Skip to content

Privacy Policy

Effective: August 11, 2026 (revised) | Pursuant to Article 30 of the Personal Information Protection Act

This English translation is provided for convenience only. The legally binding version is the Korean original; in case of any discrepancy, the Korean version prevails.

PLEUM. AI Co., Ltd. (the "Company") establishes and discloses this Privacy Policy as follows, pursuant to Article 30 of the Personal Information Protection Act (PIPA), in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This Policy applies to the PleumRouter service (the "Service").

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes and does not use it for any other purpose. Where the purpose of use changes, the Company obtains separate consent pursuant to Article 18 of PIPA.

(1) Member registration and management (identity verification and authentication, prevention of fraudulent use, notices and notifications); (2) provision of the AI API routing service (request routing, issuance and management of API keys, usage measurement); (3) payment and settlement (charging and deducting prepaid credits, KRW payments, refunds); (4) issuance of tax invoices and transaction records; (5) customer support and complaint handling; (6) service improvement and security (detection of fraudulent or abnormal use, bot blocking).

Article 2 (Items of Personal Information Collected and Methods of Collection)

CategoryItems CollectedMethod of Collection
Registration (email)Email, password (one-way encrypted), display nameRegistration form
Registration (social)Social member identifier; provider email/display name (form prefill); final email/display name reviewed and submitted by the user (email verified with a six-digit code)Kakao / Naver / Google / GitHub OAuth (identifier and prefill) and registration form / email verification (final details)
PaymentPayment approval details (method, approval number, amount, date/time)Payment form (NICEPAY)
Business / tax invoiceBusiness registration number, company name, representative, address, contact person's detailsBusiness verification form
Service use (automatic)IP, access date/time, API request metadata (model, tokens, status), User-Agent, cookiesAutomatic collection
Bot preventionIP, browser information (Cloudflare Turnstile)Automatic collection
Ad attribution (at signup)Ad click referral data (UTM parameters: source, medium, campaign, content, term)Collected automatically from the visit URL
Referral link (when selected)Randomly generated pseudonymous referral Sub-ID added to the referral URL by Pleum (no email, name, or account ID; the exact parameter is operator-configured after provider confirmation), plus click technical data that may be processed in the tracking flow (IP, User-Agent, browser/OS/device, referrer/landing URL, time, country, and cookie/local-storage identifier)Transferred only when the Member chooses the referral CTA and proceeds to the external provider site

Email and display name from an OAuth provider are only prefill suggestions. The account email is the address the user confirms with a six-digit code; the account display name is the value the user reviews or edits and submits.

Sensitive payment information such as full card numbers is processed through the payment gateway NICEPAY Co., Ltd. (NICEPAY) and is not stored directly by the Company. API request bodies (prompts and generated results) are transmitted for routing purposes, and the Company processes the metadata necessary for billing and statistics.

Pursuant to Article 22 of PIPA, the Company collects consent items by distinguishing between mandatory and optional. (1) Mandatory: agreement to the Terms of Service, the personal information necessary for registration, payment, and operation as listed in the table above, and confirmation of being 14 years of age or older. (2) Optional: receipt of marketing information (email), the storage and analytical use of input content (prompts and responses) for service improvement, and disclosure of a nickname on the token-usage leaderboard. There is no restriction on use of the Service even without consent to optional items, and consent may be withdrawn at any time under 'Settings > Consent Management' after being granted. If you do not consent to the 'use of input content for service improvement,' the input and response bodies are not stored and only usage metadata is recorded.

Article 2-2 (Processing of Pseudonymized Information)

Pursuant to Article 28-2 of PIPA, the Company may process pseudonymized information without the consent of the data subject for purposes such as statistical compilation, scientific research (including industrial research such as research and development of model routing to improve service quality), and archiving in the public interest. Pseudonymized information means information processed so that a specific individual cannot be identified without additional information.

(1) Items processed: intent classification of API requests (code, translation, reasoning, creative writing, general, etc.), the number of input and output tokens, whether images are included, request parameters such as max tokens and temperature, the number of conversation turns, the request and response models, processing result signals (retry, evaluation, etc.), and irreversible hash values of prompts. The Company does not store the input or response bodies (original text).

(2) Method of pseudonymization: account identifiers (such as member IDs) are replaced with non-restorable pseudonymous keys, and direct identifying information is not included in the pseudonymized information.

(3) Ensuring safety and prohibition of re-identification: Pursuant to Article 28-4 of PIPA, the Company stores and manages pseudonymized information separately from additional information (such as information for generating or restoring pseudonymous keys), and pursuant to Article 28-5 of the same Act, does not process pseudonymized information for the purpose of identifying a specific individual. If, during processing, information identifying a specific individual is generated, the Company immediately ceases processing and recovers and destroys such information.

Article 3 (Period of Processing and Retention of Personal Information)

Retained ItemRetention PeriodBasis
Member information (email and password)Until account closureConsent of the data subject
Social linkage data (provider, social identifier, provider email)Until unlinking or account closureConsent of the data subject
Pleum local referral-click mapping (Member ↔ random pseudonymous referral Sub-ID)Up to 180 days from creation (deleted when the account is closed; expired unconverted mappings are deleted by a bounded periodic job). Future conversion evidence follows a separately disclosed legal-retention policyReferral attribution and prevention of duplicate or fraudulent conversions
Action reward deduplication marker (provider and SHA-256 hash of the social identifier)Retained permanently (user ID removed when the account is closed)Prevention of abuse and duplicate grants
Records of contracts and subscription withdrawals5 yearsE-Commerce Act
Records of payment and supply of goods5 yearsE-Commerce Act
Records of consumer complaints and dispute handling3 yearsE-Commerce Act
Tax invoices and other transaction/record ledgers5 yearsFramework Act on National Taxes; VAT Act
Electronic financial transaction records5 yearsElectronic Financial Transactions Act
Access (login) records1 year or morePIPA Article 29 and the Standards for Measures to Ensure Safety

Personal information for which the retention period has elapsed or the purpose of processing has been achieved is destroyed without delay in accordance with Article 7.

Article 4 (Outsourcing of Personal Information Processing)

For the smooth provision of the Service, the Company outsources personal information processing tasks as follows. Pursuant to Article 26 of PIPA, the Company specifies in writing, in the outsourcing contract, matters such as the prohibition of processing beyond the purpose, protective measures, restrictions on re-outsourcing, and management and supervision, and supervises the trustees.

TrusteeOutsourced TaskNote
NICEPAY Co., Ltd. (NICEPAY)Payment gateway (PG), payment approval/cancellation, automatic payment (billing key)Domestic
Resend, Inc.Sending transactional, authentication, and notification emailsOverseas (USA)
Vercel, Inc.Frontend hosting · API reverse proxy operation (pass-through only, no storage)Domestic (Seoul · icn1)
Supabase, Inc.Database (PostgreSQL) operation and storageDomestic (Seoul · ap-northeast-2)
Alibaba Cloud International (Singapore) Private LimitedAPI server and Redis operation (ECS, Tair)Domestic (Seoul · ap-northeast-2)
Railway Corporation (privacy@railway.com)Standby frontend, API server, database, and Redis for disaster recovery (DR), and operation during an outageOverseas (Singapore region · primarily operated from the USA)
Cloudflare, Inc.Bot blocking and security (Turnstile)Overseas (global edge)

Article 5 (Provision to Third Parties and Cross-Border Transfer of Personal Information)

The Company does not provide personal information to third parties except with the consent of the data subject or on the basis of statute. Due to the nature of the AI API routing service, the request body (prompt) entered by a Member is transmitted to the AI model provider selected by the Member for processing, and some of this is transferred overseas. Because such cross-border transfer constitutes outsourcing necessary for the performance of the contract (provision of the Service), the Company, pursuant to Article 28-8(1)(iii) of PIPA, discloses the following matters through this Policy in lieu of separate consent to cross-border transfer.

Recipient (Contact)Items Transferred / Purpose of UseCountry of TransferUse of Input for Model TrainingRetention / Use Period
OpenAI, L.L.C. (privacy@openai.com)API request body (prompt) — generation of model responsesUSANot used (only with explicit consent)Destroyed after 30 days of abuse monitoring
Anthropic, PBC (privacy@anthropic.com)API request body (prompt) — generation of model responsesUSA (storage); USA/EU/Asia/Australia (inference routing)Not used (paid API)Destroyed after 30 days
Google LLC (googlecloud-compliance@google.com)API request body (prompt) — generation of model responsesGlobal (any country where Google facilities are located, no guarantee)Not used (paid API; free tier subject to training and human review)Destroyed after 55 days of policy-enforcement monitoring
DeepSeek (Hangzhou DeepSeek AI · service@deepseek.com)API request body (prompt) — generation of model responsesChinaUsed (no opt-out option)Retention period not specified
MiniMax (Nanonoble Pte. Ltd. · api@minimax.io)API request body (prompt / TTS text) — generation of model responses and speechUSA (operated by a Singapore entity)Unclear (possible use)Until the purpose is achieved
Alibaba Cloud Singapore (Model Studio · dashscope-intl.aliyuncs.com)API request body (prompt) — generation of Qwen model responsesSingapore (storage); global outside mainland China (inference)Not usedNot stored after transmission
Z.ai (Jingsheng Hengxing Technology Pte. Ltd. · api.z.ai)API request body (prompt) — generation of GLM model responsesSingapore (onward overseas transfer to affiliates/third parties possible)Not used (enterprise/developer API)Not stored after transmission (DPA)
NAVER Cloud Corp. (dl_ncloud_privacy@navercorp.com)API request body (prompt) — generation of HyperCLOVA X (CLOVA Studio) model responsesRepublic of Korea (domestic processing — no cross-border transfer due to model inference; however, NAVER Cloud's privacy policy contains a clause for backup transfer of minimal data to Singapore for disaster/disaster-recovery purposes)Unclear (the terms do not specify whether inference input is used for training, nor an opt-out option)Not specified (no official document specifying a retention period dedicated to API input/output was confirmed)
Upstage, Inc. (help@upstage.ai)API request body (prompt) — generation of Solar model responsesUSA (inference infrastructure such as AWS)Not used (synchronous API)Not stored after transmission
X.AI LLC (privacy@x.ai)API request body (prompt) — generation of Grok/Composer model responsesUSANot used (only with explicit permission)Destroyed after 30 days
Mistral AI SAS (privacy@mistral.ai)API request body (prompt / TTS text) — generation of model responses and speechFrance/EUNot used (paid API)Destroyed after 30 days of abuse monitoring
Moonshot AI PTE. LTD. · Kimi (api.moonshot.ai)API request body (prompt) — generation of Kimi model responsesSingaporeUsed (no opt-out option)Retention period not specified
Perplexity AI, Inc. (support@perplexity.ai)API request body (prompt) — generation of Sonar model responsesUSANot used (Sonar API Zero-Data-Retention)Not stored after transmission
Eleven Labs Inc. (legal@elevenlabs.io)API request body (TTS text / STT audio) — voice synthesis and recognitionUSAUsed (standard API; opt-out available on Enterprise)Retained per policy
Cartesia, Inc. (cartesia.ai)API request body (TTS text / voice settings) — voice synthesisUSA (default processing; confirm region/DPA in contract)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Fish Audio (fish.audio)API request body (TTS text / voice settings) — voice synthesisGlobal (public API processing region not confirmed; confirm before contracting)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Inworld AI (inworld.ai)API request body (TTS text / voice settings) — voice synthesisUSA (default processing)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Soniox, Inc. (soniox.com)API request body (TTS text / voice settings) — voice synthesisUSA (default processing; EU/Japan regional option available)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Speechify, Inc. (speechify.com)API request body (TTS text / voice settings) — voice synthesisUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Resemble AI (resemble.ai)API request body (TTS text / voice settings) — voice synthesisUSA (default processing; confirm other transfers in policy and contract)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Gradium (gradium.ai)API request body (TTS text / voice settings) — voice synthesisAPI processing country not confirmed in public official materials (confirm before contracting)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
StepFun (stepfun.com)API request body (TTS text / voice settings) — voice synthesisChinaUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
KLING AI PTE. LTD. (support@kling.ai)API request body (video prompt) — video generationSingapore (residual processing in China cannot be ruled out)Unclear (no guarantee of non-use for training)Retained per policy
Lightricks Ltd. / LTX (dpo@lightricks.com)API request body (video prompt / audio-generation setting) — LTX 2.3 video generationGlobal (the API does not disclose a fixed inference region; LTX says processing/storage may involve affiliates, partners, and service providers in other countries)May be used subject to terms/consent; no API-specific non-training commitment foundJob status and output URL available for 24 hours after terminal status; API input retention not publicly specified
FriendliAI Corp (privacy@friendli.ai)API request body (prompt) — generation of EXAONE model responsesUSA (inference infrastructure)Unclear (no explicit statement of non-use for training)Retained per policy
DeepInfra, Inc. (deepinfra.com)API request body (prompt) — generation of NVIDIA Nemotron model responsesUSANot used (inference hosting · no training of own models)Retained per policy
BytePlus Pte. Ltd. (ModelArk)API request body (text, image, video, audio, and 3D references) and request metadata — ModelArk response, image, video, embedding, and 3D generationap-southeast-1 (Johor, Malaysia); cross-region processing in EU regions may occur according to resource availabilityUnclearRetained per policy
Cohere Inc. (privacy@cohere.com)API request body (prompt / rerank query & documents) — generation of Command model responses and rerank resultsCanada (HQ) · USA (GCP cloud infrastructure)Used (opt-out available in Data Controls)Auto-deleted after 30 days for Enterprise users
AI21 Labs Ltd. (privacy@ai21.com)API request body (prompt) — generation of Jamba and other model responsesUSANot used (paid API)Retained per policy
Reka AI, Inc. (reka.ai)API request body (prompt) — generation of Reka model responsesUSAUnclear (confirm public policy and contract)Retained per policy
Baichuan Intelligence (baichuan-ai.com)API request body (prompt) — generation of Baichuan model responsesChinaUsed (no opt-out option)Retention period not specified
Baidu, Inc. (ERNIE · privacy.baidu.com)API request body (prompt) — generation of ERNIE model responsesChinaUnclear (confirm public policy and contract)Retained per policy
Tencent (Hunyuan · privacy.qq.com)API request body (prompt) — generation of Hunyuan model responsesChinaUnclear (confirm public policy and contract)Retained per policy
01.AI (零一万物 · Yi · 01.ai)API request body (prompt) — generation of Yi model responsesChinaUnclear (confirm public policy and contract)Retention period not specified
Inception Labs (inceptionlabs.ai)API request body (prompt) — generation of Mercury and other model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Nous Research, Inc. (nousresearch.com)API request body (prompt) — generation of Hermes and other model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Cerebras Systems, Inc. (cerebras.ai)API request body (prompt) — generation of Cerebras model responsesUSANot used (inference API)Retained per policy
Groq, Inc. (groq.com)API request body (prompt) — generation of Groq inference model responsesUSANot used (inference-only)Not stored after transmission
Together AI, Inc. (together.ai)API request body (prompt) — generation of open-source and hosted model responsesUSAUsed (Zero Data Retention option available)Retained per policy
Fireworks AI, Inc. (fireworks.ai)API request body (prompt) — generation of Fireworks-hosted model responsesUSANot used (Enterprise ZDR option)Retained per policy
Hyperbolic Labs (hyperbolic.ai)API request body (prompt) — generation of Hyperbolic-hosted model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Nebius Group N.V. (nebius.com)API request body (prompt) — generation of Nebius-hosted model responsesNetherlands/EUUnclear (confirm public policy and contract)Retained per policy
GMI Cloud (gmicloud.ai)API request body (prompt) — generation of GMI-hosted model responsesChina/Singapore (confirm processing region in contract)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
SiliconFlow (siliconflow.cn)API request body (prompt) — generation of SiliconFlow-hosted model responsesChina/Singapore (confirm processing region in contract)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Avian (avian.io)API request body (prompt) — generation of Avian-hosted model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Baseten Labs, Inc. (baseten.co)API request body (prompt) — generation of Baseten-hosted model responsesUSAUnclear (confirm public policy and contract)Retained per policy
Parasail (parasail.io)API request body (prompt) — generation of Parasail-hosted model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Inference.net (inferencenet.ai)API request body (prompt) — generation of Inference.net-hosted model responsesUSAUnclear (confirm public policy and contract)Unclear (confirm policy and contract)
Lambda Labs, Inc. (lambdalabs.com)API request body (prompt) — generation of Lambda-hosted model responsesUSAUnclear (confirm public policy and contract)Retained per policy
SambaNova Systems, Inc. (sambanova.ai)API request body (prompt) — generation of SambaNova model responsesUSAUnclear (confirm public policy and contract)Retained per policy
DigitalOcean, LLC (Gradient AI · digitalocean.com)API request body (prompt) — generation of Gradient AI-hosted model responsesUSAUnclear (confirm public policy and contract)Retained per policy
Novita AI (novita.ai)API request body (prompt) — generation of Novita-hosted model responsesSingapore/China (confirm processing region in contract)Unclear (confirm public policy and contract)Unclear (confirm policy and contract)
Tapfiliate B.V. (data-support@tapfiliate.com · tapfiliate.com/privacy-policy)Randomly generated pseudonymous referral Sub-ID added to the referral URL by Pleum (no email, name, Pleum account ID, or API request body; the exact parameter is operator-configured after provider confirmation), referral/click identifiers, click time, cookie/local-storage identifier, IP, User-Agent, browser, OS, device, referrer/landing URL, and IP-derived country — referral-click and first-paid conversion attribution, referral-bonus verification, and fraud preventionNetherlands (recipient entity) · Ireland (core AWS processing/storage; Tapfiliate separately lists US subprocessors, while referral-data-specific onward transfers require DPA confirmation)Not applicable (no model-training input is transferred)Tapfiliate publishes no fixed server click/event retention period: its public policy says data is erased when no longer necessary or legally permitted, with processing restricted for legal retention; tracking cookies follow the advertiser-configured period. Pleum's local mapping follows the separate period in Article 3
Amazon Web Services, Inc. (AWS Bedrock · aws.amazon.com/bedrock)API request body (prompt) — generation of Bedrock model responsesUSA (global regions possible)Not used (Bedrock default)Per AWS policy
Vultr Holdings, LLC (vultr.com)API request body (prompt) — generation of Vultr Serverless Inference-hosted model responsesUSA (global inference regions possible)Unclear (confirm public policy and contract)Retained per policy

(1) Timing and method of transfer: data is transmitted in real time over HTTPS (TLS) encrypted communication at the moment the Member calls the API.

(2) Recipient's purpose of use: limited to the generation of responses (inference) for the model selected by the Member. The Company uses, to the extent possible, enterprise API routes in which input is not used for training (opt-out / Zero-Data-Retention, etc.); however, some model providers use input for model improvement and training, or it is unclear whether they do so. Whether each provider uses input for training is indicated in the 'Use of Input for Model Training' column of the table above, and Members can review this and select models accordingly (if you do not want your input used for training, select only models for which that column reads 'Not used').

(3) Method, procedure, and effect of refusing transfer: A Member may (a) enable the 'PII Masking' option per API key so that sensitive information is masked before transmission, or (b) select only models that are inferred and processed domestically without cross-border transfer, thereby avoiding cross-border transfer to model providers (even a model offered by a Korean business is listed as subject to cross-border transfer in the table above where its inference infrastructure is located overseas — e.g., Upstage Solar is processed on US infrastructure). However, overseas storage on the service operating infrastructure under (5) below is unavoidable for the provision of the Service (performance of the contract) and is not subject to avoidance. If transfer is refused, the relevant overseas models cannot be used, but there is no restriction on other use of the Service.

(4) The Company limits the personal information transferred overseas to the minimum necessary to achieve the purpose of processing. Where a Member has not consented to the 'use of input content for service improvement,' the Company does not store the input or response bodies and retains only usage metadata (model, tokens, cost, time, etc.). In addition, the pseudonymized information processed by the Company for statistical and research purposes under Article 2-2 does not include input or response bodies, and such pseudonymized information may, pursuant to Article 28-2 of PIPA, be processed without separate consent for cross-border transfer.

(5) Domestic processing of primary service infrastructure and cross-border transfer to disaster-recovery infrastructure: The Company's primary cloud infrastructure (servers and databases) is operated in the Seoul region (Republic of Korea, icn1 / ap-northeast-2) via Vercel, Supabase, and Alibaba Cloud. Accordingly, the primary storage location for account information, usage records, consent history, and input/response bodies stored pursuant to (4) above is domestic (see the table in Article 4 above for processors). However, the Company uses Railway as overseas disaster-recovery (DR) infrastructure to maintain service continuity during disasters and outages and discloses the transfer pursuant to Article 28-8(1)(iii) of PIPA — Recipient: Railway Corporation (privacy@railway.com) / Country of transfer: Singapore (selected hosting region) and the USA (Railway's primary country of operation) / Items transferred: account information (email and display name), authentication and session information, usage records and consent history, payment and credit ledgers, API request metadata, and input/response bodies stored pursuant to (4) above; while DR is active, authentication information and API request bodies are processed through the frontend BFF and API server / Timing and method: transferred over encrypted communications such as HTTPS (TLS) during the one-time initial backup and continuous logical replication, and during DR cutover and operation / Purpose of use: maintaining a replicated DR data copy and standby infrastructure and securing service continuity by operating the frontend BFF, API server, database, and Redis during an outage / Retention and use period: the Railway replica continuously reflects creates, updates, and deletions from the primary system; each item is retained for the applicable period in Article 3 or until membership withdrawal and is destroyed without delay when the DR purpose is achieved or the Railway contract ends (subject to Railway's DPA and legal retention obligations) / Method and effect of refusal: DR infrastructure is unavoidable for service continuity, so a refusal will be handled as withdrawal of membership. In addition, email delivery (Resend, Inc. · USA), bot blocking (Cloudflare, Inc. · global edge), website usage analytics (Google LLC · Google Analytics, USA), and service error tracking (Functional Software, Inc. · Sentry, USA) are processed overseas and are disclosed as follows — Recipient: Resend, Inc. (US entity) / Cloudflare, Inc. (global edge) / Google LLC (Google Analytics) / Functional Software, Inc. (Sentry) / Country of transfer: USA (Resend, Google, Sentry) · global edge (Cloudflare) / Items transferred: recipient email address and other minimal information necessary for delivery (Resend) · IP address, browser information, and other security-determination data (Cloudflare) · visited page addresses (URLs), event information, browser and device information (Google Analytics) · built-in exception type, occurrence time, severity, and line/column numbers for server and Edge errors (Sentry — nothing is sent from browsers; error messages, filenames, function names, URLs/requests, user-identifying information, API request bodies, and prompts are removed before transmission) / Timing and method: transmitted in real time over HTTPS (TLS) at the time of sending, access, or error occurrence / Purpose of use: transactional, authentication, and notice email delivery (Resend) · bot blocking and security (Cloudflare) · usage analytics (Google Analytics) · error tracking for service quality improvement (Sentry) / Retention period: destroyed upon withdrawal of membership or expiry of the retention period (Articles 3 and 7) · Google Analytics and Sentry are subject to each company's data retention policy / Method and effect of refusal: as email delivery, bot blocking, and error tracking are unavoidable for provision of the Service (notices, security, quality management), a refusal will be handled as withdrawal of membership. Usage analytics (Google Analytics) may be refused by blocking browser cookies, and refusal does not restrict your use of the Service.

(6) Cross-border transfer of behavioral information for advertising performance measurement and personalized advertising: Where the Company operates Meta Pixel pursuant to Article 9, behavioral information is transmitted directly from the user's browser to Meta and processed overseas. The matters under each subparagraph of Article 28-8(2) of PIPA are disclosed as follows — Recipient: Meta Platforms, Inc. (USA · facebook.com/privacy/policy) / Country of transfer: USA / Items transferred: visited page addresses (URLs), in-service event information (the occurrence of conversion events such as sign-up and credit top-up), browser and device information, and online identifiers such as cookies (the behavioral information under Article 9 — API request bodies (prompts) are not included) / Timing and method of transfer: transmitted in real time over HTTPS (TLS) from the user's browser upon website visits and event occurrences / Recipient's purpose of use: measurement of advertising performance (conversion tracking) and provision of personalized advertising / Retention and use period: in accordance with Meta's privacy policy and data policy / Method, procedure, and effect of refusal: you may refuse by the methods under Article 9(3) (blocking cookies in the browser; Meta ad settings), and refusal does not restrict your use of the Service.

(7) Disclosure of a nickname for the token-usage leaderboard (provision to third parties): Where a Member has consented to 'disclosure of a nickname on the token-usage leaderboard' (Terms of Service Article 14(7)), the Company, pursuant to Articles 17 (provision to a third party) and 22 of PIPA, displays the Member's configured nickname (or a masked display derived from the email where none is set) and the token-usage rank and statistics on the leaderboard of a public web page. Recipient: an unspecified number of persons (visitors to the leaderboard page) / Items provided: nickname (or masked email display), rank, and token-usage statistics (no other identifying information such as email, account ID, or contact details is provided) / Purpose of use: displaying token-usage rankings among Members / Retention and use period: until consent is withdrawn or the Member withdraws membership (the Member's nickname and rank are removed from the leaderboard immediately upon withdrawal) / Method and effect of refusal: you may withdraw at any time under 'Settings > Consent Management'; refusing (non-consent or withdrawal) only means the Member's rank is not displayed on the leaderboard and does not restrict use of the Service. This disclosure takes place on domestic infrastructure and does not constitute a cross-border transfer.

(8) Optional referral-link tracking (Tapfiliate): Referral tracking starts only when a Member affirmatively chooses the referral CTA and proceeds to the external provider site. At this stage, Pleum adds only a server-generated random pseudonymous referral Sub-ID to the referral URL; the exact parameter is operator-configured after provider confirmation. Pleum adds no email, name, account ID, or API request body. The browser then transmits the URL externally over HTTPS (TLS), and the advertiser-side Tapfiliate integration may process the click technical data listed in the table above. The purposes are attribution of the referral click and first paid conversion, verification of any referral bonus, and prevention of duplicate or fraudulent conversions. A Member may refuse the tracking and cross-border transfer by not choosing the referral CTA. Refusal means that referral attribution and the resulting Pleum referral bonus are unavailable, but does not restrict access to BYOK plan information or any other use of the Service. Blocking cookies may disrupt later conversion attribution but does not block the initial click transfer for a referral link already chosen. The recipient, countries, and retention period are stated in the Tapfiliate row above.

Article 6 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)

(1) A data subject may at any time request access to, correction, deletion, or suspension of processing of personal information, and withdraw consent (Articles 35, 36, and 37 of PIPA). Where you withdraw consent to leaderboard nickname disclosure or withdraw membership, your nickname and rank are removed from the leaderboard immediately.

(2) Rights may be exercised through the in-service settings or by contacting the Privacy Officer below, and the Company takes action without delay (within 10 days). When exercised through a representative, a power of attorney must be submitted.

(3) For a child under 14 years of age, a legal representative exercises the rights.

Article 7 (Procedure and Method of Destroying Personal Information)

(1) When personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the purpose of processing, the Company destroys it without delay. Information retained pursuant to other statutes is stored and managed separately.

(2) Electronic files are permanently deleted by technical means that prevent recovery, and paper documents are shredded or incinerated.

Article 8 (Measures to Ensure the Safety of Personal Information)

The Company takes measures including: (1) establishing and implementing an internal management plan and minimizing the number of staff handling data; (2) one-way encryption of passwords (bcrypt), encryption of transmission channels (SSL/TLS), and hashed storage of API keys; (3) differentiated granting of access rights and access control; (4) intrusion blocking and detection and bot blocking (Cloudflare Turnstile); and (5) retention of access logs and prevention of forgery or alteration.

Article 9 (Devices for Automatic Collection of Personal Information — Cookies)

(1) The Company uses cookies and other devices that automatically collect personal information to maintain login sessions, perform security verification, analyze usage statistics, and provide personalized advertising (collection of behavioral information). A data subject may refuse or delete the storage of cookies in their web browser settings, but in that case there may be restrictions on the use of some services that require login.

(2) Collection and use of behavioral information for online personalized advertising: To measure advertising performance and provide personalized advertising, the Company installs and operates on its website Meta Pixel, an advertising tool of Meta Platforms, Inc., thereby allowing Meta to collect and process users' behavioral information. — Items of behavioral information collected: visited page addresses (URLs) and visit/usage records, in-service event information (the occurrence of conversion events such as sign-up and credit top-up), browser and device information, and online identifiers such as cookies / Method of collection: collected and transmitted automatically via the Meta Pixel script when a user visits the website / Purpose of collection: measurement of advertising performance (conversion tracking) and provision of personalized advertising based on user interests / Retention and use period: the Company does not itself store behavioral information; Meta retains and uses it in accordance with its own privacy policy and data policy. The Company does not collect API request bodies (prompts) or other contents of Service use as behavioral information, nor use them for advertising purposes.

(3) How to refuse the collection of behavioral information (exercise of control): (a) block or delete cookies in your web browser settings (including blocking third-party cookies); (b) restrict the display of personalized ads and data connections in your Meta account's ad settings (facebook.com/adpreferences). Refusal does not restrict your use of the Service, although non-personalized general ads may still be displayed. For harm or inquiries related to behavioral information, you may contact the Privacy Officer under Article 10.

Article 10 (Privacy Officer)

The Company designates a Privacy Officer to oversee tasks related to personal information processing and to handle complaints and remedy damage of data subjects. (Pursuant to Article 31 of PIPA, Won-young Lee, Representative Director of PLEUM. AI Co., Ltd., serves as the Privacy Officer.)

Privacy Officer: 이원영 (Representative Director)

Contact: support@pleum.ai · 010-4869-1806

Article 11 (Methods of Remedy for Infringement of Rights)

A data subject may apply to the following organizations for dispute resolution or consultation to remedy infringement of personal information: Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Supreme Prosecutors' Office Cyber Investigation Division (1301), and National Police Agency Cyber Investigation Bureau (182, ecrm.police.go.kr).

Article 12 (Changes to the Privacy Policy)

This Privacy Policy was established on June 15, 2026 and applies as revised from August 11, 2026. Any changes will be announced through service notices from 7 days (or 30 days for significant changes) before they take effect.