Privacy Policy
Exactly what this site receives, where it keeps it, and when it deletes it. Written under Article 30 of the Korean Personal Information Protection Act (PIPA) and the Privacy Policy Drafting Guidelines (April 2025).
Effective 2026-09-09 · 한국어
1. At a glance
Your answers are stored only in this browser tab, are discarded when you close the browser, and are not linked to any account. When scoring is done on the server, only the numbers you chose are sent, and they are not stored.
We store the identifier, name and email that Google or Kakao gives us, together with your answers. Buying the full report adds an order record. Age band and gender are optional and may be left blank.
Your answers and results are used only to compute your results. We never sell them, use them for advertising, or profile you. We do not receive card numbers, passwords, national ID numbers, phone numbers, postal addresses or location data.
2. Purposes, data items and legal basis
The Operator (Section 13) processes only the items below, for the purposes below. If a purpose changes we will ask for consent separately.
- Account identification and continuing across devices (required) — items: the unique identifier, name (nickname) and email address provided by the login provider (Google or Kakao); sign-up and last-seen timestamps. Basis: performance of the service contract (PIPA Art. 15(1)(4)). Your password is never passed to us or stored.
- Computing results and continuing across devices (required) — items: the number between −3 and +3 you chose for each question (answer record) and the results computed from it. Basis: performance of the service contract (PIPA Art. 15(1)(4)). Answers are used only to compute results and show them to you; they are never provided to anyone else or used for advertising, marketing or profiling. Because answers about philosophical leanings may be read as information about thought or belief, we treat them with particular care.
- Performing and recording the paid-service contract (required when you buy) — items: order number, product, amount and currency, type of payment method, payment provider transaction ID, payment and refund timestamps, and your consent to the withdrawal restriction. Basis: performance of the contract (Art. 15(1)(4)) and legal obligation under Article 6 of the Korean E-Commerce Act (Art. 15(1)(2)). Card and bank details are processed by the payment provider and never reach us.
- Peer-comparison statistics (optional) — items: age band (teens, 20s, 30s, 40s, 50s or 60+) and gender. Basis: your consent (Art. 15(1)(1)). The fields start empty; leaving them blank or clearing them later does not restrict your use of the Service in any way (Art. 16(3)). Details in Section 7.
- Enquiries and refunds — items: the email address and content you send us, and your order number. Basis: performance of the contract and legal obligation.
- Stable operation (collected automatically) — items: request time, request path, response code, IP address and browser type. These server logs are used to find errors and block abusive traffic; answer content is not logged. Basis: legitimate interest (Art. 15(1)(6)).
3. Retention periods
The rule is deletion when you close your account. Records that the law requires us to keep are separated from your other personal data and kept only for the periods below, then destroyed.
- Account data (identifier, name, email), answer records, age band and gender — until you close your account or ask for deletion. After closure we destroy them without delay (within 5 days).
- Records of contracts and withdrawals, and of payment and supply of goods — 5 years (Enforcement Decree of the E-Commerce Act, Art. 6). After closure, the name and email are removed from order records and only the account identifier and order details are kept separately.
- Records of consumer complaints and dispute handling — 3 years (same Article).
- Records of labelling and advertising — 6 months (same Article).
- Server request logs — 30 days. Administrator access logs for the personal-data system — at least 1 year (Standards for Safeguarding Personal Information).
- Progress stored in your browser (sessionStorage) — until you close the browser tab, or sooner if you clear it yourself. It is not on the server.
4. Provision to third parties
We do not provide personal data to third parties. The only exceptions are where a specific law requires it, where an investigative agency requests it under the procedure set out in law, or where you have given separate consent; where possible we will tell you when this happens. We never sell or hand over answer records or results to advertisers, data brokers or anyone else.
5. Outsourced processing
We entrust the following companies with processing on our behalf. Our agreements with them prohibit processing for any other purpose, require security measures, restrict sub-processing and provide for oversight. If a processor changes, we update this policy.
- Google LLC — Firebase Hosting (web hosting), Cloud Run (the server that scores answers and handles login and payment integration), Cloud Firestore (storage of accounts, answers and orders) and Firebase Authentication integration. Items: everything listed in Section 2. See Section 6 for processing outside Korea.
- KakaoPay and Toss Payments — domestic payment processing and refunds. Items: order number, amount, and the payment details you enter on the provider's own screen. Card details are handled by the provider only.
- Paddle.com Market Ltd. — international payments. Paddle acts as the merchant of record and processes payment, tax and refunds on its own responsibility, and within that scope is an independent controller. Items: email address, order number, amount, country. Paddle's privacy policy: paddle.com/legal/privacy
Google and Kakao, as login providers, pass your identifier, name and email to us with your consent. Data they process during login is governed by their own privacy policies. Kakao login consent is limited to nickname (and email); gender and age band are not obtained from Kakao and are collected only through our own optional form (Section 7).
6. Transfer of personal data outside Korea (overseas outsourcing and storage)
The company entrusts the processing and storage of personal data outside Korea as follows, for the operation of the Service (PIPA Art. 28-8(1)(3)).
- Recipient: Google LLC (United States, 1600 Amphitheatre Pkwy, Mountain View) · contact: privacy.google.com / support.google.com/policies
- Items transferred: account identifier, name, email, answer records, (optional) age band and gender, order records
- When and how: transmitted and stored over the network as you use the Service (primary storage location: Google Cloud Seoul region)
- Purpose: data storage and authentication (Firebase), server execution (Cloud Run)
- Retention: until you close your account (records with a statutory retention period: the periods in Section 3)
- How to refuse: you may stop using the Service or contact us at the address below; refusing may limit your use of the Service.
Data is stored in the Seoul region, but because the contracting party is Google LLC, a US company, and cross-border access may occur during backup and technical support, we conservatively disclose this as an overseas transfer. Only if you choose international payment (Paddle) are your email and order details transferred to Paddle.com Market Ltd. (London, United Kingdom) for payment processing, retained for the periods Paddle is legally required to keep them. No data goes to Paddle if you pay through a Korean provider.
7. Peer-comparison statistics
If you enter an age band and gender, we show you the average results of users in the same group (age band × gender). This feature is processed only as follows.
- For each group we store only the head count and score totals. Who answered what is not part of the statistics.
- If a group has fewer than 20 people, the statistics are not shown, to prevent re-identification.
- If you clear your age band and gender, your later results are no longer added to the statistics. Values already added to the totals cannot identify anyone.
- The statistics the Operator can see are aggregates only; there is no screen for viewing individual answers.
8. Destruction procedure and method
We destroy personal data without delay once the retention period ends or the purpose is achieved. To close your account, email the contact in Section 13; we verify your identity (by matching the login email), destroy the data within 5 days and confirm the result. Electronic files are deleted in a way that cannot be recovered; records with a statutory retention period are moved to separate storage under Section 3 and destroyed the same way when that period ends. We create no paper records.
9. Your rights and how to exercise them
You (or your legal representative or an authorised agent) may at any time request access to, correction or deletion of, or suspension of processing of your personal data, and withdraw consent.
- Directly on screen — pressing Start over or Clear and restart on the results screen clears the progress stored in your browser and, if you are logged in, also deletes the answer record stored in your account. On the profile screen you can change your age band and gender.
- By contacting us — to delete your age band and gender (withdraw consent), delete your account, or request access, correction or suspension, email the address in Section 13; after verifying your identity we act within 10 days and tell you the outcome. We may refuse to delete records we are legally required to keep, and will tell you why.
- If an agent makes the request, please include a letter of authorisation or other proof of the relationship.
- Exercising your rights never disadvantages you. If you ask us to stop processing or delete required items, account-based features will no longer be available.
10. Security measures
- All traffic is encrypted with HTTPS, and stored data is protected by Google Cloud encryption at rest.
- Login state is verified only through a signed cookie; forged values are rejected immediately. The server accepts only known question IDs and integers between −3 and +3.
- The database cannot be reached directly from outside; data is read and written only through the server and only for your own account (least-privilege rules).
- The administrator account uses two-factor authentication, the admin screen shows aggregates only, and access logs are kept.
- Card numbers, CVCs and other payment details never pass through our systems and are never stored or logged in any form. The payment page carries no advertising or analytics scripts.
- Only the representative handles personal data, under an internal management plan that is reviewed regularly.
11. Cookies and automatic collection
Our own cookies — we use cookies only to keep you logged in. If you do not log in, no cookie is set.
- phs — login session. Set with HttpOnly, SameSite=Lax and Secure, so it cannot be read by JavaScript or sent to other sites; expires after 30 days and is deleted immediately when you log out.
- phf — a temporary cookie used only while social login is in progress (request-forgery protection). Deleted as soon as login completes.
- sessionStorage — for users who are not logged in, progress and display settings are stored in the browser tab only, are discarded when the browser closes, and are never sent to the server.
You can refuse cookies in your browser settings; only the login feature will then be unavailable.
Advertising cookies (third party) — Google AdSense advertisements may appear on the free result pages. To serve them, Google and its advertising partners may use their own cookies and web beacons to personalise ads based on your visits to this and other websites. These cookies are set and controlled by Google, not by the Operator, and we never pass your answers or results to Google for advertising. No ads are shown on the question screens or the payment page.
- How Google uses advertising data: policies.google.com/technologies/ads
- Opt out of personalised ads: adssettings.google.com · other ad networks: aboutads.info/choices · youronlinechoices.com
12. Children under 14
The Service is available only to people aged 14 or over, and you confirm this when you log in. We do not knowingly collect personal data from children under 14; if we learn that we have, we delete the account and the data without delay. A parent or guardian may ask to access or delete a child's data through the contact in Section 13.
13. Privacy officer and where to send requests
As a small business, the Operator's representative serves as the privacy officer under Article 32(2) of the PIPA Enforcement Decree. All privacy enquiries, access requests, complaints and remedy requests go to the contact below.
Privacy officer (representative) the Operator
Contact letsknow.persona@gmail.com
If you are not satisfied with our response or need independent advice, you may contact the Korean Personal Information Infringement Report Center (privacy.kisa.or.kr / +82-118), the Personal Information Dispute Mediation Committee (kopico.go.kr / +82-1833-6972), the Supreme Prosecutors' Office cybercrime unit (spo.go.kr / +82-1301) or the Korean National Police Agency cyber bureau (ecrm.police.go.kr / +82-182).
14. Breach notification
If we become aware that personal data has been leaked, lost or stolen, we will notify the affected users by email without delay, stating the items involved, when and how it happened, how to minimise harm, and whom to contact, and we will report to the Personal Information Protection Commission or the Korea Internet & Security Agency within 72 hours under PIPA Article 34 and Articles 39 and 40 of its Enforcement Decree. Hacking and other intrusion incidents are reported to the Ministry of Science and ICT and KISA within 24 hours of discovery under Article 48-3 of the Network Act.
15. Scope, language and changes
The Service is operated from the Republic of Korea and this policy is written under Korean law. We do not direct our services to the EU/UK. We do not market to or maintain localised pages for any EU member state or the United Kingdom.
This English text is a translation provided for convenience. The authoritative version is the Korean text at /개인정보처리방침.html; if the two differ in meaning, the Korean version prevails.
When this policy changes we update the effective date on this page and record the change below. Changes that materially affect your rights (new data items or purposes, a change of overseas recipient, and the like) are announced on the home page 7 days before they take effect, and where consent is required we ask for it again. Earlier versions are available on request.
- 2026-09-09 — first version, covering social-login accounts, answer records, order records for the paid full report, optional items (age band and gender), outsourced processing and overseas transfer, AdSense cookies and breach notification.