Effective 2026.09.30 · Operator MOYO Studio · Contact [email protected]

MOYO Studio (Onbit) processes personal information lawfully and keeps it safe, in accordance with Korea's Personal Information Protection Act and related laws. Under Article 30 of that Act, we establish and publish this policy so that you know the procedures and standards by which your personal information is handled, and so that any related complaint can be resolved quickly.

[In one paragraph] Onbit's Globe, Passport, stamps and calendar work from start to finish without an account. Photos are read on your device for their capture location and time only; originals never leave it. You link an account only when you save a record in the Trips tab, and the trip records you write or choose are then kept on our server. The only photo uploaded is still one cover photo per city, and coordinates are never uploaded under any circumstance. Connect a friend and that one friend sees your name and city records; whether they also see your cover photos is yours to decide. Your trip records are not shown to friends. There are no ads, we do not track you outside the app, and we never sell personal information.

[Summary · key processing at a glance] The essentials before the full text. This is a summary; the full text below governs. · Permissions requested: photos, location and notifications only, each asked the moment you tap that feature (Article 2-2) · What we process: an anonymous identifier; if you link an account, your email, name, city records with the days you were there, and one cover photo per city; if you save trip records, the trip records you write or choose; if you turn on notifications, a device token · Location: coordinates are never sent to our server. However, the result of turning a photo's capture location into a city on your device (which city you were in and when), and the place names you write or choose in your trip records (where you stayed, where you ate and so on), are kept on our server once you link an account · Sensitive data, national identifiers, biometrics: not processed · What other people can see: only a friend connected by code sees your name, city records, (if enabled) cover photos, and the city and month of any calendar "Together" trip you both confirmed (Article 4-2) · Collected automatically: crash diagnostics and anonymous analytics — analytics can be turned off in Me > Data · Third-party disclosure: none / Processor: Google LLC (Firebase) / Overseas transfer: United States (diagnostics and analytics) · Retention: destroyed immediately on account deletion (diagnostics 90 days, analytics 14 months) · Complaints: MOYO Studio Privacy Officer · [email protected]

Article 1 (Scope and where to find this) This policy applies to the app "Onbit" provided by MOYO Studio ("the Company"). The same text is available at any time in the app under Me > About > Privacy Policy, and on the web. Business information · Trade name: MOYO (모두의 요리) · Representative: Kyunghwan Im · Business registration number: 836-13-02732 · Address: 18-16 Mabang-ro 10-gil, 4F E223 (Yangjae-dong, Jinwoo Bldg.), Seocho-gu, Seoul, 06776, Korea

Article 2 (What we process and how we collect it)

  1. Generated automatically when you use Onbit without an account · Anonymous authentication identifier (UID), app installation identifier · Usage records: city keys, country codes, day-count buckets and similar aggregate events · Crash diagnostics: where in the code the error occurred (stack trace), device model, OS and app version, IP address
  2. When you link an account (optional) · The email address provided by Apple or Google, and the name they supply · The passport name you choose The first time you save a record in the Trips tab, we ask you to link an account. If you do not, that record is not saved; the Globe, Passport, stamps and calendar keep working without an account.
  3. Kept automatically once an account is linked (optional) · City records (city name, country code, day count, first day lit, photo count) · The list of days you were in each city, and how many photos you took on each of those days — used so the server can send the "N years ago today" notification. Readable only by you; never shown to friends. · Light shards, places saved for this year and when you saved them, year stamps and arrival marks, quest progress, interest in printed items · One cover photo per city, and the line you wrote on that photo · On-device identifiers pointing to the photos you chose for covers and stamp backs (not the photos themselves) 3-2. When you save trip records (optional; requires a linked account) · The trip records you write or choose: legs (mode of transport; flight number, aircraft type, registration, seat, cabin, terminal, gate; scheduled and actual times; lounge, meal, miles and similar), places (name, category, rating; menu, price, wait, room, nightly rate and similar), spending (amount, currency, category), city notes, and your trip rating and one-line summary · Travel companions: their names, if you write them. Only you can see these names, and they are left out of "One image" share cards by default. · On-device identifiers pointing to the photos attached to a record (the photos themselves are not uploaded)
  4. When you connect a friend (optional) · An invite code (8 characters, single use) and the identifier of the person who created it · The link record (the identifiers of the two connected people) · The passport summary shown to your friend (name, countries lit, city keys with month and day count, whether cover photos are shared) · Calendar "Together" requests (sent from "Who were you with on this trip?"): the identifiers of the sender and the recipient, the city, the month, whether it was accepted, and when it was created
  5. When you turn on notifications (optional) · Push notification token (per device), the time you chose, device time zone and language
  6. When you fill in "About me" (optional) · Birth decade, gender
  7. Processed on your device only and never collected · The capture coordinates in your photos (EXIF) and the photo originals · The coordinates used to check that you have arrived somewhere (discarded the moment the check is made; never stored or transmitted) · Trip auto-fill calculations: the nearest airport, suggested modes of transport, candidates for where you stayed and ate, and the distance traced by your photos are computed from the airport list built into the app and the photo locations on your device. Only what you confirm with "Yes" becomes a record; a suggestion you pass over with "No" is remembered on your device only, at a resolution of about 300 m, so it is not suggested again. · Calendar photos, lock screen images and "One image" share cards: made on your device, and leave it only when you share them or save them to your photo library yourself. The recipient is then the app you chose. About location: coordinates themselves are never sent to our server under any circumstance. However, two things are kept on our server once you link an account. One is the result of turning a photo's capture location into a city on your device — that is, which city you were in and when — which is city-level information (an area of several kilometres or more). The other is the place names you write in your trip records or choose from suggestions (for example, where you stayed or ate), together with the dates of that trip. A place name is text you confirmed, not coordinates, and it is kept only so your records can follow you to a new phone. How we collect: generated automatically as you use the app, entered or chosen by you, and received through Apple or Google sign-in. What we process is the minimum needed for the purposes above. Coordinates and photo originals are not needed for those purposes, so we do not collect them.

Article 2-2 (App permissions — photos, location, notifications) Onbit asks your device for three permissions and no others. None is requested at launch; each is requested the moment you tap the button for that feature. Declining does not stop the app.

  1. Photos · Asked when: you tap "Open photos" on the first screen (onboarding), and likewise later under Me > Rescan. · What is read: the capture location (EXIF) and capture time recorded in your photos. Originals are processed on your device only. Trip auto-fill in the Trips tab needs no new permission and works only within the photos you have already allowed. · What leaves the device: not the originals. If you link an account, only the one cover photo you chose per city is kept on our server (Article 2.3), and capture locations are kept only in the form of a city. · Saving to your photo library: when you save a share image or a lock screen image to your photo library, your device may ask for permission to add photos. · If you decline: you can continue with "Start without photos" and light cities by hand. Limited access works too, using the photos you allowed.
  2. Location · Asked when: you tap "I'm here now" in onboarding, or "Get a stamp here" on a city screen. Requested only while the app is open (WhenInUse); background location is never requested. · What is read: your current coordinates, once. · What leaves the device: nothing. Coordinates are used only to decide the nearby city or landmark and are discarded immediately. What remains is a landmark id and a date. · If you decline: only arrival stamps are unavailable; everything else works.
  3. Notifications · Asked when: you pick a notification time on the last onboarding screen and tap "Start". If you pick no time, you are not asked. The same applies when you later turn a notification switch on under Me. · What is read: your device's push notification token. · What leaves the device: the token and your chosen time are sent to the server (Article 5) so notifications can be delivered. · If you decline: only notifications stop; nothing is blocked. You can turn them off at any time under Me. We request no other permissions. We do not request health or step data, camera, microphone, contacts, calendar, or iOS App Tracking Transparency (ATT). On Android there are also normal permissions that are granted at installation and never asked: internet access, vibration, re-scheduling notification times after the device restarts, and setting the lock screen wallpaper. The lock screen wallpaper is changed only when you tap "Set as lock screen".

Article 3 (Purposes of processing) · Providing the service: keeping, restoring and carrying your records across devices, restoring cover photos · Keeping trip records: storing the trip records you save and carrying them across devices · Identifying your account: verifying you through Apple or Google · Providing the friend feature: showing passports between people connected by an invite code, computing places you both reached, and showing a trip you both confirmed as "Together" on both of your calendars · Sending notifications you turned on: "N years ago today", new stamp news, a friend's new record · Crash diagnostics: finding and fixing the causes of crashes and errors · Analytics: aggregate analysis of which cities are lit and saved, and improving the service · Answering enquiries received by email If the purpose changes, we will obtain your consent in advance.

Article 4 (Disclosure to third parties) The Company does not provide your personal information to third parties, except where required by law or where an investigative authority requests it through the procedures and methods prescribed by law.

Article 4-2 (What other users can see — friends) Onbit has no public feed, no user search and no recommendations. The following is visible only between two people who exchanged a single-use invite code directly.