ONGSOOLABS
한국어

PRIVACY POLICY

Privacy policy

Controller and effective date

The controller is OngsooLabs, represented by Seungsoo Lee, with a business address of 401-33, 9, Bucheon-ro 29beon-gil, Wonmi-gu, Bucheon-si, Gyeonggi-do, Republic of Korea, and this policy takes effect on 2026-08-30.

General and business inquiries can be sent to contact@ongsoolabs.com.

Information we process

  • Google or GitHub provider identifiers and email when supplied
  • Nickname, Workspace name, and optional country, discovery source, use case, and LLM information
  • Document version and acceptance time for terms, privacy, and optional marketing consent
  • API-key issuance, status, and revocation information and service usage and credit-processing records
  • Billing orders, transaction identifiers, and payment, refund, chargeback, or reconciliation status
  • Security, audit, and operational records and minimum information supplied in support requests
  • The sign-in session cookie and authentication metadata needed to create, renew, and end the session
  • The connection IP address processed in real time for abuse prevention and minimum access metadata such as request time, route, and status

URL and API request data

Reader fetches the public HTTPS URL or supported document specified by the user to produce a result. We may process minimum request information such as the connection IP address, route, status, and processing time to provide and secure the service, prevent abuse, and respond to incidents. Normal operational records are designed not to retain URL query strings, page bodies, HTML, result content, API keys, OAuth tokens, cookies, payment data, or email.

Summary provider data

The title, extracted page body, and detected language from a URL submitted to Summary are sent to OpenAI to generate a summary and keywords. OpenAI states that API inputs and outputs may be retained for up to 30 days for abuse prevention, and the actual country or region of this processing has not been confirmed. Do not use Summary if you do not want content processed by OpenAI.

Required cookie and access information

We use required cookies for sign-in, account protection, and anonymous Playground credit limits. Blocking required cookies prevents the related features from working. When available, anonymous Playground creates its protected functional cookie after the first accepted execution and retains it for up to one year. We also use this identifier for the limited result and sign-up measurement described below. We do not use advertising cookies or follow browsing on other sites. Paddle checkout may use cookies or similar technologies described in Paddle's notices.

For security and service operations, we may process minimum access information such as the connection IP address, request time, method, route, status, and device or browser information. Access records are generally retained for up to 30 days and may be retained separately to the extent necessary for a security investigation or legal obligation.

Anonymous Playground and optional result feedback

When anonymous Playground is available, we keep a pseudonymous identifier, credit balance and minimum request, outcome and settlement records for up to one year from first use to enforce the initial allowance. Daily keyed IP hashes used to limit new identifiers are removed after 48 hours. We do not store the original IP, input URL or result body in these records.

Optional Reader feedback records your positive or negative choice, selected reasons, an optional problem description and minimum result details. You can update feedback for your result. Feedback and result display/copy records expire 30 days after the result; editing does not extend that period. We retain daily totals without identifiers after deletion. When material collection is available, separate consent before a run allows us to temporarily store that run’s HTML, result, URLs, execution options and processing version for one hour. If you attach the material to negative feedback, we retain it for 30 days from the run to investigate problems and improve Reader. Only authorized operators can access it. You can withdraw shared material from the result page without removing your rating. You can use Reader and leave feedback without agreeing to collection. Do not submit personal information, secrets or material you do not have permission to share. Expired or withdrawn material is immediately made inaccessible and deleted by a cleanup task that runs every 15 minutes. Storage failures are retried; S3 Lifecycle provides backup cleanup. Material is not automatically used for ML training or public datasets.

If you explicitly select the sign-up link below an anonymous result and create a new account in the same browser within seven days, we link that trial to the new account for up to 30 days. We measure its first completed member use and Live purchase within seven days after sign-up. Existing sign-ins, reactivated accounts and Sandbox purchases do not count. We keep daily totals after removing the link. This measurement helps assess the trial and is separate from general page-view totals.

Purposes

  • Account authentication, Workspace and API-key management, and delivery of Reader and Summary services
  • Usage calculation, order fulfillment, and refund, chargeback, or dispute reconciliation
  • Security, abuse prevention, incident investigation, audit, and legal obligations
  • Support requested by customers and product updates where optional consent was given

External providers and international processing

Google and GitHub provide external sign-in, OpenAI generates Summary results, Paddle handles buyer transactions and payments, AWS provides service infrastructure, and Google Workspace handles support email. Paddle is an independent controller for buyer transactions. OngsooLabs does not directly collect or store card numbers.

  • Google OAuth: when you sign in, your sign-in identifier, supplied email, and temporary authentication information are transferred over encrypted connections to Google and its subprocessors. Processing may occur on Google's global infrastructure, so the exact country may vary. OngsooLabs does not retain sign-in tokens permanently, and Google applies its own retention policy. If you refuse the transfer, you cannot use Google sign-in.
  • GitHub OAuth: when you sign in, your GitHub user identifier, supplied email, and temporary authentication information are transferred over encrypted connections to GitHub and its subprocessors. Processing may occur on global infrastructure, so the exact country may vary. OngsooLabs does not retain sign-in tokens permanently, and GitHub applies its own retention policy. If you refuse the transfer, you cannot use GitHub sign-in; if you refuse both sign-in providers, registration and Dashboard use are unavailable.
  • OpenAI: when you request Summary, the title, body, and detected language extracted from the public page are transferred over encrypted connections to OpenAI and its subprocessors. The purpose is to generate a summary and keywords, and the actual processing country has not been confirmed. OpenAI may retain abuse-prevention records for up to 30 days. If you refuse the transfer, you cannot use Summary.
  • Paddle: when you request a purchase, refund, or dispute handling, billing information such as name, email, country, and postal code, transaction, product, tax, payment, and refund status, and fraud-prevention information are transferred over encrypted connections to Paddle and its payment, tax, and fraud-prevention subprocessors. Processing may occur in the United Kingdom, Ireland, the United States, and other countries and is not confined to one country. Paddle applies its own legal and retention obligations. If you refuse the transfer, purchases, receipts, tax, and refunds through Paddle are unavailable.
  • AWS: while you use the service, account, usage, order, operational, and backup information is transferred over encrypted connections to AWS and its subprocessors. The purposes are hosting, data storage, security, operations, and backup, and processing occurs in US East and South Korea. Retention follows the periods below and applicable law. If you refuse the transfer, we cannot provide accounts, the Dashboard, API, or order fulfillment with the current infrastructure.
  • Google Workspace: when you send a support or privacy request, sender and recipient addresses, inquiry content and attachments, transmission metadata, and verification information you provide are transferred over encrypted connections to Google and its subprocessors. Processing may occur on Google's global infrastructure, so the exact country may vary. Retention follows the support-email period below and Google's applicable retention policy. If you refuse the transfer, email-based support and privacy requests are unavailable.

Retention and destruction

Quality and operational records
Generally retained for 30 days, then deleted.
URL submitted for support investigation
Kept only when explicitly submitted by the customer, in the operator-only support mailbox for at most seven days, and deleted sooner when the investigation ends.
Account and profile
Retained while the account is active and for up to 30 days after closure. We then delete email, nickname, and optional profile fields, and process legally retained transaction records so they are no longer directly linked to the account.
Terms and privacy consent records
Retained for five years from the last consent or account closure, then deleted or retained only as aggregates with identifying information removed.
API-key information
Retained while active and for one year after revocation or account closure. The original API key is shown only once when created, and information needed for verification and management is deleted at the end of the period.
Usage and credit records
Paid usage is retained for five years and free evaluation usage for one year; then account-linking information is deleted or de-identified and only non-identifying aggregates are retained.
Order, refund, and chargeback records
Retained for five years, then transaction and account-link data are deleted. Transaction data independently retained by Paddle follows Paddle's retention and deletion process.
Audit logs
General security and account audit data is retained for one year; commerce-related audit data for five years. We then delete it or retain only statistics with identifiers removed.
Support email
General inquiries are retained for one year after closure and consumer-complaint or dispute emails for three years, then deleted from Google Workspace.
Service access records
Retained for up to 30 days under our operating standard. Minimum records retained separately for a security investigation or legal obligation are deleted when that purpose ends.
Service data backups
Automated backups are retained for seven days. Manual and final backups are retained for up to 30 days after their purpose ends, then deleted.

Account closure stops access and new API use but does not immediately delete stored personal information. When the retention purpose and applicable legal obligation end, information is deleted in a manner intended to prevent recovery or is de-identified.

Rights and safeguards

Subject to applicable law, users may request access, correction, deletion, restriction of processing, or withdrawal of consent. We may require identity verification when needed to process a request. If a request is restricted or refused under applicable law, we explain the reason and how to object. OngsooLabs applies technical and organizational safeguards including access management, encryption in transit, separation of secrets, audit records, periodic reviews, and retention limits.

Privacy contact and changes

Privacy requests and questions can be sent to support@ongsoolabs.com or +82 70-8080-1893. When this policy changes, we publish a new version and effective date. Account closure stops access and is separate from a personal-information deletion request. Both requests and general support are available on the Support page.