Privacy Policy
Effective date: September 6, 2026
Scope. This Privacy Policy applies to users of the Service located outside the Republic of Korea ("global users"). If you are located in the Republic of Korea, our Korean-language Privacy Policy applies to you instead — under that policy, age verification is performed through mobile-phone identity verification (휴대폰 본인인증) rather than through Didit. When you begin age verification you are asked to select your country of residence; selecting the Republic of Korea routes you to mobile-phone verification and prevents any transfer of your ID or facial data to Didit.
This document is based on our Korean-language Privacy Policy, drafted under South Korea's Personal Information Protection Act (PIPA). Except for the region-specific age-verification method (Sections 3a and 3b), where there is any inconsistency between this translation and the Korean version, the Korean version controls.
Road Financial ("Company," "we") establishes and discloses this Privacy Policy pursuant to Article 30 of Korea's Personal Information Protection Act, so that data subjects' personal information is protected and related grievances can be handled promptly and smoothly.
1. Purposes of processing personal information
We process personal information for the purposes below and do not use it for any other purpose. If the purpose of use changes, we will take necessary measures, including obtaining separate consent as required under Article 18 of the PIPA.
- Account creation and management: identity verification, member identification, and fraud/abuse prevention for the membership-based Service; various notices.
- Providing the Service: generating AI chat responses, web search, agent/project/prompt management, file storage, MCP (Model Context Protocol) server integrations, and providing the Service through the developer API and the Coding Agent CLI.
- Plan and usage management: calculating and applying per-plan limits on messages, images, projects, agents, and storage; managing the paid-plan waitlist.
- Age verification: confirming that a user meets the age of majority in order to gate access to adult content.
- Protection of children under 14: estimating and confirming a user's age band, and suspending (freezing) accounts, in order to keep children under 14 from using the Service.
- Service improvement: usage analytics and error resolution.
2. Retention and use period of personal information
- We process and retain personal information within the retention/use period consented to by data subjects, or as required by applicable law.
- Specific retention periods:
- Account information: until account deletion (or until the conclusion of any related legal investigation, if one is pending).
- Service content (chats, files, agent configurations, etc.): until deleted by the Member or until account deletion.
- Age verification result: until account deletion. The underlying ID/biometric data used for verification is not stored by us; it is processed and retained by our verification processor, Didit, under its own policy. What we retain is limited to whether verification succeeded, whether you are of age, whether you are 14 or older, the time of verification, and the verification method.
- Payment records, under Korea's Act on Consumer Protection in Electronic Commerce: records of contracts/withdrawal of subscription for 5 years, records of payment and supply of goods/services for 5 years, records of consumer complaints/dispute resolution for 3 years. On account deletion these records are not deleted; instead, personally identifying fields are stripped and the records are retained in anonymized form for the periods above (Section 7(2)).
- Content-moderation and security records: an excerpt of the conversation (up to 500 characters) that formed the basis of a policy-violation determination, the violation category and time, and security event records — until account deletion.
- Developer API usage records: per-request model, token counts, usage, and response time — until account deletion.
- Access logs under the Protection of Communications Secrets Act: 3 months.
3. Categories of personal information processed
- Required: email address, display name, and profile image, collected via our authentication provider.
- Generated while using the Service: chat messages and prompts, uploaded files, agent configurations, artifacts, MCP server connection details, selected AI model, plan/usage data (message counts, images generated, token usage, storage used, etc.), API usage records, and error logs.
- Content-moderation records: where content is blocked or a warning is issued because it is suspected of violating our terms or applicable law, an excerpt of the conversation (up to 500 characters) that formed the basis of that determination, the violation category, and the time of the action.
- Security records: where abnormal access or privilege-escalation attempts are detected, the event type and related information.
- Payment information (for paid plans): order number, amount, payment status, card issuer information (issuer code and card name), and — for recurring payments — a payment token (billing key) issued by our payment processor. We do not store card numbers, expiry dates, or passwords.
- Identity verification during payment: when you register a payment method for recurring billing, an identity-verification step may take place inside the payment window operated by our payment processor, NHN KCP Corp., together with the card issuer and identity-verification agencies. That personal information is handled entirely within the payment window by those parties; we neither receive nor store it. What we receive is limited to the payment token (billing key) and card issuer information. This is separate from the age verification described in Section 3a.
- Developer API information: a one-way hash of the API key (the key itself is shown once at creation and is never stored), per-request model, token counts, credits, response time, and request identifier, and files uploaded through the developer API (filename, MIME type, size, etc.).
- Coding Agent CLI information: the account to which an API key issued via OAuth login is attributed, and that key's usage information (as above). The CLI's conversation session history, per-project memory, and MCP (Model Context Protocol) server configuration are stored only on the user's local device — we do not collect or store them on our servers. See Section 3d for details.
- Country of residence: the country you select yourself (Republic of Korea / other) in order to determine which age-verification method applies. We do not infer or look up your location; we record only your selection.
- Processed during age verification: only when a user undergoes age verification, our verification processor (Didit) processes ID document data, date of birth, nationality/issuing country, and a facial image (biometric liveness data). We do not store these originals — only the verification result (whether the user is of age, and the verification status).
- Age-band estimation data: to detect users under 14, an estimated age band derived from analyzing information generated while using the Service (such as chat content), and the related analysis records.
- Automatically collected: access logs, cookies, IP address, service usage history, and device identifiers (browser/OS information, etc.).
3a. Age verification and adult content
- To restrict access to adult content, we may require users who wish to use such features to complete an age verification process.
- Before verification begins, you select your country of residence. This selection determines the method and is enforced on our servers: if you select the Republic of Korea, we do not create a Didit session at all, so no ID or facial data leaves for Didit. Selecting a country other than the Republic of Korea means you agree to the cross-border transfer described in Section 6.
- For users outside the Republic of Korea, age verification is performed through the identity-verification provider Didit via ID document authenticity checks, facial liveness (biometric), and face matching, processing ID document data, date of birth, nationality/issuing country, and a facial image.
- Biometric data such as facial images constitutes sensitive information under Article 23 of the PIPA; separate consent for its processing is obtained directly from the user within Didit's verification flow. A user may decline, in which case age verification and adult content will be unavailable.
- We never store the originals of sensitive data (facial/biometric images) or ID documents under any circumstances, including in our API logs or operational records. We receive and retain only the result needed to determine majority status (whether the user is of age, and success/failure of verification).
- Majority (adult) status is determined by the age of majority under the law of the ID's issuing country — for example, 19 in the Republic of Korea, and 18 in the United States, the United Kingdom, EU member states, Australia, and New Zealand. Even if identity verification succeeds, verification fails if the person is below that age.
- Children under the age of 14 may not undergo age verification and may not access adult content.
3b. Restriction of children under 14 and automated age estimation
- The Service may not be used by anyone under 14 years old. We obtain confirmation that a user is 14 or older at sign-up.
- To determine whether a user is under 14, we may analyze information generated while using the Service (such as chat content) to estimate the user's age band. This analysis uses automated systems (rule-based checks and an AI classifier), considering a variety of linguistic and behavioral characteristics.
- If the analysis suggests a user may be under 14, we proceed in stages:
- (Step 1 — temporary restriction) The account is temporarily frozen. This is a provisional measure pending age confirmation, not a final decision.
- (Step 2 — explanation and verification) We inform the user of the reason and offer age verification through the same process as Section 3a (Didit). Instead of verifying, the user may also object and present their case to the Privacy Officer in Section 11.
- (Step 3 — outcome) If the user is confirmed to be 14 or older, the freeze is lifted without delay. If confirmed to be under 14, the service agreement is terminated, use of the Service is permanently restricted, and the child's personal information is destroyed 30 days after that confirmation by the methods in Section 7. Those 30 days exist so that an objection can be raised: destroying the data immediately would also destroy the evidence needed to correct an incorrect age determination. If an objection has been submitted and is under review, destruction is deferred until that review concludes. The user or their legal guardian may also request immediate destruction (account deletion) without waiting for the 30 days.
- The following measures may constitute fully automated decisions that significantly affect the ability to use the account, under Article 37-2 of the PIPA:
- the account freeze based on age estimation (this Section);
- the account restriction applied when content-policy warnings accumulate (4 warnings);
- the account suspension applied on detection of a security threat such as abnormal access or a privilege-escalation attempt (applied immediately, without prior administrator review).
- This processing is carried out to protect children and comply with applicable law. The estimated age band and related analysis records are used only to decide whether to freeze an account and to handle objections, and are destroyed upon account deletion or upon the destruction described in paragraph 3.
3c. AI processing and use for training
- Prompts, chat content, and files a user enters may be transmitted to and processed by the AI model providers we use in order to provide the Service (AI responses, image generation, etc.). For AI chat, data is routed through OpenRouter, Inc. to the provider of the model the Member selects (e.g., OpenAI, Anthropic, Google, xAI, DeepSeek, Meta); for image generation, through fal.ai to the applicable image-model provider. OpenRouter is a routing intermediary we contract with — how each underlying model provider actually handles data is governed by the agreement between OpenRouter and that provider and by the provider's own policy, not by a direct contract between us and that provider.
- Unless the user separately consents, we do not use users' chat content, prompts, or files to train our own AI models.
- How transmitted data is handled by an AI model provider (including whether it is used for training) is governed by that provider's own policy, which may change without notice to us and which we cannot directly guarantee. Based on our review:
- The infrastructure serving OpenAI, Anthropic, Google, xAI, and Meta-hosted models publicly states that it does not, by default, use API-submitted data to train its own models.
- 🔴 DeepSeek is an exception. Based on our review of DeepSeek's published policy, DeepSeek may, unlike other providers, use API-submitted data by default to improve its own technology and models, and we found no clear opt-out mechanism for API accounts. DeepSeek also states that it directly collects, processes, and stores data within the People's Republic of China. If you pin your model choice directly to a DeepSeek model, these facts apply to that request. See Section 6 for cross-border transfer details.
- fal.ai, used for image generation, states that it may use anonymized/aggregated data derived from your input to develop its services and AI models; an explicit promise that inputs are never used for training is documented only for fal.ai's separate enterprise agreements.
- For content moderation and the age estimation in Section 3b, both user input and AI-generated responses are processed by automated classification systems. Specifically, (i) OpenAI's Moderation API (classification of illegal/harmful content, including attached images) and (ii) AI models accessed through OpenRouter (Korean-language content classification and age-band estimation). This processing is used solely for child protection, terms enforcement, and legal compliance.
- When you use the web search feature, your search query and the address of the web page being retrieved are transmitted to the search providers listed in Section 5. The search provider currently active in production, Exa Labs, Inc., states in its published policy that it may use query data to improve its services and train its models, and we found no documented opt-out for standard customers. Tavily, Brave Search, and Jina AI are currently configured only as inactive fallback routes; each provider's own policy will apply equally once activated.
- A Member (business or sole proprietor) who uses the developer API or the Coding Agent CLI to process the personal data of its own end users or other third parties is additionally subject to our Data Processing Agreement (DPA).
3d. Coding Agent CLI
- The Coding Agent CLI is a tool that runs on the user's own local computer and can read, write, and delete files, and execute system commands, in a directory the user designates. It is not a web service or a cloud sandbox.
- Stored only locally, never collected by us: the entire conversation session history, per-project memory (facts the model records for itself), the user's registered MCP server configuration (which may include addresses and credentials), and the original API key issued at login. This information is stored only in the user's home directory on their own device — it is never transmitted to, or viewable by, our servers.
- Transmitted to and processed by our servers: the conversation content the CLI sends to our servers (the developer API) each turn — prompts, and any portion of local file content or command output the CLI includes in the prompt — is passed on to AI model providers under Section 3c in order to generate a response. We do not persistently store this conversation content (a stateless design); we record only usage metadata (model, token counts, credits, etc.) under Section 3, as with any other developer API call.
- Login (OAuth) reuses the user's existing account authentication; no new personal information is collected. We do record which account an issued API key is attributed to.
- Third-party MCP servers a user registers with the CLI are not pre-screened by us; what information is sent to such a server depends entirely on that server's own behavior and is outside our control.
- The serve/connect feature operates only over the user's local network port and does not pass through our servers.
4. Provision of personal information to third parties
We process personal information only within the scope stated in Section 1, and provide it to third parties only where a data subject has consented or where required under Articles 17 and 18 of the PIPA. We do not sell or provide Members' personal information to third parties for marketing purposes. Processing by the external services we use to operate the Service (Clerk, Convex, OpenRouter, OpenAI, Exa, Tavily, Brave, Jina AI, fal.ai, Didit, NHN KCP, NHN Cloud, etc.) constitutes outsourced processing and cross-border transfer — not third-party provision — as detailed in Sections 5 and 6.
5. Outsourcing of personal information processing
To operate the Service smoothly, we outsource certain personal information processing tasks as follows:
| Processor | Outsourced task |
|---|---|
| Clerk, Inc. | Member authentication and login session management |
| Convex, Inc. | Application database storage and backend processing |
| OpenRouter, Inc. and the underlying AI model provider selected by the Member | Processing prompts/conversation content to generate AI chat responses |
| OpenAI, L.L.C. | Content moderation — classification of illegal/harmful content and attached images |
| Exa Labs, Inc. / Tavily / Brave Software, Inc. / Jina AI GmbH | Web search and retrieval of web page content |
| fal.ai (Features and Labels, Inc.) | AI image generation |
| Didit (Identity Verification Solutions, S.L.) | Age verification for users outside the Republic of Korea (ID authenticity checks, biometric liveness, face matching) |
| Dream Security Co., Ltd. (㈜드림시큐리티) and Korean mobile carriers / identity-verification agencies | Age verification for users in the Republic of Korea (mobile-phone identity verification) |
| NHN KCP Corp., together with card issuers and identity-verification agencies | Credit card and recurring payment processing, and identity verification performed inside the payment window when a payment method is registered |
| NHN Cloud Corp. | Service server operation (in the Republic of Korea) |
When entering into outsourcing agreements, we specify — in accordance with Article 26 of the PIPA — restrictions on processing personal information outside the scope of the outsourced task, technical/managerial safeguards, restrictions on re-outsourcing, oversight of the processor, and liability for damages.
6. Cross-border transfer of personal information
To provide the Service, we transfer personal information overseas as described below; the transferred information may be subject to the laws of the destination jurisdictions.
| Recipient | Country | Items and purpose |
|---|---|---|
| Clerk, Inc. | United States | Email, name, profile image — member authentication and session management |
| Convex, Inc. | United States | Service data listed in Section 3 — database storage and backend processing |
| OpenRouter, Inc. | United States | Chat messages and prompts — AI model routing (intermediary) |
| The AI model provider the Member selects (e.g., infrastructure serving OpenAI, Anthropic, Google, xAI, or Meta models) | United States, United Kingdom, Canada, etc. (the provider's location) | Chat messages and prompts — AI response generation |
| 🔴 DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) — only when the Member pins their model choice directly to a DeepSeek model | People's Republic of China | Chat messages and prompts — AI response generation. Unlike other providers, DeepSeek may also use this data to train its own models (see Section 3c). |
| OpenAI, L.L.C. | United States | Conversation content and attached images — content moderation |
| Exa Labs, Inc. / Tavily / Brave Software, Inc. | United States | Search queries — web search |
| Jina AI GmbH | Germany | Address of the web page being retrieved — web page content retrieval |
| fal.ai (Features and Labels, Inc.) | United States | Image-generation prompts — AI image generation |
| Didit (Identity Verification Solutions, S.L.) | Spain (EU) | (Only when age verification is performed, and only if you selected a country of residence other than the Republic of Korea) ID document data, date of birth, nationality/issuing country, and facial (biometric) image — age verification |
Where the Service itself runs. The Company is established in the Republic of Korea and operates the Service on servers located in the Republic of Korea (NHN Cloud). Accordingly, personal information described in Section 3 is processed in the Republic of Korea in addition to the transfers listed above. Card payments — and any identity verification performed inside the payment window when a payment method is registered — are processed by a Korean payment processor (NHN KCP), together with card issuers and identity verification agencies, within the Republic of Korea.
- Timing and method: real-time transmission over the network at the time the Service is used.
- Recipient's purpose and retention period: same as Sections 1, 2, and 3a — until the outsourced task ends or the account is deleted (plus any backup retention period of the processor).
If a data subject does not wish their personal information to be transferred overseas, they may object by withdrawing their account or discontinuing use of the Service, which may limit access to all or part of the Service.
7. Destruction of personal information
- We destroy personal information without delay once it becomes unnecessary, such as when the retention period has elapsed or the processing purpose has been achieved. On account deletion, the Member's account information and Service content (chats, files, images, agent configurations, knowledge base, integration details, etc.) are deleted from our operational database and storage without delay by an automated process; information remaining in backups is handled under paragraph 4 below.
- The following are exceptions to destruction:
- Payment and transaction records: under the retention obligations of Korea's Act on Consumer Protection in Electronic Commerce, these are not deleted. Instead, fields that could identify an individual (payment trace number, payment approval key, payment page URL) are removed and the record is retained in anonymized form for the periods in Section 2. Only information needed for accounting — the fact, amount, and time of the transaction — remains.
- Administrator action logs: audit records of administrator actions taken on an account (plan changes, account deletion, granting or revoking administrator rights) may retain the email address of the affected account, for internal control and fraud prevention.
- All personal information other than the above is deleted on account deletion.
- Electronic files are destroyed using the following technical methods that make the records unrecoverable:
- Permanent deletion: the data is irrecoverably deleted from our database and storage.
- Cryptographic erase: information stored encrypted is destroyed by destroying the per-user encryption key, permanently making decryption impossible — including for any ciphertext remaining in backups.
- Information remaining in the backups of our processors (cloud service providers) is destroyed under each processor's procedures once its backup retention period elapses.
- Paper documents are shredded or incinerated.
8. Rights of data subjects and legal guardians
- Data subjects may at any time request to view, correct, delete, or suspend the processing of their personal information.
- Such requests can be made through in-Service settings, or in writing/by email to the Privacy Officer listed in Section 11; we will act on these requests without delay.
- Where a data subject requests correction or deletion of erroneous personal information, we will not use or provide that information until the correction or deletion is complete.
- We obtain consent from a legal guardian before processing personal information of a child under 14.
9. Measures to secure personal information
- Administrative: establishment and implementation of an internal management plan, the principle of least privilege for access to personal information, and server-side authorization checks that scope access to the owning user.
- Technical: encrypted transport (HTTPS/TLS), encrypted storage of credentials (via our authentication provider), envelope encryption of third-party integration credentials under a per-user data encryption key (DEK), with cryptographic erase on account deletion (Section 7), server-side ownership checks on every data access, blocking of unauthorized outbound requests (SSRF) including refusal of private IP ranges, IP-restricted access to administrative interfaces, and retention and tamper-protection of access logs.
- Physical: data is stored on infrastructure operated by our processors (Clerk, Convex, etc.), which maintain their own physical access controls.
10. Automatic data collection devices (cookies)
- We use cookies and similar technologies (such as browser local storage) for (i) maintaining login sessions (authentication), (ii) security and abuse prevention, and (iii) saving user preferences such as theme and language. Authentication cookies are required for using the signed-in parts of the Service.
- Data subjects may refuse cookies via their browser settings, which may make it difficult to use features that require login.
11. Privacy Officer
We have designated a Privacy Officer who is responsible for personal information processing and for handling data subjects' complaints and remedies.
- Privacy Officer: Inung Kang (강인웅), Representative (CEO)
- Responsible department: Privacy team (reporting to the CEO)
- Email: support@roadfinancial.co.kr
- Response time: without delay from receipt (with notice of the reason if unavoidable delay occurs)
Data subjects may direct any privacy-related inquiries, complaints, or requests for remedy to the Privacy Officer.
12. Remedies for infringement of rights
Data subjects may seek dispute resolution or consultation regarding personal information infringement from the following government bodies, which are independent of the Company:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.cyber.go.kr)
13. Changes to this Privacy Policy
This Privacy Policy is effective as of the date shown above. If there are additions, deletions, or corrections to this policy required by law or company decision, we will announce the changes within the Service at least 7 days before they take effect (at least 30 days for material changes).