개인정보처리방침 (Privacy Policy)
최종 수정: 2026년 8월 1일
1. 서비스 개요
SongScan(“본 서비스”)은 YouTube 재생목록의 곡을 장르별로 분류하여 사용자의 YouTube 계정에 새 재생목록을 생성하는 웹 애플리케이션입니다.
2. 수집하는 정보
2.1 Google OAuth를 통해 수집하는 정보
- Google 계정 이메일 주소 및 프로필 이름
- YouTube 재생목록 접근을 위한 OAuth access token
- 자동 재개 기능을 위한 OAuth refresh token (암호화 저장)
2.2 서비스 이용 시 생성되는 정보
- 분류된 곡 정보 (제목, 채널명, 장르)
- 생성된 재생목록 정보
- 사용자 식별을 위한 해시된 ID (이메일의 단방향 해시)
3. YouTube API Services 사용
본 서비스는 YouTube API Services Terms of Service를 준수합니다.
YouTube API를 통해 다음 기능을 제공합니다:
- 재생목록 영상 목록 조회
- 새 재생목록 생성 및 영상 추가
Google의 개인정보 수집 및 사용에 대해서는 Google 개인정보처리방침을 참조하시기 바랍니다.
3.1 Google API Services User Data Policy 준수
SongScan의 Google 사용자 데이터 사용 및 다른 앱으로의 전송은 Google API Services User Data Policy(제한적 사용 요건 포함)를 준수합니다. 구체적으로:
- Google 데이터는 본 서비스의 핵심 기능(재생목록 분류 및 생성) 제공 목적으로만 사용됩니다.
- Google 데이터를 광고 게재 목적으로 사용하지 않습니다.
- 사용자의 명시적 동의 없이 Google 데이터를 제3자에게 전송하지 않습니다.
- 법적 요구, 보안 목적, 또는 사용자 본인의 동의가 있는 경우에만 예외적으로 데이터 전송이 가능합니다.
- 인간이 Google 사용자 데이터를 읽는 것은 사용자 동의가 있거나, 보안/법적 목적, 또는 익명화된 내부 운영에 한정됩니다.
4. 정보의 저장 및 보호
- OAuth refresh token은 AES-256-GCM으로 암호화하여 저장합니다.
- 사용자 식별 정보는 단방향 해시로만 저장하며, 원본 이메일을 역추적할 수 없습니다.
- 모든 통신은 HTTPS(TLS)로 암호화됩니다.
5. 정보의 공유
본 서비스는 사용자의 개인정보를 제3자에게 판매, 대여 또는 공유하지 않습니다. 법적 요구가 있는 경우에만 관계 법령에 따라 정보를 제공할 수 있습니다.
6. 액세스 취소
사용자는 언제든지 Google 보안 설정에서 SongScan의 액세스 권한을 취소할 수 있습니다. 취소 즉시 본 서비스는 해당 사용자의 YouTube 데이터에 접근할 수 없게 됩니다.
7. 데이터 삭제
액세스 권한을 취소하면, 저장된 refresh token은 더 이상 유효하지 않으며 다음 cron 실행 시 자동으로 만료 처리됩니다. 사용자 데이터 삭제를 원하시면 피드백 기능을 통해 요청해 주세요.
8. 쿠키 및 로컬 저장소
- 인증 세션 유지를 위한 쿠키 (next-auth)
- 언어 설정 저장을 위한 localStorage
- 임시 작업 상태 저장을 위한 sessionStorage
9. 변경 사항 고지
본 방침이 변경되는 경우, 이 페이지에 업데이트하며 최종 수정일을 갱신합니다.
10. 개인정보 보호책임자
- 책임자: SongScan 운영자
- 연락처: 사이트 내 피드백 기능
개인정보 관련 문의, 열람·정정·삭제 요청은 위 연락처를 통해 접수해 주세요. 접수 후 10일 이내에 처리 결과를 안내드립니다.
Privacy Policy (English)
SongScan (“the Service”) uses YouTube API Services. By using the Service, you agree to be bound by the Google Privacy Policy.
Data We Collect
- Google account email and display name (via OAuth)
- YouTube OAuth access token and refresh token (encrypted at rest with AES-256-GCM)
- Classified track data (titles, channels, genres)
- One-way hashed user identifier
How We Use Your Data
- Read your YouTube playlists to classify tracks by genre
- Create new playlists on your YouTube account
- Automatically resume playlist creation after API quota resets
Revoking Access
You can revoke SongScan's access at any time via your Google Security Settings. Once revoked, we can no longer access your YouTube data.
Google API Services User Data Policy
SongScan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google data to provide the core functionality of the Service.
- We do not use Google data for serving advertisements.
- We do not transfer Google data to third parties without explicit user consent.
- Humans may only read Google user data with consent, for security purposes, legal compliance, or anonymized internal operations.
Data Sharing
We do not sell, rent, or share your personal information with third parties.
Contact
For privacy-related inquiries, please use the in-app feedback feature.