Privacy Policy
Effective: February 18, 2026
Check&Do ("Service") values your privacy and complies with applicable data protection laws. This policy describes what personal information we collect, how we use it, and how long we retain it.
1. Purpose of Processing Personal Information
We process personal information for the following purposes:
- Account management: identity verification, maintaining service eligibility
- Service delivery: timeboxing, task management, memos, and analytics
- Service improvement: usage analytics and error resolution
2. Personal Information Collected
Required (OAuth sign-in)
- Email address, profile name, OAuth provider identifier
Automatically collected
- Service usage logs, access timestamps, browser type
Guest usage
- No personal information is collected. Only an anonymous session identifier is generated.
3. Retention Period
- Data is retained until account deletion and destroyed immediately upon request.
- If retention is required by law, data is stored for the legally mandated period.
- Guest data is automatically deleted 30 days after last access.
4. Sharing with Third Parties
We do not share your personal information with third parties, except when required by law.
5. Data Processing Delegation
| Provider | Purpose |
|---|---|
| Supabase Inc. | Database hosting, authentication services |
6. International Data Transfers
The Service uses Supabase cloud infrastructure, and data may be stored on overseas servers (United States, Singapore, etc.).
- Recipient: Supabase Inc.
- Data transferred: All service usage data
- Purpose: Cloud infrastructure operation
- Retention: Until account deletion
7. Data Destruction
- Upon account deletion request, data is destroyed immediately. Data required to be retained by law is stored separately and destroyed upon expiration.
- Electronic files are deleted using methods that prevent recovery.
8. Your Rights
You may exercise the following rights at any time:
- Request access, correction, deletion, or suspension of processing
- Request account deletion
You can exercise these rights through in-app settings or by emailing contact@keysams.com.
9. Cookies
The Service uses cookies to maintain login sessions. You may refuse cookies through browser settings, but this may limit service functionality.
10. Data Protection Officer
- Name: Mingyu Kang
- Phone: +82-10-6222-9409
- Email: contact@keysams.com
11. Security Measures
We implement the following measures to ensure data security:
- HTTPS encrypted communication
- Supabase Row Level Security (RLS)
- OAuth-based authentication (no password storage)
- Minimum-privilege access controls
12. Remedies for Rights Infringement
If you need assistance regarding privacy issues, you may contact the Korean Personal Information Dispute Mediation Committee (1833-6972) or email us at contact@keysams.com.
13. Children Under 14
The Service is not intended for children under 14, and we do not knowingly collect personal information from children under 14.
14. Changes to This Policy
This policy may be updated due to changes in laws, policies, or the Service. Changes will be announced within the Service.
15. Effective Date
This Privacy Policy is effective as of February 18, 2026.