Last updated: February 24, 2026
Data Controller / 운영자
Operator: KIMSUNJIN
Country: Republic of Korea
Email: gene1996@naver.com
Website: https://testte.site
K-Saju (“we”, “our”, “the Service”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights — in compliance with the Korean Personal Information Protection Act (PIPA / 개인정보보호법), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
We collect only the minimum data necessary to provide the Service:
| Item | Purpose | Retention |
|---|---|---|
| Name | Account creation, display | Until withdrawal |
| Email address | Login, notifications | Until withdrawal |
| Password (hashed) | Authentication | Until withdrawal |
| Google OAuth ID | Social login | Until withdrawal |
| Birth date & time | Saju analysis generation | Until withdrawal |
| Birth gender | Saju card image selection | Until withdrawal |
| IP address / device info | Security, fraud prevention | 90 days |
| Payment records | Billing compliance (tax law) | 5 years |
We use your personal information solely for the following purposes:
• Providing AI-generated Saju analysis and destiny card services
• Account management and authentication
• Subscription billing and payment processing (via Gumroad)
• Service improvement and security monitoring
• Legal compliance obligations
• Responding to your inquiries
⚠️ We do NOT use your data for purposes beyond what is stated above. We do NOT sell, rent, or trade your personal information to any third party for marketing purposes.
🗑️ Account Withdrawal Policy
When you delete your account, all personal information (name, email, birth data, Saju profiles, community posts) is permanently and irrecoverably deleted within 7 days of your withdrawal request. Payment records are retained for 5 years as required by Korean tax law, but are anonymized and isolated from your profile.
Retention periods by category:
• Account data (name, email, birth info): Deleted immediately upon withdrawal
• Saju profiles & analysis results: Deleted immediately upon withdrawal
• Community posts & comments: Anonymized or deleted upon withdrawal
• Access logs: 90 days, then automatically purged
• Payment records: 5 years (Korean Act on Consumer Protection in E-Commerce)
• Inactive accounts: After 1 year of inactivity, we will notify you by email and delete data within 30 days unless you respond
We share minimum necessary data with the following third-party processors:
• Gumroad (payment processing) — email, payment info only
• Google OAuth (authentication) — profile info for login only
• OpenAI (AI analysis engine) — birth data for analysis only; not stored by OpenAI per their API policy
• Google Analytics (usage analytics) — anonymized usage data; you can opt out at tools.google.com/dlpage/gaoptout
All third-party processors are bound by data processing agreements and applicable privacy regulations.
We use only essential session cookies for authentication. We do not use advertising or tracking cookies without your consent. When you accept our cookie banner, only functional cookies are stored. You can manage cookies through your browser settings at any time.
Under PIPA, GDPR, and CCPA, you have the following rights:
• Right to access: Request a copy of your personal data
• Right to rectification: Correct inaccurate data
• Right to erasure: Request deletion of your data (Right to be Forgotten)
• Right to portability: Receive your data in a machine-readable format
• Right to object: Object to processing of your data
• Right to withdraw consent: Withdraw consent at any time (does not affect prior processing)
To exercise any right, contact gene1996@naver.com. We will respond within 30 days. You may also request account deletion directly in Settings → Account → Delete Account.
K-Saju is not directed to children under 14 (Korea) or 13 (international). We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it promptly.
Our servers are located in the Republic of Korea. If you are accessing from the EU or other regions, your data may be transferred internationally. We ensure appropriate safeguards (Standard Contractual Clauses) are in place.
We implement industry-standard security measures including password hashing (bcrypt), HTTPS/TLS encryption, and regular security audits. However, no method of transmission over the internet is 100% secure.
We will notify you by email or prominent in-app notice at least 7 days before any material changes to this Privacy Policy. Continued use after changes constitutes acceptance.
For privacy-related requests or complaints:
Email: gene1996@naver.com
Response time: Within 30 days
Korean supervisory authority: Personal Information Protection Commission (PIPC)
EU supervisory authority: Your local Data Protection Authority