Privacy Policy
Last Updated: 2026-07-23
1. Personal Information Collected
1) Required Information
- Email address (may be required depending on the login method chosen by the User)
- Name and profile information
- Social login identifier (Google, Kakao, Line, etc.)
- Account authentication information
2) Optional Information
- Email address
- Collected optionally when using certain social login methods
- Profile image
- Stored as profile information when set directly by the User
- Uploaded files and RAG reference documents
- Chat attachments: processed as temporary input for generating AI responses and deleted immediately afterward
- RAG reference documents: retained on a per-account basis only where the User chooses to save them
- System prompt
- AI response style and preference information set by the User
- One-line bio (Personal Bio)
- Self-introduction information entered by the User for their profile
- Contact number (mobile) and shipping address
- Collected only when participating in an event or promotion; not collected otherwise
- Information collected when using the Contact Us feature
- Name, email address, and information contained in the inquiry
- Collected only for the purpose of receiving and responding to the inquiry, and may be collected even from a visitor who is not a member
※ Not providing optional information does not restrict use of the Service.
3) Automatically Collected Information
- Service usage records
- IP address, device information, browser information
- Cookies and analytics information
- AI tool usage records (tool type, number of calls, time of use)
- Subscription product information, payment status, refund history
- A friend's usage history of the User's AI tools
- Unsubscribe history for automation-task emails (unsubscribed email address, time of unsubscribe)
- Consent history for media upload requirements (whether consent was given, date and time of consent)
- Information processed when using the automation task feature
- The Company may process and store information within the scope necessary to perform automation tasks, such as the request content, email address, and schedule information.
- A minimum level of usage records may be generated to provide the Service and prevent misuse; the specific items and retention criteria may vary according to operational needs.
※ Details regarding the use of cookies and similar technologies may be provided through a separate Cookie Policy.
4) Information Processed Through Google Calendar Integration
Only where the User has expressly consented to Google Calendar integration, the Company processes the following information.
- Scope requested
- https://www.googleapis.com/auth/calendar.events.readonly (read-only)
- Items processed
- Calendar event titles (event titles)
- Event dates and times (event dates and times)
- Other event details required for analysis (other event details required for analysis)
- Lookback period: limited to events within the most recent three months (most recent three months)
- Method of processing
- At the time of integration, the above information is collected once and used immediately for analysis; after the analysis is complete, the original calendar event data is discarded and is not permanently stored on the Company's servers. Only the analysis output — the AI profile (system prompt) text — is stored in the User's account, and the User may edit or delete that output at any time.
- The Company does not create, modify, or delete Google Calendar events (VORA does not create, modify, or delete Google Calendar events.).
- The Company stores only the access token and refresh token issued under the OAuth 2.0 standard, in encrypted form, and does not, under any circumstances, collect the User's Google account password or other credentials.
- The User may revoke VORA's calendar access permission at any time from the Google account security page (https://myaccount.google.com/permissions); once permission is revoked, the token held by the Company immediately loses effect and can no longer be used to access the User's calendar data.
2. Purposes of Processing Personal Information
The Company processes personal information only for the following purposes.
The Company does not use files, images, documents, text, chat content, or AI-generated output uploaded by a User to train the Company's own AI models.
This Service may include automated processing of personal information for the purpose of providing AI-based features.
Such automated processing is limited to technical processing intended to perform Service functions, and decisions that materially affect a User's rights or legal status — such as account suspension, restriction of Service use, or termination of the contract — are not made solely through automated means.
1) Providing the Service and Performing the Contract
- Providing personalized AI features
- Generating RAG-based AI responses
- Providing automation features
- Account creation, authentication, and management
- Processing necessary to perform the contract, including payment, subscription, and refunds
- Creating external sharing links for chat content and AI-generated output
- Confirming and managing history of consent to media upload requirements (compliance with applicable law and payment service provider policy, prevention of fraudulent use)
- Receiving, handling, and responding to inquiries
※ The Company uses Retrieval-Augmented Generation (RAG) technology to generate AI responses. Data used for RAG is managed as belonging to the User's account, and is deleted upon the User's request or upon account deletion.
※ When a document is uploaded during use of the Service, if it contains general personal information, that information may be automatically removed or de-identified before being stored. To protect personal information, the Company may perform automated detection, removal, or de-identification of personal information in uploaded files. This process is carried out by the system without human intervention. Automated detection and processing of personal information may be incomplete due to technical limitations, and the Company does not guarantee the accuracy of the detection or processing results.
※ In the course of using this Service, the User must provide only their own personal information or personal information they are lawfully authorized to use.
※ All legal disputes and liability arising from a User providing or using another person's personal information (email address, contact information, account information, etc.) without that person's consent are attributable to the User, and the Company bears no responsibility for such matters.
※ Restrictions on the User's conduct, prohibited acts, and conditions of use of the Service in this connection are governed by the Terms of Service.
2) Service Operation Notices (No Consent Required)
The following items are notices essential to the operation of the Service rather than for marketing purposes, and may be provided without separate marketing consent.
- Notices regarding payment completion, failure, or refunds
- Security alerts and account-protection notices
- Notices of service outages, maintenance, or suspension
- Notice of changes to the Terms and policies
- Notices required to fulfill legal or administrative obligations
3) Service Improvement and Statistical Analysis (De-identified Processing)
- Analysis of Service usage patterns
- Monitoring feature usage and improving performance
- Error analysis and stability improvement
※ Such analysis is carried out in de-identified or aggregated form so that individuals cannot be identified, and is not used for marketing, advertising, or profiling directed at individual Users.
4) Billing Settlement and Management of AI Tool Use and Data Processing
The Company processes personal information for billing settlement, usage management, and ensuring the operational stability of the Service in connection with a User's use of subscribed AI tools.
A User's subscribed AI tools may be used by the User or by a friend previously authorized by the User, and in connection with this the Company may process the following information.
- The party using the AI tool (the User, or a friend authorized by the User)
- The time and amount of AI tool usage (number of calls, or slot-occupancy/task-execution history, etc.)
- Internal usage logs for calculating remaining usage and settling charges
In addition, where a User permits the use of Friend AI, RAG reference data belonging to that friend's account may be used in the process of generating AI responses. Even in this case, use of the RAG data is limited to the purpose of generating an AI response in response to the User's request, and is separated and managed on a per-account basis.
Such information is processed only within the scope necessary to perform the contract, and except for the scope of automated processing needed for providing the Service, maintaining security, responding to incidents, and fulfilling obligations under applicable law, the Company does not view or analyze the specific content of a User's AI conversations or AI-generated output. However, exceptional access within the minimum necessary scope may occur where: ① automated content filtering, moderation, and safety review is required; ② fact-finding is required in response to a User report or an automatically detected possible violation; or ③ a response is required to fulfill an obligation under applicable law or to comply with a lawful request from an investigative authority.
Where a User shares outside the Service a conversation in which a Friend AI participated, the Company may de-identify the participating AI's profile image and name within the shared view. Complete de-identification of personally identifiable information that may be included in the body of an AI response or in AI-generated output cannot be guaranteed due to technical limitations, and the User should review the conversation content directly before sharing.
5) Automatic AI Profile Suggestion Feature (Google Calendar Integration)
Where a User has consented to Google Calendar integration, the Company processes Google user data solely for the following single purpose.
- Automatically suggesting or improving a Personalized AI Profile (system prompt) for the User by analyzing the User's recent calendar activity
- Analyze the user's recent calendar activity for the professional-profile suggestion feature
- Generate or improve the user's personalized AI profile within VORA
- Provide user-requested personalization features
The Company does not use Google Calendar data for any of the following purposes beyond those stated above.
- Advertising or marketing targeting (advertising, marketing targeting)
- Credit evaluation (credit evaluation)
- Employment decisions (employment decisions)
- Surveillance (surveillance)
- Sale to third parties (sale to third parties)
In addition, the Company does not use data obtained from the Google Workspace API to train, retrain, or fine-tune generalized AI/ML models. This Service's processing of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
6) Operation of Events and Promotions
The Company processes personal information of event or promotion participants only for the following purposes.
- Verifying event participants
- Notifying winners
- Shipping prizes
※ The retention period for personal information related to events and promotions is governed by Article 4.
3. Provision of Personal Information to Third Parties and Entrustment of Processing
The Company uses the following external services in connection with personal information processing to provide the Service. The manner of processing and the legal character of the processing may differ depending on the role of each external service provider.
1) Payment Service Providers
The Company does not directly provide payment functionality; payments are processed by one of the following methods depending on the payment method and region. The method applied to each transaction is displayed on the payment screen.
- Paddle payments (independent data controller): Paddle.com Market Limited, as the Merchant of Record, directly collects and processes the personal information necessary for payment and handles payment, billing, tax processing, and refunds.
- Payment gateway (PG) payments (entrusted processing): the Company acts as the seller, and an electronic payment service provider (hereinafter "PG company") connected through PortOne (포트원), the PG integration platform used by the Company, handles payment processing on the Company's behalf. Card information and recurring-payment method information (billing key) are processed by the relevant PG company in accordance with its own terms and security standards.
The Company does not directly store or process a User's card information or payment method information, and receives and uses only the minimum payment-result information necessary for operating the Service, such as whether payment was completed, subscription status, and the payment identifier.
※ Once the PG company that the Company contracts with is determined, this Policy will be amended to reflect and disclose it in the status of entrusted vendors.
2) Overseas Transfer for Providing AI-Based Features
To provide AI-based features, the Company may transmit data entered by a User (text, files, images, etc.) to servers of AI model providers located overseas for processing.
- Recipient: OpenAI, Inc.
- Country of transfer: United States
- Items transferred: user input data (text, files, images), request information, session information
- Purpose of use: generating AI responses and providing Service functions
- Retention period: deleted immediately after processing is complete, or discarded after brief retention
In addition, the Company may use an AI API relay service to provide a variety of AI models.
- Recipient: OpenRouter
- Country of transfer: United States
- Items transferred: user input data (text, files, images), request information
- Purpose of use: calling various AI models and generating responses
- Retention period: deleted immediately after processing is complete, or discarded after brief retention
Where a User has consented to Google Calendar integration, calendar event information from the most recent three months may be transmitted to an AI model provider during the one-time analysis process performed to run the automatic AI profile suggestion feature. Such data is discarded immediately after analysis and, in accordance with the AI model provider's data use policy, is not used to train models (based on OpenAI's Enterprise/API data use policy).
3) Cloud and Infrastructure Service Providers (Entrusted Processing and Overseas Transfer)
The Company uses cloud infrastructure services to operate the Service and store data.
- Recipient: Render, Inc.
- Country of transfer: United States
- Entrusted task: server hosting, data storage, and infrastructure operation
- Items transferred: account information, Service usage data, uploaded data
- Retention period: for the duration of use of the Service, or the retention period required by applicable law
4) External API Service Providers (Entrusted Processing)
The Company uses a variety of external APIs to provide Service functions, and in this process a User's input data (text, files, images, etc.) may be transmitted to and processed by the relevant service provider.
The principal external service providers used are as follows.
- Google LLC (maps/place-search API)
- SlideSpeak (PPT generation API)
- ConvertAPI (document conversion API)
- PDFEndpoint (HTML-to-PDF conversion API)
Additional external API services may be used to provide certain other features.
5) Status of Entrustment of Personal Information Processing and Overseas Transfer
To provide the Service, the Company may entrust personal information processing tasks to external vendors or transfer personal information overseas as follows.
(1) Principal Entrusted Vendors
| Vendor | Entrusted Task | Country of Transfer | Contact |
|---|---|---|---|
| Paddle.com Market Ltd | Payment processing, subscription management, refund processing (MoR) | United Kingdom | privacy@paddle.com |
| OpenAI, Inc. | AI response generation and data processing | United States | privacy@openai.com |
| Render, Inc. | Server hosting, data storage, and infrastructure operation | United States | privacy@render.com |
| Google LLC | (1) Maps/place-search API processing (2) Retrieval of calendar events from the most recent three months via the Google Calendar API (calendar.events.readonly) — for the purpose of providing the automatic AI profile suggestion feature, processed on a one-time basis | United States | https://policies.google.com/privacy |
| OpenRouter | AI model API relay and request processing | United States | https://openrouter.ai/privacy |
| SlideSpeak | PPT generation API processing | United States | https://slidespeak.co |
| ConvertAPI | Document conversion API processing | United States | https://www.convertapi.com |
| PDFEndpoint | PDF conversion API processing | United States | https://pdfendpoint.com |
| Pilpost (필포스트) | Packaging and shipping of event prizes | Republic of Korea | pilpost@hanmail.net |
| PortOne (포트원) | Operation of the PG payment integration and management platform | Republic of Korea | cs@portone.io |
| Atlassian | Operation of the inquiry reception and handling system (Jira) | United States | privacy@atlassian.com |
※ Name, contact information, and shipping address are provided to Pilpost (필포스트) for the shipment of event prizes.
※ Name, email address, and inquiry content are stored with Atlassian for receiving and responding to inquiries.
(2) Other External Service Providers
| Vendor | Entrusted Task | Country of Transfer | Contact |
|---|---|---|---|
| SerpAPI, LLC | Web search API processing | United States | contact@serpapi.com |
| RapidAPI, Inc. | External API relay service | United States | support@rapidapi.com |
| browser-use | Web automation API processing | United States | https://browser-use.com |
| Replicate, Inc. | Image generation and processing API | United States | https://replicate.com |
| E2B (e2b.dev) | User code execution and data processing (sandbox environment) | United States | https://e2b.dev |
6) Notice of Changes to Sub-processors
The Company may change the external service providers or sub-processors to which it entrusts personal information processing tasks, and will give advance notice of any such change through a Service notice or an amendment to this Privacy Policy.
A User may object to such a change and, where there is a legitimate reason, may request that processing of their personal information be restricted or that they discontinue use of the Service.
The Company does not sell a User's personal information.
4. Retention and Use Period of Personal Information
- General AI conversation content
- Retained for up to 30 days and then automatically deleted
- Chat data that has been deleted (automatically or by the User) — whether automatically deleted (30 days after the last chat) or deleted directly by the User — is retained for an additional 30 days from the time of deletion.
- Purpose of retention: responding to requests to recover accidental deletion, responding to system failure or data loss, and preserving logs for legal disputes
- After that period elapses, the data is completely and irrecoverably destroyed.
- Bookmarked or saved conversations
- Retained until deleted by the User or until the account is withdrawn
- RAG reference documents (My Data)
- Retained on a per-account basis until deleted by the User or until the account is withdrawn
- Where a User has a paid storage subscription and, due to a downgrade, cancellation, payment failure, or similar event, the stored data exceeds the applicable limit: retained during a 7-day cleanup period, after which any excess data still not cleaned up is automatically deleted (destroyed), starting with the oldest uploaded data, until the data is within the limit; such deleted data cannot be recovered. Advance notice is given to the User before automatic deletion.
- Upon a request for account deletion
- Retained during a 30-day grace period from the date of the request, after which all active data is completely deleted
- If the User logs back in to the same account within the grace period, the account deletion request is automatically cancelled and all data is restored
- After 30 days elapse, the data is completely and irrecoverably destroyed
- Backup data
- Destroyed within a maximum of 30 days from the time active data is deleted
- Payment and accounting-related information
- Retained for up to 5 years in accordance with applicable law
- Media upload requirement consent records
- Retained until withdrawal of membership (account deletion confirmed)
- After withdrawal, retained separately for up to 3 years for the purpose of handling consumer complaints or disputes and demonstrating policy compliance, and then destroyed
- Automation task-related information
- Where a User registers an automation task to run repeatedly, the Company may retain related information for the period necessary to perform that task, and will destroy it without delay if the User deletes the automation task or withdraws their account (except that, where retention is required under applicable law, it is retained for the period specified by that law).
- Where minimum usage records are generated and retained for Service operation and security purposes, the Company retains them only for the minimum period necessary to achieve that purpose, and then destroys them.
- Files attached during chats and derived data
- Original files: not stored
- Even where AI response generation or file processing fails, the original attached file is automatically deleted and is not accumulated in temporary storage.
- Text-based derived data: retained only within the chat retention period
- Derived data: not used for personal identification or to restore the original file, and not used for any purpose beyond that stated
- Information related to violations of the Terms: where a possible violation of prohibited conduct is identified, related content, account information, generation-request records, and logs may be retained for the period necessary to confirm the violation, take disciplinary action, respond to disputes, and fulfill obligations under applicable law, and are destroyed without delay once that purpose is achieved.
- Waitlist registration email: upon completion of sign-up, integrated into the member's information; while not yet a member, retained until the operator deletes it from the admin console.
- Information processed via the Google Calendar API
- Original calendar event data (event titles, dates/times, other details): discarded immediately after the automatic AI profile suggestion analysis is complete. Not separately stored on the Company's servers.
- OAuth access token and refresh token: lose effect immediately once the User revokes access on the Google security page; if the User deletes their account or requests deletion of the token by writing to contact@vora.im, the token information held by the Company is also destroyed. While the integration remains active, it is retained in encrypted form to support the User's re-analysis requests (e.g., regenerating a profile).
- Analysis output (automatically suggested AI profile / system prompt): the User may edit or delete it directly, and upon account deletion it is handled in accordance with Article 4 of this Policy.
- Unsubscribe request email address
- Retained permanently, as an exception to the principle of destroying personal information, to fulfill the obligation to prevent re-sending
- Used only to block sending and not for any other purpose
- The blocking effect is maintained regardless of whether the User (recipient) deletes their account or withdraws
- Information of event/promotion participants (name, contact information, shipping address)
- Destroyed within 3 months after prize shipment is completed (except where retention is required under applicable law, in which case it is retained for that period)
- Records of inquiries and consultations (name, email address, inquiry content)
- Retained for 3 years as a record concerning the handling of consumer complaints or disputes, in accordance with applicable law, and then destroyed
4-1. Processing of Personal Information When Sharing Conversation Output Externally
A User may share, via a sharing link, AI conversation content and AI-generated output created within the Service with third parties outside the Service. In this case, the Company processes personal information as follows.
1) De-identification: within the shared view, the profile image and name of the AI that participated in the conversation may be displayed in de-identified form.
2) Limits of de-identification: complete automatic de-identification cannot be guaranteed, due to technical limitations, for personally identifiable information that may be contained in the body of an AI response or in AI-generated output. The User is responsible for directly reviewing the conversation content before sharing.
3) Validity period of the sharing link: a sharing link is valid for 1 day from the time it is created, and the shared content cannot be modified or edited.
4) Advance notice: before a User shares conversation output externally, the Company provides a process that notifies the User that the conversation content may contain another person's personal information and requests that the User confirm this.
5) User responsibility: all legal liability arising from a User sharing externally conversation content that contains another person's personal information, despite having confirmed the advance notice, is attributable to that User.
5. Personal Information Protection and Security Measures
- Encryption in transit and at rest (HTTPS / AES-256)
- Access control based on the principle of least privilege
- Regular security inspections and vulnerability analysis
- Notification in accordance with applicable law in the event of a personal information breach
- OAuth tokens issued by Google API Services are managed in encrypted form at rest (AES-256), and access to the tokens is limited to the minimum system components necessary to provide the automatic AI profile suggestion feature.
※ Except for the scope of automated processing necessary for providing the Service, maintaining security, responding to incidents, and fulfilling obligations under applicable law, the Company does not view a User's AI conversation content or message records. Conversation content is processed in an environment where administrator access is technically restricted, and is processed automatically only to provide the Service and to perform functions requested by the User. However, exceptional access within the minimum necessary scope may occur where: ① automated content filtering, moderation, and safety review is required; ② fact-finding is required in response to a User report or an automatically detected possible violation; or ③ a response is required to fulfill an obligation under applicable law or to comply with a lawful request from an investigative authority.
6. Rights of the User
The User may exercise the following rights at any time.
- Requesting access to personal information
- Requesting correction of personal information
- Requesting deletion of personal information
- Requesting restriction of processing of personal information
- Exercising the right to data portability
For information processed through the Google Calendar API, the User may exercise these rights by the following methods.
- Editing or deleting the automatically suggested AI persona (system prompt) from [Settings > My AI Profile]
- Directly revoking VORA's access permission from the Google account security page (https://myaccount.google.com/permissions)
- Once permission is revoked, the access/refresh tokens held by the Company immediately lose effect and can no longer be used to access the User's calendar data. If the User wishes to have the token information itself deleted, they may request this through item 3 below, and it will also be destroyed if the User deletes their account.
- contact@vora.im — request deletion by email (processed within 7 business days)
Because the original calendar event data is discarded immediately after analysis, it is not subject to a separate deletion request.
7. Data Controller Information
The data controller for this Service is as follows.
- Company name: Linkbricks Horizon-AI Inc.
- Representative: Yoonsung Ji
- Business registration number: 146-87-03100
- Address: 7, Yeonmujang 5(o)-gagil, Seongdong-gu, Seoul, Republic of Korea (Hyundai Terrace Tower W1005, Seongsu-dong 2(i)-ga)
- Contact: +82 (02) 571-0214
- Email: contact@vora.im
8. Data Protection Officer
The Company has designated a Data Protection Officer as follows to protect Users' personal information and to handle complaints related to personal information. A User may direct any inquiry, complaint, or request for remedy concerning personal information protection arising from use of the Company's Service to the Data Protection Officer, and the Company will respond and act on it without delay.
- Name: Sang-gyu Kim
- Title: Data Protection Officer
- Contact: +82 (02) 571-0214
- Email: contact@vora.im
9. Remedies for Infringement of Rights
A User may apply for dispute resolution or consultation with the following agencies to obtain a remedy for a personal information infringement.
- Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회): 1833-6972 (no area code) / www.kopico.go.kr
- Personal Information Infringement Report Center (개인정보침해 신고센터): 118 (no area code) / privacy.kisa.or.kr
- Supreme Prosecutors' Office Cyber Investigation Division (대검찰청 사이버수사과): 1301 (no area code) / www.spo.go.kr
- National Police Agency Cyber Investigation Bureau (경찰청 사이버수사대): 182 (no area code) / ecrm.cyber.go.kr
9-1. Compliance with the Google API Services User Data Policy
VORA's use and transfer of information received from Google API Services (including Google Calendar data) strictly complies with the Limited Use requirements of the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy). The Company does not process Google Calendar data as follows.
- It is not used for any purpose other than the feature that is disclosed to the User (automatic AI profile suggestion).
- It is not used to train, retrain, or fine-tune generalized AI/ML models.
- It is not used for advertising or marketing targeting purposes.
- It is not used for credit evaluation, employment decisions, or surveillance.
- It is not sold or transferred to third parties.
- The Company does not permanently store Google Calendar data on its servers, and processes it only through automated systems even during analysis, so there is, in principle, no pathway through which the Company's employees or contractors could directly view a User's Google Calendar data. However, exceptional human access may occur only in the following cases. - Where the User has given explicit prior consent - Where necessary for operationally essential purposes such as investigating a security breach or preventing fraud - Where necessary to fulfill an obligation under applicable law - Where limited to data that has been de-identified or aggregated so that individuals cannot be identified