Privacy Policy · Effective May 11, 2026
Last updated: September 10, 20261. Basic Information
• Company Name: Echad Labs Inc.• Service Name: Echad (Mobile App, Website)• Implementation Date: May 11, 2026• Previous Policy URL: https://www.echad.io/legal/privacy-20250501• Following SPEC-CONSENT-IMPLICIT-001 (approved 2026-05-10), agreement to this policy at sign-up satisfies PIPA and GDPR consent requirements.2. Purpose and Items of Personal Information Processing
2.1. Personal Information Processed with Data Subject ConsentWe collect and use personal information for the following purposes:• Member registration and user identification - Member information (email/nickname)• Marketing (event participation) - Participant name, email, mobile phone number• Marketing (discount information, newsletters, event notifications, product information) - Name, email, mobile phone number
2.2. Personal Information Processed without Data Subject Consent Based on Legal GroundsWe process personal information based on the following legal grounds:• KakaoTalk 1:1 inquiry and consultation - Inquiry and consultation content• Service provision and usage record management - Service usage records (Bible reading records (book/chapter/verse))• Service operation and management (refund) - Refund information (account number/bank name/account holder name)• Service operation and management (product order, delivery, payment) - Orderer information (name/mobile phone number/email), delivery information (name/address/mobile phone number), payment information (card company name/card information/installment)• Compliance with legal obligations - Service usage records, access records, payment records, and other items required by relevant laws
2.3. Information Automatically Collected During Service UseService usage records (visit time, IP address, browser type, OS, service usage patterns, etc.), access records, etc.Collection purpose: Service analysis and improvement, prevention of fraudulent use, provision of customized services, etc.3. Religious Belief Data (PIPA § 23 · GDPR Art. 9)
Given the nature of Echad as a Bible meditation service, the following items are classified as sensitive data (religious belief / GDPR special category) under PIPA § 23 and GDPR Art. 9, and are protected accordingly.3.1. Sensitive Data We ProcessThe following items are entered or selected directly by you; agreement to this privacy policy at sign-up establishes the legal basis for processing:• Interest selection (🌱 beginner / 📖 depth / 📜 Torah / ✡ messianic) — chosen at Onboarding Stage 5• Bible translation preference (NKRV / RNKSV / KJV / KRV) — chosen at Onboarding Stage 4• Parasha progress and seven-portion reading records — initiated by you• Meditation notes and highlights — entered by you (E2E encryption is on a separate β/GA+ track)• Community shared reflections — only when you explicitly publish• Notification category selection (Shabbat · Parasha · Feasts) — religious cadence alerts
3.2. Legal BasisPIPA § 23(1)(1) — Separate consent obtained from the data subject. Agreement to this policy at sign-up satisfies this requirement for the items listed above.GDPR Art. 9(2)(a) — Explicit consent. Your active input of interests/notes/shared reflections, combined with the explicit description in this policy, constitutes explicit consent equivalent.GDPR Art. 9(2)(d) — Not-for-profit body, religious purposes — relevant as supporting legal basis given Echad serves a faith community.3.3. Data Subject RightsYou can exercise the following rights at any time from My Page > Settings:• Change your interest selection, or reset it to "Unspecified"• Delete individual notes / highlights / shared reflections• On account deletion, all religious belief data is permanently destroyed within 30 days (cascade hard delete)• Withdrawal of consent stops all religious belief data processing immediately4. Personal Information Processing and Retention Period
3.1. Personal Information Retention PeriodWe retain personal information for the following periods:• Member registration information (email/nickname, etc.): Until membership withdrawal or consent withdrawal• Optionally collected member information (name/mobile phone number/gender/birthday): Until membership withdrawal or consent withdrawal• Channel Talk 1:1 inquiry content: Until membership withdrawal or consent withdrawal• Optionally collected Channel Talk inquiry information (nickname, last digits of mobile phone): Until membership withdrawal or consent withdrawal• Mandatorily collected service usage records: Until membership withdrawal or consent withdrawal• Optionally collected service usage records (Bible reading records, photos): Until membership withdrawal or consent withdrawal• Marketing information collection (event participation): Until the end of the event• Marketing information collection (discount notifications, etc.): Until membership withdrawal or consent withdrawal
3.2. Information Retained According to LawsWe retain personal information based on the following legal grounds:• Act on Consumer Protection in Electronic Commerce: Records related to contracts or subscription withdrawal (5 years), records related to payment and supply of goods (5 years), records related to consumer complaints or dispute resolution (3 years)• Protection of Communications Secrets Act: Computer communication or internet connection records, communication confirmation data (3 months)• Framework Act on National Taxes, Corporate Tax Act, Value-Added Tax Act, etc.: Books and evidence documents related to transactions (5 years)
5. Disposal of Personal Information
4.1. Disposal ProcedurePersonal information that has exceeded its retention period or achieved its purpose will be promptly disposed of. In cases where personal information must be preserved in accordance with relevant laws, it will be transferred to a separate DB and then disposed of after the legally prescribed retention period has elapsed.4.2. Disposal MethodElectronic file format information: Using technical methods (Low Level Format, etc.) that cannot reproduce the records, or permanently destroying the physical storage media containing the data.Paper document format information: Shredding using a shredder or incineration.6. Provision of Personal Information to Third Parties
The company processes personal information only within the scope specified in Section 1 regarding the collection and use of personal information, and provides personal information to third parties only when separate prior consent from users is obtained or when required by relevant laws.6.1. Recipients of Personal Information (OAuth Identity Providers)We exchange the following information with OAuth identity providers for sign-in identification (PIPA § 17 separate consent — satisfied by agreement to this policy at sign-up):• Apple (Sign in with Apple): Login identifier (sub), email (private relay or actual), display name• Google (OAuth 2.0): Login identifier (sub), email, profile photo, display name• Kakao (OAuth 2.0 · Better Auth Generic Plugin · post-α): Login identifier (sub), email, nickname, profile photo
6.2. Provision Based on Legal RequirementsProvision to third parties without prior consent based on relevant laws may occur in the following cases:• When provided in a form that cannot identify specific individuals for the purpose of compiling statistics, academic research, or market research• When requested by national institutions in accordance with relevant laws• When there is a purpose for investigation of crimes or when requested by the Korea Communications Standards Commission• When there is a request according to procedures set forth in other relevant laws
7. Entrustment of Personal Information Processing
7.1. Current Status of Personal Information Processing EntrustmentFor smooth operations we entrust personal information processing as follows. All processors operate under Standard Contractual Clauses (SCC) or equivalent protections meeting PIPA § 28-8 and GDPR Art. 28:• Vultr Holdings Corporation: Compute and Managed PostgreSQL hosting (Seoul region · US-headquartered)• Cloudflare, Inc.: R2 Object Storage (audio Bible · backups), DNS, TLS termination, global CDN POP acceleration• RevenueCat, Inc.: Subscription entitlement management and billing webhooks (United States)• PostHog, Inc.: Anonymous usage analytics (limited to interest/region/age cohort · United States / EU)• Postmark (ActiveCampaign LLC): Transactional email (verification, donation receipts · United States)
7.2. Compliance Matters for Entrustment ContractsWhen concluding entrustment contracts, in accordance with Article 26 of the Personal Information Protection Act, we specify in documents such as contracts matters concerning the prohibition of personal information processing beyond the purpose of performing the entrusted tasks, technical and managerial protection measures, restrictions on re-entrustment, management and supervision of trustees, liability for damages, etc. We regularly manage and supervise whether trustees safely process personal information. If the content of the entrusted tasks or trustees are added or changed, we will promptly disclose this through prior consent notice in accordance with relevant laws or through this privacy policy.8. International Transfer of Personal Information (PIPA § 28-8)
Pursuant to PIPA § 28-8 (effective 2023 amendment), Echad discloses the fact of international transfer, the receiving country, the time and method of transfer, the recipient, the contact for the recipient's data protection officer, the recipient's purpose of use, and the retention period — all set out in this policy. Agreement to this policy at sign-up satisfies the consent requirement (PIPA § 28-8(1)(1)).8.1. Details of the Six Cross-Border ServicesThe following six services receive your personal information abroad:• Cloudflare R2 · United States (Global) · audio Bible streaming + migration backups · items: audio usage logs · backup archives · retention: until contract termination · DPO: [email protected]• Vultr · United States (Seoul region · US-headquartered) · Compute + Managed PostgreSQL hosting · items: all service data (account · notes · progress) · retention: 30 days after account deletion · DPO: [email protected]• RevenueCat · United States · subscription entitlement + billing webhooks · items: subscription ID · transaction ID · entitlement · retention: 30 days after account deletion · DPO: [email protected]• PostHog · United States / EU (selectable) · anonymous analytics · items: non-identifiable cohort (interest · region · 5-bucket age) · retention: 1 year · DPO: [email protected]• Postmark · United States · transactional email · items: email address · message body · retention: 30 days · DPO: [email protected]• Cloudflare · United States (Global POP) · DNS, TLS termination, CDN · items: IP address, request metadata · retention: 30 days · DPO: [email protected]
8.2. Method and Timing of TransferTransfer method: HTTPS / TLS 1.3+ encrypted channels via API call or standard RDBMS replication. Timing: occurs in real time at service use (e.g., Postmark verification email at sign-up · RevenueCat webhook at payment · PostHog event at analytics emission).Echad hosts on Vultr's Seoul region, so Korean users' data physically resides on Korean soil. However, since the operator (Vultr Holdings) is a US entity, this constitutes international transfer under PIPA § 28-8.8.3. Right to Refuse Consent and ConsequencesYou have the right to refuse this cross-border transfer; however, doing so may limit your use of Echad (PIPA § 28-8(4) — transfer without consent is permitted where the transfer is essential to service provision). This policy adopts a unified consent approach for convenience; partial refusal of any of the six services will be addressed during sign-up.9. Rights and Obligations of Data Subjects and Legal Representatives
8.1. Rights of Data SubjectsData subjects (or legal representatives) have the following rights regarding the processing of their personal information:• Right to request access to personal information• Right to request correction or deletion of personal information• Right to request suspension of personal information processing• Right to withdraw consent and request deletion• Right to data portability (GDPR Art. 20)
8.2. Method and Procedure for Exercising RightsData subjects can exercise the above rights at any time through the following methods:• Access/Modification: My Page > Edit My Profile• Download your data: export your own data as JSON directly from the Data Portability page (/data-export)• Account Deletion: My Page > Settings > Withdraw• Others: Request suspension of processing and deletion of personal information through written documents, email, etc.The company will not use or provide the personal information until the correction or deletion is completed when a request for correction or deletion of errors in personal information is made.8.3. Exercise of Rights by Legal RepresentativesWhen a legal representative or delegate exercises the user's rights (access, correction, suspension of processing, deletion), they must submit a power of attorney according to Form No. 11 of the Enforcement Rules of the Personal Information Protection Act.The company verifies whether the person requesting access, correction/deletion, or suspension of processing is the data subject or a legitimate representative when such requests are made.8.4. Limitations on the Exercise of Data Subject RightsRequests for correction and deletion of personal information cannot be made for personal information that is specified as a collection target in other laws.