1. Purpose of Collecting and Using Personal Information
Anote (hereinafter "the Company") collects and uses personal information for the following purposes. Collected information will not be used beyond these purposes, and prior consent will be obtained if the purpose changes.
- ·Registration & account management — Identity verification, sign-up confirmation, service delivery and account management
- ·Service delivery — Record management, goal & habit tracking, journal, archive, finance, calendar, team features, etc.
- ·Public profiles — Providing user-published profile and repository pages
- ·Service improvement — Usage analytics, quality improvement, error diagnosis
- ·Customer support — Responding to inquiries, delivering announcements
2. Types of Personal Information Collected
A. Directly collected
- ·Required — Email address, password (stored encrypted), username
- ·Optional — Profile image, bio, display name
B. Collected via social login
- ·Google — Email address, name, profile image
- ·GitHub — Email address, username, profile image
C. Automatically generated during use
- ·Access logs, IP address, browser type, device information
- ·Service usage records (page visits, feature usage statistics)
D. User-uploaded content
- ·Photos, videos, text records, file attachments (encrypted in transit and stored in cloud storage)
3. Retention Period
- 1.Retained until account deletion; destroyed without delay upon deletion.
- 2.Where required by applicable law, records are retained separately for the following periods:
- ·Contract or withdrawal records: 5 years (E-Commerce Act)
- ·Payment and supply records: 5 years (E-Commerce Act)
- ·Access logs: 3 months (Telecommunications Privacy Act)
Beta period notice: If a data reset is required during the beta period for service stabilization, all collected personal information and usage data will be deleted after at least 7 days' prior notice.
4. Disclosure to Third Parties
The Company does not share personal information with third parties, except in the following cases:
- ·When the user has given prior consent
- ·When required by law or regulation
5. Third-Party Services
The Company uses the following third-party services:
- ·Google Analytics — Usage statistics collection (anonymized visit and usage data)
- ·Oracle Cloud Object Storage — User file storage (Korea region)
- ·Google OAuth / GitHub OAuth — Social login authentication
6. Cookies & Local Storage
- ·Auth tokens — Session tokens for maintaining login state (cookies / local storage)
- ·Theme preferences — Dark/light mode and other user preferences
- ·Language preferences — Korean/English locale settings
- ·Analytics cookies — Google Analytics usage statistics (anonymized)
You may disable cookies through your browser settings, but some features may be limited.
7. Your Rights
You may exercise the following rights at any time:
- ·Access — View your personal information on the settings page
- ·Correction — Edit profile information (name, bio, image, etc.)
- ·Deletion — Delete individual records or all data by deleting your account
- ·Visibility control — Change public/private settings for repositories and profiles
8. Security Measures
The Company takes the following measures to protect your personal information:
- ·Password encryption (bcrypt)
- ·HTTPS (TLS) encrypted communication
- ·Minimized and managed access permissions
- ·Encrypted file transfer and separate storage
9. Changes to This Policy
This Privacy Policy may be updated due to changes in law, policy, or our service. Changes will be announced via in-app notice or email at least 7 days before taking effect.
10. Data Protection Officer & Contact
For privacy-related complaints, you may also contact the following organizations (Korea):
- ·Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- ·Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
Effective: February 20, 2026