XixiTyping 운영자(이하 “운영자”)는 웹사이트와 Android 앱에서 처리하는 개인정보와 이용자의 권리를 다음과 같이 알린다.
이메일 이용에 관한 중요 안내 서비스는 이메일을 계정 중복 확인, ID 찾기 및 비밀번호 재설정 시 계정 일치 여부를 확인하는 데만 쓴다. 인증메일, 비밀번호 재설정 메일, 광고 또는 소식지를 자동으로 보내지 않는다. Android의 도전 알림은 이메일이 아니라 Firebase Cloud Messaging(FCM) 푸시로 전송한다.
가입, 로그인, 중복 방지, ID 찾기, 안전한 비밀번호 재설정, 복구용 코드와 현재·과거 비밀번호의 중복 방지, 동의 입증
계정 삭제 때까지. 세션은 로그아웃·비밀번호 재설정·계정 삭제 시 또는 발급 후 최대 30일
연습·랭킹·도전
사용자 ID·닉네임, 텍스트/언어, 입력 방식, CPM·KPM·정확도·완료율·입력 글자 수·소요시간·작성시각, 도전 이력
연습기록 동기화, 랭킹, 도전
사용자가 기록을 지우거나 계정을 삭제할 때까지. 다른 이용자의 도전 이력에 포함된 탈퇴자의 ID·닉네임은 계정 삭제 시 익명화
실시간 대전
방 코드, 사용자 ID·닉네임, 준비·접속 상태, 실시간 입력 진도, 성적, 승패와 결과
대전 매칭·진행·결과 표시
대전 방이 삭제되거나 계정 삭제·서비스 정리 시까지
사용자 텍스트 신청
사용자 ID·닉네임, 제목·본문·언어, 검토 상태·시각·의견
연습 텍스트 신청과 검토
신청 삭제·계정 삭제 때까지. 승인되어 공용 텍스트로 분리된 본문은 게시 종료 때까지
Android 푸시
사용자 ID, FCM 토큰, 플랫폼·기기명·UI 언어, 등록·갱신시각
도전 관련 푸시 알림
토큰 해제·무효화 또는 계정 삭제 때까지
방문·보안
IP 주소에서 만든 가명 해시, 날짜; 호스팅 환경이 자동 생성할 수 있는 IP 주소, User-Agent, 요청·오류 시각
중복을 줄인 방문자 통계, 보안, 남용 방지, 장애 대응
방문자 통계 해시는 서비스 운영 기간. 호스팅 로그는 제공자의 설정·법적 요구에 따른 필요한 최소 기간
기기 내부 저장
UI 언어·테마·연습 설정·로컬 연습기록·로그인 토큰 등
설정 유지와 앱/웹 기능 제공
이용자가 브라우저 저장정보·앱 데이터·앱을 삭제할 때까지
3. 필수 제공과 거부
웹 회원가입 때 계정·인증 항목 수집 동의는 필수다. 동의를 거부하면 계정을 만들 수 없지만 로그인 없는 타자연습은 이용할 수 있다. 일부 Android 구버전은 이메일 입력을 선택사항으로 처리할 수 있다.
4. 공개되거나 다른 이용자와 공유되는 정보
랭킹·도전·실시간 대전에서 ID 또는 닉네임과 타자 성적, 입력 방식, 도전 이력·진도가 다른 이용자에게 표시될 수 있다. 비밀번호·복구용 코드 인증정보와 이메일은 공개하지 않는다. 승인된 사용자 신청 텍스트는 공용 연습문으로 게시될 수 있다.
5. 처리위탁·국외 처리
서비스 운영을 위해 Railway 및 연결된 PostgreSQL 데이터베이스 제공자가 서버·데이터베이스를 처리할 수 있다. Android 푸시를 켜면 Google Firebase Cloud Messaging이 토큰과 알림 전달정보를 처리한다. 실제 보관 국가·리전은 운영자가 선택한 배포 설정에 따르며, 각 제공자의 보안·개인정보 조건이 적용된다. 운영자는 제공자·리전을 변경하면 이 방침을 갱신한다.
6. 쿠키와 로컬 저장소
현재 웹서비스는 광고·추적 쿠키를 설정하지 않는다. 설정 유지와 로그인 등에는 브라우저 localStorage를 사용한다. 브라우저 저장정보를 지우면 기기에 남은 설정과 로그인 상태를 삭제할 수 있다.
7. 이용자의 권리
이용자는 개인정보의 열람, 정정, 처리정지, 삭제와 동의 철회를 요청할 수 있다. 앱/웹의 계정정보에서 이메일을 수정하고 계정 삭제 기능을 이용하거나 위 연락처로 요청할 수 있다. 본인 확인에 필요한 최소 정보가 요구될 수 있다.
8. 계정·개인정보 삭제
계정 삭제 시 계정정보, 세션, FCM 토큰, 본인 소유 랭킹, 동기화 기록, 텍스트 신청을 삭제하고, 다른 이용자가 보유한 도전 이력 속 탈퇴자의 ID·닉네임은 익명화한다. 이미 공용 텍스트로 승인되어 계정과 분리된 내용, 법적 의무에 따라 보존해야 하는 자료, 즉시 갱신할 수 없는 제한적 백업은 예외가 될 수 있다. 기기에 저장된 자료는 서버 계정 삭제만으로 지워지지 않는다. 자세한 절차는 계정·개인정보 삭제 안내에서 확인할 수 있다.
9. 안전성 확보조치
비밀번호와 복구용 코드는 원문이 아니라 각각의 salt를 적용한 반복 단방향 해시로 저장하고, 인증 API에 호출 제한을 적용하며, 통신에는 HTTPS를 사용하도록 배포한다. 접근권한 최소화, 보안 헤더, 만료 세션 정리와 유효하지 않은 FCM 토큰 제거도 적용한다.
10. 아동
서비스는 아동을 대상으로 설계하지 않았다. 적용 법률상 보호자 동의가 필요한 나이의 이용자는 보호자와 함께 이용해야 한다. 보호자 동의 없이 아동 개인정보가 수집된 사실을 알게 되면 연락처로 삭제를 요청할 수 있다.
11. 변경과 문의
처리 항목·목적·제공자 등 중요한 내용이 바뀌면 시행 전에 이 페이지에서 알리고 필요한 경우 새 동의를 받는다. 문의는 zhengxi980@naver.com으로 할 수 있다.
Effective and last updated: August 22, 2026 · Policy version: 2026-08-22
The operator of XixiTyping (“we”) describes below the personal data processed by the website and Android app and your rights.
Important notice about email Email is used only to prevent duplicate accounts and to match an account during ID lookup or password reset. The service does not automatically send verification emails, password-reset emails, advertising, or newsletters. Android challenge alerts use Firebase Cloud Messaging (FCM) push notifications, not email.
ID, nickname, email, password and recovery-code authentication data protected with salts and one-way hashes, password-hash history, signup date, consent time/policy version/UI language/source, session token
Signup, login, duplicate prevention, ID lookup, secure password reset, preventing recovery-code reuse of current or previous passwords, proof of consent
Until account deletion; sessions until logout, password reset, account deletion, or no more than 30 days after issue
Practice, ranking, challenge
ID, nickname, text/language, input method, CPM, KPM, accuracy, completion, character counts, elapsed time, timestamps, challenge history
Record sync, rankings, challenges
Until record or account deletion; a deleted user's ID and nickname in another user's challenge history are anonymized
Live duel
Room code, ID, nickname, ready/connection state, live progress, scores, result
Matching, duel operation, result display
Until room removal, account deletion, or service cleanup
Visitor hash for the life of the service; hosting logs for the minimum period required by provider settings and law
On-device storage
UI language, theme, practice settings, local records, login token, etc.
Remember settings and provide features
Until you clear browser/app data or uninstall
3. Required data and refusal
Account/authentication data and consent are required for website signup. You may refuse, but cannot create an account; typing practice without login remains available. Some older Android versions may treat email as optional.
4. Data visible to others
Rankings, challenges, and live duels may show your ID or nickname, typing metrics, input method, challenge history, and progress to other users. Email, password, and recovery-code authentication data are not public. Approved submissions may become public practice text.
5. Processors and international processing
Railway and the connected PostgreSQL provider may process server and database data. When Android push is enabled, Google Firebase Cloud Messaging processes tokens and notification-delivery data. The actual country/region depends on the operator's deployment configuration; provider security and privacy terms apply. We will update this policy if providers or regions change.
6. Cookies and local storage
The website currently sets no advertising or tracking cookies. It uses browser localStorage for settings and login. Clearing the site's browser data removes local settings and login state.
7. Your rights
You may request access, a copy, correction, restriction or suspension, deletion, and withdrawal of consent. You can update email or delete the account in account settings, or contact us. Minimum identity verification may be required.
8. Account and data deletion
Account deletion removes account data, sessions, FCM tokens, your rankings, synchronized records, and text requests, and anonymizes the deleted user's ID/nickname within other users' challenge histories. Approved public text separated from the account, legally required records, and limited backups that cannot be updated immediately may be exceptions. Server deletion does not erase local device data. See Account & Data Deletion.
9. Security
Passwords and recovery codes are stored separately as salted, iterated one-way hashes rather than plaintext. Authentication endpoints are rate-limited, deployments use HTTPS, and the service applies least privilege, security headers, expired-session cleanup, and invalid FCM token removal.
10. Children
The service is not designed for children. A user below the age at which parental consent is required by applicable law should use it with a parent or guardian. A guardian may contact us to request deletion of data collected without consent.
11. Changes and contact
We will post material changes before they take effect and obtain renewed consent when required. Contact: zhengxi980@naver.com.