Effective: July 19, 2026 (enacted July 16, 2026; research use, processors and retention clarified)
On sign-up: name (nickname) and email address — provided by your Google/GitHub account, or collected directly for email sign-up.
During use: audited URLs and results, evaluator judgments/notes, report details (site name, evaluator, etc.), and inquiry contents.
For service protection: sign-in records (including IP address) and server error logs.
Cookies: authentication cookies for session management only — no advertising or tracking cookies.
Identifying members and providing the service (audit history and reports), resource management such as quotas, responding to inquiries, sending service notification emails such as scheduled audit results (opt-out per domain), and non-identifying statistics for service improvement.
Audit target URLs and results may be processed into aggregate statistics that cannot identify any user or account, and used for academic research and policy proposals. Identifying elements such as domains are removed or generalized into categories.
Personal data is deleted without delay upon account deletion, together with service data such as audit results. Data required by law is stored separately for the mandated period, then destroyed.
Sign-in records collected for security (including IP addresses) and server error logs are kept for 90 days and then deleted automatically.
We entrust processing to: Supabase (database, authentication, file storage), Vercel (hosting, audit execution), Cloudflare (abuse-prevention checks at sign-up/sign-in), and Resend (notification emails), each under their own security standards. Their servers may be located outside Korea.
We do not provide or sell personal data to third parties except as required by law.
You can view and edit your information on My Page at any time, and request deletion by deleting your account.
Privacy inquiries: isaaceryn@gmail.com or the in-service support page.