Privacy Policy
Last updated: June 12, 2026
This Privacy Policy explains how Seoultokyo("Seoultokyo," "we," "us," or "our"), a financial-filing intelligence service available at https://seoultokyo.ioand in our mobile apps (the "Service"), collects, uses, stores, shares, and protects your information. By using the Service you agree to this Policy.
1. Who We Are
Seoultokyo provides readable summaries and indicators built from public corporate disclosures (U.S. SEC EDGAR, Korea OpenDART, and upcoming Japan sources). For privacy questions, contact us at [email protected].
2. Information We Collect
2.1 Account information
- Google Sign-In:when you choose "Continue with Google," we receive your basic Google profile: your name, email address, profile picture, and Google account identifier.
- Email sign-up: your email address and a one-time verification code.
- Passkeys (WebAuthn): a public-key credential and credential identifier used for passwordless sign-in. We never receive or store your biometrics or device PIN.
2.2 Service data
- Watchlists, alert subscriptions, language and market preferences.
- Subscription status for paid plans (we do not store your card or bank details).
- Push notification device tokens, where you enable alerts.
2.3 Technical data
- IP address, device and browser type, and request logs used for security and abuse prevention.
- Cookies and local storage used to keep you signed in and remember preferences (no advertising cookies).
3. Google User Data
When you sign in with Google, we request only the name, email address, and basic profile scopes. We use this data solely to create and authenticate your Seoultokyo account and to display your name and profile picture inside the app.
- We do not access your Gmail, Google Drive, Calendar, Contacts, or any other Google service.
- We do not use Google user data for advertising.
- We do not sell Google user data or transfer it to data brokers.
- We do not use Google user data to train generalized AI/ML models.
Limited Use disclosure.Seoultokyo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Information
- Create, authenticate, and secure your account (including Google Sign-In and passkeys).
- Provide the Service: deliver filing summaries, watchlists, and alerts you request.
- Process and manage paid subscriptions through our payment processor.
- Send transactional messages (verification codes, security and account notices).
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our Terms of Service.
5. How We Share Information
We do not sell your personal information. We share it only with service providers who process it on our behalf under contract:
- Supabase — authentication and database storage.
- Hanko — passkey (WebAuthn) credential management.
- Railway — application hosting.
- Cloudflare — content delivery, DNS, and security/WAF.
- PayPal — subscription payment processing (PayPal handles your payment details directly under its own privacy policy).
- Resend / Brevo — delivery of verification and transactional emails.
We may also disclose information if required by law, to protect our rights and users' safety, or in connection with a corporate transaction, subject to this Policy.
6. Data Retention
We keep account and service data while your account is active. When you delete your account, we delete associated personal data within 30 days, except where retention is required by law (for example, tax or transaction records) or to resolve disputes and enforce agreements.
7. Security
- Encryption in transit (HTTPS/TLS) for all traffic.
- Passwordless sign-in with passkeys; we do not store plaintext passwords.
- Row-level security on user data and least-privilege service access.
- Edge WAF, rate limiting, and continuous monitoring.
No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard measures.
8. Your Rights and Choices
- Access, correct, or update your account information in the app.
- Delete your account and associated data — see our Data Deletion page.
- Revoke Google access at any time via your Google Account permissions.
- Disable alerts and marketing-style messages in settings.
Depending on your location, you may have additional rights under the GDPR (EU/EEA), the CCPA/CPRA (California), or Korea's PIPA. To exercise any right, contact [email protected].
9. International Transfers
Your information may be processed in countries other than your own, including the United States and the Republic of Korea. We rely on appropriate safeguards for such transfers.
10. Children
The Service is not directed to children under 14, and we do not knowingly collect their personal information.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted here with an updated "Last updated" date.
12. Contact
Privacy questions or requests: [email protected].
개인정보처리방침 (요약 · 한국어)
Seoultokyo(이하 "회사")는 SEC·OpenDART 등 공개 공시 데이터를 읽기 쉽게 제공하는 서비스입니다. 이용자의 개인정보를 다음과 같이 처리합니다.
수집 항목
- Google 로그인 시: 이름, 이메일, 프로필 사진, Google 계정 식별자
- 이메일 가입 시: 이메일 주소, 인증코드
- 패스키(WebAuthn): 공개키 자격증명 (생체정보·PIN은 수집하지 않음)
- 서비스 이용 정보: 관심종목, 알림 설정, 언어·시장 설정, 구독 상태, 기기 토큰
- 기술 정보: IP, 기기·브라우저 정보, 접속 로그 (보안 목적)
이용 목적
- 회원 가입·인증·보안 (Google 로그인, 패스키 포함)
- 공시 요약·관심종목·알림 등 서비스 제공
- 유료 구독 결제 처리, 거래성 안내 발송
- 부정 이용·보안 사고 방지, 법적 의무 준수
Google 데이터 이용
Google 로그인으로 받은 정보(이름·이메일·기본 프로필)는 계정 생성·인증 목적으로만 사용하며, Gmail·Drive 등 다른 Google 서비스에 접근하지 않고, 광고에 사용하거나 판매하지 않습니다. 회사의 Google API 정보 이용은 Google API Services User Data Policy(Limited Use 포함)를 준수합니다.
제3자 처리위탁
Supabase(인증·DB), Hanko(패스키), Railway(호스팅), Cloudflare(보안·CDN), PayPal(결제), Resend·Brevo(이메일 발송).
보유 기간 및 파기
회원 탈퇴 시 관련 개인정보를 30일 이내 파기합니다(법령상 보관 의무가 있는 경우 예외).
이용자 권리
열람·정정·삭제·처리정지를 요청할 수 있으며, 데이터 삭제 페이지 또는 [email protected]로 요청할 수 있습니다.
