(주) 스프링웨어 (the "Company") complies with applicable data protection laws including the Personal Information Protection Act of Korea, and establishes and discloses this Privacy Policy to protect the personal information of data subjects and to handle related concerns promptly. This policy applies to the Springware IVE service (the "Service") provided by the Company.
1. Personal Information Collected and Methods of Collection
The Company collects the following personal information during sign-up, service provision, and external repository integration.
- ·Email sign-up: email address, name, password (stored as a non-reversible hash)
- ·Social login (GitHub, GitLab, Slack): email address, name, profile image, social account identifier (provider user ID), Slack member ID, OAuth access/refresh tokens
- ·External repository integration: GitHub/GitLab access tokens (stored encrypted)
- ·Information generated automatically during use: IP address, browser information (User-Agent), cookies, usage records (activity logs, task execution records), and access timestamps
- ·Optional information: preference settings such as language, time zone, and display currency
2. Purpose of Collection and Use
- ·Member identification, authentication, and maintaining login sessions
- ·Service provision — automated issue processing, AI agent execution, and integration with external repositories (GitHub/GitLab) including issue and merge/pull request handling
- ·Sending email verification codes, notifications, and report emails
- ·Sending task notifications via Slack (DM/mention)
- ·Generating usage statistics and cost/work reports
- ·Security, prevention of misuse, ensuring service stability, and dispute resolution
3. Retention and Use Period
In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, the following information is retained for the periods stated.
- ·Member information: until account deletion (withdrawal). Upon withdrawal, the member's account and associated data (projects, agents, task execution records, etc.) are deleted immediately.
- ·Usage records (activity logs): 90 days from collection
- ·Task execution records: per the retention period configured for each project
- ·Email verification codes: 10 minutes after issuance (deleted upon verification or expiry)
- ·Where applicable laws require retention for a certain period, for the period prescribed by such laws
4. Provision to Third Parties and Entrustment
The Company does not use personal information beyond the purposes disclosed herein, nor does it sell it externally. However, data is exchanged with the following external services to provide the Service.
- ·GitHub / GitLab: For repositories the user has integrated, task data such as issues, comments, and merge/pull requests is exchanged. Processing is limited to the scope of the access token (or OAuth authorization) provided by the user.
- ·Slack: Member ID and message content are sent to the Slack API to deliver task notifications (DM, channel mentions).
- ·Email (SMTP) delivery: Verification codes, notifications, and report emails are sent to recipient email addresses.
- ·These external services are not operated by the Company; each provider's own privacy practices apply to their processing.
5. Destruction Procedure and Method
- ·Procedure: Personal information whose retention period has elapsed or whose purpose has been achieved is destroyed without delay in accordance with internal policy.
- ·Method: Information in electronic file form is permanently deleted using a method that prevents recovery or restoration.
6. Rights of Data Subjects and How to Exercise Them
Data subjects may exercise the following rights regarding their personal information at any time.
- ·Request access to, correction/deletion of, or suspension of processing of personal information
- ·Within the Service, you can directly edit certain information such as your name, avatar, and email on the 'My Info' screen.
- ·You may request account deletion (withdrawal); upon processing, the account and associated data are deleted.
- ·Requests may be made in writing or by email to the Data Protection Officer below, and the Company will act without delay.
7. Security Measures
- ·Passwords are stored as a one-way, non-reversible hash (bcrypt).
- ·Sensitive information such as OAuth tokens and external repository access tokens is stored encrypted with AES-256-GCM.
- ·Transport encryption (HTTPS) is applied, and authentication sessions are managed via HttpOnly cookies.
- ·Access to systems processing personal information is limited to a minimal number of personnel.
8. Use of Cookies
The Company uses cookies to maintain login sessions and for security.
- ·Authentication session cookie (ive-token): used to maintain login state, valid for 7 days after issuance (HttpOnly).
- ·OAuth state cookie (ive-oauth-state): used temporarily to secure the social login process (CSRF protection) and deleted immediately upon completion.
- ·You may refuse cookie storage through your browser settings, but doing so may restrict certain services such as login.
9. Data Protection Officer
For inquiries, complaints, or remedies regarding the processing of personal information, please contact the officer below.
- ·Data Protection Officer: 개인정보 보호책임자
- ·Email: privacy@dazzleat.link
- ·Address: 서울특별시 관악구 남부순환로247 나길 35, 301호
10. Duty to Notify
If this Privacy Policy is amended, added to, or deleted, the changes will be announced within the Service before they take effect.