This summary is for convenience. The full text below governs.
Y2do ("Company") recognizes the importance of the personal information of Itdasy ("Service") users and establishes this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea (PIPA) and related laws.
Swipe horizontally to read the full table.
| Type | Items | Purpose | Retention |
|---|---|---|---|
| Required | Email, hashed password, name | Authentication, support | Until account deletion |
| Optional | Shop name, address, phone, Instagram handle, industry | AI caption personalization | Until account deletion |
| Auto-collected | IP, device info (model/OS), usage logs, cookies | Security, quality improvement | Login logs: 3 months. Member usage, action and generation records support limits, statistics, deduplication and work history until deletion request or account deletion, subject to statutory retention. Not every record automatically expires by age. |
| Billing | App Store/Play transaction IDs | Subscription status, refunds | 5 years (e-commerce law) |
Information entered by salon owners about their own customers is treated as entrusted processing on behalf of the owner as controller. Salon owners are responsible for obtaining valid consent from their end-customers before entering data into Itdasy.
Customer names identify bookings and records. Optional customer phone numbers, birthdays, notes and visit history support customer management. Review text entered by an owner is used for review management and requested caption drafts. Health notes such as allergies and treatment reactions require separate explicit consent from the customer and are eligible for scheduled content removal after 30 days when classified as medical notes. Customer linkage and record timestamps can remain. Automated classification may miss a note; owners can delete it or request removal. Other customer records remain until owner deletion or account deletion, subject to statutory retention.
This disclosure compares the operating configuration with official provider information as of October 1, 2026. Data retained by Itdasy and data processed by providers have separate deletion rules. Image-deletion periods below do not apply to every provider account, billing, security or backup record.
Swipe horizontally to read the full table.
| Provider / location | Purpose | Data |
|---|---|---|
| Google LLC / Google Cloud · Korea / US | Hosting, AI, push delivery | Service requests, AI inputs/responses, device push tokens; AI-specific terms below |
| Meta Platforms, Inc. · US / Ireland | Instagram connection, publishing, style analysis | User ID/name, posts, access tokens, photos and captions submitted for publication |
| Supabase, Inc. / Amazon Web Services · Korea | Database and photo storage | Account, customer, booking, revenue and photo records |
| Cloudflare, Inc. · Korea / US | Storage traffic protection and transport | Connection data and service requests |
Stored records follow Section 3. Disconnecting Instagram stops subsequent collection and publishing requests. Already published content can be managed in Instagram. Providers apply their own policies to account and security records.
Data / purpose: Text, photos, conversations, booking/revenue context and responses needed for selected caption, assistant, image-description, voice, recognition and DM features.
Location / retention: The primary request region is Seoul, Korea. Current Google guidance permits abuse-monitoring prompt retention for up to 90 days in the selected region. Search grounding has a separate 30-day retention period. We do not guarantee zero retention or an abuse-monitoring exemption.
Training: Google Cloud terms restrict model training or fine-tuning with customer data without prior permission or instruction. Authorized staff may review abuse-monitoring material.
Current route: Vertex AI quota or similar failures can switch requests to Gemini API. Billing is disabled for the fallback project, so unpaid-service terms must be distinguished from paid Vertex AI terms.
Training / review: Unpaid-service terms permit use of inputs and responses to improve Google products and machine-learning technologies, and human review. We cannot promise no training use for this route. Google instructs users not to submit personal, sensitive or confidential information to unpaid services.
Location / retention: Processing is not limited to Korea; it may take place in the US and other countries where Google or its agents operate. Abuse-monitoring prompts, context and responses are retained for 55 days. This is not a deletion deadline for all product-improvement data under unpaid terms.
If you do not accept these terms, stop using AI features and request AI processing suspension or consent withdrawal at contact@itdasy.com. Do not submit customer names, contact details, health information or identifying photos to this route.
Data / purpose: Photos, edit masks, settings and results for background removal, enhancement or inpainting. Itdasy requests inference, not training or fine-tuning on customer photos.
Retention: The documented API default deletes prediction inputs, outputs, files and logs within one hour after completion. Results and caches saved by Itdasy follow Section 3. This is not a one-hour deletion guarantee for all provider account/security records or backups.
Data / purpose: Background-removal photos and results, including fallback after Replicate failure. The provider states EU hosting; the exact processing datacenter country is not established by that statement alone.
Retention / training: The provider states API images are deleted immediately after processing; ordinary uploads within about one hour. Training contribution is a separate optional improvement program. Itdasy's removal API calls do not donate images to that program.
Data / purpose: Background-description prompt, image dimensions and generated results. The current route does not send the original treatment photo to fal.ai; Itdasy composites the generated background with that photo on its server. Personal information typed in the prompt is transmitted.
Retention: The public DPA's baseline is retention until contract termination unless otherwise agreed. CDN file expiry also depends on account/request settings. Access to verify this account's expiry settings was unavailable; we do not promise automatic deletion after a fixed number of hours or days. We forward deletion/suspension requests and communicate their status.
Training: API terms restrict use of client content to develop or train provider products, with exceptions for models designated as excluded from Enterprise Ready protection. We do not guarantee identical safeguards for every model.
DPA / retention · API / training terms · Expiry settings · support@fal.ai
Transfers occur when a selected AI feature or enabled auto-reply runs, through encrypted server-side HTTPS APIs. Required signup terms and AI choices are separate. AI choices are available through app Home/Settings, with additional notices for photo features. Declining AI does not prevent core customer, booking or revenue management. Where withdrawal is unavailable in-app, email contact@itdasy.com. Previously transmitted data follows provider retention/deletion rules and legal obligations; withdrawal does not instantly erase every external copy.
Some structured features remove or replace identifiers. DM replies can use a supplied name, and free-form text, photos and notes may contain names, faces or health information. We do not claim every AI input is anonymous.
Descriptions of public terms and DPAs do not certify a separately executed enterprise contract, valid consent for every transfer, an account-specific zero-retention approval, or readiness to offer services in every jurisdiction. Contact us before transfer if a specific country or safeguard is required. Clarifying this notice does not establish consent for a new collection or transfer.
itdasy.com is hosted on GitHub Pages (GitHub, Inc.). The hosting provider may process IP addresses and request information to deliver and secure pages. This marketing site has no separate registration, payment or email-collection form, and no advertising trackers. App and external-policy links take you to those services. GitHub privacy statement
We do not use third-party advertising or cross-site tracking cookies. First-party session tokens, preferences, local drafts and offline cache are used, along with error reporting described in this policy. Clearing OS/browser storage may require login again and permanently remove device-only drafts, settings and offline data. Save needed work first.
The Service uses Google AI, Replicate, remove.bg, fal.ai, and related processors for caption suggestions, assistant drafts, image processing, and other optional features. Provider-specific transfer, retention and training conditions are described in Section 2. These are advisory only and do not produce legal or financial effects without user confirmation. Users may decline feature-specific transfers or request consent withdrawal at contact@itdasy.com. Inappropriate AI output can be reported via the in-app 🚩 button; we review reports and communicate necessary follow-up.
Users may also contact the Korean Personal Information Dispute Mediation Committee (+82-1833-6972, kopico.go.kr) or KISA Privacy Complaint Center (118, privacy.kisa.or.kr).
The Service is not intended for children under 14. If we learn that a child under 14 has registered, we will immediately delete the account and all related data. Registration by children under 14 is not permitted.
In the event of a data breach, affected users will be notified via email and in-app notice within 72 hours, including details of what was leaked, mitigation steps, and contact information for reporting. Reportable incidents include 1,000+ affected individuals, sensitive or unique-identification data, and unlawful external access. Reports are made to the Personal Information Protection Commission/KISA within 72 hours, subject to statutory exceptions and supplementary reporting.
Material changes (new entrustment, expanded collection, longer retention) will be notified at least 30 days before taking effect, and re-consent will be requested where applicable. Other changes will be notified at least 7 days in advance via in-app announcement and email.
Swipe horizontally to read the full table.
| Version | Effective | Changes |
|---|---|---|
| v1.4 | 2026-10-01 | Corrected AI fallback, provider retention/training, fal.ai data scope, operational record retention and breach reporting. Does not establish new collection/transfer consent. |
| v1.3 | 2026-10-01 | Clarified marketing-site access processing, consent and rights-request guidance, on-device data deletion and retention descriptions. No new collection purpose or items |
| v1.2 | 2026-09-15 | Corrected processors, AI consent, deletion status, and security descriptions to match the current system |
| v1.1 | 2026-04-22 | Added GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), APPI (Japan), PIPEDA (Canada), Australia Privacy Act regional notices |
| v1.0 | 2026-04-22 | Initial publication — full PIPA compliance framework |
Swipe horizontally to read the full table.
| Purpose | Legal Basis |
|---|---|
| Account creation, authentication, service delivery | Art. 6(1)(b) — Contract performance |
| Billing (IAP transaction records) | Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation (tax) |
| AI processing via Google Gemini (captions, assistant) | Art. 6(1)(a) — Separate AI choice before use; not bundled into required signup terms |
| Cross-border data transfer to US providers | Applicable Chapter V transfer basis and safeguards, assessed for the provider and route; no blanket claim of executed SCCs |
| Security, fraud prevention, error monitoring | Art. 6(1)(f) — Legitimate interest (service integrity) |
| End-customer data entered by salon owners | Processor role under Art. 28 — owner as controller, Y2do as processor |
| Health-related notes about end-customers (e.g. allergies, treatment reactions) | Special category data under Art. 9 — the salon owner must obtain the customer's explicit consent before entering it. Medical-classified content is eligible for scheduled removal after 30 days; linkage and timestamps can remain, and missed classification requires owner deletion or a removal request. |
We respond to all verified requests free of charge within 30 days.
Swipe horizontally to read the full table.
| Category (§1798.140) | Collected? | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| A. Identifiers (name, email, user ID) | Yes | You | Account, service | Processors (Supabase, Google Cloud) |
| B. §1798.80 customer records | Yes | You | Billing, support | Apple/Google (IAP); processors |
| D. Commercial info (purchase history) | Yes | Apple/Google stores | Billing, subscription | Apple, Google |
| F. Internet/network activity (error logs) | Limited | Device | Security/debug | Sentry |
| G. Geolocation | No | — | — | — |
| I. Professional/employment | Yes (shop info) | You | Personalization | Processors |
| K. Inferences (retention risk) | Limited | Your usage | Churn alerts | Not shared |
| L. Sensitive Personal Info — health-related customer notes | May be entered with separate explicit consent | Salons entering customer notes | Treatment precautions and requested note processing | Storage and AI processors as described in Sections 1–2 |
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. If our practices change, we will update this Policy and provide an opt-out in the app.
Exercise rights: email contact@itdasy.com with subject "CCPA Request — [right]". We verify identity by email confirmation and respond within 45 days.
We do not disclose PI to third parties for their direct marketing, so no such disclosure is required.
We do not knowingly collect PI from users under 16 without affirmative consent (CPRA). Users under 14 are prohibited from registering (see Section 8).
You have rights analogous to GDPR — confirmation, access, correction, anonymization, portability, deletion, information on sharing, and revocation of consent. Exercise via contact@itdasy.com. Complaints: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.
Where PIPEDA or provincial privacy laws apply, residents may exercise access, correction and consent-withdrawal rights. Complaints: Office of the Privacy Commissioner of Canada — priv.gc.ca.
Where Australian privacy law applies, residents may exercise rights under the Australian Privacy Principles (APPs). Complaints: OAIC — oaic.gov.au.
We use only strictly necessary first-party storage to operate the service (session JWT, preference settings, offline cache). We do not use cross-site tracking cookies, advertising identifiers, or third-party analytics for profiling. Optional device error diagnostics can be managed in the app privacy/diagnostics settings. Declining does not affect core functionality. Server security and operational logs are distinct from optional device diagnostics.