KONGLE Privacy Policy
- Effective date: 24 September 2026 (moved back one month on 17 August 2026 so that a lawyer can review these documents first)
- Revised: 24 August 2026 (embedded video in lesson content added — Articles 6-3 and 8: nothing is sent before you press play, and the items transferred to Google LLC on playback are recorded in the overseas-transfer table. No lesson uses this yet — a build check enforces that the clause ships before the content does)
- Previously revised: 23 August 2026 (optional collection of a full legal name when applying for an Activity Certificate — Article 2 paragraph 3 and Article 4: collected only on application and destroyed on issuance / scope of “service notifications” made explicit — Article 2 paragraph 1: answers, accepted answers and comments only; no promotional email)
- Previously revised: 18 August 2026 (how deleted posts are actually retained — Article 4: the text remains for handling reports, while attached photos are destroyed at once. The previous table said only “until deleted”, which was not what the service did)
- Previously revised: 17 August 2026 (linked service (JoyCollab) stated — Article 6-2 / video tool for Live Free-Talking — Articles 7, 8, Terms Article 15 / usage analytics purpose — Articles 7, 8 / anonymous handling of lesson reports — Article 2 / visibility of posts and nicknames — Article 2, Terms Article 12 / legal bases for processing under the GDPR — Article 12(3))
- This is an English translation provided for your convenience. The Korean version is the authoritative text; if the two differ, the Korean version governs.
Gongreen Co., Ltd. (“the Company”) establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal data of data subjects and to handle related concerns promptly.
Article 1 (Purposes of Processing)
The Company processes personal data for the purposes below and does not use it for any other purpose. If a purpose changes, consent will be obtained in advance.
| Area | Purpose |
|---|---|
| Account management | Verifying intent to register, identification and authentication, maintaining membership, blocking registration by anyone under 14, preventing misuse, delivering notices |
| Learning service | Storing and syncing progress and streaks across devices, deciding “continue” and lesson unlocking |
| Community | Publishing and displaying posts, handling reports and blocks, protecting minors and community safety |
| Live free-talking | Accepting participation requests and providing entry information |
| Service improvement | Usage statistics, identifying drop-off points in content, developing new features |
| Complaint handling | Receiving and confirming enquiries and notifying outcomes |
Article 2 (Categories of Personal Data Processed)
1. Collected at registration (required)
| Item | Reason |
|---|---|
| Email address | Account identifier, delivery of notices and service notifications |
| Password | Authentication (stored as a one-way hash; the Company cannot read the original) |
| Nickname | Shown in the Service and the community — once you post, anyone can see it without signing up (see the note below) |
| Date of birth | Verifying that the user is 14 or older, and protecting minors — not used for any other purpose |
| Interface language | Display language setting |
What “service notifications” means Emails that tell you the outcome of something you did in the Service. Specifically: (1) someone answered a question you asked, (2) an answer you wrote was chosen, and (3) someone commented on a post you wrote. We do not send advertising or promotional email. These notifications are on by default; you can turn them off at any time in Settings, and every notification email also tells you how. Learning reminders (streak nudges) are separate and are only sent if you turned them on yourself.
Why we collect a full date of birth rather than only the year of birth: the age of 14 must be determined as an exact age, and a year of birth alone leaves an error of up to one year because it does not show whether the birthday has passed. That would not satisfy the legal requirement to accurately block registration by children under 14. In addition, whether a user is a minor changes over time and must be recalculated. Date of birth is never shown anywhere in the Service or in API responses, and is not disclosed to other users.
2. Generated or collected while using the Service
| Item | Description |
|---|---|
| Learning records | Lesson completion, scores, completion time, the user’s local completion date, streak |
| Posts | Text, images and comments published in the community or Q&A — these are public (see the note below) |
| Access logs | IP address, access time, service usage history |
| Device information | Browser type and version, operating system, display language setting |
| Learning settings | Daily study goal (5/10/15 minutes), consent to receive study reminders |
Posts and nicknames are public. Anything you publish in the community or Q&A — posts, comments, images — and the nickname shown with it can be read by anyone without signing up or logging in, and may be collected and indexed by search engines. Deleting a post removes it from the Service immediately, but copies outside the Company’s control, such as search engine caches, may remain for some time.
For that reason, please do not write contact details, addresses, or where you study or work into a post. Your email address and date of birth are never shown to other users (see the note under Article 2.1).
Lesson reports are not covered by any row above. Text sent through “Something wrong with this lesson?” on a lesson page is stored without anything identifying the sender, and this is true whether or not you are logged in. The Company cannot tell who sent a report, and therefore cannot reply to one. If you write contact details into the text yourself, they are stored as written — which is why the form asks you not to.
3. Optional — collected only when a volunteer applies for an Activity Certificate
The Company collects the following item only when a Korean-speaking volunteer applies for an “Activity Certificate”. It is not collected at registration, and this paragraph does not apply to members who do not apply.
| Item | When collected | Why | Retention |
|---|---|---|---|
| Full legal name | Only when applying for an Activity Certificate | To identify the applicant on the certificate | Destroyed as soon as the certificate is issued — it is not stored |
Why it is needed. An activity certificate states who carried out the activity, so a certificate bearing only a nickname is useless — the recipient cannot connect it to the person. The Company therefore collects the name that will appear on the certificate, and only from the person who applies.
How it is handled. At the time of application the Company gives notice of the purpose and of when the data will be destroyed, obtains consent, and destroys the name as soon as the certificate is issued. The record kept of an issuance (document number, nickname, activity period, issue date) does not include the name.
Each certificate carries the sentence “The name shown on this certificate was supplied by the applicant; the Company does not retain it after issuance.”
4. Use without registration
A non-member user’s progress is stored only in that user’s browser storage (localStorage) and is not transmitted to the Company’s servers. On registration or login, the record is transferred to the account at the user’s request.
5. Data we do not collect
At registration the Company does not collect a real name, resident registration number, gender, telephone number or postal address.
The name described in paragraph 3 above has nothing to do with registration. It is supplied by the member during the certificate application itself and is destroyed on issuance, so it is never retained. Resident registration number, gender, telephone number and postal address are not collected by any route.
Article 3 (Personal Data of Children Under 14)
- The Company does not accept registration from anyone under 14 years of age.
- Where the date of birth entered during registration indicates the applicant is under 14, registration is refused and the information entered up to that point is not stored.
- Where a user is found to be under 14 after registration, the Company will suspend the account and destroy the personal data collected without delay.
Article 4 (Processing and Retention Periods)
- The Company processes and retains personal data within the period consented to at the time of collection.
- Retention periods are as follows:
| Category | Retention period |
|---|---|
| Account information (email, password, nickname, date of birth, interface language) | Until withdrawal of membership; destroyed within 30 days of the withdrawal request |
| Learning records | Destroyed together with the account on withdrawal |
| Posts | Until deleted by the member or the member withdraws. The text of a deleted post is retained in a form only operators can read, so that reports about it can still be handled; it is not shown to other members |
| Photos attached to posts | The file is destroyed as soon as the member deletes the post or withdraws (unlike the text, it is not retained) |
| Access (login) logs | 3 months (Protection of Communications Secrets Act, Article 15-2) |
| Records of misuse | Retained for 1 year to prevent misuse, then destroyed |
| Name supplied when applying for an Activity Certificate | Not retained — destroyed as soon as the certificate is issued (Article 2, paragraph 3) |
- Where retention is required by applicable law, data is kept for the period prescribed.
- If the Company begins offering paid services or selling goods, record-retention obligations under the Act on Consumer Protection in Electronic Commerce (contracts and withdrawal of subscription: 5 years; payment: 5 years; consumer complaints and dispute handling: 3 years) will apply. The Company will give notice and amend this Policy at that time. At present the Company does not process payments, so those obligations do not apply.
Article 5 (Destruction of Personal Data)
-
The Company destroys personal data without delay once the retention period has elapsed or the purpose has been achieved.
-
Method of destruction:
- Electronic files: permanently deleted by technical means that prevent recovery.
- Printed material: shredded or incinerated.
-
Destroyed learning records and posts cannot be recovered.
-
For statistical purposes to improve the Service, the Company retains the following information when a member withdraws, in a form that cannot identify an individual. It contains no member ID, email address, nickname, or any other item that can be linked to a specific person, and a withdrawn member cannot be re-identified from it.
Retained Form Date of withdrawal Date only (no time of day) Length of membership Range (same day / 1–6 days / 7–29 days / 30–89 days / 90+ days) Number of lessons completed Range (0 / 1–2 / 3–11 / 12–35 / 36+) Whether onboarding was completed Yes / No This information is anonymized information that does not constitute personal data under the Personal Information Protection Act, and is therefore excluded from destruction. It is not used for any purpose other than understanding withdrawal trends.
Article 6 (Provision to Third Parties)
- The Company does not provide personal data to third parties.
- The following are exceptions:
- where the data subject has given separate consent;
- where there is a special provision in law, or it is unavoidable in order to comply with a legal obligation;
- where an investigative authority requests it under the procedures and methods prescribed by law.
Article 6-2 (Linked Services)
The Service shows links to JoyCollab (jcollab.com), a virtual-space service the Company also operates.
- Using it is optional. If you never open the link, nothing in Kongle is limited — lessons, the community and every other feature work exactly the same.
- The operator is the same. JoyCollab is operated by Gongreen Co., Ltd., the same company that operates Kongle. This link is therefore not a provision to a third party under Article 6; it is processing within the same controller.
- Your Kongle account details are not passed on. Opening the link creates a guest (temporary) account on JoyCollab that requires no email address and no password. The Company does not pass your Kongle member identifier, email address or nickname to JoyCollab. You enter anonymously, whether or not you have a Kongle account.
- Data processed while you use JoyCollab is governed by JoyCollab’s own privacy policy. This includes access records, display name and messages you send there. See the JoyCollab Privacy Policy and JoyCollab Terms of Service (Korean).
- We tell you before you click. The points above are shown on the screen that holds the link (Live > Open rooms), before you open it.
Article 6-3 (Embedded Video in Lesson Content)
Some lessons may include a short segment (up to 40 seconds) of a YouTube (Google LLC) video, so that you can see a Korean expression being used in a real situation.
- Nothing is sent until you press play. Simply opening a lesson sends no request to YouTube. Not even the preview thumbnail is loaded — fetching a thumbnail is itself the same kind of request. The video is loaded only at the moment you press the play button.
- What is transferred when you press play. Your IP address, browser and device information, and the address of the video being played are sent to Google LLC. Details are recorded in the table in Article 8 (Overseas Transfers).
- We use the cookie-minimising address. The Company loads videos from the
youtube-nocookie.comdomain. Processing carried out by Google LLC after playback is governed by the Google Privacy Policy. - You do not have to watch. Video is supplementary. Not playing it places no limit on the lesson, its quiz, or course completion.
- The Company does not store videos or add subtitles to them. The single Korean line shown alongside a video is the expression that lesson teaches, not a transcript of the dialogue in the scene.
Article 7 (Outsourcing of Processing)
| Processor | Work outsourced | Processing location | Retention |
|---|---|---|---|
| Oracle Corporation (Oracle Cloud Infrastructure) | Operation and storage of servers and databases | Republic of Korea (Chuncheon region) | Until the end of the contract or withdrawal of membership |
| Cloudflare, Inc. | Website hosting, content delivery (CDN), traffic protection, usage analytics | Overseas (global edge network) | Until the end of the contract |
| Google LLC (Google Meet) | Running the video sessions for Live Free-Talking | Overseas (United States and others) | Until the session ends (the Company does not store it separately) |
- When entering into an outsourcing contract, the Company specifies the matters necessary for safe management of personal data and supervises the processor.
- Any change to the outsourced work or the processor will be disclosed through this Policy.
Note on processing that is not outsourcing (for transparency): the Company uses Microsoft Azure Speech (Korea Central region) to produce the learning audio. Only the Korean sentences of the learning content are transmitted in that process; no user personal data is transmitted. The audio files are produced in advance and included in the Service, so nothing is sent externally when a user plays audio. This is therefore not outsourcing of personal data processing, but it is described here to aid understanding.
Article 8 (Transfer of Personal Data Overseas)
| Recipient | Country | Items transferred | Time and method | Purpose | Retention |
|---|---|---|---|---|---|
| Cloudflare, Inc. | United States and others (global edge network) | IP address, browser and device information, requested URL | Transmitted automatically over the network when the Service is used | Website hosting, content delivery and security, usage analytics | Until the end of the contract |
| Google LLC (Google Meet) | United States and others | Display name, audio and video, IP address, time of joining | Transmitted over the network when you open the join link for a Live Free-Talking session | Running the video session | Until the session ends (the Company does not record or store it) |
| Google LLC (YouTube) | United States and others | IP address, browser and device information, address of the video played | Transmitted over the network at the moment you press play on a video in a lesson | Playing supplementary lesson video (Article 6-3) | The Company retains nothing (governed by Google LLC’s policy) |
On usage analytics: the Company uses Cloudflare Web Analytics. It does not use cookies and shows only aggregate figures — visit counts, referral sources and per-page drop-off. It does not identify individuals or track behaviour per user, and the items sent to it are the same ones already listed in the table above (IP address, browser and device information, requested URL). Nothing new is collected.
Live Free-Talking is an optional feature that only members who sign up take part in. If you do not join, no transfer to Google LLC takes place, and there is no limit on your use of lessons, the community or any other feature. The Company does not record sessions, and recording between participants is prohibited by Article 15 of the Terms of Service.
Supplementary lesson video works the same way: it happens only for the person who presses play. Leaving a lesson open sends nothing to YouTube (not even a thumbnail), and not playing a video places no limit on the lesson, its quiz, or course completion. See Article 6-3.
- Data subjects may refuse the overseas transfer of their personal data. Use of the Service may be limited as a result.
- The Service’s main database and account information are stored within the Republic of Korea (Oracle Cloud Chuncheon region) and are not transferred overseas.
- If the Company later adopts services from overseas providers, such as analytics tools, it will amend this Policy in advance and obtain separate consent where required.
Article 9 (Rights of Data Subjects and How to Exercise Them)
- Data subjects may at any time exercise the following rights in relation to the Company:
- request access to their personal data;
- request correction where there is an error;
- request deletion;
- request suspension of processing.
- Rights may be exercised through the settings screen in the Service, by email (help@gongreen.co.kr) or by telephone (0502-1931-9869). The Company will act without delay (within 10 days).
- Members may withdraw directly using the account deletion function in the Service; Article 4 then applies.
- Where a data subject requests correction of an error, the Company will not use or provide the data concerned until the correction is complete.
- Rights may be exercised through a legal representative or an authorised agent.
Article 10 (Chief Privacy Officer)
Chief Privacy Officer
| Item | Detail |
|---|---|
| Name | An Jungsu |
| Position | Representative Director |
| jsan@gongreen.co.kr | |
| Telephone | 0502-1931-9869 |
Privacy enquiry contact point
| Item | Detail |
|---|---|
| Team | Customer support |
| help@gongreen.co.kr | |
| Telephone | 0502-1931-9869 |
Data subjects may direct all privacy-related enquiries, complaints and requests for remedy arising from use of the Service to the contacts above. The Company will respond and act without delay.
Article 11 (Security Measures)
- Password encryption: member passwords are stored as a one-way hash (BCrypt), so the Company cannot read the original; a lost password can only be reset, not recovered.
- Encryption in transit: all communication between the Service and users is encrypted with HTTPS.
- Access control: the number of people who can access personal data is kept to a minimum, and access rights are changed or revoked on transfer or departure.
- Access logging: access to the personal data processing system is logged and managed.
- Authentication token management: login sessions are managed with tokens that expire and require re-authentication.
- Regular self-inspection: the Company periodically reviews how personal data is processed and whether safeguards are being applied.
Article 12 (Users Outside Korea)
-
KONGLE is aimed primarily at users outside the Republic of Korea. The Company processes personal data in accordance with the Personal Information Protection Act of the Republic of Korea.
-
Data subjects resident in the European Union or the United Kingdom may have rights under the law applicable there (such as the GDPR), including the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability and objection. Those rights may be exercised using the methods in Article 9.
-
To the extent the GDPR applies, the Company relies on the following legal bases:
Processing Legal basis Account registration and management, storing and syncing learning progress, use of the community and Q&A GDPR Art. 6(1)(b) — performance of a contract Access logs and device information, service security, aggregated usage statistics GDPR Art. 6(1)(f) — legitimate interests Checking date of birth to block sign-ups under the age of 14 GDPR Art. 6(1)(c) — compliance with a legal obligation -
Where there is a difference in interpretation between the Korean text of this Policy and any translation, the Korean text governs.
Article 13 (Cookies and Browser Storage)
- The Company stores the following in the user’s browser storage (localStorage) in order to provide the Service:
| Stored item | Purpose | How to delete |
|---|---|---|
| Login token | Keeping the user signed in | Log out, or clear browser storage |
| Account summary (nickname and similar) | Display | Log out, or clear browser storage |
| Progress and streak | Holding and displaying learning records while not signed in | Clear browser storage |
- Users may clear storage through their browser settings. Doing so signs the user out, and any learning record not linked to an account cannot be recovered.
- The Company does not use tracking cookies for advertising.
Article 14 (Remedies for Infringement of Rights)
Data subjects may apply to the following bodies for dispute resolution or advice regarding infringement of personal data rights.
| Body | Telephone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | +82-1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Centre (KISA) | +82-118 | privacy.kisa.or.kr |
| Cybercrime Investigation Division, Supreme Prosecutors’ Office | +82-1301 | www.spo.go.kr |
| National Police Agency Cyber Bureau | +82-182 | ecrm.police.go.kr |
Article 15 (Changes to This Policy)
- This Privacy Policy applies from its effective date.
- Where content is added, deleted or amended because of changes in law, policy or security technology, the Company will give notice through the Service at least 7 days before the change takes effect.
- Where there is a significant change to users’ rights, the Company will give at least 30 days’ notice and will obtain consent again where necessary.
Company Information
| Item | Detail |
|---|---|
| Company name | Gongreen Co., Ltd. (주식회사 공그린) |
| Representative | An Jungsu |
| Business address | 804, Hanshin IT Tower 2, 47 Digital 9-gil, Geumcheon-gu, Seoul, Republic of Korea |
| Business registration number | 180-86-03646 |
| Mail-order business registration | 제2026-서울금천-1110호 |
| Telephone | 0502-1931-9869 |
| Fax | 0504-849-9050 |
| help@gongreen.co.kr |
Announced: 17 August 2026 · Effective: 24 September 2026