Privacy Policy

Effective: February 18, 2026

Check&Do ("Service") values your privacy and complies with applicable data protection laws. This policy describes what personal information we collect, how we use it, and how long we retain it.

1. Purpose of Processing Personal Information

We process personal information for the following purposes:

  • Account management: identity verification, maintaining service eligibility
  • Service delivery: timeboxing, task management, memos, and analytics
  • Service improvement: usage analytics and error resolution

2. Personal Information Collected

Required (OAuth sign-in)

  • Email address, profile name, OAuth provider identifier

Automatically collected

  • Service usage logs, access timestamps, browser type

Guest usage

  • No personal information is collected. Only an anonymous session identifier is generated.

3. Retention Period

  • Data is retained until account deletion and destroyed immediately upon request.
  • If retention is required by law, data is stored for the legally mandated period.
  • Guest data is automatically deleted 30 days after last access.

4. Sharing with Third Parties

We do not share your personal information with third parties, except when required by law.

5. Data Processing Delegation

ProviderPurpose
Supabase Inc.Database hosting, authentication services

6. International Data Transfers

The Service uses Supabase cloud infrastructure, and data may be stored on overseas servers (United States, Singapore, etc.).

  • Recipient: Supabase Inc.
  • Data transferred: All service usage data
  • Purpose: Cloud infrastructure operation
  • Retention: Until account deletion

7. Data Destruction

  • Upon account deletion request, data is destroyed immediately. Data required to be retained by law is stored separately and destroyed upon expiration.
  • Electronic files are deleted using methods that prevent recovery.

8. Your Rights

You may exercise the following rights at any time:

  • Request access, correction, deletion, or suspension of processing
  • Request account deletion

You can exercise these rights through in-app settings or by emailing contact@keysams.com.

9. Cookies

The Service uses cookies to maintain login sessions. You may refuse cookies through browser settings, but this may limit service functionality.

10. Data Protection Officer

  • Name: Mingyu Kang
  • Phone: +82-10-6222-9409
  • Email: contact@keysams.com

11. Security Measures

We implement the following measures to ensure data security:

  • HTTPS encrypted communication
  • Supabase Row Level Security (RLS)
  • OAuth-based authentication (no password storage)
  • Minimum-privilege access controls

12. Remedies for Rights Infringement

If you need assistance regarding privacy issues, you may contact the Korean Personal Information Dispute Mediation Committee (1833-6972) or email us at contact@keysams.com.

13. Children Under 14

The Service is not intended for children under 14, and we do not knowingly collect personal information from children under 14.

14. Changes to This Policy

This policy may be updated due to changes in laws, policies, or the Service. Changes will be announced within the Service.

15. Effective Date

This Privacy Policy is effective as of February 18, 2026.