Recorded off-page
Privacy Policy
- Recorded on
- 2026-08-17
Scope and standards
This policy applies to every screen and public API this web service provides. The Korean and English pages carry the same content. What it discloses covers both the items required by Article 30 of Korea's Personal Information Protection Act and Article 31 of its Enforcement Decree, and the items the California Online Privacy Protection Act (Cal. Bus. & Prof. Code § 22575 et seq.) requires for users in California. This service does not meet the business-size thresholds set by the California Consumer Privacy Act (CCPA/CPRA), but it discloses that law's items voluntarily as well — the "Notice for California users" clause below is where they live.
Categories of personal information processed
What is processed falls into four groups. (1) What you post yourself — comment text, nickname, profile picture, and the note you add when filing a report. The first three appear on public pages as given; a report note is never published and is visible only on the operator's review page — but because it is something one user writes about another, it is listed here as well. (2) What the service records automatically — the cookie values stored in the browser, and, when an error occurs, the address that was being handled and when, which may be kept alongside the error record. The visiting IP address and browser type (User-Agent) are not recorded by this service — the party that sees the visitor's real IP address and keeps it in its own logs is Cloudflare, which delivers this site. We set this out separately in the clauses on automatically kept access records and on third-party provision and processing entrustment below. (3) What is received from outside when you sign in — the Google account identifier (sub) and nothing else, converted into an irreversible value the moment it arrives and used only as a marker. Name, email, phone number, address, date of birth, and gender are not received through any path. Government-issued identification numbers and sensitive information such as health, beliefs, or political opinions are not processed. (4) What Google receives directly from the browser if you agree to usage measurement — unlike the first three, this is not something we receive and store: the browser sends it straight to Google. It is the address of the page you are viewing, the address of the page you were on before it, values the browser states about itself such as browser type, language, and screen size, the connecting IP address, and the marker stored in the browser for usage measurement. As for the connecting IP address, Google states that it uses it only to determine location and discards it before the data is logged — that statement and its limits are set out in the clause on access records left automatically below. The page address is sent with any search term you typed removed. Here, though, we separate what we do from what we cannot guarantee: supplying the address with the search term removed is what this service's code does, while making Google's side use that value is a setting outside this service, in Google's console, so the code cannot enforce it. What actually goes out also depends on that setting, so we cannot assert that the list here is exhaustive. If you do not agree, none of these items is sent.
Personal information collected
There is no sign-up and no contact form. You can sign in with a Google account, but that is not registration either; what is received and what is kept are set out in the "Signing in" clause below. You are never asked for a name or contact details. Three things you write yourself are stored as given: comment text, and — once signed in — the nickname and profile picture you choose. We did not collect these; you posted them, and all three appear on public pages. So please consider that they become public before writing or uploading anything that could identify you or someone else. Search terms on the list screen travel only in the address bar's query string and are not stored — the cookie that remembers your filters does not hold them either. If you have agreed to usage measurement, one thing is set out separately — the address of the page you are viewing is also handed to Google, so the search term is stripped from that address before it is handed over. Stripping it and handing over the stripped address is what this service's code does, while the setting that makes the handed-over value the one actually used sits in Google's console, so the code cannot enforce it (the same limit is recorded in the "Categories of personal information processed" clause above and the "Cookies" clause below).
Children under 14
This service is not directed to children. Because the threshold age differs by country, both are stated: under 14 in Korea, under 13 in the United States.
The basis for saying it is not directed to children is recorded here. What this service publishes are records of unsolved social problems in various countries, and there is nothing aimed at children in its subject matter, imagery, characters, tone, or advertising. It uses no child celebrities and hosts no child-oriented activities. These are the factors that actually decide whether a service is directed to children, and we will not change in that direction.
One thing must be said plainly, though: this service does not ask for or verify age. Signing in requests only the Google account identifier, so no date of birth is received. What this clause can therefore claim is not "we do not process children's personal information" but "we are not directed to children, and we do not knowingly process their information." We will not blur that difference.
If we learn that something was posted by a child below the ages above — whether they tell us, a guardian or another user tells us, or it is apparent from the post — we remove it after checking. Nicknames, profile pictures, and comments are within that scope. Even then, we cannot undo what someone who already saw the page, or a search or AI crawler, has taken. A legal guardian may request verification or deletion at the email address in the "Privacy officer and contact" clause below, and may use the same address simply to tell us that a child has been using the service.
Access records left automatically
This service's web server keeps no access log. There is no per-visitor request log, and the visiting IP address and browser type (User-Agent) are recorded nowhere on our side — we verified this by measurement (across the entire log of the container the service runs in, the only value shaped like an IP address is the server's own listening address, printed once at startup). What the container log actually accumulates is startup records and error records, and when an error occurs the line may also carry which address was being handled and when. Those values are used only for fault response and are not combined with other information to identify an individual. The store these records accumulate in rotates under a size cap — at most three 10MB files per container, and when the cap is reached the oldest is deleted first. So the bound on these records is not "how many days" but "how much accumulates before deletion". One thing to state honestly: this method cannot delete on a time basis, so during quiet periods old records remain until the cap is reached. We have put in place no procedure guaranteeing "deletion after N days". And our not keeping it does not mean nobody keeps it. This site is delivered through Cloudflare (see the clause on third-party provision and processing entrustment below), so the party that sees the visitor's real IP address and records it in its own logs is now Cloudflare. That record is not subject to the size cap above, and we do not decide how long it is kept. There is one more party that sees it. If you agree to usage measurement and the measurement code is loaded, the browser sends requests to Google directly, so your connecting IP address reaches Google as well (see the clause on third-party provision and processing consignment below). Google states that it uses that address at collection time to determine location and discards it before the data is logged — which differs from Cloudflare, who keeps it in their own records. But that is Google's own statement, and we have no means of verifying it. So rather than "it is not kept", we write "Google states that it does not keep it". If you do not agree, the request does not happen at all, and this situation does not arise.
Cookies
This service sets ten cookies. (1) NEXT_LOCALE — remembers your language choice. Its value is ko or en, it disappears when the browser closes, and the page's scripts can read it. (2) u1_visit — a marker so the same browser is not counted twice in the visitor total; it is a random value carrying no meaning and expires after a year. (3) u1_filters — remembers the last filters you chose on the list screen (country, document language, cause type, sort) and returns you to that view on your next visit. Its value is those choices, it expires after a year, and it does not hold search terms. (4) u1_actor — the marker used for votes and comments; it carries no meaning, is not issued when you only read pages, and is attached only at the moment you sign in. (5) u1_oauth — exists only for the ten minutes the sign-in exchange runs, then is deleted. (6) u1_auth — marks that this browser is signed in. (7) u1_consent — remembers whether you agreed to advertising cookies. Its value is either agreed or declined, it expires after a year, and the page's scripts can read it too — the page reads it to decide whether to show the consent banner. (8) u1_ads — this service's judgement of whether advertising can be served to this browser at all. Its value is either "not served" or "can be served, plus the advertising publisher number"; it expires after an hour, and the page's scripts can read it too — the page reads it to decide whether to ask for consent and whether to load advertising code. It is a judgement about the request, not about the person. That judgement reads the country code that arrives with the request (derived from your connecting IP address by Cloudflare, which delivers these pages), and where that is absent, the regional subtag of the language setting your browser sends. It judges at country level only; precise location such as GPS is neither used nor stored. (9) u1_analytics — remembers whether you agreed to usage measurement. Its value is either agreed or declined, it expires after a year, and the page's scripts can read it too — the page reads it to decide whether to show the consent banner and how to show which way it currently stands. It is a separate value from your advertising consent — agreeing to one is not agreeing to the other. (10) u1_gtm — this service's judgement of whether usage measurement can be loaded in this browser at all. Its value is either "not loaded" or "can be loaded, plus the number of the measurement tag set"; it expires after an hour, and the page's scripts can read it too — the page reads it to decide whether to ask for consent and whether to load the measurement code. As with (8) it is a judgement about the request, not about the person, and it is judged from the same material set out in (8). All but (1), (7), (8), (9) and (10) are unreadable by scripts (httpOnly). All ten are set by this service itself and are not handed to any other company. They do travel with every request, however, and so pass through Cloudflare, which delivers these pages — the "Third-party provision and processing consignment" clause below sets that out. And what this service sets is not all of it — if you agree to usage measurement, Google's script sets two further cookies on this site. Those two are set out separately in the usage measurement paragraph below.
Advertising is described separately. This service intends to fund its running costs through advertising, and to show advertisements Google, as the advertising provider, needs to store and read cookies or equivalent identifiers in this browser. Those cookies are used to choose which advertisements to show, based on your earlier visits to this site and to other sites on the internet. Cookies are not the only mechanism — once advertising is served, Google and its advertising partners may also collect information using invisible images (web beacons, or tracking pixels) and your connecting IP address. Neither those cookies nor the information collected that way is handled by us: Google sets and receives them, and we do not read their values. If you do not agree, they are not stored — before consent the code that loads advertising is not executed at all, and a content security policy prevents the browser from even making requests to those addresses. Consent is asked at the bottom of the screen on your first visit. How Google uses information for advertising is set out at business.safety.google/privacy, and personalized advertising can be turned off at myadcenter.google.com. (One note: at the time of writing, no advertisement is yet shown on these pages. The consent flow and the blocking mechanism were built first; this parenthesis is removed once advertising begins.)
Usage measurement is described separately too. To count how much each page is read, this service has settled on Google's tag management tool (Google Tag Manager): one tag set is placed there, and Google Analytics is loaded through it. If you agree, that script sets two cookies on this site — one named _ga and one beginning with _ga_ — both with a default lifetime of two years, both markers for counting visits from the same browser together. These two differ in kind from the ten above — the address is this site's, but what sets them is Google's script rather than us, and their values go to Google. We do not read them. The two-year lifetime is Google's default, not a ceiling — browsers cut it shorter (Chrome to 400 days, Safari to 7). The two recorded here are what the Google Analytics tag placed in that tag set writes. The number after _ga_ is a measurement number issued by Google — a different value from the tag set number in (10) — and it lives in Google's console rather than in this service's code. What is loaded at all is decided in that console too — other tags would set other cookies, and if that happens this clause is amended with it. What is placed in that set is Google Analytics and nothing else; no advertising tag and no other company's tag is added. The search term you type is stripped before the address is handed over — what goes up is the address with the search term (q) removed. One thing to state honestly, however: whether that handed-over value is the one actually used is also settled in the console described above, so this service's code alone cannot assert that no search term goes out. What we do extends as far as handing over an address with the search term removed. Cookies are not the only thing that travels — the measurement request also carries your connecting IP address. Google states that it uses that value at collection time only to determine approximate location and discards it before the data is logged; we have no way to verify this, so we record only that Google states it. If you do not agree, those cookies are not stored — before consent the script that loads the measurement is not placed on the page at all, and a content security policy prevents the browser from making requests to those addresses. Advertising and usage measurement are asked separately and remembered separately, so you may agree to one only. Consent is asked together with advertising at the bottom of the screen on your first visit, where the two can be chosen item by item, and it can be changed later at "Where to change your advertising and usage measurement consent" below on this page. This measurement does not replace the cumulative visitor count in the page footer or the view count on each problem — those are still counted by this service itself, and they count crawlers too, regardless of consent or of whether JavaScript runs (see the "Visitor and view counts" clause above). Because they count different things, the two sets of numbers do not match. (One note: at the time of writing, usage measurement is not yet loaded — the tag set's number is not configured on this deployment, so no container is loaded and consent for it is not asked. What this paragraph describes is what happens once that number is configured; this parenthesis is removed once it begins.)
To refuse cookies, block cookie storage in your browser settings or delete the stored cookies (Chrome/Edge: Settings → Privacy and security → Cookies; Safari: Settings → Privacy). Blocking them does not affect reading the problem list, the detail pages, search, or filters. It does mean the same browser may be counted more than once in the visitor total, your filters will not be remembered, and signing in, commenting, and voting will not work. If you block cookies altogether, consent itself cannot be stored, so neither advertising nor usage measurement is loaded. If you want only to stop the filters being remembered, press "Clear all" on the list screen and that cookie is deleted on the spot; if you want only to turn off advertising or usage measurement, you can withdraw them item by item at "Where to change your advertising and usage measurement consent" below on this page.
Two more things. For users in the European Economic Area, the United Kingdom, and Switzerland, this service loads neither advertising nor usage measurement — but the reasons differ. For advertising, serving personalized advertising there requires a consent management platform certified by Google, which this service does not have; loading the advertising code first without one would conflict with the prior consent those regions' rules require. Usage measurement is not covered by that certification requirement — it is nonetheless not loaded, because this service is not yet equipped for the prior-consent regime those regions require and has closed it of its own accord. We record that this is our own choice rather than something imposed on us. So in those regions we ask for consent for neither, and neither is loaded. And if you withdraw consent, that code stops loading from then on, but the cookies already stored remain. For advertising, we cannot delete Google's cookies that are already stored — they are Google's, not ours, and there is no way for us to remove them. For usage measurement, for the two cookies beginning with _ga, this service has put in place no procedure that deletes them when you withdraw consent. To remove either, please delete cookies in your browser settings.
Visitor and view counts
The cumulative visitor count in the page footer and the view count on each problem are counted by this service itself. All that is stored on this service's own server is a number and an update time; no list of who visited is created there. The visitor count is not a count of people but of browsers that arrived without a visit-marker cookie, and the view count is the number of times that problem page was opened. People and crawlers are not distinguished, so both numbers include visits from search and AI crawlers.
A usage measurement layer has been added alongside these two numbers. For browsers whose users have agreed to usage measurement, Google's measurement tool is loaded, and which page was opened and when goes to Google visit by visit — that record is held on Google's side rather than on our server, and it is not rolled up into a single number the way the two counts above are. What is sent and what is not is set out in the "Cookies" clause above and the "Purpose of use and retention" clause below. So this service's own numbers and the number on Google's side do not agree. The count this service keeps itself includes crawlers and does not depend on consent or on JavaScript running, while the number on Google's side covers only those who agreed and whose browsers run JavaScript — so Google's number is structurally the smaller one, and there is no adjustment that makes either match the other. Rather than pick one as the true figure or reconcile the two, we record that they count different things.
Comments and votes
Each problem page has a place to add comments and to cast up/down votes. Writing a comment or casting a vote requires signing in; reading does not. Comment text is stored and displayed as plain text only — links and formatting are not rendered. Comments from users who have not set a nickname show a six-character marker: it is computed from the marker cookie together with that problem's identifier, so it links the same person only within one problem and becomes a different value on another, which means the marker alone cannot follow a person across problems. This does not apply to users who have set a nickname — their name and picture are shown, and the "Nickname and profile picture" clause below records what that means. Who a marker-only user is, we do not know either.
Signing in
You can sign in with a Google account. There is no registration. The only scope requested from Google is the account identifier (sub); name, email, and profile picture are not requested. The identifier received is not stored as-is — it is converted into an irreversible value used solely as a vote and comment marker, so the Google account cannot be recovered from what is stored. The nickname and picture shown on pages do not come from Google; you set them here. Signing in does two things: it carries your comments and votes across devices, and it lets you write comments and vote. Reading requires no sign-in at all. Signing out clears this browser's markers; there is not yet a way to end sessions left on other devices. Comments and votes made anonymously before signing in do not follow you and stay with that browser.
Nickname and profile picture
Signed-in users may set a nickname and upload a profile picture. Both are optional; every feature works without them. Once a nickname is set, that user's comments show the name and picture instead of the six-character marker, and this applies to comments already written. As a result, comments scattered across many problems can be read as one person's, and that link cannot be undone — even after deleting the nickname — in what someone who already saw the page, or a search or AI crawler, has taken. Uploaded pictures are not kept in their original form; they are re-encoded as a 512px square image, and in that step the attached metadata such as capture location and device information is stripped. Nicknames must be unique across this site.
Purpose of use and retention
Purpose and period differ by item. Access records are used only to provide the service and to handle incidents and abuse; their retention rotates under a size cap as stated in the "Access records left automatically" clause above. Visitor and view counts are kept only as cumulative numbers not linked to any individual and are not subject to destruction — the rows hold nothing but a number and a time. Votes remain until the user withdraws them; comments remain until the user deletes them — except that a reported comment stops showing its text, and while it is hidden the author cannot delete it either (something must remain in order to be appealed). A report record holds the target, the reason, the time, the reporter's marker, and the note added, and once judged, the decision and its time are added. A report record outlives its target — if the reported comment is deleted, the fact that it was reported remains. Reports about display information (nickname, picture) hold the same items. Once three different people report them, that nickname and picture become hidden from other users, and even then they are not deleted — the values remain and only the display stops (so they can be restored if no problem is found, and so nobody else can take the name during review). While hidden the owner cannot change them either; if an operator finds a problem, they are deleted at that point. Nicknames and profile pictures are kept until the user changes or deletes them. The records kept per person are these two and the report records — no name, email, or contact details are included in either. The marker attached to them (u1_actor) is not linked to any identity, and all that can be found through that value is the votes it cast and the comments it wrote. Cookie retention is stated per cookie in the "Cookies" clause above. No item this service itself stores is used for advertising, profiling, or automated assessment of individuals — advertising is something Google does with its own cookies, and we neither hand over nor use our comments, nicknames, votes, or counts for it.
Usage measurement is set out separately. If you have agreed to usage measurement, records of what you view go from your browser to Google's measurement tool (Google Analytics). The purpose is one thing: to see which pages are read and how much, by what route people arrive and what they read, and to decide from that what to fix. It is not used to identify individuals or to assess users one by one, nor is it used to choose advertisements — the settings that would put it to advertising use (Google signals, a link to a Google advertising account, advertising features) are not turned on, and were they ever turned on this clause would be amended along with them. The three named here are the ones we know of — that this service has no means of confirming whether other settings do the same thing is recorded in the "Third-party provision and processing consignment" clause below. What is sent concerns the visit — the page viewed and the time, the device and browser type — and the comments, nicknames, votes, and counts this service stores are not sent to that tool. The page address that is sent has the search term removed, although the setting that makes the removed value the one actually used sits on Google's side, so this service's code cannot enforce it end to end. The retention period is a value chosen in Google's settings screen and the default is two months — this service does not extend that default. That screen sits outside this service's code, however, so this page cannot itself prove what it is currently set to. Were it to be extended, this clause would be amended along with it and, as recorded in the "Third-party provision and processing consignment" clause below, you would be told again and asked for your consent again. How the records are handled once sent is governed by Google's policy, and the transfer itself is set out in the "Third-party provision and processing consignment" clause below. If you do not agree, the measurement does not happen at all.
Destruction procedure and method
When personal information has served its purpose or a user asks for deletion, it is destroyed without delay. No item is retained under any other statute. Destruction happens as the user's action is applied directly to the database; no paper records exist. Because what actually happens differs by item, it is stated as it is. Taking down a comment does one of two things, depending on whether it has replies. With no replies the row is deleted outright, together with the votes and reports attached to it — nothing is left on the page. With replies the place is kept (so those replies do not lose their parent); in that case not only the text but the link to its author is severed, so it can no longer be told who wrote it, and the comment also disappears from My activity. Any report filed against it keeps only who, why and when — the reporter's own note is erased. When a vote is withdrawn, that row is genuinely deleted. When a nickname is deleted, the value is removed and comments show the six-character marker again. Profile pictures have one exception: pressing "Remove picture" severs the link between you and the image immediately, but the image bytes already produced remain in storage. The picture's address is already baked into the HTML of problem detail pages, so deleting the bytes at once would leave those pages showing a broken image. These residual bytes are now collected — an image that nothing has pointed to for seven days is deleted. Seven days are allowed because a problem detail page may hold its old HTML for days; deleting sooner would leave those pages showing a broken image. Until then, the only way to reach such an image is to already know the long address computed from its contents. When an operator takes down display information, the link to the nickname and picture is deleted and that user returns to the six-character marker; the picture bytes are collected in the same way. Report records are never deleted — a record that the procedure was followed must remain for an appeal to be possible. There is one more copy, made at deploy time. Each time this service is put up as a new build, the entire database as it stood a moment earlier is written to a single file kept on the operator's machine, so that a failed deploy can be undone. That file contains the comments, nicknames and photos as they were at that moment; only the 20 most recent are kept, and older ones are removed as new copies are made. What a user deletes does not vanish from these copies at once — it is absent from copies made after the deletion, but remains in copies made before it, until those fall outside the 20 and are removed with them. There is also one copy taken once a day. When the job that automatically authors problem definitions runs each day, the entire database is written the same way, whether or not that day is one on which authoring actually happens. For this one a single file is kept and replaced on every run — so what a user deletes is gone from this copy at the next run. Unlike the deploy copies, these do not accumulate. These files are not published, do not leave the operator's machine, and are served nowhere — not from any page and not from any API. However, there is no means to remove one person's records from a particular copy; we record the absence of that means as it is. Records sent to Google by the usage measurement are beyond the reach of this destruction procedure — they sit on Google's side rather than in our storage, and this service has put in place no means of recalling and deleting what has already been sent. Those records are deleted on Google's side once the period set in Google's console elapses (the default of two months for event-level records; see the "Purpose of use and retention" clause above), and we neither perform nor verify that deletion. Nor have we put in place any means of deleting one person's measurement records selectively — if you ask for deletion there is no way for us to carry it out for what has already been sent, and what can be done is to withdraw usage measurement consent so that nothing further goes out. The two cookies beginning with _ga left in your browser are not deleted by this service either, so please delete them in your browser settings. The "destroyed without delay" in the first sentence of this clause therefore concerns the items this service stores itself.
Security measures
What this service actually does is recorded here. The Google account identifier received at sign-in is combined with a secret held only on the server and converted into an irreversible form before storage, so the original identifier cannot be recovered from what is stored. The cookies used for sign-in, votes, and comments are set so page scripts cannot read them (httpOnly). A content security policy restricts which addresses the browser may contact, and that policy depends on your advertising and usage measurement consent — while you have agreed to neither, nothing but this service's own origin is permitted, so no external script, external font, or external analytics tool is loaded at all. After you agree to advertising the addresses advertising needs are opened, and after you agree to usage measurement the addresses the measurement needs are opened. For the addresses that load scripts and the addresses that data is sent to, only those of the item you agreed to are opened, and agreeing to one leaves the other's scripts blocked. Images are the one exception: advertising creatives are uploaded by each advertiser and their addresses cannot be pinned down, so agreeing to advertising opens every address beginning with https for images alone — and the measurement side's image addresses fall within that. Agreeing to usage measurement only does not widen it that way; just the two addresses it needs are added. External fonts are opened by neither. The point of this measure is that it is enforced by the browser rather than by a document. Profile pictures are re-encoded rather than kept as uploaded, removing attached metadata such as capture location and device information. The database is not exposed externally and is reachable only from the same private network as the service. No port on this machine is open to inbound connections — pages are delivered only over a connection this machine makes outward to Cloudflare, and the only place that connection may reach is this service's web process. Traffic between you and Cloudflare is encrypted with HTTPS. The encryption ends at Cloudflare rather than at our server, however, and the last leg from there to our server is plaintext inside the private network — so it cannot be said that traffic is encrypted end to end such that only we can read it. What is exposed on that path is set out in the "Third-party provision and processing consignment" clause below. What is not done is also recorded: with a single operator there are no separate staff holding partitioned access, and there is no periodic access-log review, no storage encryption, and no regular vulnerability review procedure. Rather than write these as though they existed, we record that they do not.
Third-party provision and processing consignment
The personal information this service stores is not handed to third parties for their own purposes. Two processors are engaged, however, and both engagements also involve a transfer abroad — one is the very path by which these pages are delivered over the internet, the other is the usage measurement that counts how much each page is read. The second happens only if you agree. What actually happens is set out separately below. Exactly one decision about a user is made by an automated system: when three different people report the same comment or the same profile information, it is hidden automatically (see "About the problem records published here" above). No other decision is made automatically, and anything hidden is judged again by the operator as a person.
The processor. The processor is Cloudflare, Inc., and the work consigned to it is the delivery of these pages and the termination of the encrypted connection (HTTPS). Your browser never reaches the machine this service runs on directly; it reaches Cloudflare's servers first. Because the encryption is unwrapped at Cloudflare rather than at our server, Cloudflare is in a position to see not only the originating IP address, browser type, request time, and requested address but the contents of the requests and responses themselves — including the comments you write, the nickname you choose and the picture you upload, the note you add to a report, and the values exchanged during sign-in. We have no basis for writing "they do not look", so we write "they are in a position to see".
Transfer abroad. Because that engagement also moves personal information out of the country, the items Korea's Personal Information Protection Act (Article 28-8) requires to be disclosed are recorded here as they are. The basis for this transfer is Article 28-8(1)3 of the same Act — it is a consignment of processing and storage necessary to deliver to you the pages you requested, disclosed in this policy in the manner that provision prescribes. (1) Items transferred — the originating IP address, browser type (User-Agent), request time, requested address, and the contents of the requests and responses in transit. (2) Country, timing, and method — the United States and the other countries where Cloudflare keeps servers; the data passes over the network each time you open a page. There is no separate procedure that gathers it and sends it as a file. (3) Recipient and contact — Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA), data protection officer dpo@cloudflare.com. (4) The recipient's purpose and retention period — the purpose is limited to the delivery and connection termination described above. The retention period is not ours to set: Cloudflare's own policy governs it, and that policy does not state in days how long visit records are kept. So the size cap recorded in the "Access records left automatically" clause above binds our records only, not Cloudflare's. (5) How to refuse the transfer, the procedure, and the effect — there is no place to refuse. The transfer happens on the very path that delivers these pages, so there is no way to use this service while leaving that path out. That means there is no option other than not visiting, and rather than write as though one existed, we record that there is none.
Usage measurement is a processing consignment too. The processor is Google, and the work consigned to it is counting how much each page is read — it is loaded as a Google Tag Manager container, and Google Analytics does the counting inside it. If usage measurement is loaded after you agree, those values do not pass through our server: the browser sends them to Google directly — the same mechanism as advertising. The character differs, though: advertising is something Google receives for its own purposes, whereas usage measurement is Google counting on our behalf something we want to know, which makes it a processing consignment. That is why it is set out apart from advertising, on the consignment side of this clause. The document for this consignment is the data processing terms accepted in Google's console — Article 26(1) of the Personal Information Protection Act requires a consignment to rest on a document, and if the same material went out without those terms accepted it would be a third-party provision rather than a consignment, which would require a different procedure. This service has therefore settled on accepting them before the measurement is turned on; that console likewise sits outside this service's code, so this page cannot itself prove that it currently stands that way. The settings that would also let Google use this material for its own advertising purposes (Google signals, Google Ads linking, advertising features) are not turned on. Those settings live in Google's console rather than in this service's code, however, so the code cannot enforce them — meaning this page cannot itself prove that they are off. Nor can we assert that this page has counted every such setting in that console — the three named here are the ones we know of, and this service has no means of confirming whether others do the same thing. We record that limit alongside the statement.
Transfer abroad for usage measurement. This engagement also moves personal information out of the country, so the same items are recorded. The basis for this transfer is Article 28-8(1)1 of the Personal Information Protection Act — the data subject's separate consent. So if you do not agree to usage measurement the transfer does not happen, and if you withdraw consent it does not happen from then on. Because the five items below must be told to you before that consent is asked, they are recorded here in advance, and if any of the five changes we do not simply amend this clause: we tell you again and ask for your consent again (Article 28-8(3)). (1) Items transferred — the address of the page you are viewing (with any search term you typed removed), the address of the page you were on before it, values the browser states about itself such as browser type, language, and screen size, the connecting IP address, and the marker stored in the browser for usage measurement. The connecting IP address does not fall under the retention period in (4) below — Google states that it uses it only to determine location and discards it before the data is logged, and that statement and its limits are set out in the "Access records left automatically" clause above. What we do and what we cannot guarantee about removing search terms is set out in the "Categories of personal information processed" clause above. (2) Country, timing, and method — the United States and the other countries where Google keeps servers; that set is not ours to choose but is determined by the data centre locations Google publishes on its own pages. Once you have agreed, the browser sends it directly each time you open a page. There is no procedure on our side that gathers it and sends it as a file. (3) Recipient and contact — Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), the legal entity named as the contracting party in the Google Analytics Terms of Service this service accepts in order to use usage measurement. The channel for privacy enquiries is the one Google publishes in its own privacy policy (policies.google.com/privacy), and this service has been given no dedicated contact of its own. (4) The recipient's purpose and retention period — the purpose is limited to the counting described above. Here the retention period for event-level records is ours to set, unlike Cloudflare's: it is a value chosen in Google's console, the default is two months, and this service does not extend that default. That console sits outside this service's code, however, so this page cannot itself prove what it is currently set to; it can be checked only in that console. If it is ever increased, we do not simply amend this clause: we tell you again and ask for your consent again. And that setting does not reach everything — how long the aggregated report figures that remain after individual records are deleted are kept is neither ours to set nor known to us, so no period for them is recorded here. (5) How to refuse the transfer, the procedure, and the effect — there is a place to refuse. If you do not agree in the first place, nothing is sent at all; and after agreeing you may withdraw usage measurement consent at "Where to change your advertising and usage measurement consent" below, after which the measurement code is not loaded and the transfer does not happen. Refusing does not affect reading the problem list, the detail pages, search, filters, or comments. But we have put in place no procedure to recall and delete what has already been sent.
Advertising is different in kind, so it is set out separately. If advertising is shown after you agree, Google as the advertising provider receives connection information (IP address, browser type, the address of the page you are viewing) directly from your browser. This is not something we receive and pass on; the browser sends it to Google directly, and the value neither passes through our server nor remains in our storage. That processing is governed by Google's policy. If you do not agree, the request does not happen at all. Pressing sign-in, which takes you to Google's sign-in screen, is the same in kind: this service sends Google no user information, and what it receives in return is one account identifier.
Notice for California users
For users in California, the items that state's law requires are set out separately here. The categories of personal information this service collects are three of those enumerated by the California Consumer Privacy Act: "identifiers" (the marker computed from the sign-in account identifier, and the originating IP address), "internet or other electronic network activity information" (the addresses requested, and the filters chosen on the list screen), and "geolocation data". The latter two have items added to them only if you have agreed to usage measurement — the pages viewed and the device and browser type to the first, and a city-level location derived from the originating IP address to the second. Precise location such as GPS is neither used nor stored. As to the originating IP address the location is derived from, Google states that it uses that address at collection time to determine location and does not keep it in its records — that is not something we can verify, so we record it as what Google states. Comments, nicknames, and pictures you post yourself are posted by you for publication. The source is you and your browser, and the purposes are set out in the "Purpose of use and retention" clause above.
This service does not sell personal information. However, if you have agreed to advertising, Google as the advertising provider receives information directly from your browser, and that may amount to "sharing" as California law uses the term (disclosure for cross-context behavioural advertising). If you do not agree, no such disclosure occurs — this service does not execute advertising code before consent, and a content security policy prevents the browser from making requests to those addresses. So what amounts to opting out of sale and sharing on this service is declining advertising consent, or withdrawing it later. Usage measurement is a separate axis and so is set out separately — what goes to Google there is a record of what was viewed, and the settings that would put it to cross-context behavioural advertising use (Google signals, a link to a Google advertising account, advertising features) are not turned on, so it does not amount to the "sharing" described above. That assessment rests, however, on those three being off — the three named here are the ones we know of, and that this service has no means of confirming whether other settings do the same thing is recorded in the "Third-party provision and processing consignment" clause above. Were those settings turned on, that assessment would change, and this clause would be amended along with them. If you do not want usage measurement either, you can decline it separately from advertising in the "Where to change your advertising and usage measurement consent" clause below. Browser opt-out preference signals such as Do Not Track or Global Privacy Control are not separately read as yet — what those signals address is sale and sharing, and the only thing that falls there on this service is advertising, which does not happen at all unless you agree, so consent itself occupies that place here. Usage measurement, however, is not what those signals address and would not be turned off by them, so it has to be declined separately in that clause, and the fact that the signals are not read is stated rather than hidden.
The California Consumer Privacy Act grants rights to know, delete, correct, and not be discriminated against. This service does not meet that law's business-size thresholds and so bears no obligation under it, but the equivalent actions are available on the pages themselves: you can delete your own comments where they stand, change or remove your nickname and picture at any time on the account page, and clear remembered filters with "Clear all" on the list. Other access or correction requests are received at the email address in the "Privacy officer and contact" clause below. If this policy changes, the change is posted on this page, and the date it was last revised is the recorded-on date in the heading above.
About the problem records published here
The problem records this service publishes are derived from public reporting and public data, and the sentences are ours. As a rule they carry no information identifying a specific individual, and if we judge that identifying content has been published we take it down after checking. Comments are written by users and are not our views. Nobody reads a comment before it appears. However, once three different users report the same comment it is hidden automatically and its text stops being shown. A report can be withdrawn by the person who filed it until a decision is made, and a withdrawn report no longer counts. If we find a comment that identifies an individual or infringes rights, we take it down after checking. Nicknames and profile pictures work the same way — once three different people report them they are hidden automatically from other users, and an operator then restores them if there is no problem or deletes them if there is. Either way the person is notified of the outcome. This service's robots.txt permits collection by search engines and AI crawlers, except for pages that gather one person's activity in one place, such as the account, My activity, and Notifications pages — comments, nicknames, and pictures shown on pages are within that scope, and this is why the clauses above say that what has already been taken cannot be undone.
Your rights
You may request access to, correction of, deletion of, or suspension of processing of your personal information. Three of these can be done directly on the pages: your own comments can be deleted with "Delete my comment" while you hold the same marker (not while the comment is hidden by reports); your nickname and profile picture can be changed or removed on the account page; and remembered filters are cleared with "Clear all" on the list screen. There is one more — advertising and usage measurement consent can be withdrawn item by item at "Where to change your advertising and usage measurement consent" below, and once withdrawn that processing does not happen again. What is actually erased and what remains is set out in the "Destruction procedure and method" clause above. Even after deletion, we cannot undo what someone who already saw the page — or a search or AI crawler — has taken. Note that deleting the marker cookie severs the link to your existing comments, after which you can no longer delete them directly — though for comments written while signed in, that link returns when you sign in again with the same Google account. For requests that cannot be made on the pages (access, correction, and suspension of processing beyond what is described above), write to the email address in the "Privacy officer and contact" clause below. For the records that have gone to Google through usage measurement, however, only one of these can be carried out — what corresponds to suspension of processing is withdrawing usage measurement consent, and that place is below on this page. Because this service has no means of picking out a particular user within those records, we record in advance that requests for access, correction, or deletion cannot be carried out even if we receive them. A legal guardian may make the same requests through the same route.
Remedies for infringement
If you need help with a personal information infringement, you may seek counselling and dispute mediation from the following bodies in Korea. Personal Information Dispute Mediation Committee — 1833-6972 (www.kopico.go.kr). Privacy Infringement Report Centre — 118 (privacy.kisa.or.kr). Supreme Prosecutors' Office Cybercrime Investigation Division — 1301 (www.spo.go.kr). National Police Agency Cyber Bureau — 182 (ecrm.police.go.kr). If your rights or interests are infringed by a disposition or omission by this service in response to a request under Articles 35 (access), 36 (correction and deletion), or 37 (suspension of processing) of the Personal Information Protection Act, you may file an administrative appeal as provided by the Administrative Appeals Act (Central Administrative Appeals Commission, 110, www.simpan.go.kr).
Privacy officer and contact
The function handling privacy matters and related complaints is "Privacy Desk", reachable by email at ponderloft@gmail.com. Send requests to access, correct, delete, or suspend processing — and any other enquiry — to that address. A legal guardian may make the same requests there. Requests are handled after verification, and the outcome is sent back to the same address.
The operator’s representative name, address, telephone number, and business name are stated in the “Designated agent under US copyright law” clause of the Terms of Service. This is because 17 U.S.C. §512(c)(2) requires that publication as a condition of the safe harbour, not because Korean law requires it. What the Personal Information Protection Act requires in a privacy policy is the name of the privacy officer or the name of the department and contact details, which is filled in above.
The business registration number is not stated. This service sells no goods or services to visitors, so it is not subject to the disclosure required by Korea’s Act on Consumer Protection in Electronic Commerce. If this service begins taking payment from visitors (paid subscriptions, paid features, donations with something in return), Article 10 of that Act requires the business name, representative’s name, business address, telephone number, email address, and business registration number all at once. This field would be filled then. There is no such plan at present. You can reach us at the email address above at any time.
Where to change your advertising and usage measurement consent
You can change them below at any time, separately for each item. For an item you do not agree to, the code that loads it is not executed and a content security policy prevents the browser from making requests to those addresses. Changing them reloads this page — that policy arrives with the response, so the page has to be fetched again for it to change.
Changes to this policy
If this policy changes, the change is posted on this page. The date it was last revised is the recorded-on date in the heading above. There is currently no place that shows the before and after side by side — the revision history lives only in the repository's change log, and the page carries only the latest version.