Privacy Policy

Effective 2026-09-21

This policy explains the information we process, transfers to the AI you choose and how to request access or deletion. Privacy officer: Taejin Kang, CEO, info@hamke.ai.

1. Information and purposes

Account administration uses email, name, Google identifier and profile image when selected, language, hashed verification codes, expiry and attempt counts, and sign-in records. We do not collect new passwords; legacy accounts may retain an old password hash.

Office operations use organization details, members and invitation emails, teammate settings, connected resources and access credentials, conversations, reports, memory and run records. Billing records include order identifiers, amounts, status, receipt links, masked card details and encrypted recurring billing keys. The payment processor handles full card numbers and CVC. Support requests, IP addresses and server error records support authentication security and troubleshooting.

2. Customer data and choices

We control account and billing information. For personal data in customer work materials, we act within the customer’s instructions as a processor. Customers must establish authority and a lawful basis for processing, outsourcing and cross-border transfers, including required notices and consent. Materials are not guaranteed to be automatically anonymized; connect only necessary data.

Provider passwords, sessions and OAuth tokens for personal subscriptions remain in the official app on your computer. hamke stores a separate connector credential hash, owner, device name, last contact time and work results.

3. Processors and international transfers

AWS hosts core services and databases in Seoul, Republic of Korea. Stripe (United States) processes card authorization, payments and cancellations; card numbers are stored only at Stripe. Google processes optional Google sign-in. Connected mail, document, advertising and other services have their own processing terms.

At execution, instructions, relevant materials, conversation and tool responses are transmitted to your selected AI: Anthropic for Claude (United States and disclosed processing regions), OpenAI (United States and disclosed processing regions), Google for Gemini (United States and global processing regions), or DeepSeek (China). Provider retention and further regions depend on the applicable published policy and account contract. Review these details before connecting.

Anthropic privacy · OpenAI business data · Gemini API terms · DeepSeek privacy. Refuse transfer by leaving that provider disconnected or pausing/removing its connection; its AI execution becomes unavailable. Provider procedures govern deletion of data already transferred.

4. Retention and deletion

Account, workspace and work data remain while required for the service. We delete them on an authorized request or when their purpose ends, except statutory and dispute-related records. Detailed API response copies are cleared after 30 days; separately saved reports, conversations and financial ledgers retain their own purposes.

Korean statutory retention includes contract/withdrawal and payment/service records for five years, consumer complaints/disputes for three years and advertising records for six months. These records are restricted to their retained purpose. Automated production database backups last seven days; deleted data may remain in residual backups for that period. Deletion requests are reapplied after restoration.

5. Protection and local storage

We use HTTPS, workspace isolation, authorization checks, application encryption for AI API and billing keys, and database storage encryption. Full API keys are not returned after saving. Disconnecting stops new work and tool access; sign out of your personal provider app separately.

Browser local storage holds your login token, selected workspace and language. Sign-out removes the first two while preserving language preference. Google and payment interfaces manage their own storage technologies.

6. Rights and contact

Request access, correction, deletion, restriction, consent withdrawal or export at info@hamke.ai. We verify identity and, for organizational data, authority. We explain any legal limits. The service is not intended for people under 19.

Keuhan Inc., 550-87-02858, 3F V1421, 6 Teheran-ro 79-gil, Gangnam-gu, Seoul, Republic of Korea. Privacy officer: Taejin Kang, info@hamke.ai. Korean complaint channels include privacy.kisa.or.kr (118) and kopico.go.kr. We announce processing changes here and individually when required.