Privacy Policy

Article 1 (Personal Information Collected)

[Collected upon Registration and Service Use] ① Required: Email address, date of birth, social login identifier (Google ID or Apple ID) ② Optional: Profile name, profile picture [Automatically Collected During Service Use] ③ Device information: Device type, operating system, app version ④ Access information: IP address, access date/time, service usage records ⑤ App usage data: Feature usage count, session duration, error logs [Payment-Related Information (for Paid Services)] ⑥ Payments are processed through Google Play / Apple App Store, and the Company does not directly collect sensitive payment information such as card numbers. ⑦ Subscription status, purchase history, receipt information

Article 2 (Purpose of Collection and Use of Personal Information)

① Service provision and account management: Member identification, granting access to the service, customer support ② Service improvement and development: Usage pattern analysis, bug fixes, development of new features ③ Compliance with legal obligations: Record-keeping and legal dispute response as required by applicable law ④ Marketing and promotion: Informing users of new features, events, etc., only where consent has been obtained ⑤ Safety and security: Fraud detection, account protection, maintaining service integrity

Article 3 (Retention and Use Period of Personal Information)

① Account information: Until account deletion, except where separate retention is required under applicable law ② Service usage records: 3 years from the date of collection ③ Payment records: 5 years, as required by applicable law ④ Customer inquiry records: 3 years after resolution ⑤ Retention under legal obligations: For the period required by applicable laws such as the Act on Consumer Protection in Electronic Commerce and the Protection of Communications Secrets Act

Article 4 (Provision of Personal Information to Third Parties)

The Company does not, in principle, provide users' personal information to external parties. However, the following are exceptions: ① Where the user has given prior consent ② Where required by law or upon a lawful request from an investigative authority ③ Where deemed necessary for the life, body, or property interests of the user or a third party

Article 5 (Outsourcing of Personal Information Processing)

The Company outsources the processing of personal information as follows to provide the service: ① Cloud infrastructure provider: Amazon Web Services (AWS) — server operation and data storage ② Analytics service: Analysis of anonymized usage statistics (processed so that individuals cannot be identified) ③ Payment processing: Apple App Store ④ Customer support tool: Email-based support system Outsourced parties comply with applicable personal information laws, and the Company supervises their compliance.

Article 6 (International Data Transfer)

The Company's servers may be located in various countries/regions, and users' personal information may be transferred to such countries. ① EU/EEA users: Appropriate safeguards under Article 46 of the GDPR (such as Standard Contractual Clauses) are applied. ② Users in the Republic of Korea: The Company complies with the applicable procedures under the Personal Information Protection Act. ③ Users in other regions: The Company complies with the relevant personal information protection laws of the applicable country.

Article 7 (User Rights)

[Rights Common to All Users] ① Right to access: Confirm whether and how your personal information is being processed ② Right to rectification: Request correction of inaccurate personal information ③ Right to deletion: Request deletion of personal information upon termination of service use (except where retention is legally required) ④ Right to suspend processing: Request suspension of processing for a specific purpose [Additional Rights for EU/EEA Users (GDPR)] ⑤ Right to data portability: Receive your data in a structured format or request its transfer to another service ⑥ Right to object: Object to processing based on legitimate interest ⑦ Rights related to automated decision-making: Object to significant decisions made through automated processing (including profiling) ⑧ Right to lodge a complaint with a DPA: File a complaint with the personal data supervisory authority of any EU member state [Additional Rights for California Users (CCPA/CPRA)] ⑨ Right to opt out of the sale or sharing of personal information ("Do Not Sell or Share My Personal Information") ⑩ Right to limit the use of sensitive personal information ⑪ Right to non-discrimination for exercising privacy rights To exercise these rights, please contact us at support@fanesis.app. The Company will process such requests within 30 days of receipt (per GDPR standards).

Article 8 (Protection of Children's Personal Information)

① The service is not directed at children under the age of 14 in the Republic of Korea, under 13 in the United States (COPPA), or under 16 in the EU. ② During registration, date of birth is collected to verify age, and where the user is below the applicable age, separate consent from a legal guardian is obtained. ③ If the Company becomes aware that a child's personal information has been collected without proper consent, it will take immediate steps to delete such information.

Article 9 (Measures to Ensure the Security of Personal Information)

In accordance with the Personal Information Protection Act and other applicable laws, the Company implements the following technical and administrative safeguards to protect users' personal information — in particular, information that may be sensitive, such as login identifiers and dates of birth. ① Encryption in Transit: Users' personal information is transmitted using encryption protocols such as TLS/SSL during service use, preventing interception or tampering during transmission. ② Encryption at Rest: Key personal information such as email addresses and dates of birth is encrypted when stored in the database. Sensitive payment information (such as card numbers) is handled by Google Play/Apple App Store and is not stored on the Company's servers. ③ Access Control Management: Access to personal information processing systems is granted only to the minimum number of personnel necessary to perform their duties, and records of granting, changing, and revoking access are maintained. ④ Access Control Devices: Firewalls and intrusion detection systems are installed and operated to control unauthorized external access, and access to servers is restricted through AWS cloud infrastructure security settings (VPCs, security groups, etc.). ⑤ Retention of Access Logs and Prevention of Tampering: Access records to personal information processing systems are retained for at least one year and are securely stored to prevent forgery, alteration, theft, or loss. ⑥ Technical Measures Against Hacking: Security software such as antivirus programs is installed and regularly updated, and security vulnerability checks and system updates are performed to prevent personal information breaches. ⑦ Minimization and Training of Personnel Handling Personal Information: The number of personnel handling personal information is kept to a minimum, and such personnel receive training on their obligations and the Company's handling policies regarding personal information protection. ⑧ Establishment and Implementation of an Internal Management Plan: The Company establishes and implements an internal management plan for the safe handling of personal information and periodically reviews its implementation.

Article 10 (Cookies and Tracking Technologies)

① The service may use local storage, cookies, and similar technologies to provide app functionality and analyze usage. ② Users may restrict the use of such technologies through their device settings; however, some features may be limited as a result. ③ Data collected for analytics purposes is anonymized where possible.

Article 11 (Data Protection Officer)

① Company name: FASTRACTIVE ② Service name: FANESIS ③ Privacy inquiries: support@fanesis.app ④ Response time: Within 3 business days

Article 12 (Notice of Policy Changes)

This Privacy Policy may be amended in accordance with changes to applicable laws or the service. Material changes will be announced through in-service notices or email at least 7 days in advance.