This notice explains in plain language how Canvas Socrates handles data in its current implementation. The camera is optional, and you can complete the experience without using it.
This English page is provided for convenience. If its meaning differs from the Korean privacy notice, the Korean version governs.
1. V2 data inventory
The table below distinguishes where each item in a metaphor-canvas session is sent, where it is stored, and when it is deleted.
| Item | Processing and transfer | Storage | Deletion |
|---|
| Stage drawings (stage PNG) | Sent to the application server to observe objects, form, and changes between stages and to generate an AI report. They may also be sent to and processed by overseas AI providers. | Not stored in the application database. | The originals are discarded from application-server request memory after observation and evidence generation finish. Retention and deletion terms at overseas AI providers have not yet been finalized and will be confirmed against their official policies and contracts before launch. |
|---|
| Drawing activity (raw stroke events) | Sent to the application server to observe stroke order, speed, pauses, undo, erase, and color changes and to generate an AI report. It may also be sent to and processed by overseas AI providers. | Raw events are not stored in the application database. Only aggregated evidence remains. | Raw events are discarded from application-server request memory after evidence generation finishes. Retention and deletion terms at overseas AI providers have not yet been finalized and will be confirmed against their official policies and contracts before launch. |
|---|
| First-stage self label | Sent to the application server so that the report can prioritize the meaning you entered yourself. It may also be sent to and processed by overseas AI providers. | May be stored as user-meaning evidence in the existing report JSON. | Stored as user-meaning evidence in the existing report JSON until deleted at your request or under the automatic deletion schedule in §5: 30 days for reports without payment history and 90 days for reports with payment history. Retention and deletion terms at overseas AI providers have not yet been finalized and will be confirmed before launch. |
|---|
| Optional face blendshape summary events | In V2, raw samples and series are summarized by stage on the device. Only stageId, time relative to the session, tracking quality, and the six largest deltas from baseline are sent to the application server. These summary events may also be sent to and processed by overseas AI providers. | Raw samples, raw series, and original video are not stored in the application database. Only per-stage summary evidence remains in the existing report JSON. | Raw blendshape samples, raw series, and original video are discarded on the device and are not transmitted. Server-side summary evidence is deleted at your request or under the §5 automatic deletion schedule. Retention and deletion terms for summary events at overseas AI providers have not yet been finalized and will be confirmed before launch. |
|---|
| Evidence summary | Processed on the application server to generate free and in-depth reports. It may also be sent to and processed by overseas AI providers. | Stored in the existing report JSON without original stage PNGs, raw strokes, or raw blendshape data. | The existing report JSON is deleted at your request or under the §5 automatic deletion schedule. Retention and deletion terms at overseas AI providers have not yet been finalized and will be confirmed before launch. |
|---|
| On-device IndexedDB draft | Temporarily stores stage drawings, drawing activity, and the self label only on this browser device so you can resume a session. The draft is not transmitted to the server, and face blendshape data is excluded. | Stored only in IndexedDB on your device and not sent to the application server or database. | Expires 24 hours after it is saved and is deleted when you complete the session or start over. Face data is never stored in the draft. |
|---|
2. Other information we process and why
- Text alternative: If you describe a metaphor instead of drawing, the selected category and up to 300 characters of description are treated as meaning that you supplied. The service does not present them as if it observed an actual drawing or stroke.
- Session and consent information: The theme, per-stage timestamps, session duration, camera choice, and consent version, time, and purposes are used to validate requests and document consent.
- Report and access information: Free and paid results, generation status, and hashed access tokens are used to display reports and verify sharing permissions.
- Payment and consent records: Order numbers, transaction identifiers issued by Paddle, payment status, finalized amount and currency, consent items, and policy versions are used to fulfill purchases, recover from errors, and handle disputes. The application server neither receives nor stores payment-method details such as card numbers.
3. Camera processing
The camera is optional, and you can complete the same self-reflection flow without it. In V2, original camera frames and raw blendshape samples and series are used only for on-device processing in the browser. Only per-stage summary events containing stageId, time relative to the session, tracking quality, and the six largest deltas from baseline are transmitted. These events are not converted into psychological labels such as emotion, anxiety, or tension. Raw blendshape samples, raw series, and original video are discarded on the device and are not transmitted. Turning the camera off stops subsequent frame processing.
Beta transition notice: The current legacy V1 /test flow sends and stores expressions expression tags on the application server. This differs from the V2 summary-event contract described above and remains in place until the V2 runtime transition is complete. Until V2 is connected in the live runtime, disclosures should be read against the current V1 behavior.
4. External processing and international infrastructure
AI services such as Google Gemini and Anthropic Claude may be used to observe inputs and generate report text. Paddle.com Market Ltd, based in the United Kingdom and the United States, acts as Merchant of Record for payment and tax processing. Supabase may be used for data storage and Vercel for web-service infrastructure. Stage drawings, drawing activity, the self label, and optional V2 face blendshape summary events may be processed by overseas AI providers to the extent necessary to generate the AI report. Original face video and raw blendshape samples and series are not transmitted, and raw drawing inputs are not stored in the application database.
When you proceed to payment, Paddle.com Market Ltd processes the payment-method and billing details you enter in its checkout, together with resulting transaction information, outside South Korea, including in the United Kingdom and the United States. Because Paddle acts as an overseas seller and Merchant of Record rather than a Korean payment processor, this constitutes an international transfer of payment information. The application server does not receive card numbers or other payment-method details. It retains only the order number, Paddle transaction identifier, payment status, and finalized amount and currency. The exact items transferred to Paddle, processing countries, retention periods, and refund and dispute procedures have not yet been finalized and will be confirmed against Paddle's official policies and contract before paid public launch.
The actual operating regions, each processor's retention period, and the timing and method of transfer depend on the production environment and contractual settings. Business information and detailed tables for processors and international transfers must be finalized and published before paid public operation.
5. Retention and deletion
Evidence summaries, reports, access tokens, payment ledgers, and consent records are currently stored in the database to provide the service and recover from errors. IndexedDB drafts remain only on your device, expire after 24 hours, and are deleted when you complete the session or start over. A daily scheduled job removes reports stored on the server. For reports with no payment history, the report, access token, and generation jobs are permanently deleted after 30 days. For reports with payment history, report content, including drawing metrics, expression summaries, and report text, is cleared after 90 days and the access token is revoked. Payment and refund records that must be retained by law remain for the applicable statutory period.
6. Optional product analytics
Product-improvement analytics require separate optional consent and are not part of the required privacy or international-processing consent. Collection is off by default. If you opt in, the service does not create person profiles and collects a pseudonymous device identifier with structured funnel events such as screen transitions and completion stages. You may withdraw this optional consent at any time, which stops subsequent collection. Analytics never include drawings, self labels, face movements, report text, or report and payment identifiers. They contain only structured properties such as theme, input method, camera choice, and a duration range. Events may carry a pseudonymous device identifier generated in the same browser.
7. Your choices
You can use the experience without the camera. If you do not agree to required processing or international processing, you may choose not to start the experience or proceed to payment.
You may request deletion of your report. For a report without payment history, the report, access token, and generation jobs are permanently deleted together. For a report with payment history, the report row must remain where payment or refund records are legally required, but the connected report content, including drawing metrics, expression summaries, and report text, is cleared and its access token is revoked so it can no longer be opened. Payment and refund records follow the retention rule in §5. Independently of a request, the same 30-day and 90-day automatic deletion schedule applies. Send deletion, access, or refund requests to sswook6720@gmail.com; we will respond within three business days.
8. Important notice
The service and its AI reports are non-medical self-reflection references. They do not replace medical or clinical diagnosis, counseling, or treatment. This document is a beta notice describing the product's current behavior and is not a final legal document with a confirmed business address and retention period for every category. Privacy questions and deletion or access requests are handled by 소크라테스캔버스, represented by 서성욱, at sswook6720@gmail.com.