FoodKeep Privacy Policy
Effective date: October 1, 2026 · 한국어
Ryeong Lab (the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act of Korea to protect users' personal information and to handle related complaints promptly.
1. Purposes of processing
The Company processes personal information for the following purposes. If a purpose changes, the Company takes the measures required by applicable law.
- Sign-up and sign-in, member identification, and account management
- Storing ingredient, space, and settings data and synchronizing it across devices
- Confirming payments for the paid service (Pro), reflecting subscription status, and handling purchase withdrawals and refunds
- Applying coupons
- Receiving and answering inquiries, and handling disputes
- Preventing misuse, keeping the Service secure and stable, and analyzing errors
- Showing ads to free service users (see Section 10)
2. Personal information processed and legal basis
The Company processes only the personal information needed to provide the Service. Items A to D below are processed without consent under Article 15(1)4 of the Personal Information Protection Act (necessary to perform a contract with the data subject or to take steps at the data subject's request before entering into a contract), and item E under Article 15(1)6 of the same Act (the Company's legitimate interest in service security and misuse prevention). The Company currently processes no personal information on the basis of consent.
A. Sign-up and sign-in (members only)
- Information received from social login providers (Google, Kakao, Naver): login provider, the provider's member identifier, email address, name or nickname
- Information generated by the Company: member identifier
- Terms consent records: the version (effective date) of the Terms agreed to, time of consent, how consent was given (sign-up or re-consent), device platform, app version
B. Use of the Service (members only, stored on the server)
- Space names, ingredient names, categories, storage locations, quantities, units, expiry dates, notes
- Whether notifications are on, notification time, default space, language setting
- Device identifier, device name, operating system type, app version, last access time
C. Paid service payments (paying members only)
- Subscription product, billing cycle, purchase token, order number, payment status, payment and expiry times, whether the first-year discount applied, payment verification information sent by the payment channel
- Coupon usage history
- The Company does not receive payment method information such as card numbers. Payment methods are handled by Google Play.
D. Contact us
- Inquiry type, inquiry content, reply email address (non-members) or account email (members), device identifier, app version, user-agent, access IP
E. Information generated automatically while using the Service
- Server access records (access IP, access time, request details), error records
F. Information processed only on the device and not sent to the Company
- Receipt photos and receipt recognition results: text recognition runs on the device, and photos and recognition results are not sent to the Company's servers.
- Ingredient photos
- Ingredient and space data of non-members
3. Personal information of children under 14
The Company does not allow children under 14 to sign up as members and asks users on the sign-in (sign-up) screen to confirm that they are 14 or older. If the Company learns that personal information of a child under 14 has been processed, it destroys that information without delay.
4. Processing and retention periods
(1) The Company destroys personal information without delay once the purpose of processing has been achieved. Retention periods by item are as follows.
- Member and service usage information (Section 2 A and B): until the account is deleted
- Inquiry information (Section 2 D): 3 years from the date of the inquiry
- Server access records (Section 2 E): 3 months
- Temporary information used to process sign-in: 7 days
(2) However, information that must be retained under applicable law is kept for the following periods even after the account is deleted.
- Records of contracts or withdrawals of purchase (including Terms consent records): 5 years (Article 6 of the Act on the Consumer Protection in Electronic Commerce and Article 6 of its Enforcement Decree)
- Records of payments and supply of goods and services: 5 years (same Act)
- Records of consumer complaints or dispute handling: 3 years (same Act)
The retained items are purchase records (Section 2 C), the email, name, and social login identifier used to identify the purchaser (stored encrypted), Terms consent records (Section 2 A), and inquiry records. Purchase records are kept for 5 years from the purchase date, Terms consent records for 5 years from account deletion, and inquiry records for 3 years from the date of the inquiry.
5. Procedure and method of destruction
(1) Procedure: Personal information whose retention period has ended or whose purpose has been achieved is destroyed without delay. Information retained under applicable law is stored and managed separately from other personal information and is destroyed when its retention period ends.
(2) Method: Information in electronic form is deleted from the database so that it cannot be recovered or reproduced. The Company does not process personal information on paper.
6. Provision to third parties
The Company does not provide users' personal information to third parties, except where a law specifically requires it or an investigative agency requests it following the procedures set out in law.
7. Outsourcing of processing
The Company outsources processing of personal information as follows to provide the Service smoothly.
- Outsourcee: Cafe24 Corp.
- Outsourced work: operating the Service's servers and storing data
In outsourcing contracts, the Company sets out in writing the prohibition of processing beyond the outsourced purpose, technical and managerial safeguards, restrictions on re-outsourcing, management and supervision of the outsourcee, and liability for damages, and supervises whether the outsourcee processes personal information safely. If the outsourced work or the outsourcee changes, the Company announces it through this Privacy Policy.
8. Overseas transfer
The Company does not transfer users' personal information overseas, and the Service's servers are located in the Republic of Korea.
For reference, the following involve services of foreign operators that users use directly, or queries of information issued by those operators.
- Social login: When a user signs in directly with Google, Kakao, or Naver, the Company receives the information in Section 2 A from that provider to confirm the sign-in.
- Payment confirmation: To confirm a payment, the Company queries Google Play for the payment status using the purchase token issued by Google Play.
- Ads: See Section 10.
9. Safeguards
The Company takes the following measures to keep personal information safe.
- Managerial measures: The number of people who process personal information is kept to a minimum.
- Technical measures: Communication between the app and the server is encrypted (HTTPS); server access rights and firewalls are managed; sign-in tokens are stored as hashes; purchaser identification information retained under law is stored encrypted; and server access records are kept.
- Physical measures: Servers are located in the outsourcee's data center and follow the outsourcee's access controls.
10. Automatic collection and ads (collection of behavioral information by third parties)
(1) The app does not use cookies.
(2) The app includes Google AdMob to show ads to free service users. Through AdMob, Google may directly collect the device's advertising identifier, device and app information, access IP, ad view and click history, and similar information, and use it to deliver ads, personalize ads, and measure ad performance. Google's Privacy Policy (https://policies.google.com/privacy) applies to this processing.
(3) Users can refuse personalized ads by deleting or resetting the advertising identifier in the ads menu of the device settings. Ads are not shown while using the paid service.
11. Rights and obligations of data subjects and legal representatives, and how to exercise them
(1) Users may at any time ask the Company to let them view, correct or delete, or stop the processing of their personal information.
(2) Users can delete their member and service data themselves in [Settings > Account > Delete account] in the app. Other requests can be made through [Contact us] in the app, by email, or by phone. The Company acts on requests without delay.
(3) Users may exercise their rights through a representative, such as a legal representative or a person with a power of attorney.
(4) Personal information that applicable law requires to be retained cannot be deleted on request during its retention period.
(5) The Company verifies that the person making a request is the user or a legitimate representative.
12. Privacy officer
The Company designates the following privacy officer to oversee the processing of personal information and to handle related complaints and remedies.
- Name: Hyeonryeong Park (representative)
- Phone: +82-10-2403-2059
- Email: ryeonglab@gmail.com
Users may direct any privacy-related inquiries, complaints, or requests for remedies arising from use of the Service to the privacy officer, and the Company will respond and act without delay.
13. Remedies for infringement
Users may apply to the following bodies for dispute resolution or counseling regarding infringement of personal information.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
14. Changes to this Privacy Policy
This Privacy Policy applies from October 1, 2026. If content is added, deleted, or modified, the Company announces it in the app at least 7 days before it takes effect, and at least 30 days in advance for changes that materially affect users' rights.