Privacy Policy · Effective May 11, 2026

Last updated: September 10, 2026

1. Basic Information

• Company Name: Echad Labs Inc.• Service Name: Echad (Mobile App, Website)• Implementation Date: May 11, 2026• Previous Policy URL: https://www.echad.io/legal/privacy-20250501• Following SPEC-CONSENT-IMPLICIT-001 (approved 2026-05-10), agreement to this policy at sign-up satisfies PIPA and GDPR consent requirements.

2. Purpose and Items of Personal Information Processing

2.1. Personal Information Processed with Data Subject ConsentWe collect and use personal information for the following purposes:
Member registration and user identification - Member information (email/nickname)Marketing (event participation) - Participant name, email, mobile phone numberMarketing (discount information, newsletters, event notifications, product information) - Name, email, mobile phone number
2.2. Personal Information Processed without Data Subject Consent Based on Legal GroundsWe process personal information based on the following legal grounds:
KakaoTalk 1:1 inquiry and consultation - Inquiry and consultation contentService provision and usage record management - Service usage records (Bible reading records (book/chapter/verse))Service operation and management (refund) - Refund information (account number/bank name/account holder name)Service operation and management (product order, delivery, payment) - Orderer information (name/mobile phone number/email), delivery information (name/address/mobile phone number), payment information (card company name/card information/installment)Compliance with legal obligations - Service usage records, access records, payment records, and other items required by relevant laws
2.3. Information Automatically Collected During Service UseService usage records (visit time, IP address, browser type, OS, service usage patterns, etc.), access records, etc.Collection purpose: Service analysis and improvement, prevention of fraudulent use, provision of customized services, etc.

3. Religious Belief Data (PIPA § 23 · GDPR Art. 9)

Given the nature of Echad as a Bible meditation service, the following items are classified as sensitive data (religious belief / GDPR special category) under PIPA § 23 and GDPR Art. 9, and are protected accordingly.3.1. Sensitive Data We ProcessThe following items are entered or selected directly by you; agreement to this privacy policy at sign-up establishes the legal basis for processing:
Interest selection (🌱 beginner / 📖 depth / 📜 Torah / ✡ messianic) — chosen at Onboarding Stage 5Bible translation preference (NKRV / RNKSV / KJV / KRV) — chosen at Onboarding Stage 4Parasha progress and seven-portion reading records — initiated by youMeditation notes and highlights — entered by you (E2E encryption is on a separate β/GA+ track)Community shared reflections — only when you explicitly publishNotification category selection (Shabbat · Parasha · Feasts) — religious cadence alerts
3.2. Legal BasisPIPA § 23(1)(1) — Separate consent obtained from the data subject. Agreement to this policy at sign-up satisfies this requirement for the items listed above.GDPR Art. 9(2)(a) — Explicit consent. Your active input of interests/notes/shared reflections, combined with the explicit description in this policy, constitutes explicit consent equivalent.GDPR Art. 9(2)(d) — Not-for-profit body, religious purposes — relevant as supporting legal basis given Echad serves a faith community.3.3. Data Subject RightsYou can exercise the following rights at any time from My Page > Settings:• Change your interest selection, or reset it to "Unspecified"• Delete individual notes / highlights / shared reflections• On account deletion, all religious belief data is permanently destroyed within 30 days (cascade hard delete)• Withdrawal of consent stops all religious belief data processing immediately

4. Personal Information Processing and Retention Period

3.1. Personal Information Retention PeriodWe retain personal information for the following periods:
Member registration information (email/nickname, etc.): Until membership withdrawal or consent withdrawalOptionally collected member information (name/mobile phone number/gender/birthday): Until membership withdrawal or consent withdrawalChannel Talk 1:1 inquiry content: Until membership withdrawal or consent withdrawalOptionally collected Channel Talk inquiry information (nickname, last digits of mobile phone): Until membership withdrawal or consent withdrawalMandatorily collected service usage records: Until membership withdrawal or consent withdrawalOptionally collected service usage records (Bible reading records, photos): Until membership withdrawal or consent withdrawalMarketing information collection (event participation): Until the end of the eventMarketing information collection (discount notifications, etc.): Until membership withdrawal or consent withdrawal
3.2. Information Retained According to LawsWe retain personal information based on the following legal grounds:
Act on Consumer Protection in Electronic Commerce: Records related to contracts or subscription withdrawal (5 years), records related to payment and supply of goods (5 years), records related to consumer complaints or dispute resolution (3 years)Protection of Communications Secrets Act: Computer communication or internet connection records, communication confirmation data (3 months)Framework Act on National Taxes, Corporate Tax Act, Value-Added Tax Act, etc.: Books and evidence documents related to transactions (5 years)

5. Disposal of Personal Information

4.1. Disposal ProcedurePersonal information that has exceeded its retention period or achieved its purpose will be promptly disposed of. In cases where personal information must be preserved in accordance with relevant laws, it will be transferred to a separate DB and then disposed of after the legally prescribed retention period has elapsed.4.2. Disposal MethodElectronic file format information: Using technical methods (Low Level Format, etc.) that cannot reproduce the records, or permanently destroying the physical storage media containing the data.Paper document format information: Shredding using a shredder or incineration.

6. Provision of Personal Information to Third Parties

The company processes personal information only within the scope specified in Section 1 regarding the collection and use of personal information, and provides personal information to third parties only when separate prior consent from users is obtained or when required by relevant laws.6.1. Recipients of Personal Information (OAuth Identity Providers)We exchange the following information with OAuth identity providers for sign-in identification (PIPA § 17 separate consent — satisfied by agreement to this policy at sign-up):
Apple (Sign in with Apple): Login identifier (sub), email (private relay or actual), display nameGoogle (OAuth 2.0): Login identifier (sub), email, profile photo, display nameKakao (OAuth 2.0 · Better Auth Generic Plugin · post-α): Login identifier (sub), email, nickname, profile photo
6.2. Provision Based on Legal RequirementsProvision to third parties without prior consent based on relevant laws may occur in the following cases:
When provided in a form that cannot identify specific individuals for the purpose of compiling statistics, academic research, or market researchWhen requested by national institutions in accordance with relevant lawsWhen there is a purpose for investigation of crimes or when requested by the Korea Communications Standards CommissionWhen there is a request according to procedures set forth in other relevant laws

7. Entrustment of Personal Information Processing

7.1. Current Status of Personal Information Processing EntrustmentFor smooth operations we entrust personal information processing as follows. All processors operate under Standard Contractual Clauses (SCC) or equivalent protections meeting PIPA § 28-8 and GDPR Art. 28:
Vultr Holdings Corporation: Compute and Managed PostgreSQL hosting (Seoul region · US-headquartered)Cloudflare, Inc.: R2 Object Storage (audio Bible · backups), DNS, TLS termination, global CDN POP accelerationRevenueCat, Inc.: Subscription entitlement management and billing webhooks (United States)PostHog, Inc.: Anonymous usage analytics (limited to interest/region/age cohort · United States / EU)Postmark (ActiveCampaign LLC): Transactional email (verification, donation receipts · United States)
7.2. Compliance Matters for Entrustment ContractsWhen concluding entrustment contracts, in accordance with Article 26 of the Personal Information Protection Act, we specify in documents such as contracts matters concerning the prohibition of personal information processing beyond the purpose of performing the entrusted tasks, technical and managerial protection measures, restrictions on re-entrustment, management and supervision of trustees, liability for damages, etc. We regularly manage and supervise whether trustees safely process personal information. If the content of the entrusted tasks or trustees are added or changed, we will promptly disclose this through prior consent notice in accordance with relevant laws or through this privacy policy.

8. International Transfer of Personal Information (PIPA § 28-8)

Pursuant to PIPA § 28-8 (effective 2023 amendment), Echad discloses the fact of international transfer, the receiving country, the time and method of transfer, the recipient, the contact for the recipient's data protection officer, the recipient's purpose of use, and the retention period — all set out in this policy. Agreement to this policy at sign-up satisfies the consent requirement (PIPA § 28-8(1)(1)).8.1. Details of the Six Cross-Border ServicesThe following six services receive your personal information abroad:
Cloudflare R2 · United States (Global) · audio Bible streaming + migration backups · items: audio usage logs · backup archives · retention: until contract termination · DPO: [email protected]Vultr · United States (Seoul region · US-headquartered) · Compute + Managed PostgreSQL hosting · items: all service data (account · notes · progress) · retention: 30 days after account deletion · DPO: [email protected]RevenueCat · United States · subscription entitlement + billing webhooks · items: subscription ID · transaction ID · entitlement · retention: 30 days after account deletion · DPO: [email protected]PostHog · United States / EU (selectable) · anonymous analytics · items: non-identifiable cohort (interest · region · 5-bucket age) · retention: 1 year · DPO: [email protected]Postmark · United States · transactional email · items: email address · message body · retention: 30 days · DPO: [email protected]Cloudflare · United States (Global POP) · DNS, TLS termination, CDN · items: IP address, request metadata · retention: 30 days · DPO: [email protected]
8.2. Method and Timing of TransferTransfer method: HTTPS / TLS 1.3+ encrypted channels via API call or standard RDBMS replication. Timing: occurs in real time at service use (e.g., Postmark verification email at sign-up · RevenueCat webhook at payment · PostHog event at analytics emission).Echad hosts on Vultr's Seoul region, so Korean users' data physically resides on Korean soil. However, since the operator (Vultr Holdings) is a US entity, this constitutes international transfer under PIPA § 28-8.8.3. Right to Refuse Consent and ConsequencesYou have the right to refuse this cross-border transfer; however, doing so may limit your use of Echad (PIPA § 28-8(4) — transfer without consent is permitted where the transfer is essential to service provision). This policy adopts a unified consent approach for convenience; partial refusal of any of the six services will be addressed during sign-up.

9. Rights and Obligations of Data Subjects and Legal Representatives

8.1. Rights of Data SubjectsData subjects (or legal representatives) have the following rights regarding the processing of their personal information:
Right to request access to personal informationRight to request correction or deletion of personal informationRight to request suspension of personal information processingRight to withdraw consent and request deletionRight to data portability (GDPR Art. 20)
8.2. Method and Procedure for Exercising RightsData subjects can exercise the above rights at any time through the following methods:• Access/Modification: My Page > Edit My Profile• Download your data: export your own data as JSON directly from the Data Portability page (/data-export)• Account Deletion: My Page > Settings > Withdraw• Others: Request suspension of processing and deletion of personal information through written documents, email, etc.The company will not use or provide the personal information until the correction or deletion is completed when a request for correction or deletion of errors in personal information is made.8.3. Exercise of Rights by Legal RepresentativesWhen a legal representative or delegate exercises the user's rights (access, correction, suspension of processing, deletion), they must submit a power of attorney according to Form No. 11 of the Enforcement Rules of the Personal Information Protection Act.The company verifies whether the person requesting access, correction/deletion, or suspension of processing is the data subject or a legitimate representative when such requests are made.8.4. Limitations on the Exercise of Data Subject RightsRequests for correction and deletion of personal information cannot be made for personal information that is specified as a collection target in other laws.

10. Automatic Collection of Personal Information and Behavioral Information Processing

9.1. Installation, Operation, and Rejection of Automatic Collection Devices Such as CookiesThe following information may be automatically generated/collected from users during the service use process and may be used for the following purposes:• Purpose of using automatically collected personal information: Compliance with relevant regulations• Compliance with relevant regulations: The company has an obligation to maintain users' access records (login records) for compliance with relevant regulations.• Installation, operation, and rejection methods of cookies: - For Android phones: Phone settings > App management > Echad > Storage > User data / Cache > Clear data - For iPhones: Settings > App management > Echad > Storage > Clear data

11. Personal Information Protection Officer and Department

11.1. Personal Information Protection OfficerEchad Labs Inc. has designated a personal information protection officer as follows to be responsible for overseeing personal information processing tasks and handling complaints and remedies for data subjects related to personal information processing.Users can contact the personal information protection officer regarding all personal information protection related inquiries, complaints, and remedies that occur while using the service. The company will respond to and handle user inquiries without delay.• Name: Customer Support Department Head• Position: Personal Information Protection Officer• Contact: [email protected]11.2. Personal Information Complaint Handling DepartmentInquiries, complaints, and remedies related to personal information processing can be directed to the following department:• Department Name: Customer Support Department• Contact: [email protected]

12. Remedies for Infringement of Data Subject Rights

Data subjects can apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, Korea Internet & Security Agency's Personal Information Infringement Report Center, etc. to receive remedies for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following institutions:• Personal Information Infringement Report Center (operated by Korea Internet & Security Agency): (without area code) 118 (privacy.kisa.or.kr) - Address: Personal Information Infringement Report Center, 3rd Floor, 9 Jinheung-gil, Naju-si, Jeollanam-do (Bitgaram-dong 301-2) (58324)• Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)

13. Other Voluntary Protection Efforts

We comply with relevant regulations such as the Personal Information Protection Act and make various protection efforts to protect users' personal information. We will continue to do our utmost to protect users' personal information through continuous management and improvement.

14. Changes to the Privacy Policy

This privacy policy is effective from May 1, 2025. This policy may be changed in accordance with changes in relevant laws and policies such as the Personal Information Protection Act, or improvements to our services. If the privacy policy is changed, we will notify users through service notices or separate notifications starting 7 days before the change takes effect.