Privacy Policy

Last revised: July 2026 (v2) | Effective: upon official release

한국어 버전 보기 (Korean version)

Dokbaek ("the Service", "we") is an anonymous text-based short-form content app. This Privacy Policy explains what data we process, why, for how long, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Personal Information Protection Act of the Republic of Korea (PIPA).

1. Data Controller

2. Data We Process

The Service has no account system, and we do not require your name, email address, phone number, precise location, contact list, or advertising identifiers in order to use it. If you email us to submit a rights-infringement report or an inquiry, we process the contact details you provide solely to respond to you.

DataHow it is obtainedPurposeRetention
Device identifier (UUID)Randomly generated on your device at first launchAnonymous user distinction, credit management, duplicate-vote prevention, abuse preventionUntil you request deletion.
The copy of your UUID stored in the content archive (Section 6.3) is deleted 90 days after posting, regardless of a deletion request.
IP address, source port and access timestampAutomatically logged by the server when you post contentEvidence retention to provide the information the Service holds in the event of a dispute or a lawful request from law enforcement90 days from collection
Content you write (text)Entered by youService provision, content moderation24 hours in the feed; archived original kept 90 days
Vote recordsGenerated when you voteDuplicate-vote prevention, credit rewardsDeleted together with the related post
Reporter contact (email) and report detailsProvided by you when submitting a rights-infringement report or inquiryHandling the report and notifying you of the outcome; defence of legal claims3 years from completion of handling

3. Legal Bases for Processing (GDPR Art. 6)

4. Content Moderation and Automated Decisions

In accordance with Article 37-2 of the Personal Information Protection Act of Korea (and Article 22 of the GDPR), we disclose below the criteria and procedures for decisions made by fully automated systems.

4.1 Types of automated decisions

DecisionData processedCriteria and procedureEffect
Rejecting a post The text you submit At submission, a prohibited-word filter and an AI-based safety check (OpenAI Moderation API) are applied in sequence. Text falling into a harmful category is refused. The post is not published; the reason is shown on screen.
Hiding a post Reports accumulated against that post A post is automatically hidden once reports from other users exceed a threshold. We do not publish the exact threshold, because disclosing it would enable coordinated reporting to silence posts (abuse). The post no longer appears in the feed.
Posting restriction Violation records associated with the device identifier (UUID) Devices with repeated Community Guideline violations may have posting restricted. To prevent circumvention (reinstalling the app to regenerate the identifier), the restriction may not be visibly indicated on screen. Your posts are not shown to other users.

4.2 Explanation and appeal

You may request an explanation of the criteria and process behind any of these decisions, and you may submit your views and ask us to review whether they can be reflected in the decision. Contact us at the address in Section 1; we will confirm whether a decision applies to your device and why, and respond within 15 days. Any restriction found to be unwarranted is lifted without delay.

Where an automated decision significantly affects your rights or obligations, you may object to it. However, automated safety screening is applied to every post as a necessary part of performing our agreement with you and protecting other users; if you object to it, the posting feature will be unavailable to you. Browsing and voting remain available.

5. Sharing and International Transfers

5.1 No sale, no advertising sharing

We do not sell personal data and do not share it with advertisers or analytics providers. We use no cookies, no tracking SDKs, and no third-party analytics.

5.2 Disclosure to authorities

We disclose data only where required by applicable law or pursuant to a valid legal process (e.g., a warrant).

5.3 Transfer to OpenAI (United States)

ItemDetail
RecipientOpenAI, L.L.C., United States (privacy@openai.com)
Data transferredThe text body of your post only. Your UUID and IP address are never sent.
PurposeAutomated content safety screening (Moderation API)
Transfer timing / methodAt the moment you submit a post, over an encrypted connection (HTTPS)
SafeguardsOpenAI participates in the EU-U.S. Data Privacy Framework and offers Standard Contractual Clauses under its Data Processing Addendum. Per OpenAI's API data policy, API inputs are not used to train models.
RefusalYou may refuse this transfer by not using the posting feature or by notifying us at the contact above. Because safety screening is mandatory for all posts, refusing the transfer means the posting feature is unavailable to you; browsing and voting remain available.

5.4 Hosting (United States)

The Service is operated by a controller established in the Republic of Korea, but its application server and database are hosted on Railway (Railway Corp., United States) in the US West region. All data described in Section 2 is therefore stored in the United States.

ItemDetail
RecipientRailway Corp., United States (hosting provider)
LocationUS West region (California)
Data storedDevice identifier (UUID), IP address and access timestamp, post content, vote records
PurposeOperation of the application server and database (hosting)
RetentionSame as the retention periods in Section 2; Railway stores data only for as long as we instruct
SafeguardsRailway acts as our processor under a data processing agreement incorporating the EU Standard Contractual Clauses
RefusalHosting is essential to providing the Service; if you do not wish your data to be stored in the United States, please discontinue use and delete your data via [Settings > 데이터 삭제 / "Delete data"].

5.5 Email correspondence (United States)

Rights-infringement reports and inquiries are received by email (Gmail), which is hosted by a provider in the United States.

ItemDetail
RecipientGoogle LLC, United States (email service provider)
Data transferredReporter's email address and the content of the report or inquiry
PurposeReceiving and storing correspondence in order to handle reports and notify outcomes
Transfer timing / methodAt the moment you send us an email, via the email service
Retention3 years from completion of handling (same as Section 2)
RefusalThis transfer occurs only if you choose to email us; if you do not, no transfer takes place. If you wish to contact us by another means, let us know and we will provide an alternative.

6. Retention and Deletion

6.3 The content archive

7. Your Rights

Subject to applicable law (GDPR Art. 15–21, PIPA, and similar laws), you have the right to:

Because we hold no account information, rights requests made by email may require you to provide information available in your app's [Settings] screen so we can locate the data associated with your device.

8. Children

The Service is not directed to children. You must be at least 14 years old, or older where your local law sets a higher minimum age for consenting to data processing without parental authorization (up to 16 in some EU/EEA countries). We do not knowingly process children's data; if we learn that we have, we will delete it without delay.

You confirm that you meet the minimum age when you first launch the app. In addition, if you come across a user who appears to be under 14, you can let us know through the in-app report menu ([Report > This user appears to be under 14]). Reports are reviewed by the operator directly.

9. Security

If we become aware of a personal data breach, we will notify affected users without undue delay (within 72 hours) via in-app notice and this page, stating the data involved, the time and circumstances, the steps you can take, our response measures, and contact points for complaints. Where required by law, we will also report the breach to the Personal Information Protection Commission of Korea and, for EU/EEA users, to the competent supervisory authority.

10. Changes to This Policy

We will announce changes in the app at least 7 days before they take effect (30 days for changes that materially affect your rights).

Revision history