EON Privacy Policy
Effective Date: April 28, 2026
(Enacted April 1, 2026; First Amendment April 28, 2026)
Void and Thrill (hereinafter the “Company”) has established this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea to protect the personal information and rights of users.
1. Purposes of Personal Information Processing
The Company processes personal information for the following purposes:
- Account registration and management (email, nickname)
- Providing destiny analysis service (date of birth, time of birth, place of birth, gender)
- AI-based personalized consultation (chat content)
- Payment and Dokaebi Fire management
- Service quality improvement and error analysis
2. Personal Information Processed
- Required: Email address, nickname, date of birth (solar/lunar), time of birth, place of birth, gender
- Automatically collected: IP address (SHA-256 hashed), country of access, service usage records
- Optional: Sexual orientation, relationship status (for personalized readings)
3. Retention Periods
- Member information: Deleted immediately upon account termination (hard delete)
- Terminated-member snapshot (email, nickname — encrypted): Automatically deleted after 1 year
- Payment records: Retained for 5 years pursuant to the Act on Consumer Protection in Electronic Commerce
- Operational logs: Retained for 7 days
4. Disclosure to Third Parties
The Company does not disclose personal information to external parties except for the following limited purposes:
| Recipient | Purpose | Data Items | Cross-Border Transfer | Retention |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing | Email, payment card information | United States | Per Stripe's policy |
| Google LLC (Gemini) | Operating the AI Destiny Analysis Computation Engine | Date/time/place of birth, gender; nickname during chat | United States, Singapore, etc. | Deleted immediately after processing |
| Resend, Inc. | Email authentication (OTP) | Recipient email | United States | Deleted immediately after sending |
| Google LLC (Analytics) | Service usage statistics | Anonymous events, hashed userId, IP | United States | Per Google's policy |
- Payment card information is collected and processed directly by Stripe; the Company does not store it.
- Birth information sent to AI services is used solely for destiny analysis purposes and is not used for AI model training.
5. Entrustment of Personal Information Processing
The Company entrusts the following processing tasks for the smooth operation of the Service. Processors are listed below in order of personal data sensitivity.
| Processor | Entrusted Task | Data Items | Cross-Border Transfer | Retention |
|---|---|---|---|---|
| Render, Inc. | Hosting infrastructure for the AI Destiny Analysis Computation Engine | Date/time/place of birth, gender | United States | Erased from memory immediately after computation (request bodies are not recorded in server logs) |
| Supabase, Inc. | Authentication and database hosting | Email, nickname, birth information, chat content (stored with AES-256-GCM encryption) | United States | Deleted upon member termination |
| Google LLC (Gemini) | AI destiny analysis | Date/time/place of birth, gender; nickname during chat | United States, Singapore, etc. | Deleted immediately after processing |
| Google LLC (Analytics) | Service usage analytics (GA4) | Anonymous events, hashed userId, IP | United States | Per Google's policy |
| Stripe, Inc. | Payment processing | Email, payment card information | United States | Per Stripe's policy |
| Cloudflare, Inc. | Image storage (R2) | Dokaebi images | United States | Deleted upon member termination |
| Vercel, Inc. | Web service hosting | HTTP requests/logs (PII-minimized) | United States | Within service log retention period |
| Resend, Inc. | Email delivery | Recipient email | United States | Deleted immediately after sending |
| Replicate, Inc. | Dokaebi image generation | Text prompt (no PII) | United States | Deleted after processing |
| fal.ai (FAL AI, Inc.) | Dokaebi image generation | Text prompt (no PII) | United States | Deleted after processing |
| Upstash, Inc. | Rate limiting | Hashed identifiers (e.g., hashed IP) | United States, Europe | Short-term cache (expires within minutes) |
- Processors are contractually obligated to use personal information only for the entrusted purpose and to manage it securely.
- The Company provides prior notice through this Policy when a processor is changed or added.
6. Rights of Data Subjects
Under the Personal Information Protection Act, users may exercise the following rights:
- Request access, correction, deletion, or suspension of processing
- Direct modification/deletion through the account settings page
- Immediate deletion of all personal information upon account termination (hard delete)
- Contact: eon.ai.master@gmail.com
7. Destruction of Personal Information
- Upon termination: auth.users deletion → CASCADE deletes all related data immediately
- Terminated-member snapshot (email, nickname — encrypted): Auto-deleted after 1 year
- Destruction method: Electronic files are deleted using methods that prevent recovery
8. Security Measures
The Company implements the following technical and administrative measures to protect personal information:
Technical Measures
- Encryption at rest: AES-256-GCM (name, date of birth, time of birth, place of birth, gender, reading results, conversation content)
- One-way hashing: SHA-256 (IP address, OTP codes)
- Database access control: Supabase Row Level Security (RLS) — users can access only their own data
- Encryption in transit: TLSv1.3, AES-256-GCM, X25519MLKEM768 (post-quantum key exchange) applied. Same level applied to processors (including Render)
- Rate limiting: Prevents malicious access
Personal Data Protection at Processor (Render)
- The AI Destiny Analysis Computation Engine does not persist birth information to disk (stateless architecture).
- Birth information used in computation is erased from memory immediately after processing.
- Server request logs record only metadata (path, method, status code, duration). Request bodies (raw birth information) are not recorded in logs.
- Operational logs are automatically discarded after 7 days.
Administrative Measures
- Minimized number of personnel handling personal information
- Data Processing Agreements (DPAs) signed with processors
- Regular processor audits
9. Children Under 14
The Company does not collect personal information from children under 14 years of age.
During registration, age 14+ is verified. If a user is subsequently found to be under 14, the account is terminated immediately.
10. Cookies and Automatic Collection Devices
- Authentication cookies: Login session maintenance (Supabase Auth)
- Google Analytics: Service usage statistics (anonymous)
- Local storage: UI settings (tab selection, etc.)
11. Data Protection Officer
The Company designates the following contact to oversee personal information processing and handle user complaints and remedies:
| Item | Details |
|---|---|
| Team | EON Operations Team |
| Contact | eon.ai.master@gmail.com |
12. Business Information
| Item | Details |
|---|---|
| Business Name | Void and Thrill (보이드앤스릴) |
| Representative | Lee Young-Won |
| Business Address | 34, Nonhyeon-ro 157-gil, Gangnam-gu, Seoul, Republic of Korea |
| Phone | +82-70-5236-0201 |
| eon.ai.master@gmail.com | |
| Business Registration No. | 770-12-02769 |
| Mail-Order Business Registration No. | Filing submitted, pending acceptance (will be reflected upon acceptance) |
13. Rights of Users in Specific Jurisdictions
The Service is operated from the Republic of Korea and transfers personal data to processors located in the United States and other jurisdictions. Users in the following regions have additional rights:
EEA/UK Users (GDPR)
- Right of access, rectification, erasure ("right to be forgotten")
- Right to restriction of processing, data portability, objection
- Right to lodge a complaint with a supervisory authority
- Legal basis: Contract performance (Art. 6(1)(b)) and, where specific data is processed, consent (Art. 6(1)(a))
- Cross-border transfer: Transfers to the United States and other jurisdictions rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) where contained in the Data Processing Agreements with major processors (e.g., Supabase, Google, Stripe, Vercel, Cloudflare, Render). For certain processors handling non-PII data only (e.g., text prompts sent to image generation services), transfers rely on contract performance with additional safeguards.
Japan Users (APPI)
- Right to request disclosure, correction, addition, or deletion of retained personal data
- Right to request cessation of use or third-party provision
- Contact point for complaints: eon.ai.master@gmail.com
Thailand Users (PDPA)
- Right to access, correct, delete, and port personal data
- Right to withdraw consent and object to processing
- Right to file a complaint with the Personal Data Protection Committee
To exercise these rights, contact eon.ai.master@gmail.com.
14. Remedies for Rights Violations (Republic of Korea)
Korean users may contact the following institutions for dispute resolution or consultation regarding personal information infringement:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Reporting Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.cyber.go.kr)
15. Changes to This Privacy Policy
- Changes to this Policy will be posted within the Service at least 7 days prior to taking effect, specifying the reason for and content of the change.
- Changes unfavorable to users will be posted at least 30 days prior.
- Effective date: April 28, 2026
Language Note: This Policy is drafted with the Korean version as the authoritative text. In case of any discrepancy, the Korean version shall prevail.
Revision History
- 2026-04-01: Enacted (in force)
- 2026-04-28: First Amendment (mandatory disclosures completion + processor transparency reinforcement)
- Added Business Information (§12)
- Structured DPO section with team and contact (§11)
- Expanded processor list — reordered by sensitivity (§5)
- Added cross-border transfer and retention in third-party disclosure table (§4)
- Reinforced security measures — TLSv1.3 in transit and separate processor log policy disclosure (§8)
- Added rights for users in specific jurisdictions with clarified GDPR legal basis (§13)
- Added remedies for Korean users (§14)
- Clarified amendment notice procedures (§15)