trademd Privacy Policy
Beta version, before legal review
Document version: privacy-v2-beta-20260924
This policy is available in Korean, English, Japanese, Simplified Chinese, Spanish and French. All six language versions are authoritative and say the same thing.
This document explains what personal data trademd processes, why, and for how long we keep it. We don't use it for anything not listed here. If a new purpose or a new provider comes along, we update this document before we start. Operator details are in Article 2 of the Terms of Service.
Article 1. Purposes and legal bases
The operator processes personal data for the purposes below. The legal basis is in brackets.
- Sign-up, sign-in and account management (performance of a contract)
- Uploading, checking, registering and publishing files, and providing free summaries, views and downloads (performance of a contract)
- Recording and settling memberships and payments, view passes and download passes, refunds, royalties and payouts (performance of a contract, legal obligation). To split royalties from membership downloads, we use each member's record of which file versions they downloaded in each billing period.
- Confirming that users are adults and limiting features by country of residence, including checks for sanctioned countries (legal obligation)
- Handling reports, questions and disputes (performance of a contract, legal obligation)
- Preventing abuse and keeping the service secure, including rate limits and checks for improper rewards (legitimate interests)
- Daily totals for improving the service, using only numbers that can't identify anyone (legitimate interests)
- Recording whether you want product news (consent). This is optional and off by default. We don't send marketing messages during the beta.
Article 2. What we process and how we collect it
- Sign-in: your Google sign-in identifier (issuer and account ID) and email address, received through Google sign-in (Firebase Authentication). The name Google sends along is used only to complete sign-in and is not stored.
- Account settings: display name (alias), interface language, time zone, country of residence, adult age declaration (the country and the minimum age you confirmed), and records of the terms you agreed to (type, version, time). At sign-up, your time zone is taken automatically from your browser, and your interface language from the language the screen is showing at the time. You enter the rest yourself on the sign-up and settings screens. We don't ask for your date of birth.
- Sign-in session: a session cookie. On the server we store only a hash of the cookie value and the times it was created, expires and was signed out.
- Uploads: the original text of uploaded files, file names, the list of paths inside a ZIP, check results, listing details (title, summary, category and so on), and consent records (file hash, excerpt hash, versions of the terms and licenses, your choices, time).
- Membership and payments: your plan, membership status and billing periods, records of payments and refunds, records of view passes and download passes, the country you chose when paying, royalty and payout records, creator verification status and a payout method reference. We don't receive payment details such as card numbers.
- Usage records: records of reading a file's text, views and downloads (account, file version, time, and which of these it was). Separately, each view and download leaves a pass record (which version, when, and which pass or membership opened it), and each download leaves a royalty allocation record. Those two belong to the pass and royalty records in item 5.
- Reports: the report reason and description.
- Questions: the question category, message, reply email and interface language. The contact form works without sign-in, and we don't keep your IP address or account with the message.
- Rate limits: request counts for search and the contact form. Signed-in searches are counted by your internal account number, and searches without signing in and the contact form by a hash of your IP address. The key used for the hash changes every day, so the same IP address gives a different value on a different day. We don't store the IP address itself or your search terms.
- Notifications: the type of notification, a reference to the related payment or file, and when you read it.
- Daily totals: counts per event name, date and interface language. They contain no cookies, accounts, IP addresses or search terms.
- Security reports: we keep only totals of the Content Security Policy (CSP) violation reports that browsers send, with no information that identifies anyone.
Files can contain personal data. The upload check holds a file if it finds what looks like a secret key, a Korean resident registration number, a US Social Security number or a card number that passes the checksum, and it warns if it finds email addresses or phone numbers. This check runs only inside the operator's servers and doesn't send the text anywhere else.
Article 3. How long we keep it
- Account details: kept while you use the account. When we process an account deletion we erase the email, display name, interface language, time zone and country of residence stored on your account and close it. We also erase your Google sign-in identifier and keep only an irreversible hash of it. We use that hash for one thing: noticing when the same Google account signs up again, so that signing up again can't be used to get around limits such as upload rewards. The closed account's internal ID stays with the transaction records in item 9. Your country of residence and adult age declaration (the country code and the minimum age you confirmed) are also written in the consent records, so they stay with those records as item 9 describes. If you changed your country in settings, the audit record in item 10 keeps the old and new country codes.
- Sign-in sessions: the cookie expires after 7 days. We delete the session record on the server 90 days after it expires or you sign out.
- Uploads you didn't register: 7 days after the upload session was created, we delete the file text along with the file names, the paths inside a ZIP and the listing details (title, summary, tags and so on). Adding more files doesn't extend this. If a review case about the file is still open, we delete it once the case is closed. Uploads you cancel are deleted on the same schedule. Unfinished transfers are deleted after 1 day.
- Files rejected by the checks: deleted after 30 days. Files linked to an open review case are kept until the case is closed.
- Text of published files: kept while the file is offered to members and for as long as we need to keep serving members who already downloaded it. Even if you stop offering it or delete your account, we keep the text if members have downloaded it. For a file nobody downloaded, we delete its text, excerpt and summary once 30 days have passed since the creator or the operator stopped offering it, or it came down because the account was deleted. If a report, refund or dispute about the file is still open then, we keep it until that is closed. The text of a file the operator blocked is kept while the case or a rights dispute needs it.
- Usage records (Article 2, item 6) and operations records: 1 year. Pass records and royalty allocation records for views and downloads don't follow this period. They are kept as transaction records under item 9.
- Notifications: 6 months
- Report, question and dispute records: 3 years after the case is closed. After that we erase the message and reply email and keep only the category and times.
- Transaction records (payments, refunds, passes, royalties, payouts) and consent records: kept for at least 5 years. This includes the pass records each view and download leaves (which version, when, and which pass or membership opened it) and the royalty allocation records. Korea's Act on Consumer Protection in Electronic Commerce requires records of contracts, cancellations and payments to be kept for 5 years, and records of consumer complaints and dispute handling for 3 years. These records are checked against the ledgers in item 10, so we don't delete them after that period either. Test records from the public beta are the one exception. No real money moved in them, so they can be cleared when we change how the service works, and we cleared them once on September 24, 2026 (Terms of Service, Article 4(7)). Deleting your account only cuts the link between these records and your email and display name.
- Ledgers and audit records: these reconcile the money and the operator's actions, so they are not deleted. When you delete your account, the link between these records and your email and display name is cut.
- Rate-limit records (an account number or an IP hash, and a count): search counts in windows of 60 seconds, and the contact form in one-hour windows. A window's record is deleted while we handle a later request, once two more windows have passed for search, or one more window for the contact form.
- Daily totals: 1 year
- Security report totals: 30 days
Article 4. Sharing with third parties
- The operator doesn't give personal data to third parties, except when a request is made under the law.
- We don't tell creators a member's email address or who downloaded their files. Royalty statements only show download counts and amounts per file and month, with no information that identifies a member. Other users see your display name and, if you are a creator, the public details of the files you uploaded.
Article 5. Processors
- The operator uses the following processors.
- Google LLC (Firebase Authentication): confirming Google account sign-in
- Cloudflare, Inc.: web hosting and running the server, database (D1), file storage (R2), and forwarding email sent to the legal address (Email Routing)
- GitHub, Inc.: the environment that runs the operator's recovery drill (GitHub Actions). It processes a temporary copy of the database only during the drill, and the copy is deleted when the drill ends.
- We don't use the following providers yet. Before we start, we will add them to this policy and give notice under Article 14.
- Email delivery: Resend
- An AI API provider that creates metadata (title, summary, category) for uploaded files. We plan to start with OpenAI. Once in use, part of the file's text, up to 24,000 characters, is sent to it.
- Payment and payout providers, once real payments and payouts open
Article 6. Transfers outside Korea
To run the service, personal data is transferred outside the Republic of Korea. It is sent over an encrypted connection (HTTPS) whenever you use the service.
- Google LLC
- Country: United States
- Contact: https://firebase.google.com/support/privacy
- Data: Google account email, name, profile photo address, Firebase user ID, sign-in history
- Purpose: confirming sign-in
- Retention: while you use the account. Account deletion includes deleting your Firebase user record, and that step runs automatically. If it fails, we retry it and finish the account deletion once it succeeds.
- Cloudflare, Inc.
- Country: United States. Data may be processed in data centers around the world.
- Contact: https://www.cloudflare.com/privacypolicy/
- Data: everything listed in Article 2, plus network information such as the IP address you connect from
- Purpose: hosting, data storage, email forwarding
- Retention: the periods in Article 3
- GitHub, Inc.
- Country: United States
- Contact: https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
- Data: the items in Article 2 that are stored in the database (D1). Files in file storage (R2) are not included.
- Purpose: the recovery drill that checks the database can be restored after an outage
- When and how: when the operator runs a recovery drill, over an encrypted connection (HTTPS)
- Retention: only during the drill. The temporary copy is deleted when the drill ends.
If you don't want your data transferred abroad, you can stop using the service or ask us to delete your account. We can't run the service without Google and Cloudflare.
Article 7. Deletion
- Data past its retention period is deleted by a scheduled retention job, or when we process an account deletion. Transaction and consent records, ledgers and audit records (Article 3, items 9 and 10) are the exception, and we don't delete them.
- Values in the database are deleted or made unidentifiable, and files in storage are deleted.
- Values deleted or changed in the database stay restorable through Cloudflare's point-in-time recovery (D1 Time Travel) for up to 30 days, and can't be restored after that. Files deleted from file storage (R2) have no backup the operator can restore.
- Records kept because the law requires it are not used for anything else.
Article 8. Your rights
- You can ask to see, correct or delete your personal data, to stop processing it, to withdraw consent, and to get a copy of it.
- You can change your interface language with the language menu on any screen, and your country of residence in settings. You also request account deletion in settings. While the request is waiting to be processed, views and downloads are locked, and you can still request royalty payouts or cancel the request (Terms of Service, Article 19). To change your display name or time zone, or for anything else, use the contact form (https://trademd.org/contact) or write to legal@trademd.org.
- After confirming it's you, we reply without delay and within 10 days at the latest. We aim to finish account deletions within 10 days.
- Someone else can make a request on your behalf if they show proof that you authorized them.
- Data we must keep by law stays for the periods in Article 3 even if you ask us to delete it. If we can't do what you asked, we tell you why.
- The upload check automatically rejects only files it can't read (empty, binary or not UTF-8). Files with values such as secret keys, resident registration numbers or card numbers, and files the check couldn't finish, are put on hold for a person to review. You can ask for an explanation of a rejection or a hold, or ask for another review.
- We don't record anything on a blockchain during the beta.
Article 9. How we keep data safe
- All connections are encrypted with HTTPS.
- The session cookie can't be read by page scripts, and the server stores only a hash of its value. IP addresses are used only as hashes.
- Uploaded text is kept in private storage. Downloads use a one-time token that is valid for 60 seconds and tied to your sign-in session.
- Operator staff can open a file's text only when a review case, their role and a stated reason all match, and every access is written to an audit record.
- Ledgers, pass records and audit records are built so they can't be edited, only added to. Consent records are never edited either. We only ever add new ones.
- Access is split by role. Secret keys are kept in the deployment environment's secret store, not in the code.
- We use a Content Security Policy (CSP) and don't use outside analytics or advertising scripts.
- Stored data is covered by Cloudflare's encryption at rest.
Article 10. Cookies and browser storage
- trademd uses these cookies:
- tmd_session: keeps you signed in. Expires after 7 days.
- tmd_lang: the interface language you chose. Expires after 1 year.
- tmd_oauth: checks the sign-in steps. Expires after 10 minutes and is used only by some sign-in methods.
- When you sign in with Google, Firebase may keep your sign-in state in browser storage.
- Some screens keep progress only inside your browser and never send it to the server.
- We don't use advertising cookies, tracking cookies or outside analytics tools.
- You can block cookies in your browser settings. If you do, you won't be able to sign in.
Article 11. Minors
trademd is for adults only (Terms of Service, Article 5). If we learn that a minor has signed up, we close and delete the account. When we start the deletion, we tell the account holder why in the service, and they can respond through the contact form (https://trademd.org/contact). The deletion erases personal data as Article 3, item 1 describes. Records we have to keep, such as transaction records, stay for the periods in Article 3. When we carry out the deletion, we also refund any membership payment that could be refunded in full when we started the deletion and any unused download passes bought in packs (Terms of Service, Article 10(1) and Article 19(2)).
Article 12. Privacy officer
- Privacy officer: 김규태 (representative)
- Email: legal@trademd.org
- Contact form: https://trademd.org/contact
Article 13. Getting help with a privacy problem
For advice or help with a privacy problem, you can contact these Korean bodies:
- Personal Information Dispute Mediation Committee: www.kopico.go.kr, 1833-6972
- Privacy Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr, 118
- Supreme Prosecutors' Office: www.spo.go.kr, 1301
- Korean National Police Agency: ecrm.police.go.kr, 182
If you live in another country, you can also complain to your country's data protection authority.
Article 14. Changes to this policy
- When we change this policy, we post what is changing and the effective date in the service starting 7 days before it takes effect. For important changes, such as adding data we process, a processor or a transfer abroad, we start 30 days before.
- If a change needs your consent, we ask for it again before the change takes effect.
- All six language versions are changed together.
Article 15. Language
This policy is available in Korean, English, Japanese, Simplified Chinese, Spanish and French, and all versions are authoritative. If the language versions seem to differ in meaning, the one more favorable to the user applies.
Supplementary provision
This policy applies from the day it is posted in the service.