Privacy Policy
Effective: 2026-07-10 · v1.0
1. Data We Collect and Why
| Data | Purpose | Retention |
|---|---|---|
| E-mail, display name, password (one-way hashed) | Account creation, authentication, notices | Until account deletion |
| Sign-up verification records (attempts, timestamps) | Identity verification, abuse prevention | Purged after verification or expiry |
| Quota ledger (deductions, grants, file hashes) | Billing, duplicate-import dedup, dispute handling | Statutory retention after account deletion |
| Payment records (order ID, amount, status) | Payment processing, refunds, statutory bookkeeping | 5 years (Korean e-commerce law) |
| Uploaded analysis data (temporary files) | Performing the analyses you request | Until you delete them or periodic operational cleanup |
2. How Processing Works
- Local processing: emotion inference and Korean translation run entirely on the Service's own server; your text is never sent to external AI APIs (e.g., OpenAI, Google Translate).
- No card storage: payments are handled by Toss Payments; the Service does not collect or store card numbers.
- Passwords are stored only as irreversible hashes.
3. Third Parties and Processors
We do not sell or share personal data. Limited data is passed to processors only as needed: Toss Payments (order details) and Google Gmail SMTP (recipient e-mail addresses for service mail).
4. Cross-Border Transfers
To provide the Service, limited personal data is processed by overseas providers as commissioned processing for service delivery (Personal Information Protection Act, Art. 28-8(1)(iii)):
| Recipient | Country | Purpose | Data | Retention |
|---|---|---|---|---|
| Google LLC | United States | E-mail delivery (SMTP) | E-mail address, message content | Per Google's policies after delivery |
| Cloudflare, Inc. | United States | Service delivery (network transit, security) | Connection IP, request data | Transit processing (not stored separately) |
You may object to these transfers, but doing so may limit use of the Service (e.g., e-mail verification). Contact: [email protected]
5. Destruction of Personal Data
Personal data is destroyed without delay once its purpose is fulfilled. Electronic files are deleted irrecoverably; printed materials are shredded or incinerated. Data that must be retained under applicable law is stored separately from other personal data and destroyed without delay once the statutory retention period expires. Upon account deletion, your e-mail, display name and password are destroyed immediately (irreversibly anonymized); only records subject to statutory retention (e.g., payment records) are kept for the required period.
6. Your Rights
You may request access, correction or deletion (account closure) at any time. Account deletion is available directly on the My Account page, and uploaded analysis files can be deleted from the analysis pages. Contact: [email protected]
7. Security Measures
Password hashing, admin-privilege separation, access logging, request rate limiting, and fail-closed production configuration.
8. Data Protection Officer
Jungho Suh ([email protected])