Privacy Policy
Effective date: June 15, 2026
DevApril Co., Ltd. (the “Company”) regards the personal information of Q-MakerAI users as important and complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws.
1. Personal Information Collected
- Sign-up and sign-in: email address, password (stored one-way encrypted). Optional: display name.
- Use of paid services: payment identification data (order number, payment date and time, payment amount, card issuer name). Sensitive payment information is processed by TossPayments Inc.
- Taking an online exam (students): the nickname and PIN entered by the student (optional). Students take exams without registering as members, and the Company does not collect student accounts or contact details.
- Enquiries (including from non-members): name, email address, content of the enquiry. Optional: phone number, affiliation. Separate consent is obtained at the point of collection; if consent is declined, the enquiry cannot be accepted.
- Automatically collected: access IP, browser information (User-Agent), access date and time, usage records (cookies and sessions).
2. Purpose of Collection and Use
- Identifying members and verifying identity, and preventing fraudulent use
- Providing the Service, including question digitisation, similar-question generation, the question bank and online exams (LMS)
- Processing point top-up and plan subscription payments and refunds
- Essential operational notices (by email)
- Analysing usage statistics and improving service quality
- Responding to breaches of law or of these Terms
3. Retention and Use Period
| Type of information | Retention period |
|---|---|
| Member information | Destroyed immediately on withdrawal (within 30 days) |
| Records of contracts, payments and withdrawal of subscription | 5 years |
| Records of consumer complaints and dispute handling | 3 years |
| Access logs | 3 months |
| Records relating to tax invoices | 5 years |
4. Provision of Personal Information to Third Parties
As a rule, the Company does not provide users' personal information to outside parties. Exam results submitted by a student (nickname, PIN, answers) are made available within the Service to the member (teacher) who set that exam, which is processing essential to providing the Service.
5. Entrustment of Personal Information Processing
| Processor | Entrusted work |
|---|---|
| Supabase, Inc. | Member authentication, database hosting, file storage |
| Amazon Web Services, Inc. | Cloud infrastructure, static asset delivery |
| TossPayments Inc. | Payment processing, payment method verification, refund processing |
| OpenRouter, Inc. | AI question extraction and similar-question generation (uploaded images and text are transmitted) |
6. Cross-Border Transfer of Personal Information
To operate the Service, some personal information may be stored and processed by processors located outside Korea (in the United States and elsewhere: Supabase, AWS, OpenRouter), with safeguards such as encryption in transit and at rest. For AI processing, only the images and text required for that processing are transmitted.
7. Method of Destruction
- Electronic files: securely deleted in a manner that makes recovery or reproduction impossible
- Paper documents: shredded or incinerated
- Where retention is required by law, the information is stored separately and destroyed when the period expires
8. Rights of the Data Subject (Member)
Members may request access to, correction of, deletion of, or suspension of the processing of their personal information, and may request deletion or withdraw consent by withdrawing their membership. These rights may be exercised through profile settings or through customer support.
On withdrawal of membership, the content registered by the member is deleted and their personal information is destroyed without delay. However, information subject to a statutory retention obligation, such as payment and transaction records (under the Act on Consumer Protection in Electronic Commerce and other laws), is stored separately for the retention period set out in section 3 and then destroyed.
9. Cookies and Similar Technologies
Cookies and sessions are used to keep members signed in and to collect service usage statistics. Cookies may be refused in browser settings, but some parts of the Service may then be unavailable.
10. Measures to Ensure Security
- Access control and role-based permission management (tenant isolation)
- One-way hashing of passwords, TLS 1.2 or higher in transit, encryption at rest
- Retention and review of access logs, staff training and operation of security policies
11. Personal Information Protection Officer
Seokwoong Lee (Chief Executive Officer)
Email devapril2023@gmail.com · Phone 070-8019-1403
#413, 8, Baekbeom-ro 31-gil, Mapo-gu, Seoul, Republic of Korea
For advice regarding infringement of personal information, you may contact the Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972) or the Privacy Infringement Report Centre (privacy.kisa.or.kr / 118).
12. Changes to This Policy
Where there is a material change to this Policy, notice is given within the Service 7 days before it takes effect; where the change is unfavourable to members, notice is given by email 30 days in advance.