시행일: 2026년 8월 20일
주식회사 어나더닥터(이하 "회사")는 「개인정보 보호법」 등 관련 법령을 준수하며, 정보주체의 개인정보를 보호하기 위해 다음과 같이 개인정보처리방침을 수립·공개합니다. 본 방침은 회사가 제공하는 모바일 앱(이하 "서비스")에 적용됩니다.
제1조 (개인정보의 처리 목적)
회사는 다음의 목적으로 개인정보를 처리하며, 목적 외의 용도로는 이용하지 않습니다.
- 회원 가입 및 관리 — 이메일 계정을 통한 회원 식별·인증, 서비스 제공·유지
- 미백 측정 서비스 제공 — 치아 사진 촬영·분석을 통한 미백 지수 산출 및 경과 기록(개인 기록용)
- 서비스 운영·개선 — 오류 진단 및 서비스 안정성 확보
- 서비스 개선 및 연구 — 측정 알고리즘 정교화를 위한 치아 사진·미백 측정값의 가명처리 후 활용 (제3조)
제2조 (수집하는 개인정보의 항목 및 방법)
| 구분 | 항목 | 수집 방법 |
| 필수 | 이메일 주소, 비밀번호(해시 처리되어 저장) | 가입 시 입력 |
| 필수(민감정보) | 치아 사진, 미백 측정값(색상 지수 등) | 서비스 이용 시 카메라 촬영·산출 |
| 자동 수집 | 기기 정보(모델·OS), IP 정보, 오류/진단 로그 | 서비스 이용 중 자동 생성 |
제3조 (민감정보의 처리에 관한 별도 동의)
회사는 미백 측정 서비스 제공을 위해 치아 사진 및 이로부터 산출되는 미백 측정값을 처리합니다. 이는 「개인정보 보호법」 제23조에 따른 건강에 관한 민감정보에 해당할 수 있어, 회사는 해당 민감정보를 일반 개인정보 수집·이용 동의와 분리하여 별도로 동의를 받으며, 동의를 거부할 수 있습니다. 다만 이 경우 미백 측정 등 핵심 기능의 이용이 제한될 수 있습니다.
회사는 위 목적과 별개로, 수집된 치아 사진 및 미백 측정값을 「개인정보 보호법」 제28조의2에 따라 가명처리하여 서비스 개선 및 측정 알고리즘 정교화를 위한 과학적 연구 목적으로 활용할 수 있습니다. 가명처리된 정보는 추가 정보와 분리하여 보관하고, 특정 개인을 알아보기 위한 목적으로 이용하지 않으며, 관련 법령에 따른 안전성 확보 조치와 처리 기록의 작성·보관 의무를 준수합니다.
제4조 (개인정보의 보유 및 이용 기간)
회사는 아래 기간 동안 개인정보를 보유·이용하며, 기간 경과 또는 처리목적 달성 시 지체 없이 파기합니다.
- 계정 정보(이메일 주소, 비밀번호): 회원 탈퇴 시까지
- 측정 데이터(치아 사진, 측정값): 회원 탈퇴 시까지
- 기기 정보, IP 정보: 회원 탈퇴 시까지
- 오류/진단 로그: 수집일로부터 약 90일
- 동의 기록: 회원 탈퇴 후 5년
- 마케팅 정보 수신 동의 기록: 동의 철회 또는 탈퇴 후 3년
- 연구 목적으로 가명처리하여 활용하는 치아 사진·측정값: 회원 탈퇴 시에도 개인 식별이 불가능한 형태(익명 또는 가명처리 상태)로 보존 (서비스 개선 연구 목적으로만 사용)
관계 법령에 따라 보존 의무가 있는 경우 해당 기간 동안 분리 보관 후 파기합니다.
제5조 (개인정보 처리의 위탁)
회사는 원활한 서비스 제공을 위해 아래와 같이 개인정보 처리를 위탁하며, 위탁계약 시 개인정보가 안전하게 관리되도록 필요한 사항을 규정하고 수탁자를 감독합니다.
| 수탁자 | 위탁 업무 |
| Supabase Inc. | 회원 인증, 데이터베이스, 저장소 운영 |
| Amazon Web Services, Inc. (S3, EC2) | 데이터(사진 등) 저장 인프라 |
제6조 (개인정보의 제3자 제공)
회사는 정보주체의 개인정보를 원칙적으로 제3자에게 제공하지 않습니다. 다만, 법령에 따라 요구되는 경우에는 예외로 합니다.
제7조 (개인정보의 국외 이전)
회사는 개인정보(치아 사진, 미백 측정값, 계정 정보 등)를 국내(대한민국) 리전에 보관하며(AWS 서울 ap-northeast-2 리전 — Supabase·S3·EC2 모두 국내 보관), 개인정보를 국외로 이전하지 않습니다.
제8조 (개인정보의 파기 절차 및 방법)
보유기간 경과 또는 처리목적 달성 시 지체 없이 파기합니다. 전자적 파일은 복구할 수 없는 방법으로 삭제하며, 출력물은 분쇄 또는 소각합니다.
제9조 (정보주체와 법정대리인의 권리·의무 및 행사 방법)
정보주체는 언제든지 개인정보의 열람·정정·삭제·처리정지 및 동의 철회를 요구할 수 있습니다.
- 회원 탈퇴 및 계정·데이터 삭제는 앱 내 설정 > 계정에서 직접 요청할 수 있습니다.
- 그 밖의 권리 행사는 제13조의 문의처로 요청할 수 있으며, 회사는 지체 없이 조치합니다.
제10조 (만 14세 미만 아동의 개인정보)
서비스는 만 14세 이상을 대상으로 합니다. 회사는 가입 시 만 14세 이상임에 대한 본인의 확인을 받으며, 만 14세 미만 아동의 개인정보를 알면서 수집하지 않습니다. 가입 후 이용자가 만 14세 미만으로 확인되는 경우 회사는 즉시 해당 계정을 삭제하고 수집된 개인정보를 지체 없이 파기합니다.
제11조 (개인정보의 안전성 확보 조치)
회사는 다음의 관리적·기술적 보호조치를 시행합니다.
- 전송 구간 암호화(TLS/HTTPS) 및 저장 데이터 암호화
- 접근 권한 통제(행 수준 보안 등) 및 접근 기록 관리
- 민감정보에 대한 강화된 보호조치
- 연구 목적 가명정보의 추가 정보 분리 보관 및 처리 기록 관리
제12조 (개인정보 자동 수집 장치 및 온라인 맞춤형 광고)
서비스는 광고 식별자를 이용한 교차 앱 추적을 수행하지 않으며, 별도의 분석 SDK를 사용하지 않습니다.
제13조 (개인정보 보호책임자 및 문의처)
회사는 개인정보 처리에 관한 업무를 총괄하고 관련 문의·불만·피해구제를 처리하는 담당 부서를 두고 있습니다.
- 담당부서: 고객지원팀
- 이메일: contact@adoc.im
- 주소: 강원특별자치도 춘천시 공지로 305, 4층 401-05호
정보주체는 개인정보 보호 관련 문의·불만·피해구제를 위 문의처로 요청할 수 있으며, 회사는 지체 없이 처리합니다.
제14조 (권익침해 구제 방법)
정보주체는 아래 기관에 분쟁 해결이나 상담을 신청할 수 있습니다.
- 개인정보분쟁조정위원회 (1833-6972, www.kopico.go.kr)
- 개인정보침해신고센터 (118, privacy.kisa.or.kr)
- 대검찰청 사이버수사과 (1301) / 경찰청 사이버수사국 (182)
제15조 (개인정보처리방침의 변경)
본 개인정보처리방침은 시행일로부터 적용되며, 내용 추가·삭제·수정이 있는 경우 시행일 7일 전부터 앱 내 공지를 통해 고지합니다. 다만, 정보주체의 권리에 중요한 변경이 있는 경우 시행일 30일 전부터 공지하며, 가입 시 등록된 이메일로 개별 통지합니다.
- 공고일: 2026-08-20
- 시행일: 2026-08-20
Effective date: August 20, 2026
This English translation is provided for convenience only. In the event of any discrepancy between the Korean original and this translation, the Korean version shall prevail.
AnotherDoctor Co., Ltd. (the "Company") complies with the Personal Information Protection Act of Korea ("PIPA") and other applicable laws, and establishes and discloses this Privacy Policy to protect the personal information of data subjects. This Policy applies to the mobile application provided by the Company (the "Service").
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes and does not use it for any other purpose.
- Membership registration and management — identifying and authenticating members via email account; providing and maintaining the Service
- Whitening measurement service — calculating a whitening index from photographs of your teeth and recording progress over time (for personal record-keeping)
- Service operation and improvement — error diagnosis and ensuring service stability
- Service improvement and research — use of pseudonymized teeth photographs and whitening measurement values to refine the measurement algorithm (Article 3)
Article 2 (Items of Personal Information Collected and Collection Methods)
| Category | Items | Collection method |
| Required | Email address, password (stored in hashed form) | Entered at sign-up |
| Required (sensitive) | Teeth photographs, whitening measurement values (color indices, etc.) | Captured and computed via the camera while using the Service |
| Automatically collected | Device information (model, OS), IP information, error/diagnostic logs | Generated automatically during use of the Service |
Article 3 (Separate Consent for Processing of Sensitive Information)
To provide the whitening measurement service, the Company processes teeth photographs and the whitening measurement values derived from them. As this may constitute sensitive information concerning health under Article 23 of PIPA, the Company obtains consent for such sensitive information separately from the general consent to the collection and use of personal information. You may refuse this consent; however, in that case, the use of core features such as whitening measurement may be restricted.
Separately from the above purpose, the Company may pseudonymize the collected teeth photographs and whitening measurement values in accordance with Article 28-2 of PIPA and use them for scientific research purposes aimed at improving the Service and refining the measurement algorithm. Pseudonymized information is stored separately from any additional information, is not used for the purpose of identifying a specific individual, and is subject to the safeguards and record-keeping obligations required by applicable laws.
Article 4 (Retention and Use Period of Personal Information)
The Company retains and uses personal information for the periods below, and destroys it without delay once the period expires or the processing purpose is achieved.
- Account information (email address, password): until membership withdrawal
- Measurement data (teeth photographs, measurement values): until membership withdrawal
- Device information, IP information: until membership withdrawal
- Error/diagnostic logs: approximately 90 days from collection
- Consent records: 5 years after membership withdrawal
- Marketing consent records: 3 years after consent withdrawal or membership withdrawal
- Teeth photographs and measurement values used for research purposes in pseudonymized form: retained after membership withdrawal only in a form in which individuals cannot be identified (anonymized or pseudonymized; used only for service-improvement research)
Where retention is required by applicable laws, the information is stored separately for the required period and then destroyed.
Article 5 (Outsourcing of Personal Information Processing)
The Company outsources personal information processing as follows to provide the Service smoothly, and supervises each processor through contracts stipulating the safe management of personal information.
| Processor | Outsourced work |
| Supabase Inc. | Member authentication, database, and storage operation |
| Amazon Web Services, Inc. (S3, EC2) | Data (photographs, etc.) storage infrastructure |
Article 6 (Provision of Personal Information to Third Parties)
The Company does not, in principle, provide personal information to third parties, except where required by applicable laws.
Article 7 (Cross-Border Transfer of Personal Information)
The Company stores personal information (teeth photographs, whitening measurement values, account information, etc.) in a region located in the Republic of Korea (AWS Seoul ap-northeast-2 region — Supabase, S3, and EC2 are all hosted in Korea) and does not transfer personal information abroad.
Article 8 (Procedures and Methods for Destruction of Personal Information)
Personal information is destroyed without delay once the retention period expires or the processing purpose is achieved. Electronic files are deleted using methods that make recovery impossible, and printed materials are shredded or incinerated.
Article 9 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)
You may at any time request access to, correction of, deletion of, or suspension of processing of your personal information, and may withdraw your consent.
- Membership withdrawal and deletion of your account and data can be requested directly in the app under Settings > Account.
- Other rights may be exercised by contacting the privacy contact listed in Article 13; the Company will act without delay.
Article 10 (Personal Information of Children Under 14)
The Service is intended for persons aged 14 or older. At sign-up, users confirm that they are aged 14 or older, and the Company does not knowingly collect personal information from children under 14. If, after sign-up, a user is confirmed to be under 14, the Company will immediately delete the account and destroy the collected personal information without delay.
Article 11 (Measures to Ensure the Safety of Personal Information)
The Company implements the following managerial and technical safeguards.
- Encryption in transit (TLS/HTTPS) and encryption of data at rest
- Access control (including row-level security) and access log management
- Enhanced safeguards for sensitive information
- Separate storage of additional information and processing records for research-purpose pseudonymized data
Article 12 (Automatic Collection Devices and Online Targeted Advertising)
The Service does not perform cross-app tracking using advertising identifiers and does not use any third-party analytics SDK.
Article 13 (Privacy Contact)
The Company has designated the following department to oversee personal information processing and to handle related inquiries, complaints, and requests for remedy.
- Department in charge: Customer Support Team
- Email: contact@adoc.im
- Address: 4F 401-05, 305 Gongji-ro, Chuncheon-si, Gangwon State, Republic of Korea
You may direct privacy-related inquiries, complaints, and requests for remedy to the contact above; the Company will handle them without delay.
Article 14 (Remedies for Infringement of Rights)
You may apply for dispute resolution or consultation with the following organizations (Korea).
- Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr)
- Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation Division (1301) / National Police Agency Cyber Investigation Bureau (182)
Article 15 (Changes to This Privacy Policy)
This Privacy Policy applies from the effective date. If any content is added, deleted, or amended, the Company will give notice within the app from at least 7 days before the effective date. However, for changes material to the rights of data subjects, notice is given from at least 30 days before the effective date, with individual notification to the email address registered at sign-up.
- Announcement date: 2026-08-20
- Effective date: 2026-08-20