Privacy Policy
Privacy policy for the SYU CAMPUS service.
Effective Date
This English version is provided for convenience. If it differs from the Korean Privacy Policy, the Korean version applies. Effective March 23, 2026. Last updated October 4, 2026.
Contents
1. Purposes of Processing
Sanghyeok Seo, the individual operator using the service name SYU KR, processes personal information for SYU CAMPUS only as needed to operate and improve the service.
- Providing and operating service features
- Analyzing service usage and improving quality
- Reviewing contact requests, reports, and suggestions
- Creating schedule coordination links and collecting responses
- Creating timetable share links selected by users
- Sending service push notifications when users opt in
- Verifying school-email ownership, operating roommate recruitment, and reviewing roommate reports
- Supporting internal admin triage with AI-assisted classification when configured
For the roommate board, email verification, sessions, author identification, and processing a requested listing or report are necessary to provide the requested service under Article 15(1)(4) of the Personal Information Protection Act. Sharing a listing with other users requires the writer's consent under Article 17(1)(1). Optional living habits and introductions may be omitted.
2. Retention
- Local settings remain on the user's device and are deleted when browser data is cleared.
- Contact requests and campus-tip suggestions are retained until the review or service-improvement purpose is fulfilled.
- Schedule coordination rooms, participant responses, and timetable share links are retained for up to 90 days.
- Notification tokens are retained until the user disables notifications, the token becomes invalid, or delivery is no longer needed.
- Notification delivery records are retained for up to 90 days.
- Rate-limit counters are retained for the configured request window, and notification send locks may be retained for up to 14 days to prevent duplicate sends.
- Admin action audit records are retained for up to 365 days.
Dorm roommate board retention
- Email and Firebase authentication user record
- Used for email verification and identifying the same author on return visits. Signing out or deleting a listing does not delete this record. The current service has no automatic inactivity deletion for Firebase Authentication. To end authentication use and request deletion, contact the privacy contact in Article 9.
- Browser session and server session record
- Valid for a fixed 30 days from authentication, or 12 hours if Keep me signed in is unchecked. Signing out revokes that session. Expired server session records are deleted by the scheduled cleanup.
- Pending email in the browser
- Used for up to 24 hours to complete a sign-in link. Removed on completion or when leaving through the Campus link. An expired value is removed when the service next reads it; it may remain on a closed browser until then. You can remove it immediately by clearing site data.
- Recruitment listing, contact link, and sharing-consent record
- No longer shown to other users when completed, deleted, expired, or hidden. The deletion deadline is 30 days after the earlier of the first completion/deletion and the recruitment deadline. The latest consent time and notice version are deleted with the listing. Editing or hiding does not extend retention.
- Report, evidence snapshot, and administrator review notes
- Retained for 30 days after submission, whether resolved or not. The snapshot may include the reported nickname, introduction, dorm/room capacity, and contact link, and is accessible only to administrators.
- Author activity and writing hold
- Eligible for deletion 90 days after the last author or administrator action, if there is no active recruiting listing or current writing hold. A hold normally lasts 30 days and administrators may release or extend it with a reason.
- Administrator and cleanup audit records
- Retained for up to 365 days for abuse handling and accountability. Includes the administrator identifier, action, target identifier, status, and time. Does not copy report text or Open Chat links.
Server expiry and physical deletion are separate: access is restricted at expiry and the scheduled daily cleanup deletes expired records. These are service retention periods, not statutory retention requirements. An earlier deletion or processing-suspension request may be made through the privacy contact; where retention is legally necessary, the reason and period will be explained.
Firebase Authentication logs IP addresses for a few weeks. Other authentication data remains until the operator initiates user deletion; Google states deletion from live and backup systems may take up to 180 days after that request. Firebase retention information
Third-party data such as Kakao Maps cookies and Google service data follows each provider's policies.
3. Categories of Information
- Local settings, drafts, participant edit tokens, and owner deletion tokens
- Service logs, access records, IP address, and user agent
- Kakao Maps SDK cookies used for map and shuttle features
- Contact, report, campus-tip, and optional contact details entered by users
- Schedule room titles, descriptions, candidate times, participant nicknames, and availability responses
- Schedule response edit-token hashes and room owner-token hashes used to protect edits and deletion
- Timetable share course IDs, year, semester, and owner-token hash
- Firebase Cloud Messaging tokens and notification delivery records when notifications are enabled
- Rate-limit counters and notification duplicate-send locks
- Admin-only AI classification metadata for contact requests or suggestions, when generated
Dorm roommate board information
- Authentication and access (required for the board)
- School email, authentication user identifier, verification time, session expiry, and protected identifiers for confirming session/author ownership. Firebase also processes IP addresses and browser information for authentication security. Mailbox and SU-WINGs passwords are not collected.
- Recruitment listing (required when posting)
- Nickname, dorm and room capacity, stay dates, recruitment deadline, number of roommates needed, and Kakao Open Chat link. Used to display recruitment information and enable contact. The latest sharing-consent time and notice version are stored as evidence of the writer's choice.
- Living habits and introduction (optional)
- Selected bedtime/wake-up time, cleaning, indoor calls, sleep habits, smoking, temperature preferences, sharing preferences, and introduction. You can leave all of these blank and still post.
- Reports and operation (when used)
- Report reason, optional explanation, a snapshot of the reported listing, a protected reporter identifier, review notes/status, writing-hold reason/period, and administrator action records. Used for review, abuse prevention, and handling objections. Request counters use protected author or IP-derived identifiers.
Do not enter real names, phone numbers, exact room numbers, national identifiers, diagnoses, disability details, religious beliefs, political views, or another person's personal information. Optional entries are shown to verified users if included in a published listing. Leave them blank to keep them private.
4. Sharing, Processors, and Overseas Processing
Sharing recruitment listings
- Recipients: roommate board users verified with an @syuin.ac.kr email address. The purpose is to review roommate candidates and contact a writer.
- Shared information: nickname, dorm/room capacity, stay dates, recruitment deadline/number needed, Open Chat link, and any selected living habits or introduction. Email addresses, authentication credentials, and internal author identifiers are not shown.
- Availability: only while recruiting. The board stops displaying the listing and providing its contact link when completed, deleted, expired, or hidden. Recipients must stop using and delete the information when their roommate-contact purpose is fulfilled or recruitment ends, whichever comes first. Do not copy, repost, sell, or use it for advertising or harassment.
- You may decline sharing and continue using verification and browsing. A listing cannot be published or edited without sharing consent. To withdraw, delete the listing from My listing or contact the operator. The site cannot retrieve copies another user has already made outside the service.
Reports and evidence are available only to authorized administrators. Kakao Open Chat is an external service opened at the user's choice; SYU CAMPUS does not read or store the conversation. This link is distinct from processing entrusted to the hosting or authentication provider.
Processing entrusted to service providers
| Provider | Purpose | Retention |
|---|---|---|
| Kakao | Campus map and location-based map SDK features | According to Kakao policies |
| Email-link authentication, Firestore data storage, analytics, Search Console, and push notifications | For roommate authentication and stored data, the periods described in Articles 2 and 4; other Google services follow their respective policies | |
| Vercel | Hosting and deployment | Until the processing purpose is fulfilled or the service relationship ends |
| Sentry | Error monitoring with request bodies, cookies, headers, user identity, and URL queries removed before transmission | According to the configured Sentry retention settings |
The processors above handle data to operate the service on the operator's behalf. This is separate from sharing a writer's listing with other users. Other provision requires a legal basis, such as the individual's consent or a specific legal duty.
Overseas processing for the roommate board
The authentication and server services below are entrusted processing needed to provide the service requested by the user. Transfer details are disclosed under Article 28-8(1)(3) of the Personal Information Protection Act; this disclosure is not a claim that separate overseas-transfer consent was obtained.
Google LLC (United States Firebase processing)
- Country, information, timing, and method
- United States. School email, authentication identifier and verification/sign-in information, IP address, and browser information. Sent over encrypted connections when requesting or completing an email link and checking authentication.
- Purpose and retention
- Email delivery, mailbox verification, and authentication security. Authentication records and Google's deletion processing follow Article 2; signing out does not delete the authentication user.
Vercel Inc. (privacy@vercel.com)
- Country, information, timing, and method
- United States (the configured server-function region is iad1). The email and authentication/session data needed by a request, submitted listing/report information, IP address, and browser information are processed over encrypted connections when using the server features.
- Purpose and retention
- Website hosting, request handling, and security. Request contents are processed to complete the request; the application does not write roommate email, authentication credentials, listing contents, or contact links to runtime logs. Hobby runtime logs have a one-hour viewable retention window. Provider-generated security/service records follow Vercel's processing terms and are deleted or anonymized when their purpose ends.
The Firestore database storing roommate records is configured in Seoul, South Korea (asia-northeast3). Domestic database storage does not prevent overseas processing: the United States server functions read and process that data. Firebase Authentication separately uses United States data centers.
Google's published contracting-entity terms list Google Cloud Korea LLC for a South Korean billing address and define Google under that reseller arrangement as Google Asia Pacific Pte. Ltd. and/or its affiliates. The actual contracting entity depends on the billing address and applicable agreement. These contract roles are distinct from United States processing: Google LLC is listed as a United States data-center, service-maintenance, and support entity in Google's subprocessor list. The official list below identifies other entities and countries authorized for maintenance or customer-requested support.
To refuse these transfers, do not start email verification, or request suspension/deletion through the contact in Article 9. Refusal prevents use of authenticated roommate features, while public site features remain available. Overseas-processing or deletion questions may also be submitted to the providers through their official contacts below; user requests to SYU CAMPUS remain the operator's responsibility.
Firebase privacy contactGoogle service entitiesGoogle subprocessor entities and countriesVercel privacy contactVercel runtime-log retention
Other external service processing
Other service features may use Google analytics/notifications, Kakao maps, Sentry error monitoring, or a configured AI classification API for redacted contact/suggestion triage. These purposes do not include roommate report classification or roommate page tracking. Personal information or deletion requests must not be submitted to the public GitHub repository or issues.
5. Cookies and Browser Storage
The service primarily uses local storage for user settings. Kakao Maps SDK may set cookies for map and shuttle features. The roommate board uses an essential login cookie with a fixed 30-day expiry, or 12 hours if persistent access is declined. It is removed on sign-out. Blocking this cookie prevents authenticated board access; public service pages remain available. Pending sign-in email storage and removal are explained in Article 2.
Blocking third-party cookies may limit map or shuttle-related features.
6. Analytics, Firebase, and AI Classification
Google Analytics and Search Console support usage analysis and search visibility. Firebase Authentication verifies roommate email ownership, and Firestore stores service submissions, schedules, notification data, and roommate records. Roommate pages are excluded from Google Analytics page tracking, and roommate reports are not sent to AI classification.
When the admin classification feature is enabled, selected contact request or suggestion content may be sent to a configured AI classification API after contact details and obvious identifiers are redacted where possible. The result is stored only as admin-facing triage metadata.
7. Security Measures
The service uses HTTPS, client-side storage where appropriate, Firebase security controls, environment variable management, and administrator authentication to protect service data within the scope of its operation.
8. User Rights and How to Exercise Them
Users may request access, correction, deletion, or suspension of processing by contacting the service operator through the contact page or email.
For roommate records, you can ask the operator to review or delete a listing, report, or authentication user record, or stop processing. Signing out only ends that browser session. Requests remain available after recruitment ends or the board or email sending is paused. Identity and affected data are checked to avoid unauthorized deletion. Where a request cannot be met under law, the operator will explain the reason and available remedies.
9. Privacy Contact
Privacy Contact
Operator and privacy officer: Sanghyeok Seo (individual)
Service operating name: SYU KR
Email: singhic_dev@syu.kr
10. Remedies
Users may contact Korean privacy dispute or reporting agencies for remedies: the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the privacy infringement reporting center (118, privacy.kisa.or.kr), the prosecution service (1301, spo.go.kr), or the police (182, ecrm.cyber.go.kr).
11. Policy Changes
Changes are published on this page. Important changes affecting user rights are announced in advance or when legally required, and consent is obtained separately where required by law.
Effective date: March 23, 2026
Last updated: October 4, 2026