Privacy Policy
Effective date: 2026-08-06
티로그(TLOG)(the "Company") complies with applicable laws such as the Personal Information Protection Act and establishes and discloses the following Privacy Policy to protect users' personal information.
1. Personal Information We Collect
The Company collects the following personal information to provide the Service.
① When linking a social account (Google or Kakao): email address, name (nickname), profile image.
② Information generated in the course of using the Service: trading journal records (symbol, quantity, price, fees, notes, strategy, emotion records, etc. — including direct entry and CSV/Excel file upload), account (wallet) information (account name, brokerage, currency, balance), attached chart images, records entered by the user such as checklists, tags, and goals, and Lounge posts (posts and comments, a copy of the nickname and profile image as of the time of posting, and performance-metric snapshots of attached records).
③ Information collected automatically after login (access logs): access IP address, access date and time, login/logout records, visited-page records, and browser information (User-Agent).
④ Automatic collection from non-logged-in visitors (cookies): anonymous visit paths and referrer records via a visitor identification cookie (tlog_vid).
⑤ Automatic collection through third-party analytics tools (cookies): to improve the Service, the Company uses Google Analytics 4 and Microsoft Clarity, and in this process interaction information such as device and browser information, page usage behavior, and mouse movements and clicks may be collected via cookies. Clarity operates only on public (non-logged-in) pages and does not collect data in sensitive areas after login, such as trade records.
⑥ For paid payments: a billing key for recurring payments (stored encrypted) and payment approval records (plan, number of additional accounts, amount, payment date and time). Payment method information itself, such as card numbers, is collected and processed directly by the payment gateway Toss Payments Corp. (domestic) or the Merchant of Record Polar Software Inc. (international), and the Company does not store it.
⑦ When integrating an exchange API (optional feature): the read-only API key and secret registered directly by the user (stored encrypted) and the execution records retrieved from that exchange. When the integration is disabled, the stored API key is destroyed without delay, and the trade records already imported are retained as User Data.
2. Purposes of Collecting and Using Personal Information
① Member identification and identity verification, and provision and operation of the Service.
② Storing and analyzing trade records and providing statistics.
③ Responding to customer inquiries and delivering announcements.
④ Improving the Service and preventing fraudulent use.
⑤ Processing payments and refunds for paid services and payment-related notifications (such as recurring-payment pre-notices).
⑥ Automatically retrieving execution records and creating trading journal entries through exchange API integration.
3. Retention and Use Period of Personal Information
① The Company destroys personal information such as trading journals when a user withdraws their membership. However, for 3 days after withdrawal, the data is retained as a grace period for data recovery, and once the grace period passes, it is permanently deleted through an automatic destruction task run once daily.
② Accounts that have not agreed to the service terms at sign-up or re-login are destroyed immediately without retaining their personal information.
③ Access logs (access IP and time, login/logout, visited pages) are retained for 1 year in accordance with the Standards for Measures to Ensure the Safety of Personal Information and then automatically deleted.
④ To prevent fraudulent reuse of free trials (repeated use by re-registering after membership withdrawal), the email address of an account that used a trial is retained even after membership withdrawal until that purpose is achieved.
⑤ Transaction records that applicable laws require to be preserved are retained for the following periods and then destroyed.
- Records on contracts or withdrawal of subscription, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce).
- Records on payment and the supply of goods, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce).
- Records on consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce).
4. Provision to Third Parties, Entrustment of Processing, and Overseas Transfer
① The Company does not provide personal information to third parties without the user's consent.
② For stable service provision, the Company entrusts the processing of personal information as follows.
- Authentication and data storage: Supabase Inc. (cloud infrastructure).
- Social login: Google LLC, Kakao Corp.
- Payment processing: Toss Payments Corp. (domestic payment gateway), Polar Software Inc. (international payments, Merchant of Record).
- Notification email dispatch: Resend, Inc. (billing pre-notices, expiry reminders, etc.).
- Visit analytics: Google LLC (Google Analytics), Microsoft Corporation (Microsoft Clarity).
③ Where the servers of the above entrustees are located overseas, personal information may be transferred overseas, and the current status is as follows.
Google LLC (United States)
Items transferred: Google account identifier, email, name, profile image
Purpose of transfer: Social login (Google OAuth) authentication
Method of transfer: Transmitted over the network at the time of login
Retention and use period: Until account withdrawalResend, Inc. (United States)
Items transferred: Email address, notification email content (plan, upcoming charge amount, upcoming payment date, etc.)
Purpose of transfer: Sending service notification emails such as billing pre-notices and expiry reminders
Method of transfer: Transmitted over the network at the time of email dispatch
Retention and use period: Until the purpose of dispatch is fulfilledPolar Software Inc. (United States)
Items transferred: Email address, subscription product and payment records (payment method details are collected and processed by Polar directly)
Purpose of transfer: Processing international payments and, as Merchant of Record, handling billing and tax settlement
Method of transfer: Transmitted over the network at the time of payment
Retention and use period: Until the end of the transaction record retention period required by law
5. Procedure and Method of Destroying Personal Information
Personal information whose retention period has elapsed or whose processing purpose has been achieved is destroyed without delay. Information in electronic file form is permanently deleted by a method that makes recovery impossible, and printed materials are shredded or incinerated.
6. Notes on Public Report Sharing and Lounge Posting
If a user directly creates a public sharing link for an analysis report, anyone who knows the link can view the contents included in the report (trade records, returns, etc.) without logging in. This is a disclosure made at the user's choice and does not constitute the Company providing personal information to third parties. The user may disable sharing at any time and should take care in forwarding and managing the sharing link.
When a user posts in the Lounge, the post, the nickname and profile image as of the time of posting, and performance-metric snapshots (returns, win rate, etc.) of attached records are visible to all logged-in users. Attaching an analysis report may convert that report to a public sharing link, and deleting the post disables any public status enabled by that posting. When a report about a post is received, the Company retains the report-handling records for review and action.
7. Rights and Obligations of Data Subjects and How to Exercise Them
As a data subject, the user may at any time request ① access to, ② correction of, ③ deletion of, and ④ suspension of the processing of their personal information under Articles 35 through 37 of the Personal Information Protection Act, and may request withdrawal of consent (membership withdrawal). The user may process these directly through the Settings menu or request them from the privacy officer below, and the Company will take action within 10 days of receiving the request and notify the user of the result. Rights may also be exercised through a legal representative or a duly authorized agent.
In addition, the user may refuse the collection of analytics cookies by blocking or deleting cookie storage in the browser settings, and may additionally refuse Google Analytics collection by installing a browser add-on (a Google Analytics opt-out program).
8. Measures to Ensure the Safety of Personal Information
To protect personal information, the Company implements technical and administrative safeguards required by applicable laws, such as access-privilege management and encryption of transmission channels. IP addresses in access logs, billing keys for recurring payments, and exchange API keys are stored encrypted (AES-256-GCM), and access logs of the personal information processing system are retained and reviewed for at least 1 year in accordance with the Standards for Measures to Ensure the Safety of Personal Information.
9. Privacy Officer
Name: 정철영
Contact: tlog@tlog.ai.kr
Users may direct personal-information inquiries arising during use of the Service to the officer above, and the Company will respond and handle them without delay.
10. Remedies for Infringement of Rights
Users may contact the agencies below for consultation on and dispute mediation of personal information infringement. The agencies below are separate from the Company and may be used if you are dissatisfied with the Company's own handling or need assistance.
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (no area code) / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Cybercrime Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) / www.spo.go.kr
- National Police Agency Cyber Investigation Bureau: 182 (no area code) / ecrm.police.go.kr
11. Changes to This Privacy Policy
This Policy applies from its effective date, and if its contents are added to, deleted, or modified due to changes in laws or policies, the Company will announce the changes before they take effect.