English
This Privacy Policy explains how mmrnd.net collects, uses, stores, and shares personal
information when you use our services, including mmrnd.net, MoMoTalk, MoMoTalk Kids,
authentication, profile, talk, memo, calendar, points, letter, mail, bot, paper,
operations diagnostics, and related APIs.
Information we collect
- Account information: user ID, email (stored as a hash), password hash, role, status, created/verified timestamps.
- External login data: when you sign in with Google, GitHub, or GitLab, we receive the provider account identifier, email address, email verification status, display name, and profile picture URL to create or link your account and set profile defaults. We store the identifier, email hash, verification status, display name, profile picture URL, linked time, and last-login time. Provider access tokens used for identity verification are not retained after the verification flow.
- Auth data: access/refresh tokens, consent records, client approvals, scopes.
- App data: user-created app data (e.g., watchlists, trades, preferences) stored in app namespaces.
- Push notification data: device push tokens and delivery metadata.
- Alerts data: price alert settings (symbol, target price, currency, enabled state).
- MoMoTalk profile data: display name, username, profile image, gender, birthdate, region, profile visibility settings, last-seen region.
- MoMoTalk social graph data: friend/family/blocked relations, incoming relation state, personal contact groups and members.
- MoMoTalk conversation data: room metadata, participants, messages, threads, reactions, read/delivery status, typing status, room title, room membership changes, shared file metadata, and uploaded attachments such as images, videos, audio, and documents when a user chooses to send them.
- MoMoTalk call data: call room identifiers, participants, signaling metadata, call status, and point-billing metadata. Audio/video media is carried through realtime call connections and is not intentionally recorded by mmrnd.net.
- MoMoTalk Kids data: child account identifiers, guardian link status, guardian approvals, guardian controls, child friend/room state, chat messages, profile image chosen by the child, reports submitted by the child, play/chess/crossword/game progress, and calendar events created or edited in the Kids app.
- Bot and AI interaction data: bot registry/subscription metadata, bot room subscriptions, bot messages, and automated bot responses when a user or guardian-approved child interacts with a bot.
- Memo, calendar, letter, mail, and points data: memo titles/content/attachments/status, calendar event titles/descriptions/times/invite status, letters and gift/point metadata, linked mail account metadata and mail actions, wallet balances, transactions, and point charges for eligible features.
- MoMoTalk location lookup data: latitude/longitude used only when user triggers auto-location lookup for region update.
- Camera, microphone, photo/video, and file picker data: used only when a user starts a call, records audio, takes/selects a profile image, or chooses files/media to upload or share.
- Client error diagnostics: app version, device/OS, feature area, error type, friendly notice shown to the user, internal error code, and sanitized exception class/message. Message, letter, or mail body text, access tokens, precise location, and attachment contents are not included.
- Operational logs: request timestamps, IP address, user agent, and error logs for security and troubleshooting.
Legal basis and required information
- Account identifiers, authentication records, and information needed to provide a feature requested by the user are processed as necessary to enter into and perform the service agreement under Article 15(1)(4) of Korea's Personal Information Protection Act. We do not ask for a separate mandatory privacy consent for this processing.
- External login is optional. If selected, the external identity data described above is necessary to provide that login or account-linking request. Refusing it only prevents use of that external provider.
- We do not currently collect information for marketing under a bundled signup consent. If optional processing requiring consent is introduced, it will be presented separately and refusal will not block unrelated service features.
How we use information
- Provide authentication, authorization, and account management.
- Support external login providers and initialize profile defaults such as display name and avatar URL.
- Deliver core services and synchronize app data across devices.
- Send notifications you request (e.g., price alerts).
- Provide messaging, profile sharing controls, contact grouping, and realtime synchronization for MoMoTalk.
- Provide MoMoTalk Kids child-safe messaging, guardian approvals, guardian controls, play features, and child-friendly reporting.
- Provide memo, calendar, letter, mail, points, bot, and paper services.
- Operate user reports, blocking, moderation review, abuse prevention, and child-safety protections.
- Diagnose client connection and reliability issues without collecting message contents or sensitive payloads.
- Monitor reliability, prevent abuse, and improve service quality.
Sharing and disclosure
- We do not sell personal information.
- We share data with service providers only as needed to operate the service, such as
email delivery (SMTP), push notifications (Firebase Cloud Messaging), Google Play app
update services, and Google AdMob for MoMoTalk where ads are enabled. MoMoTalk Kids does
not include the Google Mobile Ads SDK and is not intended to show ads.
- Information may be shared between mmrnd.net service components, such as Auth, Profile,
Talk, Calendar, Memo, Points, Bot, Mail, Letter, and Ops, only as needed for the requested
feature, safety, diagnostics, or account management.
- We may disclose information if required by law or to protect our users and services.
Connected developer-service actions
When a MoMoTalk bot guides a user to connect a developer service such as GitHub, service
installation status and event metadata may be handled by mmrnd.net services. User-authorized
provider actions, such as actions that require the user's own GitHub authority, are designed
to be executed by the client app with provider tokens kept on the user's device or browser
session. MoMoTalk, DevHub, and Bot Platform servers do not ask the client to send provider
user access or refresh tokens to those servers for bot action execution.
Children and guardians
MoMoTalk Kids is designed for children with guardian-linked safety controls. Child accounts
may use chat, calendar, play/game, profile image, video call, and guardian-approved bot
features. Guardian controls may limit chat, friend actions, quiet time, and bot access.
We use child data to provide the requested Kids app features, guardian approvals, safety
controls, abuse prevention, and support. We do not use MoMoTalk Kids to show personalized
ads, and the Kids app does not request location permission.
User-generated content and safety
MoMoTalk and MoMoTalk Kids include user-generated content such as messages, profile images,
shared media, calendar entries, memos, letters, and bot interactions. Users can report
objectionable users, messages, images, and videos where supported. We may review reports,
restrict content, block users, or limit accounts to protect users and comply with law and
platform policies.
Retention
- Unverified signup records: up to 3 hours.
- Account and service records: until account deletion, unless a longer period is required by law or needed for an unresolved dispute or security incident.
- External identity records: until that provider is disconnected or the MoMoTalk account is deleted.
- Operational logs: only for the shortest period reasonably needed for security and troubleshooting.
- Backups may persist for a limited rotation period and are not used for ordinary service operation.
Security
We use reasonable security measures including encrypted transport (TLS), access controls,
and hashing for sensitive fields (such as passwords and email).
Your choices
You may request access, correction, or deletion of your personal information by contacting
support@mmrnd.net. Account deletion is available in MoMoTalk settings where supported, or
by contacting support@mmrnd.net. You may also use
https://mmrnd.net/account-deletion.html as the public deletion request page and include
the account ID or email used for the account.
한국어
본 개인정보처리방침은 mmrnd.net, MoMoTalk, MoMoTalk Kids, 인증, 프로필, 톡, 메모,
캘린더, 포인트, 편지, 메일, 봇, 페이퍼, 운영 진단 및 관련 API를 제공하는 과정에서
개인정보를 어떻게 수집·이용·보관·공유하는지 설명합니다.
수집하는 정보
- 계정 정보: 사용자 ID, 이메일(해시로 저장), 비밀번호 해시, 역할, 상태, 생성/인증 시각
- 외부 로그인 데이터: Google, GitHub, GitLab 로그인 시 provider 계정 식별자, 이메일 주소, 이메일 인증 여부, 표시 이름, 프로필 사진 URL을 받아 계정 생성/연결 및 프로필 기본값 설정에 사용합니다. 계정 식별자, 이메일 해시, 인증 여부, 표시 이름, 프로필 사진 URL, 연결 시각과 최근 로그인 시각을 저장하며, 본인 확인에 사용된 provider access token은 확인 흐름 이후 보관하지 않습니다.
- 인증 데이터: 액세스/리프레시 토큰, 동의 기록, 클라이언트 승인, 스코프
- 앱 데이터: 사용자 생성 데이터(예: 관심종목, 거래기록, 설정 등)
- 푸시 알림 데이터: 디바이스 푸시 토큰 및 전송 메타데이터
- 알림 데이터: 가격 알림 설정(종목, 목표가격, 통화, 활성 여부)
- MoMoTalk 프로필 데이터: display name, user name, 프로필 이미지, 성별, 생년월일, 지역, 프로필 공개 설정, 마지막 접속 지역
- MoMoTalk 관계 데이터: 친구/가족/차단 관계, 나를 추가한 관계 상태, 개인 연락처 그룹 및 구성원
- MoMoTalk 대화 데이터: 채팅방 메타정보, 참여자, 메시지, 스레드, 반응, 읽음/전달 상태, 입력 중 상태, 방 제목, 방 참여/탈퇴 이력, 공유 파일 메타데이터, 사용자가 직접 전송한 이미지/동영상/오디오/문서 등 첨부파일
- MoMoTalk 통화 데이터: 통화방 식별자, 참여자, 시그널링 메타데이터, 통화 상태, 포인트 과금 메타데이터. 음성/영상 미디어는 실시간 통화 연결을 위해 전송되며 mmrnd.net이 의도적으로 녹음/녹화하지 않습니다.
- MoMoTalk Kids 데이터: 아동 계정 식별자, 보호자 연결 상태, 보호자 승인, 보호자 제어 설정, 아동의 친구/방 상태, 채팅 메시지, 아동이 선택한 프로필 이미지, 아동이 제출한 신고, play/chess/crossword/game 진행 정보, Kids 앱에서 생성/수정한 캘린더 일정
- 봇 및 AI 상호작용 데이터: 봇 등록/구독 메타데이터, 봇 방 구독, 봇 메시지, 사용자 또는 보호자가 승인한 아동이 봇과 상호작용할 때의 자동 응답
- 메모/캘린더/편지/메일/포인트 데이터: 메모 제목/내용/첨부/상태, 캘린더 일정 제목/설명/시간/초대 상태, 편지 및 선물/포인트 메타데이터, 연결된 메일 계정 메타데이터와 메일 동작, 지갑 잔액, 거래, 기능 이용 포인트 차감 정보
- MoMoTalk 위치 조회 데이터: 사용자가 위치 자동 찾기를 실행한 경우의 위도/경도(지역명 변환 목적)
- 카메라, 마이크, 사진/동영상, 파일 선택 데이터: 사용자가 통화를 시작하거나, 음성을 녹음하거나, 프로필 이미지를 촬영/선택하거나, 파일/미디어 업로드 또는 공유를 선택한 경우에만 사용합니다.
- 클라이언트 오류 진단 정보: 앱 버전, 기기/OS, 화면 영역, 오류 종류, 사용자에게 표시된 안내 문구, 내부 오류 코드, 정리된 예외 클래스/메시지. 메시지/쪽지/메일 본문, 액세스 토큰, 정확한 위치, 첨부 파일 내용은 포함하지 않습니다.
- 운영 로그: 요청 시각, IP 주소, User-Agent, 오류 로그(보안/장애 대응 목적)
처리 근거와 필수 정보
- 계정 식별·인증 기록과 이용자가 요청한 기능 제공에 필요한 정보는 「개인정보 보호법」 제15조제1항제4호의 계약 체결·이행에 필요한 처리 근거로 수집·이용합니다. 이 처리에 관행적인 별도 필수 개인정보 동의를 요구하지 않습니다.
- 외부 로그인 선택은 선택 사항입니다. 선택한 경우 위 외부 신원 정보는 해당 로그인 또는 계정 연결 요청을 제공하기 위해 필요하며, 제공을 원하지 않으면 그 외부 로그인만 이용할 수 없습니다.
- 현재 회원가입 동의에 마케팅 목적 정보를 묶어 수집하지 않습니다. 추후 별도 동의가 필요한 선택 처리를 도입하면 구체적인 내용을 분리하여 동의를 받고, 거부해도 무관한 서비스 이용을 제한하지 않습니다.
이용 목적
- 인증/인가 및 계정 관리 제공
- 외부 로그인 제공 및 표시 이름/아바타 URL 등 프로필 기본값 설정
- 서비스 제공 및 앱 데이터 동기화
- 사용자가 요청한 알림 제공
- 메시지 내용이나 민감한 payload를 수집하지 않고 클라이언트 연결/안정성 문제 진단
- MoMoTalk의 메시징, 프로필 공개 제어, 연락처 그룹 기능, 실시간 동기화 제공
- MoMoTalk Kids의 아동 안전 메시징, 보호자 승인, 보호자 제어, play 기능, 아동 친화적 신고 기능 제공
- 메모, 캘린더, 편지, 메일, 포인트, 봇, 페이퍼 서비스 제공
- 사용자 신고, 차단, 운영 검토, 오남용 방지, 아동 안전 보호 운영
- 서비스 안정성 확보, 보안 및 품질 개선
제3자 제공 및 위탁
- 개인정보를 판매하지 않습니다.
- 서비스 운영에 필요한 경우에 한해 이메일 전송(SMTP), 푸시 알림(FCM), Google Play 앱 업데이트 서비스, MoMoTalk에서 광고가 활성화된 경우 Google AdMob 등의 제공업체에 위탁할 수 있습니다. MoMoTalk Kids에는 Google Mobile Ads SDK가 포함되어 있지 않으며 광고 표시를 목적으로 하지 않습니다.
- 요청한 기능, 안전, 진단, 계정 관리를 위해 필요한 범위에서 Auth, Profile, Talk, Calendar, Memo, Points, Bot, Mail, Letter, Ops 등 mmrnd.net 서비스 구성요소 사이에 정보가 전달될 수 있습니다.
- 법령에 따른 요청 또는 서비스 보호를 위해 필요한 경우에 한해 공개될 수 있습니다.
연결된 개발 서비스 동작
MoMoTalk 봇이 GitHub 같은 개발 서비스 연결을 안내하는 경우, 서비스 앱 설치 상태와 이벤트
메타데이터는 mmrnd.net 서비스가 처리할 수 있습니다. 사용자의 GitHub 권한이 필요한 작업처럼
사용자 본인 권한의 provider 동작은 클라이언트 앱이 사용자 기기 또는 브라우저 세션에 보관한
provider token으로 직접 수행하도록 설계합니다. MoMoTalk, DevHub, Bot Platform 서버는 봇
action 실행을 위해 클라이언트가 provider user access token 또는 refresh token을 해당 서버로
전송하도록 요구하지 않습니다.
아동 및 보호자
MoMoTalk Kids는 보호자 연결 안전 제어를 전제로 한 아동용 앱입니다. 아동 계정은 채팅,
캘린더, play/game, 프로필 이미지, 영상통화, 보호자가 승인한 봇 기능을 사용할 수 있습니다.
보호자 제어는 채팅, 친구 동작, 조용한 시간, 봇 접근을 제한할 수 있습니다. 아동 데이터는
Kids 앱 기능 제공, 보호자 승인, 안전 제어, 오남용 방지 및 지원 목적으로 사용됩니다.
MoMoTalk Kids는 개인 맞춤 광고를 표시하지 않으며 위치 권한을 요청하지 않습니다.
사용자 생성 콘텐츠와 안전
MoMoTalk 및 MoMoTalk Kids에는 메시지, 프로필 이미지, 공유 미디어, 캘린더 일정, 메모,
편지, 봇 상호작용 등 사용자 생성 콘텐츠가 포함됩니다. 지원되는 화면에서 이용자는 부적절한
사용자, 메시지, 이미지, 동영상을 신고할 수 있습니다. 신고 검토, 콘텐츠 제한, 사용자 차단,
계정 제한 등은 이용자 보호와 법령/플랫폼 정책 준수를 위해 수행될 수 있습니다.
보관 및 파기
- 인증하지 않은 가입 정보: 최대 3시간
- 계정 및 서비스 기록: 계정 삭제 시까지. 다만 법령상 보존 의무, 미해결 분쟁 또는 보안 사고 대응에 필요한 최소 정보는 해당 목적에 필요한 기간 동안 분리 보관할 수 있습니다.
- 외부 신원 정보: 해당 provider 연결 해제 또는 모모톡 계정 삭제 시까지
- 운영 로그: 보안과 장애 대응에 합리적으로 필요한 최소 기간
- 백업은 제한된 순환 보관 기간 동안 남을 수 있으며 일상적인 서비스 운영에는 사용하지 않습니다.
보안
전송 구간 암호화(TLS), 접근 통제, 민감정보 해시 처리 등 합리적인 보안 조치를 적용합니다.
이용자 권리
개인정보 열람, 정정, 삭제를 요청할 수 있습니다. MoMoTalk 설정에서 지원되는 경우 계정 삭제를
진행할 수 있으며, support@mmrnd.net으로도 요청할 수 있습니다. 공개 삭제 요청 페이지로
https://mmrnd.net/account-deletion.html을 사용할 수 있고, 요청 시 계정 ID 또는 계정 이메일을 함께 알려 주세요.