Privacy Policy
This is a translation for convenience. If it differs from the Korean version, the Korean version prevails.
Before going live, the actual processors, transfers abroad, retention periods and legal bases must be confirmed. This draft is not a final, legally reviewed policy.
1. Operator and privacy officer
Dando operator and privacy officer: 윤재훈
Privacy inquiries: wogns8030@naver.com
2. What we collect and why
- Sign-up (required): name, date of birth, mobile number, e-mail address, password (stored only in a form that cannot be turned back) and how you use Dando (protect my device / guardian). Used to confirm a parent’s or guardian’s consent under 14 (the time of consent is kept), to sign you in, to keep one account per person (an e-mail address and a mobile number can each have one account only), and so that your guardian or the operator can check who is asking and contact you when you ask to release blocking.
- Kakao / Naver sign-in: the member number, and what you agree to share: e-mail, mobile number, name, birth year and birthday. Used to sign you in and to join one person’s Kakao and Naver sign-ins into one account (the provider-verified number is also kept as a keyed hash for this).
- E-mail codes: codes for sign-up, password reset, changing account details and operator sign-in are kept only as a hash, for 10 minutes.
- Devices and protection: a device identifier, credentials, protection settings (always-on VPN, browser check and the like), regular status signals and protection events (turned off, another VPN turned on, app removal attempts). Used to run protection and to tell your guardian.
- Recovery record: the date you stopped gambling and, if you enter it, daily spending. The date restarts when another VPN is turned on or protection stays off without approval for 30 minutes.
- Anonymous board (app): posts, comments, likes and reports. Other users never see the writer, only “Anonymous”. The writer’s account is kept so you can edit or delete your own posts, and only the operator sees it, to handle reports, stop posting and answer requests under the law. When you delete your account, your posts stay but no longer lead to you.
- Judging gambling sites: domains, cleaned-up URLs, public pages and, on supported devices, part of the on-screen text with personal details removed. DNS lookups from a PC are used only to answer whether a site is a gambling site and are not stored as a browsing history. Network traffic as a whole is not decrypted.
- Notifications and payment: the app notification token (Android FCM, iPhone APNs) if you allow notifications, and purchase verification data when you pay. Card numbers are not collected.
- Support and launch notices: the content of inquiries and a reply address if you leave one; the e-mail address for launch notices.
3. Who else sees what
- Your guardian sees protection status and its alerts, your days without gambling, messages you send and, with a release request, your name and mobile number.
- The operator sees your name and mobile number with a release request when you have no guardian, to confirm it is you before approving.
- Nobody — guardian or operator — sees the sites you visit or your screen. Per-user block records hold only that and when something was blocked; per-site statistics are kept apart from users.
4. Retention and deletion
Account details are kept while you use Dando and deleted without delay when you delete your account. Messages, alerts, block records and closed requests are cleaned up after 180 days by default. E-mail codes expire after 10 minutes. Database backups are kept for 14 days and then replaced. The final retention period for launch-notice e-mails and resolved inquiries is to be confirmed before launch; ask support to delete them earlier.
5. Processing by other companies and transfers abroad
- Judging sites with AI: Google LLC (United States) and OpenAI, L.L.C. (United States). Only site addresses and page content are sent, never your account.
- E-mail: NAVER Corp. (mail delivery, Korea). Sign-in: Kakao Corp. and NAVER Corp. (Korea).
- App notifications: Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service), United States. Purchase verification: Google Play and Apple App Store.
- Server hosting: to be announced when the operating setup is decided.
6. How information is protected
Passwords are stored with one-way encryption, connections use HTTPS, codes and tokens are stored as hashes, the operator page needs a password and an e-mailed code, and access to personal data is limited to what each role needs.
7. Your rights
You can see and change your name, date of birth, mobile number and e-mail on the Account page (changes take a code sent to your e-mail), and delete your account in the app settings. You can also ask support to access, correct, delete or stop processing your information. Do not include passwords, codes or full payment details in inquiries.
8. Browser storage
The website keeps your sign-in and language choice in the browser. You can clear them in your browser settings (you will be signed out). Loading web fonts makes a request to Google Fonts.
9. Changes
Changes to this policy are announced on this page with their effective date. Reference: Personal Information Protection Commission privacy portal (Korea).