Privacy Policy
Privacy Policy
Effective Date: September 7, 2026
Last Revised: September 7, 2026
ThePlato Inc. ("Company") respects the freedom and rights of users and complies with the Personal Information Protection Act of Korea and all other applicable data protection laws. We are committed to processing personal information in a transparent and secure manner. In accordance with Article 30 of the Personal Information Protection Act, the Company has established this Privacy Policy to inform users (data subjects) of how their personal information is handled and to address any related grievances promptly and effectively.
I. Purpose of Collection, Items Collected, and Retention Period of Personal Information
The Company collects and uses the minimum personal information necessary to provide the Service, and does not use personal data for purposes beyond those stated. If the purposes for processing personal information change, the Company will obtain the user's consent in advance as required by Article 18 of the Personal Information Protection Act.
1. Personal Information Collected with User Consent
The Company processes the following personal information based on user consent:
| Purpose of Collection | Items Collected | Retention and Use Period | Legal Basis |
|---|---|---|---|
| Account registration and Service use | Required: Email address, SNS account integration (Apple/Google), name, contact information Optional: User ID, password, date of birth, gender, profile photo | Until membership withdrawal or as required by applicable law | Personal Information Protection Act Article 15(1)(1) |
| Service usage records management | Access logs, access IP, service usage and suspension records, cookies | 3 months (Communications Privacy Protection Act) or until membership withdrawal | Personal Information Protection Act Article 15(1)(1) |
| Device information-based optimization | MAC address, browser information, device model, OS, advertising ID, etc. | Until membership withdrawal | Personal Information Protection Act Article 15(1)(1) |
| External service integration (optional) | Google Calendar events, Notion documents, Slack messages, Confluence information, etc. | Until integration is removed or membership withdrawal | Personal Information Protection Act Article 15(1)(1) |
Important Notice Regarding Sensitive Content: During service provision, the Company may process content containing sensitive information such as voice recordings, video, and system sound that users directly upload or input.
The Company does not use such information for AI training, model improvement, marketing, or any other secondary purposes whatsoever. Except when specifically requested by users through customer service, the Company does not manually review or access such files.
Additionally, voice data is immediately and irreversibly destroyed after processing, and all conversation records and related content are encrypted with AES-256 using individual keys for each user.
Users are responsible for obtaining necessary consent in accordance with relevant laws when uploading files or using recording features that contain sensitive information such as others' voices or meeting content.
2. Information Retained as Required by Law
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Contract, cancellation, payment, and goods supply records | 5 years | Act on Consumer Protection in Electronic Commerce, etc. |
| Consumer complaint and dispute resolution records | 3 years | Same as above |
| Advertisement and labeling records | 6 months | Same as above |
| Access logs (IP, etc.) | 3 months | Communications Privacy Protection Act Article 15-2 |
II. Provision of Personal Information to Third Parties
The Company does not provide personal information to third parties in principle. However, exceptions may be made in the following cases:
- When separate consent from the data subject has been obtained
- When provision is required by law
- When there is imminent danger to the life, body, or property of the data subject or third parties
The Company is not providing personal information to third parties. Should provision become necessary in the future, the Company will notify data subjects in advance and obtain consent.
III. Outsourcing of Personal Information Processing
The Company outsources personal information processing tasks to external parties for service provision.
| Entrusted Processor | Outsourced Task |
|---|---|
| Amazon Web Services, Inc. | Server operation and storage, encryption key management (KMS) — Seoul region (ap-northeast-2), Republic of Korea |
| Microsoft Corporation (Azure OpenAI Service) | Language-model inference for summaries and documents — processed in the Korea Central region |
| Google LLC | Language-model inference (Vertex AI); statistical analysis (Google Analytics, Firebase) |
| OpenAI OpCo, LLC | Language-model inference |
| AssemblyAI, Inc. | Speech-to-text conversion |
| ElevenLabs Inc. | Speech-to-text conversion |
| Soniox Inc. | Speech-to-text conversion |
| Deepgram, Inc. | Speech-to-text conversion (fallback route) |
| NAVER Cloud Corp. | Speech-to-text conversion (CLOVA Speech) — processed in the Republic of Korea |
| Twilio Inc. (SendGrid) | Sign-up verification and notification email delivery |
| Datadog, Inc. | System log and performance monitoring |
| Functional Software, Inc. (Sentry) | Application error tracking |
| PostHog, Inc. | Product usage statistics |
| AppsFlyer Ltd. | Mobile app acquisition channel analysis |
| WorkOS, Inc. | Enterprise single sign-on (organizations using SSO only) |
| Channel Corporation | Customer support chat (Channel Talk) — processed in the Republic of Korea |
| Stripe, Inc. | Payment service provision |
| Chequer, Inc. (QueryPie) | Database access auditing and log management |
When contracting with processors, the Company clearly specifies management and supervision of processors, restrictions on re-outsourcing, and technical protection measure obligations in accordance with Article 26 of the Personal Information Protection Act, and periodically inspects whether processors handle personal information securely.
IV. International Transfer of Personal Information
Meeting content (audio, transcripts, notes and documents) and account data are stored in the AWS Seoul region (ap-northeast-2) in the Republic of Korea and are not transferred overseas for storage. For service operation, the Company transfers the following limited categories of personal information overseas. Transfers occur automatically over TLS-encrypted connections at the time of service use.
| Processor | Country | Transfer Time and Method | Contact | Items | Purpose | Retention Period |
|---|---|---|---|---|---|---|
| Google LLC | United States | Automatic transmission via encrypted connection during service use | googlekrsupport@google.com | Meeting transcript text (language-model inference); usage records and device information (statistical analysis) | Summary generation and other service provision; statistical analysis | Inference input/output not retained; statistical data until entrustment contract termination |
| OpenAI OpCo, LLC | United States | Automatic transmission via encrypted connection during service use | privacy@openai.com | Meeting transcript text | Language-model inference for service provision | Not retained (zero data retention) |
| AssemblyAI, Inc. | United States | Automatic transmission via encrypted connection during service use | support@assemblyai.com | Meeting audio (streamed), transcript text | Speech-to-text conversion | Not retained (deleted immediately after conversion) |
| ElevenLabs Inc. | United States | Automatic transmission via encrypted connection during service use | elevenlabs.io/privacy-policy | Meeting audio, transcript text | Speech-to-text conversion | Not retained (deleted immediately after conversion) |
| Soniox Inc. | United States | Automatic transmission via encrypted connection during service use | soniox.com/policies/privacy-policy | Meeting audio (streamed), transcript text | Speech-to-text conversion | Not retained (zero retention by default) |
| Deepgram, Inc. | United States | Automatic transmission via encrypted connection during service use (fallback route) | deepgram.com/privacy | Meeting audio, transcript text | Speech-to-text conversion (fallback route) | Not retained (deleted immediately after conversion) |
| Twilio Inc. (SendGrid) | United States | Automatic transmission via encrypted connection when an email is sent | twilio.com/en-us/legal | Email address, name, delivery history | Sign-up verification and notification email delivery | Delivery history 30 days |
| Datadog, Inc. | United States | Automatic transmission via encrypted connection during service use | datadoghq.com/legal | Access logs, IP address, internal identifiers, error logs (no meeting content) | System monitoring and incident response | 15 days |
| Functional Software, Inc. (Sentry) | United States | Automatic transmission via encrypted connection during service use | sentry.io/legal | Internal identifiers, IP address, device and browser information, error logs (no meeting content) | Application error tracking | 90 days |
| PostHog, Inc. | United States | Automatic transmission via encrypted connection during service use | posthog.com/privacy | Pseudonymous identifiers, device information, usage events (no meeting content) | Product usage statistics | Deleted upon expiry of the retention period |
| AppsFlyer Ltd. | Israel | Automatic transmission via encrypted connection when the mobile app is installed or used | appsflyer.com/legal/privacy-policy | Device information, advertising identifier | Mobile app acquisition channel analysis | Until entrustment contract termination |
| WorkOS, Inc. | United States | Automatic transmission via encrypted connection at sign-in (organizations using SSO only) | workos.com/legal | Email address, name, SSO identifiers | Enterprise single sign-on authentication | For the life of the account (authentication logs 30 days) |
| Stripe, Inc. | United States | Automatic transmission via encrypted connection at payment | stripe.com/privacy | Payment-related information | Payment processing | Retention period required by applicable law |
If you do not wish international transfer, you may disconnect external service integrations or withdraw membership.
V. Personal Information Destruction Procedures and Methods
The Company destroys information without delay when the personal information retention period expires or processing purposes are achieved.
- Electronic files: Deletion using technically irreversible methods (e.g., permanent database deletion and overwriting)
- Paper documents: Shredding or incineration
Information requiring separate retention under relevant laws is stored separately and securely from other information. Additionally, upon user request or withdrawal, related data (notes, paragraphs, context, audio, etc.) is immediately and irreversibly deleted, and logs are retained for at least one year before destruction.
VI. Rights and Obligations of Data Subjects and Legal Representatives and Exercise Methods
Data subjects may exercise the following rights at any time:
- Request for personal information access
- Request for correction in case of errors
- Request for deletion
- Request for processing suspension
These rights may be exercised through the [My Information] menu on the website, or through written communication or email.
*Protection of Personal Information of Children Under 14
-
(General Use) The Company restricts personal membership registration for children under 14 years of age in principle. If registration by a child under 14 is confirmed, the account will be immediately deleted.
-
(Educational Institution Use Exception) When schools or other educational institutions use the Service for educational purposes in accordance with the 「Elementary and Secondary Education Act」, personal information of students under 14 years of age is processed according to the following procedures:
- a. Legal Representative Consent: Educational institutions must obtain consent from parents (legal representatives) for the collection, use, and international transfer of students' personal information before using the Service. The Company provides consent form templates to educational institutions and confirms that the institutions have obtained lawful consent. Legal representatives may withdraw consent and request deletion of their child's personal information at any time.
- b. Student Account Management: Student accounts can only be created and managed through educational institution administrators, and students cannot register directly.
- c. Minimal Collection: For educational institution use, only names and school email addresses are collected from students.
- d. Retention and Destruction: Student personal information is destroyed without delay at the end of the relevant school year or upon termination of the educational institution's use of the Service. Educational institution administrators can batch delete student data.
VII. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
The Company may operate automatic collection devices including cookies for service provision.
- Collection items: Service usage records, access logs, device information, etc.
- Collection purpose: Customized service provision, security maintenance, statistical analysis, etc.
Data subjects may refuse or delete cookie storage through web browser settings.
VIII. Collection, Use, and Rejection of Behavioral Information
The Company does not collect behavioral information for customized advertising or user behavior-based analysis.
Should the Company collect behavioral information in the future, collection items, usage purposes, retention periods, rejection methods, etc., will be separately notified through this policy.
IX. Personal Information Protection Officer and Grievance Processing Department
The Company designates a Personal Information Protection Officer to oversee personal information-related tasks.
- Name: SangChul Kim
- Email: hello@theplato.io
For personal information inquiries, rights exercise requests, grievance processing, etc., please contact the above address and we will process your request without delay.
X. Security Measures
The Company implements the following technical, administrative, and physical measures to protect personal information:
- Encryption: Personal information is stored and transmitted using AES-256 algorithms. SSO integration is supported for secure access control implementation. For email/password accounts, passwords are protected with secure hash algorithms (SHA-512 with salt).
- Access Control and Authentication: Role-based access control (RBAC) is applied to adhere to the principle of least privilege. Administrator access is restricted with MFA (Multi-Factor Authentication), and all external database access is audited through the DB auditing solution QueryPie. Secure authentication is required for administrator system access, with login attempt limits and session timeouts applied.
- Log Management and Monitoring: All access and change logs are recorded and analyzed through CloudTrail and GuardDuty and retained for at least one year. Abnormal activities are detected and responded to in real-time. Logs can be transmitted to customer SIEM (Splunk) upon request and are provided through API documentation.
- Data Retention and Masking: Sensitive information such as conversation records and documented content is classified as highest sensitivity and stored in fully encrypted form. When displayed, it is masked to minimize unnecessary exposure. It is automatically destroyed when the retention period expires, and data is classified by sensitivity (high, medium, low) with appropriate controls applied.
XI. Obligation to Notify and Policy Changes
This Privacy Policy may be revised due to changes in laws or service content. When changes occur, advance notice will be provided at least 7 days before revision.
- Notice method: Notification through website or email
- For important changes: At least 30 days advance notice
Notice Date: August 31, 2026
Effective Date: September 7, 2026