Privacy policy
2026-09-09
1. What we collect
(a) When you buy: your email address, the currency, amount and order number, and the payment reference the payment provider returns. Card and bank account numbers are handled by the payment provider (PortOne, PayPal) and are never stored on our servers in any form. (b) Only if you request a VAT invoice: business registration number and company name. (c) If you create an account: email, a password hash (Argon2id — we cannot read your password), and, if you sign in with Google, the identifier Google gives us. (d) From the program: a random install identifier, the app version, the operating system version, the definition-pack version, and counts of findings (how many danger, warning and note items, and totals per module). (e) When you visit this site: date, language, referrer, and a coarse regional key (we do not store raw IP addresses).
2. What we do not collect
We do not send file contents, documents, photos, messages, contacts, screen images, the web addresses you visit, or the path or name of any individual file found during a scan. Scanning and verdicts happen entirely on your PC; the server only delivers definition packs and receives anonymous counts. We never collect national identity numbers, passport numbers or similar unique identifiers, for any purpose.
3. Why we use it
Email and order data are used to issue and deliver your licence, produce receipts, process refunds and answer your questions. Anonymous statistics are used only to reduce false positives (a file reported as safe from many places is promoted to the allow list), to see which version has a problem, and to decide when to publish a definition update. We do not use them for advertising and we do not sell them.
4. How long we keep it
Korean e-commerce law requires us to keep contract and payment records for 5 years and consumer complaint and dispute records for 3 years. Account data is destroyed as soon as you close your account. Anonymous statistics are deleted automatically after 180 days, as are site visit statistics. Password reset links expire 60 minutes after they are issued and the record is then deleted.
5. Sharing, processors and international transfer
We do not sell or hand your personal data to third parties. We use these processors to run the service — payments: PortOne (Republic of Korea) and PayPal (United States, for international payments); hosting: Railway (United States); email delivery: Resend (United States); network protection: Cloudflare (United States). Your email address and order data may therefore be transferred to the United States, limited to what running the service requires. If you would rather not have that happen, use the domestic payment route and note that the program works fully without an account.
6. Your rights
You may at any time ask to see, correct, delete or restrict the processing of your personal data. Do it yourself on the account page, or write to [email protected] and we will act without delay (payment records we are legally required to keep are destroyed once that period ends). The program's anonymous statistics can be switched off in settings, and scanning keeps working when they are off.
7. Security and cookies
All traffic is encrypted with HTTPS. Passwords are stored as Argon2id hashes and never in the clear. Administrative access is protected by separate authentication and rate limits. Cookies are used only to keep you signed in (HttpOnly, Secure, SameSite=Strict); we use no advertising or tracking cookies and embed no third-party analytics.
8. Contact and changes
Data protection officer: Yusang Lee (ProjectTeamForYou) · [email protected] · +82-70-7620-7256. If this policy changes we will post the change on this page 7 days before it takes effect, and 30 days before if the change is to your disadvantage. In Korea you may also contact the Personal Information Infringement Report Centre (privacy.kisa.or.kr, 118).