Back to home

Privacy Policy

Last updated · August 28, 2026

1. Information we collect

When you request a free audit, Findable collects your email address and domain URL. During service operation, your access IP address and access logs are automatically collected and stored (for abuse prevention). On paid plans we also collect payment details (processed through the payment provider PortOne), billing history, and usage logs.

2. How we use it

Collected information is used only to (1) send your audit PDF, (2) operate the service and provide support, (3) process payments and refunds, and (4) use access IP and logs solely to prevent fraud and abuse and to ensure service stability.

3. We do not train AI models on your personal data

Findable does not use your personal data (email address, name, contact details, payment information) to train AI models. What we send to external AI engines during an audit is the brand name and domain being audited; your personal data is not transmitted. The AI response text collected as audit results consists of answers about publicly available brand information, does not constitute personal data, and may be used to improve service quality.

4. Retention

Email and domain data: until account deletion or 3 years after last use. Payment data: 5 years, per Korea's e-commerce law. Access IP and access logs: retained for abuse prevention and deleted once that purpose is fulfilled. Audit results: deleted immediately on request.

5. Processing entrusted to third parties

Findable entrusts personal data processing to the following providers in order to operate the service: (1) Vercel Inc. — service hosting and deployment, (2) Neon Inc. — database operation, (3) Clerk Inc. — account authentication and management, (4) PortOne Co., Ltd. — payment processing, (5) Resend Inc. — audit result and notification email delivery, (6) PostHog Inc. — service usage analytics. Our agreements with these processors reflect the requirements of Korea's Personal Information Protection Act, including prohibition of processing beyond the entrusted purpose, security measures, restrictions on sub-processing, supervision of the processor, and liability for damages. If a processor changes, we will update this policy without delay.

6. Third-party disclosure

We do not share data with third parties except: (1) with your consent, or (2) when required by law. During an audit, the brand name and domain being audited are sent to external AI engines (OpenAI · Anthropic · Google · Perplexity · Naver · Kakao · NCloud HyperCLOVA · LETSUR, including calls routed through Vercel AI Gateway) and web retrieval services (Firecrawl · Browserbase). Your personal data is not transmitted to them.

7. Google user data

Only after you explicitly connect Google, Findable processes read-only Google Search Console site, impression, click, CTR, and average-position data and Google Analytics 4 property, session, engaged-session, key-event, and revenue data. We use this data solely to provide your search-performance dashboard and improvement recommendations. We do not use it for advertising, sale, credit decisions, or general-purpose AI model training. Google OAuth refresh tokens are encrypted at rest and never written to reports or logs. You can disconnect at any time in Findable's search-performance integration screen or your Google Account permissions; disconnecting deletes the token and synchronized data associated with that connection from Findable. Findable's use of Google API data complies with the Limited Use requirements of the Google API Services User Data Policy.

8. Your rights

You may request access, correction, deletion, or restriction of processing of your personal data. Contact: kendrick@indigochild.kr

9. Data protection officer

Hyundeok Na (CEO) · kendrick@indigochild.kr