Triver Privacy Policy

Triver ("Triver", "we", "us") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act ("PIPA") of the Republic of Korea, in order to protect the personal information of data subjects and to handle related complaints promptly and smoothly.

Triver is an AI chatbot app for international visitors to Korea that provides travel recommendations for the Busan area, itinerary planning, a travel expense tracker, and nearby medical and safety information.

This Privacy Policy is effective as of August 13, 2026.

This English version is provided for the convenience of our users. In the event of any discrepancy between the Korean and English versions, the Korean version shall prevail.


Article 1 (Purposes of Processing Personal Information)

Triver processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those listed below. Should the purpose of use change, we will take necessary measures such as obtaining separate consent in accordance with Article 18 of PIPA.

  1. Membership registration and management: To confirm intent to register via social login, identify and authenticate users, maintain and manage membership, prevent fraudulent use of the service, and handle complaints.
  2. Provision of the AI chatbot service: To generate travel information in response to user questions, provide personalized place and restaurant recommendations reflecting user travel preferences, and convert voice input into text.
  3. Provision of itinerary and expense tracker features: To create, store, and retrieve travel itineraries, manage places by day, and record travel expenses with currency conversion.
  4. Provision of location-based services: To recommend nearby attractions and restaurants, display distances, and provide information on nearby hospitals, pharmacies, and emergency rooms.
  5. Service improvement and statistical analysis: To compile app usage statistics, improve service quality, and diagnose errors (crashes).

Article 2 (Processing and Retention Period of Personal Information)

Triver processes and retains personal information within the retention and use period required by law, or within the retention and use period consented to by the data subject at the time of collection.

CategoryRetention Period
Account information, travel preferences, chat content, itineraries, expense records, saved placesUntil membership withdrawal — destroyed without delay upon withdrawal
Location coordinates recorded together with chatbot messagesUntil membership withdrawal — destroyed without delay upon withdrawal
Other location information (nearby recommendations, medical and weather lookups)Destroyed immediately after being used to generate a response (not stored separately)
Voice input dataDestroyed immediately after transcription (not stored on our servers)
AI processing records (OpenAI)Up to 30 days, in accordance with the processor's abuse-monitoring policy
Usage statistics and error logs (Firebase)Up to 14 months from the date of collection
Access IP addressAggregate counters used for rate limiting are refreshed and cleared on a 60-second cycle. Where a request is blocked as abnormal, the access IP address is recorded in server logs and retained for the log retention period of our hosting provider
Information required to be preserved under applicable lawThe period prescribed by such law

Article 3 (Categories of Personal Information Processed)

1. Membership Registration and Management

Triver offers social login only and does not collect a user-created password.

CategoryItems
Google account loginEmail address, name, profile picture URL
Apple account loginEmail address (may include Apple's Private Email Relay address), name
Generated within the serviceMember identifier (UUID), login provider, registration date and time

2. Service Provision (Optional Input and Information Generated Through Use)

CategoryItems
Travel preferences (optional)Travel style, Korean-culture interests, dietary restrictions, dislikes, display language
Chatbot conversationsContent entered by the user, AI responses, chat room titles, location coordinates (latitude/longitude) at the time each message was sent
Voice input (optional)Audio recorded via the microphone (solely for transcription)
ItinerariesTrip title, trip emoji, travel dates, number of companions (adults/children), destination area, places, times, durations, and memos per day
Expense trackerExpense name, category, amount (in KRW and the user's currency), currency code, applied exchange rate, date and time of expense, trip day number, place, memo
Saved placesIdentifiers of places saved by the user
User-registered placesPlace name, address, and coordinates entered directly by the user

Note on dietary restrictions: Dietary restriction information is an optional field and may allow inferences about religion or health condition. Triver uses this information solely to recommend restaurants and menu items and for no other purpose. Users may choose not to provide it and may modify or delete it at any time.

3. Location Information

Latitude and longitude of the mobile device. See Article 7 for details.

4. Automatically Collected Information

Device information (device model, OS type and version), app version, app usage records (screen views, feature-use events), error (crash) logs, app instance identifier, advertising identifier (such as the Android Advertising ID), app install referrer information, access IP address.

5. Information Triver Does NOT Collect

  • Passwords, resident registration numbers, passport numbers, or other unique identifying information
  • Mobile phone number, date of birth, gender, or the user's own residential address
  • Payment information (card numbers, account numbers) — Triver provides no in-app payment feature
  • Contacts, photos, camera, notifications, or any device access not listed in Article 14

Article 4 (Provision of Personal Information to Third Parties)

Triver does not provide personal information to third parties.

Exceptions apply where the data subject has given separate consent, or where there are special provisions in law such as Articles 17 and 18 of PIPA.


Article 5 (Outsourcing of Personal Information Processing)

Triver outsources personal information processing tasks as follows in order to provide the service smoothly.

ProcessorScope of Outsourced WorkRetention and Use Period
Supabase, Inc.User authentication, database storage and operationUntil membership withdrawal or termination of the outsourcing agreement
Google LLCGoogle account social login (OAuth 2.0)Until membership withdrawal or termination of the outsourcing agreement
Google LLCApp usage analytics and error diagnostics (Firebase Analytics, Firebase Crashlytics)Up to 14 months from collection, or until termination of the outsourcing agreement
Apple Inc.Apple account login (Sign in with Apple) and revocation of the app link upon withdrawalUntil membership withdrawal or termination of the outsourcing agreement
OpenAI, L.L.C.AI chatbot response generation, speech-to-text (STT), conversation summarization and translationUp to 30 days, or until termination of the outsourcing agreement
Render Services, Inc.Application server hostingUntil termination of the outsourcing agreement
Cloudflare, Inc.Network transport security and traffic handlingUntil termination of the outsourcing agreement
Kakao Corp.Map display, place and address searchUntil termination of the outsourcing agreement
Korea Tourism OrganizationLookup of nearby tourism information (TourAPI)Limited to the time of processing each lookup request
National Medical Center, KoreaLookup of nearby hospitals, pharmacies, and emergency rooms (E-Gen)Limited to the time of processing each lookup request
OpenWeather Ltd.Retrieval of weather information for the destinationLimited to the time of processing each lookup request

When entering into outsourcing agreements, Triver specifies in the contract, in accordance with Article 26 of PIPA, matters such as the prohibition of processing personal information beyond the purpose of the outsourced work, technical and administrative safeguards, restrictions on sub-outsourcing, supervision of the processor, and liability including damages. Triver supervises whether processors handle personal information safely.

Any change to the scope of outsourced work or to the processors will be disclosed without delay through this Privacy Policy.


Article 6 (Overseas Transfer of Personal Information)

Pursuant to Article 28-8(1)(3) of PIPA, Triver outsources and stores personal information processing with overseas providers as necessary to provide the service. In accordance with Article 28-8(2), we disclose the details below.

For all recipients, the time and method of transfer is common: encrypted transmission over the information and communications network (TLS) at the time the service is used.

RecipientItems TransferredCountryPurpose of UseRetention and Use PeriodContact
Supabase, Inc.Email address, name, profile picture URL, travel preferences, chat content together with the location coordinates recorded at the time each message was sent, itineraries, expense records, saved placesData is stored in the Republic of Korea (AWS Seoul region); the operator Supabase, Inc. (United States) may access it from overseas for service operation and technical supportUser authentication, data storage and operationUntil membership withdrawal or termination of the agreementprivacy@supabase.io
OpenAI, L.L.C.Chat content and voice data entered by the user, travel preferences / dietary restrictions / dislikes, location coordinates at the time of the request, recent conversation history and summaryUnited StatesAI response generation, speech-to-textUp to 30 daysprivacy@openai.com
Google LLC(For social login) Email address, name, profile picture URL / (For analytics) Member identifier (UUID), app instance identifier, device information, app usage records, error logsUnited StatesSocial login, usage analytics and error diagnosticsUp to 14 months from collection, or until termination of the agreementgooglekrsupport@google.com
Apple Inc.(For social login) Email address, nameUnited StatesSocial login; revocation of the app link upon withdrawalUntil membership withdrawal or termination of the agreementhttps://www.apple.com/privacy/contact/
Render Services, Inc.Request data sent to the server generally (chat content, location coordinates, authentication tokens, access IP address)Servers located in Singapore; operator located in the United StatesApplication server hostingUntil termination of the agreementsupport@render.com
Cloudflare, Inc.Access IP address, request headers, and other network transport informationUnited StatesNetwork security and traffic handlingUntil termination of the agreementprivacyquestions@cloudflare.com
OpenWeather Ltd.Location coordinates (latitude/longitude)United KingdomRetrieval of weather informationUntil termination of the agreementinfo@openweathermap.org

Data subjects may refuse the overseas transfer of their personal information by contacting the Chief Privacy Officer (Article 17). Please note that refusing the transfer may make membership registration and use of the service impossible or limited.


Article 7 (Processing of Location Information)

Triver complies with the Act on the Protection and Use of Location Information and processes location information as follows.

  1. Method and timing of collection: Where the user has granted location access permission, Triver collects the device's location (latitude/longitude) in real time only while the app is in use. Triver does not request "Always Allow" location permission and does not collect location while the app is in the background.

  2. Purpose of use: To recommend nearby attractions and restaurants, display distance from the user's current position, and retrieve nearby hospitals, pharmacies, and emergency rooms.

  3. How location is retained

    • When a user sends a message to the chatbot, the location coordinates at that moment are stored in the conversation record together with the message, so that the accuracy of the answer can be verified. These coordinates are permanently deleted along with the conversation record upon membership withdrawal.
    • Location information collected for other purposes (nearby recommendations, distance display, medical and weather lookups) is not stored separately; it is used only transiently to generate a response to the relevant request and is then immediately discarded.
    • Within the app, location is held only in device memory and is cleared when the app is closed.
  4. Where location information is sent: To generate responses, location coordinates are transmitted to the following. The user's email address, name, and member identifier are not transmitted together with the coordinates.

    RecipientPurpose
    OpenAI, L.L.C.AI response generation
    National Emergency Medical Center (E-Gen), KoreaLookup of nearby hospitals, pharmacies, and emergency rooms
    Korea Tourism Organization (TourAPI)Lookup of nearby tourism information
    Kakao Corp.Address and place search, map display
    OpenWeather Ltd.Weather information
    Naver Map / Apple Maps / Google MapsDestination coordinates, where the user launches directions
  5. Withdrawal of consent and effect of non-consent: Users may withdraw location access permission at any time in their device settings. The service remains usable without location permission; in that case information is provided based on a reference point in the Busan area.

  6. Children's location information: Triver does not collect personal location information of children under 14 years of age.


Article 8 (Processing of Personal Information in Connection with Generative AI)

Triver's chatbot feature uses the generative AI and speech recognition APIs of OpenAI, L.L.C.

  1. Information transmitted: The following is sent to OpenAI to generate a response.
    • The question entered by the user
    • Recent conversation history (up to 10 turns) and a summary of earlier conversation
    • The user's travel style, Korean-culture interests, dietary restrictions, dislikes, and display language
    • Location coordinates (latitude/longitude) at the time of the request
    • The identifier of the itinerary linked to the conversation
    • Weather information for the destination (not personal information)
  2. Information NOT transmitted: The user's email address, name, profile picture, and member identifier (UUID) are not transmitted to OpenAI.
  3. Voice data: Where the user asks a question by voice, the audio is transmitted to OpenAI for transcription. Triver does not write voice data to any server or storage and discards it immediately after processing.
  4. Use for model training: OpenAI does not use data submitted via its API to train its AI models, and retains it for up to 30 days for abuse-monitoring purposes before deletion.
  5. User advisory: Chat content is stored on our servers in order to provide the service. Please do not enter sensitive or critical information such as resident registration numbers, passport numbers, card numbers, or passwords into the chat.
  6. Limitations of AI responses: Information generated by AI (medical facility guidance, travel information, etc.) is for reference only and its accuracy is not guaranteed. In an emergency, please use official emergency contacts such as 119.

Article 9 (Procedure and Method of Destroying Personal Information)

Triver destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved and the information is no longer necessary.

  1. Upon membership withdrawal: The account and all linked profile information, travel preferences, chat content, itineraries, expense records, and saved places are permanently deleted (hard delete) from the database without delay. Deleted data cannot be recovered.
  2. Apple account users: Upon withdrawal, the app's token link with Apple is also revoked.
  3. Deleted itineraries: Itineraries deleted by the user are retained in a hidden state until membership withdrawal, in case restoration is requested, and are permanently deleted upon withdrawal.
  4. Information remaining after withdrawal: Place information entered directly by the user (place name, address, coordinates) may remain in service data in a form not linked to any member identifier. This information alone cannot identify a specific individual.
  5. Deleting the app is not withdrawal: Deleting the app from your device does not by itself delete personal information stored on our servers. To delete server-side data, please complete the in-app account withdrawal process.
  6. Procedure and method
    • Procedure: Personal information subject to destruction is identified and destroyed with the approval of the Chief Privacy Officer.
    • Method: Information in electronic file format is deleted using technical methods that render the records irreproducible.

Article 10 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

  1. Data subjects may at any time exercise rights including access, correction, deletion, and suspension of processing of their personal information.
  2. Viewing and editing account information and travel preferences, and withdrawing membership (deleting the account and data), can be done directly in the "My" tab in the app; deletion of conversations, itineraries, and expense records can be done in the "Chat" and "Trips" tabs respectively. Other rights may be exercised in writing or by email (see the contact in Article 17). Triver will act on such requests without delay.
  3. Rights may be exercised through a legal representative or an authorized agent. In such case, a power of attorney in the form prescribed by the Public Notice on Methods of Processing Personal Information must be submitted.
  4. Requests for access and suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA.
  5. Deletion may not be requested where the personal information is expressly specified as subject to collection under other statutes.
  6. Triver verifies whether the person exercising the right is the data subject or a duly authorized representative.

Article 11 (Personal Information of Children Under 14)

Triver does not provide its service to children under 14 years of age and does not collect the personal information of children under 14.

If it is confirmed that the personal information of a child under 14 has been collected without the consent of a legal representative, Triver will destroy such information without delay.


Article 12 (Measures to Ensure the Safety of Personal Information)

  1. Minimizing personnel handling personal information: The number of personnel who handle personal information is kept to a minimum.
  2. Access control: Row Level Security is applied to the database so that users can access only their own data, and the granting, modification, and revocation of database access rights are managed.
  3. Authentication and authorization: Authentication tokens (JWT) issued to users are verified by the server using public-key based verification, blocking data access by anyone other than the account owner.
  4. Encryption: Personal information is transmitted over the network in encrypted form (TLS), and encryption at rest provided by our processors is applied to stored data. Authentication tokens are kept in device storage.
  5. Minimization of logging: Security-related logs such as authentication failures are managed so that personal information including email addresses and member identifiers is not recorded. Error (crash) logs contain only technical information about the point of failure and are managed so as not to include user-entered content such as chat messages.
  6. Blocking abnormal requests: Rate limiting is applied to block service abuse and automated attacks. In this process, the access IP address of a blocked request is recorded in server logs, and such records are used solely for security purposes.

Article 13 (Installation, Operation, and Refusal of Automatic Collection Devices)

  1. Triver does not use web browser cookies. However, the Kakao Map SDK is loaded in an in-app web view to display maps, and network connection information from the device may be transmitted to Kakao Corp. in the process.
  2. Triver automatically collects device information, app version, app usage records, error logs, the app instance identifier, the advertising identifier, and app install referrer information through Google Firebase (Analytics, Crashlytics) for the purposes of usage analytics and error diagnostics.
  3. For logged-in users, the member identifier (UUID) is also sent as the user identifier of the analytics tools for error diagnosis and usage analysis. Email addresses and names are not transmitted.
  4. Triver does not transmit free-text content entered by users — such as chat content, place names, or trip titles — to analytics tools, and collects only minimal information such as the fact that a feature was used and character or item counts.
  5. Users may restrict this through device settings. Refusal does not restrict use of the service.
    • iOS: Settings > Privacy & Security > Tracking / Apple Advertising
    • Android: Settings > Google > Ads > Reset or delete advertising ID

Article 14 (App Permissions and How to Withdraw Them)

Triver requests only the minimum device permissions necessary to provide the service. All permissions are optional, and the service can be used without granting them.

PermissionTypePurpose
Location (while using the app)OptionalNearby place recommendations, distance display, guidance to nearby hospitals, pharmacies, and emergency rooms
MicrophoneOptionalAsking the chatbot questions by voice (speech-to-text)
  1. Triver does not request "Always Allow" location, camera, photos, contacts, notifications, or storage permissions.
  2. How to withdraw
    • iOS: Settings > Triver > Location / Microphone
    • Android: Settings > Apps > Triver > Permissions
  3. If a permission is not granted or is withdrawn, only the related feature (accuracy of nearby recommendations, voice input) is limited; all other services remain fully available.

Article 15 (Collection, Use, Provision, and Refusal of Behavioral Information)

  1. Triver does not collect, use, or provide behavioral information for the purpose of online targeted advertising, and does not display advertisements in the app.
  2. However, in the course of using our analytics tool (Firebase Analytics), the device's advertising identifier may be transmitted to Google. Users may reset the advertising identifier or restrict its collection using the methods described in Article 13(5).

Article 16 (Criteria for Additional Use and Provision)

Pursuant to Articles 15(3) and 17(4) of PIPA, Triver may additionally use or provide personal information without the consent of the data subject, taking into account the matters set forth in Article 14-2 of the Enforcement Decree of PIPA. In doing so, Triver considers:

  1. Whether the purpose of the additional use or provision is related to the original purpose of collection
  2. Whether the additional use or provision is foreseeable in light of the circumstances of collection or processing practices
  3. Whether the additional use or provision unfairly infringes upon the interests of the data subject
  4. Whether measures necessary to ensure safety, such as pseudonymization or encryption, have been taken

Article 17 (Chief Privacy Officer)

Triver has designated a Chief Privacy Officer as follows, who takes overall responsibility for personal information processing and handles complaints and remedies for data subjects.

CategoryDetails
NameGaram Kim
PositionChief Privacy Officer
Contactlucymoon.d@gmail.com

Data subjects may direct any inquiries, complaints, or requests for remedy relating to personal information protection arising from use of the Triver service to the Chief Privacy Officer. Triver will respond and take action without delay.


Article 18 (Department Receiving and Handling Access Requests)

Data subjects may submit requests for access to personal information under Article 35 of PIPA to the following. Triver will endeavor to process such requests promptly.

CategoryDetails
Person in chargeGaram Kim
Contactlucymoon.d@gmail.com

Article 19 (Remedies for Infringement of Data Subject Rights)

Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and similar bodies in order to obtain relief from personal information infringement.

OrganizationPhoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Information Infringement Report Center118privacy.kisa.or.kr
Supreme Prosecutors' Office1301www.spo.go.kr
Korean National Police Agency182ecrm.cyber.go.kr

A person whose rights or interests are infringed by a disposition or omission by the head of a public institution in response to a request under Articles 35 (Access), 36 (Correction and Deletion), or 37 (Suspension of Processing) of PIPA may file an administrative appeal as provided by the Administrative Appeals Act. For details, please refer to the website of the Central Administrative Appeals Commission.


Article 20 (Changes to this Privacy Policy)

  1. This Privacy Policy is effective as of August 13, 2026.
  2. Where content is added, deleted, or modified, we will give notice through an in-app announcement at least 7 days before the change takes effect. Where the change materially affects the rights of data subjects, such as a change in the items collected, notice will be given at least 30 days in advance.
  3. Previous versions of this Privacy Policy can be found below.
VersionEffective DateKey Changes
v1.02026-08-13Initial version