Privacy Policy
Effective: August 11, 2026 (revised) | Pursuant to Article 30 of the Personal Information Protection Act
This English translation is provided for convenience only. The legally binding version is the Korean original; in case of any discrepancy, the Korean version prevails.
PLEUM. AI Co., Ltd. (the "Company") establishes and discloses this Privacy Policy as follows, pursuant to Article 30 of the Personal Information Protection Act (PIPA), in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This Policy applies to the PleumRouter service (the "Service").
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes and does not use it for any other purpose. Where the purpose of use changes, the Company obtains separate consent pursuant to Article 18 of PIPA.
(1) Member registration and management (identity verification and authentication, prevention of fraudulent use, notices and notifications); (2) provision of the AI API routing service (request routing, issuance and management of API keys, usage measurement); (3) payment and settlement (charging and deducting prepaid credits, KRW payments, refunds); (4) issuance of tax invoices and transaction records; (5) customer support and complaint handling; (6) service improvement and security (detection of fraudulent or abnormal use, bot blocking).
Article 2 (Items of Personal Information Collected and Methods of Collection)
| Category | Items Collected | Method of Collection |
|---|---|---|
| Registration (email) | Email, password (one-way encrypted), display name | Registration form |
| Registration (social) | Social member identifier; provider email/display name (form prefill); final email/display name reviewed and submitted by the user (email verified with a six-digit code) | Kakao / Naver / Google / GitHub OAuth (identifier and prefill) and registration form / email verification (final details) |
| Payment | Payment approval details (method, approval number, amount, date/time) | Payment form (NICEPAY) |
| Business / tax invoice | Business registration number, company name, representative, address, contact person's details | Business verification form |
| Service use (automatic) | IP, access date/time, API request metadata (model, tokens, status), User-Agent, cookies | Automatic collection |
| Bot prevention | IP, browser information (Cloudflare Turnstile) | Automatic collection |
| Ad attribution (at signup) | Ad click referral data (UTM parameters: source, medium, campaign, content, term) | Collected automatically from the visit URL |
| Referral link (when selected) | Randomly generated pseudonymous referral Sub-ID added to the referral URL by Pleum (no email, name, or account ID; the exact parameter is operator-configured after provider confirmation), plus click technical data that may be processed in the tracking flow (IP, User-Agent, browser/OS/device, referrer/landing URL, time, country, and cookie/local-storage identifier) | Transferred only when the Member chooses the referral CTA and proceeds to the external provider site |
Email and display name from an OAuth provider are only prefill suggestions. The account email is the address the user confirms with a six-digit code; the account display name is the value the user reviews or edits and submits.
Sensitive payment information such as full card numbers is processed through the payment gateway NICEPAY Co., Ltd. (NICEPAY) and is not stored directly by the Company. API request bodies (prompts and generated results) are transmitted for routing purposes, and the Company processes the metadata necessary for billing and statistics.
Pursuant to Article 22 of PIPA, the Company collects consent items by distinguishing between mandatory and optional. (1) Mandatory: agreement to the Terms of Service, the personal information necessary for registration, payment, and operation as listed in the table above, and confirmation of being 14 years of age or older. (2) Optional: receipt of marketing information (email), the storage and analytical use of input content (prompts and responses) for service improvement, and disclosure of a nickname on the token-usage leaderboard. There is no restriction on use of the Service even without consent to optional items, and consent may be withdrawn at any time under 'Settings > Consent Management' after being granted. If you do not consent to the 'use of input content for service improvement,' the input and response bodies are not stored and only usage metadata is recorded.
Article 2-2 (Processing of Pseudonymized Information)
Pursuant to Article 28-2 of PIPA, the Company may process pseudonymized information without the consent of the data subject for purposes such as statistical compilation, scientific research (including industrial research such as research and development of model routing to improve service quality), and archiving in the public interest. Pseudonymized information means information processed so that a specific individual cannot be identified without additional information.
(1) Items processed: intent classification of API requests (code, translation, reasoning, creative writing, general, etc.), the number of input and output tokens, whether images are included, request parameters such as max tokens and temperature, the number of conversation turns, the request and response models, processing result signals (retry, evaluation, etc.), and irreversible hash values of prompts. The Company does not store the input or response bodies (original text).
(2) Method of pseudonymization: account identifiers (such as member IDs) are replaced with non-restorable pseudonymous keys, and direct identifying information is not included in the pseudonymized information.
(3) Ensuring safety and prohibition of re-identification: Pursuant to Article 28-4 of PIPA, the Company stores and manages pseudonymized information separately from additional information (such as information for generating or restoring pseudonymous keys), and pursuant to Article 28-5 of the same Act, does not process pseudonymized information for the purpose of identifying a specific individual. If, during processing, information identifying a specific individual is generated, the Company immediately ceases processing and recovers and destroys such information.
Article 3 (Period of Processing and Retention of Personal Information)
| Retained Item | Retention Period | Basis |
|---|---|---|
| Member information (email and password) | Until account closure | Consent of the data subject |
| Social linkage data (provider, social identifier, provider email) | Until unlinking or account closure | Consent of the data subject |
| Pleum local referral-click mapping (Member ↔ random pseudonymous referral Sub-ID) | Up to 180 days from creation (deleted when the account is closed; expired unconverted mappings are deleted by a bounded periodic job). Future conversion evidence follows a separately disclosed legal-retention policy | Referral attribution and prevention of duplicate or fraudulent conversions |
| Action reward deduplication marker (provider and SHA-256 hash of the social identifier) | Retained permanently (user ID removed when the account is closed) | Prevention of abuse and duplicate grants |
| Records of contracts and subscription withdrawals | 5 years | E-Commerce Act |
| Records of payment and supply of goods | 5 years | E-Commerce Act |
| Records of consumer complaints and dispute handling | 3 years | E-Commerce Act |
| Tax invoices and other transaction/record ledgers | 5 years | Framework Act on National Taxes; VAT Act |
| Electronic financial transaction records | 5 years | Electronic Financial Transactions Act |
| Access (login) records | 1 year or more | PIPA Article 29 and the Standards for Measures to Ensure Safety |
Personal information for which the retention period has elapsed or the purpose of processing has been achieved is destroyed without delay in accordance with Article 7.
Article 4 (Outsourcing of Personal Information Processing)
For the smooth provision of the Service, the Company outsources personal information processing tasks as follows. Pursuant to Article 26 of PIPA, the Company specifies in writing, in the outsourcing contract, matters such as the prohibition of processing beyond the purpose, protective measures, restrictions on re-outsourcing, and management and supervision, and supervises the trustees.
| Trustee | Outsourced Task | Note |
|---|---|---|
| NICEPAY Co., Ltd. (NICEPAY) | Payment gateway (PG), payment approval/cancellation, automatic payment (billing key) | Domestic |
| Resend, Inc. | Sending transactional, authentication, and notification emails | Overseas (USA) |
| Vercel, Inc. | Frontend hosting · API reverse proxy operation (pass-through only, no storage) | Domestic (Seoul · icn1) |
| Supabase, Inc. | Database (PostgreSQL) operation and storage | Domestic (Seoul · ap-northeast-2) |
| Alibaba Cloud International (Singapore) Private Limited | API server and Redis operation (ECS, Tair) | Domestic (Seoul · ap-northeast-2) |
| Railway Corporation (privacy@railway.com) | Standby frontend, API server, database, and Redis for disaster recovery (DR), and operation during an outage | Overseas (Singapore region · primarily operated from the USA) |
| Cloudflare, Inc. | Bot blocking and security (Turnstile) | Overseas (global edge) |
Article 5 (Provision to Third Parties and Cross-Border Transfer of Personal Information)
The Company does not provide personal information to third parties except with the consent of the data subject or on the basis of statute. Due to the nature of the AI API routing service, the request body (prompt) entered by a Member is transmitted to the AI model provider selected by the Member for processing, and some of this is transferred overseas. Because such cross-border transfer constitutes outsourcing necessary for the performance of the contract (provision of the Service), the Company, pursuant to Article 28-8(1)(iii) of PIPA, discloses the following matters through this Policy in lieu of separate consent to cross-border transfer.
| Recipient (Contact) | Items Transferred / Purpose of Use | Country of Transfer | Use of Input for Model Training | Retention / Use Period |
|---|---|---|---|---|
| OpenAI, L.L.C. (privacy@openai.com) | API request body (prompt) — generation of model responses | USA | Not used (only with explicit consent) | Destroyed after 30 days of abuse monitoring |
| Anthropic, PBC (privacy@anthropic.com) | API request body (prompt) — generation of model responses | USA (storage); USA/EU/Asia/Australia (inference routing) | Not used (paid API) | Destroyed after 30 days |
| Google LLC (googlecloud-compliance@google.com) | API request body (prompt) — generation of model responses | Global (any country where Google facilities are located, no guarantee) | Not used (paid API; free tier subject to training and human review) | Destroyed after 55 days of policy-enforcement monitoring |
| DeepSeek (Hangzhou DeepSeek AI · service@deepseek.com) | API request body (prompt) — generation of model responses | China | Used (no opt-out option) | Retention period not specified |
| MiniMax (Nanonoble Pte. Ltd. · api@minimax.io) | API request body (prompt / TTS text) — generation of model responses and speech | USA (operated by a Singapore entity) | Unclear (possible use) | Until the purpose is achieved |
| Alibaba Cloud Singapore (Model Studio · dashscope-intl.aliyuncs.com) | API request body (prompt) — generation of Qwen model responses | Singapore (storage); global outside mainland China (inference) | Not used | Not stored after transmission |
| Z.ai (Jingsheng Hengxing Technology Pte. Ltd. · api.z.ai) | API request body (prompt) — generation of GLM model responses | Singapore (onward overseas transfer to affiliates/third parties possible) | Not used (enterprise/developer API) | Not stored after transmission (DPA) |
| NAVER Cloud Corp. (dl_ncloud_privacy@navercorp.com) | API request body (prompt) — generation of HyperCLOVA X (CLOVA Studio) model responses | Republic of Korea (domestic processing — no cross-border transfer due to model inference; however, NAVER Cloud's privacy policy contains a clause for backup transfer of minimal data to Singapore for disaster/disaster-recovery purposes) | Unclear (the terms do not specify whether inference input is used for training, nor an opt-out option) | Not specified (no official document specifying a retention period dedicated to API input/output was confirmed) |
| Upstage, Inc. (help@upstage.ai) | API request body (prompt) — generation of Solar model responses | USA (inference infrastructure such as AWS) | Not used (synchronous API) | Not stored after transmission |
| X.AI LLC (privacy@x.ai) | API request body (prompt) — generation of Grok/Composer model responses | USA | Not used (only with explicit permission) | Destroyed after 30 days |
| Mistral AI SAS (privacy@mistral.ai) | API request body (prompt / TTS text) — generation of model responses and speech | France/EU | Not used (paid API) | Destroyed after 30 days of abuse monitoring |
| Moonshot AI PTE. LTD. · Kimi (api.moonshot.ai) | API request body (prompt) — generation of Kimi model responses | Singapore | Used (no opt-out option) | Retention period not specified |
| Perplexity AI, Inc. (support@perplexity.ai) | API request body (prompt) — generation of Sonar model responses | USA | Not used (Sonar API Zero-Data-Retention) | Not stored after transmission |
| Eleven Labs Inc. (legal@elevenlabs.io) | API request body (TTS text / STT audio) — voice synthesis and recognition | USA | Used (standard API; opt-out available on Enterprise) | Retained per policy |
| Cartesia, Inc. (cartesia.ai) | API request body (TTS text / voice settings) — voice synthesis | USA (default processing; confirm region/DPA in contract) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Fish Audio (fish.audio) | API request body (TTS text / voice settings) — voice synthesis | Global (public API processing region not confirmed; confirm before contracting) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Inworld AI (inworld.ai) | API request body (TTS text / voice settings) — voice synthesis | USA (default processing) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Soniox, Inc. (soniox.com) | API request body (TTS text / voice settings) — voice synthesis | USA (default processing; EU/Japan regional option available) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Speechify, Inc. (speechify.com) | API request body (TTS text / voice settings) — voice synthesis | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Resemble AI (resemble.ai) | API request body (TTS text / voice settings) — voice synthesis | USA (default processing; confirm other transfers in policy and contract) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Gradium (gradium.ai) | API request body (TTS text / voice settings) — voice synthesis | API processing country not confirmed in public official materials (confirm before contracting) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| StepFun (stepfun.com) | API request body (TTS text / voice settings) — voice synthesis | China | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| KLING AI PTE. LTD. (support@kling.ai) | API request body (video prompt) — video generation | Singapore (residual processing in China cannot be ruled out) | Unclear (no guarantee of non-use for training) | Retained per policy |
| Lightricks Ltd. / LTX (dpo@lightricks.com) | API request body (video prompt / audio-generation setting) — LTX 2.3 video generation | Global (the API does not disclose a fixed inference region; LTX says processing/storage may involve affiliates, partners, and service providers in other countries) | May be used subject to terms/consent; no API-specific non-training commitment found | Job status and output URL available for 24 hours after terminal status; API input retention not publicly specified |
| FriendliAI Corp (privacy@friendli.ai) | API request body (prompt) — generation of EXAONE model responses | USA (inference infrastructure) | Unclear (no explicit statement of non-use for training) | Retained per policy |
| DeepInfra, Inc. (deepinfra.com) | API request body (prompt) — generation of NVIDIA Nemotron model responses | USA | Not used (inference hosting · no training of own models) | Retained per policy |
| BytePlus Pte. Ltd. (ModelArk) | API request body (text, image, video, audio, and 3D references) and request metadata — ModelArk response, image, video, embedding, and 3D generation | ap-southeast-1 (Johor, Malaysia); cross-region processing in EU regions may occur according to resource availability | Unclear | Retained per policy |
| Cohere Inc. (privacy@cohere.com) | API request body (prompt / rerank query & documents) — generation of Command model responses and rerank results | Canada (HQ) · USA (GCP cloud infrastructure) | Used (opt-out available in Data Controls) | Auto-deleted after 30 days for Enterprise users |
| AI21 Labs Ltd. (privacy@ai21.com) | API request body (prompt) — generation of Jamba and other model responses | USA | Not used (paid API) | Retained per policy |
| Reka AI, Inc. (reka.ai) | API request body (prompt) — generation of Reka model responses | USA | Unclear (confirm public policy and contract) | Retained per policy |
| Baichuan Intelligence (baichuan-ai.com) | API request body (prompt) — generation of Baichuan model responses | China | Used (no opt-out option) | Retention period not specified |
| Baidu, Inc. (ERNIE · privacy.baidu.com) | API request body (prompt) — generation of ERNIE model responses | China | Unclear (confirm public policy and contract) | Retained per policy |
| Tencent (Hunyuan · privacy.qq.com) | API request body (prompt) — generation of Hunyuan model responses | China | Unclear (confirm public policy and contract) | Retained per policy |
| 01.AI (零一万物 · Yi · 01.ai) | API request body (prompt) — generation of Yi model responses | China | Unclear (confirm public policy and contract) | Retention period not specified |
| Inception Labs (inceptionlabs.ai) | API request body (prompt) — generation of Mercury and other model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Nous Research, Inc. (nousresearch.com) | API request body (prompt) — generation of Hermes and other model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Cerebras Systems, Inc. (cerebras.ai) | API request body (prompt) — generation of Cerebras model responses | USA | Not used (inference API) | Retained per policy |
| Groq, Inc. (groq.com) | API request body (prompt) — generation of Groq inference model responses | USA | Not used (inference-only) | Not stored after transmission |
| Together AI, Inc. (together.ai) | API request body (prompt) — generation of open-source and hosted model responses | USA | Used (Zero Data Retention option available) | Retained per policy |
| Fireworks AI, Inc. (fireworks.ai) | API request body (prompt) — generation of Fireworks-hosted model responses | USA | Not used (Enterprise ZDR option) | Retained per policy |
| Hyperbolic Labs (hyperbolic.ai) | API request body (prompt) — generation of Hyperbolic-hosted model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Nebius Group N.V. (nebius.com) | API request body (prompt) — generation of Nebius-hosted model responses | Netherlands/EU | Unclear (confirm public policy and contract) | Retained per policy |
| GMI Cloud (gmicloud.ai) | API request body (prompt) — generation of GMI-hosted model responses | China/Singapore (confirm processing region in contract) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| SiliconFlow (siliconflow.cn) | API request body (prompt) — generation of SiliconFlow-hosted model responses | China/Singapore (confirm processing region in contract) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Avian (avian.io) | API request body (prompt) — generation of Avian-hosted model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Baseten Labs, Inc. (baseten.co) | API request body (prompt) — generation of Baseten-hosted model responses | USA | Unclear (confirm public policy and contract) | Retained per policy |
| Parasail (parasail.io) | API request body (prompt) — generation of Parasail-hosted model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Inference.net (inferencenet.ai) | API request body (prompt) — generation of Inference.net-hosted model responses | USA | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Lambda Labs, Inc. (lambdalabs.com) | API request body (prompt) — generation of Lambda-hosted model responses | USA | Unclear (confirm public policy and contract) | Retained per policy |
| SambaNova Systems, Inc. (sambanova.ai) | API request body (prompt) — generation of SambaNova model responses | USA | Unclear (confirm public policy and contract) | Retained per policy |
| DigitalOcean, LLC (Gradient AI · digitalocean.com) | API request body (prompt) — generation of Gradient AI-hosted model responses | USA | Unclear (confirm public policy and contract) | Retained per policy |
| Novita AI (novita.ai) | API request body (prompt) — generation of Novita-hosted model responses | Singapore/China (confirm processing region in contract) | Unclear (confirm public policy and contract) | Unclear (confirm policy and contract) |
| Tapfiliate B.V. (data-support@tapfiliate.com · tapfiliate.com/privacy-policy) | Randomly generated pseudonymous referral Sub-ID added to the referral URL by Pleum (no email, name, Pleum account ID, or API request body; the exact parameter is operator-configured after provider confirmation), referral/click identifiers, click time, cookie/local-storage identifier, IP, User-Agent, browser, OS, device, referrer/landing URL, and IP-derived country — referral-click and first-paid conversion attribution, referral-bonus verification, and fraud prevention | Netherlands (recipient entity) · Ireland (core AWS processing/storage; Tapfiliate separately lists US subprocessors, while referral-data-specific onward transfers require DPA confirmation) | Not applicable (no model-training input is transferred) | Tapfiliate publishes no fixed server click/event retention period: its public policy says data is erased when no longer necessary or legally permitted, with processing restricted for legal retention; tracking cookies follow the advertiser-configured period. Pleum's local mapping follows the separate period in Article 3 |
| Amazon Web Services, Inc. (AWS Bedrock · aws.amazon.com/bedrock) | API request body (prompt) — generation of Bedrock model responses | USA (global regions possible) | Not used (Bedrock default) | Per AWS policy |
| Vultr Holdings, LLC (vultr.com) | API request body (prompt) — generation of Vultr Serverless Inference-hosted model responses | USA (global inference regions possible) | Unclear (confirm public policy and contract) | Retained per policy |
(1) Timing and method of transfer: data is transmitted in real time over HTTPS (TLS) encrypted communication at the moment the Member calls the API.
(2) Recipient's purpose of use: limited to the generation of responses (inference) for the model selected by the Member. The Company uses, to the extent possible, enterprise API routes in which input is not used for training (opt-out / Zero-Data-Retention, etc.); however, some model providers use input for model improvement and training, or it is unclear whether they do so. Whether each provider uses input for training is indicated in the 'Use of Input for Model Training' column of the table above, and Members can review this and select models accordingly (if you do not want your input used for training, select only models for which that column reads 'Not used').
(3) Method, procedure, and effect of refusing transfer: A Member may (a) enable the 'PII Masking' option per API key so that sensitive information is masked before transmission, or (b) select only models that are inferred and processed domestically without cross-border transfer, thereby avoiding cross-border transfer to model providers (even a model offered by a Korean business is listed as subject to cross-border transfer in the table above where its inference infrastructure is located overseas — e.g., Upstage Solar is processed on US infrastructure). However, overseas storage on the service operating infrastructure under (5) below is unavoidable for the provision of the Service (performance of the contract) and is not subject to avoidance. If transfer is refused, the relevant overseas models cannot be used, but there is no restriction on other use of the Service.
(4) The Company limits the personal information transferred overseas to the minimum necessary to achieve the purpose of processing. Where a Member has not consented to the 'use of input content for service improvement,' the Company does not store the input or response bodies and retains only usage metadata (model, tokens, cost, time, etc.). In addition, the pseudonymized information processed by the Company for statistical and research purposes under Article 2-2 does not include input or response bodies, and such pseudonymized information may, pursuant to Article 28-2 of PIPA, be processed without separate consent for cross-border transfer.
(5) Domestic processing of primary service infrastructure and cross-border transfer to disaster-recovery infrastructure: The Company's primary cloud infrastructure (servers and databases) is operated in the Seoul region (Republic of Korea, icn1 / ap-northeast-2) via Vercel, Supabase, and Alibaba Cloud. Accordingly, the primary storage location for account information, usage records, consent history, and input/response bodies stored pursuant to (4) above is domestic (see the table in Article 4 above for processors). However, the Company uses Railway as overseas disaster-recovery (DR) infrastructure to maintain service continuity during disasters and outages and discloses the transfer pursuant to Article 28-8(1)(iii) of PIPA — Recipient: Railway Corporation (privacy@railway.com) / Country of transfer: Singapore (selected hosting region) and the USA (Railway's primary country of operation) / Items transferred: account information (email and display name), authentication and session information, usage records and consent history, payment and credit ledgers, API request metadata, and input/response bodies stored pursuant to (4) above; while DR is active, authentication information and API request bodies are processed through the frontend BFF and API server / Timing and method: transferred over encrypted communications such as HTTPS (TLS) during the one-time initial backup and continuous logical replication, and during DR cutover and operation / Purpose of use: maintaining a replicated DR data copy and standby infrastructure and securing service continuity by operating the frontend BFF, API server, database, and Redis during an outage / Retention and use period: the Railway replica continuously reflects creates, updates, and deletions from the primary system; each item is retained for the applicable period in Article 3 or until membership withdrawal and is destroyed without delay when the DR purpose is achieved or the Railway contract ends (subject to Railway's DPA and legal retention obligations) / Method and effect of refusal: DR infrastructure is unavoidable for service continuity, so a refusal will be handled as withdrawal of membership. In addition, email delivery (Resend, Inc. · USA), bot blocking (Cloudflare, Inc. · global edge), website usage analytics (Google LLC · Google Analytics, USA), and service error tracking (Functional Software, Inc. · Sentry, USA) are processed overseas and are disclosed as follows — Recipient: Resend, Inc. (US entity) / Cloudflare, Inc. (global edge) / Google LLC (Google Analytics) / Functional Software, Inc. (Sentry) / Country of transfer: USA (Resend, Google, Sentry) · global edge (Cloudflare) / Items transferred: recipient email address and other minimal information necessary for delivery (Resend) · IP address, browser information, and other security-determination data (Cloudflare) · visited page addresses (URLs), event information, browser and device information (Google Analytics) · built-in exception type, occurrence time, severity, and line/column numbers for server and Edge errors (Sentry — nothing is sent from browsers; error messages, filenames, function names, URLs/requests, user-identifying information, API request bodies, and prompts are removed before transmission) / Timing and method: transmitted in real time over HTTPS (TLS) at the time of sending, access, or error occurrence / Purpose of use: transactional, authentication, and notice email delivery (Resend) · bot blocking and security (Cloudflare) · usage analytics (Google Analytics) · error tracking for service quality improvement (Sentry) / Retention period: destroyed upon withdrawal of membership or expiry of the retention period (Articles 3 and 7) · Google Analytics and Sentry are subject to each company's data retention policy / Method and effect of refusal: as email delivery, bot blocking, and error tracking are unavoidable for provision of the Service (notices, security, quality management), a refusal will be handled as withdrawal of membership. Usage analytics (Google Analytics) may be refused by blocking browser cookies, and refusal does not restrict your use of the Service.
(6) Cross-border transfer of behavioral information for advertising performance measurement and personalized advertising: Where the Company operates Meta Pixel pursuant to Article 9, behavioral information is transmitted directly from the user's browser to Meta and processed overseas. The matters under each subparagraph of Article 28-8(2) of PIPA are disclosed as follows — Recipient: Meta Platforms, Inc. (USA · facebook.com/privacy/policy) / Country of transfer: USA / Items transferred: visited page addresses (URLs), in-service event information (the occurrence of conversion events such as sign-up and credit top-up), browser and device information, and online identifiers such as cookies (the behavioral information under Article 9 — API request bodies (prompts) are not included) / Timing and method of transfer: transmitted in real time over HTTPS (TLS) from the user's browser upon website visits and event occurrences / Recipient's purpose of use: measurement of advertising performance (conversion tracking) and provision of personalized advertising / Retention and use period: in accordance with Meta's privacy policy and data policy / Method, procedure, and effect of refusal: you may refuse by the methods under Article 9(3) (blocking cookies in the browser; Meta ad settings), and refusal does not restrict your use of the Service.
(7) Disclosure of a nickname for the token-usage leaderboard (provision to third parties): Where a Member has consented to 'disclosure of a nickname on the token-usage leaderboard' (Terms of Service Article 14(7)), the Company, pursuant to Articles 17 (provision to a third party) and 22 of PIPA, displays the Member's configured nickname (or a masked display derived from the email where none is set) and the token-usage rank and statistics on the leaderboard of a public web page. Recipient: an unspecified number of persons (visitors to the leaderboard page) / Items provided: nickname (or masked email display), rank, and token-usage statistics (no other identifying information such as email, account ID, or contact details is provided) / Purpose of use: displaying token-usage rankings among Members / Retention and use period: until consent is withdrawn or the Member withdraws membership (the Member's nickname and rank are removed from the leaderboard immediately upon withdrawal) / Method and effect of refusal: you may withdraw at any time under 'Settings > Consent Management'; refusing (non-consent or withdrawal) only means the Member's rank is not displayed on the leaderboard and does not restrict use of the Service. This disclosure takes place on domestic infrastructure and does not constitute a cross-border transfer.
(8) Optional referral-link tracking (Tapfiliate): Referral tracking starts only when a Member affirmatively chooses the referral CTA and proceeds to the external provider site. At this stage, Pleum adds only a server-generated random pseudonymous referral Sub-ID to the referral URL; the exact parameter is operator-configured after provider confirmation. Pleum adds no email, name, account ID, or API request body. The browser then transmits the URL externally over HTTPS (TLS), and the advertiser-side Tapfiliate integration may process the click technical data listed in the table above. The purposes are attribution of the referral click and first paid conversion, verification of any referral bonus, and prevention of duplicate or fraudulent conversions. A Member may refuse the tracking and cross-border transfer by not choosing the referral CTA. Refusal means that referral attribution and the resulting Pleum referral bonus are unavailable, but does not restrict access to BYOK plan information or any other use of the Service. Blocking cookies may disrupt later conversion attribution but does not block the initial click transfer for a referral link already chosen. The recipient, countries, and retention period are stated in the Tapfiliate row above.
Article 6 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)
(1) A data subject may at any time request access to, correction, deletion, or suspension of processing of personal information, and withdraw consent (Articles 35, 36, and 37 of PIPA). Where you withdraw consent to leaderboard nickname disclosure or withdraw membership, your nickname and rank are removed from the leaderboard immediately.
(2) Rights may be exercised through the in-service settings or by contacting the Privacy Officer below, and the Company takes action without delay (within 10 days). When exercised through a representative, a power of attorney must be submitted.
(3) For a child under 14 years of age, a legal representative exercises the rights.
Article 7 (Procedure and Method of Destroying Personal Information)
(1) When personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the purpose of processing, the Company destroys it without delay. Information retained pursuant to other statutes is stored and managed separately.
(2) Electronic files are permanently deleted by technical means that prevent recovery, and paper documents are shredded or incinerated.
Article 8 (Measures to Ensure the Safety of Personal Information)
The Company takes measures including: (1) establishing and implementing an internal management plan and minimizing the number of staff handling data; (2) one-way encryption of passwords (bcrypt), encryption of transmission channels (SSL/TLS), and hashed storage of API keys; (3) differentiated granting of access rights and access control; (4) intrusion blocking and detection and bot blocking (Cloudflare Turnstile); and (5) retention of access logs and prevention of forgery or alteration.
Article 9 (Devices for Automatic Collection of Personal Information — Cookies)
(1) The Company uses cookies and other devices that automatically collect personal information to maintain login sessions, perform security verification, analyze usage statistics, and provide personalized advertising (collection of behavioral information). A data subject may refuse or delete the storage of cookies in their web browser settings, but in that case there may be restrictions on the use of some services that require login.
(2) Collection and use of behavioral information for online personalized advertising: To measure advertising performance and provide personalized advertising, the Company installs and operates on its website Meta Pixel, an advertising tool of Meta Platforms, Inc., thereby allowing Meta to collect and process users' behavioral information. — Items of behavioral information collected: visited page addresses (URLs) and visit/usage records, in-service event information (the occurrence of conversion events such as sign-up and credit top-up), browser and device information, and online identifiers such as cookies / Method of collection: collected and transmitted automatically via the Meta Pixel script when a user visits the website / Purpose of collection: measurement of advertising performance (conversion tracking) and provision of personalized advertising based on user interests / Retention and use period: the Company does not itself store behavioral information; Meta retains and uses it in accordance with its own privacy policy and data policy. The Company does not collect API request bodies (prompts) or other contents of Service use as behavioral information, nor use them for advertising purposes.
(3) How to refuse the collection of behavioral information (exercise of control): (a) block or delete cookies in your web browser settings (including blocking third-party cookies); (b) restrict the display of personalized ads and data connections in your Meta account's ad settings (facebook.com/adpreferences). Refusal does not restrict your use of the Service, although non-personalized general ads may still be displayed. For harm or inquiries related to behavioral information, you may contact the Privacy Officer under Article 10.
Article 10 (Privacy Officer)
The Company designates a Privacy Officer to oversee tasks related to personal information processing and to handle complaints and remedy damage of data subjects. (Pursuant to Article 31 of PIPA, Won-young Lee, Representative Director of PLEUM. AI Co., Ltd., serves as the Privacy Officer.)
Privacy Officer: 이원영 (Representative Director)
Contact: support@pleum.ai · 010-4869-1806
Article 11 (Methods of Remedy for Infringement of Rights)
A data subject may apply to the following organizations for dispute resolution or consultation to remedy infringement of personal information: Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Supreme Prosecutors' Office Cyber Investigation Division (1301), and National Police Agency Cyber Investigation Bureau (182, ecrm.police.go.kr).
Article 12 (Changes to the Privacy Policy)
This Privacy Policy was established on June 15, 2026 and applies as revised from August 11, 2026. Any changes will be announced through service notices from 7 days (or 30 days for significant changes) before they take effect.