DDirong

Privacy Policy

DDirong maintains this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of Korea, in order to protect users' personal information and to handle related grievances.

Effective Date: August 31, 2026

This is an English translation of DDirong's Privacy Policy, provided for reference only. If there is any conflict or discrepancy between this translation and the Korean original, the Korean version shall prevail.

1. Personal Information Collected

The Service collects the following items when a user signs in with a Google account.

The scopes requested from Google are openid, email, profile, and calendar.readonly, which is used to read calendar events on a read-only basis. The Service does not access data from any other Google service besides Calendar, such as Gmail or Drive.

The calendar screen displays the user's default Google Calendar events retrieved using the scope above. The retrieved event data is only displayed on screen and is not stored on the server.

In addition, to-dos, memos, and workspace names that a user directly enters are stored in association with the user's account. The date and time of access and the access IP may be automatically recorded in server logs while the Service is used.

2. Purpose of Processing Personal Information

Personal information is not used for any purpose other than those above, and prior consent is obtained if the purpose changes. It is not used for advertising, profiling, or tracking user behavior. Google Calendar data is used solely for the purpose of displaying it on the calendar screen, in accordance with the Limited Use requirements of the Google API Services User Data Policy, and is not provided to third parties, used for advertising, or viewed by any human.

3. Retention and Use Period of Personal Information

Account information and content a user has entered are retained while the account remains active, and are destroyed without delay upon the user's request for deletion. Server access logs are retained for 3 months from the date recorded and then destroyed.

The Google OAuth refresh token is also retained while the account remains active and is destroyed without delay when the account is deleted. Google Calendar events are not stored, so no separate retention period applies to them.

Because the Service does not provide the sale of goods or services, the record-keeping obligations under the Act on the Consumer Protection in Electronic Commerce, etc. of Korea do not apply.

4. Provision of Personal Information to Third Parties

The Service does not provide or sell users' personal information to third parties, except where otherwise specifically required by law or requested by an investigative agency in accordance with the procedures and methods prescribed by law.

5. Outsourcing of Personal Information Processing

The Service outsources the following personal information processing task for the smooth operation of the Service.

Data is physically stored in Chuncheon, Republic of Korea, and personal information is not transferred overseas.

6. Procedure and Method of Destroying Personal Information

When personal information becomes unnecessary because the retention period has passed or the purpose of processing has been achieved, it is destroyed without delay. Information in electronic file form is permanently deleted by a method that prevents recovery, and destruction covers both the corresponding database record and any backups.

7. Rights and Obligations of Data Subjects, and How to Exercise Them

Users may exercise the following rights at any time.

To exercise these rights, please contact the Personal Information Protection Officer listed below by email, and the Service will take action without delay. Requests may also be made through a legal representative or an authorized agent. If the Service must continue processing despite a user's request because it is required to do so by law, the Service will notify the user of the reason.

8. Measures to Secure Personal Information

9. Operation of Cookies and Other Automatic Collection Tools, and How to Refuse Them

The Service uses only the authentication cookie refresh_token, used to maintain login sessions, and a cookie used to prevent forgery during the login process. It does not use cookies for analytics or advertising purposes.

Cookies can be refused or deleted in browser settings. However, refusing the authentication cookie prevents login sessions from being maintained, making the Service unusable.

10. Personal Information Protection Officer

The Service designates a Personal Information Protection Officer, who is responsible for personal information processing overall and for handling related grievances.

11. Remedies for Infringement of Rights

If you need consultation or relief for harm caused by a personal information infringement, you may contact the agencies below. Please use these if you are not satisfied with the Service's own handling of your request or need further assistance.

12. Changes to This Privacy Policy

This Privacy Policy applies from its effective date. If the content changes due to a change in law or the Service, the change will be posted on this page, and material changes will be announced at least 7 days before they take effect.