Privacy Policy
Privacy Policy — PackRoom (챙겨방)
This page describes how personal information is handled in the PackRoom (챙겨방) app. App-specific notices come first, followed by the common terms that apply across all Centora Labs services.
Effective and last updated: 2026-09-03
Overview
PackRoom helps families, friends, and small groups prepare shared trip packing lists. It processes only the data needed for account sign-in, guest join, shared-room terms acceptance, rooms, items, item and plan comments, optional comment image and document attachments, member reports and room-scoped blocks, checkpoints, invite links, optional account profile photos, optional push notifications, and optional destination weather. In addition to automatic app launch and session events, Firebase Analytics processes fixed screen entry and foreground dwell time, selected app language, account, guest, or signed-out mode, native build number and debug or release classification, operation type, result, and duration, product milestones such as list, item, and invite actions, search result presence and count without the search term, and ad-slot load, impression, click, and paid callbacks for product improvement and release monitoring. It receives no app-defined user ID, room or item identifier, invite token, name, title, comment, attachment, profile photo, report content, email, URL, search term, or other user-entered content. App language, authentication mode, numeric native build number, and debug or release classification are the only app-defined Analytics user properties. The app does not use crash-reporting SDKs, payments, or device GPS location permissions.
Advertising (Android and iOS Google AdMob)
The Android and iOS apps may show compact banner ads between packing-list content and comments. To deliver and measure ads, prevent fraud, and operate the SDK, Google Mobile Ads SDK may collect or share with Google approximate location derived from IP address, device identifiers, advertising identifiers when available under operating-system permissions and settings, ad and app interactions, advertising data, and diagnostics and performance data. Data is encrypted in transit. See the Google Privacy Policy (policies.google.com/privacy) and how Google uses information from sites or apps that use its services (policies.google.com/technologies/partner-sites).
Accounts and guest identity
Hosts and account members may sign in with Google. Account identifiers and email addresses are processed only to provide app features and manage accounts. Guests join through invite links using a device-scoped guest credential and member identifier. Raw invite tokens are not stored; only hashed invite metadata is retained.
Shared-room terms, reports, and blocks
Before a user first creates, opens, or joins a shared room, PackRoom records the current terms version, the account or guest principal reference, and the server acceptance time. A joined member may report another joined member from that person's profile with a reason and optional detail. Ordinary reports go to the room host. Reports against a host, serious safety reasons, and reports for which the user requests operator review also enter a protected Centora Labs review queue. A report contains reporter and target member identifiers, room identifier, reason, optional detail, routing, and resolution status. If a host blocks and removes a member, PackRoom keeps a room-scoped block that prevents the same account or guest principal from rejoining that room. Reports and blocks are deleted with the room, and account or guest deletion applies the required anonymization or principal-reference removal. Report text and reporter identity are excluded from diagnostic logs.
Data we process
To run the app we process account identifiers and email, member display names, user-selected account profile photos, terms version and acceptance time, room metadata, packing items, item and plan comments, user-selected comment image and document attachments, member-report and room-block metadata, checkpoint state, invite metadata, user settings such as language, theme, and notification preferences, push device tokens when notifications are enabled, operational logs for sync and diagnostics, and account-deletion records. Profile photos and report details are optional. A profile photo is stored in private account-owned storage and shown only as an avatar to participants in the same room. Firebase Analytics processes pseudonymous app-instance data, automatic lifecycle events, fixed screen names and foreground dwell time, app language and authentication mode, native build number and debug or release classification, operation outcomes and duration, product milestones, and aggregate ad responses. Diagnostic and Analytics payloads must not include raw invite tokens, room, item, or member identifiers, comment bodies, full item titles, attachments, profile photos, report details or reporter identity, raw push tokens, auth secrets, email, URLs, search terms, or app-defined user IDs.
Comment image and document attachments
Users may optionally attach supported images and documents to item or plan comments. File bytes and file-name, type, size, and author metadata are stored in private Supabase Storage and room-scoped metadata. Only current members of the same room can open them through short-lived signed links. Attachments are deleted with the owning comment or room, and uncommitted upload reservations are cleaned after one hour.
Destination and weather
Destination is user-entered plan place data. PackRoom does not collect device GPS or network location permissions. A city-level place label and coordinate snapshot may be stored with the room and are deleted with the room. Weather and place-search requests send only coordinates or search text, never room names, item titles, member names, or account identifiers.
Push notifications
When collaboration notifications are enabled, APNs or FCM device push tokens and notification event status are processed. Push copy uses privacy-safe summaries. Disabling notifications or deleting the account disables or removes the device registration.
Service providers and international transfer
PackRoom may use Supabase Cloud for authentication, database, and server functions; Apple for App Store, APNs, and distribution; Google for Play, sign-in, FCM, Firebase Analytics, and distribution; and weather or place-search providers that receive only coordinates or query text needed for the request. Firebase Analytics is subject to separate Google Analytics terms and aggregates the lifecycle and product-interaction events described above. Processing is limited to app operation, security, support, compliance, product improvement, and aggregate release monitoring. Because of backend and platform design, some processing may occur outside Korea.
Account and data deletion
Account deletion runs inside the app under More → Account and privacy, completes immediately, and cannot be undone. Confirmation requires typing an explicit phrase. Where platforms require a web path, use https://packroom.centoralabs.com/privacy/delete-request. The app has no paid purchases, and Centora Labs does not directly retain advertising data. Shared room content that other members still rely on may remain with identifying fields cleared so the room stays usable.
Sale, advertising, and children
PackRoom does not sell user data and does not use room content or account information for third-party advertising or developer marketing. Google AdMob may process the advertising-related data described above under its own policies. The app is not designed for children.
Controller
Centora Labs is responsible for this Privacy Policy. The official website is centoralabs.com. Send privacy inquiries to contact@centoralabs.com.
Information we collect
Through this website and support channels, we may process information users provide directly, such as name, email address, inquiry details, device information, screenshots, and other details needed to respond or investigate an issue.
Purposes
We use personal information to respond to inquiries, operate services, investigate errors, handle user requests, and meet legal obligations.
Retention
We retain information for the period needed to handle the inquiry and operate the service. When the purpose has been met, we delete the information unless retention is required by law.
Deletion
When personal information is no longer needed, we review whether retention is required and then delete it. Electronic files are deleted in a way that makes recovery difficult, and paper records are shredded or destroyed by an equivalent method.
Third-party disclosure
We do not provide users' personal information to external parties except where required by law.
Service providers
Website hosting, email delivery, and security operations may involve infrastructure providers. If an app requires additional providers for login, analytics, advertising, payments, or similar functions, service-specific notices will be added.
Security
We limit access to personal information and apply appropriate safeguards during transmission and storage.
User rights
Requests to access, correct, delete, or restrict processing of personal information can be sent to the official contact email.
Accounts and sign-in
If an app offers Google, Apple, or other external account sign-in, account identifiers, email addresses, and related information are processed only to provide app features and manage accounts, and service-specific notices will be added.
Cookies and similar technologies
This website does not currently use cookies for personalized advertising or behavioral tracking. If an app or service uses cookies, analytics, or similar technologies, service-specific notices will be added.
Policy changes
If this policy changes, the effective date and last updated date on this page will be revised. Important changes will be announced through appropriate channels, such as in-service notices.
Contact
Send privacy inquiries and related requests to the official email below.
- Privacy contactCentora Labs Privacy Contact
- Emailcontact@centoralabs.com
Please include enough information for us to verify the request and the email address where you can receive a response.