PRIVACY
Privacy Policy
This is a pre-launch draft. Company details and specifics will be finalized at launch, and we will ask for your consent again at that time.
This policy explains how Assemble Group (어셈블그룹)(“we”) processes personal information in the HAEDU service (website and studio) in accordance with the Personal Information Protection Act of Korea and other applicable laws. Items marked “when available” describe features that are not live yet and apply from the day each feature launches. If this English version differs from the Korean version, the Korean version prevails.
1. Information we process
| Category | Items | How we collect it |
|---|---|---|
| Sign-up and sign-in (required) | Email address, name, profile photo URL, Google account ID | Provided by Google when you sign in with Google |
| Consent records (required) | Versions of the terms and this policy, time of consent, optional consents and when they changed | Sign-up and settings screens |
| Service use (required) | Content profiles (brand or account descriptions, tone and style settings), brand kits, generation requests, AI outputs and their revisions, satisfaction feedback and the style memory derived from it, saved and reported references, posting schedules and posting history, share-link settings | What you enter and how you use the service |
| Company workspaces (if applicable) | Invitees' email addresses, roles, invitation, acceptance and leaving records | Entered by company admins |
| Payments (paid plans) | Depositor name, requested plan or add-on and amount, processing status and time | Payment request screen |
| Connected social accounts (optional, when available) | Platform account ID, username, profile photo, access tokens, granted permissions, post IDs and URLs, post performance (views, likes, comments, shares, saves), follower counts | When you authorize a connection on each platform and when you later request performance data |
| Files (when available) | Images, videos and audio you upload, and images and videos generated by AI | Upload and generation |
| Automatically generated | IP address, access time, browser and device information, sign-in session cookies, service usage records (generation success or failure, processing time, errors), AI safety check records | Generated automatically while you use the service |
2. Purposes
- Identifying members, confirming sign-up intent and keeping you signed in
- Providing the service: AI planning and generation, saving and editing outputs, scheduling and publishing, performance lookups, share links and company workspaces
- Confirming payments and managing plan periods and usage allowances
- Handling inquiries and reports, and sending service notices
- Operating safely: preventing abuse, safety checks on AI inputs and outputs, error analysis and security
- Anonymous aggregate metrics, such as success rate, processing time, error rate and regeneration rate, that cannot identify individuals
- [With optional consent] Service quality improvement: using your requests and outputs to improve HAEDU’s generation quality. For company workspaces, only when the workspace owner turns it on for the workspace.
- [With optional consent] Marketing messages about new features and events
3. Retention
We delete personal information without delay when you leave the service or when its purpose has been fulfilled, except as follows.
- Work and files you delete are removed from the service immediately. If a duplicated post still uses the same file, the file is removed when the last copy is deleted.
- Company workspace data stays with the company while the workspace exists, even after a member leaves.
- Share links stop working as soon as they expire or you turn them off.
- When you disconnect a social account, we revoke its access tokens immediately and delete the information obtained from that account within 7 days. Posts already published remain on the platform.
- Information in database backups is removed when the backup retention period (up to 7 days) ends, and deletions are re-applied if a backup is restored. Infrastructure providers’ operational logs are deleted automatically after up to 7 days.
| Information kept under law | Period | Legal basis |
|---|---|---|
| Records of contracts and withdrawal of offers | 5 years | Act on the Consumer Protection in Electronic Commerce |
| Records of payment and supply of goods | 5 years | Act on the Consumer Protection in Electronic Commerce |
| Records of consumer complaints and dispute resolution | 3 years | Act on the Consumer Protection in Electronic Commerce |
| Records of labeling and advertising | 6 months | Act on the Consumer Protection in Electronic Commerce |
| Sign-in records (access logs) | 3 months | Protection of Communications Secrets Act |
4. Deletion procedure
We delete personal information without delay once its retention period ends or its purpose is fulfilled. Electronic files are deleted in a way that cannot be recovered. Information kept under law is stored separately and deleted when the period ends.
5. Disclosure to third parties
We do not provide your personal information to third parties, except with your consent or where the law specifically requires it or it is unavoidable to comply with a legal obligation.
- When you confirm a post, we send that content to the platform through the social account you connected, at your request.
- Anyone who receives a share link you created can view that post without signing in.
6. Processors
We entrust the following tasks to provide the service. We will update this policy if processors or tasks change.
| Processor | Task |
|---|---|
| Supabase Inc. | Member authentication, database storage and operation |
| Vercel Inc. | Web hosting and server execution |
| Cloudflare, Inc. | Storage of files such as images and videos (when available) |
| OpenAI, L.L.C. | AI text generation; image generation and transcription (when available) |
| Higgsfield | AI video generation (when available) |
| Resend | Invitation and posting reminder emails (when available) |
7. International transfers
To provide the service, we transfer personal information to, or have it processed by, overseas providers as follows. Information is sent over encrypted connections each time you use the service.
| Recipient (contact) | Country and location | Items | Purpose | Retention |
|---|---|---|---|---|
| Supabase Inc. supabase.com/privacy | US company; data stored in Seoul, Korea | All items in section 1 | Authentication and data storage | Until you leave or the processing contract ends |
| Vercel Inc. vercel.com/legal/privacy-policy | US company; servers run in Seoul, Korea; traffic may pass through its global network | Information exchanged while using the service, access records | Hosting and server execution | Until the request is handled (operational logs up to 7 days) |
| Cloudflare, Inc. cloudflare.com/privacypolicy | US company; files stored in the Asia-Pacific region | Uploaded and generated files (when available) | File storage | Until you delete them or leave |
| OpenAI, L.L.C. openai.com/policies/privacy-policy | United States | Generation requests, content profile settings, outputs (images and audio when available) | AI generation | Kept up to 30 days for abuse monitoring, then deleted |
| Higgsfield | United States | Video generation requests and reference images | AI video generation (when available) | To be confirmed before launch of the feature |
| Resend | United States | Recipient email address, email content | Email delivery (when available) | To be confirmed before launch of the feature |
If you do not want these transfers, you may choose not to sign up or you may leave the service. These transfers are necessary to provide the service, so the service cannot be used without them. Transfers tied to specific features, such as video generation or email reminders, happen only when you use those features.
8. AI processing and data use
- To create outputs, we send your requests, content profile settings and the references you selected to our AI processors.
- OpenAI states that it does not use information received through its API to train its models.
- We use requests and outputs to improve HAEDU only for members who gave optional consent. You can withdraw consent anytime in studio settings, and information created after withdrawal is not used.
- Inputs and outputs go through safety checks, and the reason is recorded when something is blocked.
- Our operators may view generation records only as needed for error handling, safety checks and support.
- The reference library shows analyses of how public social media posts were made. The analyses use only public titles, descriptions and videos, do not include personal information such as people’s names or contact details, and the original videos are deleted after analysis.
9. Connected social media accounts (when available)
- A social account is connected only when you grant permission yourself on the platform’s official sign-in screen. We never ask for or store your social media passwords, and we store access tokens encrypted.
- We use a connected account only to publish posts you confirmed and to fetch, when you request it, the performance of posts published through HAEDU and your follower count. We do not use this data for any other purpose, for advertising, or sell it.
- You can disconnect in HAEDU or remove HAEDU in each platform’s settings. When you do, we revoke the access tokens immediately and delete information obtained from that account within 7 days. See Data Deletion for details.
Instagram and Threads (Meta)
We use Meta’s Instagram API and Threads API. Information processed by Meta is governed by the Meta Privacy Policy. If you remove HAEDU under website permissions (apps and websites) in Instagram or Threads settings, Meta sends us a deletion request and we delete the related information.
TikTok
We use the TikTok API. Information processed by TikTok is governed by the TikTok Privacy Policy.
YouTube
HAEDU uses YouTube API Services. By using HAEDU’s YouTube features, you agree to be bound by the YouTube Terms of Service. Information processed through YouTube API Services is subject to the Google Privacy Policy. You can revoke HAEDU’s access anytime on the Google security settings page for third-party access. We re-check YouTube data we store every 30 days and refresh or delete it.
10. Cookies
- Essential cookies keep you signed in. If you block cookies in your browser, features that require sign-in will not work.
- Embedded content: reference detail pages load the original posts from YouTube (youtube-nocookie.com), Instagram and TikTok. Those services may use cookies or receive access information under their own policies.
- We do not use advertising or behavioral tracking cookies or tools.
- You can refuse or delete cookies in your browser settings.
11. Your rights
- You may request access to, correction, deletion or suspension of processing of your personal information, and withdraw consent.
- You can change optional consents directly in studio settings.
- You can delete your account yourself on the Account page in the studio, and it takes effect immediately.
- For other requests, email the privacy officer below. We will verify your identity, act within 10 days and tell you the result.
- You may also make requests through a legal representative or an authorized agent with a power of attorney.
- Information we must keep under law cannot be deleted during the required period.
12. Children under 14
HAEDU is only for people aged 14 or older, and we do not knowingly collect personal information from children under 14. If we learn that we have, we delete it without delay.
13. Security measures
- Administrative: we keep the number of operators with access to personal information to a minimum and keep audit records of their key actions.
- Technical: all traffic is encrypted with HTTPS; row-level access control limits database access to authorized people; credentials such as social media access tokens are stored encrypted; secret keys are kept separate from code; and files are kept in private storage and served only through short-lived URLs.
- Physical: we use data centers of cloud providers with security certifications.
14. Privacy officer
| Role | Details |
|---|---|
| Privacy officer | 강성경 |
| Contact | assemblegroup.kr@gmail.com |
15. Remedies
If you need help with a privacy infringement, you can apply for dispute mediation or consultation with the following Korean agencies.
- Personal Information Dispute Mediation Committee: www.kopico.go.kr, +82-1833-6972
- Personal Information Infringement Report Center: privacy.kisa.or.kr, 118 (in Korea)
- Supreme Prosecutors’ Office: www.spo.go.kr, 1301 (in Korea)
- Korean National Police Agency: ecrm.police.go.kr, 182 (in Korea)
16. Changes to this policy
This policy applies from the public launch date. When we change it, we will announce the change on the service 7 days before it takes effect (30 days for changes unfavorable to you) and ask for your consent again when required.