Last updated · 2026-07-13
Privacy Policy
How Kapy Korea collects, uses, transfers, and protects personal data.
Plain-language summary
- Kapy Korea does not store passport numbers, alien registration numbers, bank account numbers, or card numbers.
- Nationality, visa type, and visa expiry are optional and private by default.
- Community content is user-generated content and is not used as AI Kapy context.
- AI Kapy uses only the user's question plus selected verified guide context.
- Product analytics is optional, excludes raw user content and sensitive profile fields, and can be withdrawn in Settings.
Data we collect
- Account and profile: email, display name, language, optional nationality, optional visa type, optional visa expiry.
- Service activity: saved guides, notifications, community posts/comments/reports, event and market activity.
- AI Kapy activity: question, selected guide IDs, answer metadata, refusal/escalation status, timestamp.
- Security and operations: audit logs, rate-limit records, error telemetry, request metadata.
- Optional product analytics after separate consent: allowlisted event name, time, session UUID, locale, safe properties, and consent reference. Search text and user-authored content are not collected in analytics.
Why we use it
- To provide account, profile, guide, community, notification, and moderation features.
- To personalize guide suggestions and visa D-day reminders when the user chooses to provide those fields.
- To operate AI Kapy safely with verified guide context, logs, rate limits, and abuse prevention.
- To protect the service through RLS, audit logs, fraud/abuse monitoring, and incident response.
- With optional consent, to measure whether verified guides and tools lead to useful outcomes and improve the product.
Overseas transfer and subprocessors
Kapy Korea uses overseas cloud and AI subprocessors. Refusing required overseas transfer consent means we cannot provide account, AI, hosting, or security features.
| Processor | Country | Purpose | Items | Retention |
|---|---|---|---|---|
| Supabase | United States / provider-operated regions | Authentication, database, storage, and row-level security enforcement | Account email, profile settings, optional nationality/visa fields, UGC, reports, consent records, and consented product events | While the account is active, then deleted or anonymized according to the deletion request flow and legal/security retention needs |
| Vercel | United States / global edge regions | Application hosting, deployment, routing, runtime logs, and environment variable management | Request metadata, deployment/runtime logs, non-secret public configuration | According to the Vercel project retention and log settings |
| Anthropic | United States | AI Kapy answer generation from the user's question and selected verified guide context | Question text, selected guide context, answer metadata. UGC and private profile fields are not sent as AI context. | Anthropic commercial/API retention terms apply, including short backend retention and abuse/legal/safety exceptions |
| Sentry | United States / European Union / provider-operated regions | Error monitoring, performance traces, and masked session replay for debugging | Error stack traces, route metadata, device/browser data. Replay is configured to mask text, inputs, and media. | According to the Sentry project retention settings |
AI Kapy / Claude API notice
When using AI Kapy, Kapy Korea sends the question and selected verified guide context to Anthropic's Claude API. Kapy Korea does not send community posts, private visa/profile fields, passport numbers, ARC numbers, bank account numbers, or card numbers as AI context. Do not type those identifiers into AI Kapy.
Your choices and rights
- You can choose not to provide nationality, visa type, or visa expiry.
- You can request access, correction, deletion, processing suspension, or withdrawal of consent.
- Community posts and comments may be retained in anonymized form when needed for moderation, safety, legal, or dispute records.
- You can grant or withdraw optional product analytics consent in Settings at any time; withdrawal stops new analytics events.
Retention
Account/profile data is kept while the account is active. Raw consented product events are retained for up to 13 months. Security, audit, payment webhook, report, and AI answer logs follow their separate safety, dispute, legal, and abuse-prevention retention needs, then are deleted or anonymized.
Privacy contact
Contact privacy@kapy-korea.app for access, correction, deletion, withdrawal of consent, or privacy questions.
privacy@kapy-korea.app