---
title: "PigNote Privacy Policy | WISP"
description: "Privacy Policy for PigNote, a location-based journaling app. Covers the information collected, how location and photos are handled, retention periods, provision to third parties, and how to delete data."
url: https://www.j2w2.org/pignote-privacy.html
lang: ko
---

PigNote

# Privacy Policy

This document explains what information PigNote, a location-based journaling app (package name org.j2w2.pignote), handles and how. This English version is provided for convenience; if it differs from the Korean version, the Korean version prevails.

[Terms of Service](https://www.j2w2.org/en/pignote-terms.md) [Privacy Policy](https://www.j2w2.org/en/pignote-privacy.md) [Account and Data Deletion](https://www.j2w2.org/en/pignote-account-deletion.md) [Child Safety Standards](https://www.j2w2.org/en/pignote-child-safety.md)

**Service** PigNote **Package name** org.j2w2.pignote **Developed and operated by** WISP **Effective date** September 10, 2026

**Summary —** PigNote is an app that handles location and photos. However, it receives location **only while you use the app** and does not follow you in the background, and coordinates shown to other people are **blurred to a grid of about 30 m**. Real-time location is not disclosed, and photos have **the GPS information in EXIF removed** before upload. There is no sign-up; the default account is an anonymous ID created by the device.

## Article 1 (General Provisions)

WISP (the "Company") uses this Policy to inform users of the categories and purposes of the personal information it processes in PigNote (the "Service"), a mobile application and web service created and operated by the Company, as well as the retention periods and users' rights. The Service is provided in three forms — an Android app, the web (`j2w2-pignote.web.app`), and a Toss mini-app — and this Policy applies equally to all three.

## Article 2 (Personal Information Collected and Purposes)

The Service collects the information below. There is no sign-up process, and the Service **does not collect** names, dates of birth, gender, phone numbers, addresses or payment information.

| Item | Details | Purpose of collection | Required/optional |
|---|---|---|---|
| Device identifier | A random ID generated by the app | Creating an anonymous account so that records and Pig can be continued even without an account | Required |
| Location information | Current location (latitude and longitude) while using the app | Specifying where to leave a note (sticky note), determining whether the user is within the viewing radius, discovering nearby records | Optional |
| Photos · messages | Photos, text and stickers uploaded by the user | Storing and displaying note content | Optional |
| Object anchor photos | Photos of objects taken by the author and their image embeddings (512-dimensional numeric values) | Determining whether the same object is shown, to unlock the note | Optional |
| Nickname · friend code | The nickname set by the user and the friend code issued by the app | Showing the author, connecting friends | Required |
| Google account | Unique account ID, email, profile photo URL | Linking an account to continue the same records after changing devices or across multiple targets (Android, web, Toss) | Optional |
| Activity records | Records of discoveries, reactions, comments, saves, reports and blocks; Pig's level and experience points; notification settings | Providing service features, calculating Pig's growth, handling reports | Required |

The Service contains no advertising SDK and does not collect the advertising ID (AAID). No separate analytics or tracking tools have been added.

## Article 3 (Processing of Location Information)

Because the Service's core features are tied to location, location information is processed according to the principles below.

- Location is collected **only while you are using the app**. The Service does not request background location permission and does not track users while the app is closed.

- Note coordinates shown to other users are **blurred to a grid of about 30 m**. The original coordinates are used only to check the viewing radius.

- Users' **real-time location is not disclosed to anyone.** What the map shows is the approximate location of notes, not the location of people.

- Whether a user is within the viewing radius is **verified again by the server**, not by the app. This prevents falsifying location to open other people's records.

- You can use the Service even if you deny location permission. Viewing your own records and the Pig Room work as usual; only nearby discovery and creating new notes are restricted.

- Location information is stored only as attached to notes, and is deleted together with the note when that note is deleted. Movement paths are not separately recorded or accumulated.

## Article 4 (Processing of Photos)

- **Location metadata (EXIF GPS) is removed** from photos before upload.

- Photos are kept in private storage (Google Cloud Storage) and provided only to users whose viewing rights have been confirmed, through **signed URLs with a short validity period**.

- Object anchor photos are converted into image embeddings (512-dimensional numeric values) for matching and stored together with them. Embeddings are generated by calling Vertex AI in the **Seoul (asia-northeast3) region**, so the photos are not transferred outside Korea.

- **Scan photos taken by the person opening a note are deleted immediately after the check** and are not stored.

## Article 5 (Retention and Use Period of Personal Information)

| Category | Retention period |
|---|---|
| Public notes (photos, text, coordinates) | Until the expiry date set by the author (30 days by default). After expiry, they disappear from the map and lists |
| Only-me · friends-only notes | Until the user deletes them |
| Account information · Pig growth · friend relationships | Until the account is deleted |
| Object anchor photos and embeddings | Until the note is deleted |
| Scan photos taken during discovery | Deleted immediately after the check |

When a user deletes their account, the information above is deleted together without delay. How to delete is described on the [Account and Data Deletion](https://www.j2w2.org/en/pignote-account-deletion.md) page.

## Article 6 (Provision to Third Parties)

The Company **does not sell users' personal information and does not provide it to third parties for advertising purposes.** It does not provide personal information externally, except where there is a lawful request under applicable laws.

However, if a user sets a note's visibility to **Public** or **Friends**, its text and photos, the blurred coordinates and the nickname are visible to other users within that scope. This is provision of the Service according to the user's choice, and the user can change the visibility or delete the post at any time after writing it.

## Article 7 (Outsourcing of Processing)

To operate the Service, the Company uses the infrastructure of the businesses below. Each business's own processing policy also applies.

| Processor | Outsourced task |
|---|---|
| Google Cloud Platform | Server (Cloud Run) operation, photo storage (GCS), object anchor embeddings (Vertex AI, Seoul region) |
| Company-operated database | Storing note content, coordinates and account information (in Korea; accessed only through a Cloudflare tunnel) |
| Firebase | Web hosting, Android test distribution |
| Google Sign-In | Authentication for optional account linking |
| Naver Cloud Platform | Mobile map display (Naver Map SDK) |
| OpenStreetMap | Web map tile display |
| Cloudflare | Secure tunnel between the server and the database |
| Viva Republica (Toss) | When provided as a Toss mini-app: the app runtime environment and intermediation of location and sharing features |

## Article 8 (Users' Rights and How to Exercise Them)

Users may exercise the rights below at any time, and most are handled immediately within the app.

- **Access and correction** — You can view and edit your records and profile on the My (마이) screen.

- **Export** — With Settings (설정) > Privacy (개인정보) > **Export my records (내 기록 내보내기)**, you can copy the notes you have left in JSON format.

- **Deletion** — Posts can be deleted individually, and with Settings > Privacy > **Delete all data (모든 데이터 삭제)** you can erase your account and all of your server records.

- **Suspension of processing** — Turning off location permission stops location collection immediately. Google account linking can also be removed in Settings.

- **Blocking and reporting** — If you block a specific user or report a post, that content is hidden immediately.

## Article 9 (Children's Personal Information)

The Service is not directed at children under the age of 14 and does not knowingly collect children's personal information. If the Company learns that information of a user under the age of 14 has been collected, it deletes that information without delay.

## Article 10 (Security Measures)

- Communication between the app and the server is encrypted with HTTPS.

- The connection between the server and the database is not exposed to the public internet; it runs only through a Cloudflare tunnel.

- Photos are kept in private storage, not in a public bucket, and are served only through signed URLs.

- Coordinate blurring (30 m grid), non-disclosure of real-time location and non-use of background location are not relaxed for the sake of feature convenience.

- Database connection details and authentication keys are kept in a secret management service, not in the code.

## Article 11 (Changes to This Policy)

If the content of this Policy changes, the changes and the effective date are posted on this page. For changes that add collected items or purposes of use, the Policy is revised first, before the feature is released.

## Article 12 (Contact)

Please send inquiries and deletion requests regarding the processing of personal information to the contact below.

- In charge: WISP, personal information protection officer

- Email: [nathak@j2w2.org](mailto:nathak@j2w2.org)

- Response: within 7 business days

If you need counseling or want to report an infringement of personal information, you can contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 with no area code), the Cyber Investigation Division of the Supreme Prosecutors' Office (spo.go.kr, 1301), or the Cyber Bureau of the Korean National Police Agency (ecrm.police.go.kr, 182).

[Back to app info](https://www.j2w2.org/en/project-pignote.md) [Terms of Service](https://www.j2w2.org/en/pignote-terms.md) [Account and Data Deletion](https://www.j2w2.org/en/pignote-account-deletion.md) [Child Safety Standards](https://www.j2w2.org/en/pignote-child-safety.md)
