Privacy Policy

Effective date: 2026-08-08

Article 1 (Categories of Personal Information Collected and Collection Method)

The Service collects only the following information through Google OAuth login: - Email address - Name - Profile picture There is no separate sign-up process or password entry, and no information beyond the above is collected.

Article 2 (Purpose of Processing)

- Member identification and login session maintenance - Granting feature access permissions (role) within the Service - Preventing fraudulent use

Article 3 (Retention and Use Period)

Personal information is retained until account deletion, and is destroyed immediately upon request via the "Delete account" feature in the Service. No information is subject to a separate retention obligation under applicable law.

Article 4 (Provision of Personal Information to Third Parties)

The Service does not provide users' personal information to external parties. However, since login itself is performed through Google account authentication, Google's own privacy policy also applies during the login process.

Article 5 (Overseas Transfer of Personal Information)

The Service transfers and stores personal information overseas as follows for stable server operation: - Recipient: Amazon Web Services, Inc. - Destination country: United States (Oregon) - Timing and method of transfer: Transmitted and stored electronically over the network from sign-up through the end of the Service usage period - Items transferred: Email address, name, profile picture - Recipient's purpose of use: Hosting the server and database (cloud infrastructure) - Retention and use period: Until account deletion or termination of the hosting arrangement Inquiries regarding this overseas transfer may be directed to downct21@gmail.com.

Article 6 (Installation, Operation, and Refusal of Cookies)

The Service uses session cookies to maintain login state. These cookies are essential for providing the login feature; refusing them will prevent use of login-dependent features. (Advertising services are not currently operated; if introduced in the future, this policy will be revised and separately notified.)

Article 7 (Rights of Data Subjects and How to Exercise Them)

Users may request access to, correction of, deletion of, or suspension of processing of their personal information at any time via the "Delete account" feature in the Service, or by contacting the address below. Account deletion requests are processed immediately and cannot be recovered.

Article 8 (Procedures and Methods of Destruction)

Once the retention period has elapsed or the processing purpose has been achieved, information stored in electronic file form is deleted using methods that make recovery impossible.

Article 9 (Measures to Ensure Safety)

The Service is designed to never store passwords (Google OAuth only), minimizing exposure risk, and applies role-based access restrictions and session expiration management.

Article 10 (Data Protection Officer)

Contact: Vantage operator (Hyoen Chae) Email: downct21@gmail.com

Article 11 (Remedies for Infringement of Rights)

For consultation regarding personal information infringement, users may contact the Personal Information Protection Commission (privacy.go.kr) or other relevant authorities.

Article 12 (Changes to this Policy)

This policy may be revised due to changes in law or the Service; the effective date will be updated and announced within the Service upon any revision.