Privacy Policy
Last updated: 2026-08-22
Effective date: 2026-08-22
1. Information We Receive and Information We Do Not Store
The Service processes submitted images and, when provided, reference images and briefs for an inspection. Hashes calculated from images and inspection results may be used and retained.
No path was identified that persistently writes original image bytes to the Service’s data stores. This does not mean that there is no in-memory processing, processing by a hosting provider, or transmission to an inspection or OCR provider.
Purposes and Items Processed
We process email addresses, passwords, authentication and session tokens, and account identifiers for sign-up, sign-in, email verification, password recovery, and session maintenance.
We process submitted images and their file names, MIME types, and sizes, as well as reference images, briefs, locales, image and brief hashes, and assessment results when applicable, to provide image assessments and results.
We process account identifiers, hashes derived from IP addresses, image and brief hashes, and usage and cost-related records to operate caches and result records, manage free usage and feedback benefits, and enforce request rate limits and the global budget.
We process sign-in identities, account-linking information, and the status of deletion requests to receive, handle, and notify users about account-deletion requests.
Items Processed and Application-level Safeguards
The Service processes submitted images, reference images, file names, MIME types, sizes, briefs, locales, image, brief, and request-related hashes, assessment results, usage and cost-related records, hashes derived from IP addresses, email addresses, passwords, authentication and session tokens, Auth UUIDs and internal account IDs, beta-access demand buckets, and feedback receipts.
We apply the following measures to ensure safety. Authentication cookies are set so that browser scripts cannot read them, and are transmitted only through encrypted connections in production. For usage management and abuse prevention, we use IP addresses only after converting them into an irreversible form. We separate permissions so that the deletion procedure can access only authorised work, and its execution record does not retain email addresses, credentials, or request content.
These measures are applied to the Service application. The security measures of external processors, backup access controls, and incident-response procedures have not yet been confirmed (Section 8).
2. Retention Periods and Cleanup Method
The information retained by the Service and its retention periods are as follows.
| Information | Retention period |
|---|---|
| Assessment results and image hashes | Up to 90 days |
| Usage and rate-limit counters | Up to 48 hours |
| Records of usage allowances granted once during the life of an account | While the account is maintained |
| Account information and usage records | See the explanation below |
Information whose retention period has ended is deleted through periodic cleanup work. Because this work has a limit on the amount it processes at one time, we do not promise that information will disappear immediately when the period ends.
Some account information and usage records do not have a set expiry period. The statutory-retention items, basis, and period that apply to them have not yet been established; we will update this policy when they are confirmed (Section 8). The absence of an expiry period does not mean that their retention has been determined to be lawful.
The actual retention and deletion periods of external processors and their backups and logs have not been confirmed (Sections 3 and 8).
Destruction Procedure and What May Remain
Assessment results and image hashes whose retention period has ended are deleted through the cleanup work described above. When you request account deletion, we clean up caches and records linked to that account and then delete the authentication account. Completion of this procedure does not mean that every item of information about the account has been deleted.
After this procedure, the following may remain: a disabled account identifier, plan-term records, usage and accounting records that cannot be altered, records of beta requests and request items, the pseudonym assigned to the deletion request, internal records with no evidence of which account they belong to, global caches and result records not linked to an account, caches missed by the deletion index or written before that index existed, and an external processor’s retention, backups and restored copies.
3. External Processors and Cross-border Transfers
An inspection provider (OpenAI or Azure), and an OCR provider when configured, may receive a data URL for an original or reference image and a brief. Vercel Functions/platform is used for request processing and error logging, and Supabase Auth is used for authentication.
The table below is prepared from each external processor’s public documents. Items marked not established in the table and the actual retention scope of backups and restored copies have not yet been confirmed; we will update this policy when they are confirmed (Section 8).
The role of the external AI provider — we treat it as processing on our instructions
We treat the external AI provider that performs the judging as a processor acting on our instructions. Our reasons: (1) the provider processes the request we send and returns a result; it does not use the content for its own purposes; (2) on 2026-08-19 we confirmed in the OpenAI organisation settings that model feedback sharing, evaluation and fine-tuning data sharing and input and output sharing were all disabled; (3) the provider’s published policy is that API content is not used to train its models unless you opt in.
This classification can turn on the substance of the contract, so we publish the level of detail a third-party disclosure would require (recipient, country, items transferred, purpose, retention period, sub-processors) in the table below, so the information you would need is already public either way.
We apply the same view to Supabase, Upstash, Vercel and Resend, which perform authentication, storage, hosting and email delivery on our instructions.
The Company may transfer personal information to overseas service providers for processing and storage in order to provide the Service. Under PIPA Article 28-8(1)3, entrustment and storage necessary to conclude and perform the service agreement are addressed through publication of this policy. This section does not determine the legal basis or lawfulness of any transfer. You may refuse international transfers. Where the relevant processing is necessary to provide the Service, refusal may prevent you from using all or part of image assessment, sign-in/account management, receipt of authentication email, or the relevant feature. Method and contact for refusal: winnow@jhlim.dev.
| Recipient (legal entity) and contact | Destination country/region | Time and method | Data transferred | Purpose | Retention/use period | Subprocessors/onward transfer |
|---|---|---|---|---|---|---|
| OpenAI OpCo, LLC (Delaware, USA) Notice address: 1455 3rd Street, San Francisco, CA 94158, USA Contact: contract-notices@openai.com | United States and countries where OpenAI’s public subprocessors process data | When you request an image assessment, transmitted from the server through the provider’s API | Inspection images and selected reference images, briefs, locale, and, where necessary, text recognised from images | Provide image-assessment and ordering results | Up to 30 days under the provider’s public policy (subject to legal-retention and abuse-investigation exceptions). The period that actually applies to our contract is not established (Section 8). | Subprocessors published by the provider |
| Supabase (Delaware, USA or Singapore entity) Contact: the channel named in the public DPA Which of the two entities is our contracting party is not established (Section 8). | The data-storage location is the Republic of Korea. However, because the processing entity is a foreign corporation, we disclose it as a cross-border transfer. | When processing sign-up, sign-in, recovery, or sessions, and when retrieving data | Email addresses, passwords, authentication tokens and sessions, account information, and usage records | Account authentication and Service data storage | While the account is maintained. The procedure in Section 2 applies when deletion is requested. | Subprocessors published by the provider |
| Upstash, Inc. (Delaware, USA) Contact: privacy@upstash.com | The United States is the primary processing country; because of the nature of the product in use, read locations in other countries may be added or changed. We will update this table when they change. | When operating caches and managing usage | Assessment results and image hashes, and usage and rate-limit counters (including account identifiers or transformed IP values) | Cache, usage management, abuse prevention, and budget controls | The periods in Section 2. The provider’s retention period for backups and logs is not established (Section 8). | Subprocessors published by the provider |
| Vercel Inc. (Delaware, USA) Contact: the channel named in the public DPA | United States | When processing web or API requests | Images, reference images, and briefs in requests, request metadata, and application error records | Hosting, Service execution, and operational records | The retention period for operational records is not established (Section 8). | Subprocessors published by the provider |
| Plus Five Five, Inc. (Resend, USA) Address: 2261 Market Street #5039, San Francisco, CA 94114, USA | United States and sending-processing countries published by the provider | When sending sign-up confirmation and password-reset emails | Recipient email addresses, the body and links of authentication and reset emails, and delivery-result records | Send authentication-related emails | The retention period for email bodies and delivery records is not established (Section 8). | Subprocessors published by the provider |
Customer Content sent through the OpenAI API Platform is not used to train OpenAI models by default; explicit opt-in is the stated exception. Our organization has not opted in to training use. On 2026-08-19 the OpenAI organization settings showed share model feedback, share evaluation and fine-tuning data, and share inputs and outputs all set to Disabled. API inputs and outputs may be retained for up to 30 days for service provision and abuse identification under the default candidate setting; eligibility and activation of Zero Data Retention or modified abuse monitoring must be confirmed separately.
4. Account Deletion
An account-deletion request requires re-authentication and explicit acknowledgement that deletion cannot be undone. We process the deletion workflow and notify you of the result within 10 days of receiving an eligible request. These 10 days are calendar days, not business days. We adopt the boundary set by Article 36(2) of Korea’s Personal Information Protection Act and Article 43(3) of its Enforcement Decree as the most conservative applicable standard. ⚠️ Whether this request is an Article 36 deletion demand, an Article 37 suspension/withdrawal, or a contractual account closure is not yet settled. We chose the shortest of the three, so the promise holds whichever it turns out to be. We do not publish a separate start deadline — two clocks let the looser one obscure the statutory boundary. This deadline is neither a grace period nor a cancellation period. Once the workflow starts, it cannot be cancelled or linked back to the former sign-in identity.
The deletion path processes the sign-in identity, account-linking information, and designated account-attributable caches, results, and projections. A disabled pseudonymous account identifier, plan-term records, usage and accounting records that cannot be altered, records of beta requests and request items, and the pseudonym assigned to each deletion request may remain. A remaining account_id can continue to connect events. ⚠️ Whether each retained item is personal data or pseudonymised data is not settled item by item, and none of it is anonymous data. We do not call this complete deletion or anonymisation.
When an account is deleted, additional usage requests made after the usage allowance was exhausted are disconnected from the account, and only the selected usage range is retained (for demand aggregation).
Internal records with no evidence of which account they belong to (for example the notification outbox and budget totals), caches and result records held in a global or anonymous scope, caches missed by the deletion index or written before that index existed, and retention by an external processor may remain. The current terminal state is therefore reported as a partial unlinking rather than complete account deletion.
If you create a new account after deletion, the new account may receive the free 200-image allowance.
5. AI Use Notice
An inspection is based on model output from an inspection provider. This policy makes no promise about accuracy, completeness, or a particular result. The information that may be sent to inspection or OCR providers is described in Section 3.
6. Contact and Exercise of Rights
A data subject may submit privacy enquiries and account-deletion requests to winnow@jhlim.dev. The published contact for privacy grievances and exercise of rights is the same address.
The current account-deletion request flow requires re-authentication and acknowledgement that deletion cannot be undone; for an eligible request, we notify the result within 10 calendar days of receipt. A refusal notice includes its reason and an objection route.
⚠️ Procedures for access, correction, suspension of processing, withdrawal of consent, and identity/agent verification are not yet established. Send such requests to the same address; settling the procedure requires expert confirmation.
7. Cookies and Automatically Received or Derived Information
The Service uses cookies necessary to maintain sign-in. These cookies contain authentication tokens and are set so that browser scripts cannot read them. They are transmitted only through encrypted connections in production. Sign-in is maintained for up to 30 days and expires immediately on sign-out. We do not use cookies for advertising or analytics.
The Service uses temporary browser storage to prevent repeated display of guidance dialogs. It contains no identity information or inspection content and disappears when you close the browser.
When you submit an inspection request, the Service receives your IP address and uses it for usage management and abuse prevention. IP addresses are used only after being converted into an irreversible form, and we do not store the original IP address.
If you block cookies in browser settings, sign-in will not be maintained and you will not be able to use features that require sign-in. Guidance about specific blocking methods and their effect on the Service is not yet established (Section 8).
8. What is not settled yet
This policy does not hide what is unsettled. The items below await outside expert confirmation, and this document is updated as each is confirmed.
- The legal basis for each processing purpose, and the basis and period for records that remain after account deletion (pseudonymous identifiers and accounting-type records).
- Contracts with external processors (DPAs), their own sub-processors, processing regions and cross-border transfers, and the scope of deletion in backups and restored copies.
- The procedure for access, correction, suspension of processing and withdrawal of consent, and how we verify identity or an authorised agent. Requests are already accepted at the address below.
- A backup route for handling deletion requests when the responsible person is unavailable. The 10 calendar-day handling deadline is already a firm commitment.