8 8FEED

Privacy, without the fine-print maze.

This page explains how 8FEED handles photos, friend-selection links, location metadata, AI requests, subscriptions, analytics, and advertising on iOS and Android.

Effective / 시행일: August 12, 2026 / 2026년 8월 12일

Privacy Policy

8FEED is operated by XTLab ("8FEED," "we," "us"). This policy applies to the 8FEED mobile apps, backend API, public friend-selection pages, subscriptions, AI curation, and related support.

Local first

Photo organization, quality analysis, similarity matching, and the GPS metadata index run on your device.

Cloud features are optional

Reduced copies leave the device only when you start AI curation or create a friend-selection link. Friend-sharing copies are not sent to OpenAI.

Service state, not identity

The core service uses pseudonymous installation and store transaction identifiers—not a named user profile—to manage subscriptions, usage limits, and security.

1. Information we handle

InformationHow it is usedWhere it is handled
Photos, videos, and media metadata
Selected library items, capture date, media type, dimensions, quality features, Live Photo frames, and embedded GPS metadata.
Date/place search, local indexing, quality and histogram analysis, similar-photo grouping, comparison, selection, recovery, and album export.Normally on your device. Original media files, album names, and the GPS index are not uploaded by 8FEED; optional AI and friend-selection features send only the size-limited JPEG copies described below.
Optional AI curation content
Reduced candidate thumbnails, pseudonymous candidate references, local quality tags, desired count, mood, channel, purpose, caption direction, keywords, and exclusions.
Generate photo selections, reasons, captions, and hashtags when you press the AI recommendation button.Sent through the 8FEED backend to OpenAI. Thumbnails may visibly contain people, places, documents, or other content present in your media.
Optional friend-selection sharing
On-device, size-limited JPEG copies of the photos you choose to share; pseudonymous photo references; selection mode and desired count; request and result identifiers; an invited friend's browser-generated random respondent identifier; their selections; apply/decline status; and timestamps. Standard network and security logs may also process IP address, user agent, and error details.
Create a link for an invited friend, run the two-photo tournament or removal review in a browser, prevent accidental duplicate responses, return the result to the requesting app, and let the requester apply or decline it.JPEG copies are uploaded directly to private Cloudflare R2 object storage and displayed through time-limited signed URLs. Request and response metadata is stored in the 8FEED backend. The respondent identifier is stored as a one-way hash on the backend. Original media files, album names, and the private GPS index are not uploaded for this feature, and friend-sharing copies are not sent to OpenAI.
App and installation data
Random installation identifier generated by the app, pseudonymous backend user identifier, authentication token, IP address supplied by Cloudflare when the installation registers, language, platform, app/build version, device model, launch count, and timestamps.
Operate the API, secure the installation, prevent abuse, apply remote configuration, diagnose service problems, and enforce usage limits.On your device and the 8FEED backend. The installation identifier is stored as a one-way hash, and the registration IP address is stored with the corresponding authentication-token record on the backend.
Landing and installation attribution
First-party random landing visit identifier, UTM source/medium/campaign/id/content/term, Meta click identifier (`fbclid`), landing and referring URLs, locale, store platform and button placement, Cloudflare-supplied IP address, user agent, and timestamps. On Android, Google Play Install Referrer also provides the visit identifier and click/install timestamps.
Measure which campaigns lead from the 8FEED landing page to a store visit and app registration, remove obvious bot traffic, and diagnose acquisition flows.8FEED landing page and backend; Google Play supplies the Android install referrer. Android matches are confirmed using the visit identifier. Because iOS does not return that identifier to the app, 8FEED records a probable match only when one unclaimed iOS store visit shares the registration IP within the configured time window. Ambiguous iOS visits are not matched.
Subscription and purchase data
Store, product and plan identifiers, transaction or purchase-token data, purchase/expiry status, and quota usage.
Verify purchases, provide paid features, prevent fraud, manage renewals, and calculate remaining AI usage.Apple App Store or Google Play and the 8FEED backend. We do not receive your full card or bank details.
Optional product analytics, AI, ad, and service activity
If you allow usage analytics: app-instance identifier, first open, screen and feature interactions, subscription funnel events, aggregate item counts and durations, stable error codes, membership plan, app language, and release channel. AI and ad operations also process candidate/request counts, model and token usage, latency, AI results, and aggregated ad eligibility, requests, impressions, and clicks. Analytics events do not include photos, album names, precise coordinates, prompts, captions, purchase tokens, or transaction identifiers.
With your separate analytics permission, understand product funnels, improve reliability, and measure advertising conversions in a privacy-preserving way. Also return AI results, prevent duplicate charges, enforce quotas, measure costs, operate ads, secure the service, and troubleshoot failures.8FEED and the providers listed below. Google Analytics for Firebase receives analytics events only after you opt in.
Support communications
Your email address and anything you voluntarily include in a message.
Answer requests, including access or deletion requests.Our support email provider and authorized support personnel.

Identity clarification: 8FEED does not require your name, phone number, postal address, contacts, or social account to operate the core service, and it does not create a named user profile. Operational controls rely on a random installation identifier generated by the app and transaction or purchase identifiers provided by the Apple App Store or Google Play. 8FEED does not directly link these values to your name or contact details. They are used only to authenticate installations, verify subscription status, apply usage limits, prevent abuse, and troubleshoot the service—not to determine your real-world identity or build a separate behavioral profile.

Location clarification: 8FEED reads location already embedded in photos to power place search. It does not need your live device location for that feature. The private location index stays on the device and is not included in AI requests.

Friend-link clarification: an invited friend does not need an 8FEED account. The request URL is a bearer link: anyone who receives it can view its reduced photo copies and respond while it is valid. Share it only with intended recipients. A recipient may still save, screenshot, or forward content they can see; 8FEED cannot control copies made outside the service.

2. Analytics, ads, maps, and stores

  • Google Mobile Ads and User Messaging Platform (iOS and Android): depending on your consent and region, Google may process IP-derived approximate location, ad/device identifiers, app interactions, and diagnostics for ad delivery, measurement, and fraud prevention. Ad privacy choices are available in 8FEED Settings where required. See Google Advertising and the Google Privacy Policy.
  • Google Analytics for Firebase (iOS and Android, optional): analytics collection is disabled by default and begins only after you choose “Allow” for optional usage analytics. It may process an app-instance identifier, first open, app sessions and interactions, IP-derived approximate location, device/app information, aggregate counts and durations, stable error codes, and subscription funnel events. If the Analytics property is linked to Google Ads, consented first opens and in-app events may also be used for aggregate advertising measurement and campaign optimization. You can turn this off at any time in 8FEED Settings; doing so stops collection and resets the SDK's local analytics data. This choice is separate from advertising consent and iOS App Tracking Transparency. The iOS app links FirebaseAnalyticsCore, which does not collect IDFA. When ATT is denied, 8FEED does not initialize Google Mobile Ads or access IDFA; eligible advertising attribution instead relies on Apple's SKAdNetwork and Google's privacy-preserving on-device or modeled measurement. Analytics data is not enabled for personalized advertising. See Firebase Privacy and Security.
  • Maps: iOS uses Apple MapKit and Android uses Google Maps Platform. Map providers may receive map viewport, interaction, device, and network information under their own privacy terms. 8FEED does not send the private photo-location index to the map provider.
  • Subscriptions: Apple and Google process payment information and provide transaction status to 8FEED. Their respective privacy policies apply to store payments.

3. AI and friend-selection processing

AI curation. AI requests are sent only after you initiate curation. The 8FEED private queue temporarily holds the reduced thumbnails and request snapshot while the job is queued or processing, then clears that request content after success or failure. We retain AI results and limited usage metadata as needed for result delivery, idempotency, quotas, security, billing, and troubleshooting.

8FEED sends OpenAI Responses API requests with provider storage disabled. Under OpenAI's published API data controls, API content is not used to train models by default unless the customer opts in, while abuse-monitoring data may be retained for up to 30 days or longer when legally required.

Friend-selection sharing. This feature begins only when the requester chooses photos and asks 8FEED to create a link. The app creates size-limited JPEG copies on the device and uploads them directly to private Cloudflare R2 storage. 8FEED returns short-lived signed image URLs to the public request page, stores the invited friend's selection as pseudonymous request data, and makes the result available to the authenticated requester. When the iOS requester previews a result, the app may replace the server copy with the original already present in the requester's own photo library; that local preview does not upload the original.

The public invitation and new friend responses expire after the configured request period, which is currently three days by default. Expiration blocks further public request access and submissions; it does not necessarily cause immediate physical deletion of related backend records, security logs, backups, or R2 objects. Reduced JPEG copies, response records, and the requester's apply/decline decision are retained only as needed to deliver and reconcile the result, secure and troubleshoot the service, handle disputes, satisfy legal obligations, or complete a verified deletion request. Friend-sharing copies are not used for AI curation or model training.

4. Sharing and sale

At the requester's direction, the friend-selection feature displays reduced JPEG copies and request context to anyone who has the invitation link. The invited friend is an independent recipient chosen by the requester, not an 8FEED processor. The requester is responsible for choosing the photos and intended recipients.

Otherwise, we share data only with processors needed to provide the service: OpenAI for optional AI curation; Cloudflare for private R2 object storage and related infrastructure; Google for ads, consent, optional iOS and Android analytics, and Android maps; Apple and Google for purchases; and hosting, database, security, and support providers. We do not sell your photos, prompts, location index, or personal information for money. Advertising-related processing by Google may be treated as "sharing" or targeted advertising under some laws; applicable consent and device controls are provided.

We may also disclose information when required by law, to protect users or the service, or as part of a business transfer with appropriate safeguards. We expect service providers to protect information consistently with this policy and applicable law.

5. Retention and deletion

  • On-device data: sessions, local analysis caches, preferences, AI results, and the location index remain until you delete relevant sessions/data or uninstall the app. Uninstalling does not delete your original photo library items.
  • Backend data: installation, entitlement, AI-result, quota, advertising counter, and operational records are retained while needed to provide the service and thereafter only for legitimate security, fraud, accounting, dispute, and legal obligations. Purchase records may be retained for the legally required period.
  • Acquisition data: landing/store IP addresses, user agents, landing/referring URLs, and the raw `fbclid` are removed after 30 days by default. Normalized UTM fields, visit/click times, platform, and confirmed or probable installation links may be retained as operational and aggregate acquisition records. The raw-data period may be changed for legitimate operational or legal needs.
  • AI queue content: reduced thumbnails and the queued request snapshot are cleared from our private job queue after the job succeeds or fails.
  • Friend-selection content: public invitation access and submissions currently expire after three days by default. Expiration is an access control, not a promise of immediate storage deletion. Reduced JPEG copies and selection records follow the purpose-based retention and deletion process described in Section 3.
  • Third parties: Cloudflare, Google, Apple, and OpenAI retain data under their own policies, contracts, and configured controls.

6. Your choices and rights

  • Limit or revoke photo-library access in iOS or Android system settings. Core photo features may stop working.
  • Do not start AI curation if you do not want thumbnails or written directions sent to our AI processor.
  • Do not create a friend-selection link if you do not want reduced copies stored in our private cloud storage or viewed by anyone who receives the link. Share only photos you are authorized to share.
  • Turn optional usage analytics on or off at any time in 8FEED Settings. This choice is separate from iOS App Tracking Transparency.
  • Manage ad consent from 8FEED Settings where the privacy option is available, and manage advertising identifiers in device settings.
  • Delete individual saved sessions in the app; uninstall the app to remove its remaining local data.
  • Request access, correction, restriction, objection, or deletion of backend data by emailing [email protected] with the subject 8FEED Privacy Request. We may request limited information to verify the installation and will respond as required by applicable law.

7. Security and international processing

We use transport encryption, pseudonymous identifiers, hashed server-side link and respondent credentials, private object storage, time-limited signed image URLs, access controls, and data minimization. No system is perfectly secure. Providers may process data in South Korea, the United States, or other countries where they operate, subject to applicable transfer safeguards.

8. Children

8FEED is not directed to children under 13, or under 14 in South Korea, and we do not knowingly create profiles for them. A parent or guardian who believes a child has provided data should contact us for deletion.

9. Changes and contact

We may update this policy when features, providers, or laws change. We will update the effective date and provide additional notice when required.

Controller / Operator: XTLab (8FEED)
Privacy contact: [email protected]
Address: 602 Yeongdong-daero, Gangnam-gu, Seoul 06083, Republic of Korea

개인정보처리방침

8FEED는 XTLab(이하 “8FEED” 또는 “회사”)이 운영합니다. 본 방침은 8FEED iOS·Android 앱, 백엔드 API, 공개 친구 선택 페이지, 구독, AI 큐레이션 및 관련 고객지원에 적용됩니다.

기기 내 처리가 기본

사진 정리, 품질 분석, 유사도 비교 및 GPS 메타데이터 색인은 기기에서 처리됩니다.

클라우드 기능은 선택 사항

AI 큐레이션을 시작하거나 친구 선택 링크를 만들 때만 축소본이 기기 밖으로 전송됩니다. 친구 공유용 축소본은 OpenAI로 전송되지 않습니다.

신원이 아닌 서비스 상태

실명 프로필 대신 가명화된 설치·스토어 거래 식별값으로 구독, 이용 한도와 보안 상태만 관리합니다.

1. 처리하는 정보

정보이용 목적처리 위치
사진·동영상 및 미디어 메타데이터
선택한 보관함 항목, 촬영일, 미디어 유형, 크기, 품질 특징, Live Photo 프레임 및 사진에 포함된 GPS 메타데이터
날짜·장소 검색, 로컬 색인, 품질·히스토그램 분석, 유사 사진 그룹화, 비교·선택, 프레임 복구 및 앨범 저장원칙적으로 기기 내 처리. 8FEED는 원본 미디어 파일, 앨범 이름 및 GPS 색인을 업로드하지 않으며 선택적 AI 및 친구 선택 기능에는 아래 설명된 크기 제한 JPEG 축소본만 전송합니다.
선택적 AI 큐레이션 정보
축소된 후보 썸네일, 가명화된 후보 참조값, 로컬 품질 태그, 원하는 장수, 분위기, 채널, 업로드 목적, 캡션 방향, 키워드 및 제외 요청
사용자가 AI 추천 버튼을 눌렀을 때 사진 선택, 선택 이유, 캡션 및 해시태그 생성8FEED 백엔드를 거쳐 OpenAI로 전송됩니다. 썸네일에는 사진 속 인물, 장소, 문서 또는 기타 내용이 보일 수 있습니다.
선택적 친구 사진 선택 공유
사용자가 공유 대상으로 고른 사진을 기기에서 크기 제한 JPEG로 만든 축소본, 가명화된 사진 참조값, 선택 방식·목표 장수, 요청·결과 식별자, 친구 브라우저가 생성한 무작위 응답자 식별자, 친구의 선택, 적용·거절 상태 및 시각 정보. 표준 네트워크·보안 로그에서 IP 주소, 사용자 에이전트 및 오류 정보가 처리될 수 있습니다.
친구에게 보낼 링크 생성, 브라우저에서 두 장 비교 토너먼트 또는 제외 검토 제공, 우발적인 중복 응답 방지, 요청 앱으로 결과 전달 및 요청자의 적용·거절 처리JPEG 축소본은 비공개 Cloudflare R2 객체 저장소로 직접 업로드되며, 유효기간이 짧은 서명 URL을 통해 표시됩니다. 요청·응답 메타데이터는 8FEED 백엔드에 저장되고, 응답자 식별자는 서버에 단방향 해시로 저장됩니다. 이 기능으로 원본 미디어, 앨범 이름 및 비공개 GPS 색인은 업로드되지 않으며 친구 공유용 축소본은 OpenAI로 전송되지 않습니다.
앱·설치 정보
앱이 생성한 무작위 설치 식별자, 가명화된 백엔드 사용자 식별자, 인증 토큰, 설치 등록 시 Cloudflare가 전달한 IP 주소, 언어, 플랫폼, 앱·빌드 버전, 기기 모델, 실행 횟수 및 시각 정보
API 운영, 설치 인증, 부정 이용 방지, 원격 설정 적용, 장애 진단 및 이용 한도 적용기기 및 8FEED 백엔드. 설치 식별자는 서버에서 단방향 해시로 저장되고, 가입 IP 주소는 해당 인증 토큰 기록과 함께 백엔드에 저장됩니다.
랜딩·설치 유입 정보
자사 랜딩 방문 무작위 식별자, UTM source·medium·campaign·id·content·term, Meta 클릭 식별자(`fbclid`), 랜딩·유입 URL, 언어, 마켓 플랫폼·버튼 위치, Cloudflare가 전달한 IP 주소, User-Agent 및 시각 정보. Android에서는 Google Play Install Referrer가 방문 식별자와 클릭·설치 시각도 제공합니다.
어떤 캠페인이 8FEED 랜딩, 마켓 방문 및 앱 가입으로 이어지는지 측정하고 명백한 봇 트래픽을 제외하며 유입 흐름의 오류를 진단8FEED 랜딩 페이지와 백엔드에서 처리하며 Android 설치 referrer는 Google Play가 제공합니다. Android는 방문 식별자로 확정 연결합니다. iOS는 해당 식별자를 앱에 돌려주지 않으므로 설정 시간 안에 가입 IP와 같은 미귀속 iOS 마켓 방문 후보가 하나뿐일 때만 추정 연결하며, 후보가 여러 개면 연결하지 않습니다.
구독·구매 정보
스토어·상품·요금제 식별자, 거래 또는 구매 토큰 정보, 구매·만료 상태 및 사용 한도
구매 검증, 유료 기능 제공, 부정 이용 방지, 갱신 관리 및 남은 AI 사용량 계산Apple App Store 또는 Google Play와 8FEED 백엔드. 회사는 전체 카드번호나 은행정보를 수신하지 않습니다.
선택적 제품 분석·AI·광고·서비스 활동
사용 분석을 허용한 경우 앱 인스턴스 식별자, 첫 실행, 화면·기능 상호작용, 구독 퍼널 이벤트, 집계된 항목 수·소요시간, 안정적인 오류 코드, 멤버십 요금제, 앱 언어 및 배포 채널을 처리합니다. AI·광고 운영에서는 후보·요청 수, 모델·토큰 사용량, 지연시간, AI 결과 및 집계된 광고 대상·요청·노출·클릭 수도 처리합니다. 분석 이벤트에는 사진, 앨범 이름, 정밀 좌표, 프롬프트, 캡션, 구매 토큰 또는 거래 식별자를 포함하지 않습니다.
별도의 분석 동의를 받은 경우 제품 퍼널 파악, 안정성 개선 및 개인정보 보호형 광고 전환 측정. 그 밖에 AI 결과 제공, 중복 차감 방지, 한도 적용, 비용 측정, 광고 운영, 보안 및 장애 해결8FEED 및 아래 명시된 처리업체. Google Analytics for Firebase에는 사용자가 동의한 후에만 분석 이벤트가 전송됩니다.
고객지원 내용
이메일 주소와 사용자가 문의에 자발적으로 포함한 내용
열람·삭제 요청을 포함한 문의 대응고객지원 이메일 제공업체 및 권한이 있는 담당자

식별정보 안내: 8FEED는 핵심 서비스 운영을 위해 이름, 전화번호, 주소, 연락처 또는 소셜 계정을 요구하지 않으며, 실명 기반 사용자 프로필을 생성하지 않습니다. 운영 제어에는 앱이 무작위로 생성한 설치 식별자와 Apple App Store·Google Play가 제공하는 거래 또는 구매 식별값을 사용합니다. 회사는 이 값을 사용자의 이름이나 연락처와 직접 연결하지 않으며, 설치 인증, 구독 상태 확인, 이용 한도 적용, 부정 이용 방지 및 장애 대응 등 필요한 범위에서만 처리합니다. 이 값으로 사용자의 실제 신원을 확인하거나 별도의 행동 프로필을 만들지 않습니다.

위치정보 안내: 8FEED는 장소 검색을 위해 사진에 이미 포함된 위치 메타데이터를 읽습니다. 이 기능에 현재 기기의 실시간 위치는 필요하지 않습니다. 비공개 위치 색인은 기기에만 저장되며 AI 요청에 포함되지 않습니다.

친구 링크 안내: 초대받은 친구는 8FEED 계정이 없어도 참여할 수 있습니다. 요청 URL은 링크 보유 방식이므로 유효기간 중 링크를 받은 사람은 축소 사진을 보고 응답할 수 있습니다. 의도한 사람에게만 공유하세요. 수신자는 보이는 내용을 저장·캡처하거나 다른 사람에게 전달할 수 있으며, 8FEED는 서비스 밖에서 만들어진 복사본을 통제할 수 없습니다.

2. 분석, 광고, 지도 및 스토어

  • Google Mobile Ads 및 User Messaging Platform(iOS·Android): 이용자의 동의와 지역에 따라 Google은 광고 제공·측정·부정 이용 방지를 위해 IP 기반 대략적 위치, 광고·기기 식별자, 앱 상호작용 및 진단 정보를 처리할 수 있습니다. 필요한 지역에서는 8FEED 설정에서 광고 개인정보 선택을 관리할 수 있습니다. Google 광고 안내Google 개인정보처리방침을 참고하세요.
  • Google Analytics for Firebase(iOS·Android, 선택 사항): 분석 수집은 기본적으로 비활성화되어 있으며 사용자가 선택적 사용 분석에 “허용”을 선택한 후에만 시작됩니다. 앱 인스턴스 식별자, 첫 실행, 앱 세션·상호작용, IP 기반 대략적 위치, 기기·앱 정보, 집계된 항목 수·소요시간, 안정적인 오류 코드 및 구독 퍼널 이벤트가 처리될 수 있습니다. Analytics 속성이 Google Ads와 연결된 경우 동의한 사용자의 첫 실행과 인앱 이벤트는 집계된 광고 성과 측정 및 캠페인 최적화에도 사용될 수 있습니다. 8FEED 설정에서 언제든 끌 수 있으며, 끄면 수집이 중단되고 SDK의 로컬 분석 데이터가 초기화됩니다. 이 선택은 광고 동의 및 iOS 앱 추적 투명성(ATT)과 별개입니다. iOS 앱은 IDFA를 수집하지 않는 FirebaseAnalyticsCore를 연결합니다. ATT를 거절하면 8FEED는 Google Mobile Ads를 초기화하거나 IDFA에 접근하지 않으며, 가능한 광고 귀속은 Apple SKAdNetwork와 Google의 개인정보 보호형 온디바이스 또는 모델링 측정을 사용합니다. 분석 데이터는 맞춤 광고에 사용되도록 설정하지 않습니다. Firebase 개인정보 보호 및 보안을 참고하세요.
  • 지도: iOS는 Apple MapKit, Android는 Google Maps Platform을 사용합니다. 지도 제공자는 자체 방침에 따라 지도 화면 영역, 상호작용, 기기 및 네트워크 정보를 수신할 수 있습니다. 8FEED는 비공개 사진 위치 색인을 지도 제공자에게 전송하지 않습니다.
  • 구독: Apple과 Google이 결제정보를 처리하고 거래 상태를 8FEED에 제공합니다. 스토어 결제에는 각 사업자의 개인정보처리방침이 적용됩니다.

3. AI 및 친구 선택 처리

AI 큐레이션. AI 요청은 사용자가 큐레이션을 직접 시작한 경우에만 전송됩니다. 8FEED 비공개 작업 큐는 작업이 대기·처리되는 동안 축소 썸네일과 요청 스냅샷을 일시 보관하며, 성공 또는 실패 후 해당 요청 내용을 삭제합니다. AI 결과와 최소한의 사용 기록은 결과 전달, 중복 요청 방지, 한도·보안·과금 및 장애 해결에 필요한 기간 보관합니다.

8FEED는 제공자 저장을 비활성화하여 OpenAI Responses API를 호출합니다. OpenAI가 공개한 API 데이터 제어 정책에 따르면 API 데이터는 고객이 별도로 동의하지 않는 한 기본적으로 모델 학습에 사용되지 않으며, 오남용 모니터링 데이터는 최대 30일 또는 법률상 필요한 더 긴 기간 보관될 수 있습니다.

친구 사진 선택 공유. 요청자가 사진을 고르고 링크 생성을 요청한 경우에만 시작됩니다. 앱은 기기에서 크기 제한 JPEG 축소본을 만들어 비공개 Cloudflare R2 저장소에 직접 업로드합니다. 8FEED는 공개 요청 페이지에 유효기간이 짧은 서명 이미지 URL을 제공하고, 친구의 선택을 가명화된 요청 정보로 저장하며, 인증된 요청자의 앱에 결과를 전달합니다. iOS 요청자가 결과를 크게 볼 때 앱이 요청자 사진 보관함에 이미 있는 원본으로 화면을 교체할 수 있으며, 이 로컬 미리보기 과정에서 원본을 업로드하지 않습니다.

공개 초대와 새로운 친구 응답은 설정된 요청 기간 후 만료되며 현재 기본값은 3일입니다. 만료되면 공개 요청 접근과 추가 응답이 차단되지만 관련 백엔드 기록, 보안 로그, 백업 또는 R2 객체가 즉시 물리적으로 삭제된다는 뜻은 아닙니다. JPEG 축소본, 응답 기록 및 요청자의 적용·거절 결정은 결과 전달·정합성 확인, 서비스 보안·장애 해결, 분쟁 처리, 법적 의무 이행 또는 확인된 삭제 요청 처리에 필요한 범위에서만 보관합니다. 친구 공유용 축소본은 AI 큐레이션이나 모델 학습에 사용하지 않습니다.

4. 제공 및 판매

친구 선택 기능은 요청자의 지시에 따라 초대 링크를 가진 사람에게 JPEG 축소본과 요청 내용을 표시합니다. 초대받은 친구는 요청자가 직접 선택한 독립적인 수신자이며 8FEED의 처리업체가 아닙니다. 요청자는 공유할 사진과 수신자를 적절하게 선택할 책임이 있습니다.

그 밖에는 서비스 제공에 필요한 처리업체에만 정보를 제공합니다. 선택적 AI 큐레이션을 위한 OpenAI, 비공개 R2 객체 저장 및 관련 인프라를 위한 Cloudflare, 광고·동의·선택적 iOS·Android 분석·Android 지도를 위한 Google, 구매 처리를 위한 Apple·Google, 그리고 호스팅·데이터베이스·보안·고객지원 제공업체가 이에 해당합니다. 회사는 사진, 프롬프트, 위치 색인 또는 개인정보를 금전의 대가로 판매하지 않습니다. Google의 광고 관련 처리는 일부 법률에서 “공유” 또는 맞춤형 광고로 해석될 수 있으며, 해당되는 동의 절차와 기기 설정을 제공합니다.

법령상 의무 이행, 이용자·서비스 보호 또는 적절한 보호조치를 갖춘 영업 양도 과정에서 정보가 제공될 수 있습니다. 회사는 처리업체가 본 방침과 관계 법령에 부합하는 보호 수준을 유지하도록 요구합니다.

5. 보유 및 삭제

  • 기기 내 정보: 세션, 로컬 분석 캐시, 설정, AI 결과 및 위치 색인은 사용자가 관련 세션·데이터를 삭제하거나 앱을 제거할 때까지 보관됩니다. 앱 제거는 사진 보관함의 원본을 삭제하지 않습니다.
  • 백엔드 정보: 설치, 권한, AI 결과, 한도, 광고 집계 및 운영 기록은 서비스 제공에 필요한 동안 보관하며, 이후에는 보안·부정 이용 방지·회계·분쟁 및 법적 의무에 필요한 범위에서만 보관합니다. 구매 기록은 관계 법령이 요구하는 기간 더 오래 보관될 수 있습니다.
  • 유입 정보: 랜딩·마켓 IP 주소, User-Agent, 랜딩·유입 URL 및 원문 `fbclid`는 기본 30일 후 삭제합니다. 정규화된 UTM, 방문·클릭 시각, 플랫폼 및 확정·추정 설치 연결은 운영·집계 유입 기록으로 보관할 수 있습니다. 원본 보관 기간은 정당한 운영 또는 법적 필요에 따라 변경될 수 있습니다.
  • AI 작업 큐: 축소 썸네일과 대기 요청 스냅샷은 작업 성공 또는 실패 후 회사의 비공개 작업 큐에서 삭제됩니다.
  • 친구 선택 정보: 공개 초대 접근과 응답은 현재 기본 3일 후 만료됩니다. 만료는 접근 통제이며 즉시 저장 삭제를 의미하지 않습니다. JPEG 축소본과 선택 기록에는 제3조의 목적 기반 보관·삭제 절차가 적용됩니다.
  • 제3자: Cloudflare, Google, Apple 및 OpenAI는 각자의 방침, 계약 및 설정된 제어에 따라 정보를 보관합니다.

6. 이용자의 선택과 권리

  • iOS 또는 Android 시스템 설정에서 사진 보관함 접근 범위를 제한하거나 권한을 철회할 수 있습니다. 이 경우 핵심 사진 기능이 동작하지 않을 수 있습니다.
  • 썸네일과 작성한 요청의 AI 처리를 원하지 않으면 AI 큐레이션을 시작하지 않을 수 있습니다.
  • 비공개 클라우드 저장소에 축소본이 저장되거나 링크를 받은 사람이 이를 보는 것을 원하지 않으면 친구 선택 링크를 만들지 않을 수 있습니다. 공유 권한이 있는 사진만 공유하세요.
  • 8FEED 설정에서 선택적 사용 분석을 언제든 켜거나 끌 수 있습니다. 이 선택은 iOS 앱 추적 투명성(ATT)과 별개입니다.
  • 해당 메뉴가 제공되는 지역에서는 8FEED 설정에서 광고 동의를 관리하고, 기기 설정에서 광고 식별자를 관리할 수 있습니다.
  • 앱에서 저장 세션을 개별 삭제할 수 있으며, 앱을 제거하면 남아 있는 로컬 앱 데이터가 삭제됩니다.
  • 백엔드 정보의 열람, 정정, 처리 제한, 반대 또는 삭제를 요청하려면 제목을 8FEED Privacy Request로 하여 [email protected]으로 문의하세요. 설치 확인에 필요한 최소한의 정보를 요청할 수 있으며 관계 법령에 따라 처리합니다.

7. 보호조치 및 국외 처리

회사는 전송 구간 암호화, 가명 식별자, 서버 측 링크·응답자 인증정보 해시, 비공개 객체 저장소, 유효기간이 짧은 서명 이미지 URL, 접근 통제 및 최소 수집 원칙을 적용합니다. 다만 어떠한 시스템도 완전한 보안을 보장할 수 없습니다. 처리업체의 운영 지역에 따라 정보가 대한민국, 미국 또는 기타 국가에서 처리될 수 있으며, 관계 법령이 요구하는 이전 보호조치를 적용합니다.

8. 아동

8FEED는 만 13세 미만 또는 대한민국의 만 14세 미만 아동을 대상으로 하지 않으며, 이를 인지한 상태에서 아동의 프로필을 생성하지 않습니다. 아동의 정보가 제공되었다고 판단하는 법정대리인은 삭제를 요청할 수 있습니다.

9. 변경 및 문의

기능, 처리업체 또는 법령이 변경되는 경우 본 방침을 개정할 수 있습니다. 시행일을 갱신하고 필요한 경우 별도로 알립니다.

개인정보처리자 / 운영자: XTLab (8FEED)
개인정보 문의: [email protected]
주소: 대한민국 서울특별시 강남구 영동대로 602, 06083