Privacy Policy
Draft for review — not yet effective. Company registration and legal review are pending.
Status: DRAFT — not published, not reviewed by counsel. Proposed launch controller: new Korean corporation (September 2026). Named privacy contact supplied; registered identity/address, operational policy and completed review remain pending. Remaining placeholders in `[SQUARE BRACKETS]` need the founder decisions in `FOUNDER-DECISIONS.md`.
Draft revision: 2026-09-11. This draft incorporates the invitation and onboarding implementation; deployment regions, provider retention and business practices still need confirmation. It is not the currently effective policy. Review notes in brackets are internal and must be resolved before publication.
Launch facts confirmed by Tara — 2026-09-11: the intended operator is a new company to be incorporated in the Republic of Korea in September 2026. `knot.e / 노트` remains a proposed name, not a confirmed registered identity. Privacy contact: 권경아, Founder; hello@altr.haus. Registered company name, registration number and office address remain pending. These terms do not represent the company as already incorporated.
Last updated: [DATE OF PUBLICATION]
1. Who is responsible for your data
[REGISTERED NAME OF NEW KOREAN COMPANY], business registration number [REGISTRATION NUMBER], registered office [REGISTERED ADDRESS], is the intended controller of personal data described here.
Privacy contact: 권경아, Founder — hello@altr.haus.
[PRE-PUBLICATION CHECK: confirm incorporation and operational responsibility. Tara supplied the contact above on 2026-09-11; verify the formal privacy-officer appointment and any additional disclosure requirements. Assess Korean law and applicable US/UAE obligations against the actual service and users.]
2. Information used by the Service
Invitations and access requests. We use your email address, requested or assigned Brand / Rights Holder role, approval status, and invitation history to manage access. An administrator may invite a personal or company email address. An access-request form may additionally ask for your organisation and role. Invitation history records when an invitation was created, sent, accepted or failed, its expiry, and a failure stage where available. “Accepted” records completed sign-in, not simply opening an email.
Sign-in and account records. We process your email for email-link or Google sign-in, authentication tokens, account identifier, associated blockchain address, login method, role, organisation membership and account timestamps. Choosing Google sign-in sends the authentication request to Google and lets us verify the returned identity information. Public wallet addresses and signed proofs are processed when you choose a wallet method.
Onboarding and profile. The current onboarding form requires first and last name, company name, industry, referral-source answer and the terms checkbox. It also accepts job title, LinkedIn URL, website and company description. The account profile supports country. We store submitted profile information and a server-recorded terms acceptance time. A document version is not yet recorded.
[PRODUCT CHANGE BEFORE PUBLICATION: make referral-source collection optional; confirm whether industry is necessary for account setup or should be collected when creating a brief. Do not describe currently mandatory fields as optional.]
Service records. Briefs and settlement records can contain company contacts, project information and public transaction references. The final inventory must cover the enabled production flows, including any separate Insights/Terminal services, before those flows are included under this policy.
Technical information. Hosting and security systems process request and error logs, which can include IP addresses, browser information, request paths and diagnostic references. Email providers process message and delivery data.
3. Cookies and browser storage
We use a signed session cookie to keep you signed in. The current application also stores display-name and organisation cookies and caches onboarding and workspace information in browser storage. The session and display cookies are configured for seven days; browser local storage has no automatic expiry.
[REVIEW BEFORE PUBLICATION: inventory all enabled analytics, chat, Google sign-in, wallet-provider and Terminal integrations, their storage and retention. The older claim that the session cookie is the only cookie is withdrawn. Do not claim “no tracking” without checking both deployed hosts and third parties.]
Do not enter private keys, recovery phrases or identity documents into profile or project text fields.
4. Purposes and legal grounds
| Information | Purpose | Review required before publication |
|---|---|---|
| Email, access role, invitation events | Approve access, deliver invitations and troubleshoot sign-in | Document the applicable Korean processing ground |
| Account, profile and membership | Create and operate the account and its organisation workspace | Separate necessary information from optional enrichment |
| Authentication tokens and security logs | Prevent replay and investigate failures or misuse | Confirm access controls and retention |
| Referral-source answer | Understand how users discover ALTR | Make optional; document the processing ground |
| Public wallet and transaction references | Provide the wallet/settlement features the user chooses | Disclose public-ledger visibility and actual enabled networks |
Acknowledging this privacy notice is not blanket consent to every processing activity. Where consent is the applicable ground, provide the required notice and choice separately; refusal of optional processing must not block account creation. Transactional sign-in emails do not constitute marketing permission.
[REVIEW: map the applicable grounds under PIPA; assess GDPR/UK GDPR only where applicable. Do not reuse the old GDPR-only table as a Korean consent design.]
5. Service providers and overseas processing
| Service | Data / purpose | Location and disclosure status |
|---|---|---|
| Vercel | Hosting, requests and diagnostics | Confirm deployment, log and support processing locations |
| Supabase | Identity, profile, organisation and enabled database records | Demo primary database shown in Singapore; backup/support processing and the public site's configuration need confirmation |
| Upstash / configured KV provider | Approvals, invitation history and single-use token records; other enabled KV stores | Confirm contracted provider, region and retention |
| Resend | Recipient address, email body and delivery information | Confirm contracted entity, locations and retention |
| Google, when selected | Authentication and identity information | Review Google's applicable terms and its role; do not classify all Google processing as solely on ALTR's instructions |
| Wallet/key and chat providers, when enabled | Feature-dependent data | Inventory deployed providers before adding them to the final policy |
Provider headquarters are not proof of where data is stored or accessed. For each overseas transfer, complete a disclosure covering recipient/contact, country, data categories, timing/method, purpose, retention and the applicable legal ground, including refusal information where required. The table above is an internal inventory, not the finished transfer notice.
6. How long we keep it
[NOT YET DECIDED — see FOUNDER-DECISIONS.md item 4.]
We will not publish a retention period we do not actually implement. There is currently no automated deletion in the Service. Until a period is set and built, this section stays open rather than stating a comfortable number that is not true.
What we can say today: your session cookie expires after 7 days.
7. Your rights
Depending on where you are, you can ask us to:
- Access the personal data we hold about you
- Correct it if it is wrong
- Delete it
- Restrict or object to how we use it
- Port it to another provider
- Withdraw consent, where we relied on consent
Write to hello@altr.haus. We will respond within the period the law requires for the applicable request and jurisdiction. [Confirm the operational response procedure and deadlines before publication.]
You can also complain to the 개인정보보호위원회 (Personal Information Protection Commission) — official website — or, if you are in the EEA, to your local supervisory authority.
[OPERATIONAL GAP: validate a deletion procedure across Supabase, KV, email providers, logs and backups before promising completed account erasure.] We cannot delete anything written to a public blockchain — that is what a public blockchain is, and no operator can undo it. During the beta this concerns test networks only. Any legal text that promises unconditional erasure of on-chain data is promising something technically impossible.
8. Security
The Service uses encrypted transport (HTTPS), signed session tokens with a short lifetime, and access controls on the systems holding account records. No system is perfectly secure, and we will not claim otherwise.
If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires . [Confirm incident thresholds, deadlines, recipients and an operational response owner under the applicable current rules; the earlier blanket 24-hour PIPA statement is withdrawn.]
9. Children
The Service is for business use and not directed to children. We do not knowingly collect data from anyone under 16 (under 14 where PIPA applies). If you believe we have, write to us and we will delete it.
10. Changes
We may update this policy. Material changes will be notified by email or in the Service before they take effect, and the "last updated" date above will change.
11. Contact
[REGISTERED NAME OF NEW KOREAN COMPANY — pending] Business registration: [REGISTRATION NUMBER] Registered office: [REGISTERED ADDRESS] hello@altr.haus
Privacy contact: 권경아, Founder — hello@altr.haus. [Confirm formal designation and remaining required details before publication.]
Internal review sources — remove from published copy
- PIPA Article 30, official law text: “개인정보의 처리 목적” and “개인정보의 처리 및 보유 기간” are specified policy contents. Use this to complete the purpose/retention sections, not to infer unverified retention periods.
- PIPA, official law text: review Articles 15, 22, 28-8, 30, 31 and 34 against the version effective at publication. This draft does not determine compliance or replace jurisdiction-specific legal review.