본문 바로가기
Narratip
  • 소개
  • 내려받기
  • 요금
  • 문의
EN ↓

English ↓

개인정보 처리방침

스파인페어리(이하 '회사'라 함)는 「개인정보 보호법」 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.

제1조(개인정보 처리방침의 적용 범위)

이 개인정보 처리방침은 회사가 제공하는 Game Dev Assistant(이하 'GDA')와 Narratip의 PC 프로그램, 모바일 앱 및 이와 관련된 제반 서비스(이하 '서비스')에 공통으로 적용됩니다. 서비스별로 다른 사항은 이 방침 안에 따로 표시합니다. GDA 계정과 Narratip 계정은 서로 별개이며, 각 서비스의 개인정보는 따로 처리됩니다.

제2조(개인정보 처리의 기본 원칙)

회사는 다음의 원칙을 준수하여 개인정보를 처리합니다.

  • 처리목적의 명확화와 최소한의 개인정보 수집
  • 목적 범위 내에서 적법하게 처리 및 목적 외 사용 금지
  • 개인정보의 정확성 확보 및 최신성 유지
  • 안전성 확보를 위한 기술적·관리적·물리적 조치
  • 정보주체의 권리 보장 및 개인정보 처리의 투명성 보장
  • 책임성 원칙에 따른 개인정보 보호 관리체계 구축

제3조(처리하는 개인정보의 항목, 목적 및 보유 기간)

회사는 서비스 제공을 위해 필요 최소한의 범위에서 개인정보를 처리합니다. 아래 항목은 「개인정보 보호법」 제15조 제1항 제4호(계약의 체결·이행)에 따라 처리합니다.

구분 처리하는 항목 처리 목적 보유·이용 기간
계정 생성·로그인 Apple 또는 Google 로그인으로 전달받는 이용자 식별값, 이메일 주소(Apple의 '이메일 가리기'를 쓰면 Apple이 만든 대체 주소), 로그인 수단의 종류, 가입 일시, 무료 체험 종료 일시 이용자 식별, 로그인, 이용 자격(무료 체험·이용권) 확인 계정 삭제 시까지
PC 연결 PC 프로그램이 만든 기기 식별값(무작위 값), 이용자가 정한 PC 이름, 연결 일시, 마지막 이용 자격 확인 일시 PC 프로그램의 이용 자격 확인, 이용 대수 관리, 모바일 앱과의 연결 연결 해제 또는 계정 삭제 시까지
모바일 앱 모바일 앱이 만든 기기 식별값(무작위 값), 단말기 종류(iOS·Android), 단말기 이름, 푸시 알림 토큰, 알림 수신 설정 푸시 알림 발송, 연결된 단말기 표시 단말기 등록 해제, 로그아웃 또는 계정 삭제 시까지
결제(정기결제) 구매한 스토어, 스토어가 부여한 거래 식별값, 이용권의 종류, 결제 상태, 이용 기간 만료 일시 이용권 부여, 결제 확인, 환불 처리 지원 결제 완료 시부터 5년(「전자상거래 등에서의 소비자보호에 관한 법률」)
이용권 코드 이용권 코드의 일방향 암호화 값, 이용권의 종류, 사용 일시 이용권 부여, 부정 사용 방지 계정 삭제 시까지(삭제 후 보관은 제5조)
고객 문의 이메일 주소, 문의 내용 문의 접수 및 답변 문의 처리 완료 후 3년(「전자상거래 등에서의 소비자보호에 관한 법률」)

서비스 이용 과정에서 다음 정보가 자동으로 생성·수집될 수 있습니다.

  • 접속 일시, IP 주소, 요청 기록: 서버의 안정적인 운영과 부정 이용 방지를 위하여 서버 접속 기록으로 남습니다. PC 연결을 시작할 때의 IP 주소는 일방향 암호화하여 호출 횟수 제한에만 쓰고 1시간 안에 삭제합니다.
  • 프로그램 버전, 운영체제 종류: PC 프로그램과 모바일 앱이 갱신(업데이트) 파일을 확인하고 내려받는 과정에서 전달됩니다.

PC를 연결하는 동안(최대 5분)에는 승인한 단말기의 이름과 일부를 가린 로그인 이메일 주소가 서버에 임시로 보관되어 PC 화면에 표시되며, 연결이 끝나거나 시간이 지나면 삭제됩니다.

정보주체의 동의를 받아 처리하는 개인정보 항목은 현재 없습니다.

제4조(회사가 수집하지 않는 정보)

서비스는 이용자의 작업을 이용자의 기기 안에서 처리하도록 만들어져 있으며, 회사는 다음 정보를 수집하지 않습니다.

  1. 작업물: 이용자가 서비스로 만들거나 입력한 글, 이미지, 소리, 코드, 프로젝트 파일은 이용자의 PC에 저장되며 회사의 서버로 전송되지 않습니다.
  2. 외부 AI 서비스와 주고받는 내용: 이용자가 외부 AI 서비스(AI 에이전트, 이미지·음성 생성 서비스 등)에 보내는 지시와 그 결과는 이용자의 PC에서 해당 외부 AI 서비스 제공자에게 직접 전달되며 회사의 서버를 거치지 않습니다(제8조).
  3. 외부 AI 서비스의 인증 정보: 이용자가 PC 프로그램에 입력한 API 키 등 인증 정보는 이용자의 PC에 운영체제의 보안 저장 기능으로 암호화되어 보관되며 회사에 전달되지 않습니다.
  4. 원격 기능으로 주고받는 내용: 모바일 앱의 원격 기능으로 주고받는 대화, 승인, 상태 등은 이용자의 PC와 단말기만 가진 키로 암호화되어 전달됩니다. 회사의 서버는 암호화된 내용을 중계할 뿐 그 내용을 알 수 없고 저장하지 않습니다. GDA의 원격 첨부 파일은 암호화된 상태로 서버에 임시 보관되었다가 PC가 받으면 삭제되며, 받지 않은 경우에도 24시간 안에 삭제됩니다. Narratip은 원격 첨부를 쓰지 않습니다.
  5. 푸시 알림의 내용: 푸시 알림에는 작업물이나 대화의 내용을 싣지 않습니다.
  6. 광고 식별자: 서비스는 광고를 싣지 않으며 광고 식별자(IDFA·AAID 등)를 수집하지 않습니다.

제5조(계정 삭제 후의 보관)

  1. 이용자가 계정을 삭제하면 회사는 계정 정보, 연결된 PC와 단말기의 정보를 지체 없이 삭제합니다.
  2. 다만 회사는 무료 체험의 중복 제공 등 부정 이용을 막고 삭제 처리를 안전하게 마치기 위하여 다음 정보를 계정을 삭제한 날부터 1년간 보관한 뒤 파기합니다(「개인정보 보호법」 제15조 제1항 제6호, 회사의 정당한 이익).
    • 로그인 수단의 식별값을 다시 알아볼 수 없도록 일방향 암호화한 값: 같은 로그인 수단으로 다시 가입했을 때 무료 체험을 다시 제공하지 않고, 남아 있는 정기결제·이용권을 새 계정에 다시 연결하는 데에만 씁니다. 이 값만으로는 이용자의 이메일 주소나 로그인 수단을 알아낼 수 없습니다.
    • 삭제한 계정의 내부 식별값: 삭제 처리 도중의 요청으로 계정이 다시 만들어지는 것을 막는 데에만 씁니다.
  3. 결제 기록(제3조의 '결제' 항목)은 관련 법령에 따라 5년간 보관하며, 계정을 삭제하면 계정과의 연결을 끊고 제2항의 일방향 암호화 값으로만 연결해 둡니다. 1년이 지나면 그 연결도 지웁니다.
  4. 관련 법령에 따라 보존하여야 하는 정보와 보존 기간은 다음과 같습니다.
    • 계약 또는 청약철회 등에 관한 기록, 대금결제 및 재화 등의 공급에 관한 기록: 5년(「전자상거래 등에서의 소비자보호에 관한 법률」)
    • 소비자의 불만 또는 분쟁처리에 관한 기록: 3년(같은 법)
    • 서비스 접속 기록: 3개월(「통신비밀보호법」)

제6조(개인정보의 제3자 제공)

회사는 이용자의 개인정보를 제3자에게 제공하지 않습니다. 다만 정보주체의 동의가 있거나 법률에 특별한 규정이 있는 등 「개인정보 보호법」 제17조 및 제18조에 해당하는 경우에는 예외로 합니다.

제7조(개인정보 처리의 위탁 및 국외 이전)

회사는 원활한 서비스 제공을 위하여 개인정보 처리 업무의 일부를 아래와 같이 외부에 위탁하고 있으며, 관련 법령에 따라 위탁계약 체결, 관리·감독 등 필요한 조치를 합니다. 일부 수탁자는 국외 사업자이므로 개인정보가 국외에서 처리될 수 있습니다.

수탁자(소재 국가) 위탁 업무 처리하는 항목 처리 위치·이전 방법 보유·이용 기간
Supabase, Inc.(미국) 계정 인증, 데이터베이스, PC와 단말기 사이의 암호화된 내용 중계, 암호화된 첨부 파일의 임시 보관(GDA) 제3조의 계정·PC 연결·모바일 앱·결제·이용권 코드 항목, 접속 기록 대한민국(서울) 리전의 서버에 저장. 서비스 이용 시 네트워크를 통해 전송 제3조·제5조의 기간
Cloudflare, Inc.(미국) PC 프로그램의 설치 파일·갱신 파일과 모바일 앱의 갱신 파일 배포 IP 주소, 프로그램 버전, 운영체제 종류 이용자와 가까운 지역의 서버. 내려받을 때 네트워크를 통해 전송 수탁자의 접속 기록 보관 기간
Apple Inc.(미국), Google LLC(미국) 푸시 알림 전달 푸시 알림 토큰 각 사업자의 서버. 알림을 보낼 때 네트워크를 통해 전송 알림 전달 시까지

Apple과 Google은 로그인 수단과 결제 수단을 제공하는 플랫폼사업자로서, 로그인과 결제 과정에서 각자의 개인정보 처리방침에 따라 이용자의 정보를 직접 처리합니다. 회사는 이용자의 결제 수단 정보(카드 번호 등)를 전달받지 않습니다.

이용자는 국외 이전을 원하지 않는 경우 서비스 이용을 중단하고 계정을 삭제할 수 있습니다. 다만 위 위탁은 서비스 제공에 꼭 필요하므로 이전을 거부하면 서비스를 이용할 수 없습니다.

제8조(외부 AI 서비스)

  1. 서비스의 주요 기능은 이용자가 직접 가입하거나 인증 정보를 입력한 외부 AI 서비스와 연동하여 동작합니다.
  2. 이용자가 외부 AI 서비스에 보내는 내용(작업물, 지시문 등)은 이용자의 PC에서 해당 제공자에게 직접 전달되며, 그 제공자의 약관과 개인정보 처리방침에 따라 처리됩니다. 회사는 이 과정에서 전달되는 내용을 수집하지 않으며, 외부 AI 서비스 제공자는 회사의 수탁자가 아닙니다.
  3. 이용자는 외부 AI 서비스에 개인정보나 민감한 내용을 보내기 전에 해당 제공자의 개인정보 처리방침을 확인하시기 바랍니다.

제9조(개인정보의 파기 절차 및 방법)

회사는 개인정보 보유기간의 경과, 처리목적 달성 등 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.

  1. 파기절차: 회사는 파기 사유가 발생한 개인정보를 선정하고, 회사의 개인정보 보호책임자의 승인을 받아 개인정보를 파기합니다.
  2. 파기방법: 전자적 파일 형태로 기록·저장된 개인정보는 기록을 재생할 수 없도록 파기하며, 종이 문서에 기록·저장된 개인정보는 분쇄기로 분쇄하거나 소각하여 파기합니다.

제10조(정보주체와 법정대리인의 권리·의무 및 행사방법)

  1. 정보주체는 회사에 대해 언제든지 개인정보 열람·정정·삭제·처리정지 요구 등의 권리를 행사할 수 있습니다.
  2. 이용자는 모바일 앱에서 연결된 PC와 단말기의 이름을 고치거나 연결을 해제할 수 있고, 모바일 앱의 설정에서 계정을 직접 삭제할 수 있습니다. 모바일 앱을 이용할 수 없는 경우에는 회사 웹사이트에 안내된 방법 또는 전자우편(cs@spinefairy.com)으로 계정 삭제를 요청할 수 있으며, 회사는 본인 확인 후 지체 없이 처리합니다.
  3. 제1항에 따른 권리 행사는 회사에 대해 「개인정보 보호법」 시행령 제41조 제1항에 따라 서면, 전자우편 등을 통하여 하실 수 있으며 회사는 이에 대해 지체 없이 조치하겠습니다.
  4. 제1항에 따른 권리 행사는 정보주체의 법정대리인이나 위임을 받은 자 등 대리인을 통하여 하실 수 있습니다. 이 경우 「개인정보 처리 방법에 관한 고시」 별지 제11호 서식에 따른 위임장을 제출하셔야 합니다.
  5. 계정을 삭제하더라도 플랫폼사업자를 통한 정기결제는 자동으로 해지되지 않으므로, 플랫폼사업자의 계정 설정에서 직접 해지하셔야 합니다.

제11조(개인정보의 안전성 확보 조치)

회사는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.

  1. 관리적 조치
    • 개인정보 처리 직원의 최소화 및 교육 실시
    • 개인정보 처리와 관련된 내부관리계획의 수립 및 시행
    • 정기적인 자체 점검 실시
  2. 기술적 조치
    • 개인정보에 대한 접근 통제 및 접근 권한의 제한
    • 전송 구간의 암호화, PC와 단말기 사이 원격 내용의 종단 간 암호화
    • 이용 자격 확인용 토큰, 이용권 코드 등은 원문이 아닌 일방향 암호화 값으로만 서버에 보관
    • 해킹이나 악성코드 등에 대비한 보안프로그램 설치 및 주기적 점검·갱신
    • 접속기록의 보관 및 위변조 방지 조치
  3. 물리적 조치
    • 개인정보가 포함된 서류, 보조저장매체 등을 안전하게 보관할 수 있는 잠금장치 마련

제12조(개인정보 보호책임자)

회사는 개인정보 처리에 관한 업무를 총괄해서 책임지고, 개인정보 처리와 관련한 정보주체의 불만처리 및 피해구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.

  • 성명: 장재혁
  • 직책: 대표
  • 연락처: support@spinefairy.com

정보주체께서는 회사의 서비스를 이용하시면서 발생한 모든 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 개인정보 보호책임자에게 문의하실 수 있습니다. 회사는 정보주체의 문의에 대해 지체 없이 답변 및 처리해드릴 것입니다.

기타 개인정보 침해에 대한 신고나 상담이 필요하신 경우에는 아래 기관에 문의하시기 바랍니다.

  • 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
  • 개인정보분쟁조정위원회: 1833-6972 (www.kopico.go.kr)
  • 대검찰청 사이버수사과: (국번없이) 1301 (www.spo.go.kr)
  • 경찰청 사이버수사국: (국번없이) 182 (ecrm.police.go.kr)

제13조(아동의 개인정보)

만 14세 미만의 아동은 법정대리인의 동의가 있어야 서비스를 이용할 수 있습니다. 회사는 만 14세 미만 아동의 개인정보를 법정대리인의 동의 없이 수집한 사실을 알게 된 경우 지체 없이 해당 정보를 삭제합니다.

제14조(개인정보 처리방침 변경)

  1. 이 개인정보 처리방침은 2026년 10월 1일부터 적용됩니다.
  2. 회사는 개인정보 처리방침을 변경하는 경우에는 변경 및 시행의 시기, 변경된 내용을 지속적으로 공개하며, 변경된 내용은 정보주체가 쉽게 확인할 수 있도록 변경 전·후를 비교하여 공개합니다.
  3. 이전의 개인정보 처리방침: 해당사항 없음(최초 제정)

Privacy Policy

Spinefairy (the "Company") establishes and publishes this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related complaints promptly.

Article 1 (Scope)

This Privacy Policy applies to the PC programs and mobile apps of Game Dev Assistant ("GDA") and Narratip and to all related services provided by the Company (the "Service"). Where the services differ, this Policy says so. GDA accounts and Narratip accounts are separate, and personal information is processed separately for each service.

Article 2 (Basic Principles)

The Company processes personal information in compliance with the following principles:

  • Making the purposes of processing clear and collecting only the minimum personal information needed
  • Processing lawfully within those purposes and not using information beyond them
  • Keeping personal information accurate and up to date
  • Taking technical, administrative, and physical measures to keep it secure
  • Protecting the rights of data subjects and being transparent about processing
  • Maintaining a personal information protection management system based on accountability

Article 3 (Items Processed, Purposes, and Retention Periods)

The Company processes personal information only to the minimum extent needed to provide the Service. The items below are processed under Article 15(1)4 of the Personal Information Protection Act (performance of a contract).

Category Items Purpose Retention period
Account creation and sign-in The user identifier received through Sign in with Apple or Google, email address (or the relay address created by Apple if you use Hide My Email), type of sign-in method, sign-up date, Free Trial end date Identifying users, sign-in, checking entitlement (Free Trial and Plans) Until the account is deleted
Linked PCs A device identifier generated by the PC program (a random value), the PC name you choose, the date linked, the date entitlement was last checked Checking the PC program's entitlement, managing the number of PCs, linking with the mobile app Until the PC is unlinked or the account is deleted
Mobile app A device identifier generated by the mobile app (a random value), device platform (iOS or Android), device name, push notification token, notification setting Sending push notifications, showing linked devices Until the device is unregistered, you sign out, or the account is deleted
Payments (subscriptions) The store used, the transaction identifier assigned by the store, Plan type, payment status, Plan expiry date Granting Plans, verifying payment, supporting refunds 5 years from completion of payment (Act on Consumer Protection in Electronic Commerce)
License Codes A one-way hash of the License Code, Plan type, date used Granting Plans, preventing misuse Until the account is deleted (see Article 5 for retention after deletion)
Customer inquiries Email address, content of the inquiry Receiving and answering inquiries 3 years after the inquiry is resolved (Act on Consumer Protection in Electronic Commerce)

The following information may be generated and collected automatically while you use the Service:

  • Access time, IP address, and request records: kept as server access records for stable operation and to prevent misuse. The IP address used when you start linking a PC is one-way hashed, used only for rate limiting, and deleted within 1 hour.
  • Program version and operating system type: sent when the PC program or the mobile app checks for and downloads updates.

While a PC is being linked (up to 5 minutes), the name of the approving device and a partially masked sign-in email address are held temporarily on the server so they can be shown on the PC screen. They are deleted when linking finishes or the time runs out.

The Company does not currently process any personal information on the basis of consent.

Article 4 (Information the Company Does Not Collect)

The Service is built so that your work is processed on your own devices. The Company does not collect the following:

  1. Works: The text, images, audio, code, and project files you create with or enter into the Service are stored on your PC and are not sent to the Company's servers.
  2. Content exchanged with Third-Party AI Services: The instructions you send to Third-Party AI Services (such as AI agents and image or audio generation services), and their output, go directly from your PC to the provider of that service and do not pass through the Company's servers (Article 8).
  3. Credentials for Third-Party AI Services: API keys and other credentials you enter in the PC program are stored on your PC, encrypted with the operating system's secure storage, and are not sent to the Company.
  4. Content exchanged through remote features: Chats, approvals, status, and other content exchanged through the mobile app's remote features are encrypted with a key held only by your PC and your mobile device. The Company's servers only relay the encrypted content; they cannot read it and do not store it. In GDA, files attached remotely are held on the server temporarily in encrypted form and deleted once your PC receives them, or within 24 hours if it does not. Narratip does not use remote attachments.
  5. Content of push notifications: Push notifications do not contain the content of your Works or conversations.
  6. Advertising identifiers: The Service carries no advertising and does not collect advertising identifiers (such as IDFA or AAID).

Article 5 (Retention After Account Deletion)

  1. When you delete your account, the Company deletes your account information and the information about your linked PCs and mobile devices without delay.
  2. However, to prevent misuse such as repeated Free Trials and to complete deletion safely, the Company keeps the following information for 1 year from the date the account is deleted and then destroys it (Article 15(1)6 of the Personal Information Protection Act, legitimate interests of the Company):
    • A one-way hash of your sign-in identifier, processed so that it can no longer identify you: used only to withhold a second Free Trial if you sign up again with the same sign-in method, and to reconnect any remaining subscription or Plan to the new account. Your email address and sign-in method cannot be recovered from this value.
    • The internal identifier of the deleted account: used only to prevent the account from being re-created by a request made while deletion is in progress.
  3. Payment records (the "Payments" category in Article 3) are kept for 5 years as required by law. When you delete your account, they are disconnected from the account and linked only through the one-way hash described in Paragraph 2. That link is also removed after 1 year.
  4. Information that must be kept under applicable laws, and the retention periods, are as follows:
    • Records on contracts or withdrawal of offers, and records on payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
    • Records on consumer complaints or dispute resolution: 3 years (same Act)
    • Service access records: 3 months (Protection of Communications Secrets Act)

Article 6 (Provision to Third Parties)

The Company does not provide users' personal information to third parties, except where the data subject has consented, where a law specifically provides for it, or in other cases falling under Articles 17 and 18 of the Personal Information Protection Act.

Article 7 (Outsourcing of Processing and Overseas Transfer)

To provide the Service, the Company outsources part of its personal information processing as shown below, and takes the measures required by applicable laws, such as entering into outsourcing agreements and supervising the processors. Some processors are overseas companies, so personal information may be processed outside the Republic of Korea.

Processor (country) Outsourced work Items processed Location and method of transfer Retention period
Supabase, Inc. (United States) Account authentication, database, relaying encrypted content between PCs and mobile devices, temporary storage of encrypted attachments (GDA) The account, linked PC, mobile app, payment, and License Code items in Article 3; access records Stored on servers in the Republic of Korea (Seoul) region. Transmitted over the network when you use the Service The periods in Articles 3 and 5
Cloudflare, Inc. (United States) Distribution of the PC program's installers and update files and the mobile app's update files IP address, program version, operating system type Servers in a region near the user. Transmitted over the network on download The processor's access record retention period
Apple Inc. (United States), Google LLC (United States) Delivery of push notifications Push notification token Each operator's servers. Transmitted over the network when a notification is sent Until the notification is delivered

Apple and Google are Platform Operators that provide the sign-in and payment methods. During sign-in and payment, they process your information directly under their own privacy policies. The Company does not receive your payment method details, such as card numbers.

If you do not want your information transferred overseas, you may stop using the Service and delete your account. Because the outsourcing above is essential to providing the Service, the Service cannot be used if you refuse the transfer.

Article 8 (Third-Party AI Services)

  1. The main features of the Service work together with Third-Party AI Services that you sign up for, or enter credentials for, yourself.
  2. Content you send to a Third-Party AI Service (such as Works and instructions) goes directly from your PC to that provider and is handled under that provider's terms and privacy policy. The Company does not collect the content sent in this process, and providers of Third-Party AI Services are not processors of the Company.
  3. Please review the provider's privacy policy before sending personal or sensitive content to a Third-Party AI Service.

Article 9 (Destruction of Personal Information)

The Company destroys personal information without delay when it is no longer needed, such as when the retention period ends or the purpose of processing has been achieved.

  1. Procedure: The Company selects the personal information to be destroyed and destroys it with the approval of the Company's personal information protection officer.
  2. Method: Personal information stored as electronic files is destroyed so that it cannot be restored. Personal information on paper is shredded or incinerated.

Article 10 (Rights of Data Subjects and Legal Representatives)

  1. Data subjects may at any time exercise rights against the Company such as requesting access to, correction of, deletion of, or suspension of processing of their personal information.
  2. In the mobile app, you can rename or unlink your linked PCs and mobile devices, and you can delete your account yourself in the app's settings. If you cannot use the mobile app, you can request account deletion by the method described on the Company website or by email (cs@spinefairy.com). The Company will process the request without delay after verifying your identity.
  3. Requests under Paragraph 1 may be made to the Company in writing, by email, or by similar means under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on them without delay.
  4. Rights under Paragraph 1 may be exercised through a legal representative or an authorized agent. In that case, a power of attorney in the form of Appendix No. 11 of the Public Notice on Personal Information Processing Methods must be submitted.
  5. Deleting your account does not automatically cancel a subscription made through a Platform Operator. Please cancel it in your Platform Operator account settings.

Article 11 (Security Measures)

The Company takes the following measures to keep personal information secure:

  1. Administrative measures
    • Keeping the number of staff who handle personal information to a minimum and training them
    • Establishing and carrying out an internal management plan for personal information processing
    • Conducting regular self-inspections
  2. Technical measures
    • Controlling access to personal information and limiting access rights
    • Encrypting data in transit, and end-to-end encrypting remote content between PCs and mobile devices
    • Storing entitlement tokens, License Codes, and similar values on the server only as one-way hashes, never in their original form
    • Installing security programs against hacking and malware and checking and updating them regularly
    • Keeping access records and protecting them from tampering
  3. Physical measures
    • Using locks to securely store documents and storage media containing personal information

Article 12 (Personal Information Protection Officer)

The Company has appointed the following personal information protection officer to oversee personal information processing and to handle complaints and remedies for data subjects:

  • Name: Jae-hyeok Jang
  • Title: CEO
  • Contact: support@spinefairy.com

You may contact the officer about any inquiry, complaint, or request for remedy relating to personal information that arises while you use the Service. The Company will respond and act without delay.

If you need to report or seek advice about an infringement of personal information, please contact the following organizations in the Republic of Korea:

  • Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Supreme Prosecutors' Office, Cyber Investigation Division: 1301 (www.spo.go.kr)
  • Korean National Police Agency, Cyber Investigation Bureau: 182 (ecrm.police.go.kr)

Article 13 (Children's Personal Information)

Children under the age of 14 may use the Service only with the consent of a legal representative. If the Company learns that it has collected the personal information of a child under 14 without such consent, it will delete that information without delay.

Article 14 (Changes to This Privacy Policy)

  1. This Privacy Policy takes effect on October 1, 2026.
  2. If the Company changes this Privacy Policy, it will keep the timing and content of the change publicly available and will publish a comparison of the previous and updated versions so that data subjects can easily review the changes.
  3. Previous versions of this Privacy Policy: none (first enactment).

NarratipWriter Assistant

궁금한 점은 메일로 보내 주세요.

cs@spinefairy.com ↗
  • 내려받기
  • 서비스 이용약관
  • 개인정보 처리방침
  • 계정 삭제 안내
  • English ↓

상호 Spinefairy · 대표 장재혁 · 사업자등록번호 683-10-02215 · 통신판매업 신고번호 제2023-성남분당A-1145호 · 경기도 성남시 분당구 대왕판교로 645번길 12, 6층

© 2026 Spinefairy