ABTO (the “Company”) publishes this Privacy Policy under Article 30 of the Personal Information Protection Act to protect personal information and promptly address related concerns.
This Policy applies to processing through abto.app, docs.abto.app, api.abto.app, their subdomains, the dashboard, and SDKs distributed by the Company.
Article 1. Information Collected and Collection Methods
The Company collects the minimum personal information needed to provide the Service:
| Category | Information | Collection method |
|---|---|---|
| Signup and login | Email address and password (stored encrypted). For Google signup: the account identifier, email address, and name supplied by Google | Dashboard signup screen and Google login |
| Email verification | Records of verification code delivery | Generated automatically at signup |
| Paid plans | Order number, payment-provider transaction number, payment amount and date, refund amount and date | Dashboard billing screen. Card details are entered in and processed by the payment provider’s payment window; the Company neither receives nor stores them |
| Quote inquiries | Email address; for detailed inquiries, name, company or team, and contact details | Quote inquiry form at abto.app |
| Customer inquiries | Email address, inquiry content, and information supplied during the inquiry | Email and phone |
| Automatically generated during service use | IP address, browser and device information, access time, request path, and error records | Server logs |
| Advertising measurement | Browser-generated visitor identifier, IP address, browser and device information, and advertising-related actions (homepage visits, quote submissions, and dashboard access after signup and login) | Meta Pixel on the abto.app homepage and dashboard signup screen |
The Company does not collect sensitive information or unique identification information such as resident registration numbers or health information.
Article 2. Processing Purposes
The Company uses collected information only for these purposes. If a purpose changes, it takes necessary steps, such as obtaining separate consent, under Article 18 of the Personal Information Protection Act.
- Member management: confirming signup intent and identity, new signup notifications, account security, preventing misuse, and delivering notices.
- Service provision: dashboard, gateway, event collection and analysis, and applying plans.
- Payments and settlement: paid-plan payments, payment failure notices, refunds, receipts, and payment disputes.
- Quote inquiries: sending detailed inquiry links, integration consultations, and contract information.
- Customer inquiries: receiving inquiries and explaining the outcome.
- Service improvement and stability: incident analysis, security incident response, and usage statistics.
- Advertising measurement: measuring whether advertising-driven visits lead to quote inquiries and signups and adjusting advertising.
Article 3. Retention Periods
- The Company processes and retains personal information for the period consented to at collection or required by law.
- Retention periods by category are:
| Information | Retention period |
|---|---|
| Member information | Until account deletion; legally required records are retained separately for the periods below |
| Payment records | Even after account deletion: five years for contract or withdrawal records and payment and supply records, and three years for consumer complaint or dispute records, under the Act on the Consumer Protection in Electronic Commerce, etc. |
| Quote inquiry information | Deleted without delay after the integration consultation ends or when the data subject requests deletion |
| Customer inquiry records | Three years after resolution |
| Access records (IP address and access time) | Three months under the Protection of Communications Secrets Act. Other server logs are automatically deleted within 14 days of creation |
| Email verification codes | Deleted immediately after verification or expiration |
- For members who have not logged in for at least one year, the Company may separately store or delete their information after giving 30 days’ email notice.
Article 4. Processing Customers’ End-User Data
- The Service is a tool customers (members) integrate into their own applications. For their applications’ end-user data, the customer is the controller and the Company is the processor acting on the customer’s instructions. End users may contact the application operator about their personal information; the Company assists on the customer’s request.
- The Company processes the following end-user data for customers:
| Source | Information processed | Details |
|---|---|---|
| Client SDK events | SDK-generated device identifier (random UUID), session identifier, event names and values, timestamps, and screen paths (with query strings and identifier-like segments removed) | Device identifiers are generated by the SDK, not advertising identifiers, phone numbers, or device hardware identifiers. Input field contents, on-screen text, and password and payment-related input are not collected by default; broader collection requires the customer to enable it explicitly |
| Customer-specified user identifiers | Values supplied through the SDK’s user identification function | Not collected unless supplied by the customer. The customer determines whether they are personal information and is responsible for the legal basis |
| Gateway LLM requests and responses | Request and response bodies, model and provider names, token counts, costs, latency, and error information | Bodies are stored for customers to view in the dashboard and automatically deleted after 30 days. Customers may turn off body storage in project settings; only metadata such as token counts and costs then remains |
- Requests sent through the gateway are forwarded to the customer’s selected model provider (OpenAI, Anthropic, or Google). This transfer follows the customer’s instructions, and each provider processes data under its own terms and privacy policy.
- The Company does not use end-user data for purposes other than providing the Service to the customer, sell it to third parties, or use it to train the Company’s AI models.
- On termination, the Company deletes end-user data without delay except information that must be retained by law.
Article 5. Disclosure to Third Parties
The Company processes personal information only within the purposes in Article 2 and does not disclose it to third parties without the data subject’s consent or a specific legal requirement. The Company currently has no third parties to which it regularly discloses data subjects’ personal information.
Article 6. Outsourced Processing
- The Company outsources processing as follows to provide the Service:
| Processor | Tasks | Storage location |
|---|---|---|
| Amazon Web Services, Inc. | Servers, databases, file storage, and email delivery (Amazon SES) | Republic of Korea (Seoul Region) |
| Cloudflare, Inc. | abto.app hosting, DNS, and traffic protection |
Data center nearest to the request |
| NICE Payments Co., Ltd. | Credit and debit card payments and refunds | Republic of Korea |
- Under Article 26 of the Personal Information Protection Act, outsourcing contracts specify restrictions on processing outside the assigned purpose, technical safeguards, subcontracting restrictions, processor supervision, and damages. The Company supervises safe processing.
- Changes to outsourced tasks or processors are disclosed through this Policy without delay.
Article 7. Overseas Transfers
The Company transfers personal information overseas as follows. Data subjects may refuse these transfers, but doing so may limit the relevant functions (signup, Google login, quote inquiries, and customer support).
| Recipient | Information transferred | Country, timing, and method | Purpose | Retention |
|---|---|---|---|---|
| Google LLC | Account identifier, email address, and name Google supplies during Google login | United States; transferred over the network at login | Identity verification | Under Google’s Privacy Policy |
| Discord Inc. | Quote inquiries: email address, name, company or team, and contact details. Signup: email address, signup method and time, and name for Google signup | United States; sent to the Company’s internal notification channel at inquiry or signup | Inquiry notifications, integration consultations, and new signup notifications | Quote information and signup information follow their respective periods in Article 3 |
| PostHog, Inc. | Browser-generated visitor identifier and usage behavior (page navigation and clicks) when visiting the abto.app homepage or dashboard |
United States; transferred over the network during visits | Usage statistics and improvement | Up to one year from collection |
| Contentsquare SAS | Browser-generated visitor identifier and usage behavior (scrolling, clicks, and navigation paths) on the abto.app homepage |
European Union and United States; transferred over the network during visits | Homepage usability analysis | Up to 13 months from collection |
| Meta Platforms, Inc. | Browser-generated visitor identifier, IP address, browser and device information, and advertising-related actions (homepage visits, quote submissions, and dashboard access after signup and login) on the abto.app homepage and dashboard signup screen |
United States; transferred over the network during visits and the relevant actions | Advertising measurement and campaign adjustment | Under Meta’s Privacy Policy |
Questions about overseas transfers may be directed to the privacy officer in Article 11.
Article 8. Deletion
- The Company deletes personal information without delay when the retention period ends, its purpose is fulfilled, or it is otherwise no longer needed.
- Information that must be retained by law is moved to a separate database or storage area and is used only for that retention purpose.
- Deletion methods:
- Electronic files are permanently deleted using methods that prevent recovery.
- Printed records are shredded or incinerated.
Article 9. Rights of Data Subjects and Legal Representatives
- Data subjects may request access, correction, deletion, suspension of processing, or withdrawal of consent at any time.
- Requests may be made by email or phone using the contact details in Article 11. The Company communicates its response within 10 days of receiving the request. Much of the member information can be viewed and updated directly in the dashboard.
- Rights may also be exercised through a legal representative or an authorized agent. A power of attorney using Form 11 attached to the Notice on Personal Information Processing Methods must be submitted in that case.
- Access and suspension requests may be restricted under Article 35, paragraph 4 and Article 37, paragraph 2 of the Personal Information Protection Act. Deletion cannot be requested for information another law requires to be collected.
- The Company verifies the identity or authority of the person making the request.
Article 10. Safeguards
The Company takes the following measures under Article 29 of the Personal Information Protection Act:
- Administrative: minimizing staff who handle personal information, establishing and implementing an internal management plan, and periodic checks.
- Technical:
- Passwords and email verification codes are stored using irreversible one-way encryption.
- API keys are stored as hashes, not raw values.
- Databases and file storage are encrypted at rest, and all communications use TLS.
- Databases are placed in isolated networks without direct external access; only service servers and approved operators can access them.
- Request bodies, headers, and user information are removed before error information is sent to error collection tools.
- Server logs are automatically deleted after their defined retention period.
- Physical: servers operate in data centers of cloud providers with international security certifications.
Article 11. Privacy Officer
The Company appoints the following privacy officer to oversee processing, address complaints, and provide remedies:
- Privacy officer: Donghyeok Kang (Representative)
- Email: contact@abto.app
- Phone: 070-4571-7854
- Address: Room 305, 201-17 Cheongpa-ro, Yongsan-gu, Seoul, Republic of Korea (Munbae-dong, G&P Yongsan Park)
Data subjects may contact the officer about privacy questions, complaints, or remedies arising from use of the Service. The Company responds and handles them without delay.
Article 12. Cookies and Automatic Collection
- The Company uses cookies and browser storage as follows:
- Dashboard login: authentication cookies maintain login state. They cannot be read by scripts and are deleted on logout.
- Display preferences: light or dark theme choices are stored in browser storage.
- Usage statistics: PostHog and Contentsquare store visitor identifiers in cookies or browser storage. The homepage does not create personally identifying profiles and respects the browser’s Do Not Track setting. The dashboard masks on-screen text during collection and does not record the screen.
- Advertising measurement: Meta Pixel stores identifiers in cookies or browser storage to connect advertising visits with conversions. It runs only on the
abto.apphomepage and dashboard signup screen, not the detailed quote inquiry form.
- Client SDKs distributed by the Company operate in customers’ applications and do not use cookies. The web SDK stores random device and session identifiers in browser storage; mobile SDKs use app-specific storage.
- Data subjects may block or delete cookies through browser settings. Advertising measurement can also be declined through browser or Meta account advertising settings without restricting service use. Blocking authentication cookies, however, prevents dashboard login from being maintained.
Article 13. Remedies for Privacy Violations
For reports or advice about privacy violations, data subjects may contact these agencies in the Republic of Korea:
- Personal Information Infringement Report Center: 118 (without an area code), privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division: 1301 (without an area code), www.spo.go.kr
- Korean National Police Agency, Cyber Investigation Bureau: 182 (without an area code), ecrm.police.go.kr
A person whose rights or interests are harmed by the Company’s action or inaction on requests under Articles 35 (access), 36 (correction or deletion), or 37 (suspension of processing) of the Personal Information Protection Act may seek administrative adjudication under the Administrative Appeals Act.
Article 14. Changes to This Policy
- This Policy takes effect on September 23, 2026.
- Additions, deletions, or changes due to laws, policies, or service changes are announced at
abto.app/privacy/from seven days before taking effect. Changes materially affecting data subject rights, such as collection categories or purposes, are announced 30 days in advance and also notified to members by email.