Privacy Policy
This English text is provided for your convenience. The Korean version is the binding original, and it prevails if the two differ.
toodoori establishes and publishes this Privacy Policy under Article 30 of the Personal Information Protection Act of Korea (개인정보 보호법), to protect the personal information of data subjects and to handle related concerns promptly and smoothly.
The tasks and retrospectives you write, and the files you attach, are stored in the Republic of Korea (AWS Seoul region).
1. Purposes of Processing
toodoori processes personal information for the purposes below. Personal information being processed is not used for any purpose other than these, and where a purpose changes we will take the steps required under Article 18 of the Personal Information Protection Act, including obtaining separate consent.
| Purpose | Details |
|---|---|
| Sign-up and account management | Authenticating you when you sign in, maintaining and managing membership, preventing misuse of the service, and sending notices |
| Providing the service | Providing the task management service, and storing and displaying the content you write |
| Paid subscription | Subscription payment and renewal, subscription status management, and refund handling. Payment goes through Paddle as the seller |
| Handling inquiries | Receiving and handling inquiries, and informing you of the outcome |
| Improving the service | Analysing how the service is used, deciding what to improve first, compiling statistics, and analysing errors |
2. Processing and Retention Periods
toodoori processes and retains personal information within the retention and use period required by law, or within the period you consented to when the information was collected.
Account information
| Item | Purpose | Retention period |
|---|---|---|
| Identifying your account and signing in | Until you delete your account | |
| Name | Displaying you in the interface | Until you delete your account |
| Social login ID | Connecting social login | Until you delete your account |
| Nickname (optional) | Displaying you in the interface | Until you delete your account |
| Profile image (optional) | Displaying you in the interface | Until you delete your account |
| Language preference | Serving the interface in your language | Until you delete your account |
| Time zone (detected from your browser) | Date-based calculations (where a day begins and ends, Past Work, and Pattern) | Until you delete your account |
Content you write
This is what you write or upload in the service yourself. Under Article 8 of the Terms of Service, the copyright and ownership belong to you.
| Item | Purpose | Retention period |
|---|---|---|
| Tasks, projects, notes, checklists, briefs | Providing the service | Until you delete your account |
| Retrospective text and tags | Keeping your records | Until you delete your account |
| Attachments | Storing the files you upload | Until you delete your account |
| Task progress history (stage changes) | Showing your workflow and pattern | Until you delete your account |
| Inquiry content and attachments | Receiving and handling inquiries | See retention required by law below |
Automatically collected information
| Item | Purpose | Retention period |
|---|---|---|
| IP address | Preventing misuse of the service, managing access logs | Server access logs 14 days / 24 months where it is stored alongside a usage record |
| Browser type and version, operating system | Optimising the service, analysing errors | Error records 3 months / 24 months where it is stored alongside a usage record |
| Usage behaviour (screen views, feature use) | Service usage statistics and improvement | 24 months |
Usage records are stored together with an IP address and browser information. They are used only for improving the service and for statistics, and we do not single out an individual user in order to look at their activity.
Retention required by law
If you have used a paid subscription, we retain the records below as required by applicable law. A substantial part of the payment and tax records is held by Paddle as the seller.
| Record | Legal basis | Retention period |
|---|---|---|
| Records on contracts or withdrawal of subscription | Act on Consumer Protection in Electronic Commerce of Korea (전자상거래 등에서의 소비자보호에 관한 법률) | 5 years |
| Records on payment and the supply of goods | Act on Consumer Protection in Electronic Commerce of Korea (전자상거래 등에서의 소비자보호에 관한 법률) | 5 years |
| Records on consumer complaints or dispute resolution | Act on Consumer Protection in Electronic Commerce of Korea (전자상거래 등에서의 소비자보호에 관한 법률) | 3 years |
3. Provision to Third Parties
toodoori processes personal information only within the scope stated in 1. Purposes of Processing, and provides personal information to a third party only where Article 17 or 18 of the Personal Information Protection Act applies, such as with your consent or under a specific provision of law.
Paid subscription payment
The seller for paid subscriptions is Paddle.com Market Limited (United Kingdom). At checkout, your name, email, billing country, and payment method details are passed to Paddle, and Paddle processes them under its own privacy policy.
| Recipient | Items provided | Purpose | Retention period |
|---|---|---|---|
| Paddle.com Market Limited (United Kingdom) | Name, email, billing country, payment method details | Subscription payment, tax handling, invoicing, refund execution | The period set by Paddle's policy and applicable law |
Payment method details such as card numbers are not stored on toodoori's servers. You can read Paddle's privacy policy at https://www.paddle.com/legal/privacy.
We do not otherwise provide your personal information to third parties.
4. Outsourcing of Processing
toodoori outsources personal information processing as follows, so that the service runs smoothly.
| Processor | Outsourced work | Contact |
|---|---|---|
| Amazon Web Services, Inc. | Server operation, database and file storage (Seoul region, Republic of Korea) | https://aws.amazon.com/contact-us/ |
| Google LLC (Firebase Authentication) | User authentication and social login | https://support.google.com/policies?p=privpol_privts |
| Functional Software, Inc. (Sentry) | Collecting errors and logs to keep the service stable | compliance@sentry.io |
In each outsourcing contract we clearly set out compliance with personal information laws, confidentiality, the prohibition on providing information to third parties, liability in the event of an incident, the term, and the return or destruction of personal information once processing ends. We supervise each processor to ensure that it handles personal information safely.
5. Transfer of Personal Information Abroad
Your main data, including tasks, retrospectives, and attachments, is stored within the Republic of Korea (AWS Seoul region). The items below, however, are transferred abroad.
| Recipient | Contact | Country | Items | When and how | Purpose and retention |
|---|---|---|---|---|---|
| Google LLC (Firebase Authentication) | https://support.google.com/policies?p=privpol_privts | United States | Email, social login identifier | Transmitted over the network at sign-up and sign-in | User authentication / until you delete your account |
| Functional Software, Inc. (Sentry) | compliance@sentry.io | United States | User identifier, IP address, browser information, the screen path where an error occurred | Transmitted over the network when an error occurs | Error analysis / the period set by Sentry's retention policy |
| Paddle.com Market Limited | privacy@paddle.com | United Kingdom | Name, email, billing country, payment method details | Transmitted over the network at paid subscription checkout | Payment and refund handling / the period set by Paddle's policy and applicable law |
How to refuse, and what happens if you do
You can refuse the transfer of your personal information abroad by not signing up, or by deleting your account. Authentication is, however, essential to using the service, so if you refuse the transfer you cannot use the service. If you do not use a paid subscription, no payment-related information is transferred.
Service screens and files are delivered through a content delivery network (CDN), and in that process a request may pass through a point of presence abroad that is close to you. What passes through is the request itself, and we do not store it separately.
6. External Integrations and Programmatic Access
The features below work only if you choose to use them. If you do not use them, we collect no related information.
External integration (Jira)
When you connect a Jira account, we store an authentication token in encrypted form so that we can fetch Jira issue information on your behalf. What we fetch is the issue title, body, status, and the assignee's display name, and it is read only within the scope of your own Jira permissions.
What we fetch may include the personal information of people who are not toodoori users, such as an assignee display name. We store it only as part of the task you created, only for as long as that task exists, and we do not use it for anything else. You are responsible for having the right to bring that information into toodoori. toodoori does not send your data to Jira. You can disconnect the integration at any time in My Page, and the stored token is deleted when you do.
| Item | Purpose | Retention period |
|---|---|---|
| External service authentication token (stored encrypted) | Reading external service data on your behalf | Until you disconnect the integration or delete your account |
Link previews
When you paste a link into your notes, our server fetches that page title and icon to show a preview. The link is sent to that site. Nothing of yours is sent with it.
Personal access tokens (access by external programs)
Through a personal access token you issue yourself, an external program (a command line tool, an AI connector, and the like) can access your data on your behalf. You decide which program receives the token, and toodoori has no involvement in how that program handles your data.
You can revoke a token at any time in My Page, and every token you have issued is revoked automatically when you delete your account.
| Item | Purpose | Retention period |
|---|---|---|
| Token last used time and last used IP | Checking for token misuse | Until the token is revoked or you delete your account |
7. Your Rights and How to Exercise Them
As a data subject you may exercise your rights against toodoori at any time, including the right to access, correct, delete, or suspend the processing of your personal information.
How to exercise your rights
- Access: check it in the profile settings inside the service
- Correction: edit it yourself in the profile settings inside the service
- Deletion (account deletion): delete your account yourself in the account settings inside the service
- Suspension of processing: email the Privacy Officer
- Data export: download it yourself at any time using the export feature inside the service
What happens when you delete your account
When you request account deletion, your personal information is handled as follows.
- Immediately
- Personal information such as email and name is replaced with a value that cannot identify you
- Social login connection information is deleted
- Authentication tokens and every personal access token you issued are revoked
- External integrations are disconnected and stored integration tokens are deleted
- Your Firebase account is deleted
- In sequence (within 5 days of deletion)
- Attachments and profile images are deleted
- Content you wrote, including projects, tasks, and retrospectives, is deleted
- The final account record is deleted
We do keep a deletion record (the time of deletion, the outcome, and an account identifier processed so that it cannot identify you) to prevent abusive re-registration and to verify that deletion was carried out. Records subject to retention under law, as listed in 2. above, are stored separately for the required period and then destroyed.
Usage statistics already compiled may remain in a form that cannot identify an individual, and the records of a user who has deleted their account are excluded from analysis.
8. Destruction of Personal Information
toodoori destroys personal information without delay once it is no longer needed, such as when the retention period has passed or the purpose of processing has been achieved.
Deletion and destruction are different
When you delete a task or a retrospective, it disappears from the screen immediately and is no longer readable. To allow you to undo it, we keep it in a recoverable state for 30 days and then destroy it completely. On account deletion it is deleted regardless of that period.
A deleted task may appear on the Pattern screen as "let go". What appears there is only the date and a count. The title and content of the task are not shown.
Method of destruction
Personal information stored as an electronic file is completely deleted using a technical method that makes the record unrecoverable.
Timing of destruction
Once the retention period expires or the purpose of processing has been achieved, we destroy the personal information without delay (within 5 days).
9. Measures to Secure Personal Information
toodoori takes the following measures to keep personal information secure.
| Measure | Details |
|---|---|
| Administrative | Only the Operator, one person, processes personal information, and access rights are kept to a minimum |
| Technical | Encryption of stored data, encryption in transit, access rights management, retention of access logs, a web application firewall, and rate limiting |
| Physical | Personal information is stored in the data centres of a cloud provider (AWS), and physical security follows that provider's measures |
Technical measures in detail
- We do not collect passwords of our own. Only social login through a Google account is supported
- Databases and storage volumes are stored encrypted
- Traffic in transit is encrypted with TLS
- External integration tokens are stored encrypted, and personal access tokens are never stored in plain text
- Token-based authentication with expiry management, and retention of access logs
- A web application firewall (WAF) and rate limiting block abnormal access
10. Automatic Collection Tools and How to Refuse Them
toodoori uses the Local Storage in your browser to keep you signed in and to remember your screen settings.
What is stored
| Item | Contents | Purpose | Validity |
|---|---|---|---|
| Authentication tokens | Access token, refresh token, and each expiry time | Keeping your session and authenticating API calls | Access token 15 minutes, refresh token 7 days |
| Signed-in user information | Email, name, profile image URL | Showing that you are signed in | Until you sign out |
| Session identifier | A randomly generated value | Service usage statistics | Until you close the browser tab |
| Screen settings | Language, expanded state, sidebar width, and the like | Convenience while using the service | Until you delete them |
How to refuse
You can clear Local Storage in your browser settings, or sign out of the service to discard what is stored. Doing so may, however, make it difficult to use parts of the service that require signing in.
Cookies
toodoori does not use cookies. We do use the Local Storage in your browser, which the law of some countries treats the same way. Of the items above, the authentication tokens and the screen settings are needed to provide the service you asked for. The session identifier, which we use for usage statistics, is not, so we do not store it for visitors in the European Economic Area or the United Kingdom. If we start using cookies, we will tell you through this Policy.
11. Personal Information of Children Under 14
toodoori is for individual users aged 14 or older, and we do not accept sign-ups from children under 14. If we become aware that we have collected the personal information of a child under 14, we destroy that information without delay.
12. Privacy Officer
toodoori designates the following Privacy Officer, who has overall responsibility for personal information processing and deals with complaints from data subjects and with remedying any harm arising from that processing.
| Item | Details |
|---|---|
| Privacy Officer | Moonki Lee |
| peoplenexteam@gmail.com | |
| How to reach us | The inquiry feature inside the service, or the email above |
You may contact the Privacy Officer about any privacy question, complaint, or request for remedy arising from your use of the service.
13. Changes to This Privacy Policy
This Privacy Policy applies from its effective date. Where content is added, deleted, or corrected in line with law or with our policy, we will give notice inside the service from 7 days before the change takes effect.
For a change that is unfavourable to you, we give notice from 30 days in advance and also inform you by email.
14. Remedies for Infringement of Your Rights
To seek a remedy for infringement of your personal information, you may apply for dispute resolution or counselling to bodies such as the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency Privacy Infringement Report Centre. These are Korean bodies. If you are outside Korea you may also contact your local data protection authority.
| Body | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (from within Korea) | https://www.kopico.go.kr |
| Privacy Infringement Report Centre | 118 (from within Korea) | https://privacy.kisa.or.kr |
| Supreme Prosecutors Office, Cyber Investigation Division | 1301 (from within Korea) | https://www.spo.go.kr |
| National Police Agency, Cyber Bureau | 182 (from within Korea) | https://ecrm.police.go.kr |
15. If You Are Outside Korea
toodoori is operated from the Republic of Korea, and this Policy is built around the Personal Information Protection Act (개인정보 보호법).
Paid subscriptions are not sold to customers in the European Economic Area, the United Kingdom, or Switzerland. If you are there, you can still use the free plan, and the rest of this Policy applies to you.
Who is responsible
Moonki Lee, the operator of toodoori, decides how your personal information is handled. Contact: peoplenexteam@gmail.com. The Privacy Officer named in section 12 is your point of contact. That role is not a Data Protection Officer under Article 37 of the GDPR, and we are not required to appoint one.
Why we process your information
- To do what we agreed with you: your account, the content you create, and support. Signing up is how you ask us to do that.
- Because we have a legitimate interest in it: keeping the service secure, preventing abuse, diagnosing errors, and compiling aggregate usage statistics. You can object to this at any time.
- Because the law requires it: the records listed in section 2 under retention required by law.
- Because you agreed to it: anything we ask you to opt into. You can withdraw that at any time, which does not affect what we did before.
Your rights, and where to complain
Section 7 lists how to access, correct, delete, and export your information, and how to ask us to stop processing it. You can also object to the processing we do on the basis of our legitimate interest. We answer within 10 days, as the Personal Information Protection Act requires.
Please raise anything with us first. You may also complain to a data protection authority: the one in your own country, or the Personal Information Protection Commission in Korea (pipc.go.kr).
Where your information sits
Your tasks, retrospectives, and attachments stay in Korea. In 2021 the European Commission decided that Korea protects personal data adequately, and the United Kingdom made the same finding in 2022. The transfers listed in section 5 rely on the safeguards each recipient provides.
If you are in the United States
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising of any kind.
Effective date: 1 September 2026