개인정보처리방침
Hello Word(헬로 워드)는 이용자의 개인정보를 소중히 여기며, 대한민국 개인정보 보호법에 따라 개인정보를 처리합니다.
update 최종 업데이트: 2026년 7월 22일 · 시행일: 2026년 7월 29일
제1조 (총칙 및 목적)
Hello Word(이하 "서비스")는 이미지에서 의학·비즈니스·시험 대비·일반 영어 등 모든 분야의 단어·용어를 자동으로 추출하여 단어장·암기·퀴즈·복습 기능을 제공하는 웹 학습 도구입니다. 서비스 제공자(이하 "회사")는 정보주체의 개인정보를 보호하고 관련 고충을 신속하게 처리하기 위하여 이 개인정보처리방침을 수립·공개합니다.
본 방침은 서비스가 어떤 개인정보를 어떤 목적으로 수집·이용하며, 어떻게 보관·파기하는지, 그리고 정보주체가 자신의 개인정보에 대하여 어떤 권리를 행사할 수 있는지를 안내합니다.
제2조 (수집하는 개인정보 항목·수집목적·보유기간)
서비스는 회원 가입, 서비스 제공, 결제 처리 등을 위하여 다음의 개인정보를 수집·이용합니다.
| 구분 | 수집 항목 | 수집·이용 목적 | 보유 기간 |
|---|---|---|---|
| 회원 필수항목 | 아이디, 비밀번호(단방향 해시 저장), 이름, 이메일, 가입일시, 유료 여부 | 회원 식별·인증, 서비스 제공, 고지·안내 | 회원 탈퇴 시 즉시 파기(법정 보존 항목 제외) |
| 자동 수집항목 | IP 주소, 브라우저 핑거프린트, 접속 로그 | 일일 사용량 관리 및 부정 이용(어뷰징) 방지 | 접속 로그 3개월 / 그 외 탈퇴 시 즉시 파기 |
| 광고 제공 과정 | 쿠키, 온라인 식별자, IP 주소 등 | Google AdSense 광고의 제공·측정 및 법령상 허용되는 범위의 개인화 | Google의 처리방침 및 이용자 설정에 따름 |
| 서비스 이용항목 | 단어장 콘텐츠(terms_json), 학습 기록(learned_terms), 일일 사용량 카운터 | 단어장·암기·퀴즈·복습 등 학습 서비스 제공 | 회원 탈퇴 시 즉시 파기 |
| 결제 정보 | 구독 정보(빌링키, 고객키), 플랜, 결제 금액, 결제일 | 유료(Pro) 구독 정기결제 처리 및 관리 | 관련 법령에 따라 5년 보존 |
제3조 (개인정보 수집 방법)
회사는 다음의 방법으로 개인정보를 수집합니다.
- 회원 가입 및 서비스 이용 과정에서 정보주체가 직접 입력하는 방법
- 서비스 이용 과정에서 기기·접속 정보가 자동으로 생성·수집되는 방법(IP 주소, 브라우저 핑거프린트, 접속 로그)
- Google AdSense 광고 제공 과정에서 광고 파트너가 쿠키·온라인 식별자 등을 자동으로 처리하는 방법
- 유료 구독 신청 시 결제 처리를 위해 결제 대행사를 통해 수집되는 방법
제4조 (업로드 이미지 처리 정책)
서비스의 핵심 기능인 이미지 분석(OCR)은 정보주체의 개인정보 보호를 최우선으로 설계되었습니다.
- 업로드된 이미지는 서버 디스크에 저장되지 않으며, 메모리에서만 처리된 후 처리 완료 즉시 폐기됩니다.
- 이미지 분석은 서버 내 자체(로컬) 모델로 수행되며, 이미지를 외부 업체나 제3자에게 전송하지 않습니다.
- 이미지로부터 추출된 텍스트(단어·의미·발음)만 정보주체의 단어장에 저장됩니다. 원본 이미지 자체는 보관되지 않습니다.
제5조 (개인정보 처리위탁)
회사는 원활한 서비스 제공을 위하여 다음과 같이 개인정보 처리 업무를 외부에 위탁하고 있습니다. 위탁 계약 시 개인정보가 안전하게 관리되도록 관련 사항을 규정하고 있습니다.
| 수탁자 | 위탁 업무 내용 |
|---|---|
| Resend | 이메일 API 발송 업무 — 인증번호 및 안내 메일 발송 |
| Google LLC (Google OAuth) | Google 계정 선택 및 로그인 본인 인증 |
| Google LLC (Google AdSense) | 광고 제공, 측정 및 법령상 허용되는 범위의 광고 개인화 |
| (주)토스페이먼츠(Toss Payments) | 신용카드 정기결제 처리 업무 |
제6조 (개인정보의 보유 및 이용기간)
회사는 원칙적으로 개인정보 수집·이용 목적이 달성되거나 회원이 탈퇴하면 해당 개인정보를 지체 없이 파기합니다. 다만, 관계 법령에 따라 보존이 필요한 경우 아래 기간 동안 보관합니다.
| 보존 항목 | 보존 기간 | 근거 법령 |
|---|---|---|
| 계약 또는 청약철회 등에 관한 기록 | 5년 | 전자상거래 등에서의 소비자보호에 관한 법률 |
| 대금결제 및 재화 등의 공급에 관한 기록 | 5년 | 전자상거래 등에서의 소비자보호에 관한 법률 |
| 소비자의 불만 또는 분쟁처리에 관한 기록 | 3년 | 전자상거래 등에서의 소비자보호에 관한 법률 |
| 표시·광고에 관한 기록 | 6개월 | 전자상거래 등에서의 소비자보호에 관한 법률 |
| 접속(로그) 기록 | 3개월 | 통신비밀보호법 |
위 법정 보존 항목을 제외한 나머지 개인정보는 회원 탈퇴 시 즉시 파기됩니다.
제7조 (개인정보 파기 절차 및 방법)
회사는 보유기간이 경과하거나 처리 목적이 달성된 개인정보를 다음 절차와 방법으로 파기합니다.
1. 파기 절차
파기 사유가 발생한 개인정보는 내부 방침에 따라 파기 대상으로 분류되며, 지체 없이 파기됩니다. 법령에 따라 보존해야 하는 정보는 별도의 영역에 분리 보관한 뒤 보존 기간 종료 시 파기합니다.
2. 파기 방법
- 전자적 파일 형태의 정보: 복구·재생이 불가능한 방법으로 영구 삭제
- 그 밖의 기록·출력물: 분쇄하거나 소각
제8조 (정보주체와 법정대리인의 권리·의무 및 행사방법)
정보주체는 언제든지 다음의 권리를 행사할 수 있습니다.
- 개인정보 열람 요청
- 오류 등이 있을 경우 정정 요청
- 삭제 요청
- 개인정보 처리정지 요청
위 권리는 계정 설정 메뉴 또는 가입 시 등록한 이메일을 통하여 행사할 수 있으며, 회사는 지체 없이 조치합니다. 또한 정보주체는 단어장 데이터를 CSV·JSON 내보내기 기능을 통해 직접 내려받아 이동할 수 있습니다.
다만, 관계 법령(전자상거래 등에서의 소비자보호에 관한 법률 등)에 따라 일정 기간 보존이 의무화된 결제·거래 기록 등은 삭제·처리정지 요청의 대상에서 제외되며, 해당 법정 보존 기간이 종료된 후 파기됩니다.
만 14세 미만 아동에 대해서는 서비스가 회원 가입을 받지 않으므로, 별도의 법정대리인 권리 행사 절차는 적용되지 않습니다.
제9조 (만 14세 미만 아동의 개인정보)
서비스는 만 14세 이상만 회원으로 가입할 수 있으며, 만 14세 미만 아동의 개인정보는 수집하지 않습니다. 회원 가입 시 정보주체는 만 14세 이상임을 동의로 확인합니다.
제10조 (쿠키 등 자동 수집장치)
서비스는 로그인 상태 유지를 위한 세션 쿠키를 사용합니다. Google AdSense 광고가 제공되는 경우 Google 및 그 광고 기술 파트너는 광고 제공·빈도 관리·측정 및 법령상 허용되는 범위의 개인화를 위해 쿠키 또는 유사 기술을 사용할 수 있습니다.
EEA, 영국 및 스위스 이용자에 대한 광고 쿠키 동의는 Google이 지원하는 인증된 CMP를 통해 수집합니다. 이용자는 브라우저 설정 또는 Google 광고 설정에서 광고 개인화 설정을 관리할 수 있습니다. 쿠키 저장을 거부하면 로그인 유지 등 일부 기능 또는 광고 개인화가 제한될 수 있습니다.
제11조 (개인정보의 안전성 확보조치)
회사는 개인정보의 안전성을 확보하기 위하여 다음과 같은 기술적·관리적 조치를 취하고 있습니다.
- 비밀번호는 단방향 해시로 변환·저장하여 원본을 복원할 수 없도록 보호
- 데이터 전송 구간 HTTPS/TLS 암호화 적용
- 개인정보에 대한 접근 권한 통제 및 최소 권한 부여
- 접속 기록의 보관 및 관리
제12조 (개인정보 보호책임자)
회사는 개인정보 처리에 관한 업무를 총괄하고 정보주체의 고충을 처리하기 위하여 개인정보 보호책임자를 두고 있습니다.
| 구분 | 내용 |
|---|---|
| 개인정보 보호책임자 | 테크인라이프 개인정보 보호 담당자 |
| 이메일 | techinlife0@gmail.com |
정보주체는 개인정보 보호와 관련한 문의·불만·피해구제 등에 관하여 위 이메일로 문의하실 수 있으며, 회사는 지체 없이 답변·처리합니다.
제13조 (권익침해 구제방법)
정보주체는 개인정보 침해로 인한 구제를 받기 위하여 다음의 기관에 분쟁 해결이나 상담 등을 신청할 수 있습니다.
| 기관 | 전화 | 홈페이지 |
|---|---|---|
| 개인정보분쟁조정위원회 | 1833-6972 | www.kopico.go.kr |
| 개인정보침해신고센터 | 118 | privacy.kisa.or.kr |
| 대검찰청 사이버수사과 | 1301 | www.spo.go.kr |
| 경찰청 사이버수사국 | 182 | ecrm.police.go.kr |
제14조 (개인정보처리방침의 변경 고지)
이 개인정보처리방침은 시행일로부터 적용됩니다. 방침이 변경되는 경우 변경 사항의 시행 7일 전에 서비스 내 공지를 통하여 고지합니다. 다만 정보주체의 권리에 중대한 영향을 미치는 중요한 변경의 경우 시행 30일 전에 고지합니다.
Privacy Policy
Hello Word values users' personal information and processes it in accordance with the Personal Information Protection Act of the Republic of Korea.
update Last updated: July 22, 2026 · Effective: July 29, 2026
Article 1 (General Provisions and Purpose)
Hello Word (the "Service") is a web-based learning tool that automatically extracts vocabulary and terms across all fields — medical, business, test preparation, general English, and more — from images and provides memorization, quiz, and review features. The provider of the Service (the "Company") establishes and discloses this Privacy Policy to protect data subjects' personal information and promptly handle related grievances.
This Policy explains what personal information the Service collects and for what purpose, how it is stored and destroyed, and what rights data subjects may exercise over their own personal information. For business registration details, please contact the Company by email as described below.
Article 2 (Items Collected, Purpose, and Retention Period)
The Service collects and uses the following personal information for membership registration, service provision, and payment processing.
| Category | Items collected | Purpose | Retention period |
|---|---|---|---|
| Required member items | Username, password (stored as a one-way hash), name, email, sign-up date, paid status | Member identification/authentication, service provision, notices | Destroyed immediately upon withdrawal (except items subject to statutory retention) |
| Automatically collected items | IP address, browser fingerprint, access logs | Daily usage management and abuse prevention | Access logs: 3 months / others: destroyed immediately upon withdrawal |
| Ad-serving process | Cookies, online identifiers, IP address, etc. | Serving and measuring Google AdSense ads, and personalization to the extent permitted by law | Per Google's policies and the user's settings |
| Service usage items | Vocabulary content (terms_json), learning history (learned_terms), daily usage counter | Providing vocabulary, memorization, quiz, and review features | Destroyed immediately upon withdrawal |
| Payment information | Subscription data (billing key, customer key), plan, amount, payment date | Processing and managing recurring Pro subscription payments | Retained for 5 years under applicable law |
Article 3 (Methods of Collecting Personal Information)
The Company collects personal information through the following methods.
- Directly entered by the data subject during sign-up and use of the Service
- Automatically generated and collected during use of the Service (IP address, browser fingerprint, access logs)
- Automatically processed by advertising partners via cookies and online identifiers during Google AdSense ad serving
- Collected through the payment gateway when processing a paid subscription
Article 4 (Policy on Processing Uploaded Images)
The Service's core feature, image analysis (OCR), is designed with the protection of data subjects' personal information as the top priority.
- Uploaded images are never stored on server disk; they are processed in memory only and discarded immediately after processing completes.
- Image analysis is performed by a local model on the Company's own servers; images are never transmitted to any external vendor or third party.
- Only the text extracted from the image (term, meaning, pronunciation) is saved to the data subject's vocabulary set. The original image itself is never retained.
Article 5 (Outsourcing of Personal Information Processing)
To provide the Service smoothly, the Company outsources the following personal information processing tasks to external parties. The outsourcing agreements specify the measures required to keep personal information secure.
| Processor | Outsourced task |
|---|---|
| Resend | Sending emails via API — verification codes and notices |
| Google LLC (Google OAuth) | Google account selection and login authentication |
| Google LLC (Google AdSense) | Serving and measuring ads, and personalization to the extent permitted by law |
| Toss Payments Corp. | Processing recurring credit card payments |
Article 6 (Retention and Use Period of Personal Information)
In principle, the Company destroys personal information without delay once the purpose of collection is achieved or the member withdraws. However, where retention is required by applicable law, the information is kept for the periods below.
| Item retained | Retention period | Legal basis |
|---|---|---|
| Records of contracts or withdrawal of subscription | 5 years | Act on the Consumer Protection in Electronic Commerce, Etc. |
| Records of payment and supply of goods/services | 5 years | Act on the Consumer Protection in Electronic Commerce, Etc. |
| Records of consumer complaints or dispute resolution | 3 years | Act on the Consumer Protection in Electronic Commerce, Etc. |
| Records of labeling and advertising | 6 months | Act on the Consumer Protection in Electronic Commerce, Etc. |
| Access (log) records | 3 months | Protection of Communications Secrets Act |
Personal information other than the statutory retention items above is destroyed immediately upon withdrawal.
Article 7 (Procedure and Method of Destroying Personal Information)
The Company destroys personal information whose retention period has elapsed or whose processing purpose has been achieved, using the following procedure and method.
1. Destruction procedure
Personal information subject to destruction is classified for disposal under internal policy and destroyed without delay. Information that must be retained under applicable law is stored separately and destroyed once the retention period ends.
2. Destruction method
- Electronic files: permanently deleted using methods that make recovery or reproduction impossible
- Other records/printouts: shredded or incinerated
Article 8 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
Data subjects may exercise the following rights at any time.
- Request to view personal information
- Request correction in case of errors
- Request deletion
- Request suspension of processing
These rights may be exercised via the account settings menu or the email registered at sign-up, and the Company will act without delay. Data subjects may also directly download and transfer their vocabulary data using the CSV/JSON export feature.
However, payment and transaction records that must be retained for a certain period under applicable law (such as the e-Commerce Act) are excluded from deletion/suspension requests and will be destroyed once the statutory retention period ends.
Because the Service does not accept members under the age of 14, no separate procedure applies for legal representatives to exercise rights on a child's behalf.
Article 9 (Personal Information of Children Under 14)
Only individuals aged 14 or older may register as members, and the Service does not collect personal information from children under 14. At sign-up, data subjects confirm they are 14 or older by agreeing to this Policy.
Article 10 (Cookies and Other Automatic Collection Tools)
The Service uses session cookies to maintain login status. Where Google AdSense ads are served, Google and its advertising technology partners may use cookies or similar technologies for ad serving, frequency management, measurement, and personalization to the extent permitted by law.
Consent for advertising cookies from users in the EEA, the UK, and Switzerland is collected through a Google-certified CMP. Users can manage ad personalization settings via their browser settings or Google Ads Settings. Declining cookies may limit certain features, such as staying logged in, or ad personalization.
Article 11 (Measures to Ensure the Security of Personal Information)
The Company takes the following technical and managerial measures to secure personal information.
- Passwords are converted and stored as a one-way hash so the original cannot be recovered
- HTTPS/TLS encryption applied to data in transit
- Access control over personal information, with minimum necessary privileges granted
- Retention and management of access records
Article 12 (Data Protection Officer)
The Company designates a Data Protection Officer to oversee personal information processing and handle data subjects' grievances.
| Category | Details |
|---|---|
| Data Protection Officer | Tech In Life Privacy Officer |
| techinlife0@gmail.com |
Data subjects may direct inquiries, complaints, or requests for remedy relating to personal information protection to the email above, and the Company will respond and act without delay.
Article 13 (Remedies for Infringement of Rights)
Data subjects may seek dispute resolution or consultation regarding infringement of their personal information from the following agencies.
| Agency | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center | 118 | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 | www.spo.go.kr |
| National Police Agency Cyber Bureau | 182 | ecrm.police.go.kr |
Article 14 (Notice of Changes to this Privacy Policy)
This Privacy Policy applies from its effective date. If the Policy is changed, notice will be given within the Service 7 days before the change takes effect. For material changes significantly affecting data subjects' rights, notice will be given 30 days in advance.