Legal
Privacy Policy
How viewer.run processes account, workspace, server-file, billing, security and audit data.
Effective date: 2026-05-25
1. Scope
지엑스소프트 (“Company”) processes personal data in accordance with applicable privacy law to provide viewer.run. This policy applies to accounts, workspaces, server features, support, billing and operational security.
2. Purposes
- Account and authentication
- Registration, email verification, sign-in, social login, password reset and account security.
- Files and workspaces
- Authorized upload, storage, viewing, download, deletion, organization membership and collaboration.
- Subscription and billing
- Entitlements, Team trials, invitations, usage, plan requests, payment, cancellation, refund and sales inquiries.
- Security and audit
- Access control, abuse prevention, audit records, incident response and troubleshooting.
- Communications
- Authentication, invitation, trial, billing, service and support messages.
- Service improvement
- Privacy-limited telemetry, compatibility analysis and reliability improvements.
3. Data processed
- Account
- Name, email, password hash, authentication provider identifier, verification and account status, registration and last sign-in times.
- Workspace
- Organization, membership, role, invitations, projects, permissions and administrative history.
- Server files
- Original filename, size, storage reference, uploader, timestamps, thumbnail and compatibility metadata. Local-only files are not stored unless explicitly uploaded or sent to a server feature.
- Billing and inquiries
- Plan, interval, term, seat count, usage, payment status, amount, order and receipt identifiers, requests and support history. The Company does not store card numbers or CVC values.
- Technical records
- Safely hashed IP, user agent, cookies, session identifier, request path, timestamp, security and error records.
- Telemetry exclusions
- File names, file contents, remote URL query tokens, invitation tokens, sharing tokens and raw payment credentials are not collected as product telemetry.
4. Retention
- Account
- Until account deletion, subject to mandatory legal retention and dispute handling.
- Server files and metadata
- Until deleted by an authorized user or administrator, or according to an agreed workspace retention policy.
- Audit logs
- Normally 90 days for Team and 365 days for Enterprise, unless contract, law or an active security investigation requires otherwise.
- Subscription and payment
- For the period required by applicable tax, electronic commerce and dispute-resolution laws.
- Tokens
- Until expiry, successful use or revocation.
- Security and error logs
- Only as long as reasonably necessary for abuse prevention, incident response and service reliability.
5. Processors, disclosures and international transfers
- Payment
- When online billing is enabled, Toss Payments or the payment provider displayed at checkout processes authorization, cancellation, refund and receipt data.
- Hosting and storage
- The configured cloud host, PostgreSQL database, Vercel Blob or S3-compatible storage processes service and backup data.
- The configured SMTP provider sends authentication, invitation, trial and subscription messages.
- Authentication
- Google, Kakao, Naver or another provider selected by the user may return an identity identifier, email and profile data.
- Error monitoring
- When enabled, Sentry may process sanitized error, route, environment and technical diagnostic data.
- International transfer
- If a selected provider processes data outside your country, required data is encrypted in transit and transferred for service delivery or incident response for that provider’s configured retention period. The actual provider, country and period depend on the production configuration and accompanying notice.
The Company does not sell personal data and does not disclose it to third parties except with consent, under law, or to the processors needed to provide the service.
6. Cookies and sessions
Cookies and session identifiers maintain sign-in state, protect authentication and remember necessary preferences. Blocking them may prevent account and workspace features from operating.
7. Your rights
- You may request access, correction, deletion, restriction or other rights available under applicable law.
- Authorized users may delete server files through file management, subject to workspace permissions.
- Mandatory legal records, security evidence and active dispute records may not be deleted immediately.
- Send a request to the privacy contact below. The Company will verify identity and respond within the period required by law.
8. Security
- Password hashing, encrypted transport, protected tokens and least-privilege access controls.
- Server-side workspace and role validation with audit records for material actions.
- Filters intended to remove credentials, payment data, file names and file contents from operational telemetry and error reporting.
- Incident investigation, notification and mitigation as required by applicable law.
9. Children
The service is intended for business and professional file review and is not directed to children. A guardian should contact the Company if a child submitted personal data without valid authorization.
10. Privacy contact
- Company
- 지엑스소프트
- Privacy officer
- 최영구
- privacy@gxsoft.co.kr
- Phone
- 010-4404-1523
- Support hours
- 평일 10:00~17:00, 공휴일 제외
11. Changes
This policy is published in the service. Material changes will be announced through the service, email or another appropriate channel before they take effect.