This notice explains how Canvas Socrates handles data for Gemini-assisted results, optional drawing-image transfer and local camera use, and one-time payment. You can still complete the free five-stage flow with drawing and text only.
This English page is provided for convenience. If its meaning differs from the Korean privacy notice, the Korean version governs.
1. V3 data inventory
The table below distinguishes where each item in a metaphor-canvas session is sent, where it is stored, and when it is deleted.
| Item | Processing and transfer | Storage | Deletion |
|---|
| Stage drawings (stage PNG) | Only when you opt into both Google AI processing and drawing-image observation is each saved stage PNG submitted without resizing or re-encoding over TLS to the Vercel application server and temporarily sent to Google Gemini to produce object candidates. If the full request exceeds 3.6 MB, no PNG is sent to the application server or Google and the request stops with a 413 error. If you decline only image transfer, it never leaves the device; with Google AI consent still active, structured drawing evidence and writing may still be included in Gemini report input. Camera frames are excluded from every path. | The on-device IndexedDB draft temporarily stores the saved stage PNG and same-tab sessionStorage stores a reduced preview. The transferred PNG has the same bytes as the on-device PNG and is processed in Vercel request memory. Google processing and retention follow the Google row in §4; no drawing PNG is stored in the application database or Supabase. | The IndexedDB original expires 24 hours after saving and is deleted on the next app or storage access; completing the session or starting over deletes it immediately. The same-tab preview disappears when the tab closes. The transferred image is discarded from Vercel request memory after the response; Google retention follows the Google row in §4. |
|---|
| Drawing activity (raw stroke events) | Processed on the Vercel-hosted application server to observe stroke order, speed, pauses, undo, erase, and color changes. Raw events are not sent to Google or Paddle; only aggregated evidence may be included in Gemini report input when you separately consent to AI processing. | Raw events are not stored in the application database. Only aggregated evidence remains. | Raw events are discarded from application-server request memory after evidence generation finishes. Retention of Vercel service-generated logs and security metadata follows the processor table in §4 and Vercel's official DPA. |
|---|
| Short first-stage alias (self label) | Sent to the Vercel application server so reports can prioritize meaning you entered. With separate Google AI consent it may be included in Gemini report input; if you decline, it is used only by the pre-reviewed copy path. It is not sent to Paddle. | May be stored as user-meaning evidence in the existing report JSON. | Stored as user-meaning evidence in the existing report JSON in Supabase until deleted at your request or under the automatic deletion schedule in §5: 30 days for reports without payment history and 90 days for reports with payment history. |
|---|
| Stage writing and metaphor categories | The metaphor category and up to 300 characters of writing per stage are sent to the Vercel application server as meaning you supplied. With separate Google AI consent they may be included in Gemini report input; if you decline, they are used only by the pre-reviewed copy path. They are not sent to Paddle. | Stage writing and metaphor categories may be stored as user-meaning evidence in the existing report JSON. They are excluded from optional product analytics. | Deleted from the existing report JSON in Supabase on request or under the §5 automatic deletion schedule: 30 days for reports without payment history and 90 days for reports with payment history. |
|---|
| Evidence summary | Processed on the Vercel application server to create free and in-depth reports. With separate Google AI consent, structured evidence may be included in Gemini input. It is not sent to Paddle. | Stored in the existing report JSON without original stage PNGs, raw strokes, or camera-derived data. | The existing report JSON in Supabase is deleted at your request or under the §5 automatic deletion schedule. |
|---|
| On-device IndexedDB draft | Temporarily stores stage drawings, drawing activity, stage writing, metaphor categories, and the self label only on this browser device so you can resume a session. The draft itself is not transmitted, and camera values are excluded. | Stored only in IndexedDB on your device and not sent to the application server or database. | Expires and can no longer be restored 24 hours after saving, then is deleted on the next app or storage access. Completing the session or starting over deletes it immediately. Camera data is never stored in the draft. |
|---|
| Optional support and rights-request email | The free session does not request an email address. Only if you contact the support mailbox for a question or an access, correction, deletion, or restriction request, the service processes the sender address, display name if present, message text, and any report ID you choose to provide to receive and answer the request and verify rights. | May be retained in the operator's Gmail support mailbox provided by Google LLC and in Google's systems. It is not automatically copied into the session or report database. | Retained only as long as needed to handle the request and related disputes, then deleted by the operator in Gmail. A deleted message remains in Trash for up to 30 days before permanent deletion, and Google's safe system-deletion process may take additional time. A record required by law is segregated and retained only for that statutory period. |
|---|
2. Legal basis, purpose, exact items, and retention for collection and use
This table maps collection and use by the operator, not the physical country of processing. International infrastructure is described separately in §4. FREE inputs and consent records rely on consent under Article 15(1)(1); the 19+ proof, access control, and rate limiting rely on Article 15(1)(4) to the extent necessary for the requested free service. Article 29 is a separate safeguards duty.
| Processing category | Legal basis | Purpose | Exact items | Retention period |
|---|
| FREE session input and free report | Processed under the mandatory FREE collection-and-use consent for 2026-08-24.en.v6. The legal basis is the data subject's consent under Article 15(1)(1) of Korea's PIPA. | Validating session requests; creating structured drawing and writing evidence; creating and delivering the free report; and recovering from errors. | schemaVersion 3; contentLocale; themeId; startedAtIso; durationMs; cameraMode off or local; each stage's stageId, capture time, inputMode, metaphor category and up to 300 characters of writing, and first-stage self label; each raw stroke event's stageId, time, kind, x/y, pressure, pointerType, and color; derived drawing metrics and evidence; and free-report text and generation status. With optional consent, stage PNGs are temporarily present in request memory but are not stored in the database. | Raw stroke events are discarded from request memory when processing finishes. The remaining values are retained with a report without payment history until 30 days after creation or a valid deletion request. Content in a legacy report with payment history is irreversibly cleared after 90 days. |
|---|
| Mandatory FREE consent and 19+ self-attestation proof | The consent record documents mandatory and optional en.v6 consent under Article 15(1)(1) of Korea's PIPA. The 19+ self-attestation proof, request-time policy and purpose validation, and re-consent check for an old policy are necessary to perform the requested free-service contract and requested measures under Article 15(1)(4) of Korea's PIPA. | Enforcing the adult-only boundary; consent preflight; confirming that the policy and purposes match at request time; re-consent after an old policy; and documenting consent. | Consent policy version, purposes, and time; 19+ age band; proof policy version, issue and expiry times; pseudonymous session binding and its one-way hash. Date of birth, name, and identity-document data are excluded. | Server-signed 19+ and pseudonymous-session cookies last up to 30 days. The submission consent-preflight cookie lasts up to two minutes and is deleted immediately after a successful submission. The database FREE consent record is retained with a report without payment history until 30 days after creation or a valid deletion request. Consent data in sessionStorage disappears when the tab closes. |
|---|
| Report access control | Article 15(1)(4) of Korea's PIPA is the collection-and-use basis because this processing is necessary to perform the requested free-service contract and requested measures. Article 29 is a separate safeguards duty and is not a collection-and-use basis. | Verifying report ownership; preventing unauthorized access or deletion; and recovering generation-job errors. | Report ID; hashed access token; generation-job ID and status; and the browser's ownerToken report-ownership cookie. Card numbers and identity-document data are excluded. | Database access tokens and generation jobs for reports without payment history remain until 30 days after creation or a valid deletion request. The ownerToken cookie lasts up to 90 days and is revoked when the report is deleted. A legacy report with payment history has its access token revoked when its content is destroyed. |
|---|
| Rate limiting and security | Article 15(1)(4) of Korea's PIPA is the collection-and-use basis because this processing is necessary to provide the requested free service reliably and fulfill the request. Article 29 separately requires safeguards such as the HMAC pseudonymous identifier and access controls; it is not a collection-and-use basis. | Limiting excessive requests; maintaining service reliability and security; and preventing abuse. | An HMAC pseudonymous rate-limit identifier derived from the raw network address with a server secret, the remaining token count, and the last-refill time. The application database does not store the raw IP address. | Entries whose last use was more than 24 hours ago are deleted on the next rate-limit check. The application database does not store the raw IP address. |
|---|
| Paid-report order, payment, and refund ledger | Processed to form and perform the one-time paid-report contract you confirm and to meet e-commerce legal duties, within Article 15(1)(4) of Korea's PIPA and applicable law. Payment processing and cross-border items are confirmed separately before checkout. | Creating orders, confirming completed payment, granting in-depth-report access, processing receipts, refunds and chargebacks, preventing duplicate events, and handling disputes. | Internal order and report identifiers; Paddle transaction, adjustment, and event identifiers; price identifier; payment, refund and chargeback status; amount and currency; event-processing time; and payment-consent version. The application server does not receive or store card number, CVC, or date of birth. | Report content is cleared and its access token revoked after 90 days. Contract, payment, supply and cancellation records are segregated and retained for five years where Korean e-commerce law requires it; consumer complaint and dispute records are retained for three years, then deleted. |
|---|
Paddle transaction scope: New checkout starts only when you open the payment screen. The application processes signed payment-completed, refund, and chargeback lifecycle webhooks to grant or revoke access and retains only the minimum ledger listed above rather than the full webhook body.
On-device processing — IndexedDB draft
This is temporary processing on your device, separated from collection and use on the operator's servers. The draft itself is not sent to the operator. Only items that you finally submit are transferred under the FREE session-input row above and §4.
| Processing category | Purpose | Exact items | Retention period | Server transmission |
|---|
| On-device IndexedDB draft | Resuming an interrupted five-stage session in the same browser. | themeId, startedAtIso, currentStageIndex, cameraMode setting (off or local), savedAt and expiresAt; each stage's stageId, capture time since session start, inputMode, stage drawing (stage PNG) or metaphor category and writing, and first-stage self label; and each raw stroke event's stageId, time, kind, x/y, pressure, pointerType, and color. Camera frames, landmarks, blendshapes, and movement values are excluded. | Until the earliest of 24 hours after saving, session completion, or starting over. After 24 hours it can no longer be restored and is physically deleted on the next app or storage access. Completing the session or starting over deletes it immediately. | Saving or restoring the draft alone sends nothing to the server, application database, or an external provider. |
|---|
Other information we process and why
- Text alternative: If you describe a metaphor instead of drawing, the selected category and up to 300 characters of writing at each stage may be stored as report evidence that you supplied. The service does not present them as if it observed an actual drawing or stroke. The service does not ask for names, contact details, account handles, or health information; do not enter information that identifies you or another person.
- Session and consent information: Theme, stage timestamps, duration, structured cameraMode, and consent version, time, and purposes validate requests and document consent. Choosing camera records local; declining records off. No frame or face value is recorded. A 19+ self-attestation uses a server-signed HttpOnly proof containing only an age band, policy version, issue and expiry times, and a pseudonymous session binding. The database keeps only a one-way hash. We do not request or store a date of birth, name, or identity document.
- Security and recovery information: Rate limiting uses an HMAC pseudonymous identifier instead of storing the raw network address. Entries whose last use was more than 24 hours ago are deleted on the next rate-limit check. Paddle payment-completed, refund, and chargeback lifecycle webhooks are processed only to reconcile transaction state, grant or revoke access, handle disputes, and meet legal duties. The service retains event and transaction identifiers, status, currency, price identifier, and total rather than the full webhook body.
- Report and access information: Free and paid results, generation status, and hashed access tokens are used to display reports and verify sharing permissions.
- Payment and consent records: Order numbers, transaction identifiers issued by Paddle, payment status, finalized amount and currency, consent items, and policy versions are used to fulfill purchases, recover from errors, and handle disputes. The application server neither receives nor stores payment-method details such as card numbers.
3. Camera processing
The camera is optional. Only after you choose camera use on screen and grant browser permission does the browser read frames transiently and use face presence for a current-screen indicator. Declining or using drawing only provides the same five stages, free and paid scope, and price.
Video, landmarks, blendshapes, movement values or summaries, and expression or psychological tags are not stored in the session, draft, product analytics, application server, database, Google Gemini, or Paddle. Turning the camera off, revoking permission, or leaving the screen stops tracking and releases the media track.
The camera does not judge emotion, personality, or health and does not make a psychological result more accurate.
4. External processing and international infrastructure
Vercel and Supabase infrastructure rely on mandatory free-session consent, Google Gemini relies on separate optional consent, and Paddle checkout relies on confirmation and consent before a paid order. If you decline an optional transfer, that external feature is not used; public pages and the no-image, no-Google free path remain available.
| Recipient and contact | Processing countries | Items | Purpose | Timing and method | Retention and deletion | Legal basis and effect of refusal |
|---|
| Vercel Inc. (Customer Data web-hosting and application/API request processor), privacy@vercel.com | The current function execution region is iad1 in the United States (Washington, D.C.). Vercel may process data in the United States and other service locations under its official DPA, Privacy Notice, and subprocessor list. This notice will be updated before a material change applies. | Raw stroke events, stage writing, metaphor categories, self labels, evidence and free or in-depth reports, report-access and payment identifiers, 19+ and consent proofs, and stage PNGs where optional consent exists. Camera frames, landmarks, blendshapes, and movement values are excluded. | Hosting the Next.js application and APIs; validating requests, age, and consent; creating and delivering evidence and reports; relaying opted-in stage PNGs to Google; handling payment requests and webhooks; and security and incident response. | Processed over TLS with API requests to start, continue, and complete a session and to view or delete a report. | Raw stroke events are discarded from application-server request memory when request processing finishes. Other Customer Data is processed under the operator's instructions while the service is used and, after service termination, is deleted within a commercially reasonable period under the DPA except where legal retention applies. | Separate consent under Article 28-8(1)(1) of Korea's PIPA. You may refuse, but then cannot use the free session or report; public information pages remain available. |
|---|
| Vercel Inc. (service-generated operations and security data), privacy@vercel.com | The United States and operating locations covered by Vercel's Privacy Notice and current service-provider list. This notice will be updated before a material change applies. | IP address; city and country derived from IP; user-agent, browser, and device settings; request time, frequency, performance, errors, diagnostics, logs, telemetry, and system configuration. Drawing PNGs, raw strokes, and user writing are not supplied for these service-generated-data purposes. | Service operation, monitoring, support, security, incident response, performance and service improvement, and other lawful business purposes described in Vercel's Privacy Notice. | Automatically generated or collected and processed over TLS during web and API requests and use of the service. | Vercel's Privacy Notice says it retains information for the minimum period needed for legal and contractual duties, dispute resolution, security, and legitimate business purposes, then deletes or anonymizes it; backups that cannot be deleted immediately are kept securely. It does not publish a fixed number of days. | Separate consent under Article 28-8(1)(1) of Korea's PIPA. You may refuse, but then cannot use the free session or report; public information pages remain available. |
|---|
| Google LLC and Google's published subprocessors (Google Cloud Vertex AI processor), Google privacy inquiry form | The United States and other countries where Google or its processors operate facilities. Requests may be handled by Google's global infrastructure; current locations and subprocessors follow Google Cloud's published privacy and subprocessor documentation. | Separately consented stage PNGs, derived object candidates and evidence, drawing metrics, metaphor categories, stage writing, self labels, structured report prompts and responses, model and token-usage metadata. Raw stroke events, camera frames, and face values are excluded. | Observing object candidates in drawings and generating structured selection plans for free and in-depth reports. It does not determine personality, emotion, or health status or make a legally significant decision. | Transferred over TLS when a session is submitted or an in-depth report is generated after separate Google AI cross-border consent. Stage PNGs transfer without resizing or re-encoding only when drawing-image analysis is also selected; if the full request exceeds the transfer limit, they are not sent. | Under the Google Cloud Service Specific Terms, Google does not use inputs or outputs to train or fine-tune AI/ML models without prior permission or instruction. Prompt logging for safety and abuse monitoring may apply under the governing agreement, and project-isolated in-memory caching of up to 24 hours is enabled by default. This service does not claim Zero Data Retention unless the project's abuse-monitoring exception and disabled-cache state are verified with account evidence. | Separate optional consent under Article 28-8(1)(1) of Korea's PIPA. If you decline Google AI processing, no drawing images, writing, or evidence are sent to Google; the same free scope remains available through pre-reviewed copy and Google-generated in-depth output is unavailable. If you keep Google AI consent but decline only drawing-image transfer, the image is not transferred while Gemini may still process structured evidence and writing. |
|---|
| SUPABASE PTE. LTD. (database and access-control processor), DPA privacy contact: privacy@supabase.io | Primary application-database storage and processing are in Seoul, Republic of Korea (ap-northeast-2). Contracting, support, and authorized subprocessors may involve Singapore, the United States, and other locations covered by Supabase's official DPA, TIA, and subprocessor list. This notice will be updated before a material change applies. | Derived evidence, stage writing, metaphor categories, self labels, drawing metrics, free and in-depth reports, hashed access tokens, consent version, time and purposes, 19+ and pseudonymous-session proofs, HMAC security identifiers, and order, Paddle transaction, adjustment and webhook identifiers, states, amount and currency. Original stage PNGs and raw stroke events are not stored. | Storing sessions, evidence, reports and the payment ledger; verifying access and refund revocation; rate limiting; error recovery; deletion on request; and scheduled deletion. | Processed over TLS when a session is completed, a report is created, viewed, or deleted, or a rate-limit check is performed. | Rate-limit entries whose last use was more than 24 hours ago are deleted on the next rate-limit check. A free report with no payment history and its access token and generation jobs are deleted after 30 days or on a valid deletion request. After service termination, Customer Data follows Supabase's DPA export and deletion process. | Separate consent under Article 28-8(1)(1) of Korea's PIPA. You may refuse, but then cannot use the free session or report; public information pages remain available. |
|---|
| Paddle.com Market Ltd. or the Paddle Merchant of Record entity shown in the checkout and receipt, and its processors | The United Kingdom, United States, Ireland, Canada, and service locations listed in Paddle's Privacy Notice and subprocessor information. The transaction seller follows the buyer's location and the actual checkout display. | Name, email, billing country and payment-method information entered by the buyer in Paddle checkout; purchase, consent, transaction, price, amount, currency, tax, receipt, refund and chargeback information; and internal order and report identifiers. The application server does not receive or store card number or CVC. | Acting as Merchant of Record for checkout, payment collection, tax calculation and remittance, receipts, fraud prevention, refunds, chargebacks, customer support, and legal duties. | Processed over TLS and signed webhooks when you confirm paid-report and Paddle processing and open checkout, or when a payment, refund, or chargeback lifecycle event occurs. | Paddle retains data as needed for the transaction relationship, tax, accounting and legal duties, fraud prevention, limitation periods, and disputes, then deletes or anonymizes it. The operator's ledger follows the domestic table and §5. | Formation and performance of the one-time paid contract plus separate pre-checkout confirmation and consent under Article 28-8 of Korea's PIPA. If you decline, you cannot purchase the in-depth report but may continue using the free service. |
|---|
The controlling sources are the Vercel DPA, Vercel Privacy Notice, Vercel subprocessor list, Supabase DPA, Supabase subprocessor list, Supabase TIA, the Google Cloud Data Processing Addendum, Google Cloud Service Specific Terms, Google Cloud subprocessor list, Vertex AI retention and ZDR guidance, Paddle Privacy Notice, and the actual deployment and transaction screen. The table and consent copy will be updated before a material change applies.
Optional support email: Only when you choose to contact the support address, Google LLC's Gmail provides message receipt, storage, and security functions. Google operates servers around the world, so a message may be processed outside your country. This optional channel is not required to start a free session and is not part of the mandatory international-infrastructure consent above. The controlling sources are the Google Privacy Policy, Google data-transfer frameworks, and Gmail deletion guidance.
Data minimization: The free session does not request a name, date of birth, address, phone number, email address, account, or identity document. The support mailbox processes a sender address and message only when you contact it. Stage PNGs and Google AI input transfer only with separate consent, and original PNGs are not stored in the application database. Supabase stores pseudonymous access data, derived evidence, writing, reports, and the minimum payment ledger for the periods above.
Refusal and withdrawal: Turning off Google AI before submission sends no new data to Google. Withdrawing after submission stops later calls and you may request deletion of the application report, but it does not retroactively undo completed lawful processing, provider security logs, or mandatory retention. Declining payment consent does not open checkout and does not affect the free result.
5. Retention and deletion
Evidence summaries, stage writing, metaphor categories, self labels, reports, access tokens, and consent records are stored to provide the service and recover from errors. A report without payment history and its consent record, access token, and jobs are deleted after 30 days. An IndexedDB draft expires on the device after 24 hours and is deleted immediately on completion or restart. For a report with payment history, report content is irreversibly cleared after 90 days and access is revoked. Contract, payment, supply, and cancellation records are segregated for five years where required by Korean e-commerce law; complaint and dispute records remain for three years, then are deleted. Stage PNGs are not stored in the application database.
Destruction procedure and method
- Selecting records: Electronic information whose retention period has expired, purpose has been fulfilled, or valid deletion request has been accepted is selected under a destruction plan.
- CPO review: The representative acting as the personal information protection officer is responsible for reviewing scheduled-deletion results and statutory-retention exceptions. Runtime evidence for the scheduled job is recorded separately in the operational evidence.
- Destroying electronic information: Database rows, consent records, and generation jobs for reports without payment history are deleted and access tokens revoked. For a paid row, report content is separated from the statutory transaction ledger, cleared, and access revoked. Stage PNGs and raw stroke events are not placed in persistent file storage and are discarded from request memory when processing finishes.
- Device and paper: IndexedDB and sessionStorage data are deleted from browser storage. The operator does not create or retain application personal data on paper, so there is currently no paper record to destroy.
The explanation above covers active application storage controlled by the operator. Vercel and Supabase backup and disaster-recovery copies are access-restricted and rotated under each provider's official DPA and security and deletion procedures. The operator does not invent a fixed number of days that a provider has not published and will update this notice if those procedures materially change.
6. Optional product analytics
The current FREE service disables optional product analytics. The analytics SDK can load only when an explicit public analytics switch, an approved collection host, and a project key are all present. The current service does not display analytics consent, load an analytics SDK, or send analytics events externally. Before analytics is enabled, this notice will add the recipient, countries, items, purposes, and retention period and request separate optional consent under a new policy version. Drawings, stage writing, metaphor categories, self labels, camera values, report text, and report and payment identifiers will remain excluded.
7. Third-party disclosure, sensitive data, and automated decisions
The service does not sell personal information. Vercel and Supabase provide hosting, security, and database functions; Google performs separately consented AI processing; and Paddle acts as Merchant of Record for a checkout you start, all within §4. PostHog product analytics does not load without separate optional consent and the public enablement switch.
The service does not ask for or intentionally collect health or biometric data, resident registration numbers, passport numbers, driver's licence numbers, or alien registration numbers. Do not put identifiable names, contact details, account handles, faces, or health information in a drawing or writing. If such information appears in a transferred drawing image or text, it may transfer to Google within your optional consent. Reports are not used for automated decisions producing legal or similarly significant effects.
8. Essential cookies and browser storage
- 19+ self-attestation cookies:
socrates_adult_19_v1 and socrates_anon_session_v1 retain a server-signed pseudonymous session binding in HttpOnly, Secure, SameSite cookies for up to 30 days. - Submission consent-preflight cookie:
socrates_consent_preflight_v1 is an essential HttpOnly, Secure, SameSite=Strict cookie that binds the current consent version to the pseudonymous 19+ session. It is scoped to /api/analyze, lasts for at most two minutes, is deleted immediately after a successful submission, and otherwise expires. - Report-ownership cookie:
ownerToken_<reportId> is an HttpOnly, Secure, SameSite cookie used to authorize report access and deletion for up to 90 days and is cleared when the report is deleted. - Device storage: The IndexedDB draft expires and can no longer be restored after 24 hours, then is deleted on the next app or storage access as described in §1 and §5. The consent version and time and same-tab artwork preview in sessionStorage disappear when the tab is closed.
These are essential to an accountless session, security, access control, and draft resumption. You may clear this site's cookies and site data in your browser, but then must repeat age and consent checks and may lose access to an existing report or draft. The current service uses no advertising, personalized-advertising, or third-party analytics cookies.
9. Your rights and how to exercise them
You may request access, correction, deletion, restriction or suspension, withdrawal of consent, and, where applicable, transfer of your personal information. With a valid report-ownership cookie in the same browser, you can delete a report directly from its result page. Submit other requests to sswook6720@gmail.com. As an operating target, we acknowledge the request and provide a status within three business days.
Ten-day response and extension notice: Within 10 days after receiving an access request, the service will provide access or notify you of the information, method, and schedule for access. If a justifiable reason prevents access within that period, the service will notify you within the original 10 days of the reason for delay, the limited scope, and how to object, and will provide access without delay when the reason ends. Within 10 days after receiving a correction, deletion, or processing-suspension request, the service will notify you of the action taken or, when lawfully unable to comply, the specific reason and how to object.
Verifying you or a representative: Because there is no login account, the service first verifies you through a valid report-ownership capability. Without it, the service compares only the target report ID and the minimum information already held that is necessary to process the request; it does not ask you to email an identity-document copy. A legal representative or a person authorized by you may act through the form prescribed by Korea's Personal Information Protection Commission. Only the minimum information needed to verify the authority and scope of the request is checked.
Limitation, refusal, and objection: The service limits or refuses only the necessary part if access is prohibited or restricted by law, could unjustifiably harm another person's life, body, property, or other interests, or the accountless design does not permit verification that the requester is the data subject or a valid representative. Data that another law requires to be retained is segregated rather than deleted. To object, reply to the same email with Objection and the request reference. The representative acting as the personal information protection officer will review the scope and basis again and respond in writing. You may also use the external remedies in §12.
The service is intended only for adults aged 19 or older and does not knowingly process children's data. A parent or guardian who believes a child's data was processed may request deletion at the same address.
For a report without payment history, a valid deletion request removes the report, access token, and generation jobs together. For a report with payment history, only payment and refund records legally required for retention remain; connected report content is cleared and its access token is revoked. Withdrawal does not retroactively affect lawful processing already completed or records that must be retained by law.
10. Security measures
- Administrative: The representative acting as the personal information protection officer manages processing scope and processors and grants and removes access so only the minimum personnel required for operations may access data.
- Technical: The service uses TLS in transit; HttpOnly, Secure, SameSite cookies; one-way hashes for access tokens; short-lived HMAC rate-limit identifiers instead of raw IP storage; server-only secrets; database RLS and least privilege; and access logging.
- Physical: The operator does not keep application personal data on paper or removable media. Data-centre physical controls are provided under the processors' DPAs and security controls described in §4.
11. Effective date and change history
This notice (2026-08-24.en.v6) takes effect on socrates-canvas.com when the new consent screen is applied. It adds the actual processing scope for Google AI and optional drawing-image transfer, local camera use, and Paddle one-time payments. Saved stage PNGs are transferred without resizing or re-encoding; if the full request exceeds the transfer limit, they are not sent and the request stops with an error. If recipients, purposes, or items expand, the service will notify you and request consent again under a new policy version.
Public effective history
- 2026-08-26 implementation clarification: Pre-transfer resizing and re-encoding were removed, and an oversized original request now stops before network transfer. Because no recipient, purpose, or item expanded, the en.v6 consent version remains unchanged.
- 2026-08-24.en.v6: Adds separate optional Google AI and stage-PNG consent, the local-camera boundary, and Paddle payment, refund, and provider-specific international processing. Sessions consented under en.v5 must consent again before a new submission.
- 2026-08-12.en.v5: Described mandatory Vercel and Supabase processing and the 19+ pseudonymous session binding for FREE V3.
- 2026-07-21.v2: Full public V2 Privacy Notice. It applies from 21 July 2026 until immediately before the FREE V3 domain cutover; the exact end date and time are retained in the operational record.
Material-change comparison
This table compares the public V2 source with the material changes in 2026-08-24.en.v6.
| Area | Public V2 source · 21 July 2026 | Current 2026-08-24.en.v6 notice |
|---|
| Report and payment paths | It said external AI services might be used and that Paddle might process payment and tax. The providers named at the time remain available in the linked full public V2 notice. | It specifies optional Gemini and drawing-image processing, the no-image fallback, Paddle one-time checkout, and refund revocation. |
|---|
| Camera | It described an optional camera, possible transmission of per-stage V2 blendshape summary events, and legacy V1 expressions tags remaining until the V2 runtime transition. | It says the camera indicates face presence only on the device after explicit choice and sends or stores no frame or face value. |
|---|
| External-processing detail | It described possible use of AI providers, Paddle, Supabase, and Vercel, leaving provider-level details to be confirmed before paid public launch. | It separates the items, purposes, countries, timing, retention, and refusal effects for Vercel, Google Gemini, Supabase, and Paddle. |
|---|
Prior internal candidate summaries (not public effective history)
- 2026-08-12.en.v4 (internal candidate, never effective): Added FREE copy-bank Vercel and Supabase international processing, separated Vercel processor and controller roles, identified the privacy officer, described essential storage and rights, and corrected the 19+ proof to a pseudonymous session binding.
- 2026-08-07.en.v3 (internal candidate, never effective): Described the prior beta candidate's processing scope.
12. Privacy officer, complaints, and remedies
The personal information protection officer and privacy complaint contact is 서성욱 (representative). sswook6720@gmail.com is the intake address for privacy questions and access, correction, deletion, or restriction requests. The operator is responsible for handling valid requests under the procedure and deadlines in this notice and applicable law. The service does not invent an unverified phone number or department name.
The service is available only to adults aged 19 or older. Its minimal self-attestation proof uses a pseudonymous session binding and is not a substitute for identity or date-of-birth verification. Reports are non-medical self-reflection references and do not replace diagnosis, counselling, or treatment.