Privacy Policy
This global notice explains what MYMU processes, why, for how long, where it goes, and how you can control it.
Posted 2026-07-21 · Effective 2026-08-01
MYMU is operated by Younggun Park in the Republic of Korea. This notice covers the MYMU mobile application, mymu.app, public sharing pages, support, and release-list services. Contact: support@mymu.app.
1. Data we process, why, and for how long
We collect data directly from you, from Apple or Google when you choose their sign-in service, from your device with permission, and automatically when you use the service. We do not require optional analytics or precise location to create an account.
| Activity | Data | Purpose and basis | Retention |
|---|---|---|---|
| Account, sign-in, and age check | Email, sign-in provider and provider ID, display name, profile image, region category, applicable minimum age, confirmation version and time (not date of birth) | Create and secure the account, synchronize records, and protect children / contract and legal duty | For the life of the account; promptly removed from active systems after deletion, with backups ordinarily expiring within 30 days |
| Culture records | Exhibition, venue, date, rating, notes, photo URLs, and photo metadata or location clues the user elects to submit | Store, sync, and recommend records / contract and consent for optional features | Until the record or account is deleted |
| Public features | Display name, bio, public records, photos and lists, share-link status, follows | Provide public profile and sharing requested by the user / contract | Until made private or deleted; caches ordinarily refresh within 30 days |
| Discovery and location | Current or last-known device location, map-center coordinates, record coordinates | Nearby discovery, maps, and record suggestions / device permission and service request | Current location is not kept as a separate history after the request. Coordinate-free use records: 6 months. Record coordinates remain until record deletion |
| Saves, follows, reports | Saved events, relationships, submitted content, report reason and status | Provide features, prevent abuse, resolve disputes / contract and legitimate interests | Until feature or account deletion; dispute records up to 3 years after closure |
| Push notifications | Push token, scheduling and delivery status | Deliver notifications requested by the user / consent | Until token invalidation, opt-out, or account deletion |
| Android release list | Email, signup time, language, consent version | Release and testing notices / consent | Deleted immediately on unsubscribe or no later than 24 months after the last signup |
| Optional analytics and diagnostics | Minimized events, app/browser/device context, random identifier, error, crash, and performance data | Improve quality and reliability / consent | New collection stops on withdrawal. Ordinarily no more than 14 months, subject to contracted backup deletion cycles |
| Access and security | IP address, user agent, request time and path, security incident records | Protect the service, diagnose failures, prevent abuse / legitimate interests and legal duties | Ordinarily up to 90 days; incident and legal records as needed to resolve the matter |
| Support | Email and device, version, screen, or error information the user includes | Answer requests and resolve disputes / requested steps and legitimate interests | Up to 3 years after closure |
Where Korean law applies, core account and record data is processed as necessary to perform the service contract; optional analytics, release email, push notifications, and device location rely on separate permission or consent. Where GDPR-type law applies, our bases are contract, consent, legal obligation, and our legitimate interests in security, reliability, and abuse prevention. You may object to legitimate-interest processing.
2. Public content and sensitive information
Records are private unless you deliberately publish a profile, list, record, or share link. A public item may expose your display name, review, visit date, rating, venue, and selected photos. Photos and text can reveal faces, health, beliefs, affiliations, or other sensitive facts. Review the preview, remove metadata or people you should not publish, and keep the item private if disclosure is inappropriate. Turning off public access stops new access; search or recipient caches may take up to 30 days to refresh.
3. Service providers and international transfers
We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive information to infer characteristics. The following providers process only the data needed for their task under contractual and security controls. Transfers occur over encrypted networks when you use the relevant feature and may continue for the retention period above.
- Vercel — Landing hosting, delivery, and security; data: IP address, user agent, request path and time; primary processing location: United States and global edge locations; provider privacy contact.
- Neon — Android release-list database; data: Email, signup time, language, and consent version; primary processing location: United States (AWS us-east-1); provider privacy contact.
- DigitalOcean — API hosting and operational logs; data: Account, records, feature data, and access/security logs; primary processing location: Singapore (sgp1); provider privacy contact.
- Cloudflare R2 — User-photo storage and delivery; data: Submitted photos, object keys, and technical metadata; primary processing location: Cloudflare's global network; automatic placement controlled by Cloudflare; provider privacy contact.
- Resend — Release-list confirmation and notification email; data: Email address, language, message, and delivery status; primary processing location: United States; provider privacy contact.
- PostHog — Optional product analytics; data: Minimized events, device context, and random identifier; primary processing location: United States; provider privacy contact.
- Google Analytics — Optional web analytics; data: Minimized web events, device context, and random identifier; primary processing location: United States and other Google processing locations; provider privacy contact.
- Sentry — Optional error, crash, and performance diagnostics; data: Error stack, app/device context, and random installation identifier; primary processing location: United States; provider privacy contact.
- Expo — Push-token processing; data: Push token and notification delivery metadata; primary processing location: United States; provider privacy contact.
- Apple Push Notification service — Notification delivery; data: Device push token, notification payload, and delivery metadata; primary processing location: United States and global delivery locations; provider privacy contact.
- Apple — Sign-in and identity verification selected by the user; data: Authentication token, provider ID, and profile fields Apple releases; primary processing location: United States and global processing locations; provider privacy contact.
- Google — Sign-in and identity verification selected by the user; data: Authentication token, provider ID, and profile fields Google releases; primary processing location: United States and global processing locations; provider privacy contact.
- Kakao — Venue-name geocoding for records and discovery; data: Venue name, address, and geocoding query; primary processing location: Republic of Korea; provider privacy contact.
For EEA, UK, or Swiss transfers, we use an applicable adequacy decision or contractual safeguards such as approved standard contractual clauses where required. Japanese users may request information about the foreign recipient safeguards. Korean transfers rely on contract-performance transfer/hosting disclosures or separate consent where the law requires it. Contact us for a copy or summary of applicable safeguards.
4. Cookies, local storage, and analytics choices
Essential local storage remembers language, release-list completion, and your analytics choice. Optional PostHog and Google Analytics storage loads only after you select Allow. It can include random browser identifiers and analytics storage lasting up to 24 months, subject to earlier deletion or browser controls. We disable advertising personalization, session recording, raw search terms, raw campaign values, referrers, email, and share tokens. Global Privacy Control and Do Not Track signals are treated as a denial of optional analytics.
현재 선택: 선택하지 않음
5. Your choices and rights
Depending on your location, you may request access, confirmation, correction, deletion, restriction, portability, withdrawal of consent, or objection. You may also appeal a refusal and complain to your local regulator. We will not discriminate against you for exercising a privacy right. Delete an account in app Settings, unsubscribe from release email at mymu.app/en/unsubscribe, or email support@mymu.app. We may verify the request and may retain information required by law or needed for security and legal claims.
6. Regional disclosures
- Japan: residents may request disclosure of retained personal data and third-party transfer records, correction, suspension of use, and deletion where the APPI provides. Foreign transfers are described above.
- California and other U.S. states: we voluntarily provide rights to know, access, correct, delete, and obtain a portable copy where applicable. In the preceding 12 months we collected the categories shown in section 1 and disclosed them to the provider categories in section 3 for business purposes. We do not sell or share personal information for targeted advertising and do not offer financial incentives for data.
- EEA, UK, and Switzerland: you may exercise GDPR-style rights and complain to the authority where you live or work. We do not make solely automated decisions producing legal or similarly significant effects. If local law requires a representative before MYMU specifically targets that market, we will designate and publish one.
- Australia, Canada, Brazil, and other regions: we honor access, correction, deletion, consent withdrawal, objection, and complaint rights to the extent applicable local law provides them.
7. Children
MYMU blocks self-service account creation below 14 in Korea, 13 in the United States, 16 in the EEA/UK/Switzerland, and—under our conservative product rule—18 in Japan and other regions. We ask for a region and age-band confirmation but do not collect a birth date. We do not currently offer a parental-consent account path. Contact us if you believe a child created an account using an inaccurate confirmation.
8. Security, deletion, and complaints
We use access controls, encryption in transit, credential separation, log redaction, backups, least-privilege access, and provider reviews. When retention ends, electronic data is securely deleted or de-identified; data retained by law is isolated. No service is risk-free.
Privacy lead: Younggun Park · support@mymu.app. Korean residents may also contact the Personal Information Infringement Report Center (118), Personal Information Dispute Mediation Committee (1833-6972), or Personal Information Protection Commission. Other residents may complain to their local privacy authority.
9. Changes
We post the effective date and keep prior material dates visible. We will give advance notice in the service or by email when required for a material change. The Korean notice controls for Korean-law interpretation; this English notice is intended to provide equivalent information for international users.