HanFlow AI Privacy Policy
- Effective date: May 25, 2026 · Last revised: August 27, 2026 (English version published July 22, 2026)
- Data controller: Quantum Materials Co., Ltd. (CEO: Hwan-Yeol Park · Business Registration No. 734-88-03845 · E-commerce Registration No. 2026-Chungnam-Asan-0713)
- Address: B410, Industry-Academic Cooperation Building, 22-7 Soonchunhyang-ro, Sinchang-myeon, Asan-si, Chungcheongnam-do, Republic of Korea
Quantum Materials Co., Ltd. (the "Company") complies with the Personal Information Protection Act of Korea and other applicable laws, and processes personal information as follows. This English translation is provided for convenience; in case of conflict, the Korean version (hanflowai.com/privacy) prevails to the extent permitted by applicable law.
Article 1 (Information We Collect)
| Category | Items | When collected |
|---|---|---|
| Required | Email, password (stored as a hash), display name | Sign-up |
| Optional | Marketing consent, referrer email | Sign-up |
| Social login | Google or Kakao account identifier, email, profile (name/photo) | Social login |
| Payment | Payment history (plan/amount/time), payment-instrument token (raw card numbers are held by the payment processor) | Paid checkout |
| Automatically | IP address, cookie/local-storage values (login session, device identifier), browser/OS info, access logs | While using the Service |
| Security verification | Email verification codes, login device/IP history | Sign-up, new-device login |
| Content | Uploaded files (documents, images, etc.), prompts, AI-generated results | While using the Service |
※ We do not collect personal information of children under 14; sign-up includes an age-confirmation step that blocks them.
Article 2 (Purposes of Use)
- Member identification, authentication, and account management (including new-device login checks)
- Providing the AI document generation service and delivering/storing results
- Paid-plan payment, refunds, and credit settlement
- Customer support and service notices
- (With consent) marketing and promotional communications
- Fraud prevention (multi-account, referral abuse, etc.) and security incident response
- Service quality improvement (statistics are de-identified)
- Compliance with legal obligations
Article 3 (Retention Periods)
| Category | Retention | Basis |
|---|---|---|
| Member information | Until account deletion | Consent |
| Uploaded files, AI results (workspace storage) | Until the user deletes them or deletes the account | Contract performance |
| Temporary files from generation jobs | Periodically purged after the period needed for operations | Service provision |
| Job metadata (request type, credit usage) | 90 days | Quality improvement, billing disputes |
| Login device/IP history | 90 days from last seen | Account protection |
| Payment records | 5 years | Korean E-commerce Act |
| Contract / withdrawal records | 5 years | Korean E-commerce Act |
| Consumer complaint / dispute records | 3 years | Korean E-commerce Act |
| Access logs | 3 months | Protection of Communications Secrets Act |
Personal information whose retention period has expired or whose purpose has been achieved is destroyed without delay by irreversible means (electronic files: permanent deletion; printouts: shredding/incineration).
Article 4 (Processors and Cross-Border Transfers)
The Company does not, in principle, provide personal information to third parties. For service provision (contract performance), processing is entrusted as follows; some processors are located abroad. Cross-border transfers are disclosed through this policy pursuant to Article 28-8(1)3 of the Personal Information Protection Act (entrustment/storage necessary for contract performance). Transfers occur over telecommunications networks at the time of service use, and information is retained until the entrusted purpose is achieved (or per Article 3).
| Processor | Entrusted work (transferred items) | Country | Contact |
|---|---|---|---|
| Anthropic, PBC | AI text generation (prompts, uploaded document content, results) | USA | privacy@anthropic.com |
| OpenAI, L.L.C. | AI image generation (image request content) | USA | privacy@openai.com |
| Google LLC | Social login authentication (account identifier, email, profile) | USA | support.google.com |
| Kakao Corp. | Social login authentication (account identifier, email, profile) | Republic of Korea | cs@kakao.com |
| Fly.io, Inc. | Backend server operation and data storage (service data) | Japan (Tokyo region) | support@fly.io |
| Cloudflare, Inc. | Web hosting, CDN, security (WAF), file storage (R2) | Global edge (Korea preferred) | privacy@cloudflare.com |
| Resend (Plus Five Five, Inc.) | Email delivery (verification/notification email addresses) | USA | support@resend.com |
| Google LLC (Google Drive) | Secondary storage of database backups | USA | support.google.com |
Notice regarding payment providers (third-party provision and cross-border transfer)
To process paid checkout, the Company provides user personal information to the payment provider below. That provider acts as merchant of record and reseller, and its own Data Processing Agreement states that it is an independent data controller in respect of buyer payment data. This is therefore not entrustment but a third-party provision and cross-border transfer under the Personal Information Protection Act, and the transfer is made with the user's separate consent under Article 28-8(1)1 of that Act. Consent is obtained on the screen shown immediately before the checkout window opens.
| Recipient | Purpose (categories transferred) | Country | Contact |
|---|---|---|---|
| Dodo Payments Inc. (a Delaware, USA corporation) | Payment processing, settlement and tax filing (name, email address, billing country, order identifier, purchased product information) | United States | support@dodopayments.com |
| Dodope Payments Limited (affiliate) | Same as above | United Kingdom | support@dodopayments.com |
| Sarvapanchhi Technologies Private Limited (affiliate) | Same as above | India | support@dodopayments.com |
- Timing and method: at the moment the user opens the checkout window, the data is transmitted over the network from the user's browser to the provider's checkout page under encryption (HTTPS). Card numbers and other original payment-instrument details are collected directly by the provider and are not stored on the Company's servers.
- Storage location and sub-processors: the data is stored in the Amazon Web Services Mumbai region (ap-south-1), India. The provider's sub-processors are Amazon Web Services, Airwallex, Stripe and Cashfree.
- Retention: retained until the end of the applicable statutory limitation period plus two (2) months following the end of the relationship; upon termination of the service agreement the data is deleted or returned within thirty (30) business days.
- Right to refuse and consequences: the user may refuse consent to this cross-border transfer. In that case the paid checkout cannot be used. Free use of the Service is unaffected.
- Governing law and jurisdiction: the agreement with the provider is governed by the law of the State of Delaware, USA, and the US courts have exclusive jurisdiction.
Data-protection measures for AI subprocessors: For user inputs (prompts, uploaded content) and generated results sent to AI providers (Anthropic, OpenAI), the Company configures and manages processing so that:
- No use for model training: These subprocessors do not use data submitted via their API to train or improve their AI models (the default policy of each provider's API terms). The Company does not consent to, and does not enable, any training-use option.
- Minimized retention: Transmitted data is retained only briefly for limited purposes such as abuse-monitoring and is then deleted; it is not subject to long-term storage or indexing. The Company applies a store-disable setting (store=false) to API requests where available.
- No collection on proxied routing: Where requests are routed through an intermediary, the Company enforces routing only to upstream providers that do not collect, retain, or train on data (zero data collection).
- No secondary use: This data is not used for advertising, marketing, or sale to third parties.
Users may refuse cross-border transfer by declining to sign up or use the Service; in that case the Service cannot be provided. No cross-border transfers are made for marketing purposes.
Article 5 (Your Rights)
You may at any time:
- Request access to your personal information
- Request correction or deletion of errors
- Request suspension of processing
- Withdraw consent (including marketing consent) and delete your account
- Request data portability (download)
How to exercise: the in-service Settings menu, or the contact in Article 8 (email/phone). The Company acts without delay (within 10 days) and notifies you of the result.
Article 6 (Security Measures)
- Passwords stored with one-way encryption (Argon2id)
- TLS encryption in transit (HTTPS), web application firewall (WAF), and rate limiting
- Additional email verification for logins from new devices/IPs
- Least-privilege access control and access logging
- Regular security reviews (including dependency vulnerability checks) and an incident response process
Article 6-2 (Breach Notification)
Under Article 34 of the Personal Information Protection Act, upon becoming aware of a breach the Company will:
- Notify within 72 hours: notify affected users within 72 hours of awareness and, where legally required, report to the Personal Information Protection Commission (or KISA).
- Notification contents: items leaked / time and circumstances / expected harm / the Company's countermeasures / how users can minimize harm / report and inquiry contacts
- Method: email, in-service notice, or website announcement, whichever is fastest; for large-scale breaches a website announcement is made in parallel.
- Follow-up: root-cause analysis, recurrence prevention, and notification of results.
Article 7 (Cookies and Similar Technologies)
The Service uses only essential cookies and local storage for login session persistence and account protection (device identification). No advertising or behavioral-analytics cookies are used. You may block cookies in your browser settings, but features requiring login will then be limited.
Article 8 (Privacy Officer)
- Name: Hwan-Yeol Park
- Title: CEO
- Email: info@qmscience.net
- Phone: +82-70-7609-1376
Article 9 (Remedies)
- Personal Information Dispute Mediation Committee (+82-1833-6972, www.kopico.go.kr)
- Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
- Supreme Prosecutors' Office (1301, www.spo.go.kr)
- National Police Agency Cyber Bureau (182, ecrm.police.go.kr)
Article 10 (Changes to This Policy)
This policy took effect on May 25, 2026. Changes are announced in the Service at least 7 days before taking effect (30 days for material changes).
- Revised July 21, 2026: processor list aligned with the current service (Anthropic, OpenAI, Kakao, Resend, backup storage), file retention aligned with actual operation (workspace storage), cross-border transfer basis updated to the amended Personal Information Protection Act (Article 28-8), cookie usage corrected to reflect essential-only use.
- July 22, 2026: English version published.
- Revised July 24, 2026: added "Data-protection measures for AI subprocessors" to Article 4, stating that AI providers do not use user data for model training, retain it only briefly before deletion, and that requests are routed only to providers that do not collect data.
- Revised August 6, 2026: Article 4 now states that as of the revision date no personal information is entrusted to any payment gateway. Any new payment gateway will be disclosed in advance by revising this policy.
- Revised August 7, 2026: the planned adoption of a payment gateway was cancelled, and the corresponding entry — listed in anticipation of that adoption — was removed from the processor list. This Service has never put any payment-gateway integration into operation, and no user personal information has ever been provided to or entrusted with a payment gateway.
- Revised August 27, 2026: with the launch of paid checkout, Article 4 adds a Notice regarding payment providers (third-party provision and cross-border transfer). Because the provider is a merchant of record and therefore an independent controller, the disclosure is made as a third-party provision and cross-border transfer rather than as entrustment, and states the entity names, countries (United States, United Kingdom, India), categories transferred, timing, method, storage location and retention period. Because this change rests on the user’s separate consent, it applies from the moment that consent is given, as set out in the proviso to Article 9.