HanFlow AI
AboutFeaturesSlidesCourse materialPricingFAQPDF
Sign inGet started

한국어 (Korean) →

HanFlow AI Privacy Policy

  • Effective date: May 25, 2026 · Last revised: July 24, 2026 (English version published July 22, 2026)
  • Data controller: Quantum Materials Co., Ltd. (CEO: Hwan-Yeol Park · Business Registration No. 734-88-03845 · E-commerce Registration No. 2026-Chungnam-Asan-0713)
  • Address: B410, Industry-Academic Cooperation Building, 22-7 Soonchunhyang-ro, Sinchang-myeon, Asan-si, Chungcheongnam-do, Republic of Korea

Quantum Materials Co., Ltd. (the "Company") complies with the Personal Information Protection Act of Korea and other applicable laws, and processes personal information as follows. This English translation is provided for convenience; in case of conflict, the Korean version (hanflowai.com/privacy) prevails to the extent permitted by applicable law.


Article 1 (Information We Collect)

Category Items When collected
Required Email, password (stored as a hash), display name Sign-up
Optional Marketing consent, referrer email Sign-up
Social login Google or Kakao account identifier, email, profile (name/photo) Social login
Payment Payment history (plan/amount/time), payment-instrument token (raw card numbers are held by the payment processor) Paid checkout
Automatically IP address, cookie/local-storage values (login session, device identifier), browser/OS info, access logs While using the Service
Security verification Email verification codes, login device/IP history Sign-up, new-device login
Content Uploaded files (documents, images, etc.), prompts, AI-generated results While using the Service

※ We do not collect personal information of children under 14; sign-up includes an age-confirmation step that blocks them.

Article 2 (Purposes of Use)

  1. Member identification, authentication, and account management (including new-device login checks)
  2. Providing the AI document generation service and delivering/storing results
  3. Paid-plan payment, refunds, and credit settlement
  4. Customer support and service notices
  5. (With consent) marketing and promotional communications
  6. Fraud prevention (multi-account, referral abuse, etc.) and security incident response
  7. Service quality improvement (statistics are de-identified)
  8. Compliance with legal obligations

Article 3 (Retention Periods)

Category Retention Basis
Member information Until account deletion Consent
Uploaded files, AI results (workspace storage) Until the user deletes them or deletes the account Contract performance
Temporary files from generation jobs Periodically purged after the period needed for operations Service provision
Job metadata (request type, credit usage) 90 days Quality improvement, billing disputes
Login device/IP history 90 days from last seen Account protection
Payment records 5 years Korean E-commerce Act
Contract / withdrawal records 5 years Korean E-commerce Act
Consumer complaint / dispute records 3 years Korean E-commerce Act
Access logs 3 months Protection of Communications Secrets Act

Personal information whose retention period has expired or whose purpose has been achieved is destroyed without delay by irreversible means (electronic files: permanent deletion; printouts: shredding/incineration).

Article 4 (Processors and Cross-Border Transfers)

The Company does not, in principle, provide personal information to third parties. For service provision (contract performance), processing is entrusted as follows; some processors are located abroad. Cross-border transfers are disclosed through this policy pursuant to Article 28-8(1)3 of the Personal Information Protection Act (entrustment/storage necessary for contract performance). Transfers occur over telecommunications networks at the time of service use, and information is retained until the entrusted purpose is achieved (or per Article 3).

Processor Entrusted work (transferred items) Country Contact
Anthropic, PBC AI text generation (prompts, uploaded document content, results) USA privacy@anthropic.com
OpenAI, L.L.C. AI image generation (image request content) USA privacy@openai.com
Payment gateway (Korea PortOne Inc.·KG Inicis) Domestic payment processing/integration (payment instrument, history) Republic of Korea —
Paddle.com Market Ltd International payment processing as Merchant of Record (email, order and payment details) — applies only when paying via international checkout United Kingdom privacy@paddle.com
Google LLC Social login authentication (account identifier, email, profile) USA support.google.com
Kakao Corp. Social login authentication (account identifier, email, profile) Republic of Korea cs@kakao.com
Fly.io, Inc. Backend server operation and data storage (service data) Japan (Tokyo region) support@fly.io
Cloudflare, Inc. Web hosting, CDN, security (WAF), file storage (R2) Global edge (Korea preferred) privacy@cloudflare.com
Resend (Plus Five Five, Inc.) Email delivery (verification/notification email addresses) USA support@resend.com
Google LLC (Google Drive) Secondary storage of database backups USA support.google.com

Data-protection measures for AI subprocessors: For user inputs (prompts, uploaded content) and generated results sent to AI providers (Anthropic, OpenAI), the Company configures and manages processing so that:

  1. No use for model training: These subprocessors do not use data submitted via their API to train or improve their AI models (the default policy of each provider's API terms). The Company does not consent to, and does not enable, any training-use option.
  2. Minimized retention: Transmitted data is retained only briefly for limited purposes such as abuse-monitoring and is then deleted; it is not subject to long-term storage or indexing. The Company applies a store-disable setting (store=false) to API requests where available.
  3. No collection on proxied routing: Where requests are routed through an intermediary, the Company enforces routing only to upstream providers that do not collect, retain, or train on data (zero data collection).
  4. No secondary use: This data is not used for advertising, marketing, or sale to third parties.

Users may refuse cross-border transfer by declining to sign up or use the Service; in that case the Service cannot be provided. No cross-border transfers are made for marketing purposes.

Article 5 (Your Rights)

You may at any time:

  1. Request access to your personal information
  2. Request correction or deletion of errors
  3. Request suspension of processing
  4. Withdraw consent (including marketing consent) and delete your account
  5. Request data portability (download)

How to exercise: the in-service Settings menu, or the contact in Article 8 (email/phone). The Company acts without delay (within 10 days) and notifies you of the result.

Article 6 (Security Measures)

  1. Passwords stored with one-way encryption (Argon2id)
  2. TLS encryption in transit (HTTPS), web application firewall (WAF), and rate limiting
  3. Additional email verification for logins from new devices/IPs
  4. Least-privilege access control and access logging
  5. Regular security reviews (including dependency vulnerability checks) and an incident response process

Article 6-2 (Breach Notification)

Under Article 34 of the Personal Information Protection Act, upon becoming aware of a breach the Company will:

  1. Notify within 72 hours: notify affected users within 72 hours of awareness and, where legally required, report to the Personal Information Protection Commission (or KISA).
  2. Notification contents: items leaked / time and circumstances / expected harm / the Company's countermeasures / how users can minimize harm / report and inquiry contacts
  3. Method: email, in-service notice, or website announcement, whichever is fastest; for large-scale breaches a website announcement is made in parallel.
  4. Follow-up: root-cause analysis, recurrence prevention, and notification of results.

Article 7 (Cookies and Similar Technologies)

The Service uses only essential cookies and local storage for login session persistence and account protection (device identification). No advertising or behavioral-analytics cookies are used. You may block cookies in your browser settings, but features requiring login will then be limited.

Article 8 (Privacy Officer)

  • Name: Hwan-Yeol Park
  • Title: CEO
  • Email: info@qmscience.net
  • Phone: +82-70-7609-1376

Article 9 (Remedies)

  • Personal Information Dispute Mediation Committee (+82-1833-6972, www.kopico.go.kr)
  • Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
  • Supreme Prosecutors' Office (1301, www.spo.go.kr)
  • National Police Agency Cyber Bureau (182, ecrm.police.go.kr)

Article 10 (Changes to This Policy)

This policy took effect on May 25, 2026. Changes are announced in the Service at least 7 days before taking effect (30 days for material changes).

  • Revised July 21, 2026: processor list aligned with the current service (Anthropic, OpenAI, Kakao, Resend, backup storage), file retention aligned with actual operation (workspace storage), cross-border transfer basis updated to the amended Personal Information Protection Act (Article 28-8), cookie usage corrected to reflect essential-only use.
  • July 22, 2026: added Paddle.com Market Ltd as processor for international payments; English version published.
  • Revised July 24, 2026: added "Data-protection measures for AI subprocessors" to Article 4, stating that AI providers do not use user data for model training, retain it only briefly before deletion, and that requests are routed only to providers that do not collect data.
  • Revised July 24, 2026: updated the domestic payment gateway to PortOne (Korea PortOne Inc.) and KG Inicis in the processor list to reflect the current payment integration.
HanFlow AI

한국어 문서 자동화의 새로운 표준.

제품
  • 기능
  • 슬라이드
  • 교육자료
  • 가격
지원
  • 자주 묻는 질문
  • 1:1 문의
  • 변경 이력
법률
  • 이용약관
  • 개인정보처리방침
  • 환불 정책
(주)퀀텀머티리얼즈 · 대표 박환열 · 사업자등록번호 734-88-03845 · 통신판매업신고번호 2026-충남아산-0713호 · 충남 아산시 신창면 순천향로 22-7 산학협력관 B410호 · 고객문의 070-7609-1376 · info@qmscience.net
© 2026 HanFlow AI. All rights reserved.
일부 아이콘: Solar Icons by 480 Design, CC BY 4.0