Registration uses only the minimum information needed for email-based authentication.
Current coordinates and automatic visit determinations are never sent to the operator server.
Improvement sharing is off by default and can be withdrawn at any time.
1. Overview
This English text is a translation of the Korean Privacy Policy for user convenience. If an interpretation differs, the Korean version governs to the extent permitted by applicable law.
The operator of Scene Tracker provides this Privacy Policy under the Personal Information Protection Act of the Republic of Korea. Scene Tracker is operated free of charge and on a non-commercial basis by an individual developer who is not registered as a business and uses etfactory.dev as the service name. Privacy inquiries are accepted at factory@etfactory.dev or etfactory.dev. etfactory.dev is not currently a registered trade name or legal entity.
The application server and self-operated PostgreSQL database are hosted in the AWS Lightsail Seoul Region by Amazon Web Services Korea LLC.
2. Purposes, data categories, and retention
| Category | Data processed | Purpose | Retention |
|---|---|---|---|
| Member account | Email address, password hash | Identification and sign-in | Until account deletion |
| Consent record | Terms and Privacy Policy versions, consent time, confirmation that the member is at least 14 | Proof of consent | Until account deletion |
| Authentication session | Refresh-token hash; session expiry, revocation, and MFA verification times | Sign-in continuity and security | Until sign-out, account deletion, or a maximum of 30 days |
| Authentication action | HMAC hash of verification/reset code, purpose, failed-attempt count, expiry and use time | Email ownership verification and recovery | Scheduled deletion within one hour after expiry |
| Administrator MFA | Encrypted TOTP secret, recovery-code HMAC hashes, last-used counter | Administrator protection | Until account deletion or MFA re-enrollment |
| Security processing | HMAC-derived request identifier and request count | Brute-force and excessive-request prevention | Scheduled deletion within one hour after the rate-limit window ends |
| Server-side visit record | Place ID/name, region, visit date, optional note entered by the user | Travel history | Excluded immediately and permanently deleted within 30 days after record or account deletion |
| Filming-location submission | Title, place, region, scene description, public evidence URL | Moderation and publication | Excluded immediately and permanently deleted within 30 days after withdrawal or account deletion |
| On-device location | Latitude, longitude, accuracy, automatic visit determination while the app is in use | Course-place proximity detection | Processed only on the current device |
| Optional improvement sharing | HMAC-pseudonymized random on-device identifier; date, event type and count; canonical title ID for a successful title search | Service usage, active-device and return-use analysis | Until sharing is withdrawn or 180 days from creation |
Scene Tracker does not collect a real name, phone number, full date of birth, resident registration number, gender, postal address, payment information, or health information for account registration.
At registration, Scene Tracker separately presents the purpose, required data, retention period, right to refuse, and the resulting limitation on email-account features.
3. Travel data and location processing
Data stored only on the device
Saved places, favorite titles, user-created courses, and travel preferences are stored only on the current device. Only manual visit records entered by a signed-in member are stored in the member account database for restoration across devices. Manual records created before sign-in are stored temporarily on the device and merged after sign-in.
Current location and automatic visits
When automatic visit recording is enabled, Scene Tracker checks latitude, longitude, and accuracy while the app is active. The device calculates the distance to saved course places and creates an on-device visit record when accuracy is within 100 meters and the device is within a 100-meter place radius.
Current coordinates, accuracy, movement routes, and automatically detected visit records are not transmitted to the operator server and are not included in sign-in, backup, or account synchronization. Location checks stop when the app becomes inactive, and the app does not request background location permission. Search, saved places, courses, and manual visit records remain available without location permission.
External information and optional analytics
Nearby tourism and weather requests use only coordinates stored with a filming location or tourism place. The device's current coordinates are not included in requests to the operator server or content providers. Title search terms and travel conditions are processed only as needed to produce results. Email addresses, member IDs, and authentication tokens are not sent to Gemini, the Korea Tourism Organization, the Korea Meteorological Administration, or other content providers.
Service-improvement sharing is off by default and is not a condition of service. Only after a user enables it does the app transmit app-open, successful-title-search, place-save, and course-creation events. The app creates a random identifier unrelated to an account, and the server transforms it with a purpose-separated HMAC to calculate daily feature usage, active devices, and return use.
For a successful title search, Scene Tracker uses the canonical title ID instead of the original search text. Tourism search terms, email addresses, current location, saved-place names, and course names are not stored in analytics. Turning sharing off requests deletion of that device's pseudonymous totals; if offline, the app retries at the next server connection.
Filming-location submissions
A member's submission is linked to the account for moderation. For a submission marked as a residence, the detailed address and coordinates are not stored on the server and the place is not published as a visitable location. Evidence URLs must not contain non-public personal data belonging to the submitter or another person.
4. Children under 14
Scene Tracker does not accept registrations from children under 14 because it does not provide a legal-representative consent and verification process. The service does not collect a date of birth and only asks the user to confirm that they are at least 14.
5. Disclosure to third parties
The operator does not disclose personal data to third parties as a rule. If disclosure becomes necessary, the operator will identify a legal basis and separately provide the recipient, purpose, data categories, retention period, right to refuse, and effect of refusal.
The operator reviews contractual terms and safeguards so that processors and service providers apply privacy protections equivalent to or stronger than those required by this Policy and applicable law.
6. Processors and overseas transfers
| Processor | Service | Data | Retention |
|---|---|---|---|
| Amazon Web Services Korea LLC | AWS Lightsail application and self-operated PostgreSQL hosting | Account, authentication, manual visit, submission, and API operation data | Applicable service retention; logical backups up to 30 days; latest seven automatic snapshots |
| Vercel Inc. | Public Privacy Policy and account-deletion page hosting | IP address, request URL, browser/device information, request time, and response status | Hobby runtime logs available to the operator for one hour; otherwise until the service/security purpose is fulfilled or as required by law |
| Plus Five Five, Inc. (Resend) | Transactional account email delivery | Email address, email metadata, message body, and delivery logs | During the contract and up to 90 days for customer-data deletion after termination |
| Amazon Web Services, Inc. | Resend hosting and email-delivery subprocessing | Data required for that hosting and delivery | Under Resend's subprocessing agreement and applicable law |
The operational database runs in a private Docker network on the same Lightsail Seoul instance and has no public database port. Access-restricted logical backups are deleted after 30 days, and the latest seven Lightsail automatic snapshots are retained. Deletion-pending status and retention periods are reapplied after restoration, and backups are used only for disaster recovery.
The public Privacy Policy and account-deletion pages are provided through Vercel Hobby. Vercel Analytics and Speed Insights are disabled for every /about/scene-tracker route, and no Log Drain is used. Credentials entered into the deletion form are sent directly from the browser to the Lightsail Seoul API and are not routed through the Vercel application server.
Resend overseas transfer
- Recipient
- Plus Five Five, Inc. (Resend) · privacy@resend.com
- Countries
- United States and Japan
- Data
- Recipient email address; sender, recipient, subject, send time, delivery-status metadata; message body containing a verification/reset code or security notice
- Purpose
- Delivery and status confirmation for account verification, password reset, and account-security notices
- Timing and method
- Encrypted HTTPS API transfer whenever verification, reset, or a security notice is requested
- Processing locations
- Routing and delivery in Tokyo (ap-northeast-1), Japan; storage of email metadata, logs, and API records in the United States
- Retention
- During the Resend contract and up to 90 days for deletion after termination, unless a longer period is required by law
- Legal basis
- Overseas processing and storage necessary to enter into or perform the member agreement under Article 28-8(1)(3) of the Personal Information Protection Act, with disclosure in this Policy
- Refusal and effect
- Do not register or request email recovery, or request suspension/account deletion. Email-based features will be unavailable, but public browsing remains available.
Vercel public-page overseas processing
- Recipient
- Vercel Inc. · privacy@vercel.com
- Countries
- United States and countries where Vercel subprocessors operate; requests from Korea may be served from the Seoul edge
- Data
- IP address, request URL, browser/device information, request time, response status, and request identifier
- Purpose
- Delivery, transport security, and troubleshooting of the Privacy Policy and account-deletion pages
- Timing and method
- Encrypted HTTPS processing whenever a user accesses a public page
- Retention
- Hobby runtime logs available to the operator for one hour; otherwise until the service/security purpose is fulfilled or as required by law
- Legal basis
- Overseas processing necessary to perform the member agreement under Article 28-8(1)(3), with disclosure in this Policy
- Refusal and effect
- Do not use the public pages. Account deletion remains available in the app, and inquiries may be sent to factory@etfactory.dev.
Open and click tracking is disabled for account-security emails. Attachments, member IDs, travel conditions, current location, saved places, and courses are not included in email messages. Resend's current subprocessor list is available at resend.com/legal/subprocessors.
Gemini receives only a title and filming-location research request. Member email addresses, tokens, member IDs, current location, saved places, courses, and travel preferences are not transmitted to Gemini.
7. Deletion
When a retention period ends or a purpose is fulfilled, electronic data is deleted in a manner designed to prevent recovery. On an account-deletion request, the email address, password hash, and MFA information are immediately deleted or replaced with irreversible random values, and sessions, authentication actions, and consent records are immediately deleted.
The account, server-side visit records, original submissions, evidence, and moderation history are immediately excluded from general access and permanently deleted within 30 days. A deletion-pending account cannot be restored or used to sign in. Data subject to a statutory retention requirement is separated, retained for the required period, and then deleted.
An independently verified filming-location fact may remain only as service-authored information after removing the submitter, original submission, and account association. Optional analytics totals are deleted after 180 days; withdrawing sharing deletes the corresponding device-HMAC totals earlier.
8. Security measures
- One-way password hashing using scrypt
- Short-lived signed access tokens and rotating refresh tokens
- Refresh-token hashes stored on the server and invalidated at sign-out
- Authentication tokens stored in SecureStore
- Role-based administrator access controls
- HTTPS and separate production secrets
- Limits on failed sign-in and excessive requests
- Single-use email codes stored as HMAC hashes
- Administrator TOTP, recovery codes, and replay prevention
- PostgreSQL-backed HMAC rate limiting
- Purpose-separated HMAC processing for optional device identifiers
- No administrator access to unsubmitted drafts
- No detailed address or coordinates for residential submissions
9. Your rights and how to exercise them
Members may review account information, sign out, or delete their account in Account Management, and may edit or delete visit dates and notes in Visit History. A user who cannot access the app may request deletion at the public account-deletion page by confirming the registered email address and current password.
Requests to access, correct, delete, suspend processing, withdraw consent, or raise an objection may be sent to the privacy contact below and will not be made more difficult than account registration. Optional improvement sharing may be enabled or disabled in App Settings.
10. Privacy contact
- Operating status
- Free, non-commercial service operated by an individual who is not registered as a business
- Service name
- etfactory.dev
- Privacy office
- Scene Tracker Privacy Office
- Privacy email
- factory@etfactory.dev
- Website
- https://etfactory.dev
There is currently no registered business name, registration number, or business address. If monetization and business registration are introduced, the operator will publish the actual business information and notify users before the change takes effect.
11. Changes to this Policy
This Policy takes effect on September 3, 2026. Material changes will be announced in the app or through another appropriate notice before they take effect, and prior versions and revision history will be maintained.
Revision history
- Finalized the App Store release version and provided an English translation with the same substance.
- Reflected the self-operated PostgreSQL database and backup policy on AWS Lightsail Seoul and Vercel Hobby public-page processing.
- Disclosed Resend processing and overseas transfers, non-commercial individual operation, public account deletion, and permanent deletion within 30 days.
- Disclosed submissions, residential safeguards, authentication security, optional pseudonymous analytics, and retention rules.
- Disclosed on-device location processing and prohibited server transfer and account synchronization.
References
- Personal Information Protection Act
- PIPA Article 28-8: Overseas Transfer
- Resend Data Processing Addendum
- Vercel Privacy Notice
- Apple in-app account deletion requirements
This Policy applies to the currently confirmed operation and data flows. It will be reviewed and amended if applicable law or the service architecture changes. The location-information filing and terms requirements must be assessed against the actual deployed architecture.