Privacy Policy
Last updated: 2026-02-17
1. Data We Process
- Account data: email, user ID, authentication status
- Service usage data: selected region, inputs, risk scores, usage records
- Billing data: subscription/order status provided by Polar (Merchant of Record)
- Technical and security data: IP metadata, access logs, error logs
- Full payment card number and CVV are not stored in our systems.
2. Purposes and Legal Bases
- Contract performance: account operation and paid feature delivery
- Legitimate interests: service quality improvement, abuse prevention, security
- Legal obligations: tax/accounting, dispute handling, audit response
- Consent-based processing: optional communications where consent is required
3. Processors and Sharing
- Supabase: authentication and database infrastructure
- Cloudflare Pages/Edge: hosting and edge runtime
- OpenAI: AI text generation for eligible features
- Polar: billing and refund processing as Merchant of Record
- Google Analytics and Microsoft Clarity: optional analytics only after user consent, used for product improvement
- We do not sell personal information for monetary consideration.
4. International Transfers
- Personal data may be processed outside your country to provide the Service.
- Where required, we apply transfer safeguards such as contractual protections.
5. Retention Periods
- Account/profile data: for the account lifetime and up to 30 days after deletion request
- Analytics records: up to 24 months unless earlier deleted by user request
- Security/access logs: up to 180 days
- Billing/invoice records: up to 5 years or longer if required by tax/accounting laws
6. Your Rights
- Depending on local law (including GDPR/UK GDPR/CCPA-CPRA), you may request access, correction, deletion, portability, restriction, objection, and consent withdrawal.
- Requests are processed after identity verification and abuse checks.
- Standard response target is within 30 days unless local law requires a shorter period.
- You may lodge a complaint with your local supervisory authority.
7. Cookies and Local Storage
- We use required storage technologies (including local storage) for login/session continuity and core functions.
- Optional analytics cookies/scripts are activated only when you provide consent.
- You can refuse or later withdraw analytics consent from the cookie banner state on this site.
8. Contact
- Privacy inquiries: [email protected]
- Operator: 조현우 (Republic of Korea)
- Rights-infringement and content takedown requests can be submitted via the community report channel.