Privacy Policy

Published: September 30, 2026 / Effective: September 30, 2026

Kobbokkom Company (the “Company”) processes personal information only as needed to provide Kobbokkom Forum (the “Service”). Sections 1–9 describe the Service’s web and API functions. Section 10 describes the Confi desktop apps separately.

1. Controller and Contact

  • Controller: Kobbokkom Company
  • Privacy inquiries and rights requests: [email protected] or a private Service post

2. Information and Purposes

Category Information Purpose
Google sign-in Google account identifier (sub) and verified email address Member identification, sign-in, and account linking
Member profile Service member identifier, nickname, and profile creation or update time Member display and author display on posts and comments
Forum content Post title, body, preview, category, selected app, public/private state, author, and creation/update times Creating, editing, deleting, searching, displaying, applying visibility, and handling reports
Comments and likes Comment body, author, and time; member, post, and time associated with likes Community features, duplicate-like prevention, and post counts
Sessions and roles Server-side session hash, member identifier, expiry, revocation and last-seen times, and administrator status Maintaining sign-in sessions, sign-out, expiry, and authorization checks
Abuse prevention and security Member identifier, action type (post, comment, or like), time, API errors, and operational records Rate limiting, abuse prevention, security, and incident handling
Web analytics Page path and information needed to send page views in production Understanding service usage and page performance

The Company does not store Google OAuth access tokens or authorization codes as member data. It does not separately collect or store a Google profile photo or Google nickname; the Service nickname is managed within the Service.

3. Cookies and Similar Technologies

  1. To maintain the current sign-in state, the Service sets a __Secure-forum_session session cookie with the HttpOnly, Secure, and SameSite=Lax attributes. The cookie is issued for the kkom.net domain, so the browser also sends it to kkom.net subdomains. It expires with the session and is deleted on sign-out. JavaScript cannot read the cookie value, and the server stores only a hash of the session token.
  2. Google sign-in uses a temporary forum_oauth_state cookie with the same domain and attributes for request verification. The cookie is deleted when sign-in completes and otherwise expires after 10 minutes.
  3. The Service stores the display language (ko or en) in a kkom-lang cookie and in browser local storage. If no language has been chosen, the server sets the cookie from the browser's language preference. The cookie applies only to the host that set it, uses SameSite=Lax, and is kept for one year. The server reads it only to render pages in that language and does not store it as account data.
  4. In production, the Service sends page views to Google Analytics, which sets the _ga and _ga_NDMWN52156 cookies in the browser for this purpose. The scope and retention of browser, device, and network information processed by Google depend on the configured property and Google’s policies and must be confirmed against the live configuration.

4. Retention

  1. Member identification and profile information are retained until withdrawal or a deletion request is processed, except where legal retention or the rights of other users require separate retention.
  2. Posts, comments, private posts, and likes are retained as needed to provide the Service and handle disputes. Public posts and comments may remain after withdrawal with author identifiers removed.
  3. Sessions expire 8 hours after issuance under the default configuration. Revoked and expired sessions are removed through operational cleanup procedures.
  4. user_actions records used to limit repeated posts, comments, and likes are deleted by the daily backup task after they are 3 months old.
  5. Database backups may contain Service data. Backups are retained according to the backup store’s lifecycle and recovery requirements; the exact configured backup period must be confirmed and stated from the production setting.
  6. Information retained by Google Analytics, Cloudflare, Google, and any optional email delivery service follows the applicable property settings, contracts, and policies. The Company will confirm and update this period against the live configuration.

5. Processors and Third-Party Disclosure

The Company may use the following providers as needed to provide the Service. The Company does not sell personal information or disclose it to third parties for advertising purposes.

  • Cloudflare, Inc.: Cloudflare Tunnel connectivity for the web and API domains served from the Company’s own server, CDN, security, and incident response. Request, network, and security information may be processed.
  • Google LLC: Google sign-in and Google Analytics in production. Google uses the account identifier and verified email for sign-in authentication and processes information needed for page-view transmission.
  • AWS: Encrypted storage of operational database backups. The current deployment documentation identifies the backup region as Seoul, Republic of Korea (ap-northeast-2).
  • Email delivery provider: If new-post email notifications are enabled in production, an email delivery provider may be used to send post notifications. The actual provider, transfer countries, and retention period must be confirmed from the production configuration and contract before this feature is enabled.

6. International Transfers

Personal information may be transferred to or accessed from outside Korea during processing by Cloudflare, Google, Google Analytics, or an optional email delivery provider. The transferred items, country, time and method, recipient name and contact, purpose and retention period, and the method and effect of refusing the transfer must be confirmed against the production configuration and contracts and then stated in this Policy. Information that does not need an international provider is not sent to one.

If Google sign-in is not used, sign-in information is not transferred to Google for authentication. Page-view transmission to Google Analytics may occur when the production site is visited and may be limited through browser settings or available blocking methods.

7. Destruction

  1. When the retention period ends or the purpose is fulfilled, the Company destroys personal information without undue delay.
  2. Database records are deleted using methods designed to make recovery difficult. Information remaining in backups is access-restricted and removed through backup rotation and disposal procedures.
  3. Information retained by law or needed for disputes or security is stored separately from other personal information and destroyed when its retention period ends.

8. User Rights and Requests

Within the scope provided by applicable law, users may request access, correction, deletion, restriction of processing, or withdrawal of consent. Requests may be sent to [email protected] or submitted through a private Service post. The Company verifies the requester and considers applicable law, other users’ rights, and legal retention duties before processing.

9. Security Measures

The Company applies reasonable safeguards including access controls, encryption in transit, HttpOnly and Secure session cookies, session expiry and revocation, database access controls, encrypted backups, security updates, and operational record review.

10. Confi Desktop Apps

This section applies to Confi (Confi Image), Confi Compress, Confi Video, and Confi Audio for macOS.

  • Local files and settings: The apps convert or compress files on your Mac. Selected files, their contents, file paths, and conversion settings are not uploaded to the Company’s servers. Preferences and working files are stored locally as needed for the app’s features. Files you save remain in the location you choose and can be deleted using macOS.
  • Optional external actions: If you add an image from a URL, the app requests that address from the specified server, which receives request information such as your IP address. If you choose to view an image’s GPS location on a map, the app opens Google Maps with the selected coordinates. These actions occur only when you choose them and are separate from local file conversion.
  • In-app purchases: Pro purchases and purchase restoration use Apple StoreKit. Apple processes payment and account information under App Store & Privacy. The app checks Apple-provided purchase entitlements on your device to unlock Pro. The Company does not receive your Apple Account password or payment card details from this process.
  • Analytics: The apps do not include third-party advertising or analytics SDKs. Apple may provide App Store sales, usage, or diagnostic reports subject to your Apple settings and Apple’s policies; this is separate from file processing in the apps.
  • Support and website visits: If you email the Company or submit a Forum post, the Company receives the information you choose to send to answer your request. Please avoid including sensitive files or unnecessary personal information. The website and Forum practices in Sections 1–9 apply when you visit or use those services; their cookies and web analytics are not embedded in the Confi apps.

For help with any Confi app, contact [email protected] or visit Confi support.