MaroStory

Privacy Policy

MaroStory (hereinafter referred to as the "Company") values the personal information of people who use its services (hereinafter referred to as the "Services") and complies with applicable laws. This policy explains how personal information is collected, used, and protected. Processing items, storage locations, and external providers may differ by Service; a Service-specific notice or in-Service notice takes precedence where it addresses the same subject.

Article 1 (Personal Information Items Collected)

The Company may collect the following personal information to provide services.

1. Upon Membership Registration and Account Linkage

  • Required: Email address, password
  • Optional: Nickname, profile image

2. Additional Information Collected Upon Using Specific Services

For some services such as fortune-telling and Saju, the following information may be additionally collected.

  • Gender, date of birth, time of birth, place of birth

3. Information Automatically Collected Upon Using Services

  • Device information (model name, OS version, app version)
  • Log information (IP, access date and time, usage records)
  • Advertising ID (GAID, IDFA, etc.)

4. Upon Payment and Use of Paid Services

  • Payment records (payment history within the store)
  • Ad viewing history (for providing rewarded advertisements)

Article 2 (Method of Collecting Personal Information)

The Company collects personal information in the following ways:

  • Direct entry by the user when running the service and signing up
  • Social login linkage such as Google/Apple
  • Automatic collection during service use
  • Customer center inquiries and event participation

Article 3 (Purpose of Using Personal Information)

The Company uses collected personal information only to the extent necessary for each Service and for the purposes below. The examples below do not apply to every Service; a Service-specific notice applies where available.

PurposeDetails
Service ProvisionProvision of content, provision of results such as fortune-telling, Saju, and dream interpretation
Member ManagementLogin, user identification, change of member information, account management
Customized Content ProvisionAI recommendations and result analysis according to personal information
Advertising and MarketingProvision of rewarded advertisements and analysis based on statistics
Customer SupportInquiry response, error handling, delivery of announcements

Article 4 (Retention and Usage Period of Personal Information)

The Company immediately destroys the information after the purposes of collecting and using personal information are achieved. However, the following information may be stored for a certain period in accordance with relevant laws and regulations.

  • Records on labels/advertisements, contract contents and performance according to the Electronic Commerce Act: 5 years
  • Records on consumer complaints or dispute handling: 3 years

Article 5 (Provision of Personal Information to Third Parties)

The Company does not provide personal information to third parties without the user's consent. However, the following cases are exceptions:

  • When requested in accordance with laws and regulations
  • When the user has agreed in advance

Article 6 (Consignment of Personal Information Processing)

The Company may consign the processing of personal information to the following external companies to provide services.

ConsigneeContents of Consignment
Google FirebaseOptional account authentication, cloud storage, push notifications, and server functions by Service
Google AdMobAd delivery for ad-supported Services, consent-state handling, measurement, and fraud prevention
Google / AppleUser-selected social sign-in and external feature integrations
Other external providersOnly where the applicable Service actually uses them, as described in its Service-specific notice

Article 7 (Rights of the User)

Users can inquire or modify their personal information at any time, and can withdraw their consent to the collection and use of personal information through membership withdrawal. Upon membership withdrawal, all personal information is immediately deleted, and is stored only when storage is required by laws and regulations.

Article 8 (Technical/Managerial Measures for Personal Information Protection)

  • Personal information is encrypted and stored, and managed safely.
  • Passwords are stored using one-way encryption and are not decrypted.
  • Administrator access rights are limited to the minimum, and internal access history is also recorded and managed.
  • The service maintains data security during transmission through HTTPS communication.

Article 9 (Cookies and Advertising Identifiers)

The service may collect advertising identifiers (GAID, IDFA, etc.) to provide user-customized advertisements. Users can refuse this through device settings.

Article 10 (Personal Information of Children Under 14)

The Company does not intentionally collect personal information of children under 14, and takes immediate deletion measures upon confirmation.

Article 11 (SaiNote Service-Specific Notice)

This Article applies to the SaiNote app. SaiNote can be used without an account, and guest use and optional account use have different processing scopes.

1. Guest Use

During guest use, people, occasions, congratulatory/condolence and financial records, notes, and personal insights calculated by the app are kept in storage on the user's device. They are not automatically sent to Company servers. Even after an account is connected, they are transferred to account storage only when the user expressly chooses backup, merge, or replacement of account records.

2. Optional Account and Cloud Features

If the user connects an account by email, Google, or Apple, we process account identifiers, email address, authentication-provider information, display name, and an optional profile photo. People, occasions, transactions, notes, and personal insights that the user backs up or creates in the account, as well as feedback and optional attachments, may be stored and processed through Firebase services. Passwords are handled by Firebase Authentication; the Company does not retain plaintext passwords.

3. Optional Features and Permissions

Contacts, device calendar, Google Calendar, and ICS-file import are used only when the user selects the feature and grants the relevant permission. Chosen information is shown as a draft for creating a record, and only information the user confirms is retained as a record. Profile photos and feedback attachments are processed only when selected by the user. Denying a permission limits that optional feature only, not core features.

4. Notifications and Advertising

When a user connects notifications, we process a device-specific push token, platform, and refresh time to send notifications and manage the token. SaiNote advertising may be provided through Google AdMob in line with consent status and device settings. For ad delivery, measurement, and fraud prevention, Google or its partners may process IP address, device and app information, advertising or app identifiers, and ad-interaction information. The scope of advertising-identifier processing may vary by operating system and ad settings.

5. Retention, Deletion, and International Processing

Guest records stored on a device are deleted when the user deletes individual records or chooses to clear local records as part of backup, merge, or account-record replacement. Information stored in an account is deleted upon the user's deletion or account-deletion request, except where retention is required by law, in which case it is retained separately for the required period. Device and server data are separate storage areas and must be deleted separately. When features use overseas providers such as Firebase or AdMob, personal information may be transferred to or processed on servers or by subprocessors outside the user's country. Details that must be disclosed by law, including the recipient, items, country, and retention period, will be provided through a separate in-Service notice or consent process.

Article 12 (Leftty P0 Service-Specific Notice)

This Article applies to the currently released Leftty P0 app. Leftty P0 is a local-only app that keeps user-entered pass, quantity, credit, period, and subscription-schedule records only in app-specific storage on the current device.

1. On-Device Processing Items and Purpose

Leftty P0 processes on the device a managed item's name, type, note, and creation and modification times; remaining balance, quantity, credits, unit, currency, and optional purchase amount; expiration date, period end time, next billing date, and billing cycle; and change history for creation, use, recharge, adjustment, period change, subscription-payment confirmation, and cancellation. This is used only to display remaining values and schedules and to provide a change history the user can review.

2. Local Notifications

If the user permits notifications, Leftty P0 may schedule local notifications through the device operating system for expiration dates or next billing dates. A notification may show an item name and schedule information, which may be visible to someone viewing the device, including on a lock screen. Denying notification permission does not prevent the user from adding, editing, or deleting records, and permission can be changed in device settings.

3. Company-Server Transfers and External Services

Leftty P0 does not offer sign-up, sign-in, or account linkage, and does not send these records to Company servers or link them to a Company account. The current Leftty P0 has no Firebase, remote analytics tool, advertising SDK, in-app purchase SDK, remote push, or merchant, bank, card, or email integration. Accordingly, the Company does not remotely retain, view, or restore Leftty P0 user records, or transmit them for third-party provision, processing delegation, or international transfer.

4. Deletion and Retention

Users can edit or delete their own items in the app. Deleting an item also deletes its change history and associated local notification schedules from the device. Depletion, expiration, subscription cancellation, or moving an item to or hiding it in the archive is not deletion, so the record remains on the device. Because data exists only on the device, it may not be recoverable after app deletion, clearing app storage, device replacement, or reset. Retention and restoration of operating-system or user-configured device backups are governed by that operating system's policies.

5. Device Settings

Leftty P0 reads device language and regional settings locally only to display the interface language and currency. It does not automatically collect or transmit email address, phone number, password, account identifier, advertising identifier, contacts, photos, location, calendar, camera, microphone, payment method, or actual payment details.

Article 13 (Chief Privacy Officer)

The Company designates a Chief Privacy Officer as follows to take overall responsibility for tasks related to personal information processing and to handle complaints and damage relief of data subjects related to personal information processing. Chief Privacy Officer Officer: Soonoh Min Email: snow@marostory.com Inquiries can be submitted through customer support within each service or via the email above.

Article 14 (Notification of Change)

This policy may be revised in response to changes in laws, policies, or Services. Material changes will be announced before they take effect through an in-Service notice, pop-up, or this website, and prior versions will be kept available upon request.

Inquiries Regarding Personal Information

Service Name: All services provided by MaroStory Company: MaroStory Email: snow@marostory.com Department in Charge: Development Team

Privacy Infringement Report Center

If you need to report personal information infringement, you can report it to the following organizations:

  • Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
  • Personal Information Infringement Report Center: privacy.kisa.or.kr / 118
  • Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
  • National Police Agency Cybercrime Reporting System: ecrm.police.go.kr / 182

Announcement Date: August 27, 2026 Effective Date: August 27, 2026