Privacy Policy

Effective: 2026-10-01

This English version is a convenience translation. If it differs from the Korean policy, the Korean text governs.

Chapter 1 General

Article 1 (Purpose and Scope)

  1. ①

    the operator of VikiEditor (the "Company") operates VikiEditor (the website vikieditor.piai.company, the mobile app, and the API including MCP connections; together the "Service"). This Privacy Policy (the "Policy") explains how the Company protects personal information in accordance with the Personal Information Protection Act of Korea and other applicable laws.

  2. ②

    The Policy applies to members who have signed up for the Service and to non-members who use it, for example by opening a document through a share link or reading a published blog post.

  3. ③

    The Policy describes which personal information the Company processes, for what purposes and for how long, whom it entrusts or discloses it to, and which rights you have and how to exercise them. The Policy is written in Korean; if a translation differs in meaning, the Korean text governs.

Article 2 (Purposes of Processing)

  1. The Company processes personal information only for the following purposes. If a purpose changes, the Company takes the measures required by Article 18 of the Personal Information Protection Act, such as obtaining separate consent.

    1. Sign-up, identity verification, keeping you signed in, account management and answering inquiries
    2. Core features: writing and storing documents, real-time co-editing (including showing who is editing), version history and restore
    3. Communication features: document sharing, blog publishing and visit statistics, comments, feedback and handoffs
    4. AI assistance (writing assistant, AI tables and diagrams) and, through MCP connections, letting AI agents you have authorized access your documents and showing you their activity
    5. Payments for paid plans, managing plan status and period, and refunds
    6. Notifications about agent replies, handoffs and comments, and service announcements
    7. Analyzing usage, improving features and diagnosing errors
    8. Preventing abuse, responding to security incidents, complying with legal obligations and resolving disputes

Chapter 2 Collection and Retention

Article 3 (Personal Information We Process)

  1. ①

    The Company processes the minimum personal information needed to provide the Service.

    1. Account: email, name, profile image, password (for email sign-up; stored as an irreversible hash), the account identifier provided by Google or GitHub when you sign up with them, and the language chosen at sign-up
    2. Profile and blog (optional): bio, website, blog address, title and description, and the "about you" (role and context) you give the writing assistant
    3. Content: documents, blocks, version history, comments and feedback, tags, images and attachments, links between documents, and the list of collaborators on a document
    4. Agent-integration records: API key names, key previews and last-used times; names of apps connected via OAuth; MCP session labels and the connected client's name and version; tool-call summaries (action, number of blocks added, removed and modified, changed sections, time). The Company does not collect your conversations with the AI client.
    5. GitHub integration (optional): your GitHub username and access token when you connect GitHub to push documents to a repository
    6. Payment: payment identifier, amount and currency, status and method, receipt URL, plan type and period. Card numbers and other payment-instrument details are handled by the payment processor (PortOne) and the payment gateway; the Company does not store them.
    7. Notifications: Web Push subscriptions (endpoint, encryption keys, browser information), device push tokens if you use the mobile app, and your notification list
    8. Usage records: access times, device, browser and OS type, screen size, screens visited and features used (PostHog analytics), cookie and local-storage values, server access logs
    9. Blog visit statistics: daily views, visitors and referrer domains per post. To tell visitors apart, only a key derived from the IP address and browser information with a daily-rotating secret is kept for 48 hours; the raw IP address and browser information are not stored.
  2. ②

    Personal information is collected in the following ways.

    1. Entered by you on sign-up and settings screens, or created as you write and upload documents in the Service
    2. Passed to the Company by Google or GitHub, with your consent, when you sign in with them
    3. Generated automatically as you use the Service (usage records, cookies, agent activity records, payment results)
    4. Sent by you to the support email
  3. ③

    The Company does not collect sensitive information (such as beliefs or health) or unique identifiers such as national ID numbers. What you write in documents is stored as content, so take care when putting other people's personal or sensitive information in a document.

Article 4 (Retention Period)

  1. ①

    The Company keeps personal information until the purpose of collection is fulfilled, that is, until you close your account or ask for deletion. When you close your account, the Company deletes your account information and content within 30 days.

  2. ②

    The following is kept differently.

    1. Document version history and deleted documents and blocks: kept while your account exists so you can restore them; deleted when you delete them permanently or close your account
    2. AI agent activity records: kept while your account exists, even after the document is deleted, so you can see which agent changed what
    3. Backups: the database and file storage are backed up regularly for disaster recovery, and each backup is deleted automatically 30 days after it is made. Deleted information may remain in backups during that period and is used only for recovery.
    4. Blog visitor keys: 48 hours
    5. OAuth authorization requests (10 minutes), expired authorization codes and tokens, and push subscriptions that fail delivery: deleted once expiry or failure is confirmed
  3. ③

    Information that must be kept under the law is stored separately for that period and then destroyed.

    1. Records on contracts and withdrawal of offers: 5 years (Act on Consumer Protection in Electronic Commerce)
    2. Records on payment and supply of goods or services: 5 years (same Act)
    3. Records on consumer complaints and dispute handling: 3 years (same Act)
    4. Records on labeling and advertising: 6 months (same Act)
    5. Service access logs: 3 months (Protection of Communications Secrets Act)

Chapter 3 Sharing, Processors and Transfers

Article 5 (Provision to Third Parties)

  1. ①

    The Company processes personal information only within the purposes in Article 2 and does not provide it to third parties unless you have separately consented or a law specifically requires it.

  2. ②

    In the following cases personal information reaches others because of your choice or the law.

    1. You publish a document through a share link or to your blog, or invite another member as a collaborator, so that the document and your name, profile and blog information are visible to them
    2. An AI client (such as Claude) that you allowed on the OAuth consent screen or connected with an API key reads or writes your documents over MCP (Article 7)
    3. You push a document to your own GitHub repository through the GitHub integration
    4. An investigative agency or court requests it through a lawful procedure

Article 6 (Processors and International Transfers)

  1. ①

    The Company entrusts the following processing to operate the Service, and supervises each processor through contracts and reviews so that it handles personal information safely.

    1. Vercel Inc. (US) — website hosting and CDN: access records, data transmitted while you use the Service
    2. Cloudflare, Inc. (US) — image and file storage (R2), network relay and security (Tunnel, CDN): images and attachments, access records
    3. PostHog, Inc. (US) — usage analytics: usage records, device and browser information, member identifier
    4. OpenAI, L.L.C. (US) — language-model processing for AI features: the text you submit to an AI feature and the document content that feature works on. Account information is not sent. Under operating policy, accounts of designated plans or roles are served by a local model the Company runs instead of an external provider.
    5. LangChain, Inc. (US, LangSmith) — storing processing traces to check the quality of AI features (only when enabled in operations settings): text submitted to AI features and their results
    6. Google LLC (US) — Google sign-in, mobile app push notifications (Firebase Cloud Messaging): account identifier, device push token, notification content
    7. GitHub, Inc. (US) — GitHub sign-in, document export: account identifier, exported documents
    8. Web Push services (your browser's provider, such as Google, Apple or Mozilla) — delivering Web Push notifications: push subscription, notification content
    9. PortOne (Republic of Korea) and the payment gateway of the payment channel — payment processing, verification and refunds: payment identifier, amount, payment-instrument details (handled directly by the gateway)
  2. ②

    Entrustment to the overseas processors in paragraph 1 is an international transfer of personal information. The items transferred are as listed in paragraph 1; the time and method of transfer is transmission over the network as you use the Service; the contact details of each recipient are in its privacy policy. The information is kept until the purpose of the entrustment is fulfilled or the contract with the processor ends.

  3. ③

    You may refuse international transfers by writing to support@piai.company. Refusing processing essential to the Service, such as hosting and storage, means the Service cannot be provided; optional processing such as AI features and usage analytics can be refused by not using the feature or by enabling tracking protection in your browser.

  4. ④

    The database (PostgreSQL) and cache (Redis) the Company runs itself are on servers the Company manages, with access limited to the fewest staff necessary.

Article 7 (AI Agent (MCP) Connections)

  1. ①

    You can connect AI clients such as Claude to the Service over MCP (Model Context Protocol). A connection is made when you allow permissions (read documents; create and edit documents) on the OAuth consent screen or enter an API key created in Settings. You can delete an API key in Settings or disconnect the Service from the AI client at any time.

  2. ②

    A connected AI client calls tools that read and write documents within the permissions you allowed. The Company processes the inputs of these tool calls (document identifiers, search terms, text to save) and their outputs (document content), and keeps a change summary (action, number of blocks added, removed and modified, changed sections) as an activity record so you can see which session changed which document and how. The document content just before a write is saved as a version for restoring.

  3. ③

    The Company does not receive or store your conversations with the AI client. It processes only what the AI client passes to the Company's tools. Information handled by the AI client itself is governed by the privacy policy of its provider (for example, Anthropic).

  4. ④

    Content that comes from outside your account, such as a document opened through a share link, is treated as untrusted and is marked when passed on so that instructions inside it do not change the AI agent's behavior. You should also take care when having an AI agent process documents of unclear origin.

  5. ⑤

    Feedback (comments) and handoffs you leave on a document may be delivered to and processed by the AI agents you have connected.

Chapter 4 Destruction and Security

Article 8 (Destruction of Personal Information)

  1. ①

    The Company destroys personal information without delay once the retention period has passed or the purpose of processing has been fulfilled.

  2. ②

    Electronic files are deleted in a way that cannot be recovered, and backups are deleted automatically on the schedule in Article 4, paragraph 2. The Company does not produce paper records; any that are produced are shredded or incinerated.

  3. ③

    Information that must be kept under the law is stored separately and destroyed the same way when the retention period ends.

Article 9 (Security Measures)

  1. The Company takes the following measures to process personal information safely.

    1. Passwords are stored as irreversible hashes; only the hash of an API key is stored, and the key itself is shown once, when it is created.
    2. Encryption in transit (HTTPS/TLS), secure cookie settings for sign-in tokens, and CSRF tokens
    3. OAuth 2.1 (PKCE) agent authentication, minimal permission scopes, and short-lived authorization requests (10 minutes, single use)
    4. Least-privilege access to the database and storage, with access logging
    5. Regular backups and a disaster-recovery procedure
    6. Limiting and training the staff who handle personal information

Chapter 5 Your Rights and Automatic Collection

Article 10 (Your Rights and How to Exercise Them)

  1. ①

    You may exercise the following rights over your personal information with the Company at any time.

    1. Access
    2. Correction or deletion of inaccurate information
    3. Suspension of processing
    4. Withdrawal of consent and account closure
  2. ②

    You can change your name, profile and blog information yourself in Settings, and delete documents, images and other content in the Service or take them with you using export. For other requests and account closure, email support@piai.company naming your account email; after verifying your identity the Company acts within 10 days and tells you the result.

  3. ③

    You may also exercise these rights through a legal representative or an authorized person, who must submit a power of attorney in the form prescribed by the Enforcement Rules of the Personal Information Protection Act.

  4. ④

    Rights may be limited where the information must be kept under the law or where exercising them would harm another person's life, body or property; the Company will explain the reason.

  5. ⑤

    You are responsible for keeping your personal information up to date and for not infringing other people's personal information.

Article 11 (Children Under 14)

  1. The Company does not collect personal information from children under 14, and children under 14 cannot sign up. If the Company learns that it has collected a child's personal information, it deletes it without delay.

Article 12 (Cookies and Local Storage)

  1. ①

    The Company uses cookies and browser local storage to keep you signed in and to analyze usage.

    1. Essential cookies: sign-in tokens (accessToken, refreshToken), signed-in and profile-complete flags, and the CSRF token. Without them you cannot stay signed in.
    2. Analytics cookies and storage (PostHog): a visitor identifier and session information, used only to improve the Service.
    3. Local storage: editor preferences such as theme, recent documents and editing options, kept only in your browser.
  2. ②

    You can refuse or delete cookies in your browser settings. Refusing essential cookies disables features that require signing in.

  3. ③

    The Company does not use behavioral information for targeted advertising.

Chapter 6 Officer and Remedies

Article 13 (Data Protection Officer)

  1. ①

    The Company designates the following data protection officer, who is responsible for personal information processing overall and handles complaints and remedies related to it.

    1. Data protection officer: the representative of the operator of VikiEditor (see the business information below)
    2. Email: support@piai.company
  2. ②

    You may direct any privacy-related inquiry, complaint or request for remedy arising from your use of the Service to the officer, and the Company will answer and act without delay.

Article 14 (Remedies for Infringement)

  1. For remedies or counseling regarding personal information infringement, you may contact the following Korean authorities.

    1. Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
    2. Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
    3. Supreme Prosecutors' Office, Cyber Investigation Division: 1301, www.spo.go.kr
    4. National Police Agency, Cyber Bureau: 182, ecrm.cyber.go.kr

Article 15 (Changes to This Policy)

  1. ①

    The Policy may change with the law, the Company's policies or the Service. Changes are announced in the Service at least 7 days before they take effect; material changes, such as collecting more items or using them for new purposes in a way that is worse for you, are announced 30 days ahead and also sent to the email registered on your account.

  2. ②

    Earlier versions of the Policy are available on request. The revision history is kept in the addendum at the end of the Policy.

This Policy takes effect on October 1, 2026.

Revision history: 2026-10-01 — first version

Business information

Company
to be registered
Representative
to be registered
Business registration no.
to be registered
Mail-order business no.
to be registered
Address
to be registered
Email
to be registered
Phone
to be registered