PRIVACY POLICY

Privacy policy

How we process and protect personal information.

Privacy policy
Community rules Terms of service Liability and legal notice Youth protection policy Privacy policy

Effective date

1. Data controller and scope

RubyOn Studio (operator: Han Seung Sik) processes the personal information needed for Zirooms registration and community services. This policy applies to the Zirooms website, rooms, posts, messages and related management features.

We obtain consent to collect and use required information at registration. Information members later submit themselves is processed as needed to provide the relevant feature, ensure service safety and handle disputes. New purposes or processing requiring separate consent are explained before they apply.

2. Information processed and purposes

  • Registration and account management: We process email, nickname, a one-way password hash, the time and document version of consent to the terms and personal information collection and use, and the time of confirmation of being at least 14. These are used for login, account identification, password resets and consent verification. Date of birth and resident registration numbers are not collected during signup.
  • Optional profile: Avatar images and file information submitted by members are used to identify authors and provide profiles. Basic features are available without an avatar.
  • Room and board activity: We process room proposals, opening support, management permissions, invitations and acceptance records, posts, comments, replies, attachments, creation and editing times, and mention targets. Your active room list records the room where you first posted and the time. This activity remains even if all posts in the room are deleted; the record for the active room list is deleted when your account is deleted.
  • Messages, notifications and blocking: Senders, recipients, conversation content, sending and reading times, notifications and blocking relationships are used to provide these features.
  • Reports, management and rights protection: Report subjects and reasons, reasons and outcomes of posting restrictions, content hiding and appeals, management records, inquiries and contact details are used for report review, management accountability and protection of rights.
  • Authentication and security: Authentication token hashes, authentication, expiry and revocation times, session cookies and access request information are used to maintain login and prevent abnormal access. Request limits use a hash calculated from a member identifier or access IP. Depending on the environment, servers may retain access and error records including request time and IP.

Content and attachments written by members may contain personal information. Do not upload other people's information without permission or submit sensitive information the service does not need. Passwords are stored as one-way hashes, not plaintext.

3. Retention and deletion

Account identifiers are used to provide the account from registration until deletion. On deletion, the email and nickname are replaced with anonymous identifiers; passwords, password reset information and persistent login information are invalidated. The avatar and derived images are removed through deletion tasks.

Document versions and times of consent to the terms and personal information collection and use, and the time of confirmation of being at least 14, remain in the deleted account record. This verifies the confirmations and consent given at registration; it does not mean the former email and nickname are retained.

Posts, comments, room opening and management history, and existing conversations remain after account deletion to preserve context, with the author shown as a deleted member. Personal information members wrote in that content and attachments are not automatically erased. Delete posts and comments you want removed before deleting your account. For your personal information remaining in messages that cannot be deleted on screen or in content you cannot access, request necessary action through the contact below. Former members can also make requests.

Deleting a post marks the post, its comments and attachments for deletion. Deleting a comment may leave an empty record for the reply structure, but its body and attachments are marked for deletion. Replacing or deleting a room appearance image or avatar also marks its old file and derivatives for deletion. Failed file deletions are retried.

Reports, appeals and management records are kept as needed to handle the matter and disputes; information is deleted or anonymized once its purpose ends. If legal retention duties or ongoing proceedings apply, the information, basis and period are managed separately. Account deletion alone does not mean all management records are published or used for another purpose.

Access and error logs and expired or revoked authentication records are managed as needed to investigate operational and security issues. Records no longer needed are cleared after reviewing member requests and security needs.

If backups are maintained for recovery, access is restricted and they are cleared once their retention purpose ends. Deletions and account withdrawals are also reflected during recovery.

Electronic information is deleted irrecoverably or processed to prevent identification. Printed material, if any, is destroyed appropriately, such as by shredding.

4. Visibility and disclosure to third parties

Posts in open rooms may be public to other users and non-members. Nicknames and avatars are displayed for author identification and member search. Emails and passwords are not disclosed to ordinary members.

Closed room content is accessible to members who accept invitations, room managers and site administrators within their permissions. Revoking an invitation limits later access, but cannot retrieve content already viewed or lawfully saved by another member.

Messages are provided to the participants; authorized site administrators may review reported messages as needed to handle reports. Room management permissions alone do not allow viewing other members' messages or account emails. Do not disclose messages externally without the other person's permission.

Other personal information is not provided to third parties without member consent or a basis under applicable law. For lawful requests from authorities, we verify the basis and scope and process only the minimum necessary information.

5. Processing service providers and international transfers

Information systems are used for server operation, file storage and password reset emails. If personal information processing is outsourced, we verify the provider, work assigned and necessary safeguards and disclose them in this policy.

If personal information is transferred through overseas servers or providers, required details, including items, country, time and method, recipient, purpose, retention and refusal methods, are separately disclosed and a lawful basis established under applicable laws. Provider or transfer condition changes are reflected in this policy.

6. Members' rights and how to exercise them

Members may change email and nickname, delete an avatar, change passwords and delete their accounts in account settings. My posts and comments lets members view their accessible content and edit or delete it within their permissions. Editing may be limited during posting restrictions or read-only status.

Rights under applicable laws, including access, correction, deletion, suspension of processing and withdrawal of consent, may be requested through the email below. Requests are possible after account deletion or without login; we check only minimal materials needed to verify identity and protect others' rights. Representatives may submit materials verifying lawful authorization.

If law provides grounds to limit or defer a request, we explain the reasons and available actions. Stopping processing of information essential to a feature may limit its use.

Zirooms currently does not accept registration from children under 14 or operate a legal guardian consent procedure. If we learn that a child under 14's personal information was processed during registration, we take necessary actions such as restricting registration and deleting information.

7. Cookies and browser storage

Cookies are used for login status, persistent login and prevention of forged requests. Ordinary login authentication lasts 12 hours; persistent login lasts up to 30 days when selected. Logging out, password changes or account deletion may revoke authentication.

Draft content and some screen state may be stored in your browser. Drafts can be recovered in the same browser for 24 hours after the last save and are cleared after successful submission. On shared devices, clear the site's stored data after logging out.

Browser settings let you delete cookies and site data or block storage. Blocking may prevent persistent login and draft recovery. Zirooms currently does not use tracking cookies for targeted advertising or external visit analytics tools.

8. Safeguards and automated decisions

We apply necessary safeguards including account authentication, permission checks, one-way password hashing, transmission protection, request limits and upload access restrictions. Operational permissions are limited by role, and sensitive inputs are managed to avoid unnecessary retention in operational logs.

Administrators review rule violation reports and posting restrictions or content hiding. Request limits, room proposal expiry and authentication expiry apply automatically under set conditions. Questions may be sent to the contact below.

9. Responsible person and remedies

The person responsible for personal information protection is Han Seung Sik; the operating entity is RubyOn Studio. Send privacy inquiries and requests to exercise rights to info@rubyon.co.kr.

For external advice or dispute mediation, contact Personal Information Infringement Report Center (118, without an area code in Korea) or Personal Information Dispute Mediation Committee (1833-6972).

10. Changes to the policy

Changes to personal information processing will be announced with details, reasons and the effective date. Separate consent is obtained before applying changes that require it. The effective date of this document appears at the top.

Operations and rights protection inquiries

RubyOn Studio · Operator: Han Seung Sik

info@rubyon.co.kr