jocoHunt Privacy Policy
The jocoHunt operations team ("Operator") establishes and publishes this Privacy Policy to protect personal information and handle related complaints promptly and smoothly under Article 30 of Korea's Personal Information Protection Act. jocoHunt (service domain: jocohunt.com) is a K-product launch community for Korean builders, and the weekly first-place product may be introduced on the JoCoding live channel and jocoLetter newsletter. The service is currently free and does not provide payment features.
Effective date: 2026-05-15 Last updated: 2026-05-15
Article 1. Purpose of Processing Personal Information
The Operator processes personal information for the following purposes. Personal information will not be used for any purpose other than those listed below. If the purpose changes, the Operator will take required measures, including obtaining separate consent where required by law.
Member management - GitHub OAuth-based identification, session maintenance, abuse prevention, same-IP cluster vote detection, and abuse blocking.
Service operation - Maker profiles, product pages, votes, comments, feedback, follows, bookmarks, and reports.
Vote eligibility determination - GitHub account age and public commit activity are used to determine voting eligibility and prevent abuse.
Notifications - Transactional email through Resend, including weekly winner notices, maker-story form invitations, and in-app notifications.
Service analytics - PostHog may be used to aggregate page views and feature usage at an anonymous or aggregated level. If a PostHog API key is not configured, analytics are disabled.
Article 2. Categories of Personal Information Processed
The Operator processes the following personal information.
Required information automatically provided by GitHub OAuth:
- Name - member identification and profile display
- Email address - member identification, notifications, and maker-story form invitations
- GitHub handle - member identification and profile display
- GitHub user id - member identification and duplicate signup prevention
- GitHub account creation date - vote eligibility (whether at least 7 days old)
- Whether the account has public commit activity - vote eligibility (activity trust signal)
- Avatar URL - profile image display
Optional information entered by users:
- Site handle - profile URL and display
- Display name - profile display
- Bio - profile display
- Interest categories - recommendations and feed composition
- Notification preferences - email and in-app notification controls
Automatically collected information may include IP address, User-Agent, browser cookies, service activity records such as votes, comments, feedback, follows, reports, bookmarks, visit records, and abuse records. If PostHog analytics is enabled, page view events and feature click events may also be collected.
The Operator does not collect sensitive information such as ideology, beliefs, union membership, political views, health, sexual life, genetic information, or criminal history.
The Operator does not collect resident registration numbers, passport numbers, driver's license numbers, alien registration numbers, or similar unique identifiers.
Article 3. Retention and Use Period
The Operator processes and retains personal information within the retention and use periods required by law or agreed to when collecting the information.
| Processing activity | Retention period | Basis |
|---|---|---|
| Member information | Until account deletion | Service contract |
| Notification preferences | Until account deletion | Service contract |
| Abuse records | 1 year after abuse handling ends | Legitimate interest in abuse prevention |
| Posts, comments, feedback, and reports | Anonymized after account deletion | Community continuity and user consent |
| Access logs | 3 months | Protection of Communications Secrets Act Enforcement Decree |
Article 4. Third-Party Provision
The Operator processes personal information only within the purposes stated in Article 1 and provides personal information to third parties only where the data subject has consented or where Korean law permits or requires it. The Operator currently does not separately provide personal information to third parties.
Article 5. Outsourcing of Personal Information Processing
The Operator outsources personal information processing as follows. Because several processors are located outside Korea, this policy also serves as public notice of overseas transfer under Article 28-8 of Korea's Personal Information Protection Act.
| Processor | Outsourced work | Period | Country |
|---|---|---|---|
| GitHub, Inc. (Microsoft Corporation) | OAuth login and authentication | Until account deletion or contract termination | United States |
| Resend, Inc. | Transactional email | Until account deletion or contract termination | United States |
| PostHog Inc. | Usage analytics, opt-out available, disabled if no key is configured | Until account deletion or contract termination | United States |
| Tencent Cloud Computing (Beijing) Co., Ltd. (Lighthouse) | Cloud infrastructure | Until contract termination | Seoul, Korea IDC |
| Cloudflare, Inc. | CDN, DNS, and Cloudflare Tunnel | Until contract termination | Global, U.S. headquarters |
| Self-hosted MinIO object storage | User-uploaded image storage | Until account deletion or contract termination | Seoul, Korea, inside Tencent server |
When entering into outsourcing agreements, the Operator specifies restrictions on processing outside the outsourced purpose, technical and managerial safeguards, restrictions on re-outsourcing, supervision, and liability, and supervises processors so that personal information is handled safely.
Article 6. Destruction of Personal Information
The Operator destroys personal information without delay when it becomes unnecessary, such as when the retention period expires or the processing purpose is achieved. Electronic files are permanently deleted in a way that makes recovery difficult, and paper documents, if any, are shredded or incinerated. If retention is required by law, the relevant personal information is separated and stored separately. Posts created by members may be retained only in anonymized form for community continuity.
Article 7. Rights of Data Subjects and How to Exercise Them
Data subjects may request access, correction, deletion, suspension of processing, and data portability at any time. Rights may be exercised by email or other written/electronic means under applicable law, and the Operator will respond without undue delay. For children under 14, a legal representative may exercise these rights.
How to exercise rights:
- Email: [email protected]
- Profile and notification preference changes: settings page (/settings)
- Account deletion: directly through the settings page
For data portability requests, transferable items include email, display name, handle, bio, interest categories, notification preferences, and user-created posts such as products, comments, and feedback. The transfer format may be JSON or CSV, and requests will be handled within 10 business days where applicable.
Article 8. Cookies and Similar Technologies
The Operator uses cookies and similar browser storage (localStorage) for the following purposes:
- Required session cookies — used by better-auth for login sessions. If rejected, member features cannot be used.
- Analytics identifiers (statistics) — PostHog stores an anonymous
distinct_idin localStorage along with page view and feature click events to aggregate usage statistics. The Operator does not directly identify individuals; non-logged-in traffic is treated as anonymous aggregate data (person_profiles: identified_only). DOM autocapture and session replay are disabled, so body text and form inputs are not collected. - Auxiliary analytics — Google Analytics 4 (when
NEXT_PUBLIC_GA4_MEASUREMENT_IDis set) and Microsoft Clarity may collect anonymous usage data for the same statistical purposes. They are automatically inactive when keys are not configured.
How to exercise your right to refuse
- Enable the Do Not Track (DNT) header in your browser; the PostHog SDK respects DNT and automatically stops tracking.
- PostHog opt-out: use browser incognito mode, an ad/tracker blocker, or call
https://us.posthog.com/decide?disable=trueto disable. - Google Analytics opt-out: install the official add-on at
https://tools.google.com/dlpage/gaoptout. - Microsoft Clarity opt-out: enable browser tracking protection or block the
clarity.microsoft.comdomain. - Per-browser cookie / localStorage clearing
- Chrome: Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions
- Firefox: Settings > Privacy & Security > Cookies and Site Data
Rejecting required cookies disables login state and member-only features. Blocking only the analytics identifier has no impact on regular service use.
Article 9. Security Measures
The Operator takes managerial, technical, and physical measures to protect personal information. Access to systems is controlled through SSH keys and protected GitHub secrets, logs are kept, passwords and session tokens are stored using one-way or strong encryption methods where applicable, and Cloudflare firewall/Tunnel is used. Physical access control depends on Tencent Cloud's Seoul IDC policies.
Article 10. Privacy Officer and Complaint Handling
Privacy officer:
- Department: jocoHunt operations team
- Email: [email protected]
- Contact: email only; no separate phone line is operated
Complaint handling:
- Department: jocoHunt operations team
- Email: [email protected]
- Hours: weekdays 09:00-18:00 KST, with a target first response within 48 hours by email
Article 11. Children Under 14
The Operator does not allow children under 14 to sign up. The service uses GitHub OAuth only and is operated to align with GitHub's age policy and Korea's rules on consent for children under 14. If a member is found to be under 14 after signup, the account may be suspended and related personal information destroyed.
Article 12. Automated Decisions
The Operator uses rule-based automated processing to determine voting eligibility.
Criteria include whether a GitHub account is connected, GitHub account age, public commit activity, and self-vote checks.
Voting is allowed only for members who meet all of the following. Every vote is counted equally as 1, with no weighting:
- A GitHub account is connected
- The GitHub account is at least 7 days old
- The account has at least one public commit
- The product is not one's own (self-votes are blocked)
Abuse handling: signals such as same-IP cluster voting or rapid voting from new accounts are surfaced to the Operator, who may review and manually void the relevant votes. This voiding is an operator decision, not an automated one.
This is a rule-based algorithm. No machine learning model is used and no training data is used.
Data subjects may request an explanation, object to an automated decision, or request human review. Requests may be sent to [email protected].
Remedies for Rights Infringement
Data subjects may contact the following Korean institutions for dispute resolution or counseling.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- KISA Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
Changes to This Privacy Policy
This Privacy Policy applies from its effective date. If laws or this policy change, material additions, deletions, or corrections will be announced through service notices at least 7 days before they take effect.
Revision history:
- 2026-05-15 Initial publication
This Privacy Policy is effective from 2026-05-15.