Privacy Policy
This Privacy Policy explains the items of personal information collected, the purpose of use, retention period, provision to third parties, entrustment of processing, and the rights of users and how to exercise them during the use of the Notit service (hereinafter referred to as the “Service”) provided by the Company.
Notit's Privacy Principles
- Data minimization: We collect personal information only to the extent necessary to provide and operate the Service, and do not request information unrelated to the stated purposes.
- Purpose limitation: We use personal information only for the purposes described in this Policy. If a purpose changes, we follow the procedures required by applicable law.
- Secure storage and encryption: The Company uses Google Cloud as part of its service infrastructure. Customer content that the Company stores in Google Cloud is protected by default encryption at rest. Information entrusted to external service providers listed in Sections 5 and 6 may be processed on their systems, and personal information transmitted between the Service and our servers over the internet is protected using encrypted communications such as HTTPS/TLS.
- Limited access: Access to personal information is granted and managed only for personnel and systems with a job-related need.
- Limited retention: We securely dispose of personal information when its processing purpose is fulfilled or its retention period ends, except where applicable law requires separate retention.
- User control: Users may request access, correction, deletion, suspension of processing, withdrawal of consent, or account deletion at any time.
1. Items of Personal Information Processed
The Company collects only the minimum personal information necessary for each processing purpose, including providing the Service and meeting applicable legal obligations. We do not request information unrelated to the stated purposes and, where applicable, identify whether an item is required or optional.
1) Membership Registration and Account Management
- Required items: Email address, name or nickname, password or social login credentials
- Optional items: Profile image, preferred language, school or affiliation information
2) Information Collected During Service Provision
- Information generated or stored during service use, such as voice data (including recordings of classes made by users), uploaded files, transcriptions, translations, summaries, study materials, and notes
- Device IDs (including Android Advertising ID, app set ID, iOS IDFA and IDFV), device information, browser information, OS information, access logs, IP address, cookies, and service usage history
3) Payment and Paid Service Usage
- Payment status, transaction history, paid product information, payment method identifier
- ※ The Company may process sensitive payment information such as card numbers and account numbers through payment service providers without directly storing it.
4) Customer Support and Inquiry Responses
- Inquiry content, response history, attachments, report and dispute resolution records
5) Marketing and Notifications
- Email address, marketing consent status, campaign response information
6) Rewarded Advertising
- IP address; user interactions such as app launches, taps, and rewarded video views; and app and advertising SDK diagnostic information
- Device and account identifiers (including Android Advertising ID, app set ID, iOS IDFA and IDFV), device, OS and app information, and approximate location
- Advertising privacy consent status and ad reward processing records
- ※ The iOS IDFA is available only when App Tracking Transparency permission is granted. If permission is denied, non-personalised ads may still be served when allowed by the applicable privacy choices.
2. Purpose of Personal Information Processing
- Membership registration, identity verification, account management
- Service provision including voice transcription, translation, summarization, storage, and study material generation
- Paid service provision, payment processing, refund processing, subscription management
- Responding to customer inquiries, handling complaints, resolving disputes
- Preventing fraudulent use, conducting security checks, ensuring service stability
- Service improvement, statistical analysis, feature enhancement
- Using device IDs for third-party advertising, advertising and service usage analytics, and marketing
- Providing rewarded ads, measuring and analysing ad performance, preventing advertising fraud, and issuing ad rewards
- Providing marketing information such as events, benefits, and updates (only if separate consent is obtained)
How Class Recording Data Is Processed
- Recordings of classes made by users are stored with Google Cloud Storage's default encryption at rest.
- Other users cannot access, play, copy, or download a user's class recording data. The Company limits access to systems required to provide the Service and personnel with a job-related need.
- Class recording data is used only to generate outputs requested by the user, such as notes, Replay, and Exam Insights. It is not used for any other purpose, including AI training or analysis.
- Class recording data is converted to text to generate the outputs requested by the user. During this process, LLMs provided by OpenAI, Google, and others may read and transform the content.
- Class recording data is retained until the user deletes their account.
3. Processing and Retention Period of Personal Information
The Company retains and uses personal information until the purpose of collection and use is achieved. However, if retention for a specific period is required by relevant laws and regulations, it may be stored separately for that period.
| Category | Retention Period |
|---|---|
| Member Information | Until account deletion |
| Class Recording Data | Until account deletion |
| Marketing Communication Information | Until consent is withdrawn |
| Customer Inquiry and Dispute Resolution Records | 1 year after resolution or as required by applicable laws |
| Contract or subscription withdrawal, payment settlement, goods/service supply records | Retention period as required by relevant laws and regulations |
| Access logs and security records | Period necessary for security and service operation purposes or as required by relevant laws and regulations |
4. Provision of Personal Information to Third Parties
The Company does not, in principle, provide users' personal information to external parties. However, exceptions may apply in the following cases:
- When the user has given prior consent
- When required by special provisions of law or upon lawful request from state agencies such as investigative authorities
- When urgently necessary to protect the life, body, or property of the user or a third party
5. Outsourcing of Personal Information Processing
The Company may outsource certain tasks to external specialized companies to ensure smooth service provision. When entering into outsourcing agreements, the Company stipulates necessary requirements and supervises the contractor to ensure safe processing of personal information in accordance with relevant personal information protection laws and regulations.
| Contractor | Outsourced Tasks |
|---|---|
| Google Cloud | Server operation and data storage |
| Mailtrap | Email delivery |
| Paddle | Payment processing and refund processing |
| Google and OpenAI | AI processing including converting class recording data to text, translation, summarization, and generating outputs requested by the user |
| Google AdMob and Google User Messaging Platform | Rewarded ad delivery, consent management, ad measurement and analytics, and fraud prevention |
6. Cross-border Transfer of Personal Information
The Company may store personal information overseas or entrust its processing to overseas service providers during service operations. In such cases, the Company will notify users of the recipient, destination country, transferred items, purpose of transfer, and retention and usage period in accordance with relevant laws and regulations.
| Recipient | Destination Country | Items Transferred | Purpose of Transfer | Retention and Use Period |
|---|---|---|---|---|
| The aforementioned cloud and AI service providers | United States | Email, class recording data and its transcribed content, other service usage data, etc. | Service operation, data storage, and AI processing to generate outputs requested by the user | Until the outsourcing contract ends |
| Google LLC (AdMob and User Messaging Platform) | United States and other countries where Google provides its services | IP address, ad and app interactions, diagnostics, device and advertising identifiers, consent status | Ad delivery, consent management, performance analytics, and fraud prevention | For the period specified by Google's privacy policy and applicable law |
7. Procedures and Methods for Disposing of Personal Information
The company promptly disposes of personal information once its retention period expires or its processing purpose is fulfilled. However, if retention is required by relevant laws and regulations, the information will be separately stored.
- Electronic files: Securely deleted using methods that prevent recovery or regeneration
- Paper documents: Shredded or incinerated
8. User Rights and How to Exercise Them
Users may exercise the following rights with the company at any time.
- Request to access personal information
- Request to correct or delete personal information
- Request to suspend processing of personal information
- Request to withdraw consent
- Request to terminate membership
These rights may be requested through the contact information below, and the Company will take necessary measures without delay in accordance with relevant laws and regulations.
9. Measures to Ensure the Security of Personal Information
The Company takes the following technical and organizational measures, taking into account the service environment and level of risk, to protect the confidentiality, integrity, and availability of personal information.
- Default encryption at rest for customer content stored in Google Cloud
- Encrypted communications such as HTTPS/TLS for personal information transmitted over the internet
- Restriction and management of access to personnel and systems with a job-related need
- Protection of passwords, authentication information, and secrets
- Protection and review of access logs for service security
- Application of security updates and remediation of identified vulnerabilities
If a breach affecting personal information is confirmed, the Company will take steps to mitigate harm and follow required procedures, including notifying users and relevant authorities as required by applicable law.
Google states that the Google Cloud Services information security management system has undergone an independent third-party audit and received ISO/IEC 27001 certification. The certification is limited to the services within Google's published scope and does not certify the Company or Notit.
10. Use of Cookies and Similar Technologies
The Company may use cookies or similar technologies to provide services, offer a customized user experience, and analyze access patterns. Users may refuse cookie storage through their browser settings. Mobile app users can manage advertising identifier and personalised advertising choices through iOS App Tracking Transparency, Android advertising privacy controls, and the in-app privacy settings. However, refusing cookie storage may restrict access to certain services.
11. Children's Personal Information
The Company does not intentionally collect personal information from children under the age of 14. If the Company confirms that a child's personal information has been collected without the consent of a legal guardian, it will endeavor to delete such information without delay.
12. Chief Privacy Officer
| Name | Lloyd |
|---|---|
| Position | CIO |
| help@metaplad.com |
13. Remedies for Rights Violations
Users may contact the following agencies for reporting or consulting regarding personal information violations.
- Personal Information Infringement Reporting Center
- Personal Information Dispute Mediation Committee
- Supreme Prosecutors' Office
- National Police Agency
14. Changes to the Processing Policy
This Personal Information Processing Policy is effective as of August 13, 2026. The company will notify users of any additions, deletions, or modifications to the content via service announcements or separate notices.
