ChatCar 법적 문서

ChatCar 앱의 개인정보 처리방침 및 이용약관

View the Project on GitHub yw-proj/chatcar-legal

ChatCar Privacy Policy

Effective date: May 11, 2026 Last revised: September 2, 2026

ChatCar (the “Company” or “Service”) complies with the personal-information protection provisions of applicable laws, including the Personal Information Protection Act, and does its utmost to protect users’ personal information safely. This Privacy Policy applies to the ChatCar mobile application (the “App”) and related services provided by the Company.


1. Personal Information Collected

1-1. Sign-up and Identity Verification

Item Collection method Notes
Email address Entered by the user, or via Kakao account Member identification, notifications
Nickname Kakao account (optional consent) Displayed as the in-app username
Kakao user identifier (user_id) Kakao OAuth integration Member identification
Password Entered by the user (for email sign-up) Stored encrypted

1-2. Use of Vehicle Diagnosis Service

Item Collection method Notes
Vehicle information (make/model/year) User input or OBD auto-detection Providing the diagnosis service
Vehicle Identification Number (VIN) OBD auto-detection or user input Vehicle identification
License plate User input Vehicle identification
OBD sensor data Collected automatically when an OBD adapter is connected Real-time diagnosis, AI analysis
AI diagnosis questions/answers User input + AI-generated Diagnosis-history management

1-3. Maintenance-History Management

Item Collection method Notes
Receipt photos Taken/uploaded by the user Deleted immediately after OCR processing
Maintenance items and amounts OCR extraction + user edits Stored as maintenance history
Repair-shop information Extracted from the receipt Stored as maintenance history

1-4. Automatically Collected Information

Item Collection method Notes
Device information (OS, app version) Collected automatically Compatibility, error analysis
App usage logs Collected automatically Service improvement
IP address Collected automatically Security, anomalous-access detection

Payments are processed through the in-app purchase and payment infrastructure of each app marketplace (App Store · Google Play) and RevenueCat. The Company retains only payment records (payment date, amount, product name) and Point accrual/deduction/balance records. The Company does not directly collect payment-method information such as card numbers or CVC.


2. Purpose of Collection and Use

The Company uses the collected personal information for the following purposes:

  1. Member management: Member identification, identity verification, confirmation of intent to sign up, prevention of fraudulent use
  2. Providing the vehicle diagnosis service: OBD data analysis, AI diagnosis, vehicle health-score calculation
  3. Maintenance-history management: Receipt OCR, classification and storage of maintenance items, history lookup
  4. Point management: Granting/deducting/balance management of Points, payment processing
  5. Service improvement: Usage-pattern analysis, development of new features
  6. Customer support: Responding to inquiries, sending notices
  7. Fulfilling legal obligations: Compliance with applicable laws, dispute resolution

3. Retention and Use Period

A member’s personal information is retained and used for the following periods:

Item Retention period Basis
Member information (email, nickname, etc.) Until membership withdrawal Company policy
Vehicle information, diagnosis history Until membership withdrawal Service provision
Maintenance-receipt data Until membership withdrawal Service provision
Payment records 5 years Act on Consumer Protection in Electronic Commerce, Art. 6
Records of contracts or withdrawal of subscription 5 years Act on Consumer Protection in Electronic Commerce, Art. 6
Records of consumer complaints and dispute handling 3 years Act on Consumer Protection in Electronic Commerce, Art. 6
Access logs, IP information 3 months Protection of Communications Secrets Act
Fraudulent-use records 1 year Company policy

Upon a withdrawal request, information is destroyed immediately; however, information that must be retained under the law is stored separately for the relevant period and then destroyed.


4. Provision to Third Parties

As a rule, the Company does not provide users’ personal information to outside parties. The following are exceptions:

  1. Where the user has consented in advance
  2. Where required by law, or where an investigative agency requests it in accordance with the procedures and methods prescribed by law for investigative purposes

5. Outsourcing of Personal-Information Processing

The Company outsources personal-information processing tasks as follows for smooth service provision:

Processor Outsourced task Information provided
Supabase Inc. (USA) Member authentication, database management Email, nickname, vehicle information, etc.
OpenAI, LLC (USA) AI vehicle-diagnosis analysis Diagnosis questions, vehicle/sensor data (excluding personally identifiable information)
Google LLC (USA) OCR (Document AI), Gemini AI Receipt images (deleted immediately after processing)
Kakao Corp. (Republic of Korea) Social login (OAuth) Kakao user_id, nickname, email
RevenueCat, Inc. (USA) In-app purchase / Point-purchase management App user identifier, purchase events (excluding payment-method information)

The Company enters into contracts with processors for safe processing in accordance with the Personal Information Protection Act, and will announce any change of outsourced tasks through this Policy.

Notice on Cross-Border Transfer

Some processors (Supabase, OpenAI, Google, RevenueCat) store data overseas. A user’s personal information is transferred abroad, and this is deemed consented to upon sign-up or upon agreeing to this Policy.


Users may exercise the following rights at any time:

  1. Request to access personal information: Check in the app under [Settings → Account], or request it from the Privacy Officer
  2. Request to correct/delete personal information: In the app under [Settings → Edit Vehicle Information], or request it from the Privacy Officer
  3. Request to suspend processing: Request it from the Privacy Officer
  4. Withdraw membership (delete personal information): Use the in-app [Settings → Delete Account] menu

For children under the age of 14, a legal representative may exercise these rights.


7. Procedure and Method of Destroying Personal Information

Upon membership withdrawal or expiration of the retention period, the Company destroys personal information according to the following:

  1. Destruction procedure: After the purpose of use is achieved or the retention period expires, information is moved to a separate storage area and destroyed after a certain period
  2. Destruction method
    • Electronic files: Permanently deleted in an unrecoverable manner
    • Paper documents: Shredded or incinerated

8. Measures to Ensure Security

The Company takes the following measures to protect personal information:

  1. Administrative measures: Establishing an internal management plan, regular staff training
  2. Technical measures
    • One-way encrypted storage of passwords
    • HTTPS/TLS encryption of communication channels
    • Access-rights management, application of security solutions
  3. Physical measures: Access control to server rooms (compliance with processors’ security policies)

9. Installation/Operation of Automatic Collection Devices and Refusal

The Company may use cookies or similar technologies to analyze user information.


10. Privacy Officer

The Company designates a Privacy Officer as below to oversee personal-information processing and to handle user complaints and remedy damages:

Privacy Officer

Users may direct all inquiries, complaints, and damage-remedy matters related to personal-information protection arising from use of the Company’s Service to the contact above.


11. Remedies for Infringement of Rights

To obtain relief for personal-information infringement, users may apply for dispute resolution or counseling to the following organizations (Republic of Korea):


12. Changes to This Policy

If this Privacy Policy changes, the Company will notify users through an in-app announcement or email at least 7 days before the change takes effect. However, where there is a material change to users’ rights or obligations, notice will be given at least 30 days in advance.


13. Post-Withdrawal Data Retention (Abuse Prevention and Data Restoration on Re-registration)

As a rule, the Company deletes all personal information upon membership withdrawal. However, to prevent repeated receipt of free sign-up Points (abuse) and to restore data upon re-registration (service continuity), the Company retains the following information for 6 months and automatically destroys it after the retention period. (Consent to this retention and restoration is deemed given by agreeing to this Policy at sign-up.)

Retained Items

Item Retention form Purpose
Kakao user identifier SHA-256 hash Identifying the same user upon re-registration
Email address SHA-256 hash (after normalization) Identifying the same user upon re-registration
Point balance Plaintext Restoring the Point balance upon re-registration
Vehicle information (make, model, year, VIN, mileage, etc.) Plaintext (personal information) Restoring vehicle information upon re-registration
Diagnosis history Plaintext (personal information) Restoring diagnosis history upon re-registration

Retention Purpose

Processing Method

Retention Period and Destruction


Addendum

This Privacy Policy applies from June 16, 2026; the amended Policy (addition of RevenueCat as a processor, etc.) applies from July 10, 2026. The amended Policy resulting from the transition from subscription to Point-based payment (payment information, purposes of use, outsourcing, retained items, etc.) applies from September 2, 2026.