Effective: July 24, 2026
ffgg (에프에프지지, hereinafter "Company") processes personal information for the following purposes to provide QA Note. If a purpose changes, the Company will take any measures required by applicable law, including obtaining separate consent where required.
The Company collects the following personal information for service provision:
Required Items:
Social Login:
Automatically Collected During Service Use:
Payment:
After an account deletion request, the Company provides a 30-day grace period for recovery and data transfer, then destroys account identifiers. The user may cancel the deletion request during the grace period.
Organization work records, including issues and reports, follow the organization's contract and plan retention policy. After account deletion, records may remain in de-identified form where necessary for other authorized organization members.
However, if retention is required by applicable laws, the information is retained for the legally mandated period:
The Company does not provide personal information to third parties without user consent, except as required by law.
If the user has configured integrations, data may be transmitted to the following external services:
The Company outsources personal information processing as follows for service provision:
| Service Provider | Outsourced Tasks | Retention Period |
|---|---|---|
| PortOne Co., Ltd. | Payment processing when paid billing is enabled; cancellation and refunds for existing payments | Statutory e-commerce retention period or until the processing agreement ends |
| Cloudflare, Inc. | R2 file storage and CDN delivery | Applicable plan or contract work-record retention period |
| Plus Five Five, Inc. (Resend) | Account and notification email delivery | Email data for 30 days |
| Anthropic, PBC | Issue analysis and drafting from screenshots and annotations | Up to 30 days under the default API retention policy |
| OpenAI, LLC | Text analysis and drafting for issues, reports, and project code chat | Up to 30 days under the default API retention policy |
| Supabase, Inc. | PostgreSQL database hosting | Applicable plan or contract period and the account-deletion grace period |
| Vercel, Inc. | Web application hosting and request-log processing | Service period and provider log or backup policy |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Configured project event-retention period, up to 90 days |
| Upstash, Inc. | Rate limiting, abuse prevention, and short-lived caching | Per-key TTL, no longer than 24 hours |
Under Article 28-8(1)(3) of the Korean Personal Information Protection Act, the Company transfers personal information overseas as processing or storage necessary to perform the service contract. Transfers occur over TLS when the relevant feature or service request is used:
| Recipient | Country / Region | Items Transferred | Purpose | Timing / Method | Retention Period |
|---|---|---|---|---|---|
| Anthropic, PBC | United States | Issue content, screenshots and annotations, and required technical metadata | Issue analysis and drafting | TLS transfer when an AI feature runs | Up to 30 days under the default API retention policy |
| OpenAI, LLC | United States | Issue and report text, summarized technical metadata, and user-requested project code context | Text analysis, narrative drafting, and code chat | TLS transfer when an AI feature runs | Up to 30 days under the default API retention policy |
| Cloudflare, Inc. | United States and global network (R2 location hint: APAC) | Screenshots, session records, and attachments | File storage and CDN delivery | TLS transfer on upload or retrieval | Applicable plan or contract work-record retention period |
| Supabase, Inc. | Seoul, South Korea (AWS ap-northeast-2; provider headquartered in the United States) | Account, organization, issue, report, and other service data | PostgreSQL database hosting | TLS transfer during service use | Applicable plan or contract period and the account-deletion grace period |
| Vercel, Inc. | United States and global CDN | IP address, User-Agent, request path, and error or performance metadata | Web application hosting | TLS transfer on service request | Provider log and backup policy |
| Plus Five Five, Inc. (Resend) | United States | Email address, name, and outbound message content | Account and notification email delivery | TLS transfer when an email is sent | Email data for 30 days |
| Functional Software, Inc. (Sentry) | United States | Error message, stack trace, query-free request path, and performance metadata | Error and performance monitoring | TLS transfer when an error or performance event occurs | Configured project period, up to 90 days |
| Upstash, Inc. | Seoul, South Korea (icn1; provider headquartered in the United States) | Hashed or other identifiers derived from IP, account, or email values for rate-limit keys, and short-lived cache entries | Rate limiting, abuse prevention, and caching | TLS transfer on service request | Per-key TTL, no longer than 24 hours |
Users (data subjects) may exercise the following rights:
The Company destroys personal information without delay when the retention period has expired, or when the processing purpose has been achieved and the information is no longer needed.
Destruction Procedures:
Destruction Methods:
The Company takes the following measures to ensure the security of personal information:
The Company may collect behavioral information through the session replay feature for QA purposes. This is collected only when the user has explicitly activated the feature.
Behavioral Information Collected:
Purpose of Collection:
How to Opt Out:
The QA Note Chrome Extension collects technical metadata solely for the purpose of creating QA reports. All data collection begins only after the user's explicit consent.
Prerequisites for Data Collection:
Technical Metadata Collected:
Data Storage and Transmission:
Sensitive Information Protection Measures:
The Company uses AI technology to perform the following automated processing:
Automated Processing:
User Rights:
Due to the nature of the B2B SaaS service, the Company restricts service use by children under 14 years of age.
If a user is confirmed to be under 14, service registration is denied without the consent of a legal guardian, and any collected personal information is immediately destroyed.
The Company has designated a Privacy Officer to oversee personal information processing operations and to handle complaints and remedies related to personal information:
The QA Note Chrome Extension is distributed through the Google Chrome Web Store and complies with Google's Chrome Web Store User Data Policy.
QA Note's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Limited Use Compliance:
This Privacy Policy may be amended due to changes in laws, policies, or services. Any changes will be announced through in-service notices at least 7 days in advance.
Significant changes (addition of collected items, changes to third-party provision, etc.) will be announced at least 30 days in advance.