개인정보처리방침Privacy Policy
최종 업데이트: 2026-07-01 · 시행일: 2026-07-01 Last updated: 2026-07-01 · Effective: 2026-07-01
Expanion(익스패니언, 이하 “서비스”)은 이용자의 개인정보를 소중히 여기며, 「개인정보 보호법」 및 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」(정보통신망법) 등 관련 법령을 준수합니다. 본 개인정보처리방침은 서비스가 어떤 정보를, 어떤 목적으로, 어떻게 수집·이용·보관·파기하는지, 그리고 이용자가 어떤 권리를 행사할 수 있는지를 설명합니다.
Expanion (“the Service”) values your privacy and complies with the Republic of Korea’s Personal Information Protection Act (PIPA) and the Network Act, among other applicable laws. This Privacy Policy explains what information the Service collects, for what purposes, how it is used, stored, and destroyed, and what rights you may exercise.
1. 수집하는 개인정보 항목 및 수집 방법1. Information We Collect and How
서비스는 아래 항목을 이용자의 서비스 이용 과정에서 수집합니다. 계정 연결 전 익명 이용 시에는 개인을 식별하지 않는 익명 식별자와 학습·사용 데이터만 처리됩니다.
The Service collects the following during your use. Before linking an account (anonymous use), only a non-identifying anonymous identifier and learning/usage data are processed.
| 구분 | 수집 항목 | 수집 방법 |
|---|---|---|
| 계정(선택) | 익명 식별자(기본), 계정 연결 시 이메일 주소 및 인증 제공자 식별정보(Apple/Google) | Firebase Authentication을 통한 이용자의 계정 연결 시 |
| 학습 콘텐츠 | 이용자가 입력한 영어 표현·예문, AI 분석 결과, 저장한 학습 카드, 복습 기록 | 이용자 직접 입력 및 서비스 이용 과정에서 생성 |
| 사용량 데이터 | 일일 검색 횟수 등 사용량 정보(무료 한도 관리 목적) | 서비스 이용 시 자동 생성·저장(Firestore) |
| 결제 관련 | 구독 상태, 스토어 거래·영수증 검증 정보(구매 토큰 등). 카드번호 등 결제수단 정보는 수집하지 않음 | App Store/Google Play 인앱결제 및 서버 영수증 검증(Cloud Functions) |
| 광고 식별자 | 광고 식별자(iOS IDFA / Android 광고 ID) 등 광고 SDK가 처리하는 정보 (무료 이용자 한정) | Google AdMob 광고 SDK를 통해 자동 처리 |
| 진단·분석 | 앱 이용 이벤트, 크래시(오류) 로그, 성능 데이터, 기기·OS 정보, 앱 버전, 대략적 지역 등 | Firebase Analytics·Crashlytics를 통해 자동 수집 |
| Category | Data collected | How |
|---|---|---|
| Account (optional) | Anonymous identifier (default); on account linking, your email address and provider identifiers (Apple/Google) | When you link an account via Firebase Authentication |
| Learning content | The English expressions/example sentences you enter, AI analysis results, saved cards, and review history | Entered by you and generated during use |
| Usage data | Usage information such as daily search counts (for free-tier limit management) | Generated and stored automatically (Firestore) |
| Payment-related | Subscription status and store transaction/receipt-verification data (purchase tokens, etc.). We do not collect card numbers or payment credentials. | App Store/Google Play in-app purchase and server receipt verification (Cloud Functions) |
| Advertising ID | Advertising identifiers (iOS IDFA / Android Advertising ID) and data handled by the ad SDK (free users only) | Handled automatically by the Google AdMob SDK |
| Diagnostics/Analytics | App usage events, crash logs, performance data, device/OS info, app version, approximate region, etc. | Collected automatically via Firebase Analytics/Crashlytics |
2. 개인정보의 이용 목적2. Purposes of Use
- 서비스 제공: AI 영어 표현 분석(의미·예문·직역), 학습 카드 생성·저장·동기화, SM-2 기반 간격 반복 복습, 발음 쉐도잉·TTS 재생 기능 제공
- 계정 관리: 익명·연결 계정의 식별, 여러 기기 간 학습 데이터 동기화, 회원탈퇴 처리
- 무료 한도 관리: 일일 검색 횟수, 저장 카드 수, 아카이브 접근 등 무료·유료 이용 범위 관리
- 결제·구독: 인앱결제 처리, 영수증 검증, 무료체험 및 구독 상태 관리
- 광고: 무료 이용자에 대한 광고(전면·보상형·배너) 제공 및 게재
- 서비스 개선·안정화: 오류 진단, 성능 개선, 이용 통계 분석, 부정 이용 방지
- Providing the Service: AI analysis of English expressions (meaning, examples, literal translation), creating/saving/syncing cards, SM-2 spaced-repetition review, and pronunciation shadowing/TTS playback
- Account management: identifying anonymous/linked accounts, syncing learning data across devices, and processing account deletion
- Free-tier limits: managing daily search counts, saved-card limits, archive access, and other free/paid scope
- Payments/subscriptions: processing in-app purchases, verifying receipts, and managing free trials and subscription status
- Advertising: serving ads (interstitial, rewarded, banner) to free users
- Improvement/stability: error diagnosis, performance improvement, usage analytics, and abuse prevention
3. 제3자 제공 및 처리위탁3. Third-Party Provision and Processing
서비스는 원활한 기능 제공을 위해 아래와 같이 개인정보 처리를 위탁하거나 제3자에게 제공합니다. 이 과정에서 OpenAI 및 Google 등 일부 처리자는 개인정보를 국외에서 처리할 수 있습니다.
To provide its features, the Service entrusts processing to, or shares data with, the parties below. In this process, some processors such as OpenAI and Google may process data outside of Korea (overseas transfer).
| 수탁자/제공받는 자 | 위탁·제공 목적 | 처리 항목 |
|---|---|---|
| OpenAI, L.L.C. (미국 등 국외) | 이용자가 입력한 영어 표현·예문의 AI 분석(의미·예문·직역 생성) | 이용자가 입력한 학습 콘텐츠(영어 표현·예문 텍스트) |
| Google LLC / Firebase (국외 처리 가능) | 계정 인증, 데이터베이스(Firestore) 저장, 서버 함수(Cloud Functions), 이용 분석, 크래시 로그 | 익명·연결 계정 정보, 학습·사용 데이터, 진단·분석 데이터 |
| Google AdMob (국외 처리 가능) | 무료 이용자 대상 광고 게재 | 광고 식별자 및 광고 SDK가 처리하는 정보 |
| Apple Inc. / Google LLC | 인앱결제 처리 및 영수증 발급 | 스토어 거래·영수증 정보(카드정보 제외) |
| Recipient / Processor | Purpose | Data processed |
|---|---|---|
| OpenAI, L.L.C. (overseas, e.g., USA) | AI analysis of the English expressions/examples you enter (generating meaning, examples, literal translation) | The learning content you enter (English expression/example text) |
| Google LLC / Firebase (may process overseas) | Authentication, database (Firestore), server functions (Cloud Functions), usage analytics, crash logs | Anonymous/linked account info, learning/usage data, diagnostics/analytics data |
| Google AdMob (may process overseas) | Serving ads to free users | Advertising identifiers and data handled by the ad SDK |
| Apple Inc. / Google LLC | In-app purchase processing and receipt issuance | Store transaction/receipt info (excluding card details) |
AI 분석 요청에 대한 서버 프록시 로그 정책Server-proxy logging policy for AI requests
이용자의 AI 분석 요청은 서비스 자체 서버 프록시(Google Cloud Functions)를 경유하여 OpenAI API로 전송됩니다. 이때 다음 정책이 적용됩니다.
Your AI analysis requests are sent to the OpenAI API through the Service’s own server proxy (Google Cloud Functions). The following policy applies:
- 서버 프록시는 검색 요청의 원문 텍스트를 로그로 저장하지 않습니다. 토큰 수, 비용, 모델명 등 메타데이터만 기록합니다.
- 다만 AI 분석 결과 자체는 캐시(Firestore) 및 이용자가 저장한 학습 카드 형태로 보관됩니다.
- The server proxy does not log the raw text of search requests. It records only metadata such as token counts, cost, and model name.
- However, the AI analysis results themselves are stored as a cache (Firestore) and as the cards you save.
4. 개인정보의 보유·이용 기간 및 파기4. Retention and Destruction
- 서비스는 이용 목적이 달성될 때까지 개인정보를 보유하며, 이용자가 앱 내 회원탈퇴를 진행하면 서버(클라우드)에 저장된 데이터와 기기 로컬 저장소의 데이터를 삭제합니다.
- 관계 법령에 따라 보존이 필요한 정보(예: 전자상거래 등에서의 소비자 보호에 관한 법률상 거래·결제 기록 등)는 해당 법령이 정한 기간 동안 보관 후 파기합니다.
- 전자적 파일 형태의 정보는 복구가 불가능한 방법으로 삭제하며, 파기 사유가 발생한 개인정보는 지체 없이 파기합니다.
- The Service retains personal data until its purpose is fulfilled. When you delete your account within the app, data stored on the server (cloud) and in local device storage is deleted.
- Information required to be kept by law (e.g., transaction/payment records under the Act on Consumer Protection in Electronic Commerce) is retained for the legally prescribed period and then destroyed.
- Electronic files are deleted in an unrecoverable manner, and data whose retention purpose has ended is destroyed without delay.
5. 이용자의 권리와 행사 방법5. Your Rights and How to Exercise Them
이용자는 언제든지 자신의 개인정보에 대해 다음 권리를 행사할 수 있습니다.
You may exercise the following rights regarding your personal data at any time:
- 개인정보 열람·정정·삭제·처리정지 요구
- 동의 철회 및 회원탈퇴
- Request access, correction, deletion, or suspension of processing
- Withdraw consent and delete your account
앱 내 계정 삭제: 앱의 설정 메뉴에서 회원탈퇴를 실행하면 서버 데이터와 기기 로컬 데이터가 삭제됩니다. 그 밖의 권리 행사는 아래 문의처의 이메일로 요청하실 수 있으며, 서비스는 관련 법령에 따라 지체 없이 처리합니다.
In-app account deletion: Running Delete Account in the app’s settings removes server data and local device data. Other requests can be made via the email in the Contact section, and the Service will act without undue delay in accordance with applicable law.
계정 및 데이터 삭제Account & Data Deletion
- 앱 내 삭제: 설정 → 계정 → 회원탈퇴 → 확인하면 계정과 모든 학습 데이터가 영구적으로 삭제되며, 되돌릴 수 없습니다.
- 앱 없이 요청: [[문의 이메일]] 로 “계정 삭제 요청”과 가입 시 사용한 이메일 주소를 보내주시면, 본인 확인 후 삭제합니다.
- 삭제 범위: 계정(인증 정보), 서버에 저장된 학습·사용량 데이터, 기기 로컬 데이터를 삭제합니다. 다만 재악용 방지를 위해 개인을 식별할 수 없는 최소 표식(이메일 해시)만 보존할 수 있습니다.
- 처리 기간: 요청 접수 후 영업일 기준 [[N]]일 이내에 처리합니다.
- 참고: 진행 중인 유료 구독은 App Store / Google Play 계정에서 별도로 해지해야 합니다(구독은 스토어가 관리).
- In-app deletion: Settings → Account → Delete Account → confirm, and your account and all learning data are permanently deleted (this cannot be undone).
- Request without the app: Email [[문의 이메일]] with the subject “Account deletion request” and the email address you signed up with; we will delete your data after verifying your identity.
- Scope of deletion: your account (authentication info), learning/usage data stored on the server, and local device data. To prevent abuse, only a non-identifying minimal marker (an email hash) may be retained.
- Processing time: within [[N]] business days of receiving the request.
- Note: Any active paid subscription must be canceled separately in your App Store / Google Play account (subscriptions are managed by the store).
6. 만 14세 미만 아동의 개인정보6. Children Under 14
서비스는 만 14세 이상을 이용 대상으로 하며, 만 14세 미만 아동의 개인정보는 수집하지 않습니다. 만 14세 미만 아동이 서비스를 이용한 사실이 확인될 경우, 해당 정보를 지체 없이 파기합니다. (「개인정보 보호법」 준수)
The Service is intended for users aged 14 and over and does not collect personal data from children under 14. If we learn that a child under 14 has used the Service, we will destroy the relevant data without delay (in compliance with PIPA).
7. 광고 및 식별자7. Advertising and Identifiers
- 서비스는 무료 이용자에게만 Google AdMob을 통한 광고(전면·보상형·배너)를 제공합니다. 유료(Premium) 이용자에게는 광고가 표시되지 않습니다.
- 광고 제공 과정에서 광고 식별자(iOS IDFA / Android 광고 ID) 등 광고 SDK가 처리하는 정보가 이용될 수 있습니다.
- iOS 앱 추적 투명성(ATT): iOS에서는 앱 추적 허용 여부를 이용자에게 요청하며, 이용자가 추적을 허용하지 않을 경우 맞춤형 광고에 식별자가 사용되지 않습니다. 이용자는 기기 설정에서 언제든지 광고 식별자 및 추적 설정을 변경할 수 있습니다.
- The Service shows Google AdMob ads (interstitial, rewarded, banner) to free users only. Premium users see no ads.
- Serving ads may involve advertising identifiers (iOS IDFA / Android Advertising ID) and other data handled by the ad SDK.
- iOS App Tracking Transparency (ATT): On iOS we ask for your permission to track; if you decline, identifiers are not used for personalized ads. You can change advertising identifier and tracking settings on your device at any time.
8. 개인정보 보호책임자 및 문의처8. Data Protection Officer and Contact
개인정보 처리에 관한 문의, 불만 처리, 피해 구제 등에 관한 사항은 아래 개인정보 보호책임자에게 연락하실 수 있습니다.
For inquiries, complaints, or remedies regarding personal data processing, you may contact the Data Protection Officer below.
- 상호Company
- [[상호]]
- 대표자Representative
- [[대표자명]]
- 사업자등록번호Business Reg. No.
- [[사업자번호]]
- 주소Address
- [[사업장 주소]]
- 개인정보 보호책임자Data Protection Officer
- [[이름/직책]]
- 문의·개인정보 이메일Contact / Privacy email
- [[이메일]]
그 밖의 개인정보 침해에 대한 신고·상담은 개인정보분쟁조정위원회(1833-6972), 개인정보침해신고센터(118) 등에 문의하실 수 있습니다.
You may also report or seek advice on privacy infringements from Korea’s Personal Information Dispute Mediation Committee (1833-6972) or the Privacy Infringement Report Center (118).
9. 개정 이력 및 고지9. Changes and Notice
본 개인정보처리방침은 법령·서비스 정책의 변경에 따라 개정될 수 있습니다. 개정 시에는 앱 내 공지 또는 본 페이지를 통해 변경 사항과 시행일을 사전에 고지합니다.
This Privacy Policy may be revised due to changes in law or service policy. We will announce changes and the effective date in advance via in-app notice or this page.
- 공고일: 2026-07-01
- 시행일: 2026-07-01
- Announced: 2026-07-01
- Effective: 2026-07-01
관련 문서: 이용약관 보기 → Related: View Terms of Service →