Privacy Policy
Effective: August 22, 2026 (revising the April 13, 2026 edition for unified accounts and subscriptions)
Article 1 (Purpose of Processing Personal Data)
MassLabs (the "Company") processes personal data for the purposes below. Data is not used for any purpose other than these, and if the purpose changes the Company will obtain separate consent and take any other measures required.
- Account management: sign-up, sign-in, identity verification, and unified authentication across every program the Company provides
- Service delivery: determining plan tier, managing credits, and linking devices for the Rhino plug-in
- Payment processing: charging service fees, recurring billing, refunds, and sending receipts
- Customer support: receiving enquiries and communicating outcomes
- Service analytics: improving the service using country-level usage data
- Data collection: verifying refund requests and improving product quality
Article 2 (Categories of Personal Data Collected)
- Personal data: email address, and the account identifier supplied by Google if you signed up with Google
- Usage data: plan tier, credit usage, country of access, and whether the free trial has been used
- Payment data: payment channel, currency and amount, payment method label, payment identifier, payment provider response records, and the billing key
- Device linking data: device identifier, linking code, and device name
- Data: output generated using MassLabs
- Automatically generated data: service usage records and access timestamps
Article 3 (Retention and Use Period)
- Account data: retained until you close your account, then destroyed without delay
- Payment and subscription data: retained for 5 years under the Act on Consumer Protection in Electronic Commerce, then destroyed
- Device linking data: destroyed when the device is unlinked or the account is closed. Device linking codes expire automatically 10 minutes after issue
- Data: destroyed when you close your account
- Country of access: retained in a form that cannot identify an individual once aggregated
Article 4 (Delegation of Personal Data Processing)
The Company delegates personal data processing as set out below in order to provide the service. Each processor is supervised so that personal data is handled safely in accordance with the Personal Information Protection Act.
- Supabase — account authentication and data storage
- Cloudflare — data storage
- Vultr — data storage
- Vercel — service hosting and operation
- PortOne — payments
Article 5 (Use of Cookies)
The Company uses cookies to keep you signed in. These cookies are shared by masslabs-archi.com and its subdomains, so signing in once keeps you signed in across every program the Company provides. You may refuse cookies in your browser settings. If you do, you will not be able to use services that require signing in.
Article 6 (Provision to Third Parties)
As a rule the Company does not provide your personal data to third parties. Exceptions apply only where you have given prior consent or where disclosure is required by law.
Article 7 (User Rights)
You can close your account and cancel your subscription yourself from the My Plan screen. For anything else — access to, correction of, deletion of, or suspension of processing of your personal data — send a request to masslabs.archi@gmail.com and we will act on it within 10 business days.
Article 8 (Destruction of Personal Data)
Personal data whose retention period has passed or whose purpose has been fulfilled is destroyed without delay. Electronic files are permanently deleted by a method that makes recovery impossible.
Article 9 (Security Measures)
- Passwords and plug-in authentication tokens are stored one-way hashed; the originals are never kept.
- All communication between you and the Company is encrypted with HTTPS.
- Row-level security (RLS) is applied to the database so that you can only reach your own records.
Article 10 (Data Protection Officer)
For enquiries about personal data processing, please contact: Representative: Baek Jonghwi | Email: masslabs.archi@gmail.com
Article 11 (Remedies for Rights Infringement)
You may contact the following bodies for relief from personal data infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Center: 118 / privacy.kisa.or.kr
- Supreme Prosecutors' Office: 1301 / www.spo.go.kr
- National Police Agency: 182 / ecrm.cyber.go.kr
Article 12 (Changes to This Policy)
This policy applies from its effective date. If it changes, notice will be given on the service at least 7 days before the change takes effect.