Privacy Policy
천시록 (the “Company”) processes personal information provided by users while delivering the 천시록 service (the “Service”). The Company complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws and publishes this Policy to protect user information and address privacy concerns promptly.
1. Information we collect
The Company collects information when it is needed to provide and operate the Service reliably. Required information is necessary to use the relevant service; optional information may be withheld without limiting use.
1) Account registration and service operation
- Required: email, password stored in encrypted form, name, and date of birth
- Optional: gender
- Service records such as user identifier, access time, IP address, misuse records, and usage history, together with device information, operating system, model, language, and cookies, may be collected automatically.
2) AI Saju analysis
- Required: date of birth, gender, solar or lunar calendar, and birth time or an indication that the time is unknown
- Optional: name and concern keywords
3) Payment processing
- Payment-method and approval information is processed by Toss Payments. The Company stores only the payment key and order number required to manage the purchase.
- For a purchaser under 18, the Company stores the confirmation that a parent or legal guardian approved the purchase.
4) Customer support
- Required: email and inquiry details
The Service is available to users who are at least 13 years old. The Company does not knowingly collect or process personal information from anyone under 13.
2. Purposes
The Company uses collected personal information only for the following purposes.
- Identifying users and confirming their intent to use the Service
- Generating and providing AI Saju analysis results
- Processing payments and refunds and resolving disputes
- Responding to inquiries and improving the Service
- Preventing misuse, protecting accounts, and restricting violations of law or the Terms
3. Disclosure to third parties
The Company does not disclose personal information to third parties except in the following cases.
- An administrative or investigative authority lawfully requests disclosure under applicable law.
- The user has separately consented to disclosure.
4. Retention
Personal information is destroyed without delay when its collection and use purpose has been fulfilled. The following records are retained when required by Korean law.
| Record | Legal basis | Retention period |
|---|---|---|
| Access time and IP address | Protection of Communications Secrets Act, Article 15-2 | 3 months |
| Consumer complaints and dispute records | Electronic Commerce Act, Article 6 | 3 years |
| Contracts and cancellation records | Electronic Commerce Act, Article 6 | 5 years |
| Payment and supply records | Electronic Commerce Act, Article 6 | 5 years |
5. Destruction
Electronic files are destroyed so they cannot be restored, and paper records are shredded or incinerated.
6. Processors and international transfers
The Company engages the following processors to provide the Service.
1) Processing in Korea
| Processor | Purpose |
|---|---|
| Toss Payments | Payment processing and payment-data management |
2) Overseas processing and transfer
| Processor | Purpose | Country | Processing period |
|---|---|---|---|
| Supabase Inc. | Database operation and authentication | United States | Until account closure or termination of the processing agreement |
| OpenAI / Google | AI Saju analysis | United States | Processed only when the Service is used and not separately retained for this task |
| Vercel Inc. | Web hosting | United States | Until account closure or termination of the processing agreement |
7. Your rights
Users may refuse or restrict processing and may request access, correction, deletion, or transfer. Contact the privacy officer below by email for assistance.
- Users may view or update their personal information through My Account.
- Deletion may be requested through Settings or by email at controlsc@daum.net.
- The Company responds to an access request within ten days.
8. Safeguards
- Administrative safeguards: internal management plans, regular staff training, and processor oversight
- Technical safeguards: access controls, encryption, and security software
- Physical safeguards: controlled access to computer rooms and record-storage areas
9. Cookies
Cookies support personalized service and usage analysis. You may refuse cookies in your browser, but parts of the Service may not function correctly.
10. Privacy contact
- Privacy officer: 이성범
- Email: controlsc@daum.net
You may also contact the following independent Korean authorities about a privacy violation.
- Privacy Infringement Report Center (privacy.kisa.or.kr / 118)
- Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972)
- Supreme Prosecutors’ Office Cyber Investigation Division (www.spo.go.kr / 1301)
- Korean National Police Agency Cyber Bureau (ecrm.cyber.go.kr / 182)
11. Changes
Changes to this Policy are announced on the website at least seven days before taking effect. A material change to user rights is announced at least thirty days in advance.
Supplement
Effective date: August 27, 2026
