Privacy Policy
Effective date: 2026-06-22
This English version is a courtesy translation. In case of any conflict, the Korean version governs.
Tajagi Studio (the “Company”) complies with the Personal Information Protection Act and other applicable laws, and maintains this Privacy Policy to protect users’ personal data as follows.
1. Personal data collected and methods
- On social login (Google) sign-up: email address, name (profile name), profile image, social account identifier
- Generated while using the Service: works/chapters you write, content such as characters, relationship boards, and settings, AI consultation history, and usage records (access timestamps, etc.)
- Collection methods: social login authentication, and direct input by the user while using the Service
2. Purpose of processing
- Member identification/authentication and account management
- Providing the writing editor, AI plot coach, and other features, and saving/syncing content
- Operating and improving the Service, responding to inquiries, preventing misuse
- (With optional consent) informing you of marketing such as new features and events
3. Retention and use period
Content such as AI consultations is retained until you delete it or withdraw. On withdrawal or a deletion request, it is destroyed without delay from the Company’s active database. However, it may not be deleted immediately from the systems, backups, and logs of entrusted/cross-border providers, as below.
- Active database (Supabase): deleted without delay on withdrawal/deletion. System backups and logs may be deleted sequentially after a period per the provider’s policy.
- AI plot coach (Anthropic): transmitted inputs/outputs are generally deleted within about 30 days. However, if classified as a usage-policy violation, inputs/outputs may be retained for up to 2 years and safety classification scores for up to 7 years.
- Embeddings (Voyage AI): where training/storage opt-out applies, transmitted data is not retained; otherwise it follows the provider’s policy.
- Hosting (Vercel): processing logs/caches may be deleted after a period per the provider’s policy.
Where the law requires retention, data is kept for that period, and it may be retained exceptionally to the extent necessary for legitimate purposes such as misuse prevention and security incident response. Account withdrawal and full data deletion can be requested via in-service features or at [email protected]; we process it after verifying your identity and notify you of the result.
4. Entrustment and cross-border transfer
To provide a stable service, the Company entrusts personal data processing as below, and some processors are located overseas, so personal data may be transferred and processed abroad. You have the right to refuse this processing, but refusal may limit all or part of the Service.
| Processor | Entrusted task | Transferred items | Country |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, storage hosting | Account info, all content | USA |
| Google LLC | Social login authentication | Email, profile, account identifier | USA |
| Anthropic, PBC | AI plot coach (generative AI) processing | Questions and related chapter/setting excerpts | USA |
| Voyage AI | Embedding generation for chapter search | Parts (chunks) of chapter text | USA |
| Vercel, Inc. | Application hosting and deployment | Data during use of the Service | USA, etc. |
※ Timing/method of transfer: transferred as needed over the network when you use the Service. Processors’ data-protection measures and contacts follow each company’s policy. The above is kept up to date for the actual providers and regions used.
5. Provision to third parties
The Company does not provide personal data to third parties without the user’s consent, except as required by law.
6. Data subject rights and how to exercise them
You may at any time request access, correction, deletion, suspension of processing, and withdrawal of consent. You can request via in-service features or at [email protected], and the Company acts without delay. We do not collect personal data of children under 14.
7. Destruction procedure and method
When the retention period elapses or the purpose is achieved, electronic files are deleted irrecoverably and printouts are shredded or incinerated.
8. Security measures
We implement technical and administrative protections required by law, such as access rights management, transit encryption (HTTPS), and access control.
9. Cookies and automatic collection
The Company uses essential cookies to maintain the login session. You may refuse cookies in your browser settings, but doing so may limit some features such as login.
10. Data protection officer
Name: Jaewoong Cho · Contact: [email protected]
For privacy infringements, data subjects may consult or report to bodies such as the Personal Information Dispute Mediation Committee and the KISA Privacy Infringement Report Center (privacy.kisa.or.kr / 118 toll-free).
11. Changes to this policy
This policy applies from its effective date; any changes will be announced within the Service.