
- Information created where vehicle sharing is used: the invitation code issued and its period of validity, whether the code has been used and the UID of the account that used it, the UIDs and the permissions of the users taking part in the sharing, the scope of sharing chosen by the user (the kinds of records and the starting date), the date and time the sharing was accepted, and the version of the consent text displayed at the time of acceptance. Details are set out in item 4.

(d) Information that the Company does not collect
The Company does not collect the items below. However, where an external service included in the app processes something even though the Company does not collect it, that fact is stated together with the item.
- Actual vehicle photographs taken by the user or chosen from the album: these are not transmitted to the server and are not kept. Details are set out in item 11.
- The address book, call records and text messages: not collected.
- Location information: the app does not request location permission, does not use the location functions of the device such as GPS, and has no function that uses location. The Company does not measure, collect or use the location of users, and does not use the IP address remaining in the server access logs ((c) above) to estimate location either.
  However, the Google AdMob advertising SDK included in the app collects the IP address used for the connection, and Google can estimate the approximate location of the device from this IP address. This is something Google does for its own advertising service and the Company does not receive the result of that estimation, but it actually happens in the course of a user's use of the app, so it is stated here. For the same reason the data safety information of the app market also indicates that approximate location is collected and shared. The related information and how to limit it are set out in item 10.
- Authentication information for payment methods, such as card numbers, account numbers and payment passwords: not collected. Payment for the Premium subscription is made only through Google Play in-app purchase and payment method information is processed by Google, so the Company neither receives nor keeps it. The payment method that a user writes in a record ((b) above) is only a short phrase that the user writes in order to classify an expense, and it is not used for actual payment.
- Purchase details: transaction details such as the amount paid, the date and time of payment and receipts are kept by Google Play and are not kept by the Company. What the Company checks with Google Play is whether that purchase is valid at present and until when it is valid, and of that result it stores only the items set out in (c) above. However, because the order number issued by Google Play is needed to identify a purchase when a user requests a refund or makes an enquiry, the Company stores it as well; the amount is not stored.

2. Purposes for which personal information is processed
- Identification of members and provision of the Service (saving, viewing and compiling statistics on vehicle records, CSV export)
- Handover of data and recovery of the account when the device is changed (where a Google account has been linked)
- AI-based automatic entry of records (refueling, maintenance, expense and symptom records), the vehicle registration dialogue, generation of consumable replacement cycles, estimation of expected running costs and new-car list prices by vehicle model, and generation of AI vehicle images
- Reminders of consumable replacement times (local notifications scheduled only within the device)
- Management of the daily usage limits of AI functions and prevention of improper use
- Management of the Wishcar creation limit and accrual of extensions to that limit (watching rewarded advertisements, friend invitations), and prevention of a user circumventing the limit or inflating the popularity count
- Accrual of Wishcar creation limits for friend invitations and prevention of duplicate accrual and of self-invitation
- Display of advertisements
- Checking of the membership level (anonymous, general, Premium) and provision of the functions of each level
- Provision of the vehicle sharing function (issuing and checking invitation codes, applying the scope of sharing chosen by the user, managing participants) and confirmation of the fact that consent to provision to a third party was obtained (keeping the date and time of the consent and the version of the consent text)
- Confirmation of purchases of Premium subscriptions and reflection of the subscription status (expiry of the usage period, refunds), and prevention of one purchase being applied to several accounts
- Giving a notification that the statutes require the Company to give to users, such as notification of a leak of personal information under Article 34 of the Personal Information Protection Act. Where a Google account has been linked, the email address of that account may be used for such a notification.

3. Period of retention and use of personal information
- Where a user applies to withdraw membership, the account stored on the server and all the data belonging to that account (vehicle information, refueling, maintenance, expense and symptom records, app settings, AI usage counts, Wishcar creation limit management information, Premium subscription information and the purchase verification token, and Premium granted by the Company) are deleted immediately. However, in the case of an account that has purchased a Premium subscription, only the items set out below under "transaction records preserved in accordance with the applicable statutes" are separately moved and preserved in respect of that purchase before deletion.
- Transaction records preserved in accordance with the applicable statutes: Article 6(1) of the Act on the Consumer Protection in Electronic Commerce and Article 6(1) of the Enforcement Decree of that Act provide that records concerning contracts and records concerning payment and the supply of goods and the like are each to be preserved for five years. Accordingly, where a user who has purchased a Premium subscription withdraws, the Company moves the items below to a separate storage space that is separated from the account data, preserves them there and then destroys them, and stores and manages them separately from other personal information in accordance with the proviso of Article 21(1) and Article 21(3) of the Personal Information Protection Act.
  · Items preserved: the unique identifier (UID) of the user, the order number issued by Google Play, the type of subscription product and the identifiers of the base plan and the discount applied within that product, the date and time on which that purchase was connected to the account, the date and time on which the Premium usage period expires, the date and time of withdrawal, whether a refund has been processed and when it was processed, whether that purchase is a Google Play test purchase, and the scheduled destruction date calculated according to the retention period below
  · Items not preserved: the name, the email address and the profile photograph address are not preserved and are deleted together with the authentication account. The purchase verification token itself is not preserved either; only a value converted from it in a way that cannot be reversed is kept, so that a refund notification arriving after withdrawal can be attached to the same transaction. Data that are not transaction records, such as vehicle information, refueling, maintenance, expense and symptom records and app settings, are deleted on withdrawal as stated in the first line above.
  · Retention period: five years from the later of the expiry date of the Premium usage period and the date of withdrawal. The Company records the scheduled destruction date together with this record and destroys the record once that date has passed.
  · Because this record contains values by which a user can be identified (the UID and the order number), it is different in nature from the data set out below that are stored in a form not connected to any particular user and remain after withdrawal.
- Withdrawal of membership does not cancel the Google Play subscription itself. If a user withdraws without cancelling the subscription, renewal fees continue to be charged thereafter, so a user who is subscribing is asked to cancel first on the subscriptions screen of the Play Store app before withdrawing. In addition, any Premium usage period still remaining disappears upon withdrawal (Articles 7 and 9 of the Terms of Use).
- However, the data below are stored in a form that is not connected to any particular user and remain after withdrawal.
  · Vehicle specification catalogue: the specifications and consumable replacement cycles by vehicle model that were identified by AI. This is information about a particular vehicle model and not information about a user, and it is reused for other users who register the same vehicle model.
  · Vehicle expression aliases: where a vehicle was identified at once in the vehicle registration dialogue without any follow-up question, the original text of the sentence entered is stored without any user identifier and is reused when another user enters the same expression.
  · Estimates of expected running costs and new-car list prices by vehicle model: the range of motor insurance premiums, the motor vehicle tax, the annual maintenance cost, the official combined fuel economy, the new-car list price and a one-line description, all estimated by AI from the vehicle model alone. This is information about a particular vehicle model and not information about a user, and it is reused for other users who save or register the same vehicle model.
  · Popular Wishcar counts: the cumulative number of times each vehicle model has been saved as a Wishcar, and the name of the vehicle model to be displayed on the screen. Who saved it is not stored, so no value by which an individual can be identified is included.
  · AI-generated vehicle images: images created from the manufacturer, vehicle name, generation and colour alone, kept in a cache used in common by all users.
  · Vehicle generation hints: where the generation (detailed model) of a vehicle model is not known when a vehicle image is created, the AI is asked once, using the manufacturer, vehicle name and model year alone, in order to obtain a generation code, and that answer is stored by vehicle model and model year. What is stored is only the generation code, the name of the AI model that produced the answer and the date and time of storage; no information about a user is included, and it is reused for other users who create an image of the same vehicle model. However, because the name under which it is stored is composed of the manufacturer, vehicle name and model year, where the manufacturer and the vehicle name were entered directly by a user, the value that user entered remains as part of that name.
  · Statistics of the total number of AI calls per day: no value by which an individual can be identified is included.
- The actual vehicle photographs and the scheduled notifications stored on the user's device are deleted by the app when withdrawal is processed.
- Vehicle sharing relationship information (the UIDs and permissions of participants, the scope of sharing, the date and time of acceptance, the version of the consent text) is kept while the sharing is maintained. When sharing is terminated, the information concerning that participant is deleted, and when the last participant leaves, the sharing relationship information of that vehicle is itself deleted.
- An invitation code for vehicle sharing is effective only for 72 hours from the time it is issued. If a new invitation code is issued for the same vehicle, the previous code that has not yet been used is deleted, and the record of issue (the code, the vehicle identifier, the dates and times of issue and expiry, whether it has been used and the UID of the account that used it) is deleted when that vehicle is deleted or the member withdraws.
- Records left by a user in a vehicle shared by another user are the data of that vehicle's owner, so they remain in the owner's vehicle as they are even after that user leaves the sharing or withdraws membership. The UID of the author is stored together with these records (Article 8-2 of the Terms of Use).
- Server access logs (including IP addresses, item 1(c)) are kept in the server operation logs for 30 days and are then deleted automatically.
- Records of an administrator's viewing or changing of a user's personal information (item 1(c)) are kept for one year and are then deleted. The period differs from that of the server access logs in the line immediately above because the two records differ in nature and in the basis on which they are kept. Server access logs are records of the requests a user has sent to the server in order to view or save that user's own records, and they are kept for a period the Company has itself set for operating the server and for blocking excessive repeated requests. Records of an administrator's viewing or changing, by contrast, are records of a person other than the user having viewed or handled that user's personal information, and Article 8(1) of the public notice above requires them to be kept for at least one year. That same paragraph expressly excludes a user's own access records from its scope, so the one-year period does not apply to the 30 days in the line above.
- Where there is an obligation to preserve information under the applicable statutes, it is kept separately from other data for the period concerned and then destroyed.

4. Provision of personal information to a third party
Except in the cases set out in (a) and (e) below, the Company does not provide users' personal information to any third party. The processing necessary to provide the Service is carried out through the entrustment set out in item 5 below.

(a) Provision under the vehicle sharing function
Where a user invites another user through the vehicle sharing function and the other party accepts that invitation, the records within the scope chosen by the user are provided to the other party. The Company makes this provision only with the consent of the user (Article 17(1)1 of the Personal Information Protection Act), and it informs the user of the following matters and obtains separate consent at the time an invitation is created and at the time an invitation is accepted.
- The person to whom the personal information is provided: the other party invited by the user (another user of Chakeylog). The Company does not determine that other party; the user determines to whom the invitation code is delivered.
- The purpose for which the recipient uses it: to view the records of the shared vehicle together and to leave records within the scope shared
- The items of personal information provided: all the records falling within the kinds chosen by the user (those chosen from maintenance and repair, refueling and general expenses) and the period chosen (all, or after a chosen date), together with the information of that vehicle. This includes not only figures such as dates, mileage and amounts but also the content of every input field written directly by the user, such as maintenance items, the names of repair shops and gas stations, places, categories, payment methods and memos. Symptom records are not provided, and actual vehicle photographs, which are stored only on the user's device, are not provided either (see item 11). In addition, users who share the same vehicle are shown each other's account display name (the name of the Google account, or the part of the email address before the @ where there is no name) and the date and time on which they joined the sharing.
- The period for which the recipient retains and uses it: while the sharing is maintained. If the owner terminates the sharing, if the other party leaves the sharing, or if either side withdraws membership, the other party can no longer view that vehicle and its records. The Company does not make a copy of the records in the other party's account.
- The fact that the user has the right to refuse consent and the disadvantage of refusing: the user may refuse this consent. If the user refuses, only the vehicle sharing function cannot be used, and there is no disadvantage of any kind to the use of the rest of the Service.

(b) Withdrawal of consent
Sharing may be terminated at any time by either the owner or a participant, and that termination is itself the withdrawal of this consent. How to do so is set out in item 8.

(c) Obligations of a user to whom information has been provided
A user who has been given sharing must not use the records provided for any purpose other than that for which they were provided, and must not provide them to any other person (Article 19 of the Personal Information Protection Act). The same content is laid down as an obligation of users in Article 8(4) of the Terms of Use.

(d) Friend invitation does not constitute provision to a third party
Where a user has invited another user through friend invitation, the Company accrues only a Wishcar creation limit to the inviting user, and does not tell that user who the invited user is or what records that user has left. Conversely, the invited user is not told who the inviting user is either. The Company keeps the fact that the two accounts are connected by an invitation (item 1(c)) only within the Company, and this is in order to prevent the same account from receiving an invitation reward repeatedly.

(e) Provision arising from the display of advertisements
The Google AdMob advertising SDK included in the app sends the items below, including the advertising identifier, to Google in order to display advertisements and to measure their performance. The advertising terms entered into between the Company and Google state that, in relation to these items, the two companies are each independent controllers determining their own purposes and means, so Google does not process these items only on the Company's instructions. The Company therefore treats this processing not as an entrustment but as a provision to a third party, and ensures that it takes place only with the user's consent (Article 17(1)1 of the Personal Information Protection Act). The Company informs the user of the following matters and obtains consent on a separate screen, and this consent is kept distinct from the consent to the Terms of Use and this Privacy Policy that is obtained when the app is first launched.
- The persons to whom the personal information is provided: Google Asia Pacific Pte. Ltd. (the counterparty to the advertising terms entered into by the Company) and Google LLC
- The purpose for which the recipients use it: the display of advertisements and the measurement of advertising performance, and Google's own advertising business. The Company can neither instruct nor control that processing by Google.
- The items of personal information provided: identifiers related to the device and to accounts, such as the advertising identifier (the Android advertising ID) and the app set ID, the IP address, app usage interaction information (launches of the app, taps, views of advertising videos), and diagnostic information about the performance of the app and of the advertising SDK (item 1(c))
- The period for which the recipients retain and use it: the Company can neither determine nor control this period; it is as provided in Google's own privacy policy (https://policies.google.com/privacy).
- The fact that the user has the right to refuse consent and the disadvantage of refusing: the user may refuse this consent. Even if the user refuses, advertisements continue to be displayed; they are simply not tailored to the user's interests. Viewing banner advertisements, and using functions by watching rewarded advertisements, remain the same as before.
These items do not pass through the Company's server; the advertising SDK sends them directly to Google, and the Company neither receives nor keeps those values. This provision also constitutes a cross-border transfer, so please read item 6 as well. How to limit the advertising identifier itself on the device is set out in item 10.
When a user uses this app, Google, which is a party other than the Company, may use the items above to collect information about the user's online activities over time and also across other services, websites and apps outside this app, and the Company can neither ascertain nor control the scope of that collection.

5. Entrustment of the processing of personal information
For the provision of the Service, the Company entrusts the processing of personal information as follows.

(a) Person entrusted: Google LLC (Firebase Authentication)
   Work entrusted: authentication of members and management of accounts
   Items entrusted: UID, email address, name, profile photograph address, dates and times of account creation and access

(b) Person entrusted: Google LLC (Cloud Firestore, Cloud Storage for Firebase)
   Work entrusted: storage of vehicle information and of the various records, keeping of AI-generated images
   Items entrusted: the information in items 1(b) and 1(c) (actual vehicle photographs excluded)

(c) Person entrusted: Google LLC (Google Cloud Run)
   Work entrusted: operation of the application server
   Items entrusted: the request data transmitted to the server in the course of using the Service

(d) Person entrusted: Google LLC (the Gemini models through Vertex AI)
   Work entrusted: analysis of record sentences (automatic entry of refueling, maintenance, expense and symptom records), processing of the vehicle registration dialogue, generation of consumable replacement cycles, estimation of expected running costs and new-car list prices by vehicle model, generation of vehicle images (including checking the generation of the vehicle model before an image is created)
   Items entrusted: the original text of the sentence entered by the user, the vehicle specifications (manufacturer, vehicle name, generation, model year, fuel type, engine displacement, transmission, drive type), and the vehicle colour chosen by the user
   The Company does not send the UID or account information together with these requests. For the estimation of expected running costs and new-car list prices, the sentence entered by the user is not sent and only the vehicle specifications above are sent. Conversely, for the automatic entry of records only the sentence written by the user and today's date are sent, and vehicle specifications and other records already stored are not sent with them.
   The vehicle registration dialogue, the generation of consumable replacement cycles, the estimation of expected running costs and new-car list prices, and the generation of vehicle images reuse the stored result where the same request has already been processed, so no transmission takes place. However, where the generation of a vehicle model is not known when a vehicle image is created, a transmission asking about the generation on the basis of the manufacturer, vehicle name and model year alone may take place first in order to determine which image to use. This transmission may take place even where a stored image ends up being reused as it is, and once an answer is received it is stored by vehicle model and model year (item 3) so that no further transmission takes place for the same vehicle model and model year. In addition, where a stored result for expected running costs and new-car list prices has a missing item, a further transmission may take place for the same vehicle model up to once a day in order to fill that item. Automatic entry of records is available for all four kinds of records: refueling, maintenance, expense and symptom. Because there is no stored result that can be reused, the sentence entered is transmitted every time the user uses this function. The same applies to the automatic entry of symptom records: a sentence describing a symptom is transmitted only when the user has pressed that function, and where the function is not used it is not transmitted.

(e) Display of advertisements — this processing is not an entrustment and has been moved to item 4(e).
The advertising terms entered into between the Company and Google state that, in relation to the advertising-related items, the two companies are each independent controllers determining their own purposes and means. Google is therefore not a person entrusted who processes those items on the Company's instructions. What was previously set out in this item has accordingly been moved to item 4(e) (provision to a third party), and the matters concerning the cross-border transfer are set out in item 6.

(f) Person entrusted: Google LLC (Google Play in-app purchase, Google Play Developer API)
   Work entrusted: payment processing for Premium subscriptions, confirmation of the validity of purchases and of the subscription status
   Items entrusted: the purchase verification token issued by Google Play
   Payment method information (card numbers and the like) is processed directly by Google Play and is not passed to the Company. The Company does not send the UID or account information together with these requests either.

6. Cross-border transfer of personal information
The records left by users are stored within the Republic of Korea. However, some processing takes place outside the country, and that part is disclosed as follows.

(a) Basis of the cross-border transfer
The Company transfers personal information abroad on the following two bases only.
(1) The entrustment set out in item 5 and the storage arising from it: the Company transfers personal information abroad only to the extent that the entrustment of the processing and the storage of personal information are necessary in order to conclude and perform the service use contract with the user. The basis for this is Article 28-8(1)3 of the Personal Information Protection Act, and that subparagraph requires the matters set out in (c) below to be disclosed in the privacy policy. Accordingly, for this part the Company does not obtain separate consent, and the disclosure below takes the place of such consent.
(2) The advertising-related provision under item 4(e): this part is not an entrustment of processing and so does not fall within subparagraph 3 above. The Company therefore obtains separate consent from the user under Article 28-8(1)1 of the Personal Information Protection Act, and before obtaining that consent it gives advance notice of the matters listed in Article 28-8(2) (set out under "Advertising-related provision" in (c) below).

(b) What is processed in the Republic of Korea
Vehicle information, refueling, maintenance, expense and symptom records, and AI-generated vehicle images are stored in the Seoul region (asia-northeast3) of Google Cloud, and the application server is operated in the same region. This part is not transferred outside the Republic of Korea. However, the records of users who are outside the Republic of Korea are also stored here, so for those users this storage is itself a transfer out of the country in which they are.

(c) What is transferred abroad

- The person to whom the information is transferred: Google LLC. However, in relation to item 4(e) (advertising), the counterparty to the advertising terms entered into by the Company is Google Asia Pacific Pte. Ltd., and those terms do not specify the Google entity in whose facilities the processing takes place.
- Contact details of the person to whom the information is transferred: the point of contact set out in the Google Privacy Policy (https://policies.google.com/privacy)
- The country to which it is transferred: the countries in which Google LLC operates data processing facilities (AI processing takes place in a global region that does not designate a particular country)
- The date, time and method of transfer: transmitted over the information and communications network through an encrypted connection (HTTPS) at the time the user uses the function concerned
- The items transferred: the same as the items entrusted for each entrusted work in item 5.
- The purpose for which the person to whom the information is transferred uses it: performance of each entrusted work in item 5
- The period for which the person to whom the information is transferred retains and uses it: until the purpose of the entrustment has been achieved, or until withdrawal of membership. However, the payment and purchase records of Google Play are kept separately by Google in accordance with its own policy and the applicable statutes, irrespective of the Company's processing of a withdrawal.
- How and by what procedure to refuse the cross-border transfer, and the effect of refusal: because the transfer is made on the basis set out in (a)(1) above, no refusal procedure in the form of withdrawing consent is provided. The storage and the authentication of the Service are all carried out through the person entrusted above and it is not possible to exclude only part of the processing from the cross-border transfer, so a user who does not wish personal information to be transferred abroad may stop using the Service and delete the account and its data with Delete account on the Settings tab. In that case the Service can no longer be used.
(The eight lines above concern the transfer arising from the entrustment in item 5. The advertising-related provision under item 4(e) is as follows.)
- Advertising-related provision — items of personal information transferred: the same as the items set out in item 4(e).
- Advertising-related provision — the country to which it is transferred, and the time and method of transfer: at the point at which the user launches the app and an advertisement is requested, the advertising SDK sends the items directly to Google's advertising servers over an encrypted connection (HTTPS). The advertising terms do not specify the country in whose facilities the processing takes place, and the Company cannot designate that location.
- Advertising-related provision — the name and contact details of the recipients: Google Asia Pacific Pte. Ltd. and Google LLC. The contact point is the one set out in the Google Privacy Policy (https://policies.google.com/privacy).
- Advertising-related provision — the purpose for which the recipients use it and the period for which they retain and use it: the same as set out in item 4(e).
- Advertising-related provision — how and by what procedure to refuse the transfer, and the effect of refusal: the user may refuse by not giving consent on the consent screen, and may withdraw consent at any time on the Settings tab after having given it. Where the user refuses or withdraws consent, the Company requests advertisements in a manner that is not tailored to the user's interests. Refusing or withdrawing consent carries no other disadvantage in using the app.

(d) The level of protection where the information is transferred
For items 5(a) to 5(d) (authentication, storage, server operation and AI processing), Google LLC, the person to whom the information is transferred, processes personal information only on the instructions of the Company under the data processing terms entered into with the Company, implements and maintains technical and organisational protective measures including encryption, and imposes the same obligations on any person it further entrusts with the processing while remaining responsible for that person's acts. Where the Company instructs deletion, it deletes the information from its own systems within a maximum period of 180 days.
Item 4(e) (advertising) is different. The advertising terms entered into between the Company and Google provide that the two companies are each independent controllers, so Google also processes the advertising-related items for its own purposes and by its own means, and the Company can neither instruct nor control that processing. Those terms do, however, require Google to comply with the data protection laws of each country that apply to that processing.
Through the terms above and the measures in item 12, the Company sees to it that personal information processed outside the country is protected at a level comparable to that within the country. However, the terms do not specify the country in whose facilities the person to whom the information is transferred will process it, and the Company cannot designate that location.

7. Procedures and methods for destroying personal information
- Destruction procedure: when an application to withdraw membership is received, the server first moves the transaction records that must be preserved in accordance with the applicable statutes (item 3) into separate storage, then deletes the data of that account down to its sub-records in a single operation and deletes the authentication account, after which the app deletes the vehicle photographs and the scheduled notifications remaining on the device.
- When vehicle sharing is terminated, the part of the sharing relationship information that concerns that participant is deleted immediately, and when the last participant leaves, the sharing relationship information of that vehicle is itself deleted.
- Destruction method: information stored in the form of electronic files is deleted by a method by which it cannot be recovered.
- Where information has to be kept separately, it is kept separately from other data and is destroyed by the same method once the retention period has ended.

8. Rights and obligations of data subjects and legal representatives, and how to exercise such rights
- A user may view, correct and delete the records that user has left at any time within the app.
- A user may receive a copy of the user's records at any time through Export data (CSV) on the Settings tab, without any separate condition such as the membership level or watching an advertisement.
- A user may request the deletion of personal information through Delete account on the Settings tab.
- A user may turn off the receipt of notifications at any time on the Settings tab.
- Consent to provision to a third party for vehicle sharing (item 4) may be withdrawn at any time by terminating the sharing. The owner of a vehicle may remove participants under Manage sharing on the Settings tab, and a user who has been given sharing may terminate the sharing in the same place by choosing that vehicle and pressing Unlink this vehicle, or by choosing Unlink from the More menu for that vehicle in the vehicle list. Once the sharing has been terminated, the other party can no longer view that vehicle and its records.
- A request to access, correct or delete personal information, or to suspend its processing, may also be made to chakeylog@gmail.com, and the Company takes the necessary action without delay.
- In the case of a child under 14 years of age, a legal representative may exercise the above rights on the child's behalf.

9. The age for which the Service is intended, and children's personal information
This Service is intended for adults aged 18 or over, and it is not designed for or promoted to children or adolescents. Given the nature of a service that manages the refueling, maintenance and expense records of a vehicle, its actual users are people who own or drive a vehicle. It is also registered with the app market as being intended for those aged 18 or over.
The Company does not have a separate age verification procedure. Instead, if the Company becomes aware that a child under 14 years of age is using the Service, or receives a notification from a legal representative, it deletes the account and the data concerned without delay. If you become aware of such a fact, please let us know at chakeylog@gmail.com.

10. Installation and operation of automatic personal information collection tools, and refusal thereof
- This app uses the Google AdMob advertising SDK, and the advertising SDK uses the advertising identifier (the Android advertising ID) to display advertisements and to measure their performance.
- In addition to the advertising identifier, the advertising SDK also collects the IP address, app usage interaction information and diagnostic information about the performance of the app, and Google can estimate the approximate location of the device from the IP address. The items collected are set out in item 1(c) and the explanation concerning location is set out in item 1(d).
- Of the automatic collection described above, the items sent to Google, including the advertising identifier, are sent only with the user's consent. How that consent is obtained, and what happens where it is not given, are set out in item 4(e). Consent may be withdrawn at any time on the Settings tab.
- A user may delete the advertising identifier, or turn off personalised advertising, in the settings of the Android device. The path differs according to the device manufacturer and the version of Android; usually Delete advertising ID or Opt out of personalised ads can be chosen under Settings > Privacy > Ads or Settings > Google > All services > Ads.
- Even where the advertising identifier is deleted, advertisements themselves continue to be displayed, and advertisements unrelated to the user's interests are shown. In addition, because the IP address is a value used for internet communication itself, its transmission cannot be prevented by deleting the advertising identifier or turning off personalised advertising.
- At the Premium level, banner advertisements are not displayed and functions can be used without watching rewarded advertisements. That is, no advertisements are displayed at the Premium level. However, because the advertising SDK is initialised together with the app when the app is launched regardless of the membership level, the automatic collection described above may take place even while no advertisement is displayed.
- The only way in which a user can become Premium by paying a fee is a paid subscription through Google Play in-app purchase. This subscription renews automatically and is charged again at the end of each usage period unless the user cancels it, and it may be cancelled at any time on the subscriptions screen of the Play Store app. The terms of the subscription, its renewal and cancellation, and the end of the usage period and the refund procedure, are set out in Article 7 of the Terms of Use.
- Separately from this, there are cases in which the Company grants a user the Premium level for a certain period at no charge to the user. The method and the scope of that grant are set out in item 12, the items stored when it is made are set out in item 1(c), and its terms are set out in Article 6(4) of the Terms of Use.

11. Handling of actual vehicle photographs
- Actual vehicle photographs taken by a user or chosen from the album are not transmitted to the server and are stored only within the user's device. Because a licence plate, the place where the vehicle is parked and the surroundings of the user's home are easily captured in such photographs, the Company has taken it as a principle not to keep them at all.
- The only thing stored on the server in relation to an actual photograph is the indication that an actual photograph has been registered for that vehicle; neither the photograph file nor its address is stored.
- In return, actual vehicle photographs are not carried over to a new device when the device is changed.
- Vehicle images generated by AI are different in nature. They are created from the manufacturer, vehicle name, generation and colour alone, so they contain no information by which an individual can be recognised, and they are stored in a cache used in common by all users and provided as they are to other users who have registered the same vehicle model.
- Even where a vehicle is shared with another user through the vehicle sharing function, the actual vehicle photograph is not displayed to the other party. This is because the photograph is not on the server, and the vehicle image seen by a user who has been given sharing is only the image generated by AI.
- Where an owner applies an AI-generated image and then changes it to an actual photograph, the actual photograph is shown on the owner's screen, but the AI-generated image that was last applied continues to be shown on the screen of a user who has been given sharing. This is because the actual photograph is not on the server and cannot be sent to the other party, and leaving that place empty would be an unexplained blank for the user who has been given sharing. For this purpose the Company keeps, in the vehicle information, the address of the AI-generated image that was last applied to that vehicle, and it is deleted when the vehicle is deleted or the member withdraws.
- Where a user exports a photograph by another route (sharing through a messenger service, social media and the like), responsibility for the information contained in that photograph rests with the user.
- The Android operating system has a function that backs up data stored on the device by an app to the user's own Google account, or carries it over to a new device. From the version in which this notice takes effect, the Company has configured the app so that actual vehicle photographs and the sign-in information, the purchase verification token and the app settings stored on the device by the app (item 1(c)) are excluded both from that backup and from device-to-device transfer. In versions of the app before that, the function was enabled, so these items may have been copied into the app's backup area in the user's own Google account. That backup resides in the user's own account and the Company can neither read nor delete it, so it is not deleted even when you withdraw your membership, and you cannot ask the Company to delete it. To remove it, you must yourself delete this app's backup data in the backup settings of your device or on the backup management screen of your Google account; the path, and whether deletion is possible, differ according to the device manufacturer, the version of Android and the settings of the Google account.

12. Measures to ensure the security of personal information
- Access control: direct access by the app to the database and to the file storage is entirely blocked by security rules. All reads and writes go through the server, which verifies the authentication token. Each request can access only the data of the account confirmed in the token and the data within the scope that another user has provided through vehicle sharing.
- Application of the scope of sharing: the kinds and the periods of records that a user who has been given sharing can view are determined and filtered by the server before being sent down. Records outside the scope are not transmitted to the app, and statistics and totals are recalculated using only the filtered records.
- Encryption in transit: communications between the app and the server, and between the server and the persons entrusted, are encrypted with HTTPS.
- Minimisation of privileges: the administrator screen and the administrator-only access path can be accessed only by accounts to which separate administrator privileges have been granted. Users' account information, vehicle information, refueling, maintenance, expense and symptom records and sharing relationship information can only be viewed there; no function to create, correct or delete them has been provided. The only thing an administrator can change in relation to a user's account is the membership level, as set out in "What an administrator can change" below.
- What an administrator can change: the Company can raise a user's membership level to Premium (for one week or for one year) on the administrator screen, or reverse a rise so made. The only thing stored in the user's account when this is done is "Premium granted by the Company" under item 1(c); the subscription information that the user has paid for through Google Play (the type of subscription product, the expiry date of the usage period and the purchase verification token) is neither read nor altered by this function. A reversal likewise extends only to a period granted by the Company, so a subscription that the user has paid for cannot be cancelled by this function. Where a period granted by the Company and a usage period paid for by the user exist together, the Premium level is maintained until the later of the two ends, and the level returns of itself once the period has passed. Such a change is also recorded in "Records of an administrator's viewing and changing" below. A user's records and vehicle information are not altered by this function.
- What an administrator can delete: separately from the viewing and changing functions above, a deletion function is provided only for shared data that is not connected to any particular user. It covers only three things: AI-generated vehicle images, the vehicle generation hints used when creating those images, and the popular Wishcar counts (all of them items set out in item 3). This is in order to take down an image about which a report of rights infringement has been received, and to delete an image that has been created incorrectly so that it can be created again. For an image taken down following a report, the image file is deleted and only a mark that it has been taken down is left, so that the same image is not created again. Users' accounts and records are not deleted by this function.
- Records of an administrator's viewing and changing: where a user's personal information is viewed through the administrator screen, or a change under "What an administrator can change" above is made, a record of it is created and kept for one year (items 1(c) and 3). This is a security measure laid down by the applicable statutes, and its purpose is to make it possible to confirm afterwards who viewed whose information, when, what information, and what was changed.
- Restriction of abnormal requests: the server restricts excessive repeated requests coming from the same access point.
- Minimal collection: actual vehicle photographs, which carry the greatest risk of identifying an individual, are not collected in the first place.

13. The agency that collects and holds personal information, and the privacy officer
- The agency that collects and holds the personal information: Chakeylog (operated by Sang Ho Cho)
- Address: 114-1902, 1645, Seohaean-ro, Siheung-si, Gyeonggi-do, Republic of Korea
- Privacy officer: Sang Ho Cho
- Contact: chakeylog@gmail.com
Enquiries, the handling of complaints and matters concerning remedies for harm in relation to the protection of personal information may be addressed to the contact above, and the Company will reply without delay.

14. Remedies for infringement of rights and interests
A user may raise a complaint about the processing of personal information, or an objection to a breach of this Policy, directly with the Company using the contact details in item 13. The Company investigates what it receives and replies with the outcome and the action taken; where the handling is delayed, it first informs the user of the reason and the expected timeframe.
Irrespective of the complaint procedure above, in order to obtain relief for harm caused by an infringement of personal information, you may apply to the bodies below for dispute resolution or for consultation. The same applies where you do not agree with the outcome of the Company's handling.
If you use the Service outside the Republic of Korea, you may also lodge a complaint with the personal data protection authority of the country in which you are located. The bodies listed below are the channels in the Republic of Korea.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Call Center: 118 (privacy.kisa.or.kr)
- Cyber and Technology Crime Investigation Division of the Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Cybercrime Report System (ECRM) of the National Police Agency: 182 (ecrm.police.go.kr)

15. Amendment of this Privacy Policy
This Policy may be amended in line with changes in the applicable statutes or in the content of the Service. Where it is amended, the Company posts the content of the amendment and its effective date on the Privacy Policy screen of the app and on the privacy policy page operated by the Company (https://carmanager-server-94717856434.asia-northeast3.run.app/privacy), and continues to post them after the amendment so that they can be checked at any time. These two places are the method of giving notice of an amendment.
- Content of this amendment: there are two.
  · How the currency attached to a newly created refueling, maintenance or expense record is determined has been restated in item 1(b) so as to match the facts. The previous wording mentioned only the region setting of the device and omitted that the app follows the currency chosen by the user in the app's settings. That has now been stated together with the country chosen by the user in the app's settings and a currency clearly stated in the sentence when the user enters a record by AI, and it has been added that the currency of a record saved by the user can be changed by opening that record. It has also been made clear that the records treated as being in Korean won because no currency code is stored include records created with a version of the app from before currency codes were stored together with the amounts. The currency code is a value that has been stored all along; this amendment states accurately how that value is determined.
  · The country sent by the app when the user requests estimated running costs by vehicle model has been set out in item 1(c). That value has been sent together with the request all along so that the estimated running costs can be shown in the currency and at the price level of that country, and the Company's server does not store it.
- Content of the previous amendment (announced and effective on September 14, 2026): there were two.
  · It has been stated in item 1(b) that the amounts in refueling, maintenance and expense records are stored together with a currency code indicating the currency in which the amount is expressed. No value separately asked of and received from the user has come into being; what is recorded is what the amounts that the user has been entering all along are expressed in. Existing records for which no currency code is stored are treated as being in Korean won, and the Company neither alters the amounts in existing records nor converts them into another currency.
  · The order in which vehicles are arranged in the vehicle list, one of the app settings stored in the user's account, was missing from item 1(c) and has been added. That value has been stored all along, and the items that the Company collects or keeps are not increased by this amendment.
- Content of the amendment before that (announced and effective on September 13, 2026): there was one.
  · It has been stated in item 11 that data stored on the device by this app may have been copied into the user's own Google account through the backup and device-transfer functions of the Android operating system, and that only the user can delete such a copy. In addition, from this version the Company has configured the app so that actual vehicle photographs, the sign-in information, the purchase verification token and the app settings are excluded both from that backup and from device-to-device transfer. Even previously, that backup took place only within the user's own account and the Company has never read or kept it; the items that the Company collects or keeps are not increased.
- Content of the amendment before those (announced and effective on September 11, 2026): there were three.
  · The Company can now raise a user's membership level to Premium on the administrator screen, or reverse a rise so made. This is in order to provide users with the Premium level at no charge to them; the subscription information that a user has paid for through Google Play is neither read nor altered by this function, and the Company cannot cancel a subscription that has been paid for. Five places have accordingly been corrected. (1) The items stored in the user's account when this is done have been set out in item 1(c). (2) That item has been added to the data deleted on withdrawal in item 3. (3) Item 10 now states separately how a user can become Premium by paying a fee and the cases in which the Company grants the level at no charge. (4) In "Minimisation of privileges" in item 12 it is stated that the only thing an administrator can change is the membership level, and a new entry "What an administrator can change" has been added. (5) The descriptions of administrators' records in items 1(c), 3 and 12 have been widened to cover not only viewing but also changing. The items that the Company newly collects from users are not increased.
  · Item 14 now states that a user who uses the Service outside the Republic of Korea may also lodge a complaint with the personal data protection authority of the country in which the user is located. Item 14 previously listed only four bodies in the Republic of Korea, which are not channels actually available to users outside the Republic of Korea. The items that the Company collects or processes are unchanged; a right that users have had all along has simply been stated.
  · A statement has been added at the end of item 4(e) that, when a user uses this app, Google, which is a party other than the Company, may collect information about the user's online activities over time and also across other services, websites and apps outside this app. This is because California Business and Professions Code section 22575(b)(6) requires that fact to be disclosed in the privacy policy. The items that the Company collects or that are sent to Google are not increased; a fact that has existed all along has simply been stated.
- Content of the amendment earlier still (announced and effective on September 10, 2026): there were two.
  · The processing by which the advertising SDK included in the app sends the advertising identifier and other items to Google has been reclassified as a provision to a third party rather than an entrustment of the processing of personal information, and it now takes place only after the user's consent has been obtained. This is because the advertising terms entered into between the Company and Google make the two companies each independent controllers, so that processing is not bound by the Company's instructions. Four places have accordingly been corrected. (1) What was set out in item 5(e) has been moved to item 4(e), and the five matters of which the user is informed when consent is obtained have been set out there. (2) A note has been left in item 5(e) stating that its content has been moved to item 4. (3) The basis for the cross-border transfer in item 6(a) has been divided in two, stating that separate consent is obtained for the advertising-related provision under Article 28-8(1)1 of the Personal Information Protection Act, and the matters of which the user is given advance notice before that consent have been set out in item 6(c). (4) How consent is given and withdrawn has been set out in item 10. The items that the Company collects or that are sent to Google are not themselves increased; a consent procedure has newly been put in place for processing that previously took place without consent.
  · Where an administrator of the Company views a user's personal information through the administrator screen, a record of that viewing is now created. This is a security measure laid down by Article 30(1)5 of the Enforcement Decree of the Personal Information Protection Act and by Article 8(1) of the public notice issued under the delegation in that provision. Three places have accordingly been corrected. (1) The items recorded have been set out in item 1(c). (2) The retention period (one year) has been set out in item 3, together with an explanation of why it differs from the 30 days for a user's own server access logs. (3) That measure has been set out in item 12. The items that the Company newly collects from users are not increased.
- Date of announcement: September 27, 2026
- Effective date: September 27, 2026