Last revised: July 2026 (v2) | Effective: upon official release
Dokbaek ("the Service", "we") is an anonymous text-based short-form content app. This Privacy Policy explains what data we process, why, for how long, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Personal Information Protection Act of the Republic of Korea (PIPA).
The Service has no account system, and we do not require your name, email address, phone number, precise location, contact list, or advertising identifiers in order to use it. If you email us to submit a rights-infringement report or an inquiry, we process the contact details you provide solely to respond to you.
| Data | How it is obtained | Purpose | Retention |
|---|---|---|---|
| Device identifier (UUID) | Randomly generated on your device at first launch | Anonymous user distinction, credit management, duplicate-vote prevention, abuse prevention | Until you request deletion. The copy of your UUID stored in the content archive (Section 6.3) is deleted 90 days after posting, regardless of a deletion request. |
| IP address, source port and access timestamp | Automatically logged by the server when you post content | Evidence retention to provide the information the Service holds in the event of a dispute or a lawful request from law enforcement | 90 days from collection |
| Content you write (text) | Entered by you | Service provision, content moderation | 24 hours in the feed; archived original kept 90 days |
| Vote records | Generated when you vote | Duplicate-vote prevention, credit rewards | Deleted together with the related post |
| Reporter contact (email) and report details | Provided by you when submitting a rights-infringement report or inquiry | Handling the report and notifying you of the outcome; defence of legal claims | 3 years from completion of handling |
In accordance with Article 37-2 of the Personal Information Protection Act of Korea (and Article 22 of the GDPR), we disclose below the criteria and procedures for decisions made by fully automated systems.
| Decision | Data processed | Criteria and procedure | Effect |
|---|---|---|---|
| Rejecting a post | The text you submit | At submission, a prohibited-word filter and an AI-based safety check (OpenAI Moderation API) are applied in sequence. Text falling into a harmful category is refused. | The post is not published; the reason is shown on screen. |
| Hiding a post | Reports accumulated against that post | A post is automatically hidden once reports from other users exceed a threshold. We do not publish the exact threshold, because disclosing it would enable coordinated reporting to silence posts (abuse). | The post no longer appears in the feed. |
| Posting restriction | Violation records associated with the device identifier (UUID) | Devices with repeated Community Guideline violations may have posting restricted. To prevent circumvention (reinstalling the app to regenerate the identifier), the restriction may not be visibly indicated on screen. | Your posts are not shown to other users. |
You may request an explanation of the criteria and process behind any of these decisions, and you may submit your views and ask us to review whether they can be reflected in the decision. Contact us at the address in Section 1; we will confirm whether a decision applies to your device and why, and respond within 15 days. Any restriction found to be unwarranted is lifted without delay.
Where an automated decision significantly affects your rights or obligations, you may object to it. However, automated safety screening is applied to every post as a necessary part of performing our agreement with you and protecting other users; if you object to it, the posting feature will be unavailable to you. Browsing and voting remain available.
We do not sell personal data and do not share it with advertisers or analytics providers. We use no cookies, no tracking SDKs, and no third-party analytics.
We disclose data only where required by applicable law or pursuant to a valid legal process (e.g., a warrant).
| Item | Detail |
|---|---|
| Recipient | OpenAI, L.L.C., United States (privacy@openai.com) |
| Data transferred | The text body of your post only. Your UUID and IP address are never sent. |
| Purpose | Automated content safety screening (Moderation API) |
| Transfer timing / method | At the moment you submit a post, over an encrypted connection (HTTPS) |
| Safeguards | OpenAI participates in the EU-U.S. Data Privacy Framework and offers Standard Contractual Clauses under its Data Processing Addendum. Per OpenAI's API data policy, API inputs are not used to train models. |
| Refusal | You may refuse this transfer by not using the posting feature or by notifying us at the contact above. Because safety screening is mandatory for all posts, refusing the transfer means the posting feature is unavailable to you; browsing and voting remain available. |
The Service is operated by a controller established in the Republic of Korea, but its application server and database are hosted on Railway (Railway Corp., United States) in the US West region. All data described in Section 2 is therefore stored in the United States.
| Item | Detail |
|---|---|
| Recipient | Railway Corp., United States (hosting provider) |
| Location | US West region (California) |
| Data stored | Device identifier (UUID), IP address and access timestamp, post content, vote records |
| Purpose | Operation of the application server and database (hosting) |
| Retention | Same as the retention periods in Section 2; Railway stores data only for as long as we instruct |
| Safeguards | Railway acts as our processor under a data processing agreement incorporating the EU Standard Contractual Clauses |
| Refusal | Hosting is essential to providing the Service; if you do not wish your data to be stored in the United States, please discontinue use and delete your data via [Settings > 데이터 삭제 / "Delete data"]. |
Rights-infringement reports and inquiries are received by email (Gmail), which is hosted by a provider in the United States.
| Item | Detail |
|---|---|
| Recipient | Google LLC, United States (email service provider) |
| Data transferred | Reporter's email address and the content of the report or inquiry |
| Purpose | Receiving and storing correspondence in order to handle reports and notify outcomes |
| Transfer timing / method | At the moment you send us an email, via the email service |
| Retention | 3 years from completion of handling (same as Section 2) |
| Refusal | This transfer occurs only if you choose to email us; if you do not, no transfer takes place. If you wish to contact us by another means, let us know and we will provide an alternative. |
Subject to applicable law (GDPR Art. 15–21, PIPA, and similar laws), you have the right to:
Because we hold no account information, rights requests made by email may require you to provide information available in your app's [Settings] screen so we can locate the data associated with your device.
The Service is not directed to children. You must be at least 14 years old, or older where your local law sets a higher minimum age for consenting to data processing without parental authorization (up to 16 in some EU/EEA countries). We do not knowingly process children's data; if we learn that we have, we will delete it without delay.
You confirm that you meet the minimum age when you first launch the app. In addition, if you come across a user who appears to be under 14, you can let us know through the in-app report menu ([Report > This user appears to be under 14]). Reports are reviewed by the operator directly.
If we become aware of a personal data breach, we will notify affected users without undue delay (within 72 hours) via in-app notice and this page, stating the data involved, the time and circumstances, the steps you can take, our response measures, and contact points for complaints. Where required by law, we will also report the breach to the Personal Information Protection Commission of Korea and, for EU/EEA users, to the competent supervisory authority.
We will announce changes in the app at least 7 days before they take effect (30 days for changes that materially affect your rights).