On-Care Legal

개인정보 처리방침

On-Care 회원 앱과 트레이너 웹이 개인정보를 어떻게 모으고 쓰고 지키는지 안내합니다. 앱 안의 처리방침과 같은 글입니다.

회원 앱 · 개인정보 처리방침

시행일 2026. 10. 05.

On-Care(이하 "회사")는 「개인정보 보호법」 등 관련 법령을 준수하며, 회원의 개인정보를 소중히 보호합니다.

1. 수집하는 개인정보 항목

  • ① 회원가입: 이메일, 비밀번호(암호화하여 저장), 이름. 소셜 로그인(카카오·구글·네이버·애플)으로 가입하면 해당 서비스가 넘겨주는 회원 식별자와 이메일·이름을 받습니다.
  • ② 프로필과 첫 설정: 전화번호, 생년월일, 성별, 키, 체중, 건강 목표와 식단·운동 목표.
  • ③ 서비스 이용 중 회원이 남기는 정보: 식단 기록과 음식 사진, 운동 기록, 체중 등 건강 지표, AI 코치와의 대화, 트레이너와 주고받은 메시지와 첨부 사진, 상담·예약 신청 내용.
  • ④ 자동으로 생성되는 정보: 로그인·비밀번호 변경 등 접속 기록(일시, IP 주소)과, 오류가 났을 때의 오류 내용·기기 종류·운영체제·앱 버전.
  • ⑤ 위치 정보: 헬스장 찾기에서 현재 위치 사용을 허용한 경우에만 기기의 현재 좌표를 받아 주변 검색에 쓰며, 계정에 저장하지 않습니다.

2. 개인정보의 수집 및 이용 목적

수집한 개인정보는 회원 식별, 음식 사진 분석과 영양 계산 등 건강 관리 기능 제공, 맞춤형 AI 코칭, 담당 트레이너 연결, 서비스 개선 및 고객 문의 응대의 목적으로만 이용됩니다.

3. 개인정보의 보유 및 이용 기간

회원의 개인정보는 회원 탈퇴 시까지 보유·이용하며, 탈퇴하면 10항의 절차에 따라 지체 없이 파기합니다. 다만 다음 기록은 정해진 기간 동안 보관한 뒤 파기합니다.

  • 로그인 등 접속 기록: 1년(「통신비밀보호법」상 로그인 기록 보존 의무 3개월 포함)
  • 트레이너의 회원 건강정보 열람 기록, 데이터 공유 동의·철회 기록, 탈퇴 기록: 2년(「개인정보의 안전성 확보조치 기준」에 따른 처리 기록 보관)

탈퇴할 때 고른 탈퇴 사유는 회원과 연결되지 않는 사유 항목과 시각만 남깁니다.

4. 개인정보의 제3자 제공

회사는 회원의 동의 없이 개인정보를 외부에 제공하지 않습니다. 담당 트레이너와의 공유는 5항, 업무 처리를 맡기는 위탁은 6항과 7항을 따릅니다. 다만 법령에 특별한 규정이 있는 경우는 예외로 합니다.

5. 담당 트레이너와의 정보 공유 및 동의 철회

회원이 상담 신청, 담당 요청 수락, 연결 코드 발급 중 하나로 데이터 공유에 동의하면 담당 트레이너는 회원의 식단 기록·운동 기록·신체 정보, 건강 목표와 건강상태·주의사항을 볼 수 있습니다. 회원은 MY 탭에서 담당 트레이너 또는 헬스장 연결을 삭제하여 언제든지 동의를 철회할 수 있으며, 트레이너가 담당을 해제한 경우에도 동의는 철회된 것으로 봅니다. 회사는 동의한 시각과 철회한 시각을 기록합니다. 철회한 뒤에는 트레이너가 회원의 새 기록을 볼 수 없고, 같은 트레이너와 다시 연결하려면 새로 동의해야 합니다. 다만 철회 전에 트레이너와 주고받은 대화와 전달된 리포트는 삭제되지 않고 남습니다.

6. 개인정보 처리의 위탁

회사는 서비스 제공을 위해 다음 업무를 외부 업체에 위탁합니다. 수탁자가 바뀌면 이 처리방침을 고쳐 알립니다.

  • Amazon Web Services, Inc.: 서버 운영, 채팅 사진·리포트 PDF 파일 보관
  • Neon: 데이터베이스 운영(계정 정보와 모든 기록 보관)
  • Google LLC: 음식 사진 인식, AI 코치 답변·추천 생성, AI 코치가 회원 기록을 찾아 쓰기 위한 검색 색인 생성(Gemini API)
  • 주식회사 카카오: 헬스장·장소 검색과 지도 표시
  • Functional Software, Inc.(Sentry): 앱·서버 오류 수집과 분석

7. 개인정보의 국외 이전

회사는 회원과의 계약을 이행하기 위해 다음과 같이 개인정보를 국외에서 처리·보관하도록 위탁하며, 「개인정보 보호법」 제28조의8 제1항 제3호에 따라 이 처리방침으로 알립니다. 이전은 서비스를 이용할 때마다 암호화된 네트워크로 전송하는 방법으로 이루어집니다.

  • ① Amazon Web Services, Inc. / 싱가포르 / 회원 정보와 기록 전반, 채팅 첨부 사진과 리포트 PDF / 서버 운영과 파일 보관 / 회원 탈퇴 또는 위탁 계약 종료 시까지
  • ② Neon / 싱가포르 / 계정·프로필·식단·운동·건강 기록과 대화 기록 / 데이터베이스 운영 / 회원 탈퇴 또는 위탁 계약 종료 시까지
  • ③ Google LLC / 미국 등 Google이 운영하는 데이터센터 소재 국가 / 음식 사진, 분석에 필요한 식단·운동 기록·신체 정보·건강 목표, AI 코치와의 대화 내용 / AI 분석·답변 생성과 검색 색인 생성 / 요청 처리 후 수탁자의 서비스 약관에서 정한 기간
  • ④ Functional Software, Inc.(Sentry) / 미국 / 오류 내용, 기기 종류·운영체제·앱 버전(이름·이메일·IP 주소·요청 내용은 보내지 않음) / 오류 분석 / 수탁자의 보관 기간

식단·운동 기록을 저장할 때마다 AI 코치용 검색 색인을 만들기 위해 그 내용이 ③으로 전송됩니다. 국외 이전을 원하지 않으면 탈퇴로 거부할 수 있으나, 이 경우 서비스를 이용할 수 없습니다.

8. 민감정보(건강정보)의 처리

식단·운동 기록, 신체 정보, 건강 목표, 건강상태·주의사항 등 건강에 관한 정보는 「개인정보 보호법」 제23조에 따라 가입할 때 다른 개인정보와 구분하여 별도로 동의를 받아 처리합니다. 담당 트레이너와의 공유는 5항의 동의가 있을 때만 이루어집니다.

9. 만 14세 미만 아동의 개인정보

회사는 만 14세 미만 아동의 회원가입을 받지 않으며, 가입할 때 만 14세 이상인지 확인합니다.

10. 개인정보의 파기 절차 및 방법

  • ① 절차: 회원이 MY 탭에서 탈퇴하면 즉시 계정과 함께 프로필, 식단·운동 기록과 음식 사진, AI 코치 대화와 검색 색인, 알림, 소셜 로그인 연결, 담당 트레이너와의 연결과 대화(첨부 사진·리포트 PDF 파일 포함)를 삭제합니다. 대기 중인 상담 요청과 예약은 취소되고, 관련 트레이너에게 탈퇴 사실이 안내됩니다. 트레이너의 일정표에 이미 잡혀 있던 수업 기록에는 회원 표시 이름과 일시가 트레이너의 업무 기록으로 남습니다. 3항에 따라 보관하는 기록은 기간이 지나면 자동으로 삭제합니다.
  • ② 방법: 전자적 파일 형태의 정보는 데이터베이스와 파일 저장소에서 삭제하며, 데이터베이스 복구용 백업에 남은 사본은 백업 보관 기간이 지나면 함께 사라집니다. 회사는 개인정보를 종이 문서로 처리하지 않습니다.

11. 개인정보 자동 수집 장치의 설치·운영 및 거부

회사는 광고·행태 분석을 위한 쿠키나 추적 도구를 쓰지 않습니다. 웹에서는 로그인 상태를 유지하기 위해 브라우저 저장소에 인증 정보를 보관하며, 로그아웃하거나 브라우저 데이터를 지우면 삭제됩니다.

12. 개인정보의 안전성 확보 조치

회사는 비밀번호를 암호화하여 저장하고, 전송 구간을 암호화하며, 회원 정보에 대한 트레이너의 접근을 담당 관계를 기준으로 제한합니다. 트레이너가 회원의 건강정보를 열람하면 열람한 트레이너, 대상 회원, 정보의 종류와 시각만 기록하며 건강정보의 내용은 담지 않습니다. 오류 보고에서는 이름·이메일·IP 주소와 요청 내용을 지우고 보냅니다.

13. 이용자의 권리와 행사 방법

회원은 언제든지 자신의 개인정보를 조회·수정하거나 처리 정지 및 삭제를 요청할 수 있습니다. 프로필은 MY 탭에서 직접 고칠 수 있고, 탈퇴와 트레이너 공유 동의 철회도 MY 탭에서 할 수 있습니다. 그 밖의 요청은 14항의 연락처로 보내 주시면 지체 없이 조치합니다.

14. 개인정보 보호책임자

회사는 개인정보 처리에 관한 업무를 총괄하고 관련 불만 처리와 피해 구제를 위해 개인정보 보호책임자를 지정하고 있습니다.

15. 권익침해 구제 방법

개인정보 침해에 대한 신고나 상담이 필요하면 다음 기관에 문의할 수 있습니다.

  • 개인정보분쟁조정위원회: 국번없이 1833-6972 (www.kopico.go.kr)
  • 개인정보침해신고센터: 국번없이 118 (privacy.kisa.or.kr)
  • 대검찰청: 국번없이 1301 (www.spo.go.kr)
  • 경찰청: 국번없이 182 (ecrm.police.go.kr)

16. 처리방침의 변경

이 처리방침을 바꾸면 시행일 전에 앱 안에 알리며, 동의가 필요한 변경은 다시 동의를 받습니다.

  • 2026년 10월 5일: 개인정보 보호책임자 연락처 변경
  • 2026년 10월 3일: 처리 위탁·국외 이전·민감정보·만 14세 미만·파기 절차·자동 수집 장치·안전성 확보 조치·보호책임자·권익침해 구제 항목 추가
  • 2026년 10월 1일: 제정

시행일: 2026년 10월 5일

트레이너 웹 · 개인정보 처리방침

시행일 2026. 10. 05.

On-Care(이하 "회사")는 「개인정보 보호법」 등 관련 법령을 준수하며, 트레이너와 회원의 개인정보를 소중히 보호합니다.

1. 수집하는 개인정보 항목

  • ① 트레이너 가입: 이메일, 비밀번호(암호화하여 저장), 이름, 연락처.
  • ② 프로필과 자격 확인: 소속 헬스장, 자격증, 경력, 전문 분야 등 프로필 정보.
  • ③ 서비스 이용 중 남기는 정보: 회원에게 보낸 메시지와 첨부 사진, 리포트와 코칭 내용, 일정·예약 정보, 회원 메모.
  • ④ 자동으로 생성되는 정보: 로그인·비밀번호 변경 등 접속 기록(일시, IP 주소)과, 오류가 났을 때의 오류 내용·브라우저와 운영체제 종류·앱 버전.

2. 개인정보의 수집 및 이용 목적

수집한 정보는 트레이너 식별과 운영자의 신고 처리와 계정 관리, 담당 회원 연결, 일정·메시지·리포트 기능 제공, 서비스 개선 및 문의 응대의 목적으로만 이용됩니다.

3. 담당 회원 정보의 열람과 처리

  • ① 트레이너는 담당 관계가 성립한 회원에 한하여 그 회원이 기록한 식단·운동·체중 등 건강 정보를 서비스 안에서 열람할 수 있습니다.
  • ② 이 정보의 개인정보처리자는 회사이며, 트레이너는 회사가 정한 범위 안에서 코칭과 리포트 작성 목적으로만 이를 처리합니다. 회원의 건강정보는 민감정보로서 회원의 별도 동의와 데이터 공유 동의가 있을 때만 열람할 수 있습니다.
  • ③ 트레이너가 작성해 전송한 리포트와 메시지는 해당 회원에게 전달되고 서비스에 기록으로 남습니다.
  • ④ 담당 관계가 종료되면 해당 회원 정보에 대한 열람 권한은 즉시 회수되며, 회원은 자신의 정보 제공에 대한 동의를 언제든지 철회할 수 있습니다.

4. 개인정보의 보유 및 이용 기간

트레이너의 개인정보는 탈퇴 시까지 보유·이용하며, 탈퇴하면 8항의 절차에 따라 지체 없이 파기합니다. 다만 다음 기록은 정해진 기간 동안 보관한 뒤 파기합니다.

  • 로그인 등 접속 기록: 1년(「통신비밀보호법」상 로그인 기록 보존 의무 3개월 포함)
  • 트레이너의 회원 건강정보 열람 기록, 정보 제공 동의·철회 기록, 탈퇴 기록: 2년(「개인정보의 안전성 확보조치 기준」에 따른 처리 기록 보관)

회원에게 전송된 리포트와 메시지는 회원의 기록이므로 회원의 보관 기간을 따릅니다.

5. 개인정보의 제3자 제공

회사는 트레이너와 회원의 동의 없이 개인정보를 외부에 제공하지 않습니다. 업무 처리를 맡기는 위탁은 6항과 7항을 따릅니다. 다만 법령에 특별한 규정이 있는 경우는 예외로 합니다.

6. 개인정보 처리의 위탁

회사는 서비스 제공을 위해 다음 업무를 외부 업체에 위탁합니다. 수탁자가 바뀌면 이 처리방침을 고쳐 알립니다.

  • Amazon Web Services, Inc.: 서버 운영, 채팅 사진·리포트 PDF 파일 보관
  • Neon: 데이터베이스 운영(계정 정보와 모든 기록 보관)
  • Google LLC: AI 코칭 프로그램·루틴 후보와 리포트 요약 생성(Gemini API)
  • 주식회사 카카오: 헬스장 검색과 지도 표시
  • Functional Software, Inc.(Sentry): 웹·서버 오류 수집과 분석

7. 개인정보의 국외 이전

회사는 트레이너와의 계약을 이행하기 위해 다음과 같이 개인정보를 국외에서 처리·보관하도록 위탁하며, 「개인정보 보호법」 제28조의8 제1항 제3호에 따라 이 처리방침으로 알립니다. 이전은 서비스를 이용할 때마다 암호화된 네트워크로 전송하는 방법으로 이루어집니다.

  • ① Amazon Web Services, Inc. / 싱가포르 / 트레이너 정보와 기록 전반, 채팅 첨부 사진과 리포트 PDF / 서버 운영과 파일 보관 / 탈퇴 또는 위탁 계약 종료 시까지
  • ② Neon / 싱가포르 / 계정·프로필, 메시지·리포트·일정 기록 / 데이터베이스 운영 / 탈퇴 또는 위탁 계약 종료 시까지
  • ③ Google LLC / 미국 등 Google이 운영하는 데이터센터 소재 국가 / AI 기능을 쓸 때 입력한 코칭 조건과 담당 회원의 운동 기록·주간 리포트 수치 / AI 프로그램·요약 생성 / 요청 처리 후 수탁자의 서비스 약관에서 정한 기간
  • ④ Functional Software, Inc.(Sentry) / 미국 / 오류 내용, 브라우저와 운영체제 종류·앱 버전(이름·이메일·IP 주소·요청 내용은 보내지 않음) / 오류 분석 / 수탁자의 보관 기간

국외 이전을 원하지 않으면 탈퇴로 거부할 수 있으나, 이 경우 서비스를 이용할 수 없습니다.

8. 개인정보의 파기 절차 및 방법

  • ① 절차: 트레이너가 탈퇴하면 즉시 계정과 함께 프로필, 담당 회원과의 연결과 대화(첨부 사진·리포트 PDF 파일 포함), 루틴·프로그램, 일정과 예약 가능 시간, 알림을 삭제하고, 담당 회원과 예약한 회원에게 그 사실을 알립니다. 회원이 보낸 상담 요청은 회원의 기록이므로 트레이너 정보만 지운 채 남습니다. 4항에 따라 보관하는 기록은 기간이 지나면 자동으로 삭제합니다.
  • ② 방법: 전자적 파일 형태의 정보는 데이터베이스와 파일 저장소에서 삭제하며, 데이터베이스 복구용 백업에 남은 사본은 백업 보관 기간이 지나면 함께 사라집니다. 회사는 개인정보를 종이 문서로 처리하지 않습니다.

9. 개인정보 자동 수집 장치의 설치·운영 및 거부

회사는 광고·행태 분석을 위한 쿠키나 추적 도구를 쓰지 않습니다. 로그인 상태를 유지하기 위해 브라우저 저장소에 인증 정보를 보관하며, 로그아웃하거나 브라우저 데이터를 지우면 삭제됩니다.

10. 안전성 확보 조치

회사는 비밀번호를 암호화하여 저장하고, 회원 정보에 대한 접근 권한을 담당 관계를 기준으로 제한하며, 전송 구간을 암호화합니다. 열람 기록에는 열람한 트레이너, 대상 회원, 정보의 종류와 시각만 남기며 건강정보의 내용은 담지 않습니다. 오류 보고에서는 이름·이메일·IP 주소와 요청 내용을 지우고 보냅니다.

11. 만 14세 미만 아동의 개인정보

회사는 만 14세 미만 아동의 가입을 받지 않으며, 가입할 때 만 14세 이상인지 확인합니다.

12. 이용자의 권리

트레이너는 언제든지 자신의 개인정보를 조회·수정하거나 처리 정지 및 삭제를 요청할 수 있습니다. 프로필 수정과 탈퇴는 MY 메뉴에서 할 수 있고, 그 밖의 요청은 13항의 연락처로 보내 주시면 지체 없이 조치합니다.

13. 개인정보 보호책임자

회사는 개인정보 처리에 관한 업무를 총괄하고 관련 불만 처리와 피해 구제를 위해 개인정보 보호책임자를 지정하고 있습니다.

14. 권익침해 구제 방법

개인정보 침해에 대한 신고나 상담이 필요하면 다음 기관에 문의할 수 있습니다.

  • 개인정보분쟁조정위원회: 국번없이 1833-6972 (www.kopico.go.kr)
  • 개인정보침해신고센터: 국번없이 118 (privacy.kisa.or.kr)
  • 대검찰청: 국번없이 1301 (www.spo.go.kr)
  • 경찰청: 국번없이 182 (ecrm.police.go.kr)

15. 처리방침의 변경

이 처리방침을 바꾸면 시행일 전에 서비스 안에 알리며, 동의가 필요한 변경은 다시 동의를 받습니다.

  • 2026년 10월 5일: 개인정보 보호책임자 연락처 변경
  • 2026년 10월 3일: 처리 위탁·국외 이전·파기 절차·자동 수집 장치·만 14세 미만·보호책임자·권익침해 구제 항목 추가
  • 2026년 10월 1일: 제정

시행일: 2026년 10월 5일

Member app · Privacy Policy

Effective Oct 5, 2026

On-Care (the "Company") complies with the Personal Information Protection Act and other applicable laws, and protects its members' personal information with care.

1. Personal information collected

  • (1) Sign-up: email address, password (stored encrypted) and name. If you sign up with a social login (Kakao, Google, Naver or Apple), we receive the member identifier, email address and name that service passes on.
  • (2) Profile and first setup: phone number, date of birth, gender, height, weight, health goals and diet and exercise targets.
  • (3) Information you leave while using the Service: meal records and food photos, workout records, health indicators such as body weight, conversations with the AI coach, messages and attached photos exchanged with your trainer, and consultation and booking requests.
  • (4) Information generated automatically: access logs such as sign-ins and password changes (time and IP address), and, when an error occurs, the error details, device type, operating system and app version.
  • (5) Location: only if you allow your current location in gym search, we receive the device's current coordinates and use them to search nearby. They are not saved to your account.

2. Purpose of collection and use

The personal information collected is used only to identify members, provide health management features such as food photo analysis and nutrition calculation, deliver personalised AI coaching, connect you with a trainer, improve the Service and respond to customer enquiries.

3. Retention and use period

A member's personal information is kept until the member withdraws from the Service, and is then destroyed without delay following section 10. The following records are kept for the stated period and then destroyed.

  • Access logs such as sign-ins: one year (covering the three-month retention of sign-in records required by the Protection of Communications Secrets Act)
  • Records of trainers opening members' health information, of data-sharing consent being given or withdrawn, and of account deletion: two years (processing records kept under the Standards for Personal Information Security Measures)

A reason chosen when deleting an account is kept only as a reason code and a time, with no link to the member.

4. Provision to third parties

The Company does not provide personal information to any third party without the member's consent. Sharing with your trainer follows section 5, and processing entrusted to service providers follows sections 6 and 7. The exception is where a law specifically provides otherwise.

5. Sharing with your trainer and withdrawing consent

When you agree to data sharing by requesting a consultation, accepting a coaching request or issuing a pairing code, your assigned trainer can see your meal records, workout records, body information, health goals, and health notes & cautions. You can withdraw this consent at any time by removing your trainer or gym connection in the MY tab, and consent is also treated as withdrawn when the trainer ends the coaching relationship. The Company records when consent was given and when it was withdrawn. After you withdraw, the trainer can no longer see your new records, and reconnecting with the same trainer requires your consent again. Conversations you exchanged with the trainer and reports delivered before the withdrawal are not deleted.

6. Entrusted processing

The Company entrusts the following work to outside providers to deliver the Service. If a provider changes, this policy is updated to say so.

  • Amazon Web Services, Inc.: running the servers and storing chat photos and report PDFs
  • Neon: running the database (account information and all records)
  • Google LLC: food photo recognition, generating AI coach answers and recommendations, and building the search index the AI coach uses to look up your records (Gemini API)
  • Kakao Corp.: gym and place search and map display
  • Functional Software, Inc. (Sentry): collecting and analysing app and server errors

7. Transfer of personal information overseas

To perform its contract with members, the Company has personal information processed and stored overseas as follows, and discloses this in this policy under Article 28-8(1)(3) of the Personal Information Protection Act. Each transfer happens over an encrypted network connection whenever the Service is used.

  • (1) Amazon Web Services, Inc. / Singapore / member information and records in general, chat photo attachments and report PDFs / running the servers and storing files / until the member withdraws or the contract with the provider ends
  • (2) Neon / Singapore / account, profile, diet, workout and health records and conversation records / running the database / until the member withdraws or the contract with the provider ends
  • (3) Google LLC / the United States and other countries where Google operates data centres / food photos, the diet and workout records, body information and health goals needed for analysis, and conversations with the AI coach / AI analysis, answer generation and search indexing / for the period set in the provider's terms of service after the request is processed
  • (4) Functional Software, Inc. (Sentry) / the United States / error details, device type, operating system and app version (name, email address, IP address and request contents are not sent) / error analysis / the provider's retention period

Each time you save a meal or workout record, its contents are sent to (3) to build the AI coach's search index. If you do not want your information transferred overseas, you can refuse by deleting your account, but you will then be unable to use the Service.

8. Processing of sensitive (health) information

Health information such as diet and workout records, body information, health goals, and health notes & cautions is processed under Article 23 of the Personal Information Protection Act only with a separate consent obtained at sign-up, apart from other personal information. It is shared with your trainer only with the consent described in section 5.

9. Children under 14

The Company does not accept sign-ups from children under 14, and confirms at sign-up that you are 14 or older.

10. Destruction procedure and method

  • (1) Procedure: when you delete your account in the MY tab, the Company immediately deletes the account together with your profile, meal and workout records and food photos, AI coach conversations and search index, notifications, social login links, and your trainer connection and conversations (including attached photos and report PDF files). Pending consultation requests and bookings are cancelled, and the trainers involved are told that you have left. Sessions already on a trainer's schedule keep your display name and the date and time as the trainer's work record. Records kept under section 3 are deleted automatically when their period ends.
  • (2) Method: information held as electronic files is deleted from the database and file storage, and copies remaining in database recovery backups disappear when the backup retention period ends. The Company does not handle personal information on paper.

11. Automatic collection tools

The Company does not use cookies or tracking tools for advertising or behavioural analysis. On the web, sign-in information is kept in browser storage to keep you signed in, and is removed when you sign out or clear your browser data.

12. Safeguards

The Company stores passwords encrypted, encrypts traffic in transit, and limits trainers' access to member information by assignment. When a trainer opens a member's health information, only the trainer, the member, the kind of information and the time are recorded, never the health information itself. Error reports are sent with names, email addresses, IP addresses and request contents removed.

13. Rights of the user and how to exercise them

Members may at any time view or correct their personal information, or request that its processing be suspended and the information deleted. You can edit your profile, delete your account and withdraw trainer-sharing consent in the MY tab. For any other request, contact the address in section 14 and it will be handled without delay.

14. Personal information protection officer

The Company has appointed a personal information protection officer who oversees the processing of personal information and handles related complaints and remedies.

  • Position: Personal information protection officer, On-Care service operations team
  • Contact: sudo.capstone@gmail.com

15. Remedies for infringement

For reports or advice about an infringement of personal information, you can contact the following bodies (in Korea).

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • Korean National Police Agency: 182 (ecrm.police.go.kr)

16. Changes to this policy

If this policy changes, the Company announces it in the app before the effective date, and asks for consent again where the change requires it.

  • 5 October 2026: changed the contact address of the personal information protection officer
  • 3 October 2026: added entrusted processing, overseas transfer, sensitive information, children under 14, destruction procedure, automatic collection tools, safeguards, protection officer and remedies sections
  • 1 October 2026: first issued

Effective date: 5 October 2026

This is a translation of the Korean original for reference. In case of any discrepancy, the Korean version governs.

Trainer web · Privacy Policy

Effective Oct 5, 2026

This English text is provided for convenience; the Korean original governs.

1. Information collected

  • (1) Trainer sign-up: email, password (stored encrypted), name and phone number.
  • (2) Profile and credential check: gym affiliation, certifications, career, speciality and other profile details.
  • (3) Information you leave while using the Service: messages and attached photos sent to members, reports and coaching content, schedules and bookings, and member notes.
  • (4) Information generated automatically: access logs such as sign-ins and password changes (time and IP address), and, when an error occurs, the error details, browser and operating system type and app version.

2. Purpose of collection and use

The information is used only to identify trainers and to let an operator handle reports and manage accounts, to connect them with assigned members, to provide scheduling, messaging and reports, and to improve the service and answer enquiries.

3. Access to and processing of member information

A trainer may open the diet, workout and body-weight records of members they are assigned to, inside the Service. The Company is the controller of those records; the trainer processes them only for coaching and reports, within the scope the Company sets. Members' health information is sensitive information and can be opened only with the member's separate consent and data-sharing consent. Reports and messages a trainer sends are delivered to that member and kept in the Service as a record. When an assignment ends, the trainer's access is revoked immediately, and a member may withdraw consent to share their information at any time.

4. Retention

A trainer's personal information is kept until account deletion, and is then destroyed without delay following section 8. The following records are kept for the stated period and then destroyed.

  • Access logs such as sign-ins: one year (covering the three-month retention of sign-in records required by the Protection of Communications Secrets Act)
  • Records of trainers opening members' health information, of consent being given or withdrawn, and of account deletion: two years (processing records kept under the Standards for Personal Information Security Measures)

Reports and messages already delivered belong to the member's record and follow the member's retention period.

5. Provision to third parties

The Company does not provide personal information to outside parties without consent. Processing entrusted to service providers follows sections 6 and 7. The exception is where the law specifically requires it.

6. Entrusted processing

The Company entrusts the following work to outside providers to deliver the Service. If a provider changes, this policy is updated to say so.

  • Amazon Web Services, Inc.: running the servers and storing chat photos and report PDFs
  • Neon: running the database (account information and all records)
  • Google LLC: generating AI coaching programs, routine suggestions and report summaries (Gemini API)
  • Kakao Corp.: gym search and map display
  • Functional Software, Inc. (Sentry): collecting and analysing web and server errors

7. Transfer of personal information overseas

To perform its contract with trainers, the Company has personal information processed and stored overseas as follows, and discloses this in this policy under Article 28-8(1)(3) of the Personal Information Protection Act. Each transfer happens over an encrypted network connection whenever the Service is used.

  • (1) Amazon Web Services, Inc. / Singapore / trainer information and records in general, chat photo attachments and report PDFs / running the servers and storing files / until account deletion or the end of the contract with the provider
  • (2) Neon / Singapore / account and profile, message, report and schedule records / running the database / until account deletion or the end of the contract with the provider
  • (3) Google LLC / the United States and other countries where Google operates data centres / coaching conditions entered when using AI features, and assigned members' workout records and weekly report figures / generating AI programs and summaries / for the period set in the provider's terms of service after the request is processed
  • (4) Functional Software, Inc. (Sentry) / the United States / error details, browser and operating system type and app version (name, email address, IP address and request contents are not sent) / error analysis / the provider's retention period

If you do not want your information transferred overseas, you can refuse by deleting your account, but you will then be unable to use the Service.

8. Destruction procedure and method

  • (1) Procedure: when a trainer deletes their account, the Company immediately deletes the account together with the profile, member connections and conversations (including attached photos and report PDF files), routines and programs, schedules and bookable times, and notifications, and tells assigned and booked members. Consultation requests sent by members belong to the members' records and remain with the trainer's details removed. Records kept under section 4 are deleted automatically when their period ends.
  • (2) Method: information held as electronic files is deleted from the database and file storage, and copies remaining in database recovery backups disappear when the backup retention period ends. The Company does not handle personal information on paper.

9. Automatic collection tools

The Company does not use cookies or tracking tools for advertising or behavioural analysis. Sign-in information is kept in browser storage to keep you signed in, and is removed when you sign out or clear your browser data.

10. Safeguards

Passwords are stored encrypted, access to member information is limited by assignment, and traffic is encrypted in transit. An access record holds only the trainer, the member, the kind of information and the time, never the health information itself. Error reports are sent with names, email addresses, IP addresses and request contents removed.

11. Children under 14

The Company does not accept sign-ups from children under 14, and confirms at sign-up that you are 14 or older.

12. Your rights

A trainer may review or correct their personal information, or request that its processing stop and that it be deleted, at any time. You can edit your profile and delete your account from the MY menu; for any other request, contact the address in section 13 and it will be handled without delay.

13. Privacy officer

The Company has appointed a personal information protection officer who oversees the processing of personal information and handles related complaints and remedies.

  • Position: Personal information protection officer, On-Care service operations team
  • Contact: sudo.capstone@gmail.com

14. Remedies for infringement

For reports or advice about an infringement of personal information, you can contact the following bodies (in Korea).

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • Korean National Police Agency: 182 (ecrm.police.go.kr)

15. Changes to this policy

If this policy changes, the Company announces it in the Service before the effective date, and asks for consent again where the change requires it.

  • October 5, 2026: changed the contact address of the privacy officer
  • October 3, 2026: added entrusted processing, overseas transfer, destruction procedure, automatic collection tools, children under 14, protection officer and remedies sections
  • October 1, 2026: first issued

Effective: October 5, 2026