Controller and privacy officer
모프트에이아이 주식회사 is the data controller. The privacy officer is 김기웅; inquiries may be sent to admin@moftai.com or 050-6564-8261.
We process personal data in accordance with Korea's Personal Information Protection Act and other applicable laws. If the purpose changes or additional information is required, we provide the notices and obtain the consents required by law.
Purposes and categories of data
For registration and authentication, we process email, name or display name, verification status, and social-login identifiers. For contracts, payment, and support, we process plan information, payment identifiers and amounts, the credit ledger, and support requests.
To perform AI requests and provide history, we process prompts, conversations, attachments, projects, and outputs. For security and incident response, we may process IP address, browser and device information, access time, request identifiers, and audit logs.
Collection and automatically generated data
Personal data is collected from information you submit or that the system generates during registration, social login, payment, service use, support, and API calls.
Cookies and session identifiers are used to maintain sign-in and security. Blocking cookies in the browser may prevent features such as sign-in from working.
Retention
Basic account data is retained until account deletion; conversations and messages for 90 days after creation; and asynchronous task inputs and outputs for 30 days after completion or failure. They are then deleted or irreversibly redacted. Earlier user deletion is honored except for records that must be retained by law.
E-commerce contract, withdrawal, payment, and supply records are retained for five years; consumer complaint and dispute records for three years; and advertising records for six months. Security and abuse records are deleted when their purpose is achieved unless a separate statutory period applies.
Processors and overseas processing
We may use Google Cloud Platform for servers, databases, and file storage; Resend for email; and PortOne and connected payment providers for payment processing. This policy is updated if the actual providers or scope change.
To provide the AI feature you request, prompts, necessary conversation context, or portions of files may be sent to overseas AI providers such as OpenAI, Anthropic, Google, or Moonshot. Destination, timing, method, and retention depend on the selected provider's processing locations and policy. We transmit only data needed for the request.
Third-party disclosure and choices
We do not sell or disclose personal data to third parties except with separate consent or another legal basis. AI processors and payment or infrastructure providers are managed as processors or overseas recipients, as applicable.
You may avoid features that require transmission to an external model or remove personal data from attachments. If you decline a transmission required for the selected AI feature, that feature may not be available.
Deletion and safeguards
Electronic files are deleted or de-identified so they cannot reasonably be recovered after retention ends, and paper output, if any, is securely destroyed. Exposure of API keys and credentials is minimized; hashes or limited prefixes are used where appropriate.
We apply reasonable technical and organizational safeguards, including least-privilege access, encryption in transit, administrator audit logs, secret separation, vulnerability checks, and backups.
Your rights and remedies
You may contact admin@moftai.com to request access, correction, deletion, suspension of processing, withdrawal of consent, or account deletion. We verify identity and respond within the statutory period, explaining any lawful limitation.
In Korea, privacy incident counseling is available at 118 and dispute mediation through the Personal Information Dispute Mediation Committee at 1833-6972. This Policy applies from its effective date, and material changes are announced in advance.