Privacy Policy
Effective Date: September 23, 2025
1. General Provisions
This Privacy Policy applies to the website and services (hereinafter 'Service') provided by Bear0 (hereinafter 'Company') and complies with Korean related laws including the Personal Information Protection Act and the Information and Communications Network Act.
2. Personal Information Items Collected and Collection Methods
The Company may collect the following personal information:
- Membership registration: Email, password, name (optional)
- Authentication/Login: OAuth account identifier, email
- Service usage: Access device information (browser, OS), IP, cookies, service usage records
- Diagram-related: Diagram metadata (e.g., diagram name, etc.)
- Customer inquiry: Email, inquiry content
Collection methods: Member registration/login screen input, customer inquiry, automatic generation and collection during service use, third-party login (OAuth).
3. Purpose of Personal Information Use
- Member management, identity verification, service provision and maintenance/improvement
- Security, fraud prevention, service stability assurance
- Customer inquiry response, announcement delivery
- Providing core functions such as diagram creation, storage, sharing, export
- Legal compliance and dispute response
- Marketing and promotion guidance with optional consent
4. Processing and Retention Period
- Immediate destruction upon member withdrawal
- Retention according to related laws: Contract/subscription withdrawal records 5 years, payment/goods supply records 5 years, consumer complaint/dispute processing records 3 years, access records 3 months, etc.
5. Third Party Provision and Consignment
The Company does not provide personal information to third parties without user consent in principle. However, processing tasks may be consigned within the necessary scope for service operation as follows:
- Authentication/Login: Supabase Auth (email, account identifier)
- Service infrastructure: Vercel, AWS (service logs and metadata)
- Payment (when introduced): Payment gateway (PG)
Contracts related to personal information protection are concluded with consignees and safety measures are implemented and managed.
6. User Rights and Exercise Methods
- Personal information access, correction, deletion, processing suspension requests
- Consent withdrawal and member withdrawal
- Rights can be exercised by requesting via email (dev.bearjb@gmail.com).
7. Use of Cookies, etc.
- Cookies may be used for service convenience.
- You can choose to allow/block cookies in browser settings.
8. Personal Information Destruction Procedures and Methods
- Immediate destruction after purpose achievement
- Electronic files: Deletion in an unrecoverable manner
- Printed materials: Shredding or incineration
9. Safety Measures
- Access authority management, encrypted storage, transmission section encryption (HTTPS)
- Log and access record management and minimal access control
- Disaster preparedness backup and recovery system
10. Privacy Protection Officer
Name: Privacy Protection Officer
Email: dev.bearjb@gmail.com
11. International Transfer
When using cloud services (Vercel, Supabase, AWS, etc.), data may be transferred to overseas servers within the necessary scope for service provision. In this case, notification and consent procedures according to related laws are followed.
12. Notification Duty
If there are additions, deletions, or modifications to the contents of this policy, notification will be given through service announcements from 7 days before the implementation of the revisions.