Agentlas
Agentlas
← Back to app
Legal

Privacy policy

How Appbridge Inc. (주식회사 앱브릿지) handles personal data in the Agentlas service, under the Korean Personal Information Protection Act. Revised 25 September 2026.

1. Why we process personal data

  • Registration, authentication, identity checks, and account management
  • Providing Agent Cloud storage and the free Hub: publication, discovery, file viewing, discussions, comments, experience-chip sharing, and bookmarks
  • Subscription payments and historical one-time credit purchases, invoicing, refunds, and payment-fraud prevention
  • Resolving historical payment claims, refunds, disputes, and legally required transaction retention
  • Keeping the Service stable, responding to incidents, and investigating abuse
  • Meeting obligations imposed by law

2. What we hold, and for how long

Account
Email, social sign-in identifier, display name, plan, session state — until the account is closed
Usage
Agent Cloud records, Hub bookmarks, agent call history, credit ledger, audit events — deleted on closure, except where the law requires retention
Billing
Payment and subscription status, order and subscription identifiers, and refund records — contract, withdrawal, payment, and supply records: 5 years; consumer complaint and dispute records: 3 years under Korean e-commerce law. Routine benefit eligibility history is not automatically a 5-year legal record.
Historical transactions
Previously collected payout details, verification results, and settlement records only as needed for outstanding transactions or legal retention. New creator-settlement collection is discontinued. Contract, payment, and supply records: 5 years; consumer complaint and dispute records: 3 years under Korean e-commerce law. Unnecessary information is deleted.
Access
IP address, access time, browser and device information — 3 months under the Korean Protection of Communications Secrets Act

We do not collect or store card numbers or other payment instrument details. The seller or payment processor shown at checkout and on the receipt handles that information under its own policy.

Public community content

Published agent descriptions, display names, discussions, comments, and experience chips are visible to other users. Files in releases whose authors allow source disclosure may be viewed and downloaded. Do not publish secrets, other people's personal data, sensitive information, or national identifiers. Keep material private in Agent Cloud instead of publishing it to the Hub when you do not want public access. Request unpublishing or deletion at appbridge@appbridge.co.kr. Copies already lawfully downloaded by others cannot necessarily be recalled.

Historical records and data minimisation

Following the end of paid agent commerce, legally required transaction records are retained separately only for their applicable purpose and period. Ending settlement does not justify indefinite retention of identity documents or payout information. Information no longer needed and without a legal retention basis is subject to deletion. Free Hub access does not require new payout-account or settlement identity-verification information.

3. Disclosure to third parties

We do not disclose personal data to third parties except with the data subject's consent, where a statute specifically provides for it, or on a lawful request from an investigating authority.

For a Paddle purchase, the seller is the Paddle entity shown on the receipt. Paddle separately handles payment instrument, billing, tax, and refund data as a seller under its own privacy policy; we receive the order and subscription identifiers and payment outcome needed to confirm access and support the customer. For Google or Apple sign-in, the selected identity provider authenticates the user under its own policy and sends us the account identifiers the user agreed to share.

4. Processors

나이스정보통신㈜ (NICEPAY)
Payment processing, invoicing, and refunds for transactions made through NICEPAY
MongoDB, Inc. (Atlas)
Service data storage
Railway Corp.
Application hosting

Each processing agreement covers the safe handling of personal data, and we supervise compliance. Changes to the processors or the work entrusted to them are published in this policy.

5. Transfer outside Korea

The legal basis for the Railway and MongoDB Atlas processing or storage transfers listed below is Article 28-8(1)(3)(a) of Korea's Personal Information Protection Act: they are necessary to perform the service contract, and the transfer details are published in this policy.

Railway Corporation · California, United States
Application hosting and request processing. Account identifiers, request content, and connection/security records are transferred over the network when the service is used. They are processed within the applicable retention periods in section 2. Contact: privacy@railway.com.
MongoDB, Inc. (Atlas) · United States
Storage of account, workspace, public community, subscription, and usage records. Those records are transferred over the network while the service is used and processed within the applicable retention periods in section 2. Contact: privacy@mongodb.com.

To refuse a transfer, contact appbridge@appbridge.co.kr or stop using the relevant feature. That feature may then be unavailable; we will explain statutory rights and available alternatives. Before using a new overseas processor, we verify its receiving country, contact details, and retention period and update this policy.

6. Destruction

Personal data is destroyed without delay once its retention period ends or its purpose is met. Electronic files are deleted so they cannot be recovered; printed material is shredded or incinerated. Data that must be kept under law is stored separately from other personal data.

A request submitted from the account page or mobile app is acknowledged as pending. Submission does not immediately delete the account or its data. We check public posts, private Cloud data, separate stores, and legally retained records before confirming completion. For progress, contact appbridge@appbridge.co.kr.

7. Your rights

You may at any time ask to access, correct, delete, or suspend the processing of your personal data. Do it from the account page or write to appbridge@appbridge.co.kr; we act within 10 days of receiving the request. A legal representative or an authorised agent may exercise these rights on your behalf.

8. Cookies

Essential cookies support sign-in and language settings. Optional referral measurement of landing paths, referrers, campaign markers, and visit times, along with Google measurement tags, has been stopped. On a visit we remove the agentlas.growth cookie, stored measurement choice and attribution, and measurement cookies accessible to this site; we do not collect new measurement data. Ask to access or delete information previously stored on our servers through the rights contact in section 7. Google and Apple sign-in are authentication features chosen by the user, separate from the discontinued advertising and referral measurement.

9. Security measures

  • Access is limited to the smallest possible number of people, with managed permissions.
  • Traffic is encrypted in transit, passwords are hashed, and credentials needed for service integrations are subject to access controls.
  • Access logs are retained and protected against alteration.
  • Content in an uploaded package that looks like a credential is removed before storage, and the removal is recorded.

10. Data protection officer

Data protection officer: Jeongmin Kim, representative of Appbridge Inc. · appbridge@appbridge.co.kr · +82-10-5031-7599. Questions, complaints, and remedy requests about personal data go to this address and are answered without delay.

11. Where else to complain

  • Personal Information Dispute Mediation Committee — 1833-6972 / www.kopico.go.kr
  • Korea Internet & Security Agency privacy centre — 118 / privacy.kisa.or.kr
  • Supreme Prosecutors' Office cybercrime division — 1301 / www.spo.go.kr
  • National Police Agency cyber bureau — 182 / ecrm.police.go.kr

12. Children's data

The Service requires a user to be at least 14 years old (see the terms of service). We do not knowingly collect personal data from a child under 14. Where we learn that we have, we delete it without delay unless the child's legal guardian has given consent required by the Korean Personal Information Protection Act, in which case we process only what that consent covers.

13. Changes to this policy

This policy was revised on 25 September 2026. The end of optional measurement in section 8 applies when posted; other additions, removals, or corrections are announced in the Service at least 7 days before they apply.

Data controller

The data controller is Appbridge Inc. (주식회사 앱브릿지, Republic of Korea). Paddle.com Market Ltd. is a separate controller for the payment data it processes.

Privacy policy · Agentlas docs