Privacy Policy
1. Information Collected and Purpose
a. Report Generation
| Data Collected | Purpose | Retention |
|---|---|---|
| Date of birth, time of birth, solar/lunar calendar type | Energy structure analysis and report generation | Until account deletion (30 days for non-members) |
| Email address | Report delivery and re-access code delivery | Until account deletion (30 days for non-members) |
| Country / region (optional) | Improving analysis precision and regional distribution statistics | Until account deletion (30 days for non-members) |
| Gender (optional) | Improving analysis precision and statistical analysis | Until account deletion (30 days for non-members) |
b. Sign-Up via Social Login
| Provider / Data | Purpose | Retention |
|---|---|---|
| Kakao — nickname, member number (required) | Member identification and sign-in, linking purchase history | Until account deletion or account unlinking |
| Kakao — Kakao account email (required) | Report delivery and re-access code delivery | Until account deletion or account unlinking |
| Kakao — profile image (optional) | Displaying your image within the service | Until account deletion or account unlinking |
| Google — email address, account identifier (required) | Member identification and sign-in, report delivery | Until account deletion or account unlinking |
| Google — name, profile image (optional) | Displaying your name and image within the service | Until account deletion or account unlinking |
Where a social login provider does not supply an email address, we ask you to enter one directly so that we can deliver your report. The purpose and retention period remain as stated above.
c. Paid Purchases
| Data Collected | Purpose | Retention |
|---|---|---|
| Payment amount, payment date and time, payment method type, transaction identifier | Payment processing, purchase history management, refunds and dispute resolution | 5 years (Korean Act on Consumer Protection in Electronic Commerce) |
Card numbers and other payment authentication details are handled by the payment gateway. DYU neither collects nor stores them.
d. Automatically Collected Information
| Data Collected | Purpose | Retention |
|---|---|---|
| IP address, browser information, access time, referral source (UTM) | Service operation, security, traffic analysis | 3 months |
2. Processing and Retention
For free reports used without signing up, the information you enter is deleted automatically once the access code expires (30 days from issuance).
If you sign up via social login, your account information and issued reports are retained until account deletion. This is so that you can re-open a report you purchased at any time. You may delete your account at any time through the service, or by unlinking your Kakao or Google account; upon deletion your personal data is destroyed without delay.
The following records are retained for the periods required by law.
- Records of contracts and withdrawal of subscription: 5 years (Korean Act on Consumer Protection in Electronic Commerce)
- Records of payment and supply of goods: 5 years (same Act)
- Records of consumer complaints or dispute resolution: 3 years (same Act)
- Access logs: 3 months (Korean Protection of Communications Secrets Act)
In payment records retained under these laws, member identifiers are separated so that the records are held in a form in which an individual cannot be identified.
3. Account Deletion and Account Unlinking
If you unlink DYU from your Kakao or Google account, we receive notice of the unlinking from that provider and destroy your account information. The same applies when you delete your account using the in-service function.
What is destroyed: member identifiers, email address, issued reports, and all analysis inputs such as the date of birth you entered. Payment records that must be retained under the Act on Consumer Protection in Electronic Commerce are converted to a form in which an individual cannot be identified, then held for the statutory period.
Personal data held in electronic files is deleted by means that make recovery impossible; any printed material is shredded or incinerated.
4. Outsourcing of Personal Data Processing
DYU outsources the following processing activities in order to provide the service.
| Processor | Outsourced Work | Retention / Use Period |
|---|---|---|
| Supabase, Inc. | Storage of member and report data, authentication processing (data stored in Seoul, Republic of Korea) | Until termination of the contract or account deletion |
| Vercel Inc. | Website hosting and server operation | Until termination of the contract |
| Korea PortOne Co., Ltd. | Payment processing and payment verification | Until termination of the contract |
5. Third-Party Disclosure
DYU does not provide users' personal data to third parties, except where required by law or upon a lawful request from an investigative authority.
6. Use of Cookies
DYU uses the cookies below for service analysis and improvement and for serving advertisements. Non-essential cookies are set only after you consent.
| Cookie | Provider | Purpose | Retention | Category |
|---|---|---|---|---|
| _ga, _ga_* | Visitor analysis, page view measurement | 2 years | Analytics | |
| _clck, _clsk | Microsoft | Heatmaps, session recording, UX analysis | 1 year | Functional |
| __gads, __gpi, etc. | Google AdSense | Ad serving and frequency capping | Up to 13 months | Advertising |
| _fbp (planned) | Meta | Ad targeting, conversion tracking | 90 days | Marketing |
You can choose your cookie preferences in the banner shown on your first visit, and change them at any time via the “Cookie settings” link at the bottom of the page. Disabling cookies does not prevent you from using the core service.
7. Your Rights
- Request access to, and a copy of, how your personal data is processed
- Request correction or deletion of your personal data
- Request suspension of processing
- Withdraw consent and delete your account
You may exercise these rights through the service or via the contact below. DYU responds within 10 days of receiving your request.
8. Security Measures
- Access to personal data is limited to the minimum number of people required.
- Data in transit is encrypted with HTTPS, and database access is limited to authenticated requests.
- Row-level access control ensures each member can access only their own data.
9. Privacy Officer and Contact
Please direct any questions about the processing of personal data to the contact below.
Privacy Officer: Taeseon Lee
Email: dyurprt@gmail.com
If you need assistance regarding a personal data infringement, you may contact the following Korean authorities.
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Supreme Prosecutors' Office Cybercrime Division (spo.go.kr / 1301)
- National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
10. Policy Changes
This Privacy Policy may be supplemented, removed or amended in line with changes in law or policy. Any change will be announced at least 7 days before it takes effect.