Privacy / 개인정보 안내
What the Gateway records
For API and MCP calls, an AccessCall records a generated call ID and time, client and agent identity/class, entry and tool, a restaurant or search label, counts of returned places and links, and the outcome. Where available it also records returned place IDs, response status and size, latency, fallback and evidence basis, task and request-context metadata, and evaluation flags. The request context can contain action, mode or goal. Reports and handoff outcomes are separate records submitted by authorized agents.
IP addresses and guest details
The Gateway uses the caller IP transiently for rate limits and daily quotas; raw IP is not written to AccessCall. A daily salted caller hash can be used for abuse controls and reports. Do not send guest names, contact details, payment details, health information, secrets or raw booking requests. The Gateway does not request guest personal data or execute bookings. Restaurant search text can be logged as a shop/search label, so do not place guest information in it.
Retention schedule
The collection-link job is configured to run the 90-day cleanup at most once a day, with a backup and readback check before completion. The separate command supports a dry run and a manual backup-backed apply. Restaurant facts and agent accounts are outside this cleanup.
| Data | Period or current rule | Removal |
|---|---|---|
| Calls, handoffs, outcomes, demand, AI judgments, likes, daily AI budgets, English-name cache | 90 days by default | Daily scheduled cleanup after backup and verification |
| Reviewed and pending agent reports | Not part of the 90-day cleanup | Retained as observation data; separate review or deletion needed |
| Key-request email | Up to 90 days after request or decision | Email removed; open requests expire |
| Agent accounts, credentials, credits and audit records | No deletion period implemented by this job | Contact support for a request; no automatic deletion is claimed |
| Raw IP and User-Agent | Not stored in the application database or app logs; used in memory for rate limits up to one day | Memory window expiry or restart |
| Registration-source hash | Removed after 30 days | Period-salted hash; removed after backup |
| Fly volume snapshots | Daily snapshots retained for 5 days under the current setting | Snapshot expiry |
| Pre-deletion backup files | No deletion period implemented | Restricted operator files |
External AI and overseas processing
The service and database run on Fly.io in Tokyo, Japan. Korean search text, area and hints may be sent to TypeSafe JEV in the United States even when a search is not ambiguous. Restaurant identity checks can send a name, address and candidate public facts. OpenAI may receive an English restaurant name for Hangul-name candidates, or up to the first 500 characters of a free-text request for link-type classification. These transfers occur through service APIs when the relevant operation runs; do not put guest details in search text or request context.
| Recipient / country | Purpose | Data sent | Retention | Model training |
|---|---|---|---|---|
| Fly.io · US company; servers and database in Japan (Tokyo) compliance@fly.io | Service and database hosting | Service requests and stored records, including call metadata, agent account data and any key-request email | Our schedule above; volume snapshots 5 days. Platform logs follow the provider policy; their period is not confirmed. | Not specified in the materials reviewed |
| TypeSafe AI, Inc. · United States privacy@typesafe.ai | Restaurant identification and search-condition judgment | Restaurant name, address, search text, area, hints and candidate public restaurant facts | No fixed period published; follows the provider policy. Telemetry may be used for service improvement. | Customer input is not used to train model weights without prior consent; technical logs, hashes, statistics and classifications may be used to improve services. |
| OpenAI OpCo, LLC · United States; processing region not fixed privacy@openai.com | English-name conversion and link-type classification | One English/romanized restaurant name, or the first 500 characters of a free-text request needing classification | API abuse-monitoring logs up to 30 days by default; longer where legally or safety required. See provider policy. | API data is not used for model training by default unless explicitly opted in. |
Declining or avoiding transfer: Hosting is needed to use this service. There is no guaranteed per-request switch to disable external AI. Some exact-ID or statically resolved requests may avoid an AI call, but do not rely on this for a privacy choice. To decline this processing, stop using the service and contact contact@forkpin.kr about information tied to your account. Do not submit guest personal data.
Incident response
Our proposed procedure is to investigate a confirmed security incident and notify affected users through available contact channels within 48 hours after we become aware of it, stating the known scope and response steps. We will update the notice as facts are verified.
Correction and questions
Report a wrong restaurant, link or fact through an authorized observation report, or contact contact@forkpin.kr. Include the restaurant ID, field or URL, evidence and observation time; omit guest information. Reports enter review and do not automatically replace facts. See support.
게이트웨이가 기록하는 것
API·MCP 호출의 AccessCall에는 생성된 호출 ID와 시각, 클라이언트와 에이전트 식별·분류, 진입 방식과 도구, 가게·검색 표시문, 반환 가게·링크 수, 결과가 기록됩니다. 가능한 경우 반환한 가게 ID, 응답 상태·크기, 지연 시간, 폴백·근거, 작업·요청 맥락, 평가 여부도 기록합니다. 요청 맥락에는 행동·모드·목표가 포함될 수 있습니다. 권한 있는 에이전트가 제출한 관찰·연결 결과는 별도 기록입니다.
IP와 손님 정보
IP는 한도·일일 할당량 판단에 일시적으로 쓰지만 원본 IP를 AccessCall에 저장하지 않습니다. 남용 방지와 보고에는 일별 솔트를 적용한 호출자 해시를 쓸 수 있습니다. 손님 이름·연락처·결제·건강 정보·비밀·예약 요청 원문은 보내지 마세요. 게이트웨이는 손님 개인정보를 요구하거나 예약을 실행하지 않습니다. 식당 검색어가 가게·검색 표시문으로 기록될 수 있으므로 검색어에도 손님 정보를 넣지 마세요.
데이터 종류별 보관 일정
수집 연결 작업은 하루 첫 실행 때 90일 정리를 최대 한 번 수행하도록 설정돼 있습니다. 완료 전 백업과 재조회를 확인합니다. 별도 명령은 기본 미리보기이며 수동 적용에는 백업이 필요합니다. 식당 사실과 에이전트 계정은 정리 대상이 아닙니다.
| 데이터 | 기간·현재 규칙 | 정리 방법 |
|---|---|---|
| 호출·연결·결과·수요·AI 판정·좋아요·일별 AI 예산·영어 상호 캐시 | 기본 90일 | 백업·검증 후 매일 예약 정리 |
| 검토 완료·대기 중인 에이전트 제보 | 90일 정리 대상 아님 | 관찰 자료로 보존; 별도 검토·삭제 필요 |
| 키 신청 이메일 | 신청·결정 후 최대 90일 | 이메일 제거; 열린 신청은 만료 처리 |
| 에이전트 계정·자격, 크레딧·감사 기록 | 이 작업의 삭제 기간 미구현 | 삭제 요청은 지원 창구로 접수; 자동 삭제를 약속하지 않음 |
| 원본 IP·User-Agent | 앱 DB·앱 로그에 저장하지 않음; 한도 계산용 메모리에서 최대 1일 사용 | 창 종료 또는 서버 재시작 |
| 등록 출처 해시 | 생성 후 30일 | 기간별 솔트 해시; 백업 후 제거 |
| Fly 볼륨 스냅샷 | 현재 설정상 매일 생성, 5일 보관 | 스냅샷 만료 |
| 삭제 전 백업 파일 | 삭제 기간 미구현 | 접근 제한된 운영자 파일 |
외부 AI와 국외 처리
서비스와 DB는 Fly.io의 일본 도쿄 서버에서 운영합니다. 한국어 검색어·지역·힌트는 모호하지 않은 검색에서도 미국 TypeSafe JEV로 전달될 수 있습니다. 가게 식별에는 상호·주소와 후보 가게의 공개 사실이 전달될 수 있습니다. OpenAI에는 영어 상호의 한글 표기 후보를 찾기 위한 상호 1개 또는 창구 종류 판단이 필요한 자유 질의의 앞 500자가 전달될 수 있습니다. 각 작업이 실행될 때 서비스 API로 전송합니다. 검색어나 요청 맥락에 손님 정보를 넣지 마세요.
| 받는 회사·국가 | 목적 | 전달 데이터 | 보관 | 모델 학습 |
|---|---|---|---|---|
| Fly.io · 미국 회사, 서버·DB는 일본 도쿄 compliance@fly.io | 서비스·DB 호스팅 | 요청과 저장 기록: 호출 정보, 에이전트 계정, 키 신청 이메일 등이 포함될 수 있음 | 위 FORKPIN 일정에 따름; 볼륨 스냅샷 5일. 플랫폼 로그 기간은 업체 정책에 따르며 확인되지 않음 | 검토한 자료에 명시되지 않음 |
| TypeSafe AI, Inc. · 미국 privacy@typesafe.ai | 가게 식별·검색 조건 판단 | 상호·주소·검색어·지역·힌트, 후보 가게의 공개 사실 | 고정 기간 미공개, 업체 정책에 따름. 로그·통계 등은 서비스 개선에 사용될 수 있음 | 사전 동의 없이 고객 입력을 모델 가중치 학습에 쓰지 않음. 기술 로그·해시·통계·분류 결과는 서비스 개선에 사용 가능 |
| OpenAI OpCo, LLC · 미국, 처리 지역 고정 안 됨 privacy@openai.com | 영어 상호 변환·창구 종류 분류 | 영어·로마자 상호 1개 또는 창구 종류 판단이 필요한 자유 질의 앞 500자 | API 남용 방지 로그 기본 최대 30일, 법률·안전상 더 길 수 있음. 업체 정책 참조 | 명시적 선택 없이는 API 데이터를 기본적으로 모델 학습에 쓰지 않음 |
국외 처리 거부·회피: 호스팅은 서비스 제공에 필요합니다. 요청별 외부 AI 차단 설정은 없습니다. 일부 인허가 번호 조회나 정적 규칙으로 확정되는 요청은 AI 호출을 피할 수 있지만 보장하지 않습니다. 이 처리를 거부하려면 서비스 이용을 중단하고 계정에 연결된 정보는 contact@forkpin.kr로 문의해 주세요. 손님 개인정보는 보내지 마세요.
사고 대응
보안 사고를 알게 되면 조사하고, 영향을 받은 이용자에게 확인된 범위와 대응 조치를 가능한 연락 경로로 48시간 안에 알립니다. 새 사실이 확인되면 안내를 갱신합니다.
정정·문의
잘못된 가게·링크·사실은 권한 있는 관찰 보고로 제보하거나 contact@forkpin.kr로 알려 주세요. 가게 ID, 필드·URL, 근거와 관찰 시각을 보내되 손님 정보는 제외하세요. 제보는 검토 대상이며 사실을 자동 변경하지 않습니다. 신고 안내를 보세요.
Support: contact@forkpin.kr.
