Tiro: perfectly crafted meeting notes

Privacy Policy

Privacy Policy

Effective Date: September 7, 2026

Last Revised: September 7, 2026

ThePlato Inc. ("Company") respects the freedom and rights of users and complies with the Personal Information Protection Act of Korea and all other applicable data protection laws. We are committed to processing personal information in a transparent and secure manner. In accordance with Article 30 of the Personal Information Protection Act, the Company has established this Privacy Policy to inform users (data subjects) of how their personal information is handled and to address any related grievances promptly and effectively.

I. Purpose of Collection, Items Collected, and Retention Period of Personal Information

The Company collects and uses the minimum personal information necessary to provide the Service, and does not use personal data for purposes beyond those stated. If the purposes for processing personal information change, the Company will obtain the user's consent in advance as required by Article 18 of the Personal Information Protection Act.

1. Personal Information Collected with User Consent

The Company processes the following personal information based on user consent:

Purpose of CollectionItems CollectedRetention and Use PeriodLegal Basis
Account registration and Service useRequired: Email address, SNS account integration (Apple/Google), name, contact information Optional: User ID, password, date of birth, gender, profile photoUntil membership withdrawal or as required by applicable lawPersonal Information Protection Act Article 15(1)(1)
Service usage records managementAccess logs, access IP, service usage and suspension records, cookies3 months (Communications Privacy Protection Act) or until membership withdrawalPersonal Information Protection Act Article 15(1)(1)
Device information-based optimizationMAC address, browser information, device model, OS, advertising ID, etc.Until membership withdrawalPersonal Information Protection Act Article 15(1)(1)
External service integration (optional)Google Calendar events, Notion documents, Slack messages, Confluence information, etc.Until integration is removed or membership withdrawalPersonal Information Protection Act Article 15(1)(1)

Important Notice Regarding Sensitive Content: During service provision, the Company may process content containing sensitive information such as voice recordings, video, and system sound that users directly upload or input.

The Company does not use such information for AI training, model improvement, marketing, or any other secondary purposes whatsoever. Except when specifically requested by users through customer service, the Company does not manually review or access such files.

Additionally, voice data is immediately and irreversibly destroyed after processing, and all conversation records and related content are encrypted with AES-256 using individual keys for each user.

Users are responsible for obtaining necessary consent in accordance with relevant laws when uploading files or using recording features that contain sensitive information such as others' voices or meeting content.

2. Information Retained as Required by Law

Data TypeRetention PeriodLegal Basis
Contract, cancellation, payment, and goods supply records5 yearsAct on Consumer Protection in Electronic Commerce, etc.
Consumer complaint and dispute resolution records3 yearsSame as above
Advertisement and labeling records6 monthsSame as above
Access logs (IP, etc.)3 monthsCommunications Privacy Protection Act Article 15-2

II. Provision of Personal Information to Third Parties

The Company does not provide personal information to third parties in principle. However, exceptions may be made in the following cases:

  1. When separate consent from the data subject has been obtained
  2. When provision is required by law
  3. When there is imminent danger to the life, body, or property of the data subject or third parties

The Company is not providing personal information to third parties. Should provision become necessary in the future, the Company will notify data subjects in advance and obtain consent.

III. Outsourcing of Personal Information Processing

The Company outsources personal information processing tasks to external parties for service provision.

Entrusted ProcessorOutsourced Task
Amazon Web Services, Inc.Server operation and storage, encryption key management (KMS) — Seoul region (ap-northeast-2), Republic of Korea
Microsoft Corporation (Azure OpenAI Service)Language-model inference for summaries and documents — processed in the Korea Central region
Google LLCLanguage-model inference (Vertex AI); statistical analysis (Google Analytics, Firebase)
OpenAI OpCo, LLCLanguage-model inference
AssemblyAI, Inc.Speech-to-text conversion
ElevenLabs Inc.Speech-to-text conversion
Soniox Inc.Speech-to-text conversion
Deepgram, Inc.Speech-to-text conversion (fallback route)
NAVER Cloud Corp.Speech-to-text conversion (CLOVA Speech) — processed in the Republic of Korea
Twilio Inc. (SendGrid)Sign-up verification and notification email delivery
Datadog, Inc.System log and performance monitoring
Functional Software, Inc. (Sentry)Application error tracking
PostHog, Inc.Product usage statistics
AppsFlyer Ltd.Mobile app acquisition channel analysis
WorkOS, Inc.Enterprise single sign-on (organizations using SSO only)
Channel CorporationCustomer support chat (Channel Talk) — processed in the Republic of Korea
Stripe, Inc.Payment service provision
Chequer, Inc. (QueryPie)Database access auditing and log management

When contracting with processors, the Company clearly specifies management and supervision of processors, restrictions on re-outsourcing, and technical protection measure obligations in accordance with Article 26 of the Personal Information Protection Act, and periodically inspects whether processors handle personal information securely.

IV. International Transfer of Personal Information

Meeting content (audio, transcripts, notes and documents) and account data are stored in the AWS Seoul region (ap-northeast-2) in the Republic of Korea and are not transferred overseas for storage. For service operation, the Company transfers the following limited categories of personal information overseas. Transfers occur automatically over TLS-encrypted connections at the time of service use.

ProcessorCountryTransfer Time and MethodContactItemsPurposeRetention Period
Google LLCUnited StatesAutomatic transmission via encrypted connection during service usegooglekrsupport@google.comMeeting transcript text (language-model inference); usage records and device information (statistical analysis)Summary generation and other service provision; statistical analysisInference input/output not retained; statistical data until entrustment contract termination
OpenAI OpCo, LLCUnited StatesAutomatic transmission via encrypted connection during service useprivacy@openai.comMeeting transcript textLanguage-model inference for service provisionNot retained (zero data retention)
AssemblyAI, Inc.United StatesAutomatic transmission via encrypted connection during service usesupport@assemblyai.comMeeting audio (streamed), transcript textSpeech-to-text conversionNot retained (deleted immediately after conversion)
ElevenLabs Inc.United StatesAutomatic transmission via encrypted connection during service useelevenlabs.io/privacy-policyMeeting audio, transcript textSpeech-to-text conversionNot retained (deleted immediately after conversion)
Soniox Inc.United StatesAutomatic transmission via encrypted connection during service usesoniox.com/policies/privacy-policyMeeting audio (streamed), transcript textSpeech-to-text conversionNot retained (zero retention by default)
Deepgram, Inc.United StatesAutomatic transmission via encrypted connection during service use (fallback route)deepgram.com/privacyMeeting audio, transcript textSpeech-to-text conversion (fallback route)Not retained (deleted immediately after conversion)
Twilio Inc. (SendGrid)United StatesAutomatic transmission via encrypted connection when an email is senttwilio.com/en-us/legalEmail address, name, delivery historySign-up verification and notification email deliveryDelivery history 30 days
Datadog, Inc.United StatesAutomatic transmission via encrypted connection during service usedatadoghq.com/legalAccess logs, IP address, internal identifiers, error logs (no meeting content)System monitoring and incident response15 days
Functional Software, Inc. (Sentry)United StatesAutomatic transmission via encrypted connection during service usesentry.io/legalInternal identifiers, IP address, device and browser information, error logs (no meeting content)Application error tracking90 days
PostHog, Inc.United StatesAutomatic transmission via encrypted connection during service useposthog.com/privacyPseudonymous identifiers, device information, usage events (no meeting content)Product usage statisticsDeleted upon expiry of the retention period
AppsFlyer Ltd.IsraelAutomatic transmission via encrypted connection when the mobile app is installed or usedappsflyer.com/legal/privacy-policyDevice information, advertising identifierMobile app acquisition channel analysisUntil entrustment contract termination
WorkOS, Inc.United StatesAutomatic transmission via encrypted connection at sign-in (organizations using SSO only)workos.com/legalEmail address, name, SSO identifiersEnterprise single sign-on authenticationFor the life of the account (authentication logs 30 days)
Stripe, Inc.United StatesAutomatic transmission via encrypted connection at paymentstripe.com/privacyPayment-related informationPayment processingRetention period required by applicable law

If you do not wish international transfer, you may disconnect external service integrations or withdraw membership.

V. Personal Information Destruction Procedures and Methods

The Company destroys information without delay when the personal information retention period expires or processing purposes are achieved.

  • Electronic files: Deletion using technically irreversible methods (e.g., permanent database deletion and overwriting)
  • Paper documents: Shredding or incineration

Information requiring separate retention under relevant laws is stored separately and securely from other information. Additionally, upon user request or withdrawal, related data (notes, paragraphs, context, audio, etc.) is immediately and irreversibly deleted, and logs are retained for at least one year before destruction.

VI. Rights and Obligations of Data Subjects and Legal Representatives and Exercise Methods

Data subjects may exercise the following rights at any time:

  1. Request for personal information access
  2. Request for correction in case of errors
  3. Request for deletion
  4. Request for processing suspension

These rights may be exercised through the [My Information] menu on the website, or through written communication or email.

*Protection of Personal Information of Children Under 14

  1. (General Use) The Company restricts personal membership registration for children under 14 years of age in principle. If registration by a child under 14 is confirmed, the account will be immediately deleted.

  2. (Educational Institution Use Exception) When schools or other educational institutions use the Service for educational purposes in accordance with the 「Elementary and Secondary Education Act」, personal information of students under 14 years of age is processed according to the following procedures:

    • a. Legal Representative Consent: Educational institutions must obtain consent from parents (legal representatives) for the collection, use, and international transfer of students' personal information before using the Service. The Company provides consent form templates to educational institutions and confirms that the institutions have obtained lawful consent. Legal representatives may withdraw consent and request deletion of their child's personal information at any time.
    • b. Student Account Management: Student accounts can only be created and managed through educational institution administrators, and students cannot register directly.
    • c. Minimal Collection: For educational institution use, only names and school email addresses are collected from students.
    • d. Retention and Destruction: Student personal information is destroyed without delay at the end of the relevant school year or upon termination of the educational institution's use of the Service. Educational institution administrators can batch delete student data.

VII. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices

The Company may operate automatic collection devices including cookies for service provision.

  • Collection items: Service usage records, access logs, device information, etc.
  • Collection purpose: Customized service provision, security maintenance, statistical analysis, etc.

Data subjects may refuse or delete cookie storage through web browser settings.

VIII. Collection, Use, and Rejection of Behavioral Information

The Company does not collect behavioral information for customized advertising or user behavior-based analysis.

Should the Company collect behavioral information in the future, collection items, usage purposes, retention periods, rejection methods, etc., will be separately notified through this policy.

IX. Personal Information Protection Officer and Grievance Processing Department

The Company designates a Personal Information Protection Officer to oversee personal information-related tasks.

For personal information inquiries, rights exercise requests, grievance processing, etc., please contact the above address and we will process your request without delay.

X. Security Measures

The Company implements the following technical, administrative, and physical measures to protect personal information:

  • Encryption: Personal information is stored and transmitted using AES-256 algorithms. SSO integration is supported for secure access control implementation. For email/password accounts, passwords are protected with secure hash algorithms (SHA-512 with salt).
  • Access Control and Authentication: Role-based access control (RBAC) is applied to adhere to the principle of least privilege. Administrator access is restricted with MFA (Multi-Factor Authentication), and all external database access is audited through the DB auditing solution QueryPie. Secure authentication is required for administrator system access, with login attempt limits and session timeouts applied.
  • Log Management and Monitoring: All access and change logs are recorded and analyzed through CloudTrail and GuardDuty and retained for at least one year. Abnormal activities are detected and responded to in real-time. Logs can be transmitted to customer SIEM (Splunk) upon request and are provided through API documentation.
  • Data Retention and Masking: Sensitive information such as conversation records and documented content is classified as highest sensitivity and stored in fully encrypted form. When displayed, it is masked to minimize unnecessary exposure. It is automatically destroyed when the retention period expires, and data is classified by sensitivity (high, medium, low) with appropriate controls applied.

XI. Obligation to Notify and Policy Changes

This Privacy Policy may be revised due to changes in laws or service content. When changes occur, advance notice will be provided at least 7 days before revision.

  • Notice method: Notification through website or email
  • For important changes: At least 30 days advance notice

Notice Date: August 31, 2026

Effective Date: September 7, 2026

© 2025 ThePlato Inc.. All Rights Reserved.