Privacy Policy
Last updated: 2026-07-06
The company processes users’ personal data in accordance with applicable law (PIPA, GDPR, APPI, CCPA, etc.).
Personal Data Collected and Purposes of Use
The company collects and uses the minimum personal data necessary to provide the Service as set out below, and destroys it without delay once the purpose of processing has been achieved. However, where relevant laws require retention for a certain period, such data is retained for the applicable period in accordance with “Retention and Use Period of Personal Data” below.
- Account information: email address and authentication credentials. Purpose of use = registration and identification, login and account management, responding to customer inquiries, and retaining transaction records as required by law.
- Game usage information: case play records, interrogation sessions and progress state, and usage history. Purpose of use = providing the Service, saving and restoring progress state, and improving content.
- Payment information: order details, payment status, and payment key. Purpose of use = processing purchases of paid content, granting entitlements, and handling withdrawal of subscription and refunds. The company does not store detailed payment-method information such as credit card numbers; such information is processed by the payment gateway or the Merchant of Record.
- Automatically generated and analytical information: access logs, device and browser information, cookies and similar identifiers, and service usage statistics. Purpose of use = operating and securing the Service, and usage analytics (Google Analytics). Of these, information for analytics is collected only where the user has given consent.
The company’s Service is not directed to children under the age of 14, and the company does not collect personal data from children below that age. If the company becomes aware that a child’s personal data has been collected without the consent of a legal guardian, it destroys such data without delay.
Retention and Use Period of Personal Data
As a rule, the company destroys users’ personal data without delay once the purpose of collection and use has been achieved. However, where relevant laws require retention for a certain period, the company retains it for the applicable period as follows.
- Records on contracts or withdrawal of subscription, etc.
- 5 years (Article 6(3) of the Act on Consumer Protection in Electronic Commerce (전자상거래 등에서의 소비자보호에 관한 법률) and its Enforcement Decree)
- Records on payment and the supply of goods, etc.
- 5 years (Article 6(3) of the Act on Consumer Protection in Electronic Commerce and its Enforcement Decree)
- Records on consumer complaints or dispute resolution
- 3 years (Article 6(3) of the Act on Consumer Protection in Electronic Commerce and its Enforcement Decree)
- Account information (email, authentication credentials, etc.)
- Destroyed without delay upon membership withdrawal. However, the email address of a withdrawn member is retained separately for 5 years in accordance with the item below, and other information subject to the statutory retention obligations above is retained for the applicable retention period.
- Minimum identifying information of withdrawn members (email address)
- 5 years from the date of membership withdrawal. Retained separately from other personal data in order to identify the parties to transaction records under Article 6 of the Act on Consumer Protection in Electronic Commerce and to preserve evidence of consent.
Provision of Personal Data to Third Parties
The company does not use users’ personal data beyond the scope of the purposes of use set out in this Policy, nor provide it to third parties without the user’s consent. However, pursuant to Articles 17 and 18 of the Personal Information Protection Act (PIPA), the company may provide personal data where: (i) the user has given prior consent; (ii) there are special provisions in law or it is unavoidable in order to comply with a legal obligation; or (iii) there is a lawful request from a competent authority in accordance with the procedures and methods prescribed by law for the purpose of investigation, trial, and the like.
Where the company provides personal data to a third party, it informs the user of the recipient, the purpose of provision, the items provided, and the retention and use period. The entrustment of personal data processing for purposes such as paid-content payment, hosting, and usage analytics is distinct from provision to third parties, and its content is governed by ‘Entrustment of Personal Data Processing’ below.
Entrustment of Personal Data Processing
To provide the Service smoothly, the company entrusts personal data processing tasks as set out below. When entering into an entrustment contract, the company stipulates the matters necessary to ensure that personal data is managed safely and supervises the trustee, in accordance with Article 26 of the Personal Information Protection Act (PIPA). The table below also identifies the recipients that receive information based on the user’s consent, together with their roles.
- Toss Payments Corporation (Republic of Korea)
- Authorization and capture of domestic payments and processing of payment cancellations and refunds (electronic payment gateway).
- Anthropic PBC (United States)
- Processing for the generation of case content.
- OpenAI, L.L.C. (United States)
- Processing for speech-to-text transcription of voice input.
- Supabase Inc. and Railway Corporation (United States, etc.)
- Database and server hosting, and infrastructure operation.
- Google LLC (United States)
- Service usage statistics analysis (Google Analytics). Processed only where the user has given consent.
With respect to the transfer of personal data to any of the trustees or recipients above that are located overseas, see ‘Overseas Transfer of Personal Data’ below.
Overseas Transfer of Personal Data
For the entrustment of processing and the operation of the Service above, the company may transfer users’ personal data overseas, including to the United States. The company carries out overseas transfers in accordance with Article 28-8 of the Personal Information Protection Act (PIPA), and enters into and applies appropriate safeguards such as Standard Contractual Clauses (SCC) with the transferee. Users may refuse the overseas transfer of their personal data, in which case the use of the relevant Service may be restricted.
- Transferee and country of transfer: the trustees and recipients listed in ‘Entrustment of Personal Data Processing’ above and the countries in which they are located (the United States, etc.).
- Purpose and items of transfer: the minimum personal data necessary to perform each entrustment or receipt purpose. In the case of transfers for usage analytics, only identifiers hashed with SHA-256 or the like, which cannot directly identify the user, are transferred.
- Date and method of transfer: transferred over the information and communications network at the time of Service use.
- Personal data protection regime and safeguards in the country of transfer: contractual safeguards such as Standard Contractual Clauses are applied with the transferee, and information on the level of personal data protection in the country of transfer and the safeguards implemented by the transferee is provided upon the user’s request.
Procedures and Methods for Destruction of Personal Data
In accordance with Article 21 of the Personal Information Protection Act (PIPA), the company destroys the relevant personal data without delay once the purpose of collection and use has been achieved or the retention and use period has elapsed, except where it must be retained under relevant laws.
Personal data stored in electronic file form is permanently deleted using technical methods that make recovery impossible, and personal data recorded and stored on paper documents is shredded or incinerated. Personal data retained under law is stored and managed in a database separate from other personal data, is not used for any purpose other than the purpose of retention, and once the retention period has elapsed it is destroyed without delay by the methods described above.
Measures to Ensure the Safety of Personal Data
In accordance with Article 29 of the Personal Information Protection Act (PIPA), the company takes the following measures to ensure safety so that users’ personal data is not lost, stolen, leaked, forged, altered, or damaged.
- Administrative measures: the company limits personal data handlers to the minimum necessary, and establishes and implements an internal management plan and provides regular training to handlers.
- Access control: access rights to the personal data processing system are granted differentially according to business need under the principle of least privilege, and access control devices are installed and operated to block unauthorized external access.
- Encryption: authentication credentials such as passwords and other important information are encrypted for storage and transmission.
- Retention and inspection of access records: access records of the personal data processing system are retained, and measures are taken to prevent their forgery, alteration, theft, or loss.
Cookies and Advertising Identifiers
The company uses cookies and similar advertising identifiers to provide users with customized services and to analyze service use. Except for essential cookies that are strictly necessary to provide the Service, non-essential cookies for analytics and advertising purposes are used only where the user has given prior consent.
Users may withdraw consent at any time, and may withdraw their consent to non-essential cookies via the button below. Users may also refuse the storage of cookies through their web browser settings. Once 180 days have elapsed from the date on which the company confirms the user’s consent, or 30 days from the date on which it confirms the user’s refusal, the company requests consent again regarding the use of non-essential cookies.
Rights and Obligations of Data Subjects and How to Exercise Them
Users (data subjects) and their legal guardians may at any time request the company to access, correct, delete, or suspend the processing of their personal data, and to have their personal data ported (transmitted). However, except as otherwise provided by applicable laws — that is, where another statute expressly designates such personal data as subject to collection or imposes an obligation to retain it for a certain period — the company may refuse a request for deletion or suspension of processing, in which case the company notifies the user of the grounds without delay.
Rights may be exercised through the account settings within the Service or through customer inquiry (email); for legitimate requests, the company takes the necessary measures within 10 days of receipt and notifies the user of the result. Users may withdraw their consent to the processing of personal data at any time, and such withdrawal of consent may restrict the use of services provided on the premise of that consent.
Personal Data Protection Officer
In accordance with Article 31 of the Personal Information Protection Act (PIPA), the company designates a Personal Data Protection Officer to protect users’ personal data and to handle users’ inquiries and complaints relating to personal data, as follows.
- Name and title
- Max Jeong (Representative)
- Contact
- tnalsl1984@naver.com (customer inquiry)
Remedies for Infringement of Rights
To obtain relief or counseling for damage caused by the infringement of personal data, users may apply to the following organizations. The organizations below are separate from the company; users may contact them if they are not satisfied with the company’s own handling of personal data complaints and damage relief, or if they need more detailed assistance.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
- Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
- Supreme Prosecutors’ Office Cyber Investigation Division: 1301 (no area code) / www.spo.go.kr
- National Police Agency Cyber Investigation Bureau: 182 (no area code) / ecrm.police.go.kr
Jurisdiction-Specific Notices
Changes to This Privacy Policy
The company may amend this Privacy Policy in response to changes in law or the Service, or changes in policy for the protection of personal data.
Where this Policy is amended, the company announces the details of the amendment and its effective date through the Service’s initial screen or the notices section from 7 days before the effective date (30 days before, in the case of a material change that is unfavorable to users). The amended Policy takes effect from the announced effective date.