Privacy Policy
Last updated: 2026-08-29 · Effective: 2026-08-03
Different sections may take effect on different dates. The effective date of each revision is listed in Section 13 (Revision History).
코딕스(CODIX) ("the Company") complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other relevant laws of the Republic of Korea, and operates this Privacy Policy to safeguard members' personal information.
1. Categories of Personal Information Collected
The Company collects the following personal information for member registration and service provision.
A. Collected at sign-up
- Email address, password (stored as a one-way hash)
- When using social login: the identifier, email, nickname, and name (where provided) supplied by the external authentication provider
B. Collected during service use (information we treat with heightened care)
- Birth information: date of birth, time of birth, place of birth (including coordinates)
- Profile information: name (alias), gender
- AI consultation conversation history
- The Company does not use birth information to infer race, ethnicity, health or other special categories. We treat it as not constituting special category data, while protecting it to an equivalent standard.
C. Collected at payment
- Payment processing is handled by our payment processors (domestic: PortOne; international: Dodo Payments); the Company does not directly store card numbers.
- Buyer verification details: name and mobile phone number — the value entered at checkout for payments in Korea, or the name saved at social login (item A); retained to auto-fill future payments.
- Payment identifier (billing key), payment date, payment amount, subscription status
D. Automatically collected
- Access IP address, browser information, access logs, usage logs (for fraud detection and service quality improvement)
- Values stored in your browser (local storage): invitation and referral codes (to establish an invitation), display preferences, and which profile you last chose for consultation. Invitation and referral codes are no longer used 30 days after they are stored and are deleted on your next visit. You can delete or block this storage in your browser settings; if you block it, an invitation reward may not be established.
- Cookies: we use strictly necessary cookies to keep you signed in and to protect against tampering. You can block cookies in your browser settings, but if you do, your session will not persist and the Service cannot be used.
E. Collected from non-members who respond to a compatibility invitation
- Birth information: date of birth, time of birth, place of birth (city name and coordinates)
- Gender and the display name shown in the analysis (a nickname may be used)
- Display language, whether consent to storage was given, and the version of the consent notice agreed to
- IP address (for abuse prevention and to determine the minimum age applicable to the country of access)
- The compatibility analysis generated from the information above
2. Methods of Collection
- Input via the sign-up form or external authentication providers (Google, Kakao, etc.)
- Direct input during service use and via automated collection tools
- Transferred from the payment processor during payment method registration
3. Purposes of Use
- Member identification and authentication; service provision and operation
- Birth chart calculation and AI analysis response generation
- Paid subscription management, payment processing, refunds, and fraud prevention
- Service quality improvement, new feature development, statistical analysis
- Customer inquiry response and notice delivery
- Publishing member-written reviews within the Service and using them to present and promote the Service (display names are masked so that only the first character remains)
- Generating and providing compatibility analyses using birth information submitted by non-members who respond to an invitation link, and preventing abuse
- Determining the minimum age applicable to a non-member who responds to a compatibility invitation, based on the country of access
4. Retention and Use Period
- Member information: until the member withdraws. Where there is just cause such as fraud prevention, information may be retained for the period prescribed by applicable law.
- E-commerce related records: retained for the following periods under the Korean Act on Consumer Protection in Electronic Commerce.
- Records of contracts or withdrawal of subscriptions: 5 years
- Records of payment and supply of goods: 5 years
- Records of consumer complaints or dispute resolution: 3 years
- AI memory (RAG): 90 days from the date of storage on the Free plan; for other plans, retained until the member deletes it or closes their account — members may delete it at any time.
- Access logs: 3 months under the Korean Protection of Communications Secrets Act
- Information of non-members who respond to a compatibility invitation: where storage is not consented to, birth information is deleted immediately after the analysis is generated, and the analysis and display name are deleted 30 days after the invitation link was created. Where storage is consented to, the information is retained until the inviting member deletes it or closes their account.
- Right to data portability: You can download your personal data as a ZIP archive at any time to transfer it to another service. Request from Settings > Data; a download link is sent by email and expires in 24 hours.
- Destruction procedure and method: personal information is destroyed without delay once the retention period has elapsed or the purpose of processing has been achieved. Electronic files are deleted by means that make recovery impossible, and any printed materials are shredded or incinerated. Information retained under a legal obligation is destroyed in the same manner once that period ends.
5. Provision of Personal Information to Third Parties
As a rule, the Company does not provide the personal information of users — members and non-members alike — to third parties, and does so only in the cases listed below and in the provision arising from the compatibility invitation feature set out beneath them.
- When the user has given prior consent
- When required by law or by an investigative authority through lawful procedures
Provision arising from the compatibility invitation feature
Through an invitation link created by a member, information is provided in both directions between the two people. The details are as follows.
(1) Information of the responding non-member → the inviting member
- Recipient
- The member who created the invitation link
- Purpose
- Viewing the compatibility analysis of the two people
- Items provided
- The display name entered by the respondent and the compatibility analysis. Where the respondent consents to storage, also their birth information (date of birth, time of birth, place of birth, gender)
- Retention period
- 30 days from creation of the invitation link where storage is not consented to; until the inviting member deletes it or closes their account where consented to
- Legal basis
- Performance of the service requested by the respondent (GDPR Art. 6(1)(b)); storage in the member's account rests on consent (Art. 6(1)(a))
(2) Information of the inviting member → the responding non-member
- Recipient
- The non-member who responds to the invite link. Anyone who has been given the link can also view the result while it remains valid.
- Purpose
- Delivering the compatibility analysis that was requested
- Items provided
- The inviting member's display name, and the compatibility analysis, which interprets both people's birth information together
- Retention period
- For the lifetime of the invitation link (up to 30 days); ends as soon as the inviting member closes the link or destroys the result
- Legal basis
- The member's own act of creating and sending the invitation link
Where the recipient resides outside the Republic of Korea, the information above may be transferred to that country.
6. Outsourcing of Personal Information Processing
The Company outsources personal information processing as follows for service provision.
| Trustee | Location | Outsourced Work | Information Processed |
|---|---|---|---|
| PortOne (Korea PortOne) | Republic of Korea | Domestic payment integration and recurring billing | Email, name and mobile phone number (where required by the payment method), payment identifier, payment information |
| KG Inicis / KakaoPay | Republic of Korea | Domestic card and easy-payment processing | Payment information, buyer name and mobile phone number (where required by the payment method) |
| Dodo Payments | United States (place of incorporation), India (operations office) | International (USD) payment processing (Merchant of Record) | Email, payment information |
| Supabase Inc. | United States | Database hosting | Member information, birth information, conversation history |
| Google LLC (Vertex AI) | United States and other countries where Google operates the AI model concerned (see Section 9) | AI model inference and text embedding generation (Gemini, primary provider) | AI consultation conversation content (not used to train models) |
| OpenAI Inc. | United States | AI model inference (auxiliary provider used as automatic fallback during Gemini outages) | AI consultation conversation content (not used to train models) |
| Resend Inc. | United States | Email delivery (verification, password reset, feedback replies, etc.) | Email address |
| Cloudflare, Inc. | United States (headquarters) and countries where the content delivery network operates (see Section 9) | Content delivery (CDN), security and abuse blocking, country-of-access detection | IP address, request metadata |
| Sentry | United States | Diagnosing service errors and monitoring stability | Diagnostic information collected when an error occurs (request path, error message, browser and device information, and the processing records immediately preceding the error). Those records may include parts of the information you entered or saved (for example, a name saved in a profile or birth location coordinates). |
| Google LLC (Google Cloud Platform) | Japan (application hosting region) and the United States (operational and support access from headquarters) | Application hosting, operational log storage, and temporary storage of data download files | Information passing through our servers during processing (account information, birth information, conversation content), access and error logs, and data download files you request |
| Upstash, Inc. | United States (headquarters) and Japan (database region) | Temporary storage (caching) of calculation results and usage tallies | Chart calculation results (Saju, Western, Vedic), AI-generated suggestion text, usage and limit tallies, and temporary identifiers used to process requests |
As shown in the table above, some trustees are located outside the Republic of Korea. Details of international transfers are set out in Section 9.
7. Rights of Data Subjects and How to Exercise Them
Members may exercise the following rights at any time.
- Request access, correction, or deletion of personal information
- Request suspension of personal information processing
- Withdraw membership (can be done directly via the in-service settings page or customer support)
Rights may be exercised directly within the service or by contacting customer support ([email protected]).
Non-members without an account (those who respond to a compatibility invitation) may exercise the same rights through the channel described in Section 10.
Remedies for infringement: you may seek redress for personal information infringements from the data protection supervisory authority or dispute resolution body in your jurisdiction. In the Republic of Korea these are the Personal Information Dispute Mediation Committee (kopico.go.kr) and the Privacy Infringement Report Centre (privacy.kisa.or.kr).
8. Safeguards for Personal Information
- Passwords are stored using a one-way hash algorithm (bcrypt); the original cannot be recovered.
- All communication channels are encrypted with HTTPS/TLS.
- Database access is restricted to authorized backend servers, with Row Level Security ensuring members can access only their own data.
- Birth information, conversation history, and other data are stored in databases under the access controls above and are not exposed externally.
- Administrator access logs are recorded and regularly reviewed to monitor for abnormal access.
- Authorized administrators may review pseudonymized conversation content for the purposes of service quality improvement, security, and legal compliance. Personally identifiable information in messages is automatically masked, and every access is recorded in an audit log.
- Where the Company outsources personal information processing, it sets the scope of the outsourced work and the required safeguards by contract, and supervises whether the processor handles personal information securely.
9. International Data Transfers
The Company transfers personal information outside the Republic of Korea in order to provide the Service. The details are as follows.
- Legal basis for transfer: the Company transfers personal information overseas for the purpose of outsourced processing and storage, to the extent necessary to enter into and perform its contract with you, under Article 28-8(1)3 of the Personal Information Protection Act of the Republic of Korea, and discloses the matters listed in Article 28-8(2) of that Act in this policy.
- Recipients: the overseas processors listed in the table in Section 6
- Countries of transfer: the United States, Japan, India, and the countries determined under the final item of this section (each processor's location is shown in the table in Section 6)
- Timing and method of transfer: transmitted on an ongoing basis over encrypted connections (HTTPS/TLS) as you use the Service
- Items transferred: as listed under ‘Information Processed’ in Section 6
- Purpose: limited to performing the outsourced work listed in Section 6
- Retention period: as set out in Section 4; data are destroyed once they are no longer needed for the outsourced work
- How to object: you may object to international transfers by contacting customer support. However, because these processors are essential to providing the Service, objecting means you will need to close your account or stop using the relevant features. Non-members may request deletion of their information through the channels set out in Section 10.
- Where the processing country cannot be identified in advance: the AI model the Company uses is offered only through a route that does not allow a region to be specified, so the country in which an individual request is processed is determined by how the model is operated at the time of the request and cannot be identified in advance. Content delivery network traffic may likewise be processed in a region close to the user. The countries concerned fall within the service regions published by each processor, and if you contact customer support we will tell you the scope as at the time of your enquiry together with the contact details of each processor. Regardless of the processing country, the same data processing agreement concluded between the Company and each processor applies, under which the processor is bound by obligations on security, confidentiality and control of sub-processing, and under which Google does not use this information to train its AI models.
For users in the European Economic Area and the United Kingdom, transfers are made under Standard Contractual Clauses (SCCs, including the UK Addendum where applicable) or another transfer mechanism recognised by applicable law, and a copy can be made available to you on request to customer support. Regardless of where you are located, you may exercise your rights as a data subject at any time as described in Section 7, and you have the right to lodge a complaint with your local supervisory authority.
10. Processing of Personal Information of Non-Members Who Respond to a Compatibility Invitation
The Company processes the personal information of users who respond to a compatibility invitation link without creating an account (‘non-members’) as follows.
- Controller: the Company is the controller of non-members' personal information. The fact that the analysis is stored in the inviting member's account does not make that member the controller.
- Legal basis: generating and delivering the compatibility analysis is necessary to perform the service the non-member requested (GDPR Art. 6(1)(b)). Continued storage of the non-member's birth information in the inviting member's account rests on the separate consent obtained on the input screen (Art. 6(1)(a)).
- Withdrawal of consent: a non-member who consented to storage may withdraw that consent at any time through the channel below. Withdrawal does not affect the lawfulness of processing carried out before it, and does not restrict access to the analysis already provided.
- International transfers: a non-member's birth information and analysis request are processed through the processors listed in Section 6, and Section 9 applies to those transfers in full.
- Age: the Service is not directed to children under 13 and we do not knowingly collect their personal information. In any case, persons under 14 may not respond to a compatibility invitation, and the Company verifies this from the date of birth entered. Where the applicable age in your country of residence is higher, or where the Company applies a higher age based on the country of access, you may not use this feature until the age shown on the invitation screen is reached.
- No detriment: declining to consent to storage places no restriction whatsoever on viewing the compatibility analysis.
- Supervisory authority: you may lodge a complaint with the data protection supervisory authority in your jurisdiction. In the Republic of Korea this is the Personal Information Protection Commission (privacy.go.kr); infringements may also be reported to the Privacy Infringement Report Centre (privacy.kisa.or.kr).
- Who can view the result: the compatibility result page can be opened by anyone holding the invite link. Access is blocked once the link expires or the inviting member closes it.
Exercising your rights: without an account or login, non-members may use the following channels. To withdraw only the storage consent, use ‘Delete only the saved information’ on the result screen — you will still be able to view the analysis. To erase the result and the conversation as well, use ‘Request deletion of my data’. After the invitation link has expired, please contact customer support ([email protected]). Possession of the invitation link serves as the means of identity verification.
11. Personal Information Protection Officer
12. Changes to This Policy
When this Privacy Policy is amended, the Company will notify members via in-service announcements at least 7 days before the effective date. For changes that materially affect member rights, notice will be given at least 30 days in advance. However, changes that do not restrict your rights or impose new obligations may take effect at the same time as the notice.
13. Revision History
- Effective 2026-08-29 — Amendments to Articles 1 and 6: added buyer verification details (name and mobile phone number) to the items collected and to the data handled by our payment processors (PortOne, KG Inicis/KakaoPay) — entered at checkout for payments in Korea or taken from the name provided by social login, and stored to auto-fill future payments. Retention is unchanged: until membership withdrawal (Article 4)
- Published 2026-08-26 — Correction to the stated effective date: the Compatibility Invitation feature has been available since August 3, 2026, but the effective date shown for the corresponding provisions of this Policy read October 1, 2026. We are correcting it to August 3, 2026 to match the date on which processing actually began. The full revised text was published on this page on August 3, 2026, before the feature became available, and the personal data of non-members who responded to an invitation was processed in accordance with the collection and use notice and the consent presented on the invitation screen. This correction does not change the categories collected, the purposes of use, the retention period, provision to third parties, or overseas transfers.
- Effective 2026-08-26 — Amendment to Article 4: the stated retention period for AI memory (RAG) was corrected to match actual processing (90 days from the date of storage on the Free plan; for other plans, until the member deletes it or closes their account)
- Effective 2026-08-18 — Amendment to Articles 6 and 9: added the error-diagnosis, hosting, and cache processors already used in operating the service to the table, and listed the countries to which data is transferred
- Effective 2026-08-10 — Sections 6, 8, 9 and 12 revised: added provisions on the countries in which AI model inference is processed, stated the legal basis for international transfers, revised how processor locations are described, added a processor supervision clause, and added a same-day effect proviso to the change notice clause
- Effective 2026-08-03 — Revised for the compatibility invitation feature: new section on processing non-members' personal information, revised third-party provision section, detailed international transfer disclosures, and processor locations added, new destruction procedure and infringement remedy sections, and added disclosures on browser storage and cookies
- Effective 2026-07-28 — Added the purpose of using member reviews to introduce and promote the Service
This policy is effective from 2026-08-03.
Different sections may take effect on different dates. The effective date of each revision is listed in Section 13 (Revision History).