IRIS 메신저 처리방침
이 문서는 공식 허브(운영자: Sejun Ham)가 사용자에 대해 어떤 정보를 다루는지를 밝힙니다. 자기 허브를 세운 운영자는 이 문서를 자신의 상황에 맞게 고쳐 써도 됩니다. IRIS 창·설치기·계정 중계기는 PC 밖으로 자료를 보내지 않으므로, 이 방침은 메신저 모듈의 공식 허브에만 해당합니다.
수집하는 것
- 이메일 주소(로그인용)
- 표시 이름
- 프로필 사진(선택) — 넣은 경우에만. 모듈이 PC 안에서 96×96 크기로 줄인 작은 JPEG이며, 서버는 이 값을 표시 이름과 같은 등급으로 보관합니다(암호화하지 않음). 나와 친구를 맺은 상대만 볼 수 있고 언제든 지우거나 바꿀 수 있습니다.
- 공개 열쇠(public key) — 메시지 암호화에 쓰이며, 그 자체로는 메시지를 열 수 없습니다.
- 친구 관계 — 누가 누구와 연결되어 있는지(수락된 관계, 대기 중인 관계, 차단 관계). 두 사용자의 번호(uuid)를 모두 아는 사람은 그 둘이 연결되어 있는지를 서버에 물어 알아낼 수 있습니다. 사용자 번호는 서로 친구를 맺은 상대와 서버 운영자만 알 수 있습니다.
- 메시지를 보내고 받은 시각(발신 시각·수신 시각) — "누가 누구에게 언제 몇 번 보냈는지"에 해당하는 메타데이터.
절대 수집하지 않는 것
- 메시지 내용(평문) — 서버에는 암호문만 저장되며 서버는 이를 해독할 수 없습니다.
- 파일 내용
- 사용자의 작업 내용·작업 과정·세션 기록
보관 기간
- 배달이 확인된 메시지는 배달 후 30일이 지나면 서버에서 자동 삭제됩니다.
- 계정을 삭제(탈퇴)하면 즉시 그 사용자와 관련된 모든 줄(프로필·친구 관계·메시지·초대)이 삭제됩니다.
- 첨부 파일은 배달 여부와 무관하게 업로드 후 90일이 지나면 삭제됩니다.
- 탈퇴해도 이미 올린 첨부 파일의 실체는 즉시 지워지지 않습니다 — 위 90일 청소가 돌 때 함께 삭제됩니다. 표의 줄은 즉시 사라지므로 그 파일을 가리키는 편지는 아무도 열 수 없게 됩니다.
나이 제한
이 서비스는 만 14세 이상만 사용할 수 있습니다. 로그인 화면에서 "만 14세 이상이며 처리방침을 읽었습니다"에 동의해야 계속 진행할 수 있습니다.
문의
이 처리방침이나 개인정보 처리에 관한 문의는 메신저 저장소의 GitHub Issues로 남겨 주세요.
IRIS Messenger privacy policy
This document states what the official hub (operator: Sejun Ham) handles about its users. Anyone who runs their own hub may adapt it. The IRIS window, installer and account relay send nothing off your PC, so this policy applies only to the official hub of the Messenger module.
What is collected
- Email address (for login)
- Display name
- Profile picture (optional) — only if you add one. The module shrinks it to a 96×96 JPEG on your PC; the server keeps it at the same level as the display name (not encrypted). Only people you are friends with can see it, and you can remove or change it any time.
- Public key — used to encrypt messages; on its own it cannot open any message.
- Friend relations — who is connected to whom (accepted, pending, blocked). Anyone who knows both users' ids (uuid) can ask the server whether the two are connected. A user's id is known only to their friends and to the hub operator.
- Send and receive times of messages — the metadata of who sent to whom, when, and how often.
What is never collected
- Message content (plaintext) — the server stores ciphertext only and cannot decrypt it.
- File content
- Your work, your working process, or session transcripts
Retention
- Messages confirmed as delivered are deleted from the server 30 days after delivery.
- Deleting your account immediately removes every row related to you (profile, friend relations, messages, invitations).
- Attachments are deleted 90 days after upload, whether delivered or not.
- After account deletion the attachment files themselves are not removed at once — they go with the next 90-day cleanup. The rows pointing to them disappear immediately, so nobody can open those messages.
Age
The service is for people aged 14 and over. You must agree to "I am 14 or older and have read the privacy policy" on the login screen to continue.
Contact
Questions about this policy go to GitHub Issues of the Messenger repository.