한국어

Privacy Policy

Itdasy — operated by Y2do
Effective Date: April 22, 2026
Last Updated: October 1, 2026
Operator: Y2do · Business Registration No. 179-36-01681 · Representative: Yeonjun Kang
Contact: contact@itdasy.com
Original Language: Korean (see Korean version). This English version is for reference; the Korean original prevails in case of discrepancy.

At a glance

This summary is for convenience. The full text below governs.

Y2do ("Company") recognizes the importance of the personal information of Itdasy ("Service") users and establishes this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea (PIPA) and related laws.

1. Information We Collect and Purpose

1-1. Member (salon owner) data

Swipe horizontally to read the full table.

TypeItemsPurposeRetention
RequiredEmail, hashed password, nameAuthentication, supportUntil account deletion
OptionalShop name, address, phone, Instagram handle, industryAI caption personalizationUntil account deletion
Auto-collectedIP, device info (model/OS), usage logs, cookiesSecurity, quality improvementLogin logs: 3 months. Member usage, action and generation records support limits, statistics, deduplication and work history until deletion request or account deletion, subject to statutory retention. Not every record automatically expires by age.
BillingApp Store/Play transaction IDsSubscription status, refunds5 years (e-commerce law)

1-2. End-customer data (processed on behalf of salon owners)

Information entered by salon owners about their own customers is treated as entrusted processing on behalf of the owner as controller. Salon owners are responsible for obtaining valid consent from their end-customers before entering data into Itdasy.

Customer names identify bookings and records. Optional customer phone numbers, birthdays, notes and visit history support customer management. Review text entered by an owner is used for review management and requested caption drafts. Health notes such as allergies and treatment reactions require separate explicit consent from the customer and are eligible for scheduled content removal after 30 days when classified as medical notes. Customer linkage and record timestamps can remain. Automated classification may miss a note; owners can delete it or request removal. Other customer records remain until owner deletion or account deletion, subject to statutory retention.

2. Processors and International Transfers

This disclosure compares the operating configuration with official provider information as of October 1, 2026. Data retained by Itdasy and data processed by providers have separate deletion rules. Image-deletion periods below do not apply to every provider account, billing, security or backup record.

Swipe horizontally to read the full table.

Provider / locationPurposeData
Google LLC / Google Cloud · Korea / USHosting, AI, push deliveryService requests, AI inputs/responses, device push tokens; AI-specific terms below
Meta Platforms, Inc. · US / IrelandInstagram connection, publishing, style analysisUser ID/name, posts, access tokens, photos and captions submitted for publication
Supabase, Inc. / Amazon Web Services · KoreaDatabase and photo storageAccount, customer, booking, revenue and photo records
Cloudflare, Inc. · Korea / USStorage traffic protection and transportConnection data and service requests

Stored records follow Section 3. Disconnecting Instagram stops subsequent collection and publishing requests. Already published content can be managed in Instagram. Providers apply their own policies to account and security records.

2-1. AI-specific transfers, retention and training

Google Cloud Vertex AI (Gemini)

Data / purpose: Text, photos, conversations, booking/revenue context and responses needed for selected caption, assistant, image-description, voice, recognition and DM features.

Location / retention: The primary request region is Seoul, Korea. Current Google guidance permits abuse-monitoring prompt retention for up to 90 days in the selected region. Search grounding has a separate 30-day retention period. We do not guarantee zero retention or an abuse-monitoring exemption.

Training: Google Cloud terms restrict model training or fine-tuning with customer data without prior permission or instruction. Authorized staff may review abuse-monitoring material.

Abuse monitoring · Data governance

Google Gemini API — failure fallback

Current route: Vertex AI quota or similar failures can switch requests to Gemini API. Billing is disabled for the fallback project, so unpaid-service terms must be distinguished from paid Vertex AI terms.

Training / review: Unpaid-service terms permit use of inputs and responses to improve Google products and machine-learning technologies, and human review. We cannot promise no training use for this route. Google instructs users not to submit personal, sensitive or confidential information to unpaid services.

Location / retention: Processing is not limited to Korea; it may take place in the US and other countries where Google or its agents operate. Abuse-monitoring prompts, context and responses are retained for 55 days. This is not a deletion deadline for all product-improvement data under unpaid terms.

If you do not accept these terms, stop using AI features and request AI processing suspension or consent withdrawal at contact@itdasy.com. Do not submit customer names, contact details, health information or identifying photos to this route.

Paid / unpaid API terms · 55-day abuse monitoring

Replicate, LLC · US

Data / purpose: Photos, edit masks, settings and results for background removal, enhancement or inpainting. Itdasy requests inference, not training or fine-tuning on customer photos.

Retention: The documented API default deletes prediction inputs, outputs, files and logs within one hour after completion. Results and caches saved by Itdasy follow Section 3. This is not a one-hour deletion guarantee for all provider account/security records or backups.

API retention · Privacy / privacy@replicate.com · Terms

remove.bg / Canva Austria GmbH · Austria (EU)

Data / purpose: Background-removal photos and results, including fallback after Replicate failure. The provider states EU hosting; the exact processing datacenter country is not established by that statement alone.

Retention / training: The provider states API images are deleted immediately after processing; ordinary uploads within about one hour. Training contribution is a separate optional improvement program. Itdasy's removal API calls do not donate images to that program.

API deletion · Training · Privacy / contact

fal.ai / Features & Labels, Inc. · US

Data / purpose: Background-description prompt, image dimensions and generated results. The current route does not send the original treatment photo to fal.ai; Itdasy composites the generated background with that photo on its server. Personal information typed in the prompt is transmitted.

Retention: The public DPA's baseline is retention until contract termination unless otherwise agreed. CDN file expiry also depends on account/request settings. Access to verify this account's expiry settings was unavailable; we do not promise automatic deletion after a fixed number of hours or days. We forward deletion/suspension requests and communicate their status.

Training: API terms restrict use of client content to develop or train provider products, with exceptions for models designated as excluded from Enterprise Ready protection. We do not guarantee identical safeguards for every model.

DPA / retention · API / training terms · Expiry settings · support@fal.ai

2-2. Timing, method, refusal and withdrawal

Transfers occur when a selected AI feature or enabled auto-reply runs, through encrypted server-side HTTPS APIs. Required signup terms and AI choices are separate. AI choices are available through app Home/Settings, with additional notices for photo features. Declining AI does not prevent core customer, booking or revenue management. Where withdrawal is unavailable in-app, email contact@itdasy.com. Previously transmitted data follows provider retention/deletion rules and legal obligations; withdrawal does not instantly erase every external copy.

2-3. Identifiers and contractual scope

Some structured features remove or replace identifiers. DM replies can use a supplied name, and free-form text, photos and notes may contain names, faces or health information. We do not claim every AI input is anonymous.

Descriptions of public terms and DPAs do not certify a separately executed enterprise contract, valid consent for every transfer, an account-specific zero-retention approval, or readiness to offer services in every jurisdiction. Contact us before transfer if a specific country or safeguard is required. Clarifying this notice does not establish consent for a new collection or transfer.

3. Retention and Deletion

4. Your Rights

5. Security Measures

5-1. Marketing website

itdasy.com is hosted on GitHub Pages (GitHub, Inc.). The hosting provider may process IP addresses and request information to deliver and secure pages. This marketing site has no separate registration, payment or email-collection form, and no advertising trackers. App and external-policy links take you to those services. GitHub privacy statement

6. Cookies and Tracking

We do not use third-party advertising or cross-site tracking cookies. First-party session tokens, preferences, local drafts and offline cache are used, along with error reporting described in this policy. Clearing OS/browser storage may require login again and permanently remove device-only drafts, settings and offline data. Save needed work first.

6-bis. Automated Decision-Making (AI Disclosure)

The Service uses Google AI, Replicate, remove.bg, fal.ai, and related processors for caption suggestions, assistant drafts, image processing, and other optional features. Provider-specific transfer, retention and training conditions are described in Section 2. These are advisory only and do not produce legal or financial effects without user confirmation. Users may decline feature-specific transfers or request consent withdrawal at contact@itdasy.com. Inappropriate AI output can be reported via the in-app 🚩 button; we review reports and communicate necessary follow-up.

7. Data Protection Officer

Users may also contact the Korean Personal Information Dispute Mediation Committee (+82-1833-6972, kopico.go.kr) or KISA Privacy Complaint Center (118, privacy.kisa.or.kr).

8. Children's Privacy

The Service is not intended for children under 14. If we learn that a child under 14 has registered, we will immediately delete the account and all related data. Registration by children under 14 is not permitted.

9. Data Breach Notification

In the event of a data breach, affected users will be notified via email and in-app notice within 72 hours, including details of what was leaked, mitigation steps, and contact information for reporting. Reportable incidents include 1,000+ affected individuals, sensitive or unique-identification data, and unlawful external access. Reports are made to the Personal Information Protection Commission/KISA within 72 hours, subject to statutory exceptions and supplementary reporting.

10. Changes to this Policy

Material changes (new entrustment, expanded collection, longer retention) will be notified at least 30 days before taking effect, and re-consent will be requested where applicable. Other changes will be notified at least 7 days in advance via in-app announcement and email.

Swipe horizontally to read the full table.

VersionEffectiveChanges
v1.42026-10-01Corrected AI fallback, provider retention/training, fal.ai data scope, operational record retention and breach reporting. Does not establish new collection/transfer consent.
v1.32026-10-01Clarified marketing-site access processing, consent and rights-request guidance, on-device data deletion and retention descriptions. No new collection purpose or items
v1.22026-09-15Corrected processors, AI consent, deletion status, and security descriptions to match the current system
v1.12026-04-22Added GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), APPI (Japan), PIPEDA (Canada), Australia Privacy Act regional notices
v1.02026-04-22Initial publication — full PIPA compliance framework

11. Notice to EU/EEA and UK Residents (GDPR / UK GDPR)

11-1. Controller and Contact

11-2. Legal Bases for Processing (Art. 6)

Swipe horizontally to read the full table.

PurposeLegal Basis
Account creation, authentication, service deliveryArt. 6(1)(b) — Contract performance
Billing (IAP transaction records)Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation (tax)
AI processing via Google Gemini (captions, assistant)Art. 6(1)(a) — Separate AI choice before use; not bundled into required signup terms
Cross-border data transfer to US providersApplicable Chapter V transfer basis and safeguards, assessed for the provider and route; no blanket claim of executed SCCs
Security, fraud prevention, error monitoringArt. 6(1)(f) — Legitimate interest (service integrity)
End-customer data entered by salon ownersProcessor role under Art. 28 — owner as controller, Y2do as processor
Health-related notes about end-customers (e.g. allergies, treatment reactions)Special category data under Art. 9 — the salon owner must obtain the customer's explicit consent before entering it. Medical-classified content is eligible for scheduled removal after 30 days; linkage and timestamps can remain, and missed classification requires owner deletion or a removal request.

11-3. Your Rights under GDPR / UK GDPR

We respond to all verified requests free of charge within 30 days.

11-4. International Data Transfers (Chapter V)

11-5. Supervisory Authorities (non-exhaustive)

12. Notice to California Residents (CCPA / CPRA)

12-1. Categories of Personal Information Collected (last 12 months)

Swipe horizontally to read the full table.

Category (§1798.140)Collected?SourcePurposeDisclosed to
A. Identifiers (name, email, user ID)YesYouAccount, serviceProcessors (Supabase, Google Cloud)
B. §1798.80 customer recordsYesYouBilling, supportApple/Google (IAP); processors
D. Commercial info (purchase history)YesApple/Google storesBilling, subscriptionApple, Google
F. Internet/network activity (error logs)LimitedDeviceSecurity/debugSentry
G. GeolocationNo———
I. Professional/employmentYes (shop info)YouPersonalizationProcessors
K. Inferences (retention risk)LimitedYour usageChurn alertsNot shared
L. Sensitive Personal Info — health-related customer notesMay be entered with separate explicit consentSalons entering customer notesTreatment precautions and requested note processingStorage and AI processors as described in Sections 1–2

12-2. "Do Not Sell or Share My Personal Information"

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. If our practices change, we will update this Policy and provide an opt-out in the app.

12-3. Your CCPA / CPRA Rights

Exercise rights: email contact@itdasy.com with subject "CCPA Request — [right]". We verify identity by email confirmation and respond within 45 days.

12-4. Shine the Light (Cal. Civ. Code §1798.83)

We do not disclose PI to third parties for their direct marketing, so no such disclosure is required.

12-5. Minors

We do not knowingly collect PI from users under 16 without affirmative consent (CPRA). Users under 14 are prohibited from registering (see Section 8).

13. Notice to Brazilian Residents (LGPD — Law 13.709/2018)

You have rights analogous to GDPR — confirmation, access, correction, anonymization, portability, deletion, information on sharing, and revocation of consent. Exercise via contact@itdasy.com. Complaints: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.

14. Notice to Japanese Residents (APPI — 個人情報の保護に関する法律)

15. Notice to Canadian Residents (PIPEDA)

Where PIPEDA or provincial privacy laws apply, residents may exercise access, correction and consent-withdrawal rights. Complaints: Office of the Privacy Commissioner of Canada — priv.gc.ca.

16. Notice to Australian Residents (Privacy Act 1988)

Where Australian privacy law applies, residents may exercise rights under the Australian Privacy Principles (APPs). Complaints: OAIC — oaic.gov.au.

17. Children's Privacy — Multi-jurisdictional

18. Cookies, Tracking, and Consent

We use only strictly necessary first-party storage to operate the service (session JWT, preference settings, offline cache). We do not use cross-site tracking cookies, advertising identifiers, or third-party analytics for profiling. Optional device error diagnostics can be managed in the app privacy/diagnostics settings. Declining does not affect core functionality. Server security and operational logs are distinct from optional device diagnostics.

19. Security — International Standards

v1.4 — 2026-10-01: corrected provider and operational disclosures; no new collection purpose or subscription obligation.
The original text of this policy is in Korean. This English translation is provided for convenience only. In case of any discrepancy, the Korean version shall prevail.

Last updated: October 1, 2026 (v1.4).