flyve
FAQNoticesNewsroomContact
Get the app

Privacy Policy

Effective date: August 6, 2026

molio (the “Company”) complies with the Personal Information Protection Act (PIPA) and other applicable laws, and protects users' personal information with care. This Privacy Policy explains how users' personal information is collected, used, and protected in flyve, a travel-map social service (the “Service”).

1. Personal Information We Collect

The Company collects the following personal information to provide the Service: account information (email address, password) and profile information provided through social login (nickname, profile image, and the like).

Date of birth, collected to confirm that the user is at least 14 years old and to apply protections for minors.

Photos and videos uploaded by users and the EXIF metadata of those files (GPS coordinates, capture date and time, camera and device information, and the like). Videos include their audio track unless the user chose to upload them muted.

Profile information (such as display name, handle, bio, and profile links) and content such as comments written by users.

The content of direct messages between users together with their send and receive records, and participation or invitation records for collaborative shared albums.

Device push tokens and notification category settings, used to deliver push notifications.

Information generated and collected automatically during use of the Service: service usage records, access logs, device identifiers, device and operating-system information, and IP address.

Content impression records used to personalize the feed (which posts appeared on screen) and the interest signals derived from them (regions and categories of interest). Interest signals are estimates at the region and category level; the exact coordinates of a photo are not stored as such.

2. How We Collect Personal Information

The Company collects information that users enter directly during sign-up and use of the Service, that they provide by uploading photos, or that is provided through social login.

Information generated automatically through devices or browsers may also be collected during use of the Service.

3. Purposes of Use

To identify and verify members, manage accounts, and provide the core functions of the Service.

To analyze photo metadata (capture location and time) in order to automatically organize posts, build the user's travel map, grant travel badges, and provide travel recommendations.

To deliver direct messages and enable collaborative editing of shared albums - communication features the user has requested.

To adjust the order of posts shown in the feed (personalization), using impression records and interest signals. Users can delete their interest signals by withdrawing membership. Personalization affects only the ordering of posts and makes no automated decision adverse to the user.

To improve service quality, develop new features, prevent misuse, and operate the Service safely.

To measure advertising performance and optimize advertising campaigns. Users may refuse the cross-border transfer carried out for this purpose at any time (Article 5-2).

4. Handling of Location Data

The Company uses the GPS coordinates contained in photos' EXIF metadata to identify capture locations and build the travel map.

When a user publishes a photo, its location information (GPS coordinates) may be displayed to other users on the travel map and feed at its exact coordinates.

Users should be aware that publishing a photo may reveal its precise capture location to other users, and should exercise caution when uploading or publishing photos that include sensitive locations such as their home. Users may delete their posts at any time.

5. Provision to Third Parties and Outsourcing of Processing

The Company does not provide users' personal information to third parties beyond the purposes stated in this Policy, except where there is a legal basis or the user's consent.

To provide the Service smoothly, the Company outsources the following: service infrastructure hosting (Google Cloud); image and file storage and delivery (Cloudflare); transactional email for verification codes (Resend); push notification delivery (Expo Application Services); content translation (Google Translate); error and crash analytics (Sentry); and product-usage analytics (Amplitude).

The Service uses the place-data services of Kakao, Google, and OpenStreetMap for place lookups, and the authentication services of Apple, Google, Kakao, and LINE for social login.

For advertising measurement, the Company transmits the fact that certain events occurred (sign-up, content upload, sharing) to Meta Platforms, Inc. The only user-identifying value included is a SHA-256 hash of the member identifier; no email address, phone number, IP address, or user agent is transmitted. Users may refuse this transfer at any time (Article 5-2).

5-2. Cross-Border Transfer of Personal Information

The Company transfers personal information outside the Republic of Korea as set out below. Each transfer takes place over the network at the moment the relevant processing occurs.

(1) Google Cloud Platform (Google LLC; United States and Republic of Korea regions) - service infrastructure hosting and database operation. Items: all information listed in Article 1. Retention: per Article 6.

(2) Cloudflare, Inc. (United States) - storage and delivery of image and video files. Items: photos and videos uploaded by users and their metadata. Retention: until the post is deleted or the member withdraws.

(3) Resend (United States) - delivery of email verification codes. Items: email address. Retention: until the delivery purpose is fulfilled.

(4) Expo Application Services (United States) - push notification delivery. Items: device push token, notification content. Retention: until the token is revoked or the member withdraws.

(5) Google LLC (United States) - comment translation and place lookups. Items: comment text to be translated, coordinates. Retention: until the processing purpose is fulfilled.

(6) Functional Software, Inc. (Sentry; United States) - error and crash analytics. Items: device and operating-system information, usage records at the time of an error, member identifier. Retention: 90 days.

(7) Amplitude, Inc. (United States) - product-usage analytics. Items: member identifier, usage records such as screen views and button taps, device and operating-system information. Retention: until the processing agreement ends or the member withdraws.

(8) Meta Platforms, Inc. (United States) - advertising measurement and optimization. Items: SHA-256 hash of the member identifier, event name and timestamp. Retention: per Meta policy.

Users may refuse cross-border transfers. To refuse transfer (8), which is carried out for advertising purposes, email lhs3446@flyve.kr with your sign-up address and your refusal; once we have verified your identity we stop the transfer for that account. Refusing places no restriction of any kind on your use of the Service. Transfers (1) through (7) are essential to providing the Service and cannot be refused individually; a user who wishes to refuse them can stop the processing by withdrawing membership.

6. Retention and Use Period

In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved. Account information and the photos and metadata (EXIF) uploaded by the user are retained until the user withdraws membership, and are destroyed without delay upon withdrawal.

However, the Company retains personal information for the periods stated below in the following cases: (1) service usage records and access logs (including IP addresses) - 3 months, in accordance with the Protection of Communications Secrets Act; (2) identifying information of withdrawn members (such as email address), retained to prevent fraudulent sign-ups and misuse - 30 days after withdrawal; (3) content impression records used to personalize the feed - 90 days, after which they are deleted automatically.

Interest signals and content impression records are deleted together with the account when a member withdraws. Per-post impression and engagement counts are aggregated into a form that cannot identify a user before being retained, and withdrawal statistics (account age in days, number of posts, and similar) are retained only as aggregates that contain no email address, handle, or member identifier whatsoever.

Where applicable laws require information to be retained for a certain period, the Company retains the personal information for the period prescribed by such laws and does not use it for any other purpose.

7. Rights of Users and Legal Representatives

Users may at any time access, correct, or delete their personal information, request that processing be suspended, and withdraw their consent to the collection and use of personal information.

Users may request deletion of their personal information by withdrawing membership through the in-service settings, and may also exercise these rights by contacting lhs3446@flyve.kr.

8. Destruction of Personal Information

The Company destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved.

Information in electronic file form is deleted using a technical method that prevents recovery, and information recorded on paper documents is shredded or incinerated.

9. Security Measures

The Company implements technical and administrative protective measures for the safe handling of personal information, including minimizing and managing access rights, encrypting data in transit and at rest, and operating access-control systems.

The Company minimizes the number of personnel who handle personal information and maintains the adequacy of its protective measures through regular reviews.

10. Children's Personal Information

The Service is not directed to children under the age of 14, and the Company does not knowingly collect personal information from children under 14.

If the Company becomes aware that personal information of a child under 14 has been collected, it destroys that information without delay.

11. Data Protection Officer and Contact

The Company designates a data protection officer responsible for overseeing the processing of personal information. Data Protection Officer: Lee Heesoo (이희수). Contact: lhs3446@flyve.kr · 0507-1490-3470.

Inquiries, complaints, and requests for remedy relating to the processing of personal information may be directed to lhs3446@flyve.kr.

12. Changes to this Privacy Policy

This Privacy Policy may be revised in line with changes in law or in the Service. Any changes and their effective date will be announced within the Service in advance.

flyve

flyve — the travel photo journal that builds itself from your camera roll

FAQNoticesNewsroomContact
TermsPrivacyDelete account
Business name몰리오 (molio)Representative이희수 (Lee Heesoo)Business registration number286-08-03801Address3F, 9-8 Seolleung-ro 129-gil, Gangnam-gu, Seoul, Republic of KoreaContact0507-1490-3470 · lhs3446@flyve.kr
© 2026 flyve