Skip to content
Spectra
KO EN 中文
Back home
  1. Home
  2. Privacy Policy

Spectra

Privacy Policy

Effective: May 3, 2026
Last revised: May 3, 2026

This is an informational translation provided for convenience. The Korean-language version is the legally authoritative text; in case of any discrepancy, the Korean version governs.

Spectra ("the Service" or "the Company") processes personal data lawfully and safely in accordance with South Korea's Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization, and related regulations.

1. Purpose of processing

The Company processes personal data to: (1) manage membership and prevent misuse of the Service; (2) provide the Service — AI-based note organizing, to-do extraction, reminder suggestions, and storage of organized results; (3) improve the Service and analyze errors; and (4) fulfill legal record-keeping obligations. Data is not used beyond these purposes without additional consent where required by law.

2. Data we collect

Required: social account info (name, email, profile photo URL via Google/Apple OAuth); service usage data (note content, AI-organized results, reminder settings).
Automatically collected: access timestamps, app version, OS info; crash logs (used only for service stability).
Sensitive data: the Company does not separately collect sensitive data such as health, beliefs, or political views.

3. Retention period

Personal data is retained while you use the Service and deleted without delay upon account deletion, except where law requires longer retention: consumer protection records (contracts, payment, complaints) — 3–5 years; service access logs under the Protection of Communications Secrets Act — 3 months; anti-fraud records — 1 year.

4. Destruction of data

Data is destroyed without delay once the retention period ends or the processing purpose is achieved — electronic files are permanently deleted in an unrecoverable manner, and printed records are shredded or incinerated.

5. Disclosure to third parties

The Company processes personal data only within the purposes stated in Section 1 and does not provide it to third parties except with your prior explicit consent, as required by law, or upon lawful request from investigative authorities. The Company does not currently provide personal data to third parties.

6. Data processing entrusted to others

Supabase Inc. — server infrastructure and database hosting, retained until contract termination.
Google LLC — social login (OAuth 2.0) authentication, retained until authentication completes.
Apple Inc. — Sign in with Apple authentication, retained until authentication completes.
Anthropic, PBC — AI-based note organizing and to-do extraction, deleted immediately after processing (not retained after the response is generated).

7. Cross-border transfer

To provide the Service, personal data (name, email, service usage data) is transferred to the United States, where Supabase Inc., Google LLC, Apple Inc., and Anthropic PBC process it for the purposes described in Section 6, for the retention periods described in Section 3. You may decline this transfer, but the Service cannot be provided without it.

8. Your rights

You may request access to, correction or deletion of, and suspension of processing of your data, and may withdraw consent at any time. Exercise these rights via [Profile] → [Delete Account] in the app, or by emailing the contact below. While a correction or deletion request is pending, the Company does not use or disclose the data in question.

9. Security measures

Technical: SSL/TLS encryption in transit; database Row Level Security so you can only access your own data; social login tokens stored only in on-device secure storage; least-privilege server access control.
Administrative: a designated data protection officer, regular training, and periodic access review.
Physical: reliance on our cloud provider's (Supabase) physical security policies.

10. Cookies and similar technologies

The Service stores an authentication token in on-device secure storage to keep you signed in. This is the minimum information needed to maintain your session and is removed when the app is deleted.

11. Data protection officer

Contact: service.help@outlook.kr. Responses within 10 business days of receipt.

12. Remedies for rights violations

You may seek dispute resolution or consultation from South Korea's Personal Information Dispute Mediation Committee (www.kopico.go.kr, 1833-6972) or the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118).

13. Changes to this policy

Material changes will be announced in-app at least 7 days in advance (30 days for changes unfavorable to users), together with the reason for the change.

Supplementary

This policy takes effect May 3, 2026.

Spectra
AboutPrivacy PolicyTerms of ServiceContact한국어中文

© 2026 Spectra