Privacy Policy
Effective date: June 10, 2026
PerovMax (the “Service”) complies with the Personal Information Protection Act (PIPA) and other applicable laws, and maintains the following policy to protect users’ personal information.
1. Personal Information Collected
- Sign-up and login: email address, password (stored encrypted)
- Measurement data (such as J-V and EQE) and analysis settings uploaded by the user while using the Service
- Automatically collected: access records (such as IP address and access time, for abuse prevention), cookies (to maintain login sessions and preferences, and to prevent automated sign-ups)
2. Purpose of Collection and Use
- Member identification and authentication; provision and operation of the Service
- Providing measurement data analysis features and storing results
- Responding to inquiries, improving the Service, and preventing misuse
3. Retention and Use Period
In principle, a user’s personal information is destroyed without delay upon account withdrawal (deletion). When an account is deleted, the uploaded measurement data is destroyed together. Where retention is required by applicable law (for example, access logs under the Protection of Communications Secrets Act), the information is kept for the period prescribed by that law and then destroyed.
4. Consignment and Provision to Third Parties
The Service consigns the processing of personal information as follows for smooth operation:
- Supabase Inc.: database storage and user authentication
- Anthropic PBC: AI-based measurement data analysis (automatic inference of uploaded file formats)
- Resend: sending email verification and password reset messages
- Vercel Inc.: service hosting (infrastructure operation)
- Cloudflare, Inc.: prevention of automated sign-ups (bots) and security
Except where based on law or with the user’s separate consent, the Service does not provide personal information to third parties.
5. Overseas Transfer of Personal Information
The Service processes personal information overseas through the following processors. The recipient, country, items, purpose, and retention period are as set out below; the transfer occurs over the network at the time of use of the Service.
- Supabase Inc. — USA (entity) · data center: Singapore / email, authentication data, uploaded measurement data / database storage and authentication / until account withdrawal or termination of the consignment contract
- Anthropic PBC — USA / contents of uploaded measurement files (subject of analysis) / AI format inference and analysis / used immediately and not retained (API call)
- Vercel Inc. — USA / access records and request information / service hosting / until the log retention period elapses
- Cloudflare, Inc. — USA / IP address and access information / bot prevention and security / until the purpose is achieved (temporary)
- Resend — USA / email address / sending verification and reset emails / per the provider’s policy after delivery
Users may refuse the overseas transfer of their personal information; however, doing so may limit the use of core features such as sign-up, login, and measurement data analysis.
6. Rights of Users and How to Exercise Them
Users may at any time request access to, correction or deletion of, or suspension of processing of their personal information. Users can destroy their data directly by deleting their account from the in-app settings screen; when an account is deleted, the uploaded measurement data is destroyed together. Other requests received at the contact below (Section 11) will be addressed without delay in accordance with applicable law. For children under 14, a legal guardian may exercise these rights. The Service does not disadvantage users for exercising their rights.
7. Procedure and Method of Destruction
Personal information for which the retention period has elapsed or the purpose of processing has been achieved is destroyed without delay. Electronic files are permanently deleted by a method that prevents recovery or reproduction, and other records such as printouts are shredded or incinerated.
8. Measures to Ensure Security
- Encrypted storage of sensitive information such as passwords; HTTPS encryption in transit
- Per-user data isolation through row-level security (RLS) and minimization of access privileges
- Retention of access logs and prevention of unauthorized access (such as login attempt limits)
- Prevention of automated sign-ups (CAPTCHA) and blocking of brute-force attacks
9. Cookies and Automatic Collection: Operation and Refusal
The Service uses cookies to maintain login sessions, remember preferences, and prevent automated sign-ups (bots). Users may refuse the storage of cookies or delete stored cookies through their web browser settings. However, refusing the login session cookie may limit the use of certain features such as login.
10. Personal Information of Children Under 14
The Service is not directed to children under the age of 14 and does not accept sign-ups or collect personal information from children under 14.
11. Privacy Officer and Contact
For inquiries, complaints, or remedies regarding the processing of personal information, please contact:
Privacy Officer (Operator): Dong-Gun Lee
Contact: padawan1215@gmail.com
12. Remedies for Infringement of Rights
If you need counseling or to report an infringement of personal information, you may contact the following Korean authorities:
- Personal Information Dispute Mediation Committee: 1833-6972 · www.kopico.go.kr
- Privacy Infringement Report Center (KISA): 118 · privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cybercrime Investigation: 1301 · www.spo.go.kr
- National Police Agency, Cyber Bureau: 182 · ecrm.police.go.kr
13. Changes to This Policy
This policy may be revised in line with changes in law or the Service. Any change, together with its effective date, will be announced in advance within the Service.
This English translation is provided for convenience only. In the event of any discrepancy between this version and the Korean version, the Korean version shall prevail.