Privacy Policy
Last updated: September 4, 2026
한국어: 개인정보처리방침 (Korean — controlling version)
SmileStory Co., Ltd. ("we", "us", or "our") operates WIA Code (https://wiacode.com). This Privacy Policy explains how we collect, use, and protect your information when you use our service.
1. Information We Collect
WIA Code is designed with privacy in mind. We collect minimal information:
- Language Preference: Stored locally in your browser (localStorage) to remember your language setting.
- Camera Access: Used only for real-time WIA Code scanning. Camera data is processed entirely on your device and is never transmitted to our servers. Only if on-device decoding fails and you explicitly tap the optional “Cloud Decode” button, that single image is sent to our server for decoding and is not stored.
1-A. Event Entry (WIA Code Founding Seats / the 100,000,000-people journey)
If — and only if — you submit an entry to our event, we additionally record the following. Browsing the event page, generating a code, or scanning one does not trigger any of this.
- Your submission: the account you signed in with, the country you chose, the public social-media post URL you provided, a display name, an optional image you attach, and the email address you want the reward sent to. We use these to review the entry, assign your participant number, and deliver the reward.
- Abuse signals (hashed): a salted, truncated hash of your IP address and of your browser's User-Agent string, recorded at the moment you submit. We do not store the IP address or the User-Agent itself. These hashes exist for one purpose — to notice when many entries arrive from the same origin, so a reviewer can take a look. They are never used to block anyone automatically (shared and carrier-grade NAT addresses legitimately collide), and they are not linked to any activity outside the entry form.
The anonymous usage milestone counter on our generator and scanner pages is a separate system that carries no identity, no cookies, and no account link. Nothing in this section applies to it — see 1-B.
1-B. Anonymous Usage Counter
Our generator and scanner pages count how many times a WIA Code has been created or successfully scanned. This counter is anonymous by design and stays that way:
- No identity, ever. The request carries no cookies (
credentials: 'omit'), no account link, and no device identifier. We could not attribute a count to a person even if we wanted to. - One-time token: before counting, the page fetches a short-lived signed token from us. The token contains only a timestamp and a random value — nothing about you — and can be used once.
- Abuse limits (hashed): to keep the number honest we cap how many counts can come from one origin per minute and per day. For the daily cap we keep a salted hash of your IP address and browser User-Agent for up to 24 hours. We do not store the IP address or the User-Agent itself, and these hashes are not linked to any account or to anything you do elsewhere on the site.
1-C. Signing In (optional)
You can use the generator and the scanner without an account. If you choose to sign in — the
Sign in button in the site header, which uses the shared WIA account service — we receive
your account identifier, email address, nickname, profile image URL, membership plan, role and the
provider you signed in with (for example Google or Kakao). We use these to show you your own page
(/mypage/) and the links and codes that belong to you. We do not receive your password.
1-D. Direct Links (wiacode.com short links)
If you create a direct link, we store the short token, the account that owns it, the destination URL and its host, a status flag and an optional note you write for yourself. If you verify a domain of your own, we store that domain name and the verification result. We also count how many times each link has been opened, per day. That count is a total, not a log — we do not record who opened a link, from where, or when individually.
1-E. Donations
If you donate through the “Buy us a coffee” button, the payment is processed by Stripe. Your card details are entered directly into Stripe’s own form and never reach wiacode.com. This site forwards only the amount and currency to our payment service and holds no card data and no Stripe secret key.
2. Data We Do NOT Collect
- We do not collect personal identification information unless you voluntarily provide it.
- We do not store any data from scanned WIA Codes on our servers.
- We do not sell, trade, or share your data with third parties.
3. WIA Code Data Processing
All WIA Code encoding and decoding happens locally in your browser by default. The data stored inside a WIA Code is processed on your device only. Scanned content is sent to our servers only when you explicitly opt in to the Cloud Decode fallback, and it is not stored.
4. Cookies and Local Storage
We use your browser’s localStorage to remember your language preference and PWA settings. This never leaves your device.
We set one cookie, and only after you sign in. It is named wia_session,
it is a host-only cookie (it is not shared with subdomains), it is cryptographically signed, and it
expires after 30 days or when you sign out. It carries the sign-in details listed in section 1-C so
that you stay signed in across the WIA family of sites. We use no advertising, analytics or
third-party tracking cookies of any kind. If you never sign in, this site sets no cookie at
all.
5. PWA and Offline Usage
When you install WIA Code as a PWA (Progressive Web App), the application files are cached on your device via Service Worker. This enables offline scanning. No personal data is cached — only application code.
6. Children's Privacy
WIA Code is designed for all ages. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us.
7. Data Security
We implement industry-standard security measures. Since WIA Code processes data locally on your device, the risk of data breach is minimized by design.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date.
8-A. Language of This Policy
This Privacy Policy is provided in Korean (/ko/privacy.html) and in English. If there is any difference in interpretation between the two, the Korean version prevails. Any translation into another language is provided for convenience only and has no binding effect.
9. Contact Us
If you have questions about this Privacy Policy:
- Email: global@thekoreantoday.com
- Company: SmileStory Co., Ltd.
- Address: 511 D01, 21 Magokjungang 6-ro, Gangseo-gu, Seoul, Korea