WayKo Privacy Policy · 개인정보 처리방침
Last updated: 24 September 2026 · 최종 수정: 2026년 9월 24일
English
1. About WayKo and this policy
WayKo helps travelers explore South Korea, find places and routes, save places, and build travel plans. WayKo is published on Google Play by Tagmeet Company. This policy describes the Android app, package com.wayko, and the services used by its features.
For privacy questions and requests, contact henry_kim@kakao.com.
WayKo does not require a WayKo account. Saved places and travel plans are stored on your device without WayKo cloud synchronization. Using an online feature sends the information needed for that feature to the providers described below. Optional analytics and AI processing have separate controls.
2. Travel information on your device
The app stores saved place identifiers and details, trip titles, dates, stops, notes, visited status, itinerary import text, draft settings, language preferences, and discovery history in local app storage. This lets you keep editing and revisit saved places. The app also stores local usage counters and subscription status used by its interface.
Your saved travel library is not automatically uploaded to a WayKo account or cloud planner. When you deliberately use AI, the submitted text and relevant planning context leave your device as described in section 4. Looking up places or routes also sends the relevant search or route information as described in section 3.
3. Maps, search, location, photos, and links
Map and place features use search terms, selected places, map area, language, and origin or destination coordinates to display maps, find places, retrieve photos and details, or calculate routes. Depending on the feature, requests are processed by Google Maps, Places and Routes, NAVER map and content services, or TMAP walking-route services through SK open API. WayKo's Cloudflare services and the hosts of requested maps, photos, and travel content also receive network requests.
Current location is used with your device's permission for features such as nearby places, distance, and routes from your position. Location may be precise or approximate, depending on your permission and device. WayKo uses location while the app is in use and does not implement background location tracking. You can change location access in Android settings. Declining it can limit current-position features; you can still browse and choose places manually.
These providers receive the request information relevant to their service, along with network information such as your IP address and technical app or device information. A map or photo request can reach a provider even when you have not enabled analytics. When you choose a video search, website, or other external link, the destination service receives the link request, including a place search term where applicable, and applies its own privacy practices.
Google's map SDK also processes a pseudonymous SDK identifier, device and request metadata, map interaction events, and SDK crash information to operate and improve its services. These SDK records are separate from WayKo's optional usage analytics.
The updated Android release 0.51 does not record or upload microphone audio.
Earlier Android releases, including 0.33, include optional voice search. When you use it, the app records an audio clip with microphone permission and sends it to OpenAI’s transcription API. The recognized text is then used for place searches, including requests to Google Places. Those providers receive the information needed for that request. Updating to 0.51 disables this voice feature; it does not itself delete data previously processed by providers. OpenAI’s applicable processing and retention practices are described in its API data controls.
4. Optional AI itinerary import and travel conversation
AI features are optional. When you submit an itinerary for AI organization, your pasted text, language, and request metadata are sent to WayKo's service on Cloudflare, which forwards the text to Anthropic's Claude Haiku API to create an editable itinerary.
When you send a travel-planning message, Cloudflare and Anthropic process your message and recent conversation context, selected region, party size, companion category, pace, interests, and selected place names. If you open AI for an existing trip, the request can include a short summary of the trip title, day or date, and stop names. The service can send derived place-search queries to Google Places and return relevant place results to Anthropic to prepare recommendations.
AI requests do not automatically include your live GPS position. Your text or trip context can still reveal locations or personal information. Before submitting, remove passport numbers, payment details, booking access codes, and other sensitive information that is unnecessary for planning. You can use local itinerary editing without sending content to AI.
AI conversation messages, replies, and recommendation cards remain in screen memory. Preferences and unsent input are saved locally to resume a draft. Chosen places become part of your saved travel library when you save them. AI does not automatically upload the rest of your saved travel library.
5. Subscriptions and service protection
Google Play processes Android subscription purchases. The app receives purchase evidence and subscription information from the store. For paid AI access, the app sends the purchase token to WayKo's Cloudflare service, which checks the current subscription state, product, and expiry with Google Play. The app does not receive or request your payment-card number or bank-account details.
The AI service uses a hash derived from the verified purchase token to associate usage with a subscription. This is a pseudonymous identifier, not a guarantee that the records are anonymous. The original purchase token is used for verification but is not saved in WayKo's AI usage ledger or application logs.
For introductory AI planning without a subscription, the app uses Firebase Authentication to create an anonymous sign-in identifier without asking for an email address or password. Firebase processes this identifier and authentication request metadata. The app sends a signed authentication token to Cloudflare to verify access and associate the first-use record with that identifier. Anonymous sign-in is pseudonymous identification, not a promise that no user data is processed. You can browse and edit local trips without using this optional AI feature.
Firebase App Check and Google Play Integrity process app and device integrity information to protect online service access. Requests can contain attestation tokens, app identifiers, and technical information. Cloudflare also uses the request IP address for rate limiting. WayKo records request identifiers and hashes, attempt status, timestamps, and input/output token counts to enforce AI allowances and handle retries. These protections operate independently of optional usage analytics.
6. Optional usage analytics
Usage analytics starts disabled. You can enable or disable it in My → Usage analytics. When enabled, Google Analytics for Firebase processes screen views, feature actions, app language, predefined region/place/food identifiers, day counts, result codes, and usage indicators. Its SDK also processes app-instance identifiers, technical app/device information, approximate location derived from network information, and applicable app lifecycle and purchase events.
WayKo's custom analytics events exclude free-form search, itinerary and chat text, and exact coordinates. The app sets advertising storage, advertising user data, and advertising personalization consent to disabled. Turning analytics off stops future collection through the app's consent controls; it does not delete events that were already collected.
7. Retention and deletion
- Saved travel information: kept locally until you edit or delete it, or clear the app's storage in Android settings. Saved trips have no automatic expiry. Deleting a trip removes it from the active library; separate drafts, caches, or a recovery copy created after a storage error may remain. Clearing app storage removes these local copies and preferences. Keep any information you need before doing so.
- Local AI drafts: preferences and unsent text are stored locally. Drafts older than 24 hours are not restored. This age check does not erase the stored bytes at a scheduled time; clearing app storage removes them.
- AI import results: the WayKo Cloudflare ledger caches the parsed itinerary result for retry recovery for 24 hours after its recorded update. The result may contain information from your original input. The raw submitted text is not separately persisted in that ledger.
- AI conversation records: the ledger retains a delivery marker and metering metadata, not the chat messages, generated reply, or Google recommendation bodies.
- AI usage metadata: request records are scheduled for deletion 62 days after their last update; attempt records 62 days after creation. Cleanup runs through scheduled storage jobs and on subsequent requests. These are live-storage rules; provider backup and recovery records have separate lifecycles.
- Provider records and support: analytics records, store transactions, provider operational logs and backups, and emails sent to support are not governed by WayKo's 24-hour or 62-day AI ledger rules. They are handled in the relevant provider service or support mailbox. Contact us for questions or a deletion request relating to information held by WayKo.
The AI ledger's deletion rules do not mean that Anthropic or another provider immediately deletes information it has processed. Provider retention and any exceptions are described in their own policies linked below. Removing app data does not erase information already sent to providers or cancel a Google Play subscription. The current Android app disables Android's standard app backup.
Firebase anonymous sign-in identifiers and AI first-use records remain until deletion is requested and processed; clearing app storage does not itself delete these server records. AI request/attempt metadata has the separate retention periods described above. For deletion, use the contact procedure in section 8. Do not send authentication tokens or purchase receipts in ordinary email.
8. Privacy requests and support
Email henry_kim@kakao.com to ask about access, correction, deletion, or another privacy concern. Describe the feature and approximate time involved so the relevant records can be identified. Do not include passwords, payment-card details, passport copies, or a full purchase token in your first email. Additional information may be needed to identify relevant records and avoid disclosing someone else's information.
Because WayKo has no account-based copy of your saved travel library, we cannot retrieve or remotely edit local-only trips for you. You can edit or delete those items in the app or clear app storage. There is no in-app control that deletes all provider-side records. For data held directly by a provider, its privacy controls and contact channels may also be relevant.
If you contact support, your email address, message, and attachments you choose to send are processed by your email service and the support mailbox provider to handle your request.
9. Providers, international processing, and security
WayKo uses HTTPS for production service requests and keeps AI provider and subscription-verification secrets on its backend. Local app storage is not an encrypted backup service or a secure document vault.
The providers used by WayKo operate network infrastructure in multiple countries. Information sent to an online feature may be processed outside your country. Their privacy notices explain their practices, including international processing, retention, and applicable choices:
- Google Privacy Policy — maps, place search, routes, Google Play, and Google services.
- Firebase privacy and security — App Check and Firebase services.
- Cloudflare Privacy Policy — service delivery and network infrastructure.
- Anthropic Privacy Policy and commercial API data retention — AI input and output processing.
- NAVER Privacy Policy — NAVER services.
- SK open API privacy notice — the API platform used for TMAP walking-route requests.
10. Policy updates
Updates to this policy are identified by the revision date at the top of the page. For questions about a change or the practices described here, use the privacy contact above.
한국어
1. WayKo와 이 방침의 적용 범위
WayKo는 한국의 지역과 장소 탐색, 지도와 길찾기, 장소 저장, 여행 일정 작성을 돕습니다. WayKo의 Google Play 게시자명은 Tagmeet Company입니다. 이 방침은 패키지명 com.wayko인 Android 앱과 각 기능에서 이용하는 서비스의 개인정보 처리를 설명합니다.
개인정보 문의와 요청은 henry_kim@kakao.com으로 보내 주세요.
WayKo 계정을 만들 필요는 없습니다. 저장한 장소와 여행 일정은 기기에 보관하며 WayKo 클라우드와 동기화하지 않습니다. 온라인 기능을 사용하면 해당 기능에 필요한 정보가 아래에 설명한 제공업체로 전달됩니다. 선택형 이용 통계와 AI 전송은 별도로 선택할 수 있습니다.
2. 기기에 보관하는 여행 정보
앱은 저장한 장소의 식별자와 세부 정보, 여행 제목·날짜·방문 장소·메모·방문 상태, 가져온 일정 원문, 초안 설정, 언어 설정, 탐색 이력을 기기 내 앱 저장소에 보관합니다. 이를 통해 편집을 이어 가고 저장한 장소를 다시 볼 수 있습니다. 화면에서 사용하는 이용 횟수와 구독 상태도 기기에 저장합니다.
저장한 여행 목록을 WayKo 계정이나 클라우드 플래너에 자동 업로드하지 않습니다. 사용자가 AI를 이용하면 4항에 설명한 입력 내용과 관련 여행 맥락이 기기 밖으로 전송됩니다. 장소 검색이나 길찾기에도 3항과 같이 필요한 검색어와 경로 정보가 전달됩니다.
3. 지도·검색·위치·사진·외부 링크
지도와 장소 기능은 검색어, 선택한 장소, 지도 영역, 언어, 출발지·목적지 좌표를 사용해 지도를 표시하고 장소·사진·세부 정보·경로를 찾습니다. 기능에 따라 Google Maps·Places·Routes, NAVER 지도·콘텐츠 서비스, SK open API를 통한 TMAP 도보 경로 서비스가 요청을 처리합니다. WayKo의 Cloudflare 서비스와 요청한 지도·사진·여행 콘텐츠를 제공하는 서버에도 네트워크 요청이 전달됩니다.
현재 위치는 기기 권한을 받은 뒤 주변 장소, 거리 표시, 현재 위치에서의 길찾기 등에 사용합니다. 권한과 기기에 따라 정확한 위치나 대략적인 위치가 사용될 수 있습니다. WayKo는 앱 사용 중 위치를 사용하며 백그라운드 위치 추적을 구현하지 않습니다. Android 설정에서 위치 권한을 바꿀 수 있습니다. 거부하면 현재 위치 기능이 제한될 수 있지만, 지역을 탐색하거나 장소를 직접 선택할 수 있습니다.
각 제공업체는 해당 서비스에 필요한 요청 정보와 IP 주소, 앱·기기 관련 기술 정보를 받을 수 있습니다. 이용 통계를 켜지 않아도 지도나 사진 요청은 제공업체에 전달될 수 있습니다. 영상 검색, 웹사이트 등 외부 링크를 선택하면 해당 서비스가 링크 요청과 필요한 경우 장소 검색어를 받으며, 그 서비스의 개인정보 처리 방식이 적용됩니다.
Google 지도 SDK는 서비스 운영과 개선을 위해 가명 SDK 식별자, 기기·요청 정보, 지도 조작 이벤트, SDK 오류 정보도 처리합니다. 이러한 SDK 기록은 WayKo의 선택형 이용 통계와 별개입니다.
업데이트된 Android 0.51 버전은 마이크 음성을 녹음하거나 업로드하지 않습니다.
0.33을 포함한 이전 Android 버전에는 선택형 음성 검색이 있습니다. 이용하면 마이크 권한을 받아 음성 파일을 녹음하고 OpenAI의 음성 변환 API로 보냅니다. 변환된 텍스트는 Google Places 요청을 포함한 장소 검색에 사용되며, 해당 제공업체는 요청에 필요한 정보를 받습니다. 0.51로 업데이트하면 음성 기능은 비활성화되지만, 제공업체가 이전에 처리한 정보가 함께 삭제되는 것은 아닙니다. OpenAI의 처리·보관 방식은 API 데이터 관리 안내를 참고하세요.
4. 선택형 AI 일정 가져오기와 여행 대화
AI 기능은 선택 사항입니다. AI로 일정을 정리하도록 제출하면 붙여 넣은 원문, 언어, 요청 정보가 Cloudflare에서 실행되는 WayKo 서비스로 전달됩니다. 이 서비스는 편집 가능한 일정을 만들기 위해 원문을 Anthropic의 Claude Haiku API로 보냅니다.
여행 대화 메시지를 보내면 Cloudflare와 Anthropic이 메시지와 최근 대화 맥락, 선택한 지역, 인원수, 동행 유형, 여행 속도, 관심사, 선택한 장소 이름을 처리합니다. 기존 여행에서 AI를 열면 여행 제목, 여행일 또는 날짜, 방문 장소 이름을 포함한 짧은 요약이 전달될 수 있습니다. 서비스는 생성한 장소 검색어를 Google Places로 보내고 관련 검색 결과를 Anthropic으로 전달해 추천을 작성할 수 있습니다.
AI 요청에 실시간 GPS 위치를 자동으로 넣지는 않습니다. 다만 글이나 여행 맥락 자체에 위치 또는 개인정보가 포함될 수 있습니다. 제출 전에 여행 준비에 필요하지 않은 여권 번호, 결제 정보, 예약 접근 코드 등 민감한 내용은 제거해 주세요. AI에 보내지 않고 기기에서 일정을 직접 편집할 수도 있습니다.
AI 대화의 메시지, 답변, 추천 카드는 화면 메모리에 유지합니다. 초안을 이어 쓰기 위한 취향과 보내지 않은 입력은 기기에 저장합니다. 선택한 장소는 사용자가 저장할 때 여행 목록에 들어갑니다. AI가 나머지 저장된 여행 목록을 자동 업로드하지는 않습니다.
5. 구독 확인과 서비스 보호
Android 구독 결제는 Google Play가 처리합니다. 앱은 스토어에서 구매 증빙과 구독 정보를 받습니다. 유료 AI 기능 이용 시 앱이 구매 토큰을 WayKo의 Cloudflare 서비스로 보내면, 서버가 Google Play에서 현재 구독 상태, 상품, 만료일을 확인합니다. 앱은 결제 카드 번호나 은행 계좌 정보를 받거나 요청하지 않습니다.
AI 서비스는 검증된 구매 토큰에서 만든 해시값으로 구독과 이용량을 연결합니다. 이는 가명 식별자이며 기록이 완전히 익명이라는 뜻은 아닙니다. 원본 구매 토큰은 검증에 사용하지만 WayKo AI 이용량 저장소나 애플리케이션 로그에 저장하지 않습니다.
구독 전 AI 일정 체험에는 Firebase Authentication을 사용해 이메일이나 비밀번호 입력 없이 익명 로그인 식별자를 만듭니다. Firebase는 이 식별자와 인증 요청 정보를 처리합니다. 앱은 접근 검증과 첫 이용 기록 연결을 위해 서명된 인증 토큰을 Cloudflare로 보냅니다. 익명 로그인은 가명 식별 방식이며 개인정보를 전혀 처리하지 않는다는 뜻이 아닙니다. 선택형 AI 기능을 이용하지 않고도 장소를 탐색하고 기기에서 일정을 편집할 수 있습니다.
Firebase App Check와 Google Play Integrity는 앱·기기 무결성 정보를 처리해 온라인 서비스 접근을 보호합니다. 요청에 무결성 확인 토큰, 앱 식별자, 기술 정보가 포함될 수 있습니다. Cloudflare는 요청 IP 주소를 호출 제한에도 사용합니다. WayKo는 AI 한도 관리와 재시도 처리를 위해 요청 식별자와 해시, 시도 상태, 처리 시각, 입출력 토큰 수를 기록합니다. 이 보호 절차는 선택형 이용 통계와 별개로 동작합니다.
6. 선택형 이용 통계
이용 통계는 처음에 꺼져 있습니다. My → 이용 통계에서 켜거나 끌 수 있습니다. 켜면 Google Analytics for Firebase가 화면 조회, 기능 이용, 앱 언어, 미리 정한 지역·장소·음식 식별자, 여행 일수, 결과 코드, 이용량 표시를 처리합니다. SDK는 앱 인스턴스 식별자, 앱·기기 기술 정보, 네트워크 정보로 추정한 대략적인 위치, 해당하는 앱 실행·구매 이벤트도 처리합니다.
WayKo가 직접 보내는 통계 이벤트에는 자유롭게 입력한 검색어·일정·대화 원문과 정확한 좌표를 넣지 않습니다. 앱은 광고 저장소, 광고 사용자 정보, 광고 개인화 동의를 비활성화합니다. 통계를 끄면 앱의 동의 제어를 통해 이후 수집을 중단하지만, 이미 수집된 이벤트가 삭제되지는 않습니다.
7. 보관과 삭제
- 저장한 여행 정보: 항목을 편집·삭제하거나 Android 설정에서 앱 저장소를 지울 때까지 기기에 보관합니다. 저장한 여행에 자동 만료 기간은 없습니다. 여행 삭제는 현재 목록에서 해당 여행을 제거하며, 별도 초안·캐시나 저장 오류 후 생성된 복구 사본은 남을 수 있습니다. 앱 저장소를 지우면 이러한 로컬 사본과 설정을 제거할 수 있습니다. 필요한 정보는 먼저 보관해 주세요.
- 기기 내 AI 초안: 취향과 보내지 않은 입력을 기기에 저장합니다. 24시간보다 오래된 초안은 복원하지 않습니다. 이 확인은 저장된 데이터를 정해진 시각에 삭제하는 방식이 아니며, 앱 저장소를 지우면 제거됩니다.
- AI 일정 가져오기 결과: WayKo의 Cloudflare 저장소는 재시도 복구를 위해 정리된 일정 결과를 기록 갱신 후 24시간 동안 캐시합니다. 결과에는 원문의 정보가 포함될 수 있습니다. 제출한 원문 자체를 이 저장소에 별도로 보관하지는 않습니다.
- AI 대화 기록: 저장소에는 전달 완료 표시와 이용량 관련 정보가 남으며, 대화 메시지·생성된 답변·Google 추천 응답 본문을 보관하지 않습니다.
- AI 이용량 기록: 요청 기록은 최종 갱신 후 62일, 시도 기록은 생성 후 62일에 삭제하도록 예약합니다. 정리는 예약된 저장소 작업과 이후 요청에서 실행됩니다. 이 기간은 실제 운영 저장소에 적용되며, 제공업체의 백업·복구 기록에는 별도 보관 주기가 적용됩니다.
- 제공업체 기록과 문의: 통계, 스토어 거래, 제공업체 운영 로그·백업, 문의 이메일에는 WayKo AI 저장소의 24시간·62일 규칙이 적용되지 않습니다. 해당 제공업체의 서비스 또는 문의 메일함에서 처리됩니다. WayKo가 보유한 정보에 대한 문의나 삭제 요청은 아래 연락처로 보내 주세요.
AI 저장소의 삭제 규칙이 Anthropic 등 제공업체가 처리한 정보도 즉시 삭제한다는 뜻은 아닙니다. 업체별 보관 방식과 예외는 아래 연결된 각 업체의 방침을 참고하세요. 앱 데이터를 지워도 이미 제공업체에 보낸 정보가 삭제되거나 Google Play 구독이 취소되지는 않습니다. 현재 Android 앱은 Android의 기본 앱 백업을 비활성화합니다.
Firebase 익명 로그인 식별자와 AI 첫 이용 기록은 삭제 요청이 처리될 때까지 유지합니다. 앱 저장공간을 지우는 것만으로 서버 기록이 삭제되지는 않습니다. AI 요청·시도 정보에는 위의 별도 보관 기간이 적용됩니다. 삭제는 8항의 연락 절차로 요청해 주세요. 일반 이메일로 인증 토큰이나 구매 영수증을 보내지 마세요.
8. 개인정보 요청과 문의
열람, 정정, 삭제 및 기타 개인정보 문의는 henry_kim@kakao.com으로 보내 주세요. 관련 기록을 찾을 수 있도록 사용한 기능과 대략적인 이용 시각을 알려 주세요. 첫 이메일에 비밀번호, 결제 카드 정보, 여권 사본, 구매 토큰 전체를 넣지 마세요. 관련 기록을 확인하고 타인의 정보가 제공되지 않도록 추가 정보가 필요할 수 있습니다.
WayKo에는 계정과 연결된 여행 목록 사본이 없으므로 기기에만 저장된 여행을 원격으로 조회하거나 수정해 드릴 수 없습니다. 앱에서 해당 항목을 편집·삭제하거나 앱 저장소를 지울 수 있습니다. 제공업체에 있는 모든 기록을 일괄 삭제하는 앱 내 버튼은 없습니다. 제공업체가 직접 보유한 정보에는 해당 업체의 개인정보 설정과 문의 창구도 적용될 수 있습니다.
문의 시 이메일 주소, 메시지, 직접 첨부한 파일은 요청 처리를 위해 사용자의 이메일 서비스와 문의 메일 제공업체가 처리합니다.
9. 제공업체·국외 처리·보호 조치
WayKo는 운영 서비스 요청에 HTTPS를 사용하며 AI 제공업체와 구독 검증용 비밀키를 서버에 보관합니다. 기기 내 앱 저장소를 암호화 백업 서비스나 보안 문서 보관함으로 제공하지는 않습니다.
WayKo가 이용하는 제공업체는 여러 국가에서 네트워크 인프라를 운영합니다. 온라인 기능으로 보낸 정보는 사용자가 있는 국가 밖에서 처리될 수 있습니다. 각 업체의 개인정보 방침에서 국외 처리, 보관, 이용자 선택을 포함한 처리 방식을 확인할 수 있습니다.
- Google 개인정보처리방침 — 지도, 장소 검색, 경로, Google Play 및 Google 서비스.
- Firebase 개인정보 보호 및 보안 — App Check 및 Firebase 서비스.
- Cloudflare 개인정보처리방침 — 서비스 제공과 네트워크 인프라.
- Anthropic 개인정보처리방침 및 상용 API 정보 보관 안내 — AI 입력·출력 처리.
- NAVER 개인정보처리방침 — NAVER 서비스.
- SK open API 개인정보처리방침 — TMAP 도보 경로 요청에 사용하는 API 플랫폼.
10. 방침 변경
이 방침의 변경은 페이지 상단의 수정일로 구분합니다. 변경 사항이나 이 방침에 설명한 처리 방식에 관한 문의는 위 개인정보 연락처로 보내 주세요.