Privacy Policy
Devmeca (“Company”) provides AI chat, chatbot, document, image-editing and financial-analysis services through one SSO account. This Policy explains how personal data is handled.
- One account authenticates you across connected services.
- Prompts, chats, files and images may be sent to AI or cloud providers to perform requested functions.
- Financial outputs are informational only and are not investment advice or a guarantee.
1. Scope and controller
This Policy covers the Devmeca SSO and Company-operated connected services. A separately operated service may also publish supplemental terms.
Controller: Devmeca; privacy contact: devmecacompany@gmail.com. Legal entity name, representative, address, telephone and registration number must be completed with verified business details before publication.
2. Purposes
Account creation, identity and login management, token validation, connected-service access, fraud and abuse prevention.
Providing AI chat, chatbot operation, document storage/search/summarization, image generation/editing and market-data analysis requested by users.
Billing, support, dispute handling, security monitoring, diagnostics, quality and safety improvement, and legal compliance. Marketing messages require any consent mandated by law.
3. Data collected
Account data: email, hashed password, internal ID, profile/name, locale, provider, timestamps and session/authentication data.
Content: prompts, conversations, bot configurations, documents and metadata, images and edit instructions, watchlists, queries, analysis settings, outputs and feedback.
Technical data: IP, cookies, device/browser/OS, access time, usage, error and security logs. Payment processors may directly collect payment credentials.
Data comes from user input/uploads, support requests, OAuth providers, connected services and automated logging. Do not submit government IDs, credentials, health/biometric data or other unnecessary sensitive data.
4. AI processing
Content is processed to fulfill requests, provide history where enabled, detect abuse and resolve incidents. Necessary content and technical metadata may be transmitted to external model/API providers.
Where contract and product settings permit, the Company configures API inputs not to be used for general model training. Provider-specific terms may differ and service notices control. Private content will not be used for general Company model training without a lawful basis and any required separate consent.
AI output may be inaccurate, biased or infringe third-party rights. Human review is required for consequential use; output is not legal, medical, accounting or investment advice.
5. Retention
Account/profile: until account deletion. Authentication and security logs: normally one year. User projects and content: until user deletion or account deletion; residual backups may take up to 30 days to rotate out.
Support/dispute records: three years after closure. Transaction, payment and supply records: generally five years; consumer complaints: generally three years; advertising records: generally six months, where Korean e-commerce law applies.
Data may be isolated for longer where law, litigation hold, investigation, unpaid obligations or security incidents require it.
6. Sharing, processors and transfers
The Company does not sell personal data and does not disclose it without consent except as requested for a connection or permitted by law. Connected services may receive a one-time token, internal ID and minimal profile data.
Vendors may process hosting, storage, email, billing, support, security, analytics and AI/API workloads under contract. The live vendor/transfer register must state recipient, country, data, purpose, method and retention once vendors are finalized.
Cross-border processing may occur where OAuth, cloud, CDN, email, payment or AI providers operate abroad. Required notices, consent or other lawful transfer safeguards will be applied.
7. Deletion and security
Data is securely deleted or destroyed after its purpose or retention period ends. Legally retained data is segregated; backup copies are access-restricted until rotation.
Safeguards include least-privilege access, password hashing, encryption in transit, appropriate encryption at rest, logging, monitoring, malware and vulnerability controls, backups, training and incident response. No system can guarantee absolute security.
8. Your rights and children
Subject to applicable law, users may request access, portability, correction, deletion, restriction, withdrawal of consent and account closure through account settings or devmecacompany@gmail.com. Identity or authority may be verified.
The services are generally not directed to children under 14. Data collected without required guardian consent will be deleted or otherwise handled as law requires.
9. Cookies and automated decisions
Cookies support sessions, security, preferences and statistics. Blocking essential cookies may prevent SSO from working.
Automated tools may rank, recommend, classify or detect abuse. If a solely automated decision produces legal or similarly significant effects, required information and rights to explanation, objection or human intervention will be provided.
10. Contact, changes and language
Privacy officer: Kihyun Kim; devmecacompany@gmail.com. Add a verified telephone number and department before publication.
Material changes are normally announced 7 days in advance, or 30 days for materially adverse changes. To the extent permitted by law, the Korean version controls in case of conflict. Effective October 5, 2026.