Privacy Policy
No account. We do not ask for your name, email, phone number, or location.
Effective 14 September 2026
There is no account
No sign-up, no log-in. We never ask for a name, email, phone number, date of birth, or gender. There is no field to enter them in.
As a result there is nothing on our server that could be called "your profile".
We do not use your location
We never request GPS, cell-tower, or Wi-Fi location. The browser permission prompt never appears because we never call for it.
You pick a region from a list yourself. This service is therefore outside the scope of Korea’s Location Information Act registration.
Five cookies stay on this device
yr_vid180 days- A random number. It is used only as a seed so recommendations differ between people. If everyone were sent to the same three places, those three would become the next crowded spot. It is not derived from any personal data and never leaves our server.
yr_pref180 days- The interest categories you picked, so we do not have to ask again on every screen.
yr_plan180 days- The plans you saved: region code and date, nothing else.
yr_area90 days- The last five-digit district code you viewed, so the home screen can offer one link back.
yr_seen365 days- Whether you have seen the intro screen. The value carries no meaning; only its presence matters.
All five are httpOnly, so scripts on the page cannot read them.
There are no advertising or analytics cookies. We embed no third-party trackers.
Clearing site data in your browser or app removes all of them. We hold no copy, so that is the whole of deletion.
Only a single number stays on the server
Saving a plan increments one line on the server.
50110:20260822 → 37
It means "37 people plan to be in this district on this date". We do not record who, from which device, at what time, or in what order. With no per-person record, this is a statistic rather than information about a person.
It is deleted automatically 7 days after the travel date.
If the number is below 5 we do not show it at all. In a small district, a count of 1 on some day would be a clue to anyone who knows that person.
The plan itself, where and when, never reaches the server; it lives in this device’s cookie. All the server receives is "add one".
Never in the address bar
Saving a plan is sent in the request body, not the URL. In the URL it would land in access logs alongside your IP and timestamp, reconstructing exactly what we chose not to store. Not storing something and not leaking it are two different jobs.
What leaves our server
- Vercel (hosting)
- Access logs (IP, timestamp, requested path) for operations and incident response, retained and deleted under Vercel’s own policy.
- Korea Tourism Organization TourAPI
- Only query conditions such as region code and date. Our server makes the call, so your IP is never passed on.
- Upstash (counter store)
- Only the number described above.
- Kakao Map
- When you open a map, your browser requests map tiles from Kakao directly, which passes your IP and the usual connection details to Kakao. No map, no request.
- YouTube (Google)
- Your browser loads the video card’s preview image from YouTube’s servers directly, which passes your IP and the usual connection details to Google. Tapping the card opens YouTube.
None of the above receives personal data: no name, no contact, no location. What leaves is a region code and a date, plus the ordinary connection details a browser sends when it fetches an image.
There is no analytics tool, no ad network, no third-party tracking SDK. Nobody processes user data on our behalf, so there is nothing entrusted and nothing transferred abroad.
The map and the video thumbnails are fetched by your browser straight from Kakao and Google. The connection details that reach them are covered by those companies’ own policies, and if you never open the map the request never happens.
The plan transfer link
The address you use to move plans to another device, or to send them to a travel companion, carries region codes and dates only.
Anyone holding that address can see that list of plans, so where you send it is your call.
Security
Everything is served over HTTPS. A request to http is redirected, and the browser is given a two-year HSTS so that it stops trying http at all.
All five cookies are Secure, HttpOnly and SameSite. They travel only over the encrypted connection, and no script on the page can read them.
The Korea Tourism Organization key lives on the server only. It is in neither the page code nor the app bundle, so opening the developer tools will not reveal it.
We took the view that the surest protection is not holding anything. We ask for no name, no contact, no location, so there is no personal data on the server to protect.
Children under 14
We collect no personal data, so we do not ask for age.
Your rights
Because we collect no personal data, there is nothing on the server to request access to, correct, or delete.
Everything held on this device can be erased immediately by clearing site data in your browser or app settings.
Contact
Yeoyuro team · yeoyuro.help@gmail.com
Where to complain
You may take a complaint to the Korean bodies below. They are independent of us, and you do not need to come to us first.
- Personal Information Dispute Mediation Committee
- 1833-6972 · www.kopico.go.kr
- Privacy Infringement Report Centre (KISA)
- 118 · privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cybercrime
- 1301 · www.spo.go.kr
- Korean National Police Agency, Cybercrime
- 182 · ecrm.police.go.kr
Changes
Any change is posted on this page with a new effective date.
