MulmitMARKET SIGNAL CONSOLE

개인정보처리방침

시행일 2026-08-17 · 최종 개정 2026-09-20

Mulmit은 로그인 없이 누구나 볼 수 있는 시장 데이터 대시보드입니다. 종목 고정·알림·투표에는 Google 또는 Kakao 로그인이 필요합니다. 현재 광고가 없습니다 — 다만 도입할 예정입니다(아래 8항). 방문 통계를 위해 Google Analytics를 사용합니다. 이 문서는 형식적인 문구를 늘어놓는 대신 이 사이트가 실제로 무엇을 처리하는지만 적습니다.

요약 — 선택 로그인 시 Google 또는 Kakao가 준 서비스별 사용자 식별자·표시 이름·프로필 사진 URL과 세션 해시, 동기화한 고정 종목·알림 설정·투표를 저장합니다. 이메일·전화번호·결제정보는 요청하거나 저장하지 않습니다. 그 밖에 서버가 처리하는 것은 웹서버 접속 기록, 접속자 수와 화면 이동을 집계하기 위한 익명 무작위 id, 그리고 알림을 켠 경우의 푸시 구독 정보가 전부입니다. 브라우저에는 언어·테마 같은 화면 설정이 저장됩니다.

1. 수집하지 않는 것

먼저 없는 것을 분명히 해 둡니다. Mulmit은 다음을 수집하거나 처리하지 않습니다.

2. 실제로 처리되는 정보

항목목적보관
접속 로그
(IP 주소, 접속 시각, 요청 경로, User-Agent, 응답 코드)
서비스 운영, 장애 대응, 비정상 트래픽 확인 서버 컨테이너 로그로만 저장. 별도 데이터베이스에 적재하거나 다른 정보와 결합하지 않음
IP 주소 (요청 빈도 제한용) 같은 출처의 과도한 요청 차단 서버 메모리에서만 사용하고 저장하지 않음. 프로세스가 재시작되면 사라짐
티커 조회 횟수 이용자가 실제로 찾는 종목을 다음 수집 주기에 우선 포함 종목별 누적 횟수만 저장. 누가 조회했는지는 기록하지 않으며 IP·세션과 연결되지 않음
검색창에 입력한 말 찾는 종목이 아직 없을 때 무엇을 다음에 모을지 정하는 데 사용 날짜·검색어·결과 유무로 묶은 누적 횟수만 저장. 누가 검색했는지는 기록하지 않으며 IP·세션과 연결되지 않음. 한글·영문·숫자 낱말 세 개 이하만 저장하고 그 밖의 입력은 서버가 즉시 버림
화면에서 발생한 오류
(오류 이름, 파일명, 줄 번호)
배포 후 특정 브라우저에서만 화면이 깨지는 것을 발견하기 위해 오류 메시지 본문은 전송하지 않음(이용자가 보던 값이 담길 수 있으므로). 날짜별 누적 횟수만 저장하며 누가 겪었는지는 기록하지 않음
브라우저 창 너비 구간 어느 화면 크기에 맞춰 디자인해야 하는지 판단 정확한 픽셀이 아니라 구간(예: 360px 이하)만 저장. 날짜별 누적 횟수이며 누가 어떤 기기를 쓰는지는 기록하지 않음
화면에서 누른 것
(버튼·링크에 쓰인 말, 그 버튼이 속한 영역 이름, 눌린 화면 경로)
어떤 기능이 실제로 쓰이는지 판단 — 아무도 누르지 않는 것을 화면에서 덜어내기 위해 날짜·경로·영역·이름으로 묶은 누적 횟수만 저장. 누가 눌렀는지는 기록하지 않으며 IP·세션과 연결되지 않음. 이름표는 화면에 이미 쓰여 있는 말이고, 한글·영문·숫자와 기호 몇 개로 된 낱말 여섯 개 이하만 저장하며 그 밖의 입력은 서버가 즉시 버림
화면·섹션에 머문 시간
(화면 경로, 섹션 이름, 머문 초)
어느 화면과 어느 섹션이 실제로 읽히는지 판단 탭이 앞에 있고 창이 보이는 동안만 셈. 날짜·경로·섹션으로 묶은 누적 초만 저장하며 누가 머물렀는지는 기록하지 않음
익명 방문 id별 화면 이동 기록
(익명 방문 id, 화면을 연 시각, 화면 경로, 머문 초, 누른 횟수, 가장 오래 본 섹션)
한 브라우저가 어떤 순서로 무엇을 보는지 — 화면 구성을 고칠 때 보는 자료 이 표만 브라우저 단위입니다. 90일 후 자동 삭제. 익명 무작위 id에만 묶이고 이름·IP 등 다른 정보와 결합하지 않아 개인을 식별할 수 없음. 화면에 입력한 값이나 본문은 담기지 않고 경로·시간·초뿐임. 공개되지 않으며 운영자만 별도 열쇠로 열람
익명 방문 id
(브라우저가 만든 무작위 값)
"지금 보는 중" 카운트와 일별 방문자 수 집계, 위 화면 이동 기록 실시간 카운트 기록은 1시간 내 자동 삭제, 일별 고유방문 기록은 90일 후 자동 삭제. 이름·IP 등 다른 정보와 결합하지 않아 개인을 식별할 수 없음. 로그인 도입 전 기록용 일회용 이전 코드는 이 id만 가리키며 10분 뒤 삭제
홈 “오늘의 질문”과 “지금 이슈”에서 고른 답
(질문, 고른 보기, 고른 시각, 계정 id; 이슈 투표에는 이슈 식별자)
계정당 한 표, 참여자 분포 집계, 기기 사이에 이어지는 투표 기록 표시 계정을 삭제할 때 즉시 삭제하거나 1년 후 자동 삭제. 질문이 마감되면 보기별 인원수만 따로 남기며 이 수치는 누구와도 연결되지 않음. IP와 결합하지 않음. 보기는 의견·관심을 고르는 것이며 보유 종목이나 자산 규모를 묻지 않음
웹 푸시 구독 정보
(endpoint 주소, 브라우저가 만든 암호화 키)
이용자가 직접 켠 알림 발송. 고정 종목 알림은 계정과 연결 알림을 끄면 즉시 삭제. 발송이 계속 실패하는 구독도 자동 삭제
선택 로그인 정보
(Google 또는 Kakao, 제공자가 발급한 서비스별 사용자 식별자·표시 이름·프로필 사진 URL, 로그인 세션의 SHA-256 해시)
같은 계정을 다시 알아보고 현재 계정을 표시하며 기기 사이 설정과 투표 기록을 동기화 계정을 삭제할 때 즉시 삭제. 세션은 기본 30일 후 만료. OAuth 액세스 토큰은 식별자 확인 뒤 저장하지 않음
계정에 연결한 개인 설정
(홈 대표 지수, 고정 종목 코드·이름·순서, 가격 기준 ±3%, 공시·소식 알림 여부)
기기 사이 대표 지수·고정 목록 동기화와 이용자가 직접 켠 알림 발송 이용자가 바꾸거나 계정을 삭제할 때까지. 매수·보유·관심의 의미를 구분하지 않으며 수량이나 거래 내역은 받지 않음

접속 로그는 웹서버가 동작하기 위해 남기는 기술적 기록입니다. Mulmit은 이 로그를 이용자 프로필을 만들거나 개인을 식별하는 용도로 사용하지 않습니다.

3. 브라우저에 저장되는 값

Google Analytics가 방문자를 구분하기 위해 쿠키(_ga로 시작하는 값)를 설정합니다. Mulmit은 선택 로그인 뒤에만 보안(HttpOnly) 세션 쿠키 하나를 설정하며 기본 30일 뒤 만료됩니다. 언어·테마·차트 기간 같은 화면 설정은 브라우저의 로컬 저장소(localStorage)에만 저장합니다. 로그인한 계정의 홈 대표 지수는 기기 사이 동기화를 위해 서버에 저장하며, 익명 방문 id는 방문 통계와 화면 이동 집계를 위해 서버에 전송됩니다.

브라우저의 사이트 데이터 삭제 기능으로 언제든 지울 수 있고, 지워도 서비스 이용에 지장이 없습니다. 지우면 다음 방문부터 새 id가 만들어지며 과거 방문 기록과 연결되지 않습니다. 계정의 투표 기록에는 영향이 없습니다.

4. 외부 서비스

로그인 뒤 계정 화면의 프로필 사진은 Google 또는 Kakao가 돌려준 주소에서 브라우저가 직접 불러옵니다. 이때 해당 제공자는 IP 주소와 브라우저 정보를 받을 수 있습니다. Mulmit은 사진 파일이 아닌 URL만 저장하고, 어느 Mulmit 화면인지 전달되지 않도록 referrerpolicy="no-referrer"를 사용합니다.

홈(/)과 미국·글로벌(/us) 화면의 S&P 500 종목 히트맵은 TradingView가 제공하는 공식 위젯입니다. 이 위젯은 이용자의 브라우저가 TradingView 서버에서 직접 불러오므로, 그 과정에서 TradingView가 이용자의 IP 주소, 접속한 페이지 주소, 브라우저 정보 등을 받게 됩니다. Mulmit 서버를 거치지 않는 직접 연결이며, Mulmit은 이 데이터를 받지도 저장하지도 않습니다.

해당 처리에는 TradingView의 정책이 적용됩니다. TradingView 정책을 확인하세요. 위젯을 원하지 않으면 브라우저 확장 프로그램이나 콘텐츠 차단 설정으로 막을 수 있으며, 그래도 나머지 화면은 정상 동작합니다.

홈(/) 화면의 뉴스 영상 목록에서 제목·채널명·게시시각은 Mulmit 서버가 제공하고, 미리보기 이미지(썸네일)는 이용자의 브라우저가 Google의 이미지 서버(i.ytimg.com)에서 직접 불러옵니다. 이 과정에서 Google은 이용자의 IP 주소를 받게 됩니다. 다만 이 서버는 쿠키를 설정하지 않으며(2026-08-23 확인), Mulmit은 어느 페이지를 보고 있는지 전달되지 않도록 referrerpolicy="no-referrer"를 지정합니다.

YouTube 플레이어는 이용자가 재생을 누른 그 순간에만 로드됩니다. 그때 YouTube가 IP 주소와 브라우저 정보를 받고 쿠키를 설정하며, 누르지 않으면 이 일은 일어나지 않습니다. 쿠키가 관여하는 지점은 썸네일이 아니라 재생입니다.

해당 처리에는 Google·YouTube의 정책이 적용됩니다. Google 개인정보처리방침YouTube 서비스 약관을 확인하세요. 영상의 내용은 각 채널이 게시한 것이며 Mulmit의 견해나 이 사이트의 수치와는 무관합니다.

Mulmit이 시장·공시 데이터를 받아오기 위해 외부 제공기관(예: 미국 증권거래위원회 EDGAR, Hyperliquid)에 요청을 보낼 때는 서버가 대신 요청합니다. 이때 전달되는 것은 서버의 정보이며 이용자의 IP나 브라우저 정보는 포함되지 않습니다.

5. 제3자 제공과 처리 위탁

Mulmit은 이용자의 개인정보를 제3자에게 판매하거나 제공하지 않습니다. 다만 서비스를 운영하기 위해 다음 인프라를 사용하며, 그 과정에서 접속 기록이 해당 사업자의 설비에 남을 수 있습니다.

6. 이용자의 권리와 데이터 삭제

물밑(Mulmit) 앱과 사이트가 보관하는 이용자 관련 데이터는 위 표와 같으며 다음 방법으로 삭제됩니다.

삭제 후에 남는 것은 개인과 연결되지 않는 집계 수치(일별 방문자 수, 경로별 조회수, 질문별 보기 인원수)뿐입니다. 로그인하지 않은 방문 기록은 특정 개인을 찾을 수 없는 익명 id에만 묶입니다. 로그인 계정 데이터와 투표 기록은 계정과 알림에서 직접 열람·정정·삭제할 수 있습니다. 문의나 요청이 있으면 아래 연락처로 알려 주세요. 처리 내용에 문제가 있다고 판단되면 개인정보 분쟁조정위원회(1833-6972), 개인정보침해 신고센터 (118) 등에 상담을 신청할 수 있습니다.

7. 아동의 개인정보

Mulmit은 만 14세 미만 아동을 대상으로 하지 않으며, 연령 정보를 포함해 어떤 개인정보도 수집하지 않습니다.

8. 방침 변경

광고 도입 등 처리 내용이 달라지면 이 문서를 먼저 개정하고 시행일을 바꿉니다. 특히 광고를 도입하면 광고 사업자가 쿠키나 식별자를 사용할 수 있으므로, 그 시점에 이 방침을 실제 동작에 맞게 다시 씁니다.

예고 — 광고 도입 예정. 운영비를 충당하기 위해 광고를 붙일 계획이며 현재 Google AdSense 심사를 받고 있습니다. 화면에 광고는 아직 표시되지 않습니다. 다만 심사를 받으려면 사이트가 AdSense 스크립트를 실어야 하므로, 지금 그 스크립트가 돌고 있고 쿠키나 식별자를 둘 수 있습니다 — 광고가 안 보여도 이 부분은 이미 사실이라 여기 적습니다. 광고가 실제로 실리는 날 이 문서를 다시 개정해 광고 사업자가 무엇을 두고 무엇을 읽는지, 어떻게 거부할 수 있는지를 적습니다. 이 문단은 그 개정 전에 미리 알리기 위한 것입니다 — 이 방침이 스스로 정한 순서가 먼저 적고 그다음에 바꾼다이기 때문입니다.

9. 연락처

개인정보 보호책임자: Mulmit 운영자
문의: admin@mulmit.com

Privacy Policy

Effective 2026-08-17 · Last revised 2026-09-20

Mulmit is a market-data dashboard anyone can read without signing in. Google or Kakao sign-in is required to pin markets, use alerts or vote, and no advertising today — though advertising is planned (section 8). Google Analytics is used to count visits. Rather than reciting boilerplate, this page describes only what the site actually does.

In short — optional sign-in stores a provider-specific Google or Kakao user id, display name and profile-image URL, a session hash, synced pins and alert settings, and votes. Mulmit does not request or store your email, phone number or payment details. The server also processes ordinary web access logs, one anonymous random id used to count visitors and aggregate screen journeys, and — only if you turn notifications on — your push subscription. Your browser keeps display preferences such as language and theme.

1. What is not collected

Starting with the absences. Mulmit does not collect or process:

2. What is actually processed

DataPurposeRetention
Access logs
(IP address, timestamp, request path, User-Agent, status code)
Running the service, diagnosing faults, spotting abusive traffic Kept only as server container logs. Never loaded into a database or combined with other data
IP address (rate limiting) Blocking excessive requests from one source Held in server memory only and never written to disk. Lost on restart
Ticker lookup counts Prioritising the symbols people actually search for in the next collection cycle A running count per symbol. Who searched is not recorded and is never linked to an IP or session
Words typed into the search box Deciding what to collect next when a symbol people look for is missing Only a running count grouped by date, term and whether anything matched. Who searched is not recorded and is never linked to an IP or session. Only Korean, Latin and numeric terms of three words or fewer are kept; anything else the server discards on arrival
Errors raised in the page
(error name, file, line number)
Finding pages that break in one browser after a deploy The error message body is never sent — it can contain what you were looking at. Only a daily running count is stored, with no record of who hit it
Browser window width bucket Knowing which screen sizes to design for A bucket (e.g. 360px or under), never the exact pixel value. A daily running count with no record of who uses which device
What you tap
(the words written on the button or link, the name of the area it sits in, the page path)
Telling which features are actually used, so the ones nobody touches can leave the screen Only a running count grouped by date, path, area and label. Who tapped is not recorded and is never linked to an IP or session. The label is text already printed on screen; only Korean, Latin, numeric and a few symbol characters, six words or fewer, are kept — anything else the server discards on arrival
Time spent on a page or section
(page path, section name, seconds)
Knowing which screens and which sections are actually read Counted only while the tab is in front and the window is visible. Only running totals grouped by date, path and section are stored, with no record of who stayed
Per-browser trail
(anonymous visitor id, time the page was opened, page path, seconds, taps, longest-viewed section)
Seeing the order in which one browser moves through the site — the evidence used when reworking a layout This is the one table kept per browser. Deleted automatically after 90 days. Tied only to the random anonymous id and never combined with names or IPs, so it identifies no one. It holds paths, times and seconds — never anything you typed or read. It is not public; only the operator can open it, with a separate key
Anonymous visitor id
(a random value your browser generates)
The live "viewing now" count, daily unique-visitor totals and the per-browser trail above Live-count rows delete themselves within an hour; daily-unique rows after 90 days. Never combined with names or IPs, so it identifies no one. Legacy one-time transfer codes for pre-sign-in records point only to this id and expire after 10 minutes
Answers picked in “Today's questions” and “Issues right now”
(question, option chosen, time, account id; issue identifier for issue votes)
One vote per account, the participant split, and your voting history across devices Deleted immediately with the account or automatically after one year. When a question closes, only the per-option counts are kept, linked to no one. Never combined with IPs. The options are opinions and interests — no question asks about holdings or portfolio size
Web push subscription
(endpoint URL, browser-generated encryption keys)
Delivering alerts you turned on yourself. Pinned-symbol alerts are linked to the account Deleted the moment you turn alerts off. Subscriptions that keep failing are removed automatically
Optional sign-in data
(Google or Kakao, provider-issued service-specific user id, display name, profile-image URL, SHA-256 hash of the login session)
Recognising and displaying the current account and syncing settings and voting history across devices Deleted immediately with the account. Sessions expire after 30 days by default. OAuth access tokens are not stored after resolving the identifier
Account-linked personal settings
(home index, pinned symbol, display name, order, ±3% price threshold, filing and update-alert choices)
Syncing the home index and pinned markets, and delivering alerts the user turns on Until you change them or delete the account. A pin is not treated as a holding; no quantity or trade history is collected

Access logs are the technical record a web server keeps in order to function. Mulmit does not use them to build profiles or to identify individuals.

3. Values stored in your browser

Google Analytics sets cookies (names beginning _ga) to tell visitors apart. Mulmit sets one secure, HttpOnly session cookie only after optional sign-in; it expires after 30 days by default. Language, theme and chart-period preferences stay in localStorage. A signed-in account's home-index choice is stored on the server so it can sync across devices; the anonymous visitor id is also sent for visit statistics and the per-browser trail.

Clearing site data in your browser removes them, and the site works normally afterwards. A fresh id is created on your next visit and is not linked to the old one. Your account voting record is unaffected.

4. Third-party services

After sign-in, your browser loads the account profile image directly from the URL returned by Google or Kakao. The provider can therefore receive your IP address and browser information. Mulmit stores only the URL, not the image file, and uses referrerpolicy="no-referrer" so the Mulmit page address is not sent.

The S&P 500 constituent heatmap on the home (/) and US & global (/us) pages is an official TradingView widget. Your browser loads it directly from TradingView, which means TradingView receives your IP address, the page URL and browser information in the process. That connection does not pass through Mulmit's server, and Mulmit neither receives nor stores this data.

TradingView's own terms govern that processing — see the TradingView policies. You can block the widget with a browser extension or content blocker; the rest of the page continues to work.

In the news videos list on the home page (/), the titles, channel names and publication times come from Mulmit's own server, while the preview images (thumbnails) are loaded by your browser directly from Google's image servers (i.ytimg.com). Google receives your IP address in the process. That server sets no cookies (verified 2026-08-23), and Mulmit specifies referrerpolicy="no-referrer" so the page you are viewing is not passed along.

The YouTube player itself loads only when you press play. At that moment YouTube receives your IP address and browser information and sets cookies; if you do not press play, none of that happens. Cookies enter at the play, not at the thumbnail.

Google's and YouTube's own policies govern that processing — see the Google Privacy Policy and the YouTube Terms of Service. The videos are published by their channels and represent neither Mulmit's views nor this site's figures.

When Mulmit fetches market and filing data from outside sources such as the U.S. Securities and Exchange Commission's EDGAR system or Hyperliquid, the server makes those requests. They carry the server's details, not your IP or browser information.

5. Sharing and processors

Mulmit does not sell or share personal data. It does rely on the following infrastructure to operate, and access records may exist on their systems:

6. Your rights and deleting your data

The Mulmit app and site keep only the data listed in the table above, and it is deleted as follows.

What remains afterwards are aggregate figures linked to no one — daily visitor counts, per-path totals and per-option counts for each question. Signed-out visitor records use only an anonymous id and cannot be looked up by person. Signed-in account data and votes can be viewed and deleted on Account and alerts. Questions are welcome at the contact below. If you believe the handling described here is inadequate, Korean users may contact the Personal Information Dispute Mediation Committee (1833-6972) or the privacy infringement report centre (118).

7. Children

Mulmit is not directed at children under 14 and collects no personal data, including age.

8. Changes

If what the site processes changes — for example by adding advertising — this document is revised first and its effective date updated. In particular, introducing advertising would let an ad provider set cookies or identifiers, so this policy will be rewritten to match reality at that point.

Notice — advertising is planned. Advertising is intended to cover running costs and the site is under Google AdSense review. No ads are displayed yet. Review requires the site to load the AdSense script, so that script is running now and may set cookies or identifiers — that part is already true even with no ads on screen, so it is written here. On the day ads actually appear this document will be revised again to say what the ad provider stores and reads, and how to refuse it. This paragraph exists to say so ahead of that revision — because the rule this policy sets for itself is write it down first, then change it.

9. Contact

Data protection contact: the Mulmit operator
Enquiries: admin@mulmit.com