← Painlink한국어

Last updated 2026-08-27

Privacy Policy

Painlink (the “Service”) is a community where people point at where it hurts and share what they went through. The Service does not diagnose or treat.
This policy covers both the website (painlink.kr) and the iOS app. They hold the same thing, but there are things the app does not do, and those differences are noted below where they apply.

The Korean version of this policy is the original. This English text is a translation for your convenience. If the two ever differ, the Korean version governs.

1. What we do not collect

The Service does not collect the following.

  • Legal name, date of birth, national ID number, phone number, address
  • Passwords — the Service has no accounts of its own
  • Location, contacts, photo library
  • Medical records or prescriptions from any healthcare provider
  • Payment information

Not collecting something is the surest way to protect it.

2. What we collect, and why

  • Account identifier from Google or Kakao — so that what you write is yours, and you can edit or delete it later.
  • Name and profile picture from your sign-in provider — used as the default nickname and avatar. You can change the nickname.
  • What you write: the spot, pain intensity (0–10), title, body, tags.
  • Nickname, and optionally height, weight and gender — each with its own public/private choice.
  • Meetups you open and the fact that you joined one.

The Service collects no advertising identifiers and uses no advertising company's analytics (such as Google Analytics).

On the website it does count how many people arrive and where they came from (Vercel Web Analytics, since 2026-08-08). The app does not turn this on — the app counts nothing at all. This counting uses no cookies and does not store IP addresses. Visits are distinguished by a temporary hash built from the request, discarded after 24 hours, so it is not possible to trace later who looked at what.

  • Counted: the page address, the referrer, country and city, device type and browser
  • Not counted: IP address, advertising identifiers, what you do on other sites, anything that links visits back to a person
  • Why not an advertising company's tool: our addresses look like /en/spot/knee/ — they carry what you are worried about. There is no reason to hand that list to a company that sells ads.

3. About what you write

  • What you write is public by default — that is the point of the Service. Please do not write anything that identifies you or someone else (workplace, hospital name, real names).
  • The Service does not diagnose or score you based on what you write.
  • What you write is never used for advertising or marketing.
  • What you write is never sold or handed to a third party.

4. What never leaves your device

Some parts of the Service never reach our servers. The following stay on your device, and we cannot see them.

  • Your pain map — where on your body it hurts and how much, gathered by date. It says far more about you than a single post, so we decided from the start not to upload it. If you change devices or delete the app it goes with them, and we cannot restore it. Export and import are there for when you want to move it yourself.
  • The reminder (app only) — your device raises it at the time you chose. Nothing goes through a server, so no push token is created, and the fact that you turned it on never leaves the device. The time you chose is stored on the device only. You can turn it off in Settings, or in your device settings.
  • Screen preferences — the language you chose, light or dark, and whether you have already seen the intro.

This is everything we store on your device: painlink.maps · painlink.remind · painlink.lang · painlink.theme · painlink.first.seen · painlink.install.dismissed. Clearing your browser or app storage removes all of it.

5. Separate consent for health information

Where it hurts, how much (NRS), and what it feels like are health information. So, separately from signing in, we ask again before you write anything.

  • Without agreeing you can still read every record and meetup.
  • Consent is needed only to write.
  • We also confirm you are 14 or older. Children under 14 cannot sign up.
  • We store the date of your consent and which version of the wording you agreed to, in a document only you can read.

6. Transfer outside Korea

What you write is stored in the Republic of Korea (Seoul region). However, the company operating that database is a US entity (Google LLC), and access from outside Korea can occur during incident response and system operation.

  • What is transferred: everything listed in sections 1–2 above
  • Who receives it: Google LLC (USA), Vercel Inc. (USA)
  • Why: sign-in, data storage, serving the website
  • How long: until you delete your account

You may refuse this transfer, but in that case you cannot sign in or write. Reading remains available.

7. Who processes your data for us

  • Google Firebase (Google LLC) — sign-in and database. Data is stored in the Republic of Korea (asia-northeast3, Seoul) region.
  • Vercel (Vercel Inc., USA) — website delivery and visit counting. Nothing you write is stored at Vercel. The app does not use it — the app carries every file it needs inside itself and runs without a network.
  • Kakao (Kakao Corp.) — only if you use Kakao sign-in: your account identifier and nickname.

8. How long we keep it

Your account and records are kept until you delete them. Deleting your account deletes what you wrote with it. Anything the law requires us to retain is kept separately, only for that period.

9. Your rights

You can read, correct and delete what you wrote at any time from the screen, and download all of it as a file (Settings → Download my records). The download is assembled in your browser and does not pass through our server.

To delete your account, or for anything else, write to the address below and we will take care of it.

10. Security

  • All traffic is encrypted (HTTPS).
  • Anything you mark private is never sent to the server — it is not hidden on screen while sitting in the database.
  • The Service stores no passwords, so no password can leak.
  • Who joined which meetup is readable only by that person and the host of that meetup.

11. Children under 14

The Service does not accept sign-ups from children under 14. If we learn an account belongs to a child under 14, we delete the account and its records.

12. Contact

Data protection officer: Jeon Seongho
Email: jshjsh0623@gmail.com

This policy has not been reviewed by a lawyer. Where the answer was arguable, we chose the option that is safer for you — we treat what you write as health information and ask for separate consent, we accept only people 14 and older, and we disclose the transfer outside Korea. If you find something wrong, please write to the address above.