Privacy Policy
Effective July 22, 2026 · Version 1.1 · Pango GY Co., Ltd.
Contents
- Article 1 (Who We Are)
- Article 2 (Personal Data We Collect)
- Article 3 (Purposes and Legal Bases of Processing)
- Article 4 (Retention Periods)
- Article 5 (How We Share Personal Data)
- Article 6 (International Data Transfers)
- Article 7 (Your Rights)
- Article 8 (Cookies)
- Article 9 (Data Security)
- Article 10 (Children)
- Article 11 (Automated Decision-Making)
- Article 12 (Changes to This Privacy Policy)
- Article 13 (Google API User Data)
- Article 14 (Contact)
- Article 15 (Connected Services and Platform Data)
- Article 16 (Provider-Specific API Disclosures)
- Article 17 (Deletion and Destruction)
- Article 18 (Privacy Officer and Remedies)
- Google API Limited Use Compliance Statement
Pango GY Co., Ltd. (the "Company", "we", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use and share it, and the rights you have when you use the AI marketing and advertising assistant service "Pango Neuro" (the "Service") and accept this Privacy Policy during sign-up or continued use.
Article 1 (Who We Are)
The data controller responsible for your personal data is:
| Item | Details |
|---|---|
| Controller | Pango GY Co., Ltd. |
| Address | 4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea |
| Privacy contact | [email protected] |
Article 2 (Personal Data We Collect)
| Category | Data | Source |
|---|---|---|
| Account data | Name, email address, password (stored in hashed form), account type, UI language | Provided by you at sign-up |
| Advertising account data | OAuth tokens and account identifiers for Linked Platforms (such as Google Ads or Meta Ads), and advertising data retrieved from those platforms (campaigns, performance metrics, and related settings) | Collected via API when you connect a platform |
| AI interaction data | Prompts, instructions, uploaded or connected source data, generated responses, reports, and tool execution records needed to provide AI analysis and conversational features | Provided by you or generated when you request an AI feature |
| Usage data | Access IP address, cookies, service usage records, device, browser, and OS information | Generated automatically while you use the Service |
| Payment data | Subscription status, plan, and transaction records. Payment card and billing details are collected and processed directly by Paddle, our Merchant of Record; we do not receive or store your full card details | Provided by you to Paddle at checkout |
| Support data | The content of your inquiries and correspondence with us | Provided by you when you contact us |
We do not knowingly collect special categories of personal data (such as health or biometric data), and the Service is not designed for you to submit them.
Article 3 (Purposes and Legal Bases of Processing)
We process your personal data for the following purposes and, where the GDPR or similar laws apply, on the following legal bases.
| Purpose | Details | Legal basis |
|---|---|---|
| Providing the Service | Account management, MCP integration, AI analysis, campaign management, report generation | Performance of a contract |
| Billing | Subscription management and refund handling (payments processed by Paddle) | Performance of a contract; legal obligation |
| Customer support | Receiving and handling inquiries and complaints | Performance of a contract; legitimate interests |
| Security and fraud prevention | Preventing unauthorized use, securing accounts, maintaining logs | Legitimate interests; legal obligation |
| Service improvement | Usage statistics, feature development, AI quality improvement | Legitimate interests |
| Marketing | Service announcements and promotional information | Consent (you may withdraw at any time) |
Article 4 (Retention Periods)
| Data | Retention period | Basis |
|---|---|---|
| Account data | Deleted without undue delay upon account closure | Service operation |
| Service usage records | 30 days after account closure | Dispute handling |
| Transaction and billing records | 5 years | Tax and commercial law obligations |
| Access logs | 3 months | The Protection of Communications Secrets Act of the Republic of Korea |
| Advertising campaign data | 30 days after account closure | Restoration requests |
| Support and dispute records | 3 years | Consumer protection law obligations |
| Marketing consent and communication records | Until consent is withdrawn or 3 years, whichever occurs first, unless a longer period is required by law | Consent records and marketing administration |
When a retention period expires or the purpose of processing is achieved, we delete the data without undue delay using irreversible methods. Data that must be retained under applicable law is stored separately for the required period only.
Article 5 (How We Share Personal Data)
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows.
- Service providers (processors) acting on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Firebase, Google Cloud, BigQuery) | Authentication, data storage, cloud functions, data warehouse, email delivery | United States and other Google data center locations |
| Amazon Web Services, Inc. | Web server hosting, job queues | Republic of Korea and other AWS regions |
| Anthropic PBC | AI processing (Claude API) | United States |
| OpenAI, L.L.C. | AI processing (GPT and related API features) | United States |
| Datadog, Inc. | Service monitoring, error tracking, performance and AI-interaction observability, including session replay recorded with on-screen content masked | United States |
We configure our monitoring provider to reduce the personal data it receives: we transmit your account identifier and the domain part of your email address (not the address itself), mask on-screen content in session replay, and redact email addresses and national identification numbers from error and AI-interaction records before transmission.
- Independent controllers:
| Recipient | Purpose |
|---|---|
| Paddle.com Market Limited and its affiliates | Payment processing, tax calculation and remittance, and refunds as Merchant of Record. Paddle processes your payment data under its own privacy policy (https://www.paddle.com/legal/privacy) |
| Linked Platforms (such as Google, Meta, TikTok) | When you connect an advertising account and instruct the Service to read or modify data, requests are transmitted to the relevant platform under that platform's terms and privacy policy |
- We may also disclose personal data where required by law, court order, or a lawful request by a public authority, or where disclosure is necessary to protect rights, safety, or property.
We use enterprise or API environments of our AI providers under which your data is not used to train their public models.
Article 6 (International Data Transfers)
We are a company established in the Republic of Korea, and your personal data is stored on servers located in the Republic of Korea and, depending on the provider, in the United States or other locations listed in Article 5.
- For users in the EU/EEA: the European Commission has adopted an adequacy decision for the Republic of Korea, so transfers of personal data from the EU/EEA to us in Korea are permitted without additional safeguards.
- For transfers to providers in the United States and other third countries, we rely on appropriate safeguards such as standard contractual clauses or, where applicable, an adequacy framework covering the recipient.
- You may request further information about the safeguards we use by contacting [email protected].
- Where applicable law gives you a right to object to an international transfer, you may exercise it by contacting us. Because transfers to our AI, monitoring, and infrastructure providers may be necessary to provide requested features, objecting may limit or prevent use of those features.
Article 7 (Your Rights)
- Subject to applicable law, you have the right to:
- Access the personal data we hold about you and receive a copy
- Correct inaccurate or incomplete personal data
- Delete your personal data
- Restrict or object to certain processing, including processing based on legitimate interests
- Receive your personal data in a portable format (data portability)
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
- If you are a California resident, you have the rights under the CCPA/CPRA to know, access, correct, and delete personal information, and the right not to be discriminated against for exercising your rights. We do not sell or share personal information as defined by the CCPA/CPRA.
- To exercise your rights, contact us at [email protected] or use the relevant settings within the Service. We respond within the time limits required by applicable law (and in any event within 10 business days in the ordinary course). We may need to verify your identity before acting on a request, and you may exercise your rights through an authorized agent where permitted by law.
Article 8 (Cookies)
We use cookies and similar technologies to keep you signed in, remember your preferences, and analyze usage statistics. You can refuse or delete cookies through your browser settings; some features of the Service may be limited if cookies are disabled. We do not use cookies for cross-site behavioral advertising.
Article 9 (Data Security)
| Area | Measures |
|---|---|
| Encryption | Password hashing via Firebase Authentication (bcrypt/scrypt); encrypted storage of OAuth tokens; payment card details are processed by Paddle and are not stored on our servers |
| Access control | Firestore security rules, role-based access control (owner/admin/member/guest), and minimization of staff with access |
| Transport security | HTTPS (TLS 1.2 or higher) for all data in transit |
| Logging | Access records for processing systems retained for at least 1 year |
| Incident response | Breach response procedures and periodic vulnerability reviews |
| Physical security | Infrastructure security of AWS and Google Cloud (SOC 2, ISO 27001) |
If a personal data breach occurs, we will notify the relevant supervisory authority and affected users as required by applicable law.
Article 10 (Children)
The Service is a business service intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Article 11 (Automated Decision-Making)
The Service provides AI-based analysis and recommendations. These outputs are for reference, and decisions that produce legal or similarly significant effects are not made solely by automated means. Where automated processing materially affects your rights or obligations, you may request an explanation, object, or request human review by contacting [email protected].
Article 12 (Changes to This Privacy Policy)
We may update this Privacy Policy to reflect changes in law or the Service. We will announce changes within the Service at least 7 days before they take effect, or at least 30 days in advance with individual notice for changes that are unfavorable to you.
Article 13 (Google API User Data)
Where you connect a Google service (such as Google Ads, Google Analytics 4, Search Console, or Tag Manager), we access user data through Google APIs. We share, transfer, or disclose that data only as follows.
| Recipient | Country | Purpose | Items |
|---|---|---|---|
| Amazon Web Services, Inc. | United States, Republic of Korea | Service infrastructure operation (hosting, servers, job queues) | Minimum data necessary for service operation |
| Anthropic PBC | United States | AI agent functionality (natural language processing and analysis) | Advertising analysis request context data |
| OpenAI, L.L.C. | United States | AI processing (GPT and related API features) | Advertising analysis request context data |
| Datadog, Inc. | United States | Service monitoring and fault detection | Service usage logs, performance data |
Except as described above, we do not sell user data obtained through Google APIs to third parties and do not share it for advertising purposes. Our use and transfer of user data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Article 14 (Contact)
| Item | Details |
|---|---|
| Privacy contact | [email protected] |
| Postal address | Pango GY Co., Ltd., 4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea |
For payment data processed by Paddle as Merchant of Record, you may also contact Paddle through the channels set out in Paddle's privacy policy (https://www.paddle.com/legal/privacy).
Article 15 (Connected Services and Platform Data)
The Service lets you connect external services that you choose and authorize. Available connections may change as the Service develops and currently include the following principal categories.
| Category | Connected services |
|---|---|
| Advertising | Google Ads, Meta Ads, Instagram Creator Marketplace, Naver Search Ads, Kakao Moment, TikTok Ads, TikTok Creator Marketplace, Pinterest Ads, Microsoft Ads, Criteo Ads, Apple Search Ads, Amazon Ads, DV360, and ChatGPT Ads |
| Analytics and measurement | Google Analytics 4, Google Tag Manager, Google Search Console, and AppsFlyer |
| Commerce | Naver Commerce |
| Documents and collaboration | Google Docs, Google Sheets, and Notion |
For all Connected Services:
- We access and process only the data within the permissions you grant.
- We do not sell data obtained from a Connected Service or disclose it for an unrelated third party's independent purpose.
- Processing by service providers and international transfers needed to provide requested features remain subject to Articles 5 and 6.
- We comply with the applicable API terms and data policies of each provider.
- You may disconnect a service through its account settings or by contacting us. Disconnection stops future access through that connection, subject to the provider's revocation process.
- If a new connection changes the categories of data collected, service providers used, or international transfer arrangements, we will update the relevant parts of this Privacy Policy.
Article 16 (Provider-Specific API Disclosures)
- OpenAI. When you select or use a feature powered by OpenAI, we transmit only the data needed to fulfill your request. We use OpenAI's API under terms that do not permit that API data to be used to train public models. See https://openai.com/policies/terms-of-use and https://openai.com/policies/privacy-policy.
- Anthropic. When you select or use a feature powered by Claude, we transmit only the data needed to fulfill your request. We use Anthropic's commercial API, and data sent through that API is not used to train Anthropic's generative models. See https://www.anthropic.com/legal/commercial-terms, https://www.anthropic.com/legal/privacy, and https://www.anthropic.com/legal/aup.
- Meta and TikTok. We access only data covered by the permissions you grant, do not sell API data or disclose it for an unrelated third party's independent purpose, and follow each provider's applicable platform terms and privacy policy.
- Pinterest. The Service acts as an API relay and does not retain Pinterest content or API response data after fulfilling your request. During connection setup, the list of available ad accounts and OAuth credentials may be stored in encrypted temporary records for up to 15 minutes so that you can select an account without exposing credentials to your browser. We retain the selected ad account identifier and name and the encrypted OAuth access and refresh tokens needed to maintain the connection. When you disconnect Pinterest, those stored credentials are deleted without undue delay and the Service stops using them; you may separately revoke the authorization in Pinterest account settings. We do not resell or redistribute Pinterest content or Pinterest-derived data. The Service is not endorsed, sponsored by, or affiliated with Pinterest. See https://policy.pinterest.com/en/terms-of-service, https://policy.pinterest.com/en/privacy-policy, and https://developers.pinterest.com/terms/.
Article 17 (Deletion and Destruction)
- We delete personal data without undue delay when the processing purpose is complete or the applicable retention period expires, except for data that must be retained by law.
- Electronic records are deleted using methods designed to prevent recovery, and paper records are shredded or securely destroyed.
- Data retained solely to meet a legal obligation is separated from actively used service data and is not used for another purpose.
Article 18 (Privacy Officer and Remedies)
| Item | Details |
|---|---|
| Privacy Officer | Sungyup Ko, CEO |
| Privacy Officer email | [email protected] |
| Customer privacy inquiries | [email protected] |
You may contact us to exercise your rights or raise a privacy complaint. If you are in the Republic of Korea, you may also seek assistance from the Personal Information Infringement Report Center (https://privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (https://www.kopico.go.kr, 1833-6972), the Supreme Prosecutors' Office, or the Korean National Police Agency. Users elsewhere may contact their local data protection authority.
Google API Limited Use Compliance Statement
Pango Neuro's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Pango Neuro:
- Only requests access to Google user data that is necessary for the features described in this application.
- Does not use Google user data for serving advertisements.
- Does not allow humans to read Google user data unless the user has given explicit permission, it is necessary for security purposes, or it is required by law.
- Does not use or transfer Google user data to develop, improve, or train generalized AI or ML models.
- Does not sell Google user data to third parties.
Pango GY Co., Ltd.
CEO: Sungyup Ko, Seungjae Yoo · Business Reg. No. 740-87-01471
Mail-Order Sales Business Registration No. 2025-Seoul-Gangnam-03752
Address: 4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea · Email: [email protected]