법무팀

개인정보처리방침

수집하는 정보, 수집 목적, 보유 기간을 안내합니다.

최종 개정일 2026년 8월 10일 시행일 2026년 8월 10일 버전 0.1 (초안)
Draft — not yet reviewed by counsel

This document describes how we operate and is published so you can review it early. It has not yet completed external legal review and is not a binding agreement in this form. If you need executed terms before that review completes, contact us and we will handle it directly.

English is the governing version

Translations of this page may be provided for convenience. Where a translation conflicts with the English text, the English text controls.

1. Scope

This policy covers personal information we handle as a controller — account data, billing data, and product analytics. Content you upload into your workspace is handled as a processor on your instructions and is governed by our Data Processing Addendum instead.

2. What we collect

CategoryWhat it includesWhere it comes from
IdentityName, email address, profile picture, identity provider subject identifierYour identity provider at sign-in
OrganizationWorkspace name, verified domains, role assignments, invitation recordsYou and your administrators
BillingPlan, seat counts, invoices, billing contactYou. Card details go directly to our payment processor — we never receive them
UsageFeature usage, credit consumption, error reports, approximate location from IPAutomatically, as you use the product
AuditWho did what and when, including IP address and user agent Automatically. Retained per your plan

We do not store passwords. Authentication happens at your identity provider, so there is no credential database here.

3. How we use it

  • To operate the service, authenticate users, and enforce permissions.
  • To bill you accurately and prevent abuse of usage limits.
  • To investigate security incidents and maintain the audit trail your plan provides.
  • To support you when you contact us.
  • To understand which features are used, in aggregate, so we build the right things.

We do not use your data to train machine learning models, and we do not sell personal information or share it for cross-context behavioral advertising.

4. Legal bases

Where GDPR or similar law applies, we rely on:

  • Contract — to provide the service you signed up for.
  • Legitimate interests — security, abuse prevention, and product improvement, balanced against your rights.
  • Legal obligation — tax, accounting, and lawful requests.
  • Consent — for optional communications, which you can withdraw at any time.

5. Who we share it with

We share personal information with the subprocessors listed in our subprocessor list, each bound by contract to process it only on our instructions.

Data you bring in from a connected tool (GitHub, Google, Microsoft 365, Slack, Notion, Atlassian, Linear, Figma) is covered by section 13, which sets out what we access, what we store, and how Google user data is handled.

We may also disclose information when required by law, to protect our rights or someone's safety, or as part of a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.

6. How long we keep it

DataRetention
Account and profileWhile your account is active, then deleted within 30 days
Workspace contentUntil you delete it, or 30 days after account closure
Audit logsPer your plan — 90 days, 1 year, or 3 years
Billing recordsSeven years, as required for tax and accounting
Support correspondenceThree years

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to complain to a supervisory authority.

Most of this is available directly in the product: you can export your data at any time and delete your account from workspace settings. For anything else, write to [email protected] and we will respond within 30 days. We do not charge for these requests and we will not treat you differently for making one.

If you are a member of a workspace your employer administers, direct requests about workspace content to them — they control that data, and we act on their instructions.

8. International transfers

We operate from the United States and our infrastructure providers operate globally. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with additional technical measures including encryption in transit and at rest.

Enterprise customers can request regional data residency.

9. Cookies

We use the minimum set of cookies needed to run the product:

CookiePurposeDuration
SessionKeeps you signed inSession or up to 30 days
CSRF tokenPrevents cross-site request forgerySession
PreferencesLanguage and interface settings1 year

We do not use advertising or cross-site tracking cookies.

10. Children

The service is for organizations and is not directed to anyone under 16. We do not knowingly collect information from children. If you believe we have, write to [email protected] and we will delete it.

11. Changes

We will post changes here and update the date at the top. For material changes we will notify account administrators by email at least 30 days before they take effect.

12. Contact

Privacy questions or requests: [email protected]
Security matters: [email protected]

A registered business address and, where required, an EU/UK representative will be published here before general availability.

13. Connected services and Google user data

untactit connects to the tools you already use — GitHub, Google, Microsoft 365, Slack, Notion, Atlassian (Jira and Confluence), Linear, and Figma — so the agent assets living in those tools can be inventoried, reviewed, and deployed from one place. You start every connection yourself by signing in to that vendor. We never ask for, receive, or store your password for a connected service.

What we access. Only what the connection needs: the files, pages, issues, and documents your own account can already see in the workspace you connect, plus the account or workspace identifier that tells us which connection a token belongs to. We request read-only scopes wherever the vendor offers them, and we ask for write access only where you have asked us to publish assets back.

What we store. Access and refresh tokens, encrypted at rest and scoped to your organization; the content you choose to import as an asset; and a synchronization log recording what moved and when. Tokens are never shared with other customers, and we do not sell data obtained from connected services.

Google user data — Limited Use. untactit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve the features you connected it for; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger with prior notice; we do not use it for advertising; we do not sell it; and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. Human access is limited to what you explicitly permit, to what security or law requires, and to aggregated or anonymized data used to operate the service.

Disconnecting. You can disconnect any service at any time from Settings → Connectors, or revoke untactit's access from the vendor's own security settings. Disconnecting deletes the stored tokens for that service immediately. Assets you already imported stay in your workspace until you delete them.