Privacy Policy
The operator of the Service (hereinafter referred to as the "Operator") establishes the following Privacy Policy (hereinafter referred to as the "Policy") regarding the handling of Users' personal information in the services provided on this website and the related API and MCP (Model Context Protocol) server (hereinafter collectively referred to as the "Service").
Article 1 (Personal Information)
"Personal information" refers to information about a living individual that can identify a specific individual, such as a name, email address, or other description contained in the information, as defined under the Act on the Protection of Personal Information.
Article 2 (Information We Collect)
The Service collects the following information.
- Account information: the email address provided at registration, and identifiers obtained through the authentication provider.
- Content information: information Users create and store in the Service, such as memo titles, bodies, and categories; notes; project documents; goals; skill sheet content (self-introduction, FAQ, project history, etc.); and knowledge candidates pending the User's review before being saved. This content is treated as private and visible only to the User by default, and is disclosed to third parties only for the specific items the User explicitly marks as public.
- Payment information: billing email address, credit card information, etc., when a User subscribes to a paid plan. Card numbers are not stored on the Operator's servers and are processed directly by the payment processor.
- Usage information: IP address, cookies, pages viewed, timestamps of use, and usage environment.
Article 3 (Purposes of Collecting and Using Personal Information)
The purposes for which the Operator collects and uses personal information are as follows.
- To provide and operate the Service (including storing, displaying, and searching content)
- To generate embedding vectors from the text of saved memos, notes, and project documents in order to provide similarity search and related-item suggestions (see Article 4)
- To allow a third-party AI client that a User has explicitly authorized to call the Service's API/MCP tools on that User's behalf (see Article 5)
- To respond to inquiries from Users (including performing identity verification)
- To contact Users as necessary, such as for maintenance and important notices
- To identify Users who violate the Terms of Service or who attempt to use the Service for improper or unjust purposes, and to refuse their use
- To allow Users to view, change, or delete their own registered information and view their usage status
- To bill Users for usage fees in paid plans
- To analyze usage of the Service and improve its quality
- Purposes incidental to the above
Article 4 (External Transfers and Disclosure to Third Parties)
The Operator does not disclose personal information to third parties without the User's prior consent. However, the following processors receive the information necessary for the purposes set out in this Policy.
- Google LLC (Gemini API): the text of saved memos, notes, and project documents is sent to generate embedding vectors used for similarity search. The resulting vectors are stored within the Service as a search index. Google's handling of the transmitted content is governed by Google's Privacy Policy.
- Google LLC (Google Analytics): used to understand usage of the Service and improve its quality. Google Analytics provides functionality to analyze page views, time on page, users by environment and region, and referral sources. Information such as identifiers recorded via cookies, IP address, and the URL of pages viewed is transmitted. For details, see How Google uses information from sites or apps that use Google's services. To opt out of Google Analytics cookies, see the Google Analytics Opt-out Browser Add-on.
- Stripe, Inc.: payment processing for paid plans is outsourced to Stripe. The handling of billing email addresses, credit card information, and related payment data is governed by Stripe's Privacy Policy.
The following are not considered disclosure to a third party:
- Where the Operator outsources all or part of the handling of personal information to cloud infrastructure providers to the extent necessary to achieve the purposes of use (limited to outsourcing for data storage and processing)
- Where personal information is provided in connection with a business succession due to a merger or other reason
Article 5 (Handling of Information via External AI Clients / MCP Connections)
The Service provides an MCP (Model Context Protocol) server that requires OAuth authorization. This allows external AI clients such as ChatGPT, Claude, and Codex (each, a "Connected AI Client") to call the Service's tools, but only against the account of the User who granted the authorization.
- A Connected AI Client can only connect to the Service after the User has explicitly completed OAuth authorization within that client. The scope of access is limited to the authorizing User's own account data; it cannot access other Users' data.
- The content of tool calls made through a Connected AI Client (for example, the body of a memo being created, or a search query) and the Service's responses to those calls (for example, memo bodies returned in search results, or skill sheet content) are processed by the Connected AI Client and its provider (such as OpenAI or Anthropic) as part of normal conversation handling. That processing is governed by each provider's own privacy policy.
- Even content that is not set to public will be passed to a Connected AI Client if the User has authorized the connection and the relevant tool is called. Users should take this into account before authorizing a connection.
- Users may revoke a Connected AI Client's access at any time, either from the Service's account settings or from the connector management screen of the Connected AI Client itself. Once revoked, no further tool calls can be made.
Article 6 (Retention and Account Deletion)
- Content information (memos, notes, project documents, goals, skill sheet content, etc.) is retained until the User deletes it within the Service or requests deletion of their account.
- Knowledge candidates pending review are retained until the User saves or discards them.
- When account deletion is completed, account information and User-related content information held in the PaPut database are deleted immediately and cannot be restored. For paid plans, the Stripe Customer is also deleted immediately and any active subscription ends.
- Stripe invoices, payments, refunds, tax records, and other transaction history retained by Stripe cannot be deleted by PaPut.
- Usage information retained by Google Analytics and data already sent to the Gemini API or Connected AI Client providers are governed by their respective retention policies and cannot be deleted by PaPut.
Article 7 (Correction and Deletion of Personal Information)
- Users can view, correct, and delete content they created (memos, notes, project documents, goals, skill sheet content, etc.) at any time from within the Service.
- Account deletion can be performed from the Service's settings screen. For other corrections or deletions of personal information that cannot be performed from within the Service, Users may make a request to the Operator following the Operator's designated procedure. Where the Operator determines that it is necessary to respond to such a request, it will make the correction without delay and notify the User of the outcome.
Article 8 (Suspension of Use, etc.)
- Where a User requests suspension of use or deletion ("Suspension of Use, etc.") of their personal information on the grounds that it is being handled beyond the scope of the stated purposes of use, or that it was obtained by wrongful means, the Operator will conduct the necessary investigation without delay.
- Based on the results of the investigation in the preceding paragraph, where the Operator determines that it is necessary to respond to the request, it will carry out the Suspension of Use, etc. without delay.
- The Operator will notify the User without delay after carrying out the Suspension of Use, etc. under the preceding paragraph, or after deciding not to do so.
Article 9 (Changes to This Policy)
- Except for matters otherwise provided by law or this Policy, the content of this Policy may be changed without notice to Users.
- Unless the Operator specifies otherwise, the revised Privacy Policy takes effect upon being posted on this website. Where a change materially affects the scope of information sent to or received from a Connected AI Client, the Operator will clearly indicate this on the website.
Article 10 (Contact)
For inquiries regarding this Policy, or requests for disclosure, correction, or deletion of personal information, please contact:
E-mail: paput.dev@gmail.com