App Permissions
Effective 1 August 2026 · Applies to the Koroute and WellHour mobile apps
This page lists every device permission the Koroute and WellHour apps request. For each one it states which feature uses it, what changes if you decline, and whether anything obtained through it is sent to our servers.
Principles
- Permissions are requested when you first use the feature that needs them, not all at once on first launch.
- Every permission is optional. The app runs if you decline; only that feature becomes unavailable.
- You can revoke any permission at any time in your device settings.
- Anything sent to our servers is named in the tables below. Anything not named stays on your device.
Koroute
Travel route recommendations. App identifier: place.moa.koroute.
| Permission | Requested when | Why it is needed | If you decline | Sent to our servers |
|---|---|---|---|---|
| Location — while using the app | Showing your position on the map, or finding routes nearby | To suggest journeys near you and to calculate a route from where you are without your having to type a starting point. | Nearby suggestions and the “my position” marker stop working. Search for a starting point instead and everything else behaves the same. | Coordinates are sent only while a route is being calculated and are not stored. Routes you choose to save are kept with your account. |
| Photo library | Setting a profile picture | To use the one photo you pick as your profile image. | You cannot change your profile picture. The default image is used; nothing else is affected. | Only the single photo you select and confirm. The app does not browse or read any other photo. |
| Notifications | Turning notifications on | To send reminders for saved journeys and service announcements. | You receive no notifications. The same information appears in the app when you open it. | A device notification token. It is used for nothing but delivering notifications. |
Opening other map apps
When you start navigation, Koroute can hand over to KakaoMap, Naver Map, T map or Google Maps. To offer only the apps you actually have, it checks whether each is installed (on iOS, via LSApplicationQueriesSchemes). This is a presence check, not a permission; it reads no data from those apps, and the result never leaves your device.
WellHour
Wellness recommendations and booking. App identifier: place.moa.wellhour.
| Permission | Requested when | Why it is needed | If you decline | Sent to our servers |
|---|---|---|---|---|
| Location — while using the app | Searching for venues near you | To order nearby venues by distance from where you are. | Choose an area manually instead. Booking and everything else behaves the same. | Coordinates are sent only while a nearby search runs and are not stored. |
Why signing in opens a browser
Both apps open your device browser to sign in rather than showing their own password field. That way your password goes straight to id.moa.place without passing through the app, and your saved passkeys and password manager work normally. This is a sign-in method, not a permission.
Permissions we never request
Neither app uses or asks for any of the following. If you are ever prompted for one, the build may not be a genuine release — please tell us at contact@moaplace.com.
- Camera
- Microphone
- Contacts, call logs, SMS
- Calendar
- Health and fitness data
- Background location (your position while the app is not in use)
- Full access to files on your device
Neither app collects an advertising identifier or bundles any third-party advertising or tracking SDK.
Changing permissions
- iOS / iPadOS
- Settings → Privacy & Security → the permission (for example Location Services) → choose the app. You can also select the app directly in the Settings list.
- Android
- Settings → Apps → choose the app → Permissions. Menu names vary by manufacturer.
Revoking a permission stops only that feature; your account and saved content are untouched. To delete the account itself, use id.moa.place/account.
How the data is handled
Anything marked “sent to our servers” above is processed under the Privacy Policy, which covers retention, disclosure to third parties, deletion, and how to request access or erasure.
Location coordinates are used only for the duration of the request and are not stored separately. Routes and bookings you save are kept with your account and are deleted when you close it.