Privacy policy
In effect September 5, 2026 · version 2026-09-05
츄카(ㅊㅋ) (the “Service”) is an online group card service operated by an individual on a nonprofit basis. This document explains what information it receives, where it is stored and when it is deleted.
Article 1 · Information collected
The following is the complete list of information stored by the Service.
- Login account identifier — Received when you log in with whichever of Kakao, Google, LINE or Apple you chose, so we can recognize the same person logging in again. Logging in with Google or LINE also stores your profile image URL.
- Nickname — Entered by the user.
- Party content — The birthday person's name, congratulatory messages and character settings, entered by users.
- Photos and audio — Only when attached to a message. These are optional.
What a login response contains and what the Service stores are not the same thing. We request no consent items from Kakao. Google returns a response under the openid, email and profile scopes, but we do not store your email or name; LINE is requested with openid and profile; Apple is requested with openid only, and we do not ask Apple for your name or email. What we store is the identifier above and, for Google and LINE, a profile image URL.
Article 2 · Information stored in your browser
The Service does not use cookies to identify users. Instead, it keeps the values below in your browser's localStorage and includes them in requests only when needed.
- Login token (session_token) — Received after login and sent with requests to verify your login session.
- Party and message keys (host_token:…, author_token:…, event_id:…) — Proof that lets you later edit or delete a party you created or a message you left. Issued once per party and not reissued.
- Entry codes and passes (party_pass:…, party_code:…) — Used so you do not have to enter the code again every time you visit a protected party.
- Unfinished message (guest_draft:…) — Temporarily saves your text while you go off to log in. Deleted when you send the message or close the editor. Photos and audio are not included.
- Display settings (muted, bgm_notice_seen, intro_seen:…, post_login_path) — Whether sound is muted, notices have been seen and where to return after login. These values are not sent to the server. Another value, kakao_share_pending, similarly remembers whether you pressed Kakao share until the tab closes.
Clearing the browser's site data removes all these values. However, party and message keys cannot be reissued, so clearing them may prevent you from editing or deleting your messages yourself. In that case, contact us below.
In addition, Vercel's analytics and performance measurement scripts are included on every page hosted by the Service. They measure page visits and rendering speed, and are not used for advertising or user tracking.
Article 3 · Purposes of use
- To let you find and edit parties you created and messages you left
- To make congratulatory messages visible only to the birthday person
Information is not used for other purposes or provided to third parties for advertising or analysis.
Article 4 · Personal information of children under 14
The Service does not collect personal information from children under 14. Only people aged 14 or older may use it. Processing children's information requires a legal guardian's consent. This individually operated nonprofit Service has no means of obtaining and verifying that consent.
However, the Service has no means of checking a person's age. Registration is through Kakao, Google, LINE or Apple login, and none of them gives us a date of birth or an age range. Being at least 14 is therefore something the user confirms at registration, not a fact verified by the Service. We state this openly.
If we learn that we have received information about a child under 14, we delete it without delay. A legal guardian can contact us below if their child's information remains in the Service. After checking, we delete the account and its contributions and report the result. Deletion in this situation takes precedence over Article 6 — Retaining delivered group cards is a rule set by the Service, whereas the rights of children at issue here are established by law.
Article 5 · Retention and deletion
Parties and congratulatory messages are retained without a fixed time limit. A group card is something its recipient may revisit later. Deleting it merely because time has passed would defeat that purpose.
Deletion procedure. To request deletion, contact us below. The operator checks and then deletes the data. There is not yet an automatic deletion feature or account-deletion button.
Deletion method.Records are removed from the database, not merely marked as deleted. Deleting a party also deletes its messages from the database. Photos and audio are separate files: before deleting the records, the Service collects the list of files referenced by the party or message, then deletes those files from storage after the records are removed. Files no longer referenced by any message, such as photos uploaded but never submitted, are found and deleted by a periodic server cleanup job.
Article 6 · A delivered group card belongs to its recipient
The following principle applies to deletion requests. Even if the organizer or a contributor requests deletion of their information, a group card already delivered to its recipient is not deleted.
- A party received by the birthday person remains even if its organizer leaves.
- A message remains with its recipient even if its author leaves.
- If the recipient requests deletion, the party and its contents are deleted together.
We regard a delivered letter as belonging to its recipient. However, if the birthday person has never opened the reveal link, the party has not yet been claimed and its organizer may request deletion.
Article 7 · Service providers
- Amazon Web Services — Database and file (photo and audio) storage
- Vercel — Website hosting, and the analytics and performance measurement described in Article 2
Logging in is done with a Kakao, Google, LINE or Apple account. You sign in with that service directly; what we receive from it and store is listed in Article 1.
Article 8 · Your rights
You may request access to or deletion of your information. Contact us below; we will check, process the request and inform you of the result.
Article 9 · Security measures
All communications are encrypted using HTTPS. Entry codes are stored in protected form, not as plaintext. The server restricts messages to the birthday person, and party pages are blocked from search-engine crawling.
Article 10 · Remedies for infringement of rights
If you are dissatisfied with how the Service handled a privacy matter, you may seek advice or dispute mediation from the organizations below. They are independent of the Service and can be contacted directly.
- Personal Information Dispute Mediation Committee — 1833-6972 · kopico.go.kr
- Personal Information Infringement Report Center — 118 · privacy.kisa.or.kr
Article 11 · Privacy officer and contact
The Service is operated by an individual on a nonprofit basis. The privacy officer is the operator, Kim Changheon. There are no departments or separate organization, so the same person receives and handles requests.
Send privacy questions and requests for access or deletion to changheon.whale@gmail.com .
Article 12 · Changes
When this policy changes, we will update the effective date and version on this page. Significant changes may require renewed consent within the Service.