Skip to the content.

JJTeam Privacy Policy

Effective date: 2026-05-18 Last updated: 2026-05-18

JJTeam (“the App”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (Republic of Korea), to protect personal information of data subjects and to promptly and effectively handle related grievances.

The App provides two operation modes; the scope of personal information processed differs by mode.

Users may choose either mode and can sign out or delete their account at any time to permanently delete server-side data.


1. Personal Information Processed

1.1 Local mode (all users)

The following information is stored only on the user’s device in local storage (AsyncStorage).

This data never leaves the user’s device.

1.2 Cloud mode (users who sign in)

Upon social sign-in, the following items are received from OAuth providers (Google, Apple, Kakao) and stored on the operator’s server.

1.3 Automatically collected information

The App does NOT use analytics, advertising, or crash-tracking SDKs. No advertising identifiers, cookies, or tracking pixels are used.


2. Purpose of Processing

Stored information is used only for the following purposes.

The App does NOT use personal information for marketing, advertising, profiling, or automated decision-making.


3. Retention and Use Periods

Data Storage Retention
Local data (AsyncStorage) User device Until app removal or local mode exit
JWT / push token (SecureStore) User device Until sign-out or account deletion
Account / team / session (MongoDB Atlas) Operator server (Korea region) Until account deletion
Anonymous spectator data Operator server Auto-deleted at session end or by host
HTTP access logs Operator server Auto-deleted within 30 days
Revoked JWTs (Redis blocklist) Operator server Until token expiry (max 7 days)

Upon account deletion, the user’s account, teams (including teams they host), sessions, invite codes, and anonymous spectator records are permanently deleted.


4. Third-Party Disclosure

The operator does NOT disclose user information to any third party for advertising, marketing, or profiling purposes.

However, the following infrastructure providers process data on the operator’s behalf. The scope and purpose are described in section 5.


5. Outsourcing of Processing

Processor Data Purpose Retention
Google LLC OAuth ID token validation Social sign-in Validated at login only; not stored
Apple Inc. Sign in with Apple token validation Social sign-in Same
Kakao Corp. Kakao OIDC token validation Social sign-in Same
Google Cloud Platform (asia-northeast3, Seoul) Server hosting API/WebSocket/DB operation Until account deletion
MongoDB Atlas Database Storage of account/team/session data Until account deletion
Expo (650 California St., San Francisco, CA, USA) Push tokens / delivery Push notification routing Until sign-out or token refresh

Each processor follows its own privacy policy. The operator applies contractual safeguards to ensure data subject rights are preserved.


6. Deletion Procedures and Methods

Users can delete their data by:

  1. Exit local mode — Settings → Account → “Exit local mode”
  2. Sign out — Settings → Account → “Sign out” (server data retained; device tokens revoked)
  3. Delete account — Settings → Account → “Delete account” (both server and local data permanently deleted)
  4. Remove the app — Delete the app from the device (only local data is deleted; cloud data remains)

7. Rights of Data Subjects

Under Articles 35-37 of the Personal Information Protection Act, users have the right to access, correct, delete, and suspend processing of their personal information.

For additional inquiries, contact the privacy officer in section 13.


8. Security Measures


9. Automatic Collection (Cookies, etc.)

The App does NOT use cookies, advertising identifiers (IDFA/AAID), or tracking pixels.


10. Children Under 14

The App is not directed at children under 14 and does not knowingly collect personal information from them.


11. App Permissions

The App uses only the following OS permissions, all requiring explicit user consent.

The App does NOT request camera, location, microphone, contacts, or photo permissions.


12. Cross-Border Transfer

The operator’s server is located in the Korea region (Seoul). However, transfers outside Korea may occur in the following cases.

Transfer items, countries, dates, methods, recipients, purposes, and retention periods are disclosed throughout this policy. Users may refuse cross-border transfer by exiting cloud mode (cloud features become unavailable).


13. Privacy Officer

The app operator is responsible for personal information processing and grievance handling.

Users may direct any inquiries, complaints, or remedy requests related to personal information to the above contact.


14. Remedies

Users may contact the following bodies for dispute resolution and counseling regarding personal information violations.

Authority Phone Website
Personal Information Dispute Mediation Committee 1833-6972 www.kopico.go.kr
KISA Privacy Infringement Report Center 118 privacy.kisa.or.kr
Cyber Investigation Bureau, Supreme Prosecutors’ Office 1301 www.spo.go.kr
Cyber Bureau, National Police Agency 182 ecrm.cyber.go.kr

15. Policy Changes

If this Privacy Policy is added to, deleted from, or amended, the changes will be announced on this page at least 7 days before they take effect. For changes that materially affect user rights, notice will be given at least 30 days in advance.


16. Contact

For inquiries regarding this policy, please contact:

Email: jjrottensweetpotato@gmail.com