Privacy Policy
Effective August 11, 2026
Article 1 (General Provisions)
BlackTiggle (the “Company”) complies with applicable law, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc., and through this Policy informs users of the purposes for which, and the manner in which, their personal information is processed.
Article 2 (Personal Information Collected and Methods of Collection)
(1) The following items are collected through third-party authentication (Google) upon membership registration.
1. Required: email address, third-party authentication identifier
2. Optional: name (display name), profile image URL
(2) The following items are processed upon payment for a Paid Service. Payment information such as card numbers is handled directly by the payment service provider and is not stored by the Company.
1. Payment identifiers (order number, subscription identifier), payment amount and currency, date and time of payment, type of payment method
2. The email address entered at the time of payment
(3) The following information is generated and collected automatically in the course of using the Service.
1. Access IP address, date and time of access, number of visits, time of first visit
2. First acquisition path (referrer; the advertising campaign identifiers utm_source, utm_medium, utm_campaign, utm_content and utm_term; the advertising click identifiers fbclid, gclid and ttclid)
3. Type of access device, operating system, browser, user agent string
4. Country, region and city (an approximate location based on the access IP address; precise location information is not collected)
5. Page paths viewed, learning language, session identifier
(4) The following information is stored in order to provide the learning features.
1. Identifiers of the words learned and review scheduling data
2. Daily learning volume (number of new words, quizzes and reviews) and cumulative experience points
3. Selected art style and selected learning language
(5) The following items are collected where the user submits them voluntarily.
1. The content and time of submission of 1:1 inquiries, feedback and error reports
Article 3 (Purposes of Processing Personal Information)
(1) Identification of members and maintenance of login sessions, and verification and provision of paid plans
(2) Payment processing, handling of refunds and withdrawals of subscription, and preservation of transaction records
(3) Storage of learning progress, review scheduling and learning statistics, and synchronization across devices
(4) Analysis of Service usage, analysis of acquisition paths and measurement of advertising performance
(5) Responding to inquiries, verifying errors and improving content quality
(6) Prevention of abuse, and detection of and response to attempts to circumvent access restrictions
Article 4 (Retention and Use Period of Personal Information)
(1) Member information: until withdrawal from membership. However, it is retained for 30 days after withdrawal for the prevention of abuse and is then destroyed.
(2) Retention under the Act on the Consumer Protection in Electronic Commerce, Etc.
1. Records concerning contracts or withdrawal of subscription: 5 years
2. Records concerning payment and the supply of goods and the like: 5 years
3. Records concerning consumer complaints or dispute handling: 3 years
4. Records concerning labeling and advertising: 6 months
(3) Access records under the Protection of Communications Secrets Act: 3 months
(4) Access analytics information: 12 months from the date of collection. However, first-visit information such as the acquisition path is retained until withdrawal from membership or until 24 months have elapsed, for the purpose of analyzing advertising performance.
(5) Learning records: destroyed without delay upon withdrawal from membership.
Article 5 (Provision of Personal Information to Third Parties)
The Company does not provide users’ personal information to third parties. This shall not apply, however, where there is a statutory basis for doing so or where an investigative authority so requests in accordance with lawful procedures.
Article 6 (Entrustment of the Processing of Personal Information and Transfer Abroad)
The Company entrusts the processing of personal information as set out below for the purpose of providing the Service, and some of the entrustees are located outside the Republic of Korea.
1. Vercel Inc. (United States) — web service hosting and log processing · Items transferred: access IP address, user agent, access records · Retention period: until termination of the entrustment agreement
2. Neon Inc. (United States) — database operation · Items transferred: all of the items stored under Article 2 · Retention period: until termination of the entrustment agreement
3. Polar Software Inc. (United States) — payment processing · Items transferred: email address, name, payment information · Retention period: the period prescribed by applicable law
4. Google LLC (United States) — account authentication and speech synthesis · Items transferred: authentication identifier, email address, the text to be synthesized · Retention period: until termination of the entrustment agreement
5. Meta Platforms, Inc. (United States) — measurement of advertising performance · Items transferred: hashed email address, event identifier, payment amount · Retention period: until termination of the entrustment agreement
6. OpenAI, L.L.C. (United States) — Latin speech synthesis · Items transferred: the text to be synthesized · Retention period: until termination of the entrustment agreement
7. FPT Smart Cloud (Vietnam) — Vietnamese (Southern) speech synthesis · Items transferred: the text to be synthesized · Retention period: until termination of the entrustment agreement
8. Cloudflare, Inc. (United States) — delivery of image and audio files · Items transferred: access IP address · Retention period: until termination of the entrustment agreement
Users may refuse the transfer abroad, in which case membership registration and use of the Paid Services may be restricted.
Article 7 (Cookies and Similar Technologies)
(1) The Company uses cookies and browser storage (localStorage, sessionStorage) in order to maintain login sessions, store learning settings, analyze usage and measure advertising performance.
(2) The principal items stored by the Company are as follows.
1. Login session cookie (essential) — maintaining the logged-in state
2. Advertising measurement cookie (Meta Pixel) — measurement of advertising performance
3. Storage of learning settings (voice gender, playback speed, art style, progress, learning streak)
(3) Users may refuse the storage of cookies through their browser settings, but in that case login and the use of some features will be restricted.
Article 8 (Rights of the Data Subject and How to Exercise Them)
(1) A user may at any time request access to, correction of, deletion of, or suspension of the processing of, the user’s personal information.
(2) The rights under paragraph (1) may be exercised through the 1:1 inquiry function within the Service, and the Company shall take the necessary measures without delay.
(3) Where a user requests withdrawal from membership, the Company shall destroy the personal information without delay, except for information whose retention is required by law under Article 4.
Article 9 (Destruction of Personal Information)
(1) Personal information whose retention period has elapsed or whose purpose of processing has been achieved is destroyed without delay.
(2) Information in the form of electronic files is deleted by a method that renders recovery and reproduction impossible, and printed materials are shredded or incinerated.
Article 10 (Measures to Ensure the Security of Personal Information)
(1) Encryption in transit (HTTPS applied throughout, HSTS applied)
(2) Application of the HttpOnly, Secure and SameSite attributes to session tokens and management of their expiry
(3) SHA-256 hashing of email addresses transmitted externally for the purpose of advertising measurement
(4) Access control over the administrator screens, limits on the number of login attempts and access notifications
(5) Minimization of database access privileges and management of access records
(6) Blocking of search engine indexing and application of no-cache headers (administrator screens)
Article 11 (Children Under 14 Years of Age)
The Company does not collect the personal information of children under 14 years of age without the consent of a legal representative. Where a child under 14 years of age uses the Service, the consent of a legal representative must be obtained, and where the Company confirms that information has been collected without such consent, it shall destroy that information without delay.
Article 12 (Privacy Officer and Remedies for Infringement of Rights)
(1) Privacy Officer: the operator of BlackTiggle · Contact: 1:1 inquiry within the Service
(2) Where a report or consultation regarding an infringement of personal information is required, users may contact the following bodies.
1. Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972)
2. Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 with no area code)
3. Cyber Investigation Division, Supreme Prosecutors’ Office (spo.go.kr, 1301 with no area code)
4. National Office of Investigation, Korean National Police Agency (ecrm.police.go.kr, 182 with no area code)
Article 13 (Amendment of This Policy)
This Policy applies from its effective date, and where its content is added to, deleted or amended in accordance with a change in the law or in the Service, notice shall be given from seven (7) days before the changes take effect. However, where there is a material change to the rights of users, notice shall be given from thirty (30) days before.