Connect-AI Privacy Policy

ItemDetails
Effective DateMay 13, 2026
Last UpdatedMay 13, 2026
ScopeRepublic of Korea

CONNECT AI Co., Ltd. (the "Company") complies with the Personal Information Protection Act ("PIPA") and other applicable laws, and establishes and publishes this Privacy Policy to protect data subjects' personal information and to handle related complaints promptly and effectively.

This English version is provided for the convenience of users. In case of any inconsistency between this English version and the Korean version, the Korean version shall prevail.


Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Where the Company wishes to use personal information for any other purpose, it will obtain a separate consent or take other measures required under PIPA Article 18.

  1. Member registration and management (identity verification, account authentication, prevention of misuse, notices and communications);
  2. Provision and operation of the Service (delivery of features, storage and analysis of Content, performance monitoring, customer support);
  3. Payment, settlement, billing, and refunds;
  4. Marketing communications (only where the user has separately consented);
  5. Service quality improvement and statistical analysis;
  6. Compliance with legal obligations and handling of disputes.

Article 2 (Items of Personal Information Processed)

The Company collects and processes the following items. Specific items may vary depending on how the user uses the Service.

A. Registration and Authentication

  • Required: email address, password (stored as a cryptographic hash), name, company name, contact number;
  • Where Third-Party Authentication is used: identifier, email address, name, profile image, and other items that the third-party provider makes available with the user's consent;
  • Tokens and codes used for email verification, password reset, and other security procedures.

B. Profile and Workspace Settings (optional)

  • Job title, industry, team size, country, target markets, profile image, notification preferences, etc.

C. Payment-Related Information

  • Masked card number, card-issuer name, and a billing key used solely for recurring charges to identify the payment instrument;
  • Payment records (order number, amount, payment time, payment status);
  • Where a tax invoice is requested, the business-registration information entered by the user.

D. Information Entered or Uploaded by Members in the Course of Using the Service

  • Third-party information that Members register (such as name, job title, company, email, phone number, and notes about counterparts);
  • Files and materials that Members upload (such as brochures and business-card images) and the results of analyzing them;
  • Email subject, body, recipients, sending time, and tracking results (opens, clicks, replies, bounces) of messages composed or sent by Members;
  • Where a Member connects an external email account, the authentication tokens or credentials required for the connection (stored in encrypted form).

With respect to third-party information that Members register on the Service, the Member acts as the personal information controller under PIPA, and the Company acts as the processor entrusted by the Member. Data subjects may exercise their rights against the Member, and the Company will reasonably cooperate in fulfilling such requests.

E. Automatically Collected Information

  • Information generated or collected automatically in the course of using the Service: IP address, access time, usage records, device information (browser type, operating system, screen resolution, etc.), cookie and session identifiers, authentication tokens, and error logs.

F. Sensitive Information and Unique Identifiers

The Company does not intentionally collect or process sensitive information defined in PIPA Article 23 (such as information on ideology, beliefs, political views, or health) or unique identifiers defined in PIPA Article 24 (resident-registration number, passport number, driver's license number, or alien-registration number). Where such information is incidentally included in materials uploaded by the Member (such as business-card images), the Company will delete or de-identify the relevant items upon discovery. The Company also does not generate or process pseudonymized information.

Article 3 (Retention and Use Period of Personal Information)

  1. The Company processes and retains personal information within the retention and use period required by law or consented to by the data subject.
  2. As a rule, a Member's personal information is destroyed without undue delay when the Member terminates the agreement (withdraws membership) or when the processing purpose is fulfilled. However, to prevent fraudulent use and to handle disputes, the Company separately stores the Member's personal information for 90 days from the date of withdrawal and then destroys it by means that prevent recovery; re-registration with the same email address is restricted for 7 days from the date of withdrawal. In addition, the following information is stored separately — apart from the retention period above — for the periods required by applicable laws:
    • Records of contracts and withdrawal of subscriptions: 5 years (Act on the Consumer Protection in Electronic Commerce);
    • Records of payments and supply of goods and services: 5 years (same Act);
    • Records of consumer complaints or dispute resolution: 3 years (same Act);
    • Records of electronic financial transactions: 5 years (Electronic Financial Transactions Act);
    • Records of labeling and advertising: 6 months (same Act);
    • Access logs: 3 months (Protection of Communications Secrets Act).
  3. Third-party information registered by a Member and other Content are destroyed in accordance with the Company's procedures when the Member deletes them or terminates the agreement. Where temporary retention is necessary for backups, legal compliance, or dispute resolution, such information will be separately stored in a secure manner until those purposes are fulfilled.

Article 4 (Provision to Third Parties)

The Company provides personal information to third parties only with the data subject's consent or in cases permitted by PIPA Articles 17 and 18 or other applicable laws. The Company does not provide personal information to any third party on a regular basis. Should such provision become necessary in the future, the Company will inform data subjects in advance and obtain their consent.

Article 5 (Outsourcing of Processing)

To provide the Service, the Company may outsource the following processing activities to third parties. In accordance with PIPA Article 26, the Company contractually requires processors to handle personal information securely.

Outsourced activityProcessor (category)
Cloud infrastructure (storage and compute)Amazon Web Services (AWS) — Seoul region
Payment processingDomestically registered payment-gateway providers
Transactional email deliveryEmail delivery providers
Third-party authenticationIdentity providers (Google, Naver, etc.)
AI-model based processing (draft generation, analysis, embeddings, etc.)Global AI model providers
External email account integration (where a Member opts in)Mail providers chosen by the Member
Error monitoring and operational analyticsMonitoring service providers
Service usage analyticsWeb/app analytics providers (e.g., Google Analytics)

With respect to outsourced payment processing, the Company holds only the minimum information needed to identify the payment instrument (masked card number, card-issuer name, and a billing key for recurring charges); full payment-card numbers are held and processed by the payment-gateway provider.

The specific processors and outsourced activities may change. The Company will publish material changes through this Policy.

Article 6 (Cross-Border Transfers)

Pursuant to PIPA Article 28-8 (2), the Company discloses, through this Policy, cross-border transfers undertaken for outsourcing or storage purposes. Data subjects may verify such transfers below and may, through the Company's customer-support channel, object to a transfer (although doing so may prevent the use of certain features or the Service in whole or in part).

Recipient (category)CountryPurposeItems (overview)Time and method of transferRetention
Global AI model providers (LLMs, embeddings)United States and othersAI features (draft generation, analysis, embeddings, summarization, etc.)Member's request context, parts of files and materials uploaded by the Member, parts of contact information where necessaryTransmitted over the network at the time of useUntil the outsourcing agreement ends or the processing purpose is fulfilled
Transactional email providersUnited States and othersSystem emails such as sign-up verification and password resetRecipient email, name, message body, etc.Transmitted over the network when sending events occurUntil the outsourcing agreement ends
Identity and mail providers (Google, Naver, etc.)United States, Republic of Korea, and othersThird-party authentication and sending or syncing of mail accounts that Members opt to integrateAuthentication identifiers, name, email, and the body and recipients of messages sent by the Member, etc.Transmitted over the network at the time of authentication or sendingUntil the Member disconnects the integration or the outsourcing agreement ends
Error monitoring providersUnited States and othersAnalysis of Service errors and incidentsIdentifier, IP, parts of the request context captured at the time of an errorTransmitted over the network when an error occursAccording to the outsourcing agreement or retention policy
Web/app analytics providers (e.g., Google Analytics)United States and othersService usage and behavioral analyticsCookie identifiers, IP address (anonymized where possible), page/event usage records, device and browser informationTransmitted over the network when such analytics tools are introduced and in useAccording to the retention policy of the analytics tool (typically 14–26 months)

Content and file storage operated by the Company (AWS S3) and its databases are located within the Republic of Korea (Seoul region) and are not subject to cross-border transfers. If the scope of cross-border transfers changes due to infrastructure or processor changes, this Policy will be updated accordingly.

Article 7 (Rights of Data Subjects and How to Exercise Them)

  1. Data subjects may, at any time, exercise the following rights against the Company:
    • Right to access personal information;
    • Right to correct any errors;
    • Right to request deletion (except where retention is required by law);
    • Right to request suspension of processing;
    • Right to withdraw consent.
  2. Rights may be exercised through the Service settings or by writing to the Company's privacy contact email.
  3. You may withdraw your membership (terminate the service agreement) directly from the Settings menu in the mobile app or on the web. Instructions on how to delete your account and how your personal information is handled upon deletion are available on the Customer Support page.
  4. Where a data subject is the legal representative of a child under 14 years of age, the legal representative may exercise the rights in this Article on the child's behalf.
  5. Rights may be limited as permitted by PIPA Article 35 (4), Article 37 (2), or other applicable provisions. The Company will inform the data subject of the reason without undue delay.

Article 8 (Destruction of Personal Information)

  1. Where the retention period under Article 3 has expired, or the processing purpose has been fulfilled and the personal information is no longer needed, the Company destroys such personal information without undue delay (within 5 business days) from the date such ground arises.
  2. Personal information in electronic form is permanently deleted by technical means that prevent recovery; personal information on paper is shredded or incinerated.
  3. Information that must be separately stored under applicable laws is kept in a separate database or storage and destroyed in the manner described in paragraph 2 upon expiration of the relevant retention period.

Article 9 (Personal Information of Children under 14 Years of Age)

The Company does not permit users under 14 years of age to register and does not collect or process the personal information of users under 14. If the Company becomes aware that a Member is under 14 years of age, it will destroy the account and related personal information without undue delay.

Article 10 (Automatically Collected Information and Opt-Out)

  1. To provide a tailored experience, the Company uses cookies, local storage, authentication tokens, and similar automatic-collection mechanisms.
  2. Purposes include maintaining login sessions, preserving user preferences, analyzing usage patterns, and supporting error diagnosis and security.
  3. The Company may use external analytics tools such as Google Analytics for service-quality improvement and statistical analysis. In that case, such tools collect information including cookies, identifiers, and page/event usage records; where available, the Company enables options that reduce identifiability such as IP anonymization. Members may opt out of analytics collection by:
  4. Users may refuse cookies through their browser settings. Doing so may impair certain features such as session persistence.

Article 11 (Automated Decision-Making)

  1. The Company uses AI models to analyze Member Content and to generate drafts and recommendations, among other automated processing.
  2. AI outputs are provided to the Member as supporting material; final decisions (such as whether to send a message or proceed with a transaction) are made by the Member. The Company does not, on its own, perform automated decisions that materially affect Members' rights or obligations.
  3. Members may, through the Company's privacy contact channel, request an explanation of, or object to, automated processing.

Article 12 (Google API User Data)

  1. Where a Member uses a Google account for third-party authentication or connects a Google (Gmail) account as an external mail account, the Company accesses certain user data through Google APIs within the scopes the Member has consented to. The permissions requested include:
    • Basic profile information for member identification and authentication (email, name, profile image, etc.);
    • Sending Member-reviewed sales emails from the Member's own Gmail account;
    • Processing reply metadata and parts of the body for the purpose of detecting replies to sent messages.
  2. Connect-AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements:
    • The Company does not use Google user data to develop, improve, or train generalized AI and/or ML models.
    • The Company does not transfer Google user data to third parties except as necessary to provide or improve user-facing features that are prominent in the application's user interface.
    • The Company does not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
    • The Company does not allow humans to read Google user data unless (a) the Member has given affirmative consent, (b) it is for security purposes (e.g., investigating abuse), (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized and is used for the app's internal operations.
  3. Members may revoke any permission granted to the Company at any time through the Google permissions page (https://myaccount.google.com/permissions). Upon revocation, the Company will no longer use the affected tokens for API calls and will delete Google API user data in its possession within a reasonable period. Members may also separately request deletion of such data through the Company's privacy contact channel.

Article 13 (Technical and Administrative Safeguards)

In accordance with PIPA Article 29 and Article 30 of its Enforcement Decree, the Company implements technical and administrative safeguards including:

  1. Minimization of personnel with access to personal information and management of their access rights;
  2. One-way hashing of credentials such as passwords;
  3. Encryption of sensitive credentials such as connected mail-account secrets;
  4. Access-control systems and authorization management, including logical isolation of data at the tenant (organization) level;
  5. Encryption of network traffic (TLS);
  6. Retention of access logs and prevention of tampering;
  7. Periodic security reviews and vulnerability assessments;
  8. Training of personnel who handle personal information.

Article 14 (Privacy Officer and Contact)

The Company appoints a Privacy Officer to take overall responsibility for personal-information processing and to handle data subjects' complaints and remedies.

RoleName and TitleContact
Privacy Officer (개인정보 보호책임자)An, Chang Yong (COO; Privacy Operations)korea@connectai.biz
General privacy inquiriessupport@connectai.kr

Data subjects may direct any privacy-related inquiries, complaints, or remedy requests arising from their use of the Service to the Privacy Officer or to the general privacy inquiries channel above, and the Company will respond and act without undue delay.

Article 15 (Remedies for Infringement)

Data subjects may report or seek consultation regarding personal-information infringement at the following bodies:

BodyPhoneWebsite
Personal Information Dispute Mediation Committee+82-1833-6972www.kopico.go.kr
Privacy Infringement Report Center (KISA)118privacy.kisa.or.kr
Cybercrime Investigation, Supreme Prosecutors' Office1301www.spo.go.kr
Cyber Bureau, Korean National Police Agency182ecrm.police.go.kr

A person whose rights or interests have been infringed by an act or omission of an administrative agency in connection with the rights under PIPA Articles 35 (access), 36 (correction/deletion), or 37 (suspension of processing) may file an administrative appeal as provided in the Administrative Appeals Act.

Article 16 (Changes to this Policy)

This Policy takes effect on May 13, 2026. Where the Company changes this Policy, it will publish the changes in advance through appropriate means such as service notices, stating the reasons for the change and the effective date. Changes required by applicable law may take effect immediately, in which case the Company will inform users afterwards.

Supplementary Provision

This Policy takes effect on May 13, 2026.

Where prior versions exist, the Company will separately publish a comparison with the previous version.

Change Log

VersionEffective DateChanges
v1.02026-05-13Initial release