Privacy Policy
Effective 2026·10·01 · Last updated 2026·10·01 · Version 1.2
Macro Weather (the "Company") treats your personal data with care and complies with the Korean Personal Information Protection Act ("PIPA") and related laws. This policy explains how we collect, use, store and delete personal data in the Macro Weather web app (https://macroweather.app) and related services.
⚠️ Language This English text is provided for your convenience. The Korean version is the original; where the two differ in meaning, the Korean version prevails, except where mandatory law in your country of residence provides otherwise.
1. What we collect
Required (account and service use)
- Google sign-in: email address, profile name, profile image URL, Google user identifier (UID)
- Learning activity: progress, accuracy, XP, league tier, streak days, badge history
- Device and access data: browser type, OS, access IP, access time
Optional
- Friend relationships: the other party's UID when you add a friend (with their consent)
- Persona and sector interests: A (IT/Big Tech) · B (Defence/Space) · C (Finance/REITs) · D (Energy/Consumer)
- Age mode: Kids / Teen / Adult (guardian consent required for children's accounts)
- Portfolio data (Master): holdings and weights you enter yourself (no automatic brokerage-account linking)
Paid subscriptions
- Payment data: payment method (card issuer, simple-pay provider), approval number, payment time, product details. Card numbers, CVC and similar credentials are never stored by the Company; the payment gateway handles them.
- Mobile phone number: required to register recurring payments and to send receipts and cancellation notices (a payment gateway requirement).
- Tax invoice details (on request only): business registration number, trade name, representative name, business address
💳 Note The payment gateway in use is shown on the payment screen. Paid payments are not operated during the beta period, so the payment data above is not collected.
Support enquiries (optional)
- Reply email address: collected when you contact us without signing in, so that we can respond.
- Diagnostic data: for bug reports, and only if you tick the consent box, we also send app version, browser user-agent, screen size and up to 3 recent error messages. Unticking the box prevents this.
2. How we collect it
- Automatically, with your consent, during Google OAuth sign-in
- Directly from you inside the Service (persona selection, learning activity)
- Generated automatically as you use the Service (progress, access logs)
- Provided voluntarily by you during support enquiries
3. Why we process it
| Purpose | Data used |
| Account identification and authentication | Email, Google UID |
| Progress tracking and statistics | Learning activity, XP, league |
| Personalisation and recommendations | Persona, sector interests, incorrect-answer history |
| Friend leagues and social features | Friend relationships, profile |
| Payment and subscription management | Payment data, phone number, subscription history |
| Customer support | Email, enquiry content, diagnostic data (with consent) |
| Service improvement and analytics | Anonymised usage statistics, A/B experiment identifier |
| Fraud prevention and security response | Access logs, IP |
4. How long we keep it
- Account data: until you delete your account; erased within 30 days of the request
- Learning activity: erased immediately on account deletion (retained only as anonymous statistics)
- Payment and tax records: 5 years, as required by the Act on Consumer Protection in Electronic Commerce (contract, withdrawal, payment and supply records)
- Fraud-prevention logs: 3 months, per the Protection of Communications Secrets Act
- Support enquiry records: 3 years
⚠️ Statutory retention prevails Where law requires retention, we keep the data for that period. All other personal data is destroyed without delay when you delete your account.
5. Sharing with third parties
We do not sell or share your personal data with third parties, except:
- with your prior explicit consent;
- where required by law or in response to a lawful request from an investigating authority;
- where necessary to provide the Service (see section 6, processors).
6. Processors
| Processor | Work entrusted | Retention |
| Google LLC (Firebase) | Authentication, database, hosting, push notifications | Until account deletion |
| Anthropic PBC (Claude API) | AI tutor response generation (no personal data stored) | Not retained |
| Domestic payment gateway | Payment processing and settlement (not operated during beta) | 5 years (statutory) |
| Federal Reserve Bank of St. Louis (FRED) | Macroeconomic indicator lookup (no personal data sent) | N/A |
💡 Overseas transfer Google LLC (USA) and Anthropic PBC (USA) store and process data in the United States. The data transferred, purposes and retention periods are as set out in the table above. We obtain your consent to overseas transfer at sign-up, and you may refuse. Because authentication and data storage depend on these providers, refusing means the Service cannot be provided.
7. Your rights
You may at any time:
- Access the personal data we hold about you
- Correct or delete inaccurate data
- Object to or restrict specific processing
- Port your data: download your learning data as JSON from Settings > My data · Account
- Delete your account at any time from Settings > My data · Account
You can exercise these rights in the app, or by emailing the privacy contact below; we act without undue delay.
8. Destruction
When the retention period expires or the purpose is achieved, we destroy data without delay:
- Electronic files: permanently deleted by irrecoverable means (Firebase Authentication and Cloud Firestore deletion APIs)
- Paper records: shredded or incinerated
9. Cookies and automatic collection
- localStorage · IndexedDB: learning progress, sign-in state, language preference
- Service Worker cache: PWA offline support and fast loading
- A/B experiment identifier: we store a random anonymous identifier (
ab_anon_id_v1) in your browser and record which layout variant you saw and whether you interacted with it. It is never combined with identifying information, never used for advertising and never shared with third parties.
How to refuse: block cookies and site storage in your browser settings, or clear site data (which also removes the identifier). Some features, such as staying signed in, will then be limited.
10. Children under 14
👶 Kids mode Using "Kids mode" (ages 5–9) requires the consent of a legal guardian.
- Children under 14 may register only with legal guardian consent.
- Verification: after sign-in, if the age check indicates the user is under 14, we require a guardian consent confirmation and the guardian's email address. Without confirmation, service use is restricted.
- The guardian email is kept solely to evidence consent, and we may use it to re-confirm consent.
- Kids mode also displays a guardian confirmation notice.
- Guardians may at any time request access to, correction of, deletion of, or suspension of processing of the child's data.
- Children's data is not used for any purpose other than learning, and never for advertising or marketing — including learning reminder notifications, which are not sent to accounts marked as under 14.
11. Security measures
- Encrypted transport: all traffic over HTTPS (TLS 1.2+)
- Authentication: Firebase Authentication (OAuth 2.0) with App Check
- Access control: Firestore Security Rules restrict data to its owner
- Browser hardening: Content Security Policy and related security headers
- No payment credential storage: card details are held only by the payment gateway; we store payment results only
- Ongoing review: vulnerability checks and log monitoring
12. Privacy contact
You may also contact the Korean authorities below about privacy infringement:
- Privacy Infringement Report Centre · privacy.kisa.or.kr · 118
- Personal Information Dispute Mediation Committee · www.kopico.go.kr · +82-1833-6972
- Supreme Prosecutors' Office, Cybercrime Division · www.spo.go.kr · 1301
- Korean National Police Agency, Cyber Bureau · cyberbureau.police.go.kr · 182
13. Changes to this policy
We may update this policy to reflect changes in law or the Service. We will give notice at least 7 days in advance (30 days for material changes) via in-app notice and email.
📌 Addendum
① This policy takes effect on 1 October 2026.
② Version 1.2 changed the service address to https://macroweather.app. The personal data we process, the purposes, the retention periods and our processors are unchanged.
③ Version 1.1 added explicit entries for mobile phone number (payments), diagnostic data (bug reports, with consent) and the anonymous A/B experiment identifier, and removed references to a processor not actually used (Supabase) and to an analytics feature not deployed (Firebase Analytics).