Skip to content
rootnine
Documents

Privacy Policy

A document setting out what personal data the services operated by rootnine collect and why, how long it is retained, and how it is destroyed.

Effective
2026-08-24
Applies to
RESCENE ARCHIVE · Let's Do Math · Syncronome

rootnine (the “Operator”) takes the personal data of its users seriously and complies with the Personal Information Protection Act (개인정보 보호법) and related legislation. rootnine is a development studio run by an individual, not a corporation, and this policy explains how users’ personal data is collected, used, retained, and destroyed in the services rootnine operates.

1. Categories of Personal Data Collected and Methods of Collection

The Operator collects only the minimum information necessary to provide the service.

Sign-up and authentication

Only social login (Apple, Google, Kakao) is supported; the email-and-password method is not used. At login, the following information is received from the authentication provider.

Item Required Purpose of collection
Unique identifier Required Account identification
Email address Required Account identification, sending important notices
Name or nickname Optional Display within the service
Profile image Optional Display within the service

Information generated in the course of using the service

  • Access date and time, IP address, device and browser information, service usage records
  • Push notification token (where the user has consented to receiving notifications)
  • Content written or saved by the user (collections, inquiries, etc.)

Information the user enters optionally

Information needed for personalization features, such as date of birth and items of interest, is collected only when the corresponding feature is used, and not entering it places no restriction on use of the basic service.

Information additionally collected in the study management service

Because children may be users of the study management service, the following information is additionally processed.

Subject Item Purpose of collection
Child Name or alias, school year Determining the scope of study, display on screen
Child Study records, study time, test attempts and grading results Managing progress, reviewing incorrect answers, access by the legal representative
Legal representative Name, email address, relationship to the child Confirming the person giving consent, granting access rights

2. Purposes of Using Personal Data

  • Member identification and maintaining login sessions
  • Providing the service and providing personalized content and notifications
  • Responding to inquiries and handling disputes
  • Preventing misuse and securing service stability
  • Fulfilling statutory obligations

Personal data collected is not used for purposes other than those above, and if the purpose changes, consent is obtained in advance.

3. Retention and Use Period of Personal Data

As a rule, personal data is destroyed without delay once the purpose of its collection and use has been achieved. However, in the following cases it is retained for the period stated.

Item Retention period Basis
Member information Until withdrawal of membership Service provision
Access records 3 months Protection of Communications Secrets Act (통신비밀보호법)
Records of consumer complaints and dispute handling 3 years E-Commerce Act (전자상거래법)

When a user requests deletion of their account, the related data is destroyed by a means from which it cannot be recovered, either immediately or after the statutory retention periods above have elapsed. Electronic files are permanently deleted in a manner that makes them irreproducible.

4. Personal Data of Children Under the Age of 14

The general services (RESCENE ARCHIVE, Syncronome) do not permit children under the age of 14 to sign up as members. During sign-up it is confirmed that the person is aged 14 or over, and an account confirmed to belong to a person under the age of 14 is blocked from signing up.

The study management service is a service that presupposes children as its users, and therefore a child’s personal data is processed only after the consent of a legal representative has been obtained in accordance with the procedure below.

  1. The legal representative signs up first. A child cannot create an account on their own; the legal representative authenticates with their own social account (Apple or Google) to create a guardian account.
  2. From the guardian account, the legal representative proceeds to create and link a child account. At this step a consent screen is presented that states the items collected, the purposes of use, and the retention period.
  3. When the legal representative consents, the date and time of consent, the items consented to, and the identifier of the consenting legal representative’s account are stored as a record. If consent is not given, the child account is not created.
  4. The child uses the service only through the account created and linked by the legal representative.

4-2. Means of identity verification

Whether a person is the legal representative is confirmed by the adult account verified through social authentication together with the information on the relationship to the child entered at step 2 above. For this purpose, the Operator does not collect any separate identifying information such as a resident registration number or credit card information.

A legal representative may request the following at any time.

  • Access to the child’s personal data — available directly on the guardian account screen
  • Correction of the child’s personal data
  • Deletion of the child’s personal data and termination of the account
  • Suspension of the processing of the child’s personal data
  • Withdrawal of consent

Requests that cannot be handled on the guardian account screen may be sent to the contact point below, and action will be taken without delay. If consent is withdrawn or the account is terminated, the related data, including the child’s study records, is destroyed by a means from which it cannot be recovered.

4-4. Principles for processing children’s personal data

  • A child’s personal data is used only for study management purposes and is not provided to third parties.
  • No advertising information is sent to children.
  • Children are not asked for unnecessary personal data, and only the minimum necessary to use the service is collected.
  • A child’s study records can be accessed only by the legal representative and the child themselves.

5. Provision of Personal Data to Third Parties

The Operator does not provide users’ personal data to third parties. The following cases are exceptions.

  • Where the user has consented in advance
  • Where there is a lawful request from an investigative authority under the law

6. Outsourcing of Personal Data Processing

For the operation of the service, personal data processing is outsourced to the following companies.

Processor Outsourced work Retention period
Supabase Inc. Database, authentication, file storage (region: Seoul, Republic of Korea) Until termination of the outsourcing contract
Vercel Inc. Web service hosting Until termination of the outsourcing contract
Google LLC (Firebase) Sending push notifications Until termination of the outsourcing contract
Apple Inc. Sending iOS push notifications Until termination of the outsourcing contract
Cloudflare Inc. App update distribution Until termination of the outsourcing contract

7. Users’ Rights and How to Exercise Them

Users may exercise the following rights at any time.

  • Request access to their personal data
  • Request correction where there is an error
  • Request deletion
  • Request suspension of processing

These can be handled directly on the settings screen within the service, or requested through the contact point below. The Operator acts on requests without delay after receiving them.

8. Measures to Secure the Safety of Personal Data

  • Limiting each user’s scope of access through database row level security (RLS) policies
  • Applying encryption in transit (HTTPS/TLS)
  • Secure storage of authentication tokens (using the device’s secure storage)
  • Access control for administrator screens and recording of audit logs
  • Minimizing the number of persons who handle personal data

9. Cookies and Similar Technologies

Only the minimum cookies necessary to maintain the login session are used. Third-party cookies for advertising or tracking purposes are not used.

10. Personal Data Protection Officer and Contact Point

Category Details
Personal data protection officer rootnine operator
Email support@rootnine.org

If you need consultation or wish to report an infringement of your personal data, you may contact the following organizations.

  • Korea Internet & Security Agency (KISA) Privacy Incident Report Center (개인정보침해 신고센터) (privacy.kisa.or.kr / 118)
  • Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회) (kopico.go.kr / 1833-6972)

11. Changes to This Policy

If this policy is changed, the changes and the effective date will be announced within the service. Material changes will be announced at least 7 days before the effective date.