본문으로 건너뛰기
AUWith

개인정보처리방침

Privacy Policy

1. 개요

AUWith(이하 "서비스")는 호주 Privacy Act 1988 및 2024 개정안, Australian Privacy Principles(APPs)에 따라 이용자의 개인정보를 보호합니다. 본 방침은 서비스가 수집, 사용, 보관, 공개하는 개인정보의 처리에 대해 설명합니다.

2. 수집하는 개인정보

서비스는 다음과 같은 개인정보를 수집합니다:

  • 회원가입 시: 이메일 주소, 닉네임, 비밀번호(암호화 저장), 관심 지역
  • Google 소셜 로그인 시: Google 계정 이메일, 프로필 이름, 프로필 사진 URL
  • 서비스 이용 시: 작성 게시물, 댓글, 북마크, 검색 기록 (게시물·댓글 작성 시 작성 시점의 IP 주소와 브라우저 정보가 함께 기록됩니다)
  • 자동 수집: IP 주소, 브라우저 종류, 접속 시간, 쿠키. 당사는 보안, 부정·불법행위(사기·협박·명예훼손 등) 대응, 그리고 법령상 요구되거나 권한이 있는 경우 법집행기관(호주 경찰)·재외공관(대사관)의 적법한 요청에 응하기 위한 증거 보전 목적으로 IP를 기록하며, 비로그인(익명) 방문자도 수집 대상입니다.

3. 개인정보의 이용 목적

수집된 개인정보는 다음 목적으로 사용됩니다:

  • 회원 식별 및 인증
  • 서비스 제공 및 운영 (게시판, 검색, 맞춤 콘텐츠)
  • 이용자 문의 응대 및 공지사항 전달
  • 서비스 개선을 위한 통계 분석
  • 불법행위 방지 및 서비스 보안

4. 개인정보의 보관 기간

서비스는 수집 목적 달성 시까지 개인정보를 보관하며, 카테고리별 상세 보유 기간은 다음과 같습니다:

데이터 유형보유 기간비고
회원 정보 (이메일, 닉네임)회원 탈퇴 후 30일탈퇴 후 30일 이내 파기
게시글 및 댓글영구 보관삭제 요청 시 비식별 처리
푸시 알림 기록90일90일 경과 후 자동 삭제
세션 정보 (로그인 토큰)30일만료 시 자동 폐기
접속 로그 (IP, 브라우저)90일방문 접근 로그(비로그인 포함). 보안 목적, 90일 후 자동 삭제
검색 기록6개월서비스 개선 목적
쿠키 동의 설정12개월동의 기록 보관
IP 평판 점수 (보안 자동 분석 집계 데이터)최종 관측 후 30일IP 단위 집계·판정 점수. 접속 로그에 기록되는 개별 판정 태그는 접속 로그 보유 기간(90일)을 따름
제재 IP 목록 (차단된 IP 주소)제재 해제 시까지 (해제 시 삭제)제재 회피 방지를 위한 IP 기반 이용 제한 목록(이용약관 제9조 참조). 이의가 인용되거나 관리자가 해제를 결정하면 삭제됨

방문 접근 로그(IP 등)는 90일, 로그인 이력은 180일간 보존한 후 자동 삭제합니다. 법령에 의한 의무 보관 기간이 있는 경우 해당 기간까지 보관합니다.

5. 개인정보의 제3자 제공

서비스는 이용자의 동의 없이 개인정보를 제3자에게 제공하지 않습니다. 다만, 다음의 경우는 예외로 합니다:

  • 법령에 의해 요구되는 경우
  • 법집행기관·재외공관에 대한 제공(법집행 공개): 당사는 IP 등 기록을 본인 동의 없이 제3자에게 자발적으로 제공하지 않습니다. 다만 법원의 명령·영장, 또는 법령에 의해 요구·허용되는 경우에 한해 법집행기관(호주 경찰)·재외공관(대사관)에 제공할 수 있습니다(APP 6).
  • 이용자의 생명, 신체, 재산 보호를 위해 긴급히 필요한 경우

6. 쿠키(Cookies) 사용

서비스는 이용자 경험 향상을 위해 쿠키를 사용합니다. 호주 Privacy Act 2024 개정안에 따라 비필수 쿠키는 이용자의 명시적 동의 후에만 활성화됩니다.

필수 쿠키 (Essential)

로그인 세션 유지, CSRF 보호, 보안 등 서비스의 기본 기능에 필수적인 쿠키입니다. 이 쿠키 없이는 서비스를 정상적으로 이용할 수 없으므로, 동의 여부와 관계없이 항상 활성화됩니다.

분석 쿠키 (Analytics)

Google Analytics 4(GA4)를 통해 방문자 수, 페이지 조회수, 체류 시간 등 익명 통계 데이터를 수집합니다. 이를 통해 서비스 품질을 개선합니다. 이용자가 동의하지 않으면 GA4 스크립트가 로드되지 않습니다.

기능 쿠키 (Functional)

다크모드/라이트모드 테마 설정, 언어 선택 등 이용자의 환경 설정을 기억합니다. 이 쿠키를 비활성화하면 방문할 때마다 환경을 다시 설정해야 할 수 있습니다.

쿠키 설정은 쿠키 설정 페이지에서 언제든 변경할 수 있습니다. 또한 브라우저 설정을 통해 쿠키 허용 여부를 선택할 수 있으나, 쿠키를 차단할 경우 일부 서비스 이용이 제한될 수 있습니다.

7. 개인정보 보호 조치

서비스는 다음과 같은 기술적·관리적 보호 조치를 시행합니다:

  • 비밀번호 bcrypt 암호화 저장
  • HTTPS 통신 암호화
  • 접근 권한 관리 및 로그 모니터링
  • 정기적 보안 점검

8. 이용자의 권리 (APPs 기반)

호주 Privacy Act 1988의 Australian Privacy Principles에 따라 이용자는 다음 권리를 가집니다:

  • 접근권 (APP 12): 자신의 개인정보에 접근하여 열람할 수 있습니다.
  • 정정권 (APP 13): 부정확한 개인정보의 수정을 요청할 수 있습니다.
  • 삭제권: 회원 탈퇴를 통해 개인정보 삭제를 요청할 수 있습니다.
  • 불만 제기권: 개인정보 처리에 관한 불만은 아래 연락처로 제출할 수 있습니다.

9. 개인정보의 국외 이전 (APP 8)

서비스 운영을 위해 다음 외부 서비스를 이용하며, 이 과정에서 개인정보가 해외 서버로 전송될 수 있습니다:

  • Google Analytics (미국): 익명화된 방문 통계 데이터 (분석 쿠키 동의 시에만)
  • Google OAuth (미국): 소셜 로그인 인증 처리
  • Cloudinary (미국/유럽): 이미지 호스팅 및 최적화

이 밖에 Cloudflare(엣지 네트워크 — IP 주소 처리)와 Sentry(에러 로그 수집)를 통해서도 개인정보가 해외 서버로 전송될 수 있습니다. 해당 서비스들은 Australian Privacy Principles에 상응하는 수준의 개인정보 보호 조치를 시행하고 있으며, 서비스는 APP 8에 따라 합리적인 조치를 취하고 있습니다.

10. 자동화된 의사결정 고지

서비스는 다음과 같은 자동화된 처리를 수행하며, 이는 이용자의 서비스 경험에 영향을 줄 수 있습니다:

  • 트렌딩 알고리즘: 게시글의 조회수, 댓글 수, 좋아요 수 등을 기반으로 인기 게시글을 자동으로 선별하여 노출합니다. 개인정보를 직접 활용하지는 않으며, 집계된 상호작용 데이터를 기반으로 합니다.
  • 맞춤 콘텐츠: 이용자가 설정한 관심 지역을 기반으로 해당 지역의 게시글을 우선적으로 표시합니다.
  • 보안 자동 분석 (봇/IP 평판 분류): 서비스 보호를 위해 접속 요청의 기술적 특성(User-Agent, 브라우저가 자동 전송하는 표준 부가 헤더의 존재 여부)과 IP 단위 접속 패턴을 자동 분석하여 봇/자동화 트래픽 여부를 분류할 수 있습니다. 이 분류는 통계·보안 분석, 제휴 정산에서의 부정 클릭 제외, 스팸 가입 방지를 위한 추가 보안 확인(CAPTCHA) 요청, 비정상 접속(IP) 제한 판단의 보조 신호로 활용될 수 있으며, 페이지 열람 자체를 차단하지 않습니다. 부가 헤더(client hints·언어 설정)의 원문 값은 저장하지 않고 파생된 판정 결과만 보관하며, User-Agent는 접속 로그 항목(제4조 표 참조)으로 별도 보관됩니다.

서비스는 이용자의 법적 권리에 중대한 영향을 미치는 완전 자동화된 의사결정을 수행하지 않습니다.

11. 데이터 유출 통지 (NDB 제도)

1988년 개인정보보호법(Privacy Act 1988) 제IIIC부에 정의된 적격 데이터 유출이 발생할 경우, 당사는 다음과 같이 조치합니다:

  • 유출을 인지한 날로부터 30일 이내에 합리적이고 신속한 평가를 실시합니다
  • 유출이 심각한 피해를 초래할 가능성이 있는 경우 호주 정보보호위원회(OAIC)에 통지합니다
  • 유출 내용과 권장 조치에 대한 설명을 포함하여 영향을 받는 개인에게 실무상 가능한 한 신속히 통지합니다

11. 문의처

개인정보 처리에 관한 문의사항은 아래로 연락해주세요:

호주 정보위원회(OAIC)에 불만을 제기할 수도 있습니다: www.oaic.gov.au

본 개인정보처리방침은 2026년 3월 25일부터 시행됩니다.

최종 수정일: 2026년 7월 2일


Privacy Policy

English Version

1. Introduction

AUWith (hereinafter referred to as "the Service") is committed to protecting the personal information of its users in accordance with the Australian Privacy Act 1988 (Cth) and its 2024 amendments, including the Australian Privacy Principles (APPs). This Privacy Policy describes how we collect, use, hold, and disclose personal information.

2. Personal Information We Collect

The Service collects the following categories of personal information:

  • Registration: Email address, nickname, password (stored encrypted), preferred region
  • Google Social Login: Google account email, profile name, profile image URL
  • Service Usage: Posts, comments, bookmarks, search history (when you create a post or comment, the IP address and browser information at the time of posting are recorded together)
  • Automatically Collected: IP address, browser type, access time, cookies. We record IP addresses for the purposes of security, responding to fraudulent or unlawful conduct (fraud, threats, defamation, etc.), and preserving evidence to respond to lawful requests from law enforcement (Australian Police) and overseas diplomatic missions (embassies) where required or authorised by law. Non-logged-in (anonymous) visitors are also subject to this collection.

In accordance with APP 3, we only collect personal information that is reasonably necessary for the functions and activities of the Service.

3. Purpose of Collection (APP 6)

Personal information collected is used for the following purposes:

  • User identification and authentication
  • Service provision and operation (forums, search, personalised content)
  • Responding to user enquiries and delivering notices
  • Statistical analysis for service improvement
  • Fraud prevention and service security

We will not use or disclose personal information for a purpose other than the primary purpose of collection unless an exception under APP 6 applies.

4. Retention of Personal Information (APP 11)

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected. Specific retention periods are as follows:

Data TypeRetention PeriodNotes
Account information (email, nickname)30 days after account deletionDestroyed within 30 days of deletion request
Posts and commentsRetained indefinitelyDe-identified upon deletion request
Push notification records90 daysAutomatically deleted after 90 days
Session information (login tokens)30 daysAutomatically invalidated upon expiry
Access logs (IP, browser)90 daysVisitor access logs (including non-logged-in). For security purposes; auto-deleted after 90 days
Search history6 monthsFor service improvement
Cookie consent preferences12 monthsConsent record retention
IP reputation scores (aggregated automated security analysis data)30 days after last observationAggregated per-IP classification scores. Individual classification tags recorded in access logs follow the access-log retention period (90 days)
Sanctioned IP list (blocked IP addresses)Until the sanction is lifted (deleted upon lifting)IP-based restriction list to prevent evasion of sanctions (see the Restrictions and Sanctions section of the Terms of Service). Deleted when lifted following a substantiated appeal or administrator review

Visitor access logs (including IP) are retained for 90 days and login history for 180 days, after which they are automatically deleted. Where a longer retention period is required by applicable law, we will retain the information for the required period.

5. Disclosure of Personal Information (APP 6)

We do not disclose personal information to third parties without your consent, except in the following circumstances:

  • Where required or authorised by Australian law or a court/tribunal order
  • Disclosure to law enforcement and diplomatic missions (Law Enforcement Disclosure): We do not voluntarily disclose records such as IP addresses to third parties without your consent. However, we may disclose them to law enforcement agencies (Australian Police) and overseas diplomatic missions (embassies) only where required or permitted by a court order, warrant, or law (APP 6). This also covers permitted general situations under section 16A of the Privacy Act (e.g. to lessen or prevent a serious threat to life, health, or safety).
  • For law enforcement purposes in accordance with APP 6.2(e)

6. Cookies

The Service uses cookies to enhance user experience. In accordance with the Privacy Act 2024 amendments, non-essential cookies are activated only after obtaining your explicit consent.

Essential Cookies

Required for login session management, CSRF protection, and security. These cookies are always active as the Service cannot function without them.

Analytics Cookies

Google Analytics 4 (GA4) collects anonymised statistical data such as visitor count, page views, and session duration to improve service quality. GA4 scripts are not loaded unless you consent.

Functional Cookies

Used to remember your preferences such as dark/light mode and language selection. Disabling these cookies means you may need to reconfigure your settings on each visit.

You can manage your cookie preferences at any time via the Cookie Settings page. You may also configure cookies through your browser settings; however, blocking cookies may limit certain features of the Service.

7. Security of Personal Information (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure, including:

  • Password encryption using bcrypt hashing
  • HTTPS encryption for all data in transit
  • Access control management and log monitoring
  • Regular security reviews and assessments

8. Your Rights Under the APPs

Under the Australian Privacy Principles, you have the following rights:

  • Right of Access (APP 12): You may request access to the personal information we hold about you.
  • Right of Correction (APP 13): You may request correction of any inaccurate, out-of-date, incomplete, or misleading personal information.
  • Right of Deletion: You may request deletion of your personal information by deleting your account.
  • Right to Complain: You may lodge a complaint about our handling of your personal information using the contact details below.

We will respond to access and correction requests within 30 days as required by the Privacy Act 1988.

9. Cross-border Disclosure (APP 8)

In order to operate the Service, we use the following external services which may involve the transfer of personal information to overseas servers:

  • Google Analytics (United States): Anonymised visitor statistics (only when analytics cookies are consented to)
  • Google OAuth (United States): Social login authentication processing
  • Cloudinary (United States/Europe): Image hosting and optimisation

In addition, personal information may be transferred to overseas servers through Cloudflare (edge network — IP address processing) and Sentry (error log collection). Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles, in accordance with APP 8.

10. Automated Decision-Making

The Service performs the following automated processing which may affect your experience:

  • Trending Algorithm: Automatically selects and displays popular posts based on aggregated interaction data (views, comments, likes). No personal information is directly used.
  • Personalised Content: Displays posts from your selected region of interest as a priority.
  • Automated Security Analysis (Bot / IP Reputation Classification): To protect the service, we may automatically analyse technical characteristics of access requests (the User-Agent and the presence of standard supplementary headers that browsers send automatically) and per-IP access patterns to classify bot/automated traffic. This classification may be used for statistics and security analysis, for excluding fraudulent clicks from partner settlements, for requesting an additional security check (CAPTCHA) during sign-up to prevent spam, and as a supporting signal when assessing restrictions on abnormal connections (IP); it does not block the viewing of pages themselves. The original values of supplementary headers (client hints and language settings) are not stored — only derived classification results are retained, and the User-Agent is kept separately as part of the access log (see the table in Section 4).

The Service does not engage in fully automated decision-making that has a significant effect on your legal rights.

11. Notifiable Data Breaches (NDB Scheme)

In the event of an eligible data breach as defined under Part IIIC of the Privacy Act 1988, we will:

  • Conduct a reasonable and expeditious assessment within 30 days of becoming aware of the breach
  • Notify the Office of the Australian Information Commissioner (OAIC) if the breach is likely to result in serious harm
  • Notify affected individuals as soon as practicable, including a description of the breach and recommended steps

12. Contact Us

For enquiries or complaints regarding the handling of your personal information, please contact us:

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au

This Privacy Policy is effective from 25 March 2026.

Last updated: 2 July 2026