개인정보처리방침
먼저 요약하면
- 여러분이 AI와 나눈 대화, 작업한 코드와 파일은 회사 서버로 전송되지 않습니다. 여러분의 컴퓨터에만 저장됩니다.
- AI 서비스의 API 키도 서버로 보내지 않습니다. 운영체제의 자격 증명 저장소 또는 프로그램 메모리에만 있습니다.
- 회사 서버가 보관하는 것은 계정 정보뿐입니다 — 이메일 주소, 이름, 로그인 수단.
- IP 주소는 저장하지 않습니다. 무차별 대입 차단을 위해 메모리에서만 잠시 쓰고 버립니다.
- 광고·분석 목적의 추적 도구를 쓰지 않습니다.
1. 개인정보의 처리 목적
회사는 다음의 목적으로만 개인정보를 처리합니다.
- 회원 가입 및 관리 — 본인 확인, 계정 식별, 중복 가입 방지, 부정 이용 방지, 고지사항 전달
- 서비스 제공 — 로그인 상태 유지, 여러 기기에서의 계정 연동
- 보안 — 무차별 대입 공격 차단, 비정상 접근 탐지
- 문의 응대 — 이용자가 보낸 문의에 답변
처리 목적이 변경되는 경우, 회사는 「개인정보 보호법」 제18조에 따라 별도의 동의를 받는 등 필요한 조치를 이행합니다.
2. 처리하는 개인정보의 항목
2-1. 회사 서버에 저장되는 항목
| 구분 | 항목 | 수집 방법 |
|---|---|---|
| 필수 | 이메일 주소 | 이용자 입력 또는 소셜 로그인 제공사로부터 전달 |
| 필수 | 계정 식별자(무작위 생성 값) | 회사가 생성 |
| 선택 | 이름 또는 닉네임 | 이용자 입력 또는 소셜 로그인 제공사로부터 전달 |
| 조건부 | 비밀번호 — 원문이 아닌 해시값(scrypt)만 저장하며, 회사는 원래 비밀번호를 알 수 없습니다 | 아이디/비밀번호 로그인을 쓰는 경우에 한해 이용자 입력 |
| 조건부 | 소셜 로그인 제공사가 부여한 회원번호, 해당 제공사가 알려준 이메일 | 소셜 로그인을 쓰는 경우에 한해 제공사로부터 전달 |
| 자동 | 로그인 세션 정보 — 세션 토큰의 해시값, 기기 표시명, 생성·만료·최종 사용 시각 | 로그인 시 자동 생성 |
| 자동 | 가입일시, 최종 접속일시 | 서비스 이용 시 자동 생성 |
| 임시 | 이메일 인증번호 및 그 시도 횟수 (10분 후 폐기) | 인증 요청 시 자동 생성 |
2-2. 회사 서버에 저장되지 않는 것
다음은 이용자의 기기에만 존재하며, 회사 서버로 전송되지 않고 회사는 접근할 수 없습니다.
- AI와 주고받은 대화 내용, 지시문, 답변
- 이용자가 작업한 코드·문서·그 밖의 파일과 그 경로
- 이용자가 등록한 AI 서비스 API 키 — 데스크톱 앱에서는 운영체제의 자격 증명 저장소에, 채팅 앱에서는 실행 중인 메모리에만 보관하며 디스크에 평문으로 기록하지 않습니다
- 화면 캡처 이미지 및 컴퓨터 조작 기록
2-3. 수집하지 않는 것
- IP 주소 — 무차별 대입 시도를 막기 위해 요청을 처리하는 동안 메모리에서만 사용하고, 데이터베이스나 영구 저장소에 기록하지 않습니다.
- 주민등록번호 등 고유식별정보
- 결제 카드 정보 (아래 6-2 참조)
- 위치정보, 연락처, 사진첩 등 기기 내 개인정보
- 광고 식별자, 행태정보
3. 개인정보의 처리 및 보유 기간
| 항목 | 보유 기간 |
|---|---|
| 계정 정보 (이메일, 이름, 비밀번호 해시, 연결된 로그인 수단) | 회원 탈퇴 시까지. 탈퇴 요청을 받으면 지체 없이 파기합니다. |
| 로그인 세션 | 발급일로부터 60일 후 자동 만료. 로그아웃 시 즉시 삭제. |
| 이메일 인증번호 | 10분 후 자동 폐기 |
| 데이터베이스 백업본 | 매일 1회 생성, 14일 경과분 자동 삭제. 탈퇴 후 최대 14일 이내에 백업본에서도 사라집니다. |
다른 법령에서 일정 기간의 보존을 요구하는 경우에는 해당 기간 동안 보관하며, 이 경우 보관 목적 외의 용도로 이용하지 않습니다.
4. 개인정보의 제3자 제공
회사는 이용자의 개인정보를 제3자에게 제공하지 않습니다. 다만 다음의 경우는 예외로 합니다.
- 이용자가 사전에 동의한 경우
- 법령에 특별한 규정이 있거나, 수사기관이 법령에 정한 절차와 방법에 따라 요구하는 경우
5. 개인정보 처리의 위탁 및 국외 이전
회사는 서비스 운영을 위해 아래와 같이 개인정보 처리를 위탁하고 있으며, 일부는 국외에서 처리됩니다.
| 수탁자 | 위탁 업무 | 이전 항목 | 보관 국가 · 시점 · 방법 |
|---|---|---|---|
| The Constant Company, LLC (Vultr) | 서버 및 데이터베이스 호스팅 | 제2-1항의 모든 항목 | 대한민국(서울 리전) · 서비스 이용 시점 · 암호화된 네트워크 전송 |
| Resend, Inc. | 인증번호 및 안내 메일 발송 | 이메일 주소, 인증번호 | 미국 · 메일 발송 시점 · 암호화된 네트워크 전송 |
| Cloudflare, Inc. | 도메인 이름 서비스, 웹사이트 전송, 메일 수신 전달 | 접속 IP 주소(회사가 저장하지 않음), 문의 메일 내용 | 미국 등 글로벌 네트워크 · 접속 시점 · 암호화된 네트워크 전송 |
이용자는 국외 이전을 거부할 수 있습니다. 다만 이메일 발송을 거부하는 경우 이메일 인증이 필요한 로그인 수단(이메일 인증번호 로그인, 아이디/비밀번호 로그인의 2단계 인증, 회원가입)을 이용할 수 없으며, 소셜 로그인만 이용하실 수 있습니다.
5-1. 소셜 로그인 제공사
이용자가 소셜 로그인을 선택하면, 해당 제공사는 이용자의 요청에 따라 회사에 최소한의 정보(회원번호, 이메일, 이름)를 전달합니다. 이는 회사가 제3자에게 정보를 제공하는 것이 아니라 이용자의 선택으로 정보를 받는 것입니다. 제공사에서의 처리는 각사의 개인정보처리방침을 따릅니다.
- 구글 — Google LLC
- 카카오 — 주식회사 카카오
- 네이버 — 네이버 주식회사
- 마이크로소프트 — Microsoft Corporation
- 깃허브 — GitHub, Inc.
연결된 소셜 계정은 서비스 내 계정 설정에서 언제든지 해제할 수 있습니다.
5-2. AI 서비스 제공사
이용자가 자신의 API 키 또는 구독 계정을 등록해 AI 기능을 사용하는 경우, 이용자의 프로그램은 해당 AI 서비스 제공사와 직접 통신하며 회사 서버를 거치지 않습니다. 이때 이용자가 입력한 내용은 이용자와 해당 제공사 사이에서 처리되며, 그 처리에는 각사의 약관과 개인정보처리방침이 적용됩니다. 회사는 그 내용을 열람하거나 보관하지 않습니다.
유료 구독(준비 중)의 경우 — 회사가 제공하는 AI 사용량을 이용자가 쓰는 형태의 유료 요금제를 준비하고 있습니다. 이 경우 요청이 회사의 중계 서버를 거치게 되며, 회사는 요금 정산에 필요한 사용량(토큰 수와 금액)만 기록하고 요청과 응답의 내용은 저장하지 않습니다. 해당 서비스를 시작하기 전에 이 방침을 개정하고 사전에 공지하겠습니다.
6. 정보주체와 법정대리인의 권리 및 행사 방법
이용자는 언제든지 다음의 권리를 행사할 수 있습니다.
- 개인정보 열람 요구
- 오류가 있을 경우 정정 요구
- 삭제 요구 (회원 탈퇴)
- 처리 정지 요구
서비스 내 계정 설정 화면에서 직접 하시거나, privacy@monoprise.dev 로 요청하시면 10일 이내에 조치하고 결과를 알려드립니다. 법정대리인이나 위임을 받은 자를 통해서도 하실 수 있습니다.
회사는 권리 행사를 이유로 이용자에게 불이익을 주지 않습니다.
6-1. 만 14세 미만 아동
회사는 만 14세 미만 아동의 개인정보를 수집하지 않습니다. 만 14세 미만임이 확인되면 해당 계정과 정보를 지체 없이 삭제합니다.
6-2. 결제 정보
현재 유료 서비스를 제공하지 않으므로 결제 정보를 수집하지 않습니다. 향후 유료 서비스를 시작하는 경우에도 카드번호 등 결제수단 정보는 결제대행사가 직접 처리하며 회사는 보관하지 않습니다. 시작 전에 이 방침을 개정하고 사전에 공지하겠습니다.
7. 개인정보의 파기
보유 기간이 지나거나 처리 목적이 달성된 개인정보는 지체 없이 파기합니다.
- 절차 — 파기 사유가 발생한 개인정보를 선정하고, 개인정보 보호책임자의 확인을 거쳐 파기합니다.
- 방법 — 전자적 파일은 복구할 수 없는 방법으로 영구 삭제합니다. 데이터베이스에서 즉시 삭제되며, 백업본에서는 최대 14일 이내에 순차적으로 사라집니다. 종이 문서는 분쇄하거나 소각합니다.
8. 개인정보의 안전성 확보 조치
- 비밀번호 — 원문을 저장하지 않고 scrypt 해시 함수와 계정별 무작위 값(salt)으로 변환해 보관합니다. 회사도 원래 비밀번호를 알 수 없습니다.
- 세션 토큰 — 원문이 아닌 해시값만 저장합니다. 데이터베이스가 유출되더라도 그것만으로 로그인할 수 없습니다.
- 전송 구간 암호화 — 모든 통신에 HTTPS를 적용합니다.
- 접근 통제 — 서버는 방화벽으로 필요한 포트만 열어두고, 응용프로그램은 최소 권한 전용 계정으로 실행하며, 관리자 기능은 별도의 권한 확인을 거칩니다.
- 무차별 대입 차단 — 인증번호는 5회 실패 시 잠금 처리되고, 요청 횟수를 제한합니다.
- 기록 최소화 — 서버 기록에 개인정보와 인증 수단이 남지 않도록 자동으로 걸러냅니다.
- 백업 — 매일 자동 백업하며 14일이 지난 백업본은 자동 삭제합니다.
9. 자동 수집 장치의 설치·운영 및 거부
회사는 광고나 이용 행태 분석을 위한 쿠키·추적 도구를 사용하지 않습니다. 웹사이트는 이용자가 선택한 표시 언어를 기억하기 위해 브라우저의 로컬 저장소(localStorage)에 언어 코드 하나만 저장합니다. 이는 개인을 식별하지 않으며, 브라우저 설정에서 사이트 데이터를 삭제하면 함께 지워집니다.
데스크톱 프로그램은 로그인 상태를 유지하기 위해 세션 토큰을 기기에 저장합니다. 로그아웃하면 삭제됩니다.
웹사이트는 글꼴을 표시하기 위해 외부 콘텐츠 전송 네트워크(jsDelivr)를 불러오며, 이 과정에서 접속 IP 주소가 해당 사업자에게 전달될 수 있습니다.
10. 개인정보 보호책임자
회사는 개인정보 처리에 관한 업무를 총괄하고 이용자의 불만과 피해 구제를 담당하는 책임자를 다음과 같이 지정하고 있습니다.
| 개인정보 보호책임자 | 안수현 (대표자) |
|---|---|
| 연락처 | privacy@monoprise.dev |
| 상호 | 모노프라이즈 (Monoprise) |
| 주소 | 울산광역시 중구 함월14길 35, 902호 |
이용자는 서비스를 이용하며 발생한 개인정보 보호 관련 문의, 불만 처리, 피해 구제를 위 연락처로 문의하실 수 있습니다. 회사는 지체 없이 답변하고 처리하겠습니다.
11. 권익 침해에 대한 구제 방법
개인정보 침해로 인한 신고나 상담이 필요하신 경우 아래 기관에 문의하실 수 있습니다.
- 개인정보 침해신고센터 — (국번 없이) 118 · privacy.kisa.or.kr
- 개인정보 분쟁조정위원회 — 1833-6972 · www.kopico.go.kr
- 대검찰청 사이버수사과 — (국번 없이) 1301 · www.spo.go.kr
- 경찰청 사이버수사국 — (국번 없이) 182 · ecrm.police.go.kr
「개인정보 보호법」 제35조(열람), 제36조(정정·삭제), 제37조(처리정지)에 따른 요구에 대한 회사의 조치에 불복이 있으신 경우, 행정심판법이 정하는 바에 따라 행정심판을 청구하실 수 있습니다.
12. 개인정보처리방침의 변경
이 방침이 변경되는 경우 시행일 7일 전부터 웹사이트와 프로그램 안에 공지합니다. 다만 이용자의 권리에 중대한 영향을 미치는 변경은 30일 전에 공지하며, 필요한 경우 다시 동의를 받습니다.
시행일 2026년 8월 18일 · 버전 1.0 (최초 제정)
이 방침의 이전 판본이 필요하시면
privacy@monoprise.dev 로
요청해주세요.
함께 보기 — 이용약관
Privacy Policy
The short version
- Your conversations with the AI, your code and your files never reach our servers. They stay on your computer.
- Your AI API keys never reach our servers either. They live in your operating system's credential store, or only in memory.
- What our server keeps is account data only — your email address, your name, and how you sign in.
- We do not store IP addresses. They are used in memory to block brute-force attempts, then discarded.
- We run no advertising or analytics trackers.
1. Why we process personal data
- Accounts — identifying you, preventing duplicate accounts and abuse, sending you notices
- Service delivery — keeping you signed in across your devices
- Security — blocking brute-force attacks and detecting unusual access
- Support — answering questions you send us
2. What we process
2-1. Stored on our server
- Email address (required)
- A randomly generated account identifier (required)
- Name or nickname (optional)
- Password — stored as a scrypt hash, never in plain text. We cannot recover your password.
- For social sign-in: the member ID issued by that provider, and the email address they pass to us
- Session records — the hash of the session token, a device label, and creation, expiry and last-used timestamps
- Sign-up and last-seen timestamps
- Email verification codes and attempt counts (deleted after 10 minutes)
2-2. Never sent to our server
The following exist only on your device. We cannot access them.
- Your conversations with the AI, your prompts and its answers
- Your code, documents, other files, and their paths
- Your AI service API keys — held in your operating system's credential store in the desktop app, or in memory only in the chat app; never written to disk in plain text
- Screen captures and any record of computer control actions
2-3. Never collected
- IP addresses — used in memory during a request to rate-limit abuse, then discarded. They are not written to any database or log.
- National identification numbers
- Payment card details (see 6-2)
- Location, contacts, photos or other on-device personal data
- Advertising identifiers or behavioural profiles
3. How long we keep it
- Account data — until you close your account. We delete it without delay on request.
- Sessions — expire automatically 60 days after issue; deleted immediately when you sign out.
- Email codes — discarded after 10 minutes.
- Backups — taken daily, deleted automatically after 14 days. Deleted account data disappears from backups within 14 days at most.
4. Sharing with third parties
We do not share your personal data with third parties, except where you have agreed in advance, or where the law requires it and a lawful process is followed.
5. Processors and cross-border transfer
- The Constant Company, LLC (Vultr) — server and database hosting. All items in 2-1. Stored in the Republic of Korea (Seoul region).
- Resend, Inc. — delivering verification and notice emails. Email address and verification code. Processed in the United States.
- Cloudflare, Inc. — DNS, website delivery and inbound mail forwarding. Visitor IP addresses (which we do not store) and the contents of emails you send us. Processed on a global network including the United States.
You may refuse cross-border transfer. If you refuse email delivery, you cannot use sign-in methods that depend on it — email code sign-in, two-step verification for password sign-in, and account registration — and only social sign-in will remain available.
5-1. Social sign-in providers
When you choose social sign-in, that provider passes us a minimal set of data at your request: a member ID, an email address and a name. This is us receiving data at your direction, not us disclosing yours. Their own privacy policies govern what they do. Providers: Google LLC, Kakao Corp., NAVER Corp., Microsoft Corporation, GitHub, Inc. You can disconnect a linked account at any time in your account settings.
5-2. AI service providers
When you connect your own API key or subscription, the software on your computer talks to that AI provider directly and does not pass through our servers. What you send is handled between you and that provider under their terms and privacy policy. We neither read nor retain it.
Paid subscriptions (in preparation) — we are building a paid plan where you draw on AI capacity we supply. Those requests would pass through our relay, where we would record usage only — token counts and cost — and never the content of requests or responses. We will revise this policy and give notice before that launches.
6. Your rights
You may at any time ask to access, correct, delete your personal data or stop its processing. Use your account settings, or write to privacy@monoprise.dev. We will act and reply within 10 days. You may act through a legal representative or an authorised agent. Exercising these rights will never disadvantage you.
6-1. Children under 14
We do not collect personal data from children under 14. If we learn that an account belongs to one, we delete it without delay.
6-2. Payment data
We offer no paid service today and collect no payment data. When we do, card details will be handled directly by the payment processor and never stored by us. We will revise this policy and give notice beforehand.
7. Deletion
Once the retention period ends or the purpose is met, we destroy the data without delay. Electronic records are permanently erased by a method that prevents recovery — removed from the database immediately, and from backups within 14 days. Paper records are shredded or incinerated.
8. How we protect it
- Passwords — stored as scrypt hashes with a per-account random salt. We cannot recover the original.
- Session tokens — only the hash is stored. A database leak alone would not let anyone sign in.
- Transport — HTTPS everywhere.
- Access control — a firewall exposes only the ports we need, the application runs as a least-privilege dedicated account, and administrative functions require a separate permission check.
- Brute-force defence — verification codes lock after five failures, and requests are rate-limited.
- Minimal logging — personal data and credentials are filtered out of server logs automatically.
- Backups — daily, deleted automatically after 14 days.
9. Cookies and local storage
We use no advertising or analytics cookies or trackers. The website stores one language code in your browser's localStorage so it remembers your choice. It identifies no one and disappears when you clear site data. The desktop apps store a session token on your device to keep you signed in; signing out deletes it. The website loads fonts from an external content delivery network (jsDelivr), which may receive your IP address.
10. Data Protection Officer
- Officer — Ahn Soo-hyun (Representative)
- Contact — privacy@monoprise.dev
- Business — Monoprise
- Address — 902, 35 Hamwol 14-gil, Jung-gu, Ulsan, Republic of Korea
11. Remedies
You may bring a complaint to the Korea Internet & Security Agency Privacy Infringement Report Centre (118, privacy.kisa.or.kr), the Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr), or the police cyber bureau (182, ecrm.police.go.kr).
12. Changes
We will post any change on the website and inside the apps 7 days before it takes effect, or 30 days before if it materially affects your rights — in which case we will seek your consent again where required.
Effective 18 August 2026 · Version 1.0 (first issue)
For earlier versions, write to
privacy@monoprise.dev.
See also — Terms of Service