Skip to content

Privacy Policy

Privacy Policy

Effective date: June 27, 2026

021flow (Zero to One Flow) (제로투원플로우), operator of SeoulOracle (the "Service"), takes your privacy seriously and complies with Korea's Personal Information Protection Act (PIPA), the Act on Consumer Protection in Electronic Commerce, and other applicable laws. This policy explains what personal data the Service collects, how it is used, stored and shared, and your rights.

1. Data controller

The data controller is 021flow (Zero to One Flow) (제로투원플로우), a sole proprietorship, represented by Sungtae Ryu. Business address: A-2704, 25 Beopjo-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea. For privacy inquiries and to exercise your rights, contact [email protected]. As a sole proprietorship, the representative also serves as the personal-information protection officer, reachable at the same email.

2. Data we collect

We collect the following: (1) Account data: email, name or nickname, login identifier. (2) Authentication data: social-login provider identifier, token metadata. (3) Billing-related data: payment status, subscription plan, billing date, receipt/order identifiers, Paddle customer and transaction ids — we do not directly store sensitive payment-instrument data such as card number or CVC. (4) Service-usage data: access logs, IP address, browser/device information, usage, error logs. (5) Customer-support data: inquiry content, email, attachments, support records. (6) Cookies and similar technologies. (7) Birth data you enter (date of birth, time, calendar type, gender) and the content generated from it. (8) If you use the nearby-places feature, the device location (latitude/longitude) you explicitly grant — see Section 11.

3. How we use it

We use personal data only to: (1) register and manage your account; (2) provide the Service (Saju chart calculation and interpretation); (3) verify paid-plan and subscription status; (4) process billing, invoicing, refunds and tax/accounting; (5) provide customer support and notices; (6) maintain security, prevent abuse and respond to incidents; (7) improve the Service through statistics and analytics; and (8) comply with legal obligations.

4. Third parties & subprocessors

To operate the Service we entrust certain functions to, or share data with, the external providers (subprocessors) listed below. Each processes only the minimum data needed for its purpose.

SubprocessorPurposeData shared / processed
Paddle.com Market Ltd (Merchant of Record)Payment processing, tax, receipts, refunds, chargeback handling, billing supportOrder/subscription info, email, transaction id, payment status (card number / CVC are never shared or stored)
Anthropic (Claude)AI inference for Saju interpretation and conversation generationChart summary, user questions
OpenAIAI image generation (Korean-style self-portrait, etc.)Generation prompts
GoogleSocial login (OAuth) and cloud infrastructureAccount email, profile identifier
AppleSign in with Apple and App Store in-app purchasesAccount identifier
Cloud infrastructure (database, storage, email delivery) providersService data storage, file storage, transactional/support email deliveryAccount, content and log data needed to run the service

We do not sell your personal data, and we do not share your birth data (date, time, calendar type, gender) with third parties for marketing. Each subprocessor processes personal data only within the scope of its stated purpose.

5. International transfer

Some of the subprocessors above (Paddle, Anthropic, OpenAI, Google, Apple and others) are located outside Korea, so your personal data may be processed and stored abroad (primarily in the United States, the EU, or wherever the provider is located). The data items and purposes of transfer are the same as in Section 4, and transfers occur over the network at the time you use the Service, in order to provide the Service, process payments, and perform AI inference. You may refuse consent to such transfers, but core features such as payment and AI interpretation may then be unavailable.

6. Retention

We delete personal data without undue delay once its purpose is fulfilled. When you delete your account, your profile, charts and interpretation history are deleted without undue delay (within 30 days at the latest). However, billing, transaction and dispute records that we are legally required to keep (e.g., under the Act on Consumer Protection in Electronic Commerce) are retained for the statutory periods — for example, records on contracts and withdrawal of subscription for 5 years, records on payment and supply of goods for 5 years, and records on consumer complaints or disputes for 3 years. Backup data is purged on a periodic cycle, and minimal records may be kept to prevent abuse.

7. Your rights

You may at any time request access to, correction, deletion, suspension of processing, and withdrawal of consent for your personal data, as well as deletion of your account. You can act directly in account settings or email [email protected], and we will respond without undue delay as required by law. Residents of the EEA, the UK, and California may have additional rights under the GDPR, UK GDPR and CCPA.

8. Cookies

We use strictly necessary cookies (for login and session management) and analytics cookies (to understand usage). You can refuse cookies in your browser settings, but some features such as login may then be limited.

9. Security

To keep personal data safe we apply administrative and technical safeguards including access-permission limits, encryption (e.g., in transit), access/processing log management, regular backups, security updates, and administrator access controls.

10. Children

The Service is not directed to children under 14 (or under 16 in the EEA), and we do not knowingly collect their personal data. If we learn that we have collected data from such a child, we delete it without undue delay.

11. Location data

The nearby-places feature ("where to go today") receives your browser/device location (latitude/longitude) only when you explicitly allow it by tapping the feature. The coordinates are used in real time solely to call the Google Places API and compute distances for nearby suggestions; they are not stored on our servers. You can revoke location permission at any time in your browser or device settings, and doing so does not limit any other part of the Service. The Service performs no background location tracking.

12. Changes to this policy

We may update this Privacy Policy as laws or the Service change. We will post changes on this page and give advance notice of changes that materially affect your rights. Each revision states its effective date.