Privacy Policy
Last updated: 2026-08-03 · Effective: 2026-10-01
코딕스(CODIX) ("the Company") complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other relevant laws of the Republic of Korea, and operates this Privacy Policy to safeguard members' personal information.
1. Categories of Personal Information Collected
The Company collects the following personal information for member registration and service provision.
A. Collected at sign-up
- Email address, password (stored as a one-way hash)
- When using social login: identifier, email, and nickname provided by the external authentication provider
B. Collected during service use (information we treat with heightened care)
- Birth information: date of birth, time of birth, place of birth (including coordinates)
- Profile information: name (alias), gender
- AI consultation conversation history
- The Company does not use birth information to infer race, ethnicity, health or other special categories. We treat it as not constituting special category data, while protecting it to an equivalent standard.
C. Collected at payment
- Payment processing is handled by our payment processors (domestic: PortOne; international: Dodo Payments); the Company does not directly store card numbers.
- Payment identifier (billing key), payment date, payment amount, subscription status
D. Automatically collected
- Access IP address, browser information, access logs, usage logs (for fraud detection and service quality improvement)
- Values stored in your browser (local storage): invitation and referral codes (to establish an invitation), display preferences, and which profile you last chose for consultation. Invitation and referral codes are no longer used 30 days after they are stored and are deleted on your next visit. You can delete or block this storage in your browser settings; if you block it, an invitation reward may not be established.
- Cookies: we use strictly necessary cookies to keep you signed in and to protect against tampering. You can block cookies in your browser settings, but if you do, your session will not persist and the Service cannot be used.
E. Collected from non-members who respond to a compatibility invitation
- Birth information: date of birth, time of birth, place of birth (city name and coordinates)
- Gender and the display name shown in the analysis (a nickname may be used)
- Display language, whether consent to storage was given, and the version of the consent notice agreed to
- IP address (for abuse prevention and to determine the minimum age applicable to the country of access)
- The compatibility analysis generated from the information above
2. Methods of Collection
- Input via the sign-up form or external authentication providers (Google, Kakao, etc.)
- Direct input during service use and via automated collection tools
- Transferred from the payment processor during payment method registration
3. Purposes of Use
- Member identification and authentication; service provision and operation
- Birth chart calculation and AI analysis response generation
- Paid subscription management, payment processing, refunds, and fraud prevention
- Service quality improvement, new feature development, statistical analysis
- Customer inquiry response and notice delivery
- Publishing member-written reviews within the Service and using them to present and promote the Service (display names are masked so that only the first character remains)
- Generating and providing compatibility analyses using birth information submitted by non-members who respond to an invitation link, and preventing abuse
- Determining the minimum age applicable to a non-member who responds to a compatibility invitation, based on the country of access
4. Retention and Use Period
- Member information: until the member withdraws. Where there is just cause such as fraud prevention, information may be retained for the period prescribed by applicable law.
- E-commerce related records: retained for the following periods under the Korean Act on Consumer Protection in Electronic Commerce.
- Records of contracts or withdrawal of subscriptions: 5 years
- Records of payment and supply of goods: 5 years
- Records of consumer complaints or dispute resolution: 3 years
- AI memory (RAG): 90 days for Free plan, 365 days for Basic plan, indefinite for Pro plan — members may delete it at any time.
- Access logs: 3 months under the Korean Protection of Communications Secrets Act
- Information of non-members who respond to a compatibility invitation: where storage is not consented to, birth information is deleted immediately after the analysis is generated, and the analysis and display name are deleted 30 days after the invitation link was created. Where storage is consented to, the information is retained until the inviting member deletes it or closes their account.
- Right to data portability: You can download your personal data as a ZIP archive at any time to transfer it to another service. Request from Settings > Data; a download link is sent by email and expires in 24 hours.
- Destruction procedure and method: personal information is destroyed without delay once the retention period has elapsed or the purpose of processing has been achieved. Electronic files are deleted by means that make recovery impossible, and any printed materials are shredded or incinerated. Information retained under a legal obligation is destroyed in the same manner once that period ends.
5. Provision of Personal Information to Third Parties
As a rule, the Company does not provide the personal information of users — members and non-members alike — to third parties, and does so only in the cases listed below and in the provision arising from the compatibility invitation feature set out beneath them.
- When the user has given prior consent
- When required by law or by an investigative authority through lawful procedures
Provision arising from the compatibility invitation feature
Through an invitation link created by a member, information is provided in both directions between the two people. The details are as follows.
(1) Information of the responding non-member → the inviting member
- Recipient
- The member who created the invitation link
- Purpose
- Viewing the compatibility analysis of the two people
- Items provided
- The display name entered by the respondent and the compatibility analysis. Where the respondent consents to storage, also their birth information (date of birth, time of birth, place of birth, gender)
- Retention period
- 30 days from creation of the invitation link where storage is not consented to; until the inviting member deletes it or closes their account where consented to
- Legal basis
- Performance of the service requested by the respondent (GDPR Art. 6(1)(b)); storage in the member's account rests on consent (Art. 6(1)(a))
(2) Information of the inviting member → the responding non-member
- Recipient
- The non-member who responds to the invite link. Anyone who has been given the link can also view the result while it remains valid.
- Purpose
- Delivering the compatibility analysis that was requested
- Items provided
- The inviting member's display name, and the compatibility analysis, which interprets both people's birth information together
- Retention period
- For the lifetime of the invitation link (up to 30 days); ends as soon as the inviting member closes the link or destroys the result
- Legal basis
- The member's own act of creating and sending the invitation link
Where the recipient resides outside the Republic of Korea, the information above may be transferred to that country.
6. Outsourcing of Personal Information Processing
The Company outsources personal information processing as follows for service provision.
| Trustee | Location | Outsourced Work | Information Processed |
|---|---|---|---|
| PortOne (Korea PortOne) | Republic of Korea | Domestic payment integration and recurring billing | Email, payment identifier, payment information |
| KG Inicis / KakaoPay | Republic of Korea | Domestic card and easy-payment processing | Payment information |
| Dodo Payments | United States (place of incorporation), India (operations office) | International (USD) payment processing (Merchant of Record) | Email, payment information |
| Supabase Inc. | United States | Database hosting | Member information, birth information, conversation history |
| Google LLC (Vertex AI) | United States | AI model inference (Gemini, primary provider) | AI consultation conversation content (real-time processing, not used for training) |
| OpenAI Inc. | United States | AI model inference (auxiliary provider used as automatic fallback during Gemini outages) | AI consultation conversation content (real-time processing, not used for training) |
| Resend Inc. | United States | Email delivery (verification, password reset, feedback replies, etc.) | Email address |
| Cloudflare, Inc. | United States | Content delivery (CDN), security and abuse blocking, country-of-access detection | IP address, request metadata |
As shown in the table above, some trustees are located outside the Republic of Korea. Details of international transfers are set out in Section 9.
7. Rights of Data Subjects and How to Exercise Them
Members may exercise the following rights at any time.
- Request access, correction, or deletion of personal information
- Request suspension of personal information processing
- Withdraw membership (can be done directly via the in-service settings page or customer support)
Rights may be exercised directly within the service or by contacting customer support ([email protected]).
Non-members without an account (those who respond to a compatibility invitation) may exercise the same rights through the channel described in Section 10.
Remedies for infringement: you may seek redress for personal information infringements from the data protection supervisory authority or dispute resolution body in your jurisdiction. In the Republic of Korea these are the Personal Information Dispute Mediation Committee (kopico.go.kr) and the Privacy Infringement Report Centre (privacy.kisa.or.kr).
8. Safeguards for Personal Information
- Passwords are stored using a one-way hash algorithm (bcrypt); the original cannot be recovered.
- All communication channels are encrypted with HTTPS/TLS.
- Database access is restricted to authorized backend servers, with Row Level Security ensuring members can access only their own data.
- Birth information, conversation history, and other data are stored in databases under the access controls above and are not exposed externally.
- Administrator access logs are recorded and regularly reviewed to monitor for abnormal access.
- Authorized administrators may review pseudonymized conversation content for the purposes of service quality improvement, security, and legal compliance. Personally identifiable information in messages is automatically masked, and every access is recorded in an audit log.
9. International Data Transfers
The Company transfers personal information outside the Republic of Korea in order to provide the Service. The details are as follows.
- Recipients: the overseas processors listed in the table in Section 6
- Countries of transfer: the United States and India (each processor's location is shown in the table in Section 6)
- Timing and method of transfer: transmitted on an ongoing basis over encrypted connections (HTTPS/TLS) as you use the Service
- Items transferred: as listed under ‘Information Processed’ in Section 6
- Purpose: limited to performing the outsourced work listed in Section 6
- Retention period: as set out in Section 4; data are destroyed once they are no longer needed for the outsourced work
- How to object: you may object to international transfers by contacting customer support. However, because these processors are essential to providing the Service, objecting means you will need to close your account or stop using the relevant features. Non-members may request deletion of their information through the channels set out in Section 10.
For users in the European Economic Area and the United Kingdom, transfers are made under Standard Contractual Clauses (SCCs) or another transfer mechanism recognised by applicable law. Regardless of where you are located, you may exercise your rights as a data subject at any time as described in Section 7, and you have the right to lodge a complaint with your local supervisory authority.
10. Processing of Personal Information of Non-Members Who Respond to a Compatibility Invitation
The Company processes the personal information of users who respond to a compatibility invitation link without creating an account (‘non-members’) as follows.
- Controller: the Company is the controller of non-members' personal information. The fact that the analysis is stored in the inviting member's account does not make that member the controller.
- Legal basis: generating and delivering the compatibility analysis is necessary to perform the service the non-member requested (GDPR Art. 6(1)(b)). Continued storage of the non-member's birth information in the inviting member's account rests on the separate consent obtained on the input screen (Art. 6(1)(a)).
- Withdrawal of consent: a non-member who consented to storage may withdraw that consent at any time through the channel below. Withdrawal does not affect the lawfulness of processing carried out before it, and does not restrict access to the analysis already provided.
- International transfers: a non-member's birth information and analysis request are processed through the processors listed in Section 6 (database hosting and AI inference), and Section 9 applies to those transfers in full.
- Age: the Service is not directed to children under 13 and we do not knowingly collect their personal information. In any case, persons under 14 may not respond to a compatibility invitation, and the Company verifies this from the date of birth entered. Where the applicable age in your country of residence is higher, or where the Company applies a higher age based on the country of access, you may not use this feature until the age shown on the invitation screen is reached.
- No detriment: declining to consent to storage places no restriction whatsoever on viewing the compatibility analysis.
- Supervisory authority: you may lodge a complaint with the data protection supervisory authority in your jurisdiction. In the Republic of Korea this is the Personal Information Protection Commission (privacy.go.kr); infringements may also be reported to the Privacy Infringement Report Centre (privacy.kisa.or.kr).
- Who can view the result: the compatibility result page can be opened by anyone holding the invite link. Access is blocked once the link expires or the inviting member closes it.
Exercising your rights: without an account or login, non-members may use the following channels. To withdraw only the storage consent, use ‘Delete only the saved information’ on the result screen — you will still be able to view the analysis. To erase the result and the conversation as well, use ‘Request deletion of my data’. After the invitation link has expired, please contact customer support ([email protected]). Possession of the invitation link serves as the means of identity verification.
11. Personal Information Protection Officer
12. Changes to This Policy
When this Privacy Policy is amended, the Company will notify members via in-service announcements at least 7 days before the effective date. For changes that materially affect member rights, notice will be given at least 30 days in advance.
13. Revision History
- Effective 2026-10-01 — Revised for the compatibility invitation feature: new section on processing non-members' personal information, revised third-party provision section, detailed international transfer disclosures, and processor locations added, new destruction procedure and infringement remedy sections, and added disclosures on browser storage and cookies
- Effective 2026-07-28 — Added the purpose of using member reviews to introduce and promote the Service
This policy is effective from 2026-10-01.