Article 1. Personal Information We Process
The Service processes the following personal information. The Service does not process unique identifying information, such as resident registration numbers, or sensitive information under Article 23 of the Personal Information Protection Act.
| Category | Information | Required / Optional | Legal basis |
|---|---|---|---|
| Registration and login | Account identifiers and email addresses provided by social login providers (Kakao, Google, and Apple); user IDs and nicknames chosen by users | Required | Personal Information Protection Act, Article 15(1)4 (entering into and performing a contract) |
| Information supplied by providers at registration | Name (only if a name is set on the social account) | Optional | Personal Information Protection Act, Article 15(1)1 (consent) |
| Study measurement | Images captured during study and the results of determining whether the user is studying | Required | Personal Information Protection Act, Article 15(1)4 (entering into and performing a contract) |
| Study records | Study start and end times, study time, subject names, and study statistics (study goals are stored only on the user's device and are not transmitted to the Service) | Required | Personal Information Protection Act, Article 15(1)4 (entering into and performing a contract) |
| Study Together | Live video and audio, participation records, group membership information, and study time rankings within groups | Optional (when using this feature) | Personal Information Protection Act, Article 15(1)1 (consent) |
| Study timelapse | Images captured during study and videos compiled from those images (processed only on the user's device) | Optional (when using this feature) | Personal Information Protection Act, Article 15(1)1 (consent) |
| Notifications | Device identifiers for sending notifications and device type (iOS/Android) | Optional (when notifications are allowed) | Personal Information Protection Act, Article 15(1)1 (consent) |
| Automatically generated or collected information | IP address, access date and time, device operating system and app version, app usage records, pseudonymous identifiers for analytics, whether a user has study history or group membership, and aggregate advertising impressions and clicks | Required | Personal Information Protection Act, Article 15(1)4 (entering into and performing a contract) and Article 15(1)6 (legitimate interests: preventing misuse) |
| Website advertising performance measurement | Website visits and clicks, IP address, and browser and device information | Optional | Personal Information Protection Act, Article 15(1)1 (consent) |
The Service uses social login as its sole authentication method and therefore does not collect or retain passwords. Social login providers are separate personal information controllers operating under their own privacy policies, rather than processors acting on behalf of the Service. They provide the information above to the Service with the user's consent. Under Article 20(1) of the Personal Information Protection Act, users may request to be informed of the source and processing purposes of personal information collected from someone other than the data subject, and of their right to request suspension of processing. Advertising impressions and clicks are aggregated in a form that does not identify users.
Article 2. Purposes of Processing Personal Information
- Member management — confirming the intent to register, identifying and authenticating users, maintaining and managing accounts, preventing misuse, and providing notices
- Study measurement — measuring study time by determining whether users are studying, and providing study records and statistics
- Study Together — transmitting live video and audio between participants, managing groups, and providing study time rankings within groups
- Notifications — sending study and group notifications and Service announcements
- Service improvement and statistics — analyzing usage, identifying errors, and improving the Service
- Handling inquiries — reviewing and responding to user inquiries
The Service does not use personal information for purposes other than those above. If a purpose changes, the Service takes necessary measures, including obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
Article 3. Camera Use and Processing of Captured Images
- The Service uses the camera to determine whether users are actually studying and to record their study time. The camera operates only while the study measurement or Study Together feature is in use.
- Captured images are used only to determine whether the user is studying and are discarded when that determination is complete. The Service does not separately store captured images or use them for other purposes. Only the determination results and study time records are retained.
- The Service does not generate or store features for facial recognition or identity verification (biometric information). It does not use captured images to identify individuals or compare them with other users.
- Study measurement cannot be used without camera permission. Users may revoke permission at any time in their device settings.
Article 4. Study Together: Live Video and Audio
- When a user joins a video room, their camera video and microphone audio are transmitted in real time to other users in that room.
- The Service does not record or store video or audio. Transmission ends when the user leaves the room.
- A user's nickname and study time are displayed to other users in the same video room. Users may use the Service without joining a video room by studying alone.
- The Terms of Service prohibit other users from capturing or recording the screen using their own devices. When a report is received, the facts are reviewed and action is taken under Article 10 of the Terms of Service. However, such actions cannot be completely prevented, so users should take care not to include information they do not wish to disclose in their camera view.
- Possible disclosure of sensitive information and ways to avoid it — When joining a video room, video or audio may reveal potentially sensitive information, such as health conditions or religious symbols, to other participants. Users who do not want this may turn off their camera, adjust the camera view to keep their background out of view, or use only the solo study feature without joining a video room.
Article 5. Study Timelapse
- When the timelapse feature is used, images captured during study are processed only on the user's device and are not transmitted to the Service. The Service cannot receive or view this material.
- The material is deleted from the device when video compilation is complete or when the user chooses not to save it.
- A completed video leaves the device only when the user chooses to save it to their photo album or share it externally. Users are responsible for its management and any consequences after saving or sharing it.
- Timelapse is optional and may be turned off at any time in [Settings]. Not using it does not restrict other features, including study time measurement.
Article 6. Retention and Deletion of Personal Information
The Service deletes personal information without delay once the processing purpose has been fulfilled or the retention period has expired.
| Information | Retention period |
|---|---|
| Account information (identifiers, email, user ID, nickname, and name) | Deleted without delay when the account is deleted |
| Study records, subjects and statistics; group and video room participation records | Deleted without delay when the account is deleted |
| Images captured to determine whether the user is studying | Discarded immediately after the determination (not stored) |
| Live video and audio | Not stored |
| Device identifiers for sending notifications | Deleted when the account is deleted or the user logs out. Identifiers of devices for which notification delivery repeatedly fails are automatically deleted. |
| User server access logs (IP address, access date and time) | 3 months from collection |
| Records of personnel accessing personal information processing systems | At least 1 year, in accordance with the Standards for Measures to Ensure the Safety of Personal Information |
| App usage records (based on pseudonymous identifiers) | Up to 14 months from collection |
Deletion procedures and methods
- Personal information that is due for deletion is deleted without delay after confirmation by the privacy officer.
- Personal information in electronic files is permanently deleted using methods that prevent recovery or reproduction.
- When an account is deleted, its study records and group membership information are also deleted and cannot be restored.
- Groups created by a user are deleted when that user's account is deleted. Membership information for other participants in those groups is also deleted.
Article 7. Outsourcing of Personal Information Processing
The Service outsources personal information processing as follows to provide the Service smoothly. Processing agreements set out in writing the requirements to comply with applicable laws, implement safeguards for personal information, prohibit use for other purposes, and return or delete personal information when the outsourced work ends. The Service manages and supervises these processors.
| Processor | Outsourced work |
|---|---|
| Google LLC | Sending notifications, analyzing Service usage statistics, and receiving user inquiries |
| Agora Lab, Inc. | Providing real-time communication |
| Cloudflare, Inc. | Content delivery and infrastructure operations |
| Meta Platforms, Inc. | Measuring website advertising performance |
The Service's origin servers are located in the Republic of Korea. However, when the features described in Article 8 are used, the listed information is transmitted to overseas processors. Under Article 26(6) of the Personal Information Protection Act, a processor may subcontract part of the outsourced work only with the Service's prior consent. In that case, the Service ensures that an equivalent level of personal information protection obligations is maintained. Changes to outsourced work or processors will be disclosed through this Policy.
Article 8. Overseas Transfers of Personal Information
The Service transfers personal information overseas as described below. Transfers related to Study Together, notifications, and access to the Service are made to the extent necessary to perform the contract with the user under Article 28-8(1)3 of the Personal Information Protection Act. Transfers for measuring website advertising performance are not necessary for using the Service, and users may stop them at any time by blocking cookies in their browser settings.
| Recipient | Country | Information transferred | Timing and method | Purpose | Retention period |
|---|---|---|---|---|---|
| Google LLC ([email protected]) | United States | Device identifiers for notifications, nicknames and group names included in notification messages, app usage records, and information entered by users in inquiries | Transmitted over information and communications networks when the relevant feature is used | Sending notifications, analyzing Service usage statistics, and handling inquiries | Until the outsourced purpose is fulfilled or the processing agreement ends |
| Agora Lab, Inc. ([email protected]) | United States | Live video and audio, and IP address | Transmitted over information and communications networks when Study Together is used | Providing real-time communication | Not retained after transmission |
| Cloudflare, Inc. ([email protected]) | United States | IP address, and device and app version information | Transmitted over information and communications networks when the Service is used | Content delivery and infrastructure operations | Until the processing agreement ends |
| Meta Platforms, Inc. ([email protected]) | United States | IP address, browser and device information, and website visits and clicks | Transmitted over information and communications networks when the website is visited | Measuring website advertising performance | Up to 24 months after transmission |
Article 9. Disclosure of Personal Information to Third Parties
The Service does not disclose users' personal information to third parties, except in the following cases:
- The user has given separate prior consent.
- A specific provision of another law permits it.
- A court warrant, such as a warrant for seizure, search, or inspection under the Criminal Procedure Act, is presented.
Displaying nicknames, study time, and live video to other users in the same room or group through Study Together is part of providing the Service when users choose to use that feature.
Article 10. Automatic Collection Technologies and How to Refuse Them
- The Service collects app usage records to analyze usage. It uses pseudonymized identifiers rather than transmitting account identifiers as they are. These identifiers constitute pseudonymized information under the Personal Information Protection Act and are not used to single out individual users. This is a measure to protect personal information within the purposes in Article 2, rather than processing under the special provisions for pseudonymized information in Article 28-2 of the Act.
- In-app advertisements are the same for all users, and only impressions and clicks are aggregated. The Service does not collect advertising identifiers or operate personalized advertising that tracks users.
- The Service's app does not use cookies. The website (studyhama.com) uses analytics tools from Meta Platforms, Inc. to measure advertising performance. In this process, a cookie (_fbp) is set and visit and click records are transmitted to Meta Platforms, Inc.
- Users may refuse automatic collection in the following ways:
- Website — block or delete cookies in browser settings
- App — restrict app tracking in device settings, or uninstall the app
Article 11. Automated Decisions
The following information about the Service's automated decisions is provided under Article 37-2 of the Personal Information Protection Act and Article 44-4 of its Enforcement Decree.
1. Use, purpose, and scope of automated decisions
The Service automatically determines whether a user is studying without human intervention. The purpose is to maintain the reliability of study records by recording only time actually spent studying. These decisions apply to users while they use study measurement or Study Together. Users who do not use these features are not subject to these automated decisions.
2. Main type of personal information used and its relationship to the decision
The Service uses images captured during study to determine whether the user is studying. Other personal information, including account information, study history, and group information, is not used in the determination. Past records and comparisons with other users do not affect the result.
3. Factors considered and the personal information processing procedure
- Factors considered — Visual cues related to study activities in captured images are considered together. The user's identity, appearance, personal characteristics such as gender or age, study content, and level of achievement are not considered. Accumulated personal profiles or evaluation scores are not created.
- Processing procedure — (1) Images are captured while the feature is in use → (2) automated analysis determines whether the user is studying → (3) captured images are discarded immediately after the determination (not stored) → (4) only the determination results and study time are reflected in the user's study records.
- The results are reflected in study time records. If the user is determined not to be studying, the ongoing study record may be ended or study time may be adjusted. Limitations on accuracy and resulting variations are separately addressed in Article 7 of the Terms of Service.
4. Children under 14 and sensitive information
When children under 14 use the Service with the consent of a legal representative, automated decisions use the same purposes, information types, and procedures described above. The personal information processed is limited to images captured during study. In making automated decisions, the Service does not process sensitive information under Article 23 of the Personal Information Protection Act or unique identifying information. It does not generate or store biometric features intended to identify a specific person, such as facial recognition features.
5. How to request refusal or an explanation
- Submitting a request — Use [Settings > Contact us] or the email address in Article 15. Providing the time of the determination and the relevant study record helps us review your request faster.
- Response period — The result will be provided in writing or by email within 30 days of receiving the request. If there is a justified reason why processing cannot be completed within 30 days, the reason will be explained, and the period may be extended up to twice, for no more than 30 days each time.
- Requesting an explanation — The Service explains the result, the types of personal information used, how those types influenced the determination, and the procedure used to make it.
- Refusal — Because study measurement is processing required to perform the service agreement, the right to refuse the decision itself may be restricted under the proviso to Article 37-2(1) of the Personal Information Protection Act. Users who do not want automated determinations may choose not to use study measurement. Other features, such as groups and notifications, remain available.
Article 12. Rights and Obligations of Users and Legal Representatives
- Users may request access to, correction or deletion of, or suspension of processing of their personal information at any time, and may withdraw consent.
- The following rights can be exercised directly in the app:
- Correct account information — [Settings]
- Delete an account and personal information — [Settings > Delete account]
- Opt out of notifications — app notification settings on the device (to request deletion of the device identifier used for notifications, use [Settings > Contact us])
- Stop using timelapse — [Settings]
- Other rights may be exercised through [Settings > Contact us] or the email address in Article 15. The Service takes action within 10 days of receiving the request.
- Rights may also be exercised through a legal representative or an authorized agent. In that case, a power of attorney in the form prescribed in attached Form No. 11 of the Notice on Methods of Processing Personal Information must be submitted.
- Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act. Users cannot request deletion of personal information that other laws expressly require to be collected.
- The Service verifies that the person requesting access, correction, deletion, or suspension of processing is the user concerned or their duly authorized representative.
Article 13. Personal Information of Children Under 14
- In accordance with legal requirements, children under 14 may not register for or use the Service without the consent of a legal representative. By agreeing to this Privacy Policy and the Terms of Service at registration, users confirm that they are at least 14. Users under 14 are deemed to have registered with the consent of a legal representative.
- If a child under 14 uses the Service, their legal representative may request access to, correction or deletion of, or suspension of processing of the child's personal information. The Service takes action without delay when such a request is submitted using the contact details in Article 15.
- If the Service learns that personal information of a child under 14 was collected without a legal representative's consent, it deletes that information without delay.
- While you study, we take images with your camera to check whether you are really studying.
- We delete each image as soon as the check is finished. We do not keep it.
- We do not use facial recognition to find out who you are.
- If you join a Study Together room, the other people in the room can see your camera video live. You can also study alone without joining a room.
- If you have questions, ask with a parent through [Settings > Contact us].
Article 14. Safeguards for Personal Information
- Limiting personnel — We designate and manage the minimum necessary number of people who handle personal information.
- Access permissions — We control access by granting, changing, and revoking permissions for personal information.
- Encryption — Personal information is encrypted during transmission.
- Minimizing collection and retention — We minimize the personal information we hold, including by not retaining images used to determine study activity and not collecting passwords or advertising identifiers.
- Access logs — We retain and manage records of personnel accessing personal information processing systems for at least 1 year and prevent falsification or alteration.
- Malware prevention — We apply security updates to systems used to process personal information and take measures to prevent malware infection.
- Physical safeguards — We control access to systems that store personal information and restrict administrator access routes.
Article 15. Privacy Officer and Contact for Access Requests
The Service designates the following privacy officer to oversee personal information processing and handle related complaints and remedies. Requests for access to personal information are received and handled through the same contact.
- Privacy officer — Sangwon Kwon (HamaHama operator)
- Email — [email protected]
- In-app inquiries — [Settings > Contact us]
Users may submit any privacy-related inquiries, complaints, or requests for remedies arising from use of the Service through this contact. The Service responds and takes action without delay.
Inquiries through [Settings > Contact us] are submitted through an external form service (Google LLC), so the information entered is stored on that provider's servers. If you do not want this, please contact us directly at the email address above.
Article 16. Remedies for Infringement of Rights
Users may seek dispute resolution or consultation from the following organizations for remedies relating to personal information infringements.
- Personal Information Dispute Mediation Committee — 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office — 1301 (www.spo.go.kr)
- Korean National Police Agency — 182 (ecrm.police.go.kr)
- Central Administrative Appeals Commission — 110 (www.simpan.go.kr)
A person whose rights or interests are infringed by an action or failure to act by the Service in response to a request under Article 35 (access to personal information), Article 36 (correction or deletion of personal information), or Article 37 (suspension of processing, etc.) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act.
Article 17. Changes to This Privacy Policy
- This Privacy Policy takes effect on September 16, 2026, replacing the previous Privacy Policy dated March 25, 2025.
- If this Policy is revised due to changes in laws, policies, or the Service, the Service will announce the changes and effective date on this page and through in-app notices at least 7 days before the effective date. Changes that materially affect users' rights will be announced at least 30 days in advance.