This is an English translation provided for convenience. If there is any difference between this translation and the Korean original, the Korean version prevails.
In accordance with the Korean Personal Information Protection Act, the NaviPlanner operations team (the “Operator”) protects the personal information of people who use the NaviPlanner service (the “Service”) and has adopted this Privacy Policy to handle related concerns promptly.
1. Personal information we process
- When you join (social sign-in): the member identifier, nickname (name), profile picture URL and email address (if you consent) provided by Kakao, Naver or Google
- When you join (email sign-in): the email address you enter and a name (the part of the address before the @)
- When you save a trip: saved course information such as the trip name and date, your request text, the names and coordinates of the start point and places, and the departure time
- Generated automatically while you use the Service: sign-in session information, IP address, browser information (User-Agent) and access time
- Current location (optional): your device’s coordinates if you choose “Start from current location”. They are used only to calculate the course and, if you save the trip, are saved as the start point.
- When you start navigation: the time and app when you tap the KakaoNavi, Naver Map or TMAP button, the course at that moment (place names and coordinates, departure time, distance and duration), trip region and date, companions, weather forecast and your request text. If you start from your current location, the start coordinates are blurred to about 1 km before being recorded. For members the record is linked to the account; for non-members it is recorded without an account.
- When you report an AI result: the reason you chose, the details you wrote, and the request text, course summary and place names at that moment. For members this is linked to the account.
You can create courses without signing in, but what you enter is not linked to an account or kept.
2. Purposes
- Identifying members, keeping you signed in and preventing misuse
- Creating and saving trip courses, and opening your trips on multiple devices
- Personalized recommendations: we summarize a member’s saved trips (kinds of places often added, favorite foods, places visited, departure times, recent requests) so that even vague requests produce courses that match your taste
- Finding and fixing errors, and reviewing AI result reports
- Usage statistics: analyzing which courses actually lead to departures, to improve recommendation quality
3. Retention period
- Member information and saved trips: until you delete your account. They are destroyed without delay after deletion.
- Sign-in sessions: until you sign out or they expire (up to 7 days)
- Navigation start records: destroyed with the account for members. Non-member records are kept as statistics not linked to any account.
- AI result reports: destroyed 1 year after receipt. Members’ reports are destroyed when the account is deleted.
- Daily AI usage count: to prevent misuse, only the count per day is recorded, keyed by the account for members or by an irreversibly transformed IP address for non-members, and deleted after about 7 days.
- Access logs: for the period required by law, where retention is required
4. How information is destroyed
When you delete your account, the account, linked social sign-in information, sign-in sessions, saved trips, navigation start records and AI result reports are deleted from the database immediately and cannot be recovered. Temporary data left in your device’s browser can be removed by clearing browser data.
5. Provision to third parties
The Operator does not provide users’ personal information to third parties, except where required by law.
6. Processors and transfers abroad
To provide the Service, we entrust the processing of personal information to the companies below, some of it abroad.
- Google LLC (Firebase App Hosting · Google Cloud) — servers that run the Service. Country: Taiwan (asia-east1). Items: all information sent while using the Service. When and how: sent over the network when you use the Service.
- Neon (Databricks, Inc.) — database storing member information and saved trips. Country: Singapore. Items: member information in section 1, saved trips, navigation start records and AI result reports. When and how: sent over the network when saved.
- Google LLC (Gemini API) — analyzing your request text. Country: United States. Items: the request text, start-point search terms, course information, the weather forecast for the trip date and, for members, the taste summary above (no identifying information such as name or email is sent). When and how: sent when you create or edit a course or search for a start point in a language other than Korean.
- Resend, Inc. — sending email sign-in links. Country: United States. Items: email address and sign-in link. When and how: sent over the network when you request an email sign-in.
The retention period for transfers abroad is the same as in section 3. If you do not want your information transferred abroad, you may choose not to join or delete your account.
We also send search terms, coordinates and departure times to external map, transport and weather services for place search, directions, weather and elevation, but never information that identifies you, such as your name or email. Social sign-in only authenticates you with the service you choose (section 1).
7. Your rights and how to exercise them
- You can view, edit and delete saved trips at any time on the My trips screen.
- You can delete your account at any time from “My account” in the account menu.
- Other requests to access, correct, delete or suspend processing can be sent to the contact below.
8. Cookies and similar technologies
We use cookies to keep you signed in and to remember your display language, and browser storage to keep the course you are working on and your settings on your device. We do not use advertising or tracking cookies. You can refuse cookies in your browser settings, but you will then be unable to sign in.
9. Security measures
- All communication is encrypted with HTTPS.
- Database credentials and authentication keys are kept only on the server, with minimal access rights.
- We do not collect passwords and use only social sign-in and email sign-in links. A sign-in link works once and expires in 5 minutes.
10. Privacy officer
Officer: the NaviPlanner operations team · Contact: Email yje1120@gmail.com
You can also report or seek advice on privacy violations from the Korea Internet & Security Agency’s Privacy Violation Report Center (privacy.kisa.or.kr, dial 118 in Korea) or the Personal Information Dispute Mediation Committee (kopico.go.kr, +82-1833-6972).
11. Changes to this policy
If this policy changes, we will announce it on the Service from 7 days before the change takes effect, and ask for your consent again for important changes.
12. Revision history
- Revised 2026-10-06: With email sign-in, we added the items processed (section 1), the email processor Resend (section 6) and sign-in link safeguards (section 9). We added that start-point searches typed in a foreign language are translated with Gemini (section 6), and moved map, transport and weather services that receive no personal information out of the processor list into a separate note. Nothing changes for existing members who do not use email sign-in.
- Effective 2026-10-05: previous policy. To receive a copy, contact us at the address in section 10.
Effective date: 2026-10-06