1. Personal Data Collected
- Account information: email and encrypted or hashed authentication information required for login
- Asset management data: asset names, categories, principal, valuations, transactions, history records, and FX rates entered by the user
- Snapshot records: point-in-time asset valuation data saved by the user
- Family asset data: asset records entered by the user for family assets
- External market data lookup information: ticker symbols, markets, and exchange information entered or selected by the user
- Service usage data: access time, browser information, login session cookies, display preference cookies, localStorage settings, and notice dismissal state
- App settings: theme, language, font, layout, private mode, and asset list and snapshot display preferences of logged-in users are stored on the server for cross-device synchronization. Settings of non-logged-in users are not stored on the server.
2. Cookies and Browser Storage
- Login session cookies are used to maintain authentication state and restrict access to each user's asset data.
- Display preference cookies are used to preserve theme, language, private mode, asset category order, color scheme (Korean/global), font type and size, layout width, market widget enable state and ticker settings, landing page, and asset list sorting, category filters, and archived asset display state across refreshes.
- localStorage settings store theme, language, private mode, asset list sorting and filters, statistics view mode, snapshot display settings, demo data state, and notice dismissal state in the user's browser.
- Batch input drafts may temporarily store asset input values in the user's browser localStorage so unfinished entries can be restored before submission.
- Display preference cookies are retained for up to one year, and localStorage items may remain until the user clears browser storage or resets the related settings or drafts in the app.
3. Purpose of Use
- User identification, login, and account management
- Asset record storage, history comparison, statistics, and return calculations
- Stock and ETF price, FX rate, and symbol list lookup and search features
- User setting storage with cross-device server sync for logged-in users, display optimization, and demo data state management
- Error diagnosis, security maintenance, and abuse prevention
- Visit statistics and service performance measurement
4. Retention Period
- Account and asset data are retained until account deletion, withdrawal, or the user's deletion request.
- Users may request account deletion through the account deletion feature in Settings. Upon account deletion, the Supabase authentication account and user-specific data become subject to deletion.
- Asset records deleted by the user are removed from the service interface and database.
- Scheduled Supabase project backups are not currently used, while infrastructure logs may be retained to the extent needed for service operation and security checks.
- The service currently does not provide payment or e-commerce features, so there are no separate payment or transaction records retained under related laws. If applicable law requires retention in the future, data may be kept for the legally required period.
5. Third-Party Provision and Processing
- The service does not sell or provide personal data to third parties without legal grounds or user consent.
- Supabase is used for email-based user authentication and database storage and management.
- The Supabase project runs in the Northeast Asia (Tokyo), ap-northeast-1 region, which is located in Japan.
- Vercel, Vercel Analytics, and Vercel Speed Insights are used for deployment, hosting, access logs, visit statistics, and performance measurement.
- The Vercel Functions execution region is set to Seoul, South Korea (Northeast), ap-northeast-2, icn1.
- Yahoo Finance is used for stock, ETF, and FX rate lookup, and ticker symbols, markets, and exchange information may be transmitted for lookup purposes.
- Public Data Portal APIs are used for Korean stock and ETF symbol lists, and Finnhub APIs are used for U.S. stock and ETF symbol lists.
- On the Vercel Hobby plan, Runtime Logs are retained for 1 hour, the Web Analytics reporting window is 1 month, and the Speed Insights data point reporting window is 7 days.
6. Cross-Border Transfer
- Account authentication data and asset management data processed through Supabase may be stored or processed in the Japan region (Northeast Asia, Tokyo, ap-northeast-1).
- The purpose of cross-border processing is user authentication, user-specific data storage and management, service provision, and security maintenance.
- When using infrastructure operated by overseas providers such as Vercel, Yahoo Finance, and Finnhub, access logs, browser information, performance measurement data, ticker symbols, markets, and exchange information may be processed outside Korea.
- Vercel Functions are configured to run in the Seoul, South Korea region (ap-northeast-2, icn1), while Vercel platform features such as CDN, Analytics, and Speed Insights may be processed according to the provider's global infrastructure and policies.
7. User Rights
- Users may request access, correction, deletion, or suspension of processing for their personal and asset data.
- Asset data and accounts with in-service deletion features may be deleted directly by the user. Additional requests may be submitted through the operator contact.
- Rights requests will be processed within 10 days of receipt. If processing is not possible, the reason will be communicated.
- When entering family asset data, the user must have proper authority or consent to enter and manage that information.
- Users under the age of 14 may have their access restricted. If an account held by a user under 14 is identified, access may be limited or the account may be deleted.
8. Security Measures
- The service protects personal data through HTTPS, authentication-based access control, user-level data restrictions, and environment variable management.
- Passwords are not stored in plain text and are managed by the authentication provider in encrypted or hashed form.
- Users are responsible for safely managing their account credentials and login methods.
- In the event of a security incident such as a data breach, the operator will take measures to minimize harm and notify affected users in accordance with applicable law.
9. Privacy Officer and Contact
- Privacy inquiries and requests for access, correction, deletion, or suspension of processing may be submitted to the privacy officer below.
- Privacy Officer / Operator: Jaekyung Kim
- Email: tkwk120506525@gmail.com
- Phone: +82-10-9357-5647