AkasicDB Playground Privacy Policy
The Korean version is the controlling text for regulatory compliance purposes; this English version is provided for the convenience of non-Korean speakers.
Effective date: May 22, 2026 (draft)
GraphAI, Co., Ltd. ("GraphAI", "we", "us") complies with the Personal Information Protection Act and related laws and regulations of the Republic of Korea, and is committed to protecting the personal information and rights of data subjects. This Privacy Policy (the "Policy") explains how we collect, use, store, and disclose personal information in connection with the AkasicDB Playground service (the "Service").
1. Purposes of Processing
We process personal information for the following purposes only. Personal information will not be used for any purpose other than those listed below; if the purpose of processing changes, we will obtain separate consent or take other measures required by PIPA Article 18.
- Account registration and management — verifying intent to register, identifying and authenticating users, maintaining accounts, preventing fraudulent use, sending notices, and handling grievances.
- Provision of the Service — creating, operating, stopping, and deleting AkasicDB trial instances; providing SQL query functionality; issuing access credentials.
- Product improvement and marketing — developing new features and tailored services; serving demographic-based notices; measuring service effectiveness and usage statistics.
- Grievance handling — verifying complainant identity, confirming complaint details, contacting complainants for fact-finding, and notifying them of outcomes.
- Legal compliance — fulfilling obligations under applicable laws and retaining records for the resolution of disputes.
2. Categories of Personal Information Processed
2.1 Collected at sign-up
| Type | Items | Legal basis |
|---|---|---|
| Required | Email address, password (stored hashed), full name, company | Consent of the data subject (PIPA §15(1)(1)) |
| Optional | Job role, intended use case, how the user heard about the Service | Consent of the data subject |
2.2 Collected via social sign-in (OAuth)
When you sign in with GitHub or Google, we receive the following items from the identity provider, limited to the scopes you authorize.
- GitHub: email address, username (login), display name, profile image URL.
- Google: email address, display name, profile image URL.
2.3 Automatically generated or collected during use
- Service usage records, access logs, IP addresses, cookies and session tokens.
- Instance metadata (creation, start, stop, and termination timestamps; assigned ports).
- Query usage patterns and frequency statistics. Individual SQL query texts are recorded only transiently when operationally necessary and are not retained in identifiable form after statistical processing.
- Browser type, operating system, and device identifiers.
2.4 Sensitive information and unique identifiers
We do not collect "sensitive information" under PIPA Article 23 (ideology, beliefs, union or political-party affiliation, political opinions, health, sex life, etc.) or "unique identifiers" under PIPA Article 24 (resident registration number, passport number, driver's license number, foreigner registration number).
3. Retention and Use Periods
We retain personal information for the period agreed to by the data subject or required by law, whichever applies.
| Purpose | Retention period | Basis |
|---|---|---|
| Account registration and management | Until account deletion | Data subject consent |
| Records of fraudulent use | 1 year after account deletion | Fraud prevention and dispute response |
| Service usage logs, access logs, IP addresses | 3 months | Enforcement Decree of the Protection of Communications Secrets Act §41 |
| Records concerning advertising and labeling | 6 months | Act on the Consumer Protection in Electronic Commerce §6 |
| Records of contracts or withdrawal of subscriptions | 5 years | Act on the Consumer Protection in Electronic Commerce §6 |
| Records of consumer complaints or dispute resolution | 3 years | Act on the Consumer Protection in Electronic Commerce §6 |
4. Provision of Personal Information to Third Parties
We process personal information only within the scope of the purposes stated in Section 1, and provide personal information to third parties only with the data subject's prior consent or where specifically permitted by law under PIPA Articles 17 and 18.
At present, we do not routinely provide personal information to any third party. If third-party provision becomes necessary in the future, we will amend this Policy in advance and obtain separate consent from data subjects.
5. Outsourcing of Personal Information Processing
We outsource the following personal information processing activities for the efficient operation of the Service.
| Processor | Outsourced activities | Basis |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure operation (EC2, EBS, S3, SES, etc.); data storage and processing environment | Data subject consent |
| GitHub, Inc. | Identity verification via OAuth social sign-in | Data subject consent |
| Google LLC | Identity verification via OAuth social sign-in | Data subject consent |
In accordance with PIPA Article 26, our outsourcing agreements specify in writing the prohibition of processing for purposes other than the outsourced work, technical and administrative safeguards, restrictions on sub-outsourcing, supervision of processors, and liability for damages. We supervise processors to ensure that personal information is handled securely.
6. Cross-Border Transfer of Personal Information
We transfer or store personal information outside the Republic of Korea as follows.
| Recipient | Country | Time and method of transfer | Items transferred | Purpose | Retention/use period |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | United States, Republic of Korea (Seoul region), and others | Transmitted over the network when the Service is used | All items listed in Section 2 | Cloud infrastructure operation | Until the outsourcing contract ends or the account is deleted |
| GitHub, Inc. | United States | API calls at the time of OAuth authentication | Email, username, profile information | OAuth identity verification | Duration necessary for authentication |
| Google LLC | United States and others | API calls at the time of OAuth authentication | Email, display name, profile image URL | OAuth identity verification | Duration necessary for authentication |
In accordance with PIPA Article 28-8, we provide prior notice of cross-border transfers and obtain consent from data subjects. Data subjects may refuse consent; in that case, sign-up via the relevant OAuth provider may be unavailable.
7. Destruction of Personal Information
When personal information becomes unnecessary because the retention period has elapsed or the purpose of processing has been achieved, we destroy it without delay.
7.1 Procedure
Information provided by the data subject is, after the purpose has been achieved, moved to a separate database or file (or to separate paper documents) and either stored for a defined period pursuant to internal policy and applicable law, or destroyed immediately. Information moved to a separate database is not used for any purpose other than as required by law.
7.2 Method
- Electronic files: permanently deleted by means that prevent recovery (e.g., low-level format, destruction of encryption keys).
- Paper documents: shredded or incinerated.
7.3 On account deletion
When a member withdraws, we destroy personal information either immediately or after the retention period specified in this Policy. Information for which retention is required by law (per the table in Section 3) is stored separately for the prescribed period and then destroyed.
8. Rights of Data Subjects and How to Exercise Them
8.1 Rights
Data subjects may exercise the following rights against us at any time:
- Right to request access to personal information.
- Right to request correction in case of errors.
- Right to request deletion.
- Right to request suspension of processing.
- Right to data portability (within the scope provided by PIPA Article 35-2).
- Right to refuse, or request an explanation of, automated decisions (PIPA Article 37-2).
8.2 How to exercise
Rights may be exercised by email (privacy@graphai.io), written notice, or electronic communication. We will respond and take action without delay (within 10 days of receipt).
If a data subject requests correction or deletion of personal information that contains errors, we will not use or provide the personal information until the correction or deletion is complete.
8.3 Through a representative
Rights may be exercised through a statutory representative or a duly authorized agent. In such cases, a power of attorney conforming to Form No. 11 of the Enforcement Rules of PIPA must be submitted.
8.4 Limitations
Rights of data subjects may be limited under PIPA Article 35(4) and Article 37(2).
9. Security Measures
In accordance with PIPA Article 29, we implement the following safeguards:
- Administrative measures — internal management plans; minimization and regular training of personnel handling personal information.
- Technical measures — access-control management for systems processing personal information; access-control systems and password hashing (e.g., bcrypt one-way hashes); encryption of personal information in transit (HTTPS/TLS) and at rest; installation and regular updates of security software; retention of security and access logs.
- Physical measures — access control for server rooms and document storage areas; reliance on the security controls of our cloud infrastructure provider (AWS).
10. Cookies and Similar Technologies
10.1 Purposes
We use cookies and similar technologies for the following purposes:
- Authentication cookies: maintaining the Supabase session (required).
- Studio access tokens: HMAC-signed tokens for instance subdomain access (required).
- Usage analytics: understanding service usage patterns, popular features, and access frequency (optional).
10.2 How to opt out
You can configure cookie acceptance and blocking in your browser settings. Blocking required cookies may prevent you from logging in or using parts of the Service.
- Chrome: Settings → Privacy and security → Cookies and other site data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Safari: Preferences → Privacy → Cookies and website data.
11. Data Protection Officer
We have designated a Data Protection Officer ("DPO") who is responsible for overseeing personal information processing and for handling complaints and remedies from data subjects.
▶ Data Protection Officer
- Name: (TBD)
- Title: (TBD)
- Contact:
privacy@graphai.io
▶ Data Protection Department
- Department name: (TBD)
- Contact:
privacy@graphai.io
Data subjects may direct any inquiry, complaint, or remedy request related to personal information arising from the use of the Service to the DPO or the responsible department. We will respond without delay.
12. Remedies for Infringement of Rights
Data subjects may apply to the following Korean authorities for dispute resolution, consultation, or remedy in connection with personal information infringement:
| Authority | Telephone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | 118 | privacy.kisa.or.kr |
| Cyber Investigation Division, Supreme Prosecutors' Office | 1301 | www.spo.go.kr |
| Cyber Bureau, Korean National Police Agency | 182 | ecrm.police.go.kr |
A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under PIPA Articles 35 (access), 36 (correction/deletion), or 37 (suspension of processing) may file an administrative appeal under the Administrative Appeals Act.
13. Changes to this Policy
This Policy applies from its effective date. Any addition, deletion, or correction in response to changes in laws or our practices will be announced through the in-service notice board or by email at least 7 days before the change takes effect (30 days in the case of changes that materially affect the rights of data subjects).
| Version | Effective date | Summary |
|---|---|---|
| 1.0 (draft) | 2026-05-22 | Initial draft |
Contact: privacy@graphai.io