개인정보 처리방침

시행일 2026-10-03 · v1.0

이 방침은 Fantagram Inc.(이하 “우리”)가 운영하는 Krypton 앱과 krypton.today(이하 “서비스”)에 적용됩니다. 우리가 무엇을 받고, 무엇을 받지 않으며, 무엇을 읽을 수 없는지를 적습니다. 서비스를 쓰는 약속은 이용약관에 있습니다.

한눈에

  • 가입·로그인에 전화번호·이메일을 받지 않습니다. 계정은 기기 안의 열쇠로만 만들고 들어옵니다.
  • 이름·소개·사진, 글·답·영상은 기기에서 봉인되어 서버에 갑니다. 서버와 운영자는 이를 열 열쇠가 없습니다.
  • 대신 서버는 계정 번호들이 서로 어떻게 이어져 있는지(연결 지도)와 누가 언제 누구에게 무엇을 보냈는지 같은 겉 정보는 압니다.
  • 운영자는 신고된 것과, Krypton 팀에게 직접 보낸 가입 요청만 봅니다. 신고된 것은 신고한 사람의 기기가 운영자에게 열어 줍니다.
  • Krypton+ 결제는 스토어가 처리합니다. 카드 번호나 Apple ID는 우리에게 오지 않습니다.
  • 광고를 하지 않고, 개인정보를 팔지 않으며, 추적에 쓰지 않습니다.

1받지 않는 정보

  • 가입·로그인에 쓰는 전화번호·이메일 주소, 주민등록번호 등 신원을 확인하는 번호 (메일로 문의하면 그 메일은 받습니다 — 2절)
  • 기기의 주소록, 위치, 광고 식별자
  • 되찾기 PIN 그 자체 (확인용으로 섞은 값만 받습니다 — 2절)
  • 초대 링크·초대 요청 링크·QR에 담긴 이름 (링크의 # 뒤에 있어 서버로 오지 않습니다). 초대 링크의 비밀도 서버로 오지 않습니다. 초대 요청 링크와 1촌 맺기 QR의 비밀은, 그것을 연 회원의 앱이 맞는지 확인받으려고 서버에 보냅니다. 서버는 미리 받아 둔 섞은 값과 대조만 하고 저장하지 않습니다.
  • 링크 미리보기를 만들 때 어떤 주소를 열었는지 (쓰는 사람의 기기가 그 사이트에 직접 접속합니다 — 3절)
  • 카드 번호, Apple ID 같은 결제 정보 (Krypton+ 결제는 스토어가 다룹니다 — 2절)

앱이 묻는 권한 (모두 선택)

카메라
1촌 맺기 QR이나 초대 요청 QR을 찍을 때. 찍은 화면은 기기 안에서만 읽고, 저장하거나 보내지 않습니다.
사진
글·프로필에 붙일 사진·영상을 고를 때, 그리고 사진·영상을 사진첩에 저장할 때(저장에는 쓰기 권한만 묻습니다). 고른 것만 기기에서 줄이고 봉인한 뒤 올립니다.
알림
알림을 받을 때.

허락하지 않아도 그 기능 말고는 Krypton을 쓸 수 있고, 권한은 기기 설정에서 언제든 끌 수 있습니다. 마이크·위치·주소록 권한은 묻지 않습니다.

2서버가 아는 정보

서비스가 돌아가려면 서버가 알아야 하는 것들입니다. 이 정보는 봉인되지 않습니다. 마지막 줄의 문의·요청 메일은 서버가 아니라 우리 메일함으로 옵니다.

계정 번호
가입할 때 만드는 무작위 번호. 이름과 이어져 있지 않습니다.
공개 열쇠
계정의 서명·암호화 공개 열쇠, 기기별 공개 열쇠와 기기 인증서.로그인, 누가 보냈는지 확인, 나에게 봉인할 때
가입 상태와 회원 번호
가입 대기·정식 회원·정지 여부, 역할(창립자·Krypton 팀·회원 등), 정식 회원이 된 순서, Krypton+ 기간 — 직접 산 기간과 창립자가 준 기간(준 사람 포함).가입 절차, Krypton+ 기능(사진 수·영상 길이·원본 화질·예약 전송) 판정
연결 지도
누가 누구와 1촌인지, 누가 누구를 초대하고 대부(추천인)가 되었는지, 누가 누구에게 초대를 맡겼는지, 1촌 청·소개와 그 답(수락·넘기기), 새 1촌에게 지난 글을 누가 누구에게 몇 개 이어 줬는지, 그리고 각각의 시각.글을 받을 사람 계산, 보증으로 들어오는 가입, 지난 글을 한 사람에게 한 번만 이어 주기
글의 겉 정보
쓴 사람, 쓴 때·고친 때, 공개 범위(1촌·골라서·나만), 봉투를 받은 사람(=그 글을 열 수 있는 사람), 예약한 시각, 사라지는 시각, 대화를 막았는지와 막고 연 때, 골라서 보낸 글이라는 표시(건네기를 막은 글), 대화를 나눈 두 사람과 그 수·시각, 누가 누구에게 글을 건넸는지, 사진·영상 파일의 크기·가로세로·길이.글 전달, 소식 순서, 예약 전송과 사라지는 글, 파일 자리 잡기
초대
초대한 사람(두 사람, 또는 혼자 초대할 수 있는 한 사람), 진행 상태, 만료 시각, 초대에 적은 이름을 링크에만 있는 값과 섞은 확인값(서버는 이 값만으로 이름을 알 수 없습니다), 이름을 틀린 횟수(다섯 번이면 초대가 취소됩니다).
초대 요청
요청한 계정, 링크 비밀을 섞은 값, 상태(기다림·받음·모르는 분·거둠·끝남), 답한 회원, 붙은 초대장, 만든 시각과 만료(7일). Krypton 팀에게 보낸 요청이면 팀 기기만 여는 봉인된 소개와, 가입 남용을 가리는 표시 — 같은 날 같은 곳에서 시작한 계정 수, 계정을 만들고 요청하기까지 걸린 시간 — 가 더해집니다.요청을 받은 회원의 초대를 요청한 사람에게 잇기, Krypton 팀 요청 판별
가입 시작 기록
초대장 없이 가입을 시작할 때의 접속 IP를 날마다 바뀌는 열쇠로 섞은 확인값(IP 자체가 아닙니다)과, 그때 만든 계정 번호·시각. 이틀이 지난 기록은 매일 자동으로 지웁니다.계정을 마구 만드는 것 막기, Krypton 팀 요청 판별
만나서 1촌(QR)
내 QR 코드 번호와 그 비밀을 섞은 값(코드는 5분만 쓰입니다), 그 QR로 1촌을 청한 계정과 시각. 만료 하루 뒤 지웁니다. 청 자체는 연결 지도에 남습니다.QR로 1촌 맺기
차단·신고
누가 누구의 글을 안 보기로 했는지, 누가 무엇을 어떤 사유로 신고했는지와 그 처리 상태.
알림
기기의 알림 토큰, 기기 종류, 알림 언어(한국어·English·日本語), 알림 종류별 켜고 끄기(대화·캡처·사진 저장·요청), 알림을 보낸 기록(받는 계정·종류·시각·전달 여부). 계정을 되찾으려는 요청의 알림은 끌 수 없습니다.
설정
새 1촌에게 ‘내 지난 글 보여 주기’를 켰는지 껐는지.지난 글 이어 주기
화면 캡처 시도와 사진·영상 저장
누가 누구의 화면을 어디서(대화·사람 페이지·글·소식) 캡처하려 했는지와 그 시각. 누가 누구의 어느 피드 글 사진·영상을 사진첩에 저장했는지(같은 글은 한 번만 적고, 대화 사진 저장은 적지 않습니다).그 화면과 글의 주인에게 알리기 위해
기기
기기별 마지막 로그인 시각, 해제 여부.
되찾을 방법
준비한 경우에만 — 봉인된 보관본, 서버가 맡는 조각, PIN을 확인하는 섞은 값과 틀린 횟수·잠긴 때, 열쇠 조각을 맡은 1촌이 누구인지, 되찾기 요청의 진행 상태.서버 혼자서는 보관본을 열 수 없습니다. 1촌들이 맡은 조각이 있어야 합니다
Krypton+ 구매
Krypton+를 산 경우의 스토어(Apple·Google), 거래 번호, 상품, 이번 기간의 끝(평생 이용권은 끝이 없음), 환불·취소된 때, 운영·시험 구분. 구매할 때 계정 번호를 거래에 함께 실어, 스토어가 확인해 준 구매를 계정에 잇습니다. 카드 번호·Apple ID 같은 결제 정보는 스토어가 다루고 우리는 받지 않습니다.Krypton+ 기간 계산과 갱신·환불 반영, 같은 구매를 다른 계정이 쓰지 못하게, 법이 정한 거래 기록 보존
문의·요청 메일
support@krypton.today·privacy@krypton.today로 보낸 메일의 보낸 사람 이메일 주소, 내용, 붙인 자료(권리자임을 보이는 자료, 글을 특정할 화면 등). 회원이 아닌 사람이 보낸 권리 침해·삭제 요청도 같습니다.문의에 답하기, 이의·권리 침해·삭제·청약철회·권리 행사 요청 처리

3봉인된 채 보관하는 정보

아래는 기기에서 봉인한 뒤 서버에 보냅니다. 서버와 운영자에게는 이를 여는 열쇠가 없습니다.

  • 이름, 한 줄 소개, 프로필 사진, 대부 표시
  • 글, 답, 지인평, 사진, 영상 (파일은 암호문 그대로 저장소에 둡니다)
  • 링크 미리보기 — 쓰는 사람의 기기가 만들어 글과 함께 봉인합니다
  • 소개할 때 남긴 쪽지, 글을 건넬 때 적은 이유
  • 초대에 적은 이름, 기기 이름
  • QR로 1촌을 청할 때 보내는 내 이름 — QR 주인만 엽니다
  • Krypton 팀에게 요청할 때 쓰는 이름·한 줄 소개·누구와 쓸지 — 팀 기기만 엽니다
  • 대화 알림에 실리는 한 줄 — 받는 사람의 기기만 풉니다

봉인이 뜻하지 않는 것

  • 받은 사람은 읽습니다. 글은 받은 사람의 기기에서 열리고 그 기기에 남을 수 있습니다. 받은 사람은 사진을(Krypton+ 회원은 영상도) 사진첩에 저장할 수 있고, 저장된 사본은 봉인 밖에 있습니다.
  • 신고하면 운영자가 봅니다. 신고한 사람이 그 글이나 명함을 운영자에게 열어 줍니다(8절).
  • Krypton 팀에게 요청하면 팀이 읽습니다. 그 요청에 쓴 이름·소개·누구와 쓸지를 팀이 열어 보고 받을지 정합니다(8절).
  • 명함은 회원이면 누구나 봅니다. 이름·소개·흐린 사진은 모든 회원이 여는 열쇠로 봉인됩니다. 회원이 된 사람은 누구나 볼 수 있습니다.
  • 겉 정보는 봉인되지 않습니다. 2절의 정보는 서버가 압니다. 글은 길이를 감추려 크기 단위로 채워 봉인하지만, 사진·영상 파일의 크기는 드러납니다.

링크 미리보기를 만들 때 쓰는 사람의 기기가 그 사이트에 직접 접속하므로, 그 사이트는 쓰는 사람의 접속을 봅니다. 받는 사람의 기기는 링크를 누르기 전까지 그 사이트에 접속하지 않습니다.

4자동으로 남는 기록

  • 접속 IP 주소 — 우리 데이터베이스와 서버 함수 기록에는 남기지 않습니다. 예외는 초대 없이 가입을 시작할 때의 확인값 하나로, IP를 그날만 쓰는 값으로 섞어 두고, 이틀이 지난 기록은 매일 자동으로 지웁니다(2절). 서버를 제공하는 Supabase의 플랫폼 기록에는 접속 IP가 남고 7일 뒤 지워집니다. Cloudflare는 사진·영상과 웹페이지를 전달하며 접속 IP를 처리하고, 이 기록은 Cloudflare의 개인정보 처리방침과 Cloudflare가 정한 기간을 따릅니다. 파일 저장소 앞의 Cloudflare Worker 관측 기록은 꺼 두었습니다.
  • 알림 발송 기록, 기기별 마지막 로그인 시각, 화면 캡처 시도와 사진·영상 저장, 가입 시작 기록 — 2절

대화 화면에서 오가는 ‘새 말’과 ‘쓰는 중’ 신호는 서버(Supabase Realtime)를 거쳐 그 대화의 두 사람에게만 전달됩니다. 신호에는 내용이 없고, 신호 자체는 남지 않습니다.

앱에는 분석 도구, 광고 도구, 오류 수집 도구가 들어 있지 않습니다.

5이용 목적과 법적 근거

개인정보는 아래 목적으로만 씁니다. 목적마다 쓰는 정보와 그 근거를 함께 적습니다.

서비스 제공
가입(두 사람 보증, 초대 요청, Krypton 팀 요청), 로그인, 글·답·사진·영상의 전달, 1촌 맺기(만나서 QR 포함)와 소개, 건네기, 새 1촌에게 지난 글 이어 주기, 예약 전송, 사라지는 글, 되찾기쓰는 정보 — 계정 번호·공개 열쇠, 가입 상태, 연결 지도, 글의 겉 정보, 봉인된 내용, 초대·초대 요청, QR, 설정, 기기, 되찾을 방법근거 — 계약 이행(개인정보 보호법 제15조 제1항 제4호, GDPR 제6조 제1항 (b))
알림
나를 기다리는 일, 새 대화, 새 1촌, 화면 캡처 시도, 내 사진·영상이 저장됨, 계정을 되찾으려는 요청을 알리기. 알림에는 이름도 내용도 싣지 않습니다.쓰는 정보 — 알림 토큰, 기기 종류, 알림 언어, 알림 설정, 알림 발송 기록근거 — 계약 이행(개인정보 보호법 제15조 제1항 제4호, GDPR 제6조 제1항 (b))
Krypton+ 제공
구매 확인, 갱신·해지·환불 반영, 같은 구매를 다른 계정이 쓰지 못하게 하기, 창립자가 준 Krypton+ 관리, 사진 수·영상 길이·원본 화질·예약 전송 한도 판정쓰는 정보 — Krypton+ 구매 기록, 가입 상태와 Krypton+ 기간근거 — 계약 이행(개인정보 보호법 제15조 제1항 제4호, GDPR 제6조 제1항 (b))
안전과 운영
신고 처리, 차단, 이용 제한, 초대 없는 계정 마구 만들기 막기, Krypton 팀 요청 판별, 화면 캡처 시도와 사진·영상 저장을 화면과 글의 주인에게 알리기, 운영자 작업 기록, 문의에 답하고 이의를 처리하기쓰는 정보 — 차단·신고 기록, 가입 시작 기록, 초대 요청의 판별 표시, 화면 캡처·저장 기록, 운영자 작업 기록, 문의·요청 메일근거 — 정당한 이익(개인정보 보호법 제15조 제1항 제6호, GDPR 제6조 제1항 (f)): 회원과 서비스를 남용에서 지키고, 화면과 글의 주인에게 알리기 위해
법이 요구하는 일
구매 기록 보존, 법에 따른 요청에 답하기, 아동 성착취물 신고, 권리 침해 글의 삭제 요청·청약철회·개인정보 권리 행사 처리쓰는 정보 — Krypton+ 구매 기록, 2절의 정보, 신고 사본, 문의·요청 메일근거 — 법적 의무(개인정보 보호법 제15조 제1항 제2호, GDPR 제6조 제1항 (c))

이 밖의 목적(광고, 판매, 프로필 분석 등)으로는 쓰지 않습니다.

  • 동의를 받아 처리하는 정보는 없습니다. 카메라·사진·알림은 기기에서 허락한 때만 쓰며, 기기 설정에서 언제든 끌 수 있습니다.
  • 2절의 정보는 서비스에 꼭 필요합니다(되찾을 방법과 Krypton+ 구매는 고른 사람만, 문의·요청 메일은 보낸 사람만). 주지 않으면 Krypton을 쓸 수 없습니다.
  • 정당한 이익에 근거한 처리에는 반대할 수 있습니다(13절).

우리는 건강·신념·정치적 견해 같은 민감한 정보를 받거나 따로 모으지 않습니다. 연결 지도는 누가 누구와 이어져 있는지만 알 뿐, 그 사람의 직업이나 관계의 성격은 모릅니다.

6다른 회원에게 보이는 것

모든 회원
명함 — 이름, 한 줄 소개, 대부, 흐린(모자이크) 프로필 사진.
2촌
반쯤 흐린 프로필 사진
1촌
원본 프로필 사진, 공개 범위 ‘1촌’으로 쓴 나의 글
골라서 받은 사람
나에게만 온 글이라는 ‘골라서’ 표시와 그 글. 그 글을 받은 다른 사람은 보이지 않습니다. 글쓴이는 받은 사람 목록을 봅니다.
새 1촌
내가 최근 30일 동안 공개 범위 ‘1촌’으로 쓴 글을 최대 30개까지 봅니다. 설정의 ‘내 지난 글 보여 주기’로 끌 수 있습니다.
답한 사람과 글쓴이
글에 단 답은 글쓴이와 답한 사람 둘만 봅니다. 공감은 글쓴이만 압니다.
건네받은 사람
받은 사람이 자기 1촌에게 글을 건네면, 건네받은 사람도 그 글을 봅니다. 골라서 보낸 글과 나만 보기 글은 건넬 수 없습니다.
화면의 주인
내가 다른 사람의 대화·페이지·글을 캡처하려 하면, 그 사람에게 알림이 가고 그 사람의 새 소식에 내 이름이 보입니다.
글쓴이(저장)
내가 피드 글의 사진·영상을 사진첩에 저장하면, 글쓴이에게 알림이 가고 그 사람의 새 소식에 내 이름이 보입니다. 대화 사진 저장은 알리지 않습니다.
QR 주인
내가 QR을 찍고 1촌을 청하면, 내 이름은 그 QR의 주인만 봅니다.
Krypton 팀
Krypton 팀에게 가입을 요청하면, 팀이 그 요청의 이름·소개·누구와 쓸지를 봅니다(8절).

명함(이름·한 줄 소개)은 모든 회원에게 보입니다. 건강·신념처럼 민감한 내용은 명함에 쓰지 마십시오. 글은 공개 범위(1촌·골라서·나만)로 볼 사람을 정할 수 있습니다.

7보관 기간과 파기

정보마다 아래 기간 동안 두고, 기간이 지나면 지웁니다. 지금 쓰이지 않는 관계의 흔적은 매일 한 번 자동으로 지웁니다.

끊긴 1촌
끊은 지 30일
답이 없는 1촌 청·소개
마지막 움직임에서 30일
“넘기기” 기록
180일
쓰이지 않은 초대
만료·취소 뒤 30일 (가입에 쓰인 초대는 대부 기록과 함께 남습니다)
로그인 확인값
만료 뒤 1일
처리한 신고
처리가 끝났고 신고한 지 180일이 지나면 (처리 전인 신고는 남습니다. 법이 보존을 요구하는 신고 — 예: 미국 NCMEC에 알린 것은 알린 날부터 1년 — 는 그 기간 동안 둡니다)
화면 캡처 시도와 사진·영상 저장
30일
알림 발송 기록
30일
사라지는 글
24시간 (쓸 때 고르면 나타난 때부터, 나중에 고르면 그때부터). 글·대화·사진 기록은 1분 안에, 사진·영상 파일은 곧이어 저장소에서 지웁니다.
가입 시작 기록(IP 확인값)
이틀 (매일 자동으로 지웁니다)
QR 코드와 그 청 기록
만료 하루 뒤
초대 요청, 지난 글을 이어 준 기록
계정을 쓰는 동안 (계정을 없애면 함께 지웁니다 — 12절)
Krypton+ 구매 기록
거래로부터 5년 (전자상거래법이 정한 대금 결제 기록 보존 기간). 다만 아직 쓰고 있는 이용권(끝나지 않은 평생 이용권)의 기록은 그 계정이 있는 동안 둡니다.
문의·요청 메일
처리를 마친 날부터 3년 (전자상거래법이 정한 소비자 불만·분쟁 처리 기록 보존 기간)
운영자 작업 기록
조치한 날부터 3년 동안 고칠 수 없게 남기고, 그 뒤 지웁니다
그 밖의 정보
계정을 쓰는 동안. 계정을 없앤 뒤 지우는 것과 남는 것은 12절에 적었습니다.

보관 기간이 끝나거나 목적을 이루면 지체 없이 지웁니다. 데이터베이스의 행을 지우고 사진·영상 파일은 저장소에서 지워, 다시 되살릴 수 없게 합니다. 지운 정보는 운영 데이터베이스의 매일 백업에 최대 7일 남았다가 사라집니다(백업은 장애 복구에만 씁니다). 법령 때문에 보관하는 구매 기록은 다른 정보와 나눠 두고 그 목적에만 씁니다.

8신고와 운영자 열람

운영자는 올라오는 글을 볼 수 없고, 볼 수 있게 하는 장치도 두지 않았습니다. 대신 신고할 때 신고하는 사람의 기기가 그 대상을 운영자에게 열어 줍니다.

운영자가 신고된 것을 보는 것은 약관 위반과 불법 정보에 대응하고 법이 요구하는 조치를 하기 위해서입니다(5절 — 정당한 이익·법적 의무).

글·답을 신고하면
운영자는 신고 시점의 그 글·답과, 거기 붙은 사진·영상(파일이 아직 있으면), 그리고 쓴 사람의 이름을 봅니다. 사라지는 글이 지워지거나 글이 나중에 지워져도, 신고 시점의 봉인본은 신고 기록과 함께 남습니다.
사람을 신고하면
운영자는 그 사람의 명함(이름·소개·흐린 사진)을 봅니다. 원본 사진은 가지 않습니다.
Krypton 팀에게 요청하면
팀 기기가 봉인을 풀어 이름·한 줄 소개·누구와 쓸지를 보고, 같은 날 같은 곳에서 시작한 계정 수와 계정을 만들고 요청하기까지 걸린 시간을 함께 봅니다. 팀은 이를 보고 받을지 정합니다.
운영자가 함께 보는 겉 정보
신고한 사람과 신고된 사람의 계정 번호, 사유, 시각. 계정마다 상태·역할·가입·삭제 시각·회원 번호·Krypton+ 기간·1촌 수·대부 수·기기 수·신고 수. 이름은 없습니다.
운영자 작업 기록
누가 언제 어떤 조치(정지·해제·신고 처리, 창립자의 Krypton+ 주기·거두기)를 어느 계정에 했는지와 그 메모를, 조치한 날부터 3년 동안 고치거나 지울 수 없게 남깁니다(7절).
보지 않는 것
신고되지 않은 글, 신고된 글이 아닌 그 사람의 다른 글과 대화

조치를 하면 신고된 회원에게 사유를 알립니다(앱 안 통지가 준비되기 전에는 support@krypton.today로 물으면 답합니다). 누가 신고했는지는 알리지 않습니다. 이의는 이용약관 6절의 절차를 따릅니다.

신고 사본은 운영자가 열 수 있으므로, 법에 따른 요청이 있으면 신고 기록과 함께 제공될 수 있습니다(9절).

처리한 신고는 처리가 끝났고 신고한 지 180일이 지나면 지웁니다(처리 전인 신고는 남습니다. 법이 보존을 요구하는 신고 — 예: 미국 NCMEC에 알린 것은 알린 날부터 1년 — 는 그 기간 동안 둡니다. 7절). 신고한 사람의 계정 번호가 기록에 남으므로 신고를 남용하면 드러납니다.

9제3자 제공

개인정보를 팔거나 광고·마케팅 목적으로 다른 회사에 넘기지 않습니다. 다음 경우에만 제공합니다.

  • 법령에 따른 요구 — 영장 등 법이 정한 절차를 갖춘 요청인지 확인한 뒤 필요한 만큼만 줍니다. 줄 수 있는 것은 서버가 아는 정보(2절)와 신고로 운영자에게 열린 사본(8절)뿐이며, 그 밖의 봉인된 내용은 우리도 열 수 없습니다. 법이 허용하는 범위에서 해당 회원에게 알립니다.
  • 아동 성착취물 신고 — 아동 성착취물을 발견하면 법에 따라 미국 NCMEC(실종·착취 아동 센터)와 관계 기관에 신고하며, 그 콘텐츠와 관련 계정 정보를 함께 보냅니다.
  • 급박한 위험 — 사람의 생명·신체에 급박한 위험이 분명할 때, 그 위험을 막는 데 필요한 만큼만 수사기관 등 관계 기관에 알립니다.
  • Krypton+ 결제 — 회원이 Krypton+를 살 때는 결제를 처리하는 스토어(지금은 Apple이며, Android의 Google Play 결제는 준비 중입니다)에 계정 번호(무작위 번호)가 거래와 함께 전달됩니다. 우리는 스토어에서 거래 번호·상품·기간·환불 여부만 받습니다. 스토어는 자기 개인정보 처리방침에 따라 결제 정보를 다룹니다.

10처리 위탁

서비스를 돌리는 데 아래 회사에 일을 맡깁니다. 이들이 다루는 것은 봉인된 암호문, 2절의 정보, 그리고 전달 중의 접속 정보입니다.

Supabase, Inc.
데이터베이스, 서버 함수, Realtime(대화의 실시간 신호)
Cloudflare, Inc.
사진·영상 파일(암호문) 저장과 전달 — R2와 Workers. krypton.today 웹사이트와 초대·초대 요청·QR 링크 페이지 전달 — Pages. support@·privacy@krypton.today로 오는 메일을 우리 메일함으로 넘기기 — Email Routing
Zoho Corporation
우리 메일함 — support@·privacy@krypton.today로 받은 문의·요청 메일을 보관합니다
Apple Inc.
아이폰 알림 전달(Apple Push Notification service). 기기 알림 토큰과 알림 문구를 넘깁니다. 문구에는 이름도 내용도 없습니다. 대화 알림에는 받는 사람의 기기만 풀 수 있게 봉인한 한 줄이 함께 실리고, Apple은 그 암호문만 봅니다. Apple은 토큰이 어느 기기의 것인지 압니다.
Google LLC
안드로이드 알림 전달(Firebase Cloud Messaging). 기기 알림 토큰과 이름·내용 없는 알림 문구를 넘깁니다. 대화 알림에는 받는 사람의 기기만 풀 수 있게 봉인한 한 줄이 함께 실리고, Google은 그 암호문만 봅니다. Google은 토큰이 어느 기기의 것인지 압니다.

우리는 이 회사들과 데이터 처리 계약을 맺어, 맡긴 일 밖에서는 정보를 쓰지 않고 이 방침과 같거나 그 이상의 수준으로 보호하게 합니다. 다른 회사에 다시 맡기는 것도 그 계약이 정한 대로만 합니다. 맡기는 회사가 바뀌면 이 방침을 고쳐 알립니다.

Krypton+ 결제는 스토어가 자기 책임으로 처리하므로 위탁이 아니라 9절에 적습니다.

11국외 이전

서비스를 쓰는 동안 정보는 네트워크를 통해 수시로 아래 나라로 옮겨져 보관·처리됩니다. 옮길 때는 모두 암호화된 연결(HTTPS)을 씁니다.

Fantagram Inc.
  • 나라미국·대한민국
  • 언제·어떻게운영자가 운영과 신고 처리를 위해 암호화된 연결로 운영자 페이지에 접속할 때
  • 항목2절의 정보, 신고 사본, Krypton 팀 요청
  • 목적서비스 운영, 신고 처리, 가입 요청 확인
  • 보유 기간7절
  • 연락처privacy@krypton.today
Supabase, Inc.
  • 나라대한민국 서울(AWS)에 보관, 운영사는 미국. 서버 함수는 앱을 쓰는 곳과 가장 가까운 Supabase 지역에서 처리하는 동안만 실행되며, 그 나라는 대한민국·일본·싱가포르·인도·호주·미국·캐나다·브라질·아일랜드·영국·프랑스·독일·스위스 가운데 하나입니다.
  • 언제·어떻게앱을 쓸 때마다 암호화된 연결로
  • 항목2절·3절의 정보(3절은 암호문)
  • 목적데이터베이스, 서버 함수, 실시간 신호
  • 보유 기간7절 (지운 정보는 백업에 최대 7일 더)
  • 연락처privacy@supabase.com
Cloudflare, Inc.
  • 나라파일 저장은 Cloudflare가 아시아·태평양 지역에 두는 데이터센터(Cloudflare는 그 나라를 밝히지 않으며, 지역도 보장하지 않습니다), 전달은 이용자와 가까운 전 세계의 Cloudflare 데이터센터. 본사는 미국
  • 언제·어떻게사진·영상을 올리고 받을 때, krypton.today를 열 때
  • 항목사진·영상 파일의 암호문, 전달 중의 접속 IP
  • 목적파일 저장·전달, 웹사이트 제공
  • 보유 기간파일은 글이 지워질 때까지, 접속 기록은 Cloudflare가 정한 기간
  • 연락처privacyquestions@cloudflare.com
Apple Inc.
  • 나라미국
  • 언제·어떻게아이폰에 알림을 보낼 때, Krypton+를 살 때
  • 항목알림 토큰, 이름·내용 없는 알림 문구, 대화 알림의 봉인된 한 줄, Krypton+를 살 때 거래에 싣는 계정 번호(9절)
  • 목적아이폰 알림, Krypton+ 결제를 계정에 잇기
  • 보유 기간알림은 전달하는 동안, 거래 기록은 Apple의 개인정보 처리방침을 따릅니다
  • 연락처Apple 개인정보 문의
Google LLC
  • 나라미국
  • 언제·어떻게안드로이드에 알림을 보낼 때
  • 항목알림 토큰, 이름·내용 없는 알림 문구, 대화 알림의 봉인된 한 줄
  • 목적안드로이드 알림
  • 보유 기간전달하는 동안
  • 연락처Google 개인정보 문의 양식
Cloudflare, Inc. (Email Routing)
  • 나라이용자와 가까운 전 세계의 Cloudflare 데이터센터. 본사는 미국
  • 언제·어떻게support@·privacy@krypton.today로 메일을 보낼 때, 우리 메일함으로 넘기는 동안
  • 항목보낸 사람의 메일 주소, 메일에 적은 이름과 내용
  • 목적문의·요청 메일을 우리 메일함으로 넘기기
  • 보유 기간넘기는 동안만 다루고 보관하지 않습니다. 전달 기록은 Cloudflare가 정한 기간
  • 연락처privacyquestions@cloudflare.com
Zoho Corporation
  • 나라미국
  • 언제·어떻게문의·요청 메일이 우리 메일함에 들어올 때
  • 항목보낸 사람의 메일 주소, 메일에 적은 이름과 내용
  • 목적문의·요청에 답하기
  • 보유 기간7절
  • 연락처privacy@zohocorp.com
Google LLC (Google Fonts)
  • 나라미국
  • 언제·어떻게krypton.today를 열 때 브라우저가 직접
  • 항목접속 IP, 브라우저 정보, 요청 주소
  • 목적웹사이트 글꼴 받기
  • 보유 기간Google의 개인정보 처리방침을 따릅니다
  • 연락처Google 개인정보 문의 양식

이 이전 없이는 서비스를 제공할 수 없습니다. 원하지 않으면 계정을 없애 이전을 멈출 수 있습니다(12절).

EU·영국 — 대한민국은 EU와 영국이 개인정보 보호 수준이 적정하다고 인정한 나라입니다. 그 밖의 나라로 옮길 때는 적정성 결정이나 EU 표준계약조항 같은 보호 장치를 쓰며, 그 사본은 privacy@krypton.today로 요청할 수 있습니다.

일본 — 받는 회사들이 일본 법이 요구하는 수준의 조치를 하도록 계약으로 정했습니다. 요청하면 그 내용과 각 나라 제도에 관한 정보를 알려 드립니다(나라별 제도는 일본 個人情報保護委員会의 ‘外国における個人情報の保護に関する制度等の調査’).

12계정 삭제

Krypton(운영: Fantagram Inc.) 계정을 없애는 방법입니다. 앱의 설정 맨 아래 계정 없애기에서 직접 지웁니다. 계정 열쇠가 있는 그 기기에서만 할 수 있습니다. 가입 대기 중이거나 이용이 정지된 계정은 앱에서 지울 수 없으니, 아래 ‘앱을 쓸 수 없을 때’대로 privacy@krypton.today로 요청하십시오. 되돌릴 수 없습니다.

계정을 없애도 스토어의 자동 갱신 구독은 저절로 해지되지 않습니다. 먼저 기기의 스토어 구독 설정(Krypton 설정의 [구독 관리])에서 해지하십시오. Krypton+는 산 계정 하나에만 적용되므로, 계정을 없애면 남은 기간(평생 이용권 포함)은 다른 계정으로 옮기거나 되살릴 수 없습니다.

지우는 것

  • 내가 쓴 글·답·지인평과 그 사진·영상 파일, 내 글에 달린 대화
  • 내 프로필과 그 봉투, 나에게 온 봉투 전부 (남의 글을 더는 열 수 없습니다)
  • 기기 정보와 알림 토큰, 되찾을 방법과 내가 맡은 열쇠 조각, 되찾기 요청, 넘기기 기록, 회원 열쇠 봉투, 암호화 공개 열쇠
  • 회원 번호와 Krypton+ 기간(창립자가 준 기록 포함), 차단 기록(내가 한 것과 나에게 걸린 것), 알림 설정, 내가 보낸 초대 요청(Krypton 팀에게 보낸 봉인된 소개 포함), 지난 글을 이어 준 기록(내가 이어 준 것과 내가 받은 것)

끊거나 거두는 것

  • 1촌 관계를 모두 끊습니다 (끊긴 기록은 30일 뒤 지워집니다)
  • 내가 보낸 진행 중인 초대를 취소합니다

남는 것

계정 번호와 상태
계정 번호, 서명용 공개 열쇠, 가입·삭제 시각과 상태. 다른 회원의 대부 기록이 이 번호를 가리켜 보증 사슬을 확인하는 데 필요하므로, 서비스를 운영하는 동안 둡니다. 이름은 원래 서버에 없습니다.
대부 기록
누가 누구를 들어오게 했는지. 같은 까닭으로 서비스를 운영하는 동안 둡니다.
신고 기록
처리가 끝났고 신고한 지 180일이 지나면 지웁니다. 법이 보존을 요구하면 그 기간 동안 둡니다.
Krypton+ 구매 기록
거래로부터 5년(전자상거래법)이 지나면 지웁니다. 계정을 없앤 뒤에는 평생 이용권의 기록도 같습니다.
그 밖에 남는 기록
내가 글을 건넨 기록(누구에게 건넸는지와 봉인된 이유)과 다른 회원이 나에게 글을 건넨 기록 — 건넨 길을 다른 회원의 화면에 보이는 데 쓰이며, 그 글이 지워지면 함께 지워집니다. 초대를 맡은 기록. 계정을 없앤 뒤에도 남습니다.
기간이 정해진 기록
알림 발송 기록(30일), 화면 캡처·저장 기록(30일), 가입 시작 기록(이틀), QR 코드와 그 청(만료 하루 뒤), 문의·요청 메일(처리를 마친 날부터 3년) — 7절의 기간이 지나면 지웁니다.
운영자 작업 기록
7절대로 3년 뒤 지웁니다.
다른 사람에게 간 것
이미 다른 사람의 기기로 간 글과 사진, 받은 사람이 사진첩에 저장한 사본은 거둘 수 없습니다. 다른 사람이 나에게 쓴 답은 그 사람의 것으로 남습니다.

앱을 쓸 수 없을 때

계정 열쇠가 있는 기기가 없으면 되찾을 방법으로 계정을 되찾은 뒤 지우십시오. 되찾을 방법이 없거나, 가입 대기 중이거나 이용이 정지된 계정이면 privacy@krypton.today로 요청하십시오. 우리는 이름·이메일을 받지 않아 계정 주인임을 확인할 수 없으면 지울 수 없지만, 그 계정의 내용은 우리가 열 수 없는 암호문입니다.

13이용자의 권리와 행사 방법

자기 개인정보를 열람하고, 고치고, 지우고, 처리를 멈추라고 요구할 권리가 있습니다. EU·영국 이용자는 처리를 제한하라고 요구할 권리, 이동권, 정당한 이익에 근거한 처리에 반대할 권리, 감독기관에 민원을 낼 권리도 있습니다.

앱에서 바로

  • 프로필 고치기, 글 고치기(올린 뒤 10분까지)·지우기, 사라지는 글로 바꾸기, 대화 막기
  • 1촌 끊기, 글 안 보기, ‘내 지난 글 보여 주기’ 끄기
  • 알림 종류별 끄기(대화·캡처·사진 저장·요청), [구독 관리]
  • 계정 없애기(12절)

연락해서 요청하기

  • 보내는 곳 — privacy@krypton.today. 요청은 무료입니다.
  • 본인 확인 — 우리는 이름·이메일을 모르므로 그 계정의 열쇠로 한 서명으로 확인합니다. 기기를 잃었다면 되찾을 방법으로 계정을 되찾은 뒤 요청하십시오. 확인할 수 없으면 법이 허용하는 범위에서 요청을 처리하지 못할 수 있습니다.
  • 대리인 — 대리인도 요청할 수 있습니다. 회원 본인의 위임과, 본인 확인을 위한 그 계정 열쇠의 서명이 필요합니다.
  • 열람·사본 — 봉인된 내용은 우리가 열 수 없어, 서버가 아는 정보(2절)를 드립니다. 봉인된 내용은 앱에서 직접 볼 수 있습니다.

답하는 기한

요청을 받으면 10일 안에 답합니다. 그 안에 하기 어려우면 까닭과 언제까지 할지 알립니다(EU·영국 거주자에게는 법이 정한 1개월 안).

우리는 사람의 개입 없이 회원의 권리에 중대한 영향을 주는 자동화된 결정을 하지 않습니다.

도움을 받을 수 있는 곳

답을 받지 못했거나 처리가 부당하다고 느끼면 아래 기관에 도움을 청할 수 있습니다.

  • 개인정보분쟁조정위원회 1833-6972 (kopico.go.kr)
  • 개인정보침해신고센터 118 (privacy.kisa.or.kr)
  • 대검찰청 1301 (spo.go.kr)
  • 경찰청 182 (ecrm.police.go.kr)
  • EU·영국 거주자 — 거주국 감독기관
  • 일본 거주자 — 個人情報保護委員会

14아동

Krypton은 만 18세 이상을 위한 서비스입니다. 만 14세 미만 아동을 포함해 18세 미만의 개인정보를 알면서 받지 않으며, 초대하고 보증하는 회원도 18세 미만을 들이지 않아야 합니다. 18세 미만이 가입한 것을 알게 되면 계정을 닫고 그 정보를 지웁니다. 그런 경우를 알게 되면 privacy@krypton.today로 알려 주십시오.

15안전 조치와 그 한계

관리적 조치

  • 개인정보를 다루는 사람을 최소한의 운영자로 한정합니다. 운영자 권한은 앱 계정과 따로 둔 운영자 페이지 계정으로 줍니다. 예외는 둘입니다 — Krypton 팀 요청은 팀 기기(팀 계정)에서 열어 보고, Krypton+를 주고 거두는 일은 창립자 앱에서 합니다.
  • 운영자가 바꾼 것(정지·해제·신고 처리, Krypton+ 주기·거두기)은 3년 동안 고칠 수도 지울 수도 없는 기록으로 남깁니다(7절).

기술적 조치

  • 글·프로필·파일은 기기에서 봉인합니다(종단 간 봉인). 계정의 개인 열쇠는 기기의 보안 저장소에만 있습니다.
  • 데이터베이스는 서버 함수만 쓰도록 막고(행 단위 접근 통제), 파일 주소는 공개하지 않으며 봉투를 가진 사람에게만 짧은 통행증을 줍니다.
  • 모든 통신은 암호화된 연결(HTTPS)로 오갑니다.
  • 신고를 여는 운영자 열쇠는 운영자 기기에만 두고 서버로 보내지 않습니다.
  • 되찾기 PIN은 다섯 번 틀리면 24시간 잠기고, 초대에 적은 이름을 다섯 번 틀리면 그 초대가 취소됩니다.
  • 알림에는 이름도 내용도 싣지 않습니다.
  • 앱 화면은 기본으로 캡처·녹화되지 않습니다.
  • 운영 데이터베이스는 매일 백업합니다(7일 보관).
  • 지난 관계의 흔적은 기간이 지나면 지웁니다(7절).

물리적 조치

서버는 Supabase(AWS)와 Cloudflare의 데이터센터에 있으며, 그 회사들의 물리적 보안 통제를 받습니다.

외부 환경

우리는 미국·대한민국(운영자, 데이터베이스), 서버 함수가 실행될 수 있는 일본·싱가포르·인도·호주·캐나다·브라질·아일랜드·영국·프랑스·독일·스위스, 그리고 Cloudflare가 아시아·태평양 지역에 두는 데이터센터(나라는 Cloudflare가 밝히지 않습니다)에서 개인정보를 다루며, 각 나라의 개인정보 보호 제도를 파악한 뒤 안전 조치를 합니다(11절).

막지 못하는 것

  • 다른 기기의 카메라로 화면을 찍는 것
  • 받은 사람이 사진·영상을 자기 사진첩에 저장하는 것 (피드 글이면 글쓴이에게 알리고, 대화 사진은 알리지 않습니다)
  • 글을 받은 사람이 그 내용을 다른 곳에 옮기는 것
  • 연결 지도의 모양 — 한 사람의 이름을 알면 연결을 따라 주변을 짐작할 수 있습니다
  • 회원이 볼 수 있는 명함을 누군가 모아 가는 것 — 늦출 수는 있어도 완전히 막지는 못합니다

16추적·광고·쿠키

앱에는 분석·광고·오류 수집 도구가 없습니다. 광고 식별자를 읽지 않고, 다른 회사의 데이터와 이어 붙이지 않으며, 광고를 보여 주지 않습니다. 다른 회사가 앱이나 웹사이트를 통해 회원의 활동을 모아 가도록 허락하지 않습니다. 우리는 추적을 하지 않으므로, 브라우저의 ‘추적 안 함(Do Not Track)’ 신호에 따라 다르게 동작하지 않습니다.

krypton.today는 쿠키를 쓰지 않습니다. 고른 언어만 브라우저 저장소(localStorage)에 남으며 개인정보가 아닙니다. 브라우저 설정에서 사이트 데이터를 지우면 사라집니다. 글꼴을 Google Fonts에서 받아 오므로, 페이지를 열 때 브라우저가 접속 IP·브라우저 정보·요청 주소를 Google LLC(미국)에 보냅니다(목적: 글꼴 받기, Google의 개인정보 처리방침을 따릅니다).

초대 링크·초대 요청 링크·QR 페이지는 링크의 # 뒤에 있는 이름과 비밀을 서버로 보내지 않고, 페이지 안에서만 읽어 앱으로 넘깁니다. 웹사이트는 Cloudflare가 제공하며, Cloudflare가 접속 기록을 봅니다(4절).

17개인정보 보호책임자와 연락처

운영 주체
Fantagram Inc. · 131 Continental Dr., Suite 305, Newark, DE 19713, U.S.A.
대표자
요청하시면 지체 없이 알려 드립니다 (privacy@krypton.today)
개인정보 보호책임자
William Yang (COO)
연락처
privacy@krypton.today (개인정보 문의·권리 행사·고충)
서비스 문의
support@krypton.today

18이 방침의 변경

이 방침을 바꾸면 바뀌는 내용과 시행일을 시행 7일 전에, 이용자에게 불리하게 바뀌면 30일 전에 앱과 이 페이지에서 알립니다. 지난 판은 이 페이지에서 볼 수 있게 둡니다.

이 판: v1.0 · 공고·시행 2026-10-03 (처음 게시)

이 방침은 한국어·영어·일본어로 제공됩니다. 뜻이 서로 다르면 한국어판을 따릅니다.

Privacy policy

Effective 2026-10-03 · v1.0

This policy applies to the Krypton app and krypton.today (the “service”), operated by Fantagram Inc. (“we”). It sets out what we receive, what we don’t, and what we can’t read. The rules for using the service are in our Terms of use.

At a glance

  • We don’t take your phone number or email to sign up or sign in. Your account is created and signed in with a key that stays on your device.
  • Names, bios and photos, and posts, replies and videos, are sealed on your device before they reach our servers. Neither the servers nor our staff hold the keys to open them.
  • The servers do know how account numbers are linked to each other (the connection map), and surface details such as who sent what to whom and when.
  • Our staff see only what is reported and join requests sent directly to the Krypton team. A reported item is opened to us by the reporter’s device.
  • Krypton+ payments are handled by the app store. Your card number and Apple ID never reach us.
  • We don’t run ads, sell personal data or use it for tracking.

1What we don’t receive

  • A phone number, email address or any government ID number for signing up or signing in (if you email us, we do receive that email — section 2)
  • Your address book, location, or advertising identifier
  • Your recovery PIN itself (we keep only a derived value used to check it — section 2)
  • The name carried in an invite link, an invite-request link or a QR code (it sits after the # in the link, so it never reaches the server). An invite link’s secret doesn’t reach the server either. The secret in an invite-request link or a connect QR code is sent to the server by the app of the member who opens it, only so it can be checked against the derived value the server already holds; the server doesn’t store it.
  • Which web addresses you preview (your own device fetches the link preview directly — section 3)
  • Payment details such as your card number or Apple ID (Krypton+ payments are handled by the app store — section 2)

Permissions the app asks for (all optional)

Camera
When you scan a connection QR code or an invite-request QR code. What the camera sees is read only on your device; it isn’t saved or sent.
Photos
When you choose photos or videos for a post or your profile, and when you save a photo or video to your photo library (saving asks only for permission to add). Only what you choose is resized and sealed on your device before upload.
Notifications
To receive notifications.

If you don’t allow a permission, you can still use everything in Krypton except that feature, and you can turn permissions off at any time in your device settings. The app doesn’t ask for microphone, location or contacts access.

2What the servers know

These are things the servers need to know for the service to work. They are not sealed. Emails to us, in the last row, come to our mailbox rather than the servers.

Account number
A random number created when you join. It isn’t tied to your name.
Public keys
Your account’s signing and encryption public keys, each device’s public key and certificate.Sign-in, checking who sent something, sealing things to you
Membership status and number
Pending, full member or suspended; your role (founder, Krypton team, member and so on); the order in which you became a full member; your Krypton+ periods — the period you bought and any period given by a founder (including who gave it).Joining, deciding Krypton+ features (number of photos, video length, original quality, scheduled posts)
Connection map
Who is connected with whom; who invited whom and became their sponsor; who was trusted to invite by whom; connection requests and introductions and their answers (accepted or passed); who shared how many past posts with which new connection; and when each happened.Working out who receives a post, joining by sponsorship, sharing past posts with each person only once
Post metadata
Author, time posted and edited, audience (connections, chosen people, only me), who received an envelope (who can open the post), scheduled time, disappearing time, whether chat is closed and when it was closed or reopened, a mark that the post was sent to chosen people (passing it along is blocked), the two people in each chat and its message count and times, who passed a post to whom, and the size, dimensions and length of photo and video files.Delivery, update order, scheduled and disappearing posts, storing files
Invitations
The inviters (two people, or one person who may invite alone), status, expiry, a check value made by mixing the name written on the invitation with a value that exists only in the link (the server can’t learn the name from it alone), and the number of wrong name entries (after five, the invitation is cancelled).
Invite requests
The requesting account, a value derived from the link secret, status (waiting, accepted, “I don’t know them”, withdrawn, ended), the member who answered, the invitation attached, creation time and expiry (7 days). For a request to the Krypton team, a sealed introduction only the team’s device can open is added, along with signs used to spot abuse of sign-up — how many accounts were started from the same place on the same day, and how long it took from creating the account to sending the request.Attaching the invitation of the member who answered to the person who asked, screening requests to the Krypton team
Sign-up start records
When someone starts signing up without an invitation: a check value made by mixing their IP address with a key that changes every day (not the IP address itself), and the account number and time created. Records older than two days are deleted automatically every day.Stopping mass account creation, screening requests to the Krypton team
Meeting in person (QR)
Your QR code number and a value derived from its secret (each code works for only 5 minutes), and the accounts that sent you a connection request with that QR code and when. Deleted one day after expiry. The request itself stays in the connection map.Connecting by QR code
Hiding and reports
Who chose to hide whose posts; who reported what, for which reason, and the report’s status.
Notifications
Your device’s push token, device type, notification language (Korean, English, Japanese), per-type on/off settings (chats, screenshots and saved photos, requests), and a log of notifications sent (recipient account, type, time, whether delivered). Notifications about a request to recover your account can’t be turned off.
Settings
Whether “Show my past posts” to new connections is on or off.Sharing past posts
Screen capture attempts and saved photos and videos
Who tried to capture whose screen, where (chat, person page, post, updates), and when. Who saved a photo or video from which of someone’s feed posts to their photo library (each post is recorded only once; saving chat photos isn’t recorded).To let the owner of that screen or post know
Devices
Each device’s last sign-in time and whether it has been removed.
Recovery
Only if you set it up — a sealed backup, the server’s share, a derived value to check your PIN with the number of wrong tries and any lock time, which connections hold key pieces, and the status of recovery requests.The server can’t open the backup on its own; the pieces your connections hold are needed
Krypton+ purchases
If you buy Krypton+: the store (Apple or Google), transaction number, product, the end of the current period (a lifetime pass has no end), when it was refunded or cancelled, and whether it was a live or test purchase. When you buy, your account number is attached to the transaction so the purchase the store confirms can be linked to your account. Payment details such as your card number or Apple ID are handled by the store; we don’t receive them.Working out your Krypton+ period and reflecting renewals and refunds, stopping one purchase being used by another account, keeping transaction records as the law requires
Emails to us
When you email support@krypton.today or privacy@krypton.today: your email address, the message and anything attached (such as proof that you hold rights, or screenshots that identify a post). The same applies to infringement or removal requests from people who aren’t members.Answering questions; handling appeals, infringement, removal, withdrawal and data-rights requests

3What we store sealed

These are sealed on your device and then sent to us. Neither the servers nor our staff hold the keys to open them.

  • Your name, bio, profile photo and sponsors shown on your card
  • Posts, replies, notes, photos and videos (files are stored as ciphertext)
  • Link previews — made by the writer’s device and sealed with the post
  • Notes left with an introduction, and the reason written when passing a post along
  • The name written on an invitation, device names
  • Your name, sent when you request a connection by QR code — only the QR code’s owner can open it
  • The name, one-line introduction and “who will you use it with” in a request to the Krypton team — only the team’s device can open them
  • The line carried in a chat notification — only the recipient’s device can open it

What sealing doesn’t mean

  • Recipients can read it. A post opens on each recipient’s device and may stay there. Recipients can save photos (and, as Krypton+ members, videos) to their photo library, and saved copies are outside the seal.
  • Reports are opened to us. The reporter opens that post or card to us (section 8).
  • The Krypton team reads requests sent to it. The team opens the name, introduction and “who will you use it with” in the request and decides whether to accept (section 8).
  • Your card is visible to every member. Your name, bio and blurred photo are sealed with a key all members hold. Anyone who becomes a member can see them.
  • Metadata isn’t sealed. The servers know what’s in section 2. Posts are padded to set sizes to hide their length, but the size of photo and video files is visible.

When a link preview is made, the writer’s device connects to that site directly, so the site sees the writer’s connection. Recipients’ devices don’t contact the site unless they tap the link.

4Records created automatically

  • IP addresses — we don’t record them in our database or server function logs. The one exception is the check value made when someone starts signing up without an invitation: the IP address is mixed with a value used only that day, and records older than two days are deleted automatically every day (section 2). IP addresses do appear in the platform logs of Supabase, our server provider, and are deleted after 7 days. Cloudflare processes IP addresses while delivering photos, videos and web pages; those records follow Cloudflare’s privacy policy and the periods Cloudflare sets. Observability logs for the Cloudflare Worker in front of file storage are turned off.
  • Notification log, last sign-in per device, screen capture attempts and saved photos and videos, sign-up start records — section 2

The “new message” and “typing” signals in an open chat pass through the server (Supabase Realtime) to the two people in that chat only. The signals carry no content, and the signals themselves aren’t kept.

The app contains no analytics, advertising or crash-reporting tools.

5Purposes and legal bases

We use personal data only for the purposes below. For each purpose we list the information used and the legal basis.

Providing the service
Joining (two sponsors, invite requests, requests to the Krypton team), sign-in, delivering posts, replies, photos and videos, connecting (including in person by QR code) and introductions, passing posts along, sharing past posts with new connections, scheduled posts, disappearing posts, recoveryInformation used — account number and public keys, membership status, connection map, post metadata, sealed content, invitations and invite requests, QR codes, settings, devices, recoveryLegal basis — performance of a contract (Korea’s Personal Information Protection Act (PIPA) Art. 15(1)(iv); GDPR Art. 6(1)(b))
Notifications
Telling you something is waiting, a new chat, a new connection, a screen capture attempt, that your photo or video was saved, or a request to recover your account. Notifications carry no names or content.Information used — push token, device type, notification language, notification settings, notification logLegal basis — performance of a contract (PIPA Art. 15(1)(iv); GDPR Art. 6(1)(b))
Providing Krypton+
Confirming purchases, reflecting renewals, cancellations and refunds, stopping one purchase being used by another account, managing Krypton+ given by a founder, deciding limits on number of photos, video length, original quality and scheduled postsInformation used — Krypton+ purchase records, membership status and Krypton+ periodsLegal basis — performance of a contract (PIPA Art. 15(1)(iv); GDPR Art. 6(1)(b))
Safety and operations
Handling reports, hiding, restricting accounts, stopping mass creation of accounts without invitations, screening requests to the Krypton team, telling the owner of a screen or post about capture attempts and saved photos and videos, keeping a log of staff actions, answering questions and handling appealsInformation used — hide and report records, sign-up start records, screening signs on invite requests, capture and save records, staff action log, emails to usLegal basis — legitimate interests (PIPA Art. 15(1)(vi); GDPR Art. 6(1)(f)): protecting members and the service from abuse, and letting the owner of a screen or post know
What the law requires
Keeping purchase records, responding to legal requests, reporting child sexual abuse material, handling removal requests for infringing posts, withdrawals and data-rights requestsInformation used — Krypton+ purchase records, the information in section 2, report copies, emails to usLegal basis — legal obligation (PIPA Art. 15(1)(ii); GDPR Art. 6(1)(c))

We don’t use personal data for any other purpose, such as advertising, sale or profiling.

  • We don’t process any information on the basis of consent. The camera, photos and notifications are used only when you allow them on your device, and you can turn them off at any time in your device settings.
  • The information in section 2 is needed for the service (recovery and Krypton+ purchases only if you choose them, and emails only if you send them). Without it you can’t use Krypton.
  • You can object to processing based on legitimate interests (section 13).

We don’t receive or separately collect sensitive information such as health, beliefs or political opinions. The connection map knows only who is linked with whom — not people’s professions or the nature of their relationships.

6What other members see

All members
Your card — name, bio, sponsors and a blurred (mosaic) profile photo.
2nd degree
A half-blurred profile photo
Connections
Your full profile photo and the posts you share with “Connections”
Chosen recipients
The post and a “Selected” mark showing it was sent to them in particular. They can’t see who else received it. The author sees the list of recipients.
New connections
Up to 30 of the posts you shared with “Connections” in the last 30 days. You can turn this off with “Show my past posts” in Settings.
Author and replier
A reply to a post is seen only by the author and the person replying. Only the author knows who sent a heart.
People a post is passed to
If a recipient passes your post along to one of their connections, that person sees it too. Posts sent to chosen people and “Only me” posts can’t be passed along.
The owner of a screen
If you try to capture someone’s chat, page or post, they get a notification and your name appears in their updates.
Authors (saving)
If you save a photo or video from a feed post to your photo library, the author gets a notification and your name appears in their updates. Saving chat photos doesn’t notify anyone.
A QR code’s owner
If you scan a QR code and send a connection request, only that QR code’s owner sees your name.
The Krypton team
If you ask the Krypton team to join, the team sees the name, introduction and “who will you use it with” in your request (section 8).

Your card (name and one-line bio) is visible to every member. Don’t put sensitive things such as health or beliefs on your card. For posts, you choose who sees them with the audience setting (connections, chosen people, only me).

7Retention and deletion

Each kind of information is kept for the period below and deleted when that period ends. Traces of relationships no longer in use are deleted automatically once a day.

Removed connections
30 days after removal
Unanswered requests and introductions
30 days after the last activity
“Pass” records
180 days
Unused invitations
30 days after expiry or cancellation (an invitation used to join stays with the sponsor record)
Sign-in challenges
1 day after expiry
Handled reports
Once handling is finished and 180 days have passed since the report (open reports are kept; reports the law requires us to keep — for example, those reported to the U.S. NCMEC, for 1 year from that report — are kept for that period)
Screen capture attempts and saved photos and videos
30 days
Notification log
30 days
Disappearing posts
24 hours (from when the post appears if chosen when writing, or from when it’s chosen later). The post, chat and photo records are deleted within a minute, and photo and video files are removed from storage shortly after.
Sign-up start records (IP check values)
Two days (deleted automatically every day)
QR codes and their requests
One day after expiry
Invite requests, records of shared past posts
While you use your account (deleted along with your account — see section 12)
Krypton+ purchase records
5 years from the transaction (the period Korea’s Act on the Consumer Protection in Electronic Commerce sets for payment records). Records of a pass still in use (a lifetime pass that hasn’t ended) are kept for as long as that account exists.
Emails to us
3 years after we finish handling them (the period Korea’s Act on the Consumer Protection in Electronic Commerce sets for complaint and dispute records)
Staff action log
Kept unalterable for 3 years from the action, then deleted
Everything else
While you use your account. What is deleted and what remains after you delete it is set out in section 12.

When a retention period ends or the purpose is fulfilled, we delete the information without delay. We delete the database rows and remove photo and video files from storage so they can’t be restored. Deleted information stays in the production database’s daily backups for up to 7 days before it’s gone (backups are used only to recover from failures). Purchase records kept because the law requires it are stored apart from other information and used only for that purpose.

8Reports and what we can open

We can’t see posts as they are shared, and we have built nothing that would let us. Instead, when someone reports, the reporter’s device opens the reported item to us.

We look at reported items to deal with breaches of our terms and unlawful content, and to take the action the law requires (section 5 — legitimate interests and legal obligation).

A reported post or reply
We see that post or reply as it was when reported, its photos and videos (if the files still exist), and the author’s name. If a disappearing post vanishes or the post is later deleted, the sealed copy from the time of the report stays with the report.
A reported person
We see that person’s card (name, bio, blurred photo). The full photo isn’t sent.
A request to the Krypton team
The team’s device unseals the name, one-line introduction and “who will you use it with”, and the team also sees how many accounts were started from the same place on the same day and how long it took from creating the account to sending the request. The team uses this to decide whether to accept.
Metadata we see alongside
The account numbers of the reporter and the reported person, the reason and the time. For each account: status, role, join and deletion times, member number, Krypton+ period, number of connections, number of sponsors, number of devices and number of reports. No names.
Staff action log
Who took which action (suspending, lifting a suspension, handling a report, a founder giving or withdrawing Krypton+), on which account, when, and with what note — kept for 3 years from the action so it can’t be changed or deleted (section 7).
What we don’t see
Posts that weren’t reported, and that person’s other posts and chats

When we take action, we tell the reported member the reason (until in-app notices are ready, they can ask support@krypton.today). We don’t tell them who reported. Appeals follow the process in section 6 of the Terms of use.

Because we can open report copies, they may be provided together with the report record when there is a legal request (section 9).

Handled reports are deleted once handling is finished and 180 days have passed since the report (open reports are kept; reports the law requires us to keep — for example, those reported to the U.S. NCMEC, for 1 year from that report — are kept for that period; section 7). The reporter’s account number stays on the record, so misuse of reporting is visible.

9Disclosure to third parties

We don’t sell personal data or hand it to other companies for advertising or marketing. We disclose it only in these cases.

  • Legal requirements — we check that a request follows the procedure the law requires, such as a warrant, and provide only what is needed. All we can provide is what the servers know (section 2) and report copies opened to us (section 8); we can’t open other sealed content either. Where the law allows, we tell the member concerned.
  • Reporting child sexual abuse material — if we find child sexual abuse material, we report it as the law requires to the U.S. National Center for Missing & Exploited Children (NCMEC) and the relevant authorities, together with the content and related account information.
  • Imminent danger — when there is a clear and imminent risk to someone’s life or safety, we give the relevant authorities, such as the police, only what is needed to prevent it.
  • Krypton+ payments — when a member buys Krypton+, their account number (a random number) is passed with the transaction to the store that processes the payment (currently Apple; Google Play payments on Android are still being prepared). From the store we receive only the transaction number, product, period and whether it was refunded. The store handles payment details under its own privacy policy.

10Service providers

We use the companies below to run the service. They handle sealed ciphertext, the information in section 2, and connection details while delivering data.

Supabase, Inc.
Database, server functions, Realtime (live signals in chats)
Cloudflare, Inc.
Storing and delivering photo and video files (ciphertext) — R2 and Workers. Delivering the krypton.today website and the invite, invite-request and QR link pages — Pages. Forwarding email sent to support@ and privacy@krypton.today to our mailbox — Email Routing
Zoho Corporation
Our mailbox — stores the questions and requests emailed to support@ and privacy@krypton.today
Apple Inc.
Delivering iPhone notifications (Apple Push Notification service). We pass the device push token and the notification text, which carries no names or content. Chat notifications also carry a line sealed so only the recipient’s device can open it; Apple sees only ciphertext. Apple knows which device a token belongs to.
Google LLC
Delivering Android notifications (Firebase Cloud Messaging). We pass the device push token and notification text with no names or content. Chat notifications also carry a line sealed so only the recipient’s device can open it; Google sees only ciphertext. Google knows which device a token belongs to.

We have data processing agreements with these companies so that they don’t use the information outside the work we give them and protect it to a standard equal to or higher than this policy. They pass work on to other companies only as those agreements allow. If the companies we use change, we’ll update this policy and let you know.

Krypton+ payments are processed by the store under its own responsibility, so they are covered in section 9 rather than here.

11International transfers

While you use the service, information is transferred over the network, whenever needed, to the countries below to be stored and processed. All transfers use encrypted connections (HTTPS).

Fantagram Inc.
  • CountryUnited States, South Korea
  • When and howWhen our staff sign in to the staff console over an encrypted connection to run the service and handle reports
  • ItemsInformation in section 2, report copies, requests to the Krypton team
  • PurposeRunning the service, handling reports, reviewing join requests
  • RetentionSection 7
  • Contactprivacy@krypton.today
Supabase, Inc.
  • CountryStored in Seoul, South Korea (AWS); the company is in the United States. Server functions run, only while processing, in the Supabase region closest to where you use the app, which is in one of these countries: South Korea, Japan, Singapore, India, Australia, the United States, Canada, Brazil, Ireland, the United Kingdom, France, Germany or Switzerland.
  • When and howEvery time you use the app, over an encrypted connection
  • ItemsInformation in sections 2 and 3 (section 3 as ciphertext)
  • PurposeDatabase, server functions, live signals
  • RetentionSection 7 (deleted information stays in backups for up to 7 more days)
  • Contactprivacy@supabase.com
Cloudflare, Inc.
  • CountryFiles are stored in a data center Cloudflare places in the Asia-Pacific region (Cloudflare doesn’t disclose the country and doesn’t guarantee the region) and delivered through Cloudflare data centers worldwide close to the user. Headquarters in the United States
  • When and howWhen you upload or download photos and videos, and when you open krypton.today
  • ItemsPhoto and video ciphertext, IP addresses while delivering
  • PurposeStoring and delivering files, providing the website
  • RetentionFiles until the post is deleted; access records for the period Cloudflare sets
  • Contactprivacyquestions@cloudflare.com
Apple Inc.
  • CountryUnited States
  • When and howWhen we send a notification to an iPhone, and when you buy Krypton+
  • ItemsPush token, notification text with no names or content, the sealed line in chat notifications, and the account number attached to a Krypton+ purchase (section 9)
  • PurposeiPhone notifications, linking Krypton+ payments to your account
  • RetentionWhile delivering for notifications; transaction records under Apple’s privacy policy
  • ContactApple privacy contact
Google LLC
  • CountryUnited States
  • When and howWhen we send a notification to an Android device
  • ItemsPush token, notification text with no names or content, the sealed line in chat notifications
  • PurposeAndroid notifications
  • RetentionWhile delivering
  • ContactGoogle privacy contact form
Cloudflare, Inc. (Email Routing)
  • CountryCloudflare data centers around the world, near the sender. Headquartered in the United States
  • When and howWhen you email support@ or privacy@krypton.today, while it is forwarded to our mailbox
  • ItemsSender’s email address, the name and content you write in the email
  • PurposeForwarding questions and requests to our mailbox
  • RetentionHandled only while forwarding, not stored. Delivery logs for the period Cloudflare sets
  • Contactprivacyquestions@cloudflare.com
Zoho Corporation
  • CountryUnited States
  • When and howWhen a question or request arrives in our mailbox
  • ItemsSender’s email address, the name and content you write in the email
  • PurposeAnswering questions and requests
  • RetentionSection 7
  • Contactprivacy@zohocorp.com
Google LLC (Google Fonts)
  • CountryUnited States
  • When and howSent directly by your browser when you open krypton.today
  • ItemsIP address, browser information, requested address
  • PurposeLoading the website’s fonts
  • RetentionAs set out in Google’s privacy policy
  • ContactGoogle privacy contact form

We can’t provide the service without these transfers. If you don’t want them, you can stop them by deleting your account (section 12).

EU and UK — South Korea is a country the EU and the UK recognize as providing an adequate level of data protection. Transfers to other countries rely on safeguards such as adequacy decisions or the EU Standard Contractual Clauses; you can ask for a copy at privacy@krypton.today.

Japan — our agreements require the receiving companies to take measures to the standard Japanese law requires. On request, we’ll tell you what those measures are and give you information about each country’s regime (for country regimes, see the Japanese Personal Information Protection Commission’s survey, 外国における個人情報の保護に関する制度等の調査).

12Deleting your account

This is how to delete a Krypton account (operated by Fantagram Inc.). Delete it yourself under Delete account at the bottom of Settings in the app. It works only on the device that holds your account key. Pending or suspended accounts can’t delete themselves in the app — follow “If you can’t use the app” below and write to privacy@krypton.today. It can’t be undone.

Deleting your account doesn’t cancel an auto-renewing subscription in the app store. Cancel it first in your device’s store subscription settings (Manage subscription in Krypton’s Settings). Krypton+ applies only to the one account that bought it, so when you delete your account any remaining period (including a lifetime pass) can’t be moved to another account or restored.

What is deleted

  • Your posts, replies and notes, with their photo and video files, and the chats on your posts
  • Your profile and its envelopes, and every envelope sent to you (you can no longer open others’ posts)
  • Device records and push tokens, your recovery setup and any key pieces you hold, recovery requests, pass records, member-key envelopes, your encryption public key
  • Your member number and Krypton+ periods (including any given by a founder), hide records (both those you set and those others set on you), notification settings, invite requests you sent (including sealed introductions sent to the Krypton team), records of shared past posts (both those you shared and those shared with you)

What is ended or withdrawn

  • All your connections are removed (the removed records are deleted after 30 days)
  • Invitations you sent that are still in progress are cancelled

What remains

Account number and status
Your account number, signing public key, join and deletion times and status. Other members’ sponsor records point to this number and are needed to check the chain of sponsorship, so we keep it while we run the service. Your name was never on the server.
Sponsor records
Who brought whom in. Kept while we run the service, for the same reason.
Reports
Deleted once handling is finished and 180 days have passed since the report. Kept longer if the law requires.
Krypton+ purchase records
Deleted 5 years after the transaction (Korea’s Act on the Consumer Protection in Electronic Commerce). Once your account is deleted, this applies to lifetime pass records too.
Other remaining records
Records of posts you passed along (to whom, and the sealed reason) and of posts other members passed along to you — used to show other members how a post reached them, and deleted when that post is deleted. Records of being trusted to invite. These remain after you delete your account.
Records with set periods
Notification log (30 days), capture and save records (30 days), sign-up start records (two days), QR codes and their requests (one day after expiry), emails to us (3 years after handling) — deleted when the period in section 7 ends.
Staff action log
Deleted after 3 years, as in section 7.
What went to others
Posts and photos already delivered to other people’s devices, and copies recipients saved to their photo library, can’t be recalled. Replies others wrote to you remain theirs.

If you can’t use the app

If you no longer have a device with your account key, recover your account with your recovery setup and then delete it. If you have no way to recover it, or your account is pending or suspended, email privacy@krypton.today. We don’t collect names or emails, so if we can’t confirm you own the account we can’t delete it — but its content is ciphertext we can’t open.

13Your rights and how to use them

You have the right to access, correct and delete your personal data and to ask us to stop processing it. In the EU and UK you also have the rights to restrict processing, to data portability, to object to processing based on legitimate interests, and to complain to a supervisory authority.

In the app

  • Edit your profile, edit posts (up to 10 minutes after posting) or delete them, make a post disappear, close a chat
  • Remove connections, hide someone’s posts, turn off “Show my past posts”
  • Turn off notifications by type (chats, screenshots and saved photos, requests), Manage subscription
  • Delete your account (section 12)

By contacting us

  • Where — privacy@krypton.today. Requests are free.
  • Verification — we don’t know your name or email, so we verify requests with a signature made with that account’s key. If you lost your device, recover your account first and then make the request. If we can’t verify you, we may be unable to act on the request, to the extent the law allows.
  • Representatives — someone may make a request on your behalf. We need your authorization and a signature made with your account’s key to verify you.
  • Access and copies — we can’t open sealed content, so we provide what the servers know (section 2). You can see sealed content yourself in the app.

How quickly we answer

We answer within 10 days of receiving a request. If we can’t do it in that time, we tell you why and when we will (for EU and UK residents, within the one month the law sets).

We don’t make automated decisions without human involvement that significantly affect members’ rights.

Where to get help

If you don’t get an answer or think we handled a request wrongly, you can ask the bodies below for help.

  • Personal Information Dispute Mediation Committee (Korea) 1833-6972 (kopico.go.kr)
  • Personal Information Infringement Report Center (Korea) 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors’ Office (Korea) 1301 (spo.go.kr)
  • Korean National Police Agency 182 (ecrm.police.go.kr)
  • EU and UK residents — the supervisory authority where you live
  • Residents of Japan — the Personal Information Protection Commission (個人情報保護委員会)

14Children

Krypton is a service for people aged 18 and over. We don’t knowingly collect personal data from anyone under 18, including children under 14, and members who invite and sponsor others must not bring in anyone under 18. If we learn that someone under 18 has joined, we close the account and delete that information. If you know of such a case, please tell us at privacy@krypton.today.

15Security and its limits

Organizational measures

  • We limit the people who handle personal data to a minimum number of staff. Staff access is granted through staff-console accounts kept separate from app accounts, with two exceptions: requests to the Krypton team are opened on the team’s device (a team account), and Krypton+ is given or withdrawn from the founder’s app.
  • Changes our staff make (suspending, lifting a suspension, handling reports, giving or withdrawing Krypton+) are kept for 3 years in a log that can’t be changed or deleted (section 7).

Technical measures

  • Posts, profiles and files are sealed on your device (end-to-end). Your account’s private keys stay in your device’s secure storage.
  • Only server functions can use the database (row-level access control). File addresses aren’t public; only people who hold an envelope get a short-lived pass.
  • All traffic uses encrypted connections (HTTPS).
  • The staff key that opens reports stays on staff devices and is never sent to the server.
  • Five wrong recovery PINs lock recovery for 24 hours, and five wrong name entries cancel an invitation.
  • Notifications carry no names or content.
  • App screens can’t be captured or recorded by default.
  • The production database is backed up daily (kept for 7 days).
  • Traces of past relationships are deleted after set periods (section 7).

Physical measures

Our servers are in Supabase (AWS) and Cloudflare data centers and are covered by those companies’ physical security controls.

The wider environment

We handle personal data in the United States and South Korea (staff, database); in Japan, Singapore, India, Australia, Canada, Brazil, Ireland, the United Kingdom, France, Germany and Switzerland, where server functions may run; and in the data center Cloudflare places in the Asia-Pacific region (Cloudflare doesn’t disclose the country). We take security measures after understanding each country’s data protection regime (section 11).

What we can’t prevent

  • Someone photographing the screen with another device
  • Recipients saving photos and videos to their own photo library (for feed posts the author is notified; for chat photos no one is)
  • A recipient copying what they received elsewhere
  • The shape of the connection map — knowing one person’s name, someone could infer others around them
  • Someone collecting the cards members can see — we can slow this down, not stop it entirely

16Tracking, ads and cookies

The app contains no analytics, advertising or crash-reporting tools. It doesn’t read advertising identifiers, doesn’t combine your data with other companies’ data, and shows no ads. We don’t let other companies collect members’ activity through the app or the website. Because we don’t track you, we don’t respond differently to a browser’s “Do Not Track” signal.

krypton.today uses no cookies. Only your chosen language is kept in browser storage (localStorage), and it isn’t personal data. It’s removed when you clear site data in your browser settings. Fonts are loaded from Google Fonts, so when you open a page your browser sends your IP address, browser information and the requested address to Google LLC (United States) (purpose: loading fonts; Google’s privacy policy applies).

The invite, invite-request and QR link pages don’t send the name and secret after the # in the link to the server; the page reads them only in your browser and hands them to the app. The website is provided by Cloudflare, which sees access records (section 4).

17Privacy officer and contact

Operator
Fantagram Inc. · 131 Continental Dr., Suite 305, Newark, DE 19713, U.S.A.
Representative
We’ll tell you without delay on request (privacy@krypton.today)
Privacy officer
William Yang (COO)
Privacy contact
privacy@krypton.today (privacy questions, exercising your rights, complaints)
Other questions
support@krypton.today

18Changes to this policy

If we change this policy, we’ll tell you what is changing and when it takes effect, in the app and on this page, 7 days before it takes effect — or 30 days before for changes that are less favorable to you. Earlier versions will remain available on this page.

This version: v1.0 · published and effective 2026-10-03 (first version)

This policy is available in Korean, English and Japanese. If the versions differ, the Korean version prevails.

プライバシーポリシー

施行日 2026-10-03 · v1.0

このポリシーは、Fantagram Inc.(以下「私たち」)が運営する Krypton アプリと krypton.today(以下「本サービス」)に適用されます。私たちが何を受け取り、何を受け取らず、何を読めないかを説明します。本サービスを使うときの約束は利用規約にあります。

要点

  • 登録・ログインに電話番号・メールアドレスは受け取りません。アカウントは端末の中の鍵だけで作成し、ログインします。
  • 名前・自己紹介・写真、投稿・返信・動画は、端末で封をしてからサーバーに送られます。サーバーにも運営者にも、それを開く鍵はありません。
  • 一方で、サーバーはアカウント番号どうしがどうつながっているか(つながりの地図)や、誰がいつ誰に送ったかといった外側の情報は知っています。
  • 運営者が見るのは、通報されたものと、Kryptonチームに直接送られた参加リクエストだけです。通報されたものは、通報した人の端末が運営者に開きます。
  • Krypton+ の決済はストアが処理します。カード番号や Apple ID は私たちには届きません。
  • 広告は出さず、個人情報を売らず、トラッキングにも使いません。

1受け取らない情報

  • 登録・ログインに使う電話番号・メールアドレス、マイナンバーなど本人を確認する番号(メールでお問い合わせいただいた場合、そのメールは受け取ります — 2)
  • 端末の連絡先、位置情報、広告識別子
  • 取り戻す方法の暗証番号そのもの(照合用に変換した値だけを受け取ります — 2)
  • 招待リンク・招待リクエストのリンク・QR コードに含まれる名前(リンクの # の後ろにあるため、サーバーには届きません)。招待リンクの秘密もサーバーには届きません。招待リクエストのリンクとつながる QR の秘密は、開いたメンバーのアプリが照合のためにサーバーへ送ります。サーバーはあらかじめ受け取った変換値と照らし合わせるだけで、保存しません。
  • リンクのプレビューを作るときにどのアドレスを開いたか(書く人の端末がそのサイトに直接アクセスします — 3)
  • カード番号や Apple ID などの決済情報(Krypton+ の決済はストアが扱います — 2)

アプリが求める許可(すべて任意)

カメラ
つながりの QR コードや招待リクエストの QR コードを読み取るとき。カメラに映ったものは端末の中だけで読み取り、保存も送信もしません。
写真
投稿やプロフィールに付ける写真・動画を選ぶとき、そして写真・動画を写真アプリに保存するとき(保存では追加の許可だけを求めます)。選んだものだけを端末で縮小し、封をしてからアップロードします。
通知
通知を受け取るとき。

許可しなくても、その機能以外の Krypton は使えます。許可は端末の設定でいつでもオフにできます。マイク・位置情報・連絡先の許可は求めません。

2サーバーが知っている情報

本サービスが動くために、サーバーが知っている必要のある情報です。これらは封をしていません。最後の行のお問い合わせ・ご請求のメールは、サーバーではなく私たちのメールボックスに届きます。

アカウント番号
登録時に作るランダムな番号。名前とは結びついていません。
公開鍵
アカウントの署名用・暗号化用の公開鍵、端末ごとの公開鍵と端末証明書。ログイン、送り主の確認、あなた宛てに封をするとき
登録状態と会員番号
登録待ち・正会員・停止の別、役割(創設者・Kryptonチーム・メンバーなど)、正会員になった順番、Krypton+ の期間 — ご自身で購入した期間と、創設者が付与した期間(付与した人を含む)。登録の手続き、Krypton+ の機能(写真の枚数・動画の長さ・元の画質・予約投稿)の判定
つながりの地図
誰と誰がつながりか、誰が誰を招待して推薦人になったか、誰が誰に招待を託したか、つながりの申し込み・紹介とその返事(承認・見送り)、新しいつながりに誰が誰へ過去の投稿をいくつ見せたか、それぞれの日時。投稿を受け取る人の計算、推薦による登録、過去の投稿をひとりに一度だけ見せるため
投稿の外側の情報
書いた人、投稿・編集の日時、公開範囲(つながり・選んで・自分だけ)、封筒を受け取った人(=その投稿を開ける人)、予約した日時、消える日時、会話を閉じているかと閉じた・再開した日時、選んで送った投稿であること(手渡すことを止めた投稿)の印、会話したふたりとその件数・日時、誰が誰に投稿を手渡したか、写真・動画ファイルのサイズ・縦横・長さ。投稿の配送、新着の並び、予約投稿と消える投稿、ファイルの保存
招待
招待した人(ふたり、またはひとりで招待できる人ひとり)、進行状況、有効期限、招待に書いた名前をリンクの中だけにある値と混ぜて作った確認値(サーバーはこの値だけでは名前を知ることができません)、名前を間違えた回数(5回で招待は取り消されます)。
招待リクエスト
リクエストしたアカウント、リンクの秘密から作った値、状態(待機中・承認・知らない方・取り下げ・終了)、返事をしたメンバー、付いた招待状、作成日時と有効期限(7日)。Kryptonチームへのリクエストの場合は、チームの端末だけが開ける封をした自己紹介と、登録の不正利用を見分けるための印 — 同じ日に同じ場所から始めたアカウントの数、アカウントを作ってからリクエストするまでにかかった時間 — が加わります。リクエストに応えたメンバーの招待をリクエストした人に付けるため、Kryptonチームへのリクエストの見分け
登録開始の記録
招待状なしで登録を始めたときの IP アドレスを、毎日変わる鍵で混ぜて作った確認値(IP アドレスそのものではありません)と、そのとき作ったアカウント番号・日時。2日を過ぎた記録は、毎日自動で削除します。アカウントの大量作成の防止、Kryptonチームへのリクエストの見分け
会ってつながる(QR)
あなたの QR コードの番号とその秘密から作った値(コードは5分だけ使えます)、その QR コードでつながりを申し込んだアカウントと日時。期限切れから1日後に削除します。申し込み自体はつながりの地図に残ります。QR コードでつながるため
非表示・通報
誰が誰の投稿を表示しないことにしたか、誰が何をどの理由で通報したかと、その処理状況。
通知
端末の通知トークン、端末の種類、通知の言語(韓国語・英語・日本語)、通知の種類ごとのオン・オフ(会話・キャプチャ・写真の保存・お願い)、通知の送信記録(受け取るアカウント・種類・日時・届いたかどうか)。アカウントを取り戻そうとする依頼の通知はオフにできません。
設定
新しいつながりに「これまでの投稿を見せる」をオンにしているかどうか。過去の投稿を見せるため
画面キャプチャの試みと写真・動画の保存
誰が誰の画面を、どこで(会話・人のページ・投稿・新着)キャプチャしようとしたか、その日時。誰が誰のどのフィード投稿の写真・動画を写真アプリに保存したか(同じ投稿は一度だけ記録し、会話の写真の保存は記録しません)。その画面や投稿の持ち主に知らせるため
端末
端末ごとの最後のログイン日時、解除したかどうか。
取り戻す方法
準備した場合のみ — 封をした控え、サーバーが預かるかけら、暗証番号を照合する値と間違えた回数・ロックした日時、鍵のかけらを預かったつながりが誰か、取り戻す依頼の進行状況。サーバーだけでは控えを開けません。つながりが預かったかけらが必要です
Krypton+ の購入
Krypton+ を購入した場合のストア(Apple・Google)、取引番号、商品、今の期間の終わり(「永久」には終わりがありません)、返金・取り消しの日時、本番・テストの別。購入のときにアカウント番号を取引に載せ、ストアが確認した購入をアカウントに結びつけます。カード番号や Apple ID などの決済情報はストアが扱い、私たちは受け取りません。Krypton+ の期間の計算と更新・返金の反映、同じ購入をほかのアカウントが使えないようにするため、法律が定める取引記録の保存
お問い合わせ・ご請求のメール
support@krypton.today・privacy@krypton.today に送られたメールの送信者のメールアドレス、内容、添付資料(権利者であることを示す資料、投稿を特定する画面など)。メンバーでない方からの権利侵害・削除の依頼も同じです。お問い合わせへの回答、異議・権利侵害・削除・撤回・開示等の請求の処理

3封をしたまま保管する情報

次のものは端末で封をしてからサーバーに送ります。サーバーにも運営者にも、それを開く鍵はありません。

  • 名前、自己紹介、プロフィール写真、推薦人の表示
  • 投稿、返信、ひとこと、写真、動画(ファイルは暗号文のまま保存します)
  • リンクのプレビュー — 書く人の端末が作り、投稿と一緒に封をします
  • 紹介のときに残したメモ、投稿を手渡すときに書いた理由
  • 招待に書いた名前、端末の名前
  • QR コードでつながりを申し込むときに送るあなたの名前 — QR コードの持ち主だけが開けます
  • Kryptonチームへのリクエストに書く名前・ひとこと自己紹介・誰と使うか — チームの端末だけが開けます
  • 会話の通知に載る一行 — 受け取る人の端末だけが開けます

封をしても変わらないこと

  • 受け取った人は読めます。 投稿は受け取った人の端末で開かれ、その端末に残ることがあります。受け取った人は写真を(Krypton+ メンバーは動画も)写真アプリに保存でき、保存された写しは封の外にあります。
  • 通報されると運営者が見ます。 通報した人がその投稿や名刺を運営者に開きます(8)。
  • Kryptonチームへのリクエストはチームが読みます。 リクエストに書いた名前・自己紹介・誰と使うかをチームが開いて見て、承認するかどうかを決めます(8)。
  • 名刺はメンバーなら誰でも見られます。 名前・自己紹介・ぼかした写真は、全メンバーが持つ鍵で封をしています。メンバーになった人は誰でも見られます。
  • 外側の情報は封をしていません。 2 の情報はサーバーが知っています。投稿は長さが分からないよう決まったサイズまで埋めて封をしますが、写真・動画ファイルのサイズは分かります。

リンクのプレビューを作るとき、書く人の端末がそのサイトに直接アクセスするため、そのサイトには書く人のアクセスが残ります。受け取る人の端末は、リンクを押すまでそのサイトにアクセスしません。

4自動的に残る記録

  • IP アドレス — 私たちのデータベースとサーバー関数の記録には残しません。例外は、招待なしで登録を始めるときの確認値ひとつで、IP アドレスをその日だけ使う値と混ぜて置き、2日を過ぎた記録は毎日自動で削除します(2)。サーバーを提供する Supabase のプラットフォームの記録には IP アドレスが残り、7日後に削除されます。Cloudflare は写真・動画とウェブページを配信する際に IP アドレスを処理し、その記録は Cloudflare のプライバシーポリシーと Cloudflare が定める期間に従います。ファイル保存の手前にある Cloudflare Worker の監視記録は切っています。
  • 通知の送信記録、端末ごとの最後のログイン日時、画面キャプチャの試みと写真・動画の保存、登録開始の記録 — 2

会話の画面でやりとりされる「新しいメッセージ」と「入力中」の合図は、サーバー(Supabase Realtime)を通じてその会話のふたりにだけ届きます。合図には内容がなく、合図そのものは残りません。

アプリには分析ツール、広告ツール、クラッシュ収集ツールは入っていません。

5利用目的と法的根拠

個人情報は次の利用目的のためだけに使います。目的ごとに、使う情報とその根拠をあわせて記載します。

サービスの提供
登録(ふたりの推薦、招待リクエスト、Kryptonチームへのリクエスト)、ログイン、投稿・返信・写真・動画の配送、つながり(会って QR コードでつながる場合を含む)と紹介、手渡す、新しいつながりに過去の投稿を見せること、予約投稿、消える投稿、取り戻す方法使う情報 — アカウント番号・公開鍵、登録状態、つながりの地図、投稿の外側の情報、封をした内容、招待・招待リクエスト、QR コード、設定、端末、取り戻す方法根拠 — 契約の履行(韓国個人情報保護法第15条第1項第4号、GDPR 第6条第1項(b))
通知
確認を待っていること、新しい会話、新しいつながり、画面キャプチャの試み、あなたの写真・動画が保存されたこと、アカウントを取り戻そうとする依頼を知らせるため。通知には名前も内容も載せません。使う情報 — 通知トークン、端末の種類、通知の言語、通知の設定、通知の送信記録根拠 — 契約の履行(韓国個人情報保護法第15条第1項第4号、GDPR 第6条第1項(b))
Krypton+ の提供
購入の確認、更新・解約・返金の反映、同じ購入をほかのアカウントが使えないようにすること、創設者が付与した Krypton+ の管理、写真の枚数・動画の長さ・元の画質・予約投稿の上限の判定使う情報 — Krypton+ の購入記録、登録状態と Krypton+ の期間根拠 — 契約の履行(韓国個人情報保護法第15条第1項第4号、GDPR 第6条第1項(b))
安全と運営
通報の処理、非表示、利用制限、招待なしのアカウントの大量作成の防止、Kryptonチームへのリクエストの見分け、画面キャプチャの試みと写真・動画の保存を画面や投稿の持ち主に知らせること、運営者の作業記録、お問い合わせへの回答と異議の処理使う情報 — 非表示・通報の記録、登録開始の記録、招待リクエストの見分けの印、キャプチャ・保存の記録、運営者の作業記録、お問い合わせ・ご請求のメール根拠 — 正当な利益(韓国個人情報保護法第15条第1項第6号、GDPR 第6条第1項(f)):メンバーと本サービスを不正利用から守り、画面や投稿の持ち主に知らせるため
法律が求めること
購入記録の保存、法律にもとづく求めへの対応、児童性的虐待コンテンツの通報、権利を侵害する投稿の削除依頼・申込みの撤回・開示等の請求の処理使う情報 — Krypton+ の購入記録、2 の情報、通報の控え、お問い合わせ・ご請求のメール根拠 — 法的義務(韓国個人情報保護法第15条第1項第2号、GDPR 第6条第1項(c))

これ以外の目的(広告、販売、プロファイリングなど)には使いません。

  • 同意にもとづいて取り扱う情報はありません。カメラ・写真・通知は端末で許可したときだけ使い、端末の設定でいつでもオフにできます。
  • 2 の情報は本サービスに欠かせません(取り戻す方法と Krypton+ の購入は選んだ人だけ、お問い合わせ・ご請求のメールは送った人だけ)。提供いただけない場合は Krypton を使えません。
  • 正当な利益にもとづく取り扱いには異議を述べることができます(13)。

私たちは、健康・信条・政治的な見解などの要配慮個人情報を受け取ったり、別に集めたりしません。つながりの地図が知っているのは誰と誰がつながっているかだけで、その人の職業や関係の性質は知りません。

6ほかのメンバーに見えるもの

すべてのメンバー
名刺 — 名前、自己紹介、推薦人、ぼかした(モザイク)プロフィール写真。
2次のつながり
半分ぼかしたプロフィール写真
つながり
元のプロフィール写真、公開範囲「つながり」で書いたあなたの投稿
選んで受け取った人
自分にだけ届いた投稿であることを示す「選んで」の印と、その投稿。その投稿を受け取ったほかの人は見えません。投稿者は受け取った人の一覧を見ます。
新しいつながり
あなたが最近30日に公開範囲「つながり」で書いた投稿を、最大30件まで見ます。設定の「これまでの投稿を見せる」でオフにできます。
返信した人と投稿者
投稿への返信は、投稿者と返信した人のふたりだけが見ます。共感は投稿者だけが知ります。
手渡された人
受け取った人が自分のつながりに投稿を手渡すと、手渡された人もその投稿を見ます。選んで送った投稿と「自分だけ」の投稿は手渡せません。
画面の持ち主
あなたが他の人の会話・ページ・投稿をキャプチャしようとすると、その人に通知が届き、その人の新着にあなたの名前が表示されます。
投稿者(保存)
あなたがフィード投稿の写真・動画を写真アプリに保存すると、投稿者に通知が届き、その人の新着にあなたの名前が表示されます。会話の写真の保存は知らせません。
QR コードの持ち主
あなたが QR コードを読み取ってつながりを申し込むと、あなたの名前はその QR コードの持ち主だけが見ます。
Kryptonチーム
Kryptonチームに参加をリクエストすると、チームがそのリクエストの名前・自己紹介・誰と使うかを見ます(8)。

名刺(名前・ひとこと自己紹介)はすべてのメンバーに見えます。健康や信条などの配慮が必要な内容は名刺に書かないでください。投稿は公開範囲(つながり・選んで・自分だけ)で見る人を決められます。

7保存期間と削除

情報ごとに次の期間だけ保存し、期間が過ぎたら削除します。いま使われていない関係の記録は、毎日一回自動で削除します。

解除したつながり
解除から30日
返事のない申し込み・紹介
最後の動きから30日
「見送り」の記録
180日
使われなかった招待
期限切れ・取り消しから30日(登録に使われた招待は推薦人の記録とともに残ります)
ログインの確認値
期限切れから1日
処理済みの通報
処理が終わり、通報から180日が過ぎたとき(処理前の通報は残ります。法律が保存を求める通報 — 例:米国 NCMEC に通報したものは通報から1年 — はその期間残します)
画面キャプチャの試みと写真・動画の保存
30日
通知の送信記録
30日
消える投稿
24時間(書くときに選べば表示された時から、あとで選べばその時から)。投稿・会話・写真の記録は1分以内に、写真・動画ファイルはその後すぐに保存先から削除します。
登録開始の記録(IP の確認値)
2日(毎日自動で削除します)
QR コードとその申し込みの記録
期限切れから1日
招待リクエスト、過去の投稿を見せた記録
アカウントを使っている間(アカウントを削除すると一緒に削除します — 12)
Krypton+ の購入記録
取引から5年(韓国の電子商取引消費者保護法が定める代金決済記録の保存期間)。ただし、まだ使っている利用権(終わっていない「永久」)の記録は、そのアカウントがある間は残します。
お問い合わせ・ご請求のメール
対応を終えた日から3年(韓国の電子商取引消費者保護法が定める苦情・紛争処理記録の保存期間)
運営者の作業記録
措置の日から3年間、変更できない形で残し、その後削除します
その他の情報
アカウントを使っている間。アカウントを削除した後に削除するものと残るものは 12 に記載しています。

保存期間が終わったとき、または目的を果たしたときは、遅滞なく削除します。データベースの行を消し、写真・動画ファイルは保存先から消して、元に戻せないようにします。削除した情報は、本番データベースの毎日のバックアップに最大7日残ったあと消えます(バックアップは障害からの復旧にだけ使います)。法令のために保存する購入記録は、ほかの情報と分けて置き、その目的にだけ使います。

8通報と運営者による閲覧

運営者は投稿を見ることができず、見られるようにする仕組みも置いていません。そのかわり、通報のときに通報する人の端末がその対象を運営者に開きます。

運営者が通報されたものを見るのは、規約違反や違法な情報に対応し、法律が求める措置をとるためです(5 — 正当な利益・法的義務)。

投稿・返信を通報すると
運営者は、通報した時点のその投稿・返信と、付いている写真・動画(ファイルがまだあれば)、書いた人の名前を見ます。消える投稿が消えたり、あとで投稿が削除されたりしても、通報時点の封をした控えは通報の記録とともに残ります。
人を通報すると
運営者はその人の名刺(名前・自己紹介・ぼかした写真)を見ます。元の写真は送られません。
Kryptonチームにリクエストすると
チームの端末が封を開いて名前・ひとこと自己紹介・誰と使うかを見て、同じ日に同じ場所から始めたアカウントの数と、アカウントを作ってからリクエストするまでにかかった時間もあわせて見ます。チームはこれを見て承認するかどうかを決めます。
あわせて見る外側の情報
通報した人と通報された人のアカウント番号、理由、日時。アカウントごとの状態・役割・登録と削除の日時・会員番号・Krypton+ の期間・つながりの数・推薦人の数・端末の数・通報の数。名前はありません。
運営者の作業記録
誰がいつ、どのアカウントにどんな措置(停止・解除・通報の処理、創設者による Krypton+ の付与・取り消し)をしたかとそのメモを、措置の日から3年間、変更も削除もできない形で残します(7)。
見ないもの
通報されていない投稿、その人のほかの投稿や会話

措置をとったときは、通報されたメンバーにその理由を知らせます(アプリ内のお知らせが整うまでは support@krypton.today へのお問い合わせにお答えします)。誰が通報したかは知らせません。異議は利用規約 6の手続きに従います。

通報の控えは運営者が開けるため、法律にもとづく求めがあれば、通報の記録とともに提供されることがあります(9)。

処理済みの通報は、処理が終わり、通報から180日が過ぎたら削除します(処理前の通報は残ります。法律が保存を求める通報 — 例:米国 NCMEC に通報したものは通報から1年 — はその期間残します。7)。通報した人のアカウント番号は記録に残るため、通報を濫用すれば分かります。

9第三者提供

個人情報を売ったり、広告・マーケティングの目的でほかの会社に渡したりしません。次の場合にだけ提供します。

  • 法令にもとづく求め — 令状など法律が定める手続きを備えた求めかを確かめたうえで、必要な分だけ提供します。提供できるのはサーバーが知っている情報(2)と、通報によって運営者に開かれた控え(8)だけで、それ以外の封をした内容は私たちにも開けません。法律が許す範囲で、該当するメンバーに知らせます。
  • 児童性的虐待コンテンツの通報 — 児童性的虐待コンテンツを見つけたときは、法律にもとづき米国の NCMEC(全米行方不明・被搾取児童センター)と関係機関に通報し、そのコンテンツと関連するアカウントの情報をあわせて送ります。
  • 差し迫った危険 — 人の生命・身体に差し迫った危険が明らかなときは、それを防ぐのに必要な範囲でのみ、警察などの関係機関に知らせます。
  • Krypton+ の決済 — メンバーが Krypton+ を購入するときは、決済を処理するストア(現在は Apple で、Android の Google Play 決済は準備中です)に、アカウント番号(ランダムな番号)が取引とともに渡ります。私たちがストアから受け取るのは、取引番号・商品・期間・返金の有無だけです。ストアは自らのプライバシーポリシーにもとづいて決済情報を扱います。

10委託先

本サービスの運営のため、次の会社に業務を委託しています。これらの会社が扱うのは、封をした暗号文、2 の情報、そして配信中の接続情報です。

Supabase, Inc.
データベース、サーバー関数、Realtime(会話のリアルタイムの合図)
Cloudflare, Inc.
写真・動画ファイル(暗号文)の保存と配信 — R2 と Workers。krypton.today のウェブサイトと、招待・招待リクエスト・QR のリンクのページの配信 — Pages。support@・privacy@krypton.today に届くメールを当社のメールボックスへ転送 — Email Routing
Zoho Corporation
当社のメールボックス — support@・privacy@krypton.today で受け取ったお問い合わせ・ご請求のメールを保管します
Apple Inc.
iPhone の通知の配信(Apple Push Notification service)。端末の通知トークンと通知の文面を渡します。文面には名前も内容もありません。会話の通知には受け取る人の端末だけが開ける一行が一緒に載り、Apple が見るのは暗号文だけです。Apple はトークンがどの端末のものかを知っています。
Google LLC
Android の通知の配信(Firebase Cloud Messaging)。端末の通知トークンと、名前も内容もない通知の文面を渡します。会話の通知には受け取る人の端末だけが開ける一行が一緒に載り、Google が見るのは暗号文だけです。Google はトークンがどの端末のものかを知っています。

私たちはこれらの会社とデータ処理契約を結び、委託した業務の外では情報を使わず、このポリシーと同等以上の水準で保護させています。ほかの会社への再委託も、その契約が定めるとおりにだけ行います。委託先が変わるときは、このポリシーを改めてお知らせします。

Krypton+ の決済はストアが自らの責任で処理するため、委託ではなく 9 に記載しています。

11外国への移転

本サービスを使う間、情報はネットワークを通じて随時、次の国に移転し、保存・処理されます。移転にはすべて暗号化された接続(HTTPS)を使います。

Fantagram Inc.
  • 国米国・大韓民国
  • 時期・方法運営者が運営と通報の処理のため、暗号化された接続で運営者ページにアクセスするとき
  • 項目2 の情報、通報の控え、Kryptonチームへのリクエスト
  • 目的本サービスの運営、通報の処理、参加リクエストの確認
  • 保存期間7 に記載のとおり
  • 連絡先privacy@krypton.today
Supabase, Inc.
  • 国大韓民国ソウル(AWS)に保存、運営会社は米国。サーバー関数は処理の間だけ、アプリを使う場所に最も近い Supabase の地域で実行され、その国は大韓民国・日本・シンガポール・インド・オーストラリア・米国・カナダ・ブラジル・アイルランド・英国・フランス・ドイツ・スイスのいずれかです。
  • 時期・方法アプリを使うたびに、暗号化された接続で
  • 項目2・3 の情報(3 は暗号文)
  • 目的データベース、サーバー関数、リアルタイムの合図
  • 保存期間7 に記載のとおり(削除した情報はバックアップに最大7日長く残ります)
  • 連絡先privacy@supabase.com
Cloudflare, Inc.
  • 国ファイルの保存は Cloudflare がアジア太平洋地域に置くデータセンター(Cloudflare は国を公表しておらず、地域も保証していません)、配信は利用者に近い世界各地の Cloudflare データセンター。本社は米国
  • 時期・方法写真・動画をアップロード・ダウンロードするとき、krypton.today を開くとき
  • 項目写真・動画ファイルの暗号文、配信中の IP アドレス
  • 目的ファイルの保存・配信、ウェブサイトの提供
  • 保存期間ファイルは投稿が削除されるまで、アクセス記録は Cloudflare が定める期間
  • 連絡先privacyquestions@cloudflare.com
Apple Inc.
  • 国米国
  • 時期・方法iPhone に通知を送るとき、Krypton+ を購入するとき
  • 項目通知トークン、名前も内容もない通知の文面、会話の通知の封をした一行、Krypton+ 購入時に取引に載せるアカウント番号(9)
  • 目的iPhone の通知、Krypton+ の決済をアカウントに結びつけること
  • 保存期間通知は配信の間、取引記録は Apple のプライバシーポリシーに従います
  • 連絡先Apple のプライバシーに関する問い合わせ
Google LLC
Cloudflare, Inc.(Email Routing)
  • 国送信者に近い世界各地の Cloudflare データセンター。本社は米国
  • 時期・方法support@・privacy@krypton.today にメールを送るとき、当社のメールボックスへ転送する間
  • 項目送信者のメールアドレス、メールに書いた名前と内容
  • 目的お問い合わせ・ご請求のメールを当社のメールボックスへ転送
  • 保存期間転送する間だけ扱い、保存しません。配信の記録は Cloudflare が定める期間
  • 連絡先privacyquestions@cloudflare.com
Zoho Corporation
  • 国米国
  • 時期・方法お問い合わせ・ご請求のメールが当社のメールボックスに届くとき
  • 項目送信者のメールアドレス、メールに書いた名前と内容
  • 目的お問い合わせ・ご請求への回答
  • 保存期間7 に記載のとおり
  • 連絡先privacy@zohocorp.com
Google LLC(Google Fonts)
  • 国米国
  • 時期・方法krypton.today を開くとき、ブラウザが直接
  • 項目IP アドレス、ブラウザの情報、リクエストしたアドレス
  • 目的ウェブサイトのフォントの読み込み
  • 保存期間Google のプライバシーポリシーに従います
  • 連絡先Google のプライバシーに関する問い合わせフォーム

これらの移転なしには本サービスを提供できません。望まない場合は、アカウントを削除して移転を止めることができます(12)。

EU・英国 — 大韓民国は、EU と英国が十分な水準の個人情報保護を認めた国です。それ以外の国へ移転するときは、十分性認定や EU 標準契約条項などの保護措置を用い、その写しは privacy@krypton.today に請求できます。

日本 — 移転先の会社が日本の法律の求める水準の措置を講じるよう、契約で定めています(基準適合体制)。ご請求があれば、その内容と各国の制度に関する情報をお知らせします(国ごとの制度は、個人情報保護委員会「外国における個人情報の保護に関する制度等の調査」)。

12アカウントの削除

Krypton(運営:Fantagram Inc.)のアカウントを削除する方法です。アプリの設定の一番下にあるアカウントを削除から、ご自身で削除します。アカウントの鍵があるその端末でのみ行えます。登録待ちや停止中のアカウントはアプリから削除できないため、下の「アプリを使えないとき」のとおり privacy@krypton.today にご依頼ください。元に戻せません。

アカウントを削除しても、ストアの自動更新サブスクリプションは自動では解約されません。 先に端末のストアのサブスクリプション設定(Krypton の設定の「サブスクリプションを管理」)で解約してください。Krypton+ は購入したひとつのアカウントにだけ適用されるため、アカウントを削除すると残りの期間(「永久」を含む)はほかのアカウントに移すことも、元に戻すこともできません。

削除するもの

  • あなたが書いた投稿・返信・ひとことと、その写真・動画ファイル、あなたの投稿での会話
  • あなたのプロフィールとその封筒、あなた宛ての封筒すべて(ほかの人の投稿はもう開けません)
  • 端末の情報と通知トークン、取り戻す方法とあなたが預かった鍵のかけら、取り戻す依頼、見送りの記録、会員の鍵の封筒、暗号化用の公開鍵
  • 会員番号と Krypton+ の期間(創設者が付与した記録を含む)、非表示の記録(あなたがしたものと、あなたに対してされたもの)、通知の設定、あなたが送った招待リクエスト(Kryptonチームに送った封をした自己紹介を含む)、過去の投稿を見せた記録(あなたが見せたものと、あなたが見せてもらったもの)

解除・取り消すもの

  • つながりをすべて解除します(解除した記録は30日後に削除されます)
  • あなたが送った進行中の招待を取り消します

残るもの

アカウント番号と状態
アカウント番号、署名用の公開鍵、登録・削除の日時と状態。ほかのメンバーの推薦人の記録がこの番号を指していて、推薦のつながりを確かめるのに必要なため、本サービスを運営する間は残します。名前はもともとサーバーにありません。
推薦人の記録
誰が誰を招き入れたか。同じ理由で、本サービスを運営する間は残します。
通報の記録
処理が終わり、通報から180日が過ぎたら削除します。法律が保存を求める場合はその期間残します。
Krypton+ の購入記録
取引から5年(韓国の電子商取引消費者保護法)が過ぎたら削除します。アカウントを削除した後は、「永久」の記録も同じです。
そのほかに残る記録
あなたが投稿を手渡した記録(誰に手渡したかと封をした理由)と、ほかの会員があなたに投稿を手渡した記録 — 手渡しの経路をほかの会員の画面に表示するために使い、その投稿が削除されると一緒に削除されます。招待を任された記録。アカウントを削除した後も残ります。
期間が決まっている記録
通知の送信記録(30日)、画面キャプチャ・保存の記録(30日)、登録開始の記録(2日)、QR コードとその申し込み(期限切れから1日)、お問い合わせ・ご請求のメール(対応を終えた日から3年)— 7 の期間が過ぎたら削除します。
運営者の作業記録
7 のとおり3年後に削除します。
ほかの人に届いたもの
すでにほかの人の端末に届いた投稿や写真、受け取った人が写真アプリに保存した写しは取り戻せません。ほかの人があなたに書いた返信は、その人のものとして残ります。

アプリを使えないとき

アカウントの鍵がある端末がない場合は、取り戻す方法でアカウントを取り戻してから削除してください。取り戻す方法がない場合や、登録待ち・停止中のアカウントの場合は privacy@krypton.today にご請求ください。私たちは名前やメールアドレスを受け取っていないため、アカウントの持ち主であることを確認できなければ削除できませんが、そのアカウントの内容は私たちには開けない暗号文です。

13利用者の権利と開示等の請求の手続き

ご自身の個人情報の開示・訂正・削除・利用停止を求める権利があります。EU・英国の方には、取り扱いの制限を求める権利、データポータビリティの権利、正当な利益にもとづく取り扱いに異議を述べる権利、監督機関に苦情を申し立てる権利もあります。

アプリで直接

  • プロフィールの編集、投稿の編集(投稿後10分まで)・削除、消える投稿への切り替え、会話を閉じる
  • つながりの解除、投稿を表示しない、「これまでの投稿を見せる」のオフ
  • 通知の種類ごとのオフ(会話・キャプチャ・写真の保存・お願い)、サブスクリプションを管理
  • アカウントの削除(12)

開示等の請求の手続き

  • 請求先 — privacy@krypton.today。手数料はかかりません。
  • 本人確認 — 私たちは名前もメールアドレスも知らないため、そのアカウントの鍵による署名で確認します。端末をなくした場合は、取り戻す方法でアカウントを取り戻してからご請求ください。確認できない場合は、法律が許す範囲で請求に応じられないことがあります。
  • 代理人 — 代理人による請求もできます。ご本人の委任と、本人確認のためのそのアカウントの鍵による署名が必要です。
  • 開示・写し — 封をした内容は私たちには開けないため、サーバーが知っている情報(2)をお渡しします。封をした内容はアプリで直接ご覧いただけます。

回答の期限

ご請求を受けてから10日以内に回答します。その間に対応が難しい場合は、理由といつまでに対応するかをお知らせします(EU・英国にお住まいの方には、法律が定める1か月以内)。

私たちは、人の関与なしに、メンバーの権利に重大な影響を与える自動化された決定を行いません。

相談できる窓口

回答がない、または処理が不当だと感じた場合は、次の機関に相談できます。

  • 日本にお住まいの方 — 個人情報保護委員会
  • 韓国:個人情報紛争調整委員会 1833-6972(kopico.go.kr)
  • 韓国:個人情報侵害申告センター 118(privacy.kisa.or.kr)
  • 韓国:大検察庁 1301(spo.go.kr)
  • 韓国:警察庁 182(ecrm.police.go.kr)
  • EU・英国にお住まいの方 — お住まいの国の監督機関

14子ども

Krypton は18歳以上の方のためのサービスです。14歳未満の子どもを含め、18歳未満の方の個人情報を知りながら受け取ることはしません。招待し推薦するメンバーも、18歳未満の方を招き入れてはいけません。18歳未満の方の登録が分かった場合は、アカウントを閉じてその情報を削除します。そのような場合に気づいたら、privacy@krypton.today にお知らせください。

15安全管理措置とその限界

組織的・人的安全管理措置

  • 個人情報を扱う人を最小限の運営者に限ります。運営者の権限は、アプリのアカウントとは別の運営者ページのアカウントで与えます。例外はふたつです — Kryptonチームへのリクエストはチームの端末(チームのアカウント)で開き、Krypton+ の付与・取り消しは創設者のアプリで行います。
  • 運営者が変更したこと(停止・解除・通報の処理、Krypton+ の付与・取り消し)は、3年間、変更も削除もできない記録に残します(7)。

技術的安全管理措置

  • 投稿・プロフィール・ファイルは端末で封をします(エンドツーエンド)。アカウントの秘密鍵は端末の安全な保存領域にだけあります。
  • データベースはサーバー関数だけが使えるようにし(行単位のアクセス制御)、ファイルのアドレスは公開せず、封筒を持つ人にだけ短い通行証を渡します。
  • 通信はすべて暗号化された接続(HTTPS)で行います。
  • 通報を開く運営者の鍵は運営者の端末にだけ置き、サーバーには送りません。
  • 取り戻す方法の暗証番号を5回間違えると24時間ロックし、招待に書いた名前を5回間違えるとその招待を取り消します。
  • 通知には名前も内容も載せません。
  • アプリの画面は、標準でキャプチャ・録画できません。
  • 本番データベースは毎日バックアップします(7日間保存)。
  • 過去の関係の記録は期間が過ぎれば削除します(7)。

物理的安全管理措置

サーバーは Supabase(AWS)と Cloudflare のデータセンターにあり、これらの会社の物理的なセキュリティ管理を受けています。

外的環境の把握

私たちは、米国・大韓民国(運営者、データベース)、サーバー関数が実行されることのある日本・シンガポール・インド・オーストラリア・カナダ・ブラジル・アイルランド・英国・フランス・ドイツ・スイス、そして Cloudflare がアジア太平洋地域に置くデータセンター(国は Cloudflare が公表していません)で個人情報を取り扱い、各国の個人情報保護の制度を把握したうえで安全管理措置を講じています(11)。

防げないこと

  • 別の端末のカメラで画面を撮ること
  • 受け取った人が写真・動画を自分の写真アプリに保存すること(フィード投稿なら投稿者に知らせ、会話の写真は知らせません)
  • 投稿を受け取った人が内容をほかの場所に写すこと
  • つながりの地図の形 — ひとりの名前が分かれば、つながりをたどって周りを推測できます
  • メンバーが見られる名刺を誰かが集めること — 遅らせることはできても、完全には防げません

16トラッキング・広告・クッキー

アプリには分析・広告・クラッシュ収集のツールがありません。広告識別子を読まず、ほかの会社のデータと結びつけず、広告も表示しません。ほかの会社がアプリやウェブサイトを通じてメンバーの行動を集めることを許していません。私たちはトラッキングをしないため、ブラウザの「トラッキング拒否(Do Not Track)」の信号によって動作を変えることはありません。

krypton.today はクッキーを使いません。選んだ言語だけがブラウザの保存領域(localStorage)に残り、これは個人情報ではありません。ブラウザの設定でサイトのデータを消すとなくなります。フォントを Google Fonts から読み込むため、ページを開くとブラウザが IP アドレス・ブラウザの情報・リクエストしたアドレスを Google LLC(米国)に送ります(目的:フォントの読み込み。Google のプライバシーポリシーに従います)。

招待リンク・招待リクエストのリンク・QR のページは、リンクの # の後ろにある名前と秘密をサーバーに送らず、ページの中だけで読み取ってアプリに渡します。ウェブサイトは Cloudflare が提供しており、Cloudflare がアクセス記録を見ます(4)。

17個人情報の責任者・お問い合わせ・苦情の申出先

運営者
Fantagram Inc. · 131 Continental Dr., Suite 305, Newark, DE 19713, U.S.A.
代表者
ご請求があれば遅滞なくお知らせします(privacy@krypton.today)
個人情報の責任者
William Yang(COO)
個人情報のお問い合わせ・苦情の申出先
privacy@krypton.today(個人情報に関するお問い合わせ・権利の行使・苦情)
サービスのお問い合わせ
support@krypton.today

18このポリシーの変更

このポリシーを変更するときは、変更内容と施行日を、施行の7日前に、利用者に不利な変更は30日前に、アプリとこのページでお知らせします。以前の版はこのページで見られるようにしておきます。

この版:v1.0 · 公表・施行 2026-10-03(初版)

このポリシーは韓国語・英語・日本語で提供しています。内容が異なる場合は韓国語版に従います。