Privacy Policy
Effective date: 2026-05-15
Teolemma (the "Company") processes personal information in accordance with the Personal Information Protection Act and related laws to protect the freedom and rights of data subjects. This Policy explains which personal information items are processed and how.
Article 1 (Personal Information Collected)
The Company collects the following personal information:
- Required: email address, password (stored encrypted), registration date/time.
- When using Google OAuth: email, profile name, and profile picture provided by Google.
- Collected automatically during use: access IP, browser information, cookies, access pass usage history, and problem -solving history.
- At domestic payment: payment completion information provided by the payment gateway (PG provider) — payment amount, payment method, transaction ID.
- At international payment: payment completion information provided by the reseller (merchant of record) — transaction ID, payment amount, payment currency.
* The Company does not directly collect or store detailed payment credentials such as credit card numbers or account numbers.
Article 2 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes:
- Member identification and confirmation of intent to register.
- Service provision (AI problem generation, access pass use, learning record management).
- Payment processing and settlement.
- Responding to customer inquiries and handling disputes.
- Fraud prevention and security.
- Fulfilling legal obligations.
Article 3 (Retention and Use Period)
- Member information is retained until the member withdraws and is destroyed immediately after withdrawal.
- However, the following information is retained for the periods specified by applicable laws:
- Records on contracts, withdrawal of subscription, and payment: 5 years (E-Commerce Act).
- Records on consumer complaints and dispute handling: 3 years (E-Commerce Act).
- Access logs: 3 months (Protection of Communications Secrets Act).
Article 4 (Provision of Personal Information to Third Parties)
As a rule, the Company does not provide members' personal information to external parties. The following are exceptions:
- When the member has consented in advance.
- When required by applicable laws.
- When provided overseas, within the scope disclosed in Article 5-2, in order to process an international payment.
Article 5 (Outsourcing of Personal Information Processing)
The Company outsources personal information processing tasks as follows to provide the Service smoothly:
| Processor | Outsourced task |
|---|---|
| Supabase Inc. | Member authentication, database hosting |
| Cloudflare, Inc. | Website hosting, CDN |
| Google LLC (Vertex AI) | AI problem generation (input not used for model training) |
| Korea PortOne Inc. (PortOne) | Payment processing and payment-result verification |
| KG Inicis, Kakao Pay | Card, mobile and easy-payment processing |
| Google LLC (Gmail SMTP) | Sending authentication and notification emails |
Article 5-2 (Overseas Transfer of Personal Information)
The Company transfers personal information overseas as follows in order to provide the Service and process payments. Items 1 through 4 are overseas storage under the outsourcing described in Article 5; items 5 and 6 are overseas provision for the processing of international payments.
| Recipient and contact | Country | Items transferred | Purpose and retention period |
|---|---|---|---|
| 1. Supabase, Inc. privacy@supabase.com | United States | Email address, password (encrypted), registration date/time, access pass usage history, problem-solving history, payment records | Member authentication and database hosting / until withdrawal of membership or termination of the outsourcing agreement (excluding the statutory retention periods in Article 3) |
| 2. Cloudflare, Inc. privacyquestions@cloudflare.com | United States | Access IP, browser information, cookies, service usage records | Website hosting, CDN and security / until termination of the outsourcing agreement |
| 3. Google LLC (Vertex AI) https://support.google.com/policies | United States | Learning records contained in problem-generation and diagnostic requests (no information identifying the member is included) | AI problem generation and learning diagnosis / until the request is processed (input is not used for model training on the paid tier) |
| 4. Google LLC (Gmail SMTP) https://support.google.com/policies | United States | Email address | Sending authentication and notification emails / until the email is sent |
| 5. Sold through Link, LLC (Lemon Squeezy) hello@lemonsqueezy.com | United States | Internal member identifier, product code of the access pass purchased | Processing international (USD) orders and returning the payment result / for the duration of the applicable statutory limitation period |
| 6. PayPal Pte. Ltd. https://www.paypal.com/kr/smarthelp/contact-us | Singapore | Order number, payment amount, payment currency | Authorisation and settlement of international (PayPal) payments / for the statutory retention period |
Timing and method of transfer: items 1 through 4 are transferred when the member uses the Service, and items 5 and 6 when the member proceeds with an international payment, in each case by transmission over an encrypted channel (HTTPS).
Seller for international payments: for item 5, Lemon Squeezy acts as the reseller (merchant of record) of the Company's products and is the counterparty to the sale contract with the buyer. The buyer's name, email address, billing address and payment credentials are collected directly by Lemon Squeezy on Lemon Squeezy's checkout, and the Company neither receives nor stores them. What the Company receives from Lemon Squeezy is the transaction ID, the payment amount, the payment currency and whether the payment completed.
How to refuse the transfer, and the effect of refusing: members may refuse the overseas transfer of their personal information. The transfers in items 1 through 4 are essential to providing the Service, so refusal can only be given effect by withdrawing membership, after which the Service cannot be used. The transfers in items 5 and 6 may be refused by not proceeding with an international payment; in that case the relevant payment method is unavailable, but the same access pass may be purchased using a domestic payment method. Refusal may be communicated through the customer support email (mathfolis.support@gmail.com).
Article 6 (Rights of Data Subjects)
Members may exercise the following rights at any time:
- Request to access personal information.
- Request to correct errors.
- Request to delete.
- Request to suspend processing.
These rights may be exercised through the customer support email (mathfolis.support@gmail.com), and the Company will act without delay.
Article 7 (Measures to Ensure Security)
- Passwords are stored with one-way encryption (bcrypt).
- Transmission is encrypted with HTTPS (TLS 1.3).
- Access control minimizes the number of personnel who handle personal information.
- Security reviews are conducted periodically.
Article 8 (Personal Information Protection Officer)
Protection officer: 성현모
Contact (phone): 070-8098-8749
Email: mathfolis.support@gmail.com
Addendum
This Policy takes effect on May 15, 2026.