Privacy Policy

Privacy Policy

Effective July 22, 2026 · Version 1.1 · Pango GY Co., Ltd.

Contents

Pango GY Co., Ltd. (the "Company", "we", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use and share it, and the rights you have when you use the AI marketing and advertising assistant service "Pango Neuro" (the "Service") and accept this Privacy Policy during sign-up or continued use.

Article 1 (Who We Are)

The data controller responsible for your personal data is:

ItemDetails
ControllerPango GY Co., Ltd.
Address4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea
Privacy contact[email protected]

Article 2 (Personal Data We Collect)

CategoryDataSource
Account dataName, email address, password (stored in hashed form), account type, UI languageProvided by you at sign-up
Advertising account dataOAuth tokens and account identifiers for Linked Platforms (such as Google Ads or Meta Ads), and advertising data retrieved from those platforms (campaigns, performance metrics, and related settings)Collected via API when you connect a platform
AI interaction dataPrompts, instructions, uploaded or connected source data, generated responses, reports, and tool execution records needed to provide AI analysis and conversational featuresProvided by you or generated when you request an AI feature
Usage dataAccess IP address, cookies, service usage records, device, browser, and OS informationGenerated automatically while you use the Service
Payment dataSubscription status, plan, and transaction records. Payment card and billing details are collected and processed directly by Paddle, our Merchant of Record; we do not receive or store your full card detailsProvided by you to Paddle at checkout
Support dataThe content of your inquiries and correspondence with usProvided by you when you contact us

We do not knowingly collect special categories of personal data (such as health or biometric data), and the Service is not designed for you to submit them.

Article 3 (Purposes and Legal Bases of Processing)

We process your personal data for the following purposes and, where the GDPR or similar laws apply, on the following legal bases.

PurposeDetailsLegal basis
Providing the ServiceAccount management, MCP integration, AI analysis, campaign management, report generationPerformance of a contract
BillingSubscription management and refund handling (payments processed by Paddle)Performance of a contract; legal obligation
Customer supportReceiving and handling inquiries and complaintsPerformance of a contract; legitimate interests
Security and fraud preventionPreventing unauthorized use, securing accounts, maintaining logsLegitimate interests; legal obligation
Service improvementUsage statistics, feature development, AI quality improvementLegitimate interests
MarketingService announcements and promotional informationConsent (you may withdraw at any time)

Article 4 (Retention Periods)

DataRetention periodBasis
Account dataDeleted without undue delay upon account closureService operation
Service usage records30 days after account closureDispute handling
Transaction and billing records5 yearsTax and commercial law obligations
Access logs3 monthsThe Protection of Communications Secrets Act of the Republic of Korea
Advertising campaign data30 days after account closureRestoration requests
Support and dispute records3 yearsConsumer protection law obligations
Marketing consent and communication recordsUntil consent is withdrawn or 3 years, whichever occurs first, unless a longer period is required by lawConsent records and marketing administration

When a retention period expires or the purpose of processing is achieved, we delete the data without undue delay using irreversible methods. Data that must be retained under applicable law is stored separately for the required period only.

Article 5 (How We Share Personal Data)

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows.

  1. Service providers (processors) acting on our instructions:
ProviderPurposeLocation
Google LLC (Firebase, Google Cloud, BigQuery)Authentication, data storage, cloud functions, data warehouse, email deliveryUnited States and other Google data center locations
Amazon Web Services, Inc.Web server hosting, job queuesRepublic of Korea and other AWS regions
Anthropic PBCAI processing (Claude API)United States
OpenAI, L.L.C.AI processing (GPT and related API features)United States
Datadog, Inc.Service monitoring, error tracking, performance and AI-interaction observability, including session replay recorded with on-screen content maskedUnited States

We configure our monitoring provider to reduce the personal data it receives: we transmit your account identifier and the domain part of your email address (not the address itself), mask on-screen content in session replay, and redact email addresses and national identification numbers from error and AI-interaction records before transmission.

  1. Independent controllers:
RecipientPurpose
Paddle.com Market Limited and its affiliatesPayment processing, tax calculation and remittance, and refunds as Merchant of Record. Paddle processes your payment data under its own privacy policy (https://www.paddle.com/legal/privacy)
Linked Platforms (such as Google, Meta, TikTok)When you connect an advertising account and instruct the Service to read or modify data, requests are transmitted to the relevant platform under that platform's terms and privacy policy
  1. We may also disclose personal data where required by law, court order, or a lawful request by a public authority, or where disclosure is necessary to protect rights, safety, or property.

We use enterprise or API environments of our AI providers under which your data is not used to train their public models.

Article 6 (International Data Transfers)

We are a company established in the Republic of Korea, and your personal data is stored on servers located in the Republic of Korea and, depending on the provider, in the United States or other locations listed in Article 5.

  1. For users in the EU/EEA: the European Commission has adopted an adequacy decision for the Republic of Korea, so transfers of personal data from the EU/EEA to us in Korea are permitted without additional safeguards.
  2. For transfers to providers in the United States and other third countries, we rely on appropriate safeguards such as standard contractual clauses or, where applicable, an adequacy framework covering the recipient.
  3. You may request further information about the safeguards we use by contacting [email protected].
  4. Where applicable law gives you a right to object to an international transfer, you may exercise it by contacting us. Because transfers to our AI, monitoring, and infrastructure providers may be necessary to provide requested features, objecting may limit or prevent use of those features.

Article 7 (Your Rights)

  1. Subject to applicable law, you have the right to:
  • Access the personal data we hold about you and receive a copy
  • Correct inaccurate or incomplete personal data
  • Delete your personal data
  • Restrict or object to certain processing, including processing based on legitimate interests
  • Receive your personal data in a portable format (data portability)
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
  1. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
  2. If you are a California resident, you have the rights under the CCPA/CPRA to know, access, correct, and delete personal information, and the right not to be discriminated against for exercising your rights. We do not sell or share personal information as defined by the CCPA/CPRA.
  3. To exercise your rights, contact us at [email protected] or use the relevant settings within the Service. We respond within the time limits required by applicable law (and in any event within 10 business days in the ordinary course). We may need to verify your identity before acting on a request, and you may exercise your rights through an authorized agent where permitted by law.

Article 8 (Cookies)

We use cookies and similar technologies to keep you signed in, remember your preferences, and analyze usage statistics. You can refuse or delete cookies through your browser settings; some features of the Service may be limited if cookies are disabled. We do not use cookies for cross-site behavioral advertising.

Article 9 (Data Security)

AreaMeasures
EncryptionPassword hashing via Firebase Authentication (bcrypt/scrypt); encrypted storage of OAuth tokens; payment card details are processed by Paddle and are not stored on our servers
Access controlFirestore security rules, role-based access control (owner/admin/member/guest), and minimization of staff with access
Transport securityHTTPS (TLS 1.2 or higher) for all data in transit
LoggingAccess records for processing systems retained for at least 1 year
Incident responseBreach response procedures and periodic vulnerability reviews
Physical securityInfrastructure security of AWS and Google Cloud (SOC 2, ISO 27001)

If a personal data breach occurs, we will notify the relevant supervisory authority and affected users as required by applicable law.

Article 10 (Children)

The Service is a business service intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Article 11 (Automated Decision-Making)

The Service provides AI-based analysis and recommendations. These outputs are for reference, and decisions that produce legal or similarly significant effects are not made solely by automated means. Where automated processing materially affects your rights or obligations, you may request an explanation, object, or request human review by contacting [email protected].

Article 12 (Changes to This Privacy Policy)

We may update this Privacy Policy to reflect changes in law or the Service. We will announce changes within the Service at least 7 days before they take effect, or at least 30 days in advance with individual notice for changes that are unfavorable to you.

Article 13 (Google API User Data)

Where you connect a Google service (such as Google Ads, Google Analytics 4, Search Console, or Tag Manager), we access user data through Google APIs. We share, transfer, or disclose that data only as follows.

RecipientCountryPurposeItems
Amazon Web Services, Inc.United States, Republic of KoreaService infrastructure operation (hosting, servers, job queues)Minimum data necessary for service operation
Anthropic PBCUnited StatesAI agent functionality (natural language processing and analysis)Advertising analysis request context data
OpenAI, L.L.C.United StatesAI processing (GPT and related API features)Advertising analysis request context data
Datadog, Inc.United StatesService monitoring and fault detectionService usage logs, performance data

Except as described above, we do not sell user data obtained through Google APIs to third parties and do not share it for advertising purposes. Our use and transfer of user data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Article 14 (Contact)

ItemDetails
Privacy contact[email protected]
Postal addressPango GY Co., Ltd., 4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea

For payment data processed by Paddle as Merchant of Record, you may also contact Paddle through the channels set out in Paddle's privacy policy (https://www.paddle.com/legal/privacy).

Article 15 (Connected Services and Platform Data)

The Service lets you connect external services that you choose and authorize. Available connections may change as the Service develops and currently include the following principal categories.

CategoryConnected services
AdvertisingGoogle Ads, Meta Ads, Instagram Creator Marketplace, Naver Search Ads, Kakao Moment, TikTok Ads, TikTok Creator Marketplace, Pinterest Ads, Microsoft Ads, Criteo Ads, Apple Search Ads, Amazon Ads, DV360, and ChatGPT Ads
Analytics and measurementGoogle Analytics 4, Google Tag Manager, Google Search Console, and AppsFlyer
CommerceNaver Commerce
Documents and collaborationGoogle Docs, Google Sheets, and Notion

For all Connected Services:

  • We access and process only the data within the permissions you grant.
  • We do not sell data obtained from a Connected Service or disclose it for an unrelated third party's independent purpose.
  • Processing by service providers and international transfers needed to provide requested features remain subject to Articles 5 and 6.
  • We comply with the applicable API terms and data policies of each provider.
  • You may disconnect a service through its account settings or by contacting us. Disconnection stops future access through that connection, subject to the provider's revocation process.
  • If a new connection changes the categories of data collected, service providers used, or international transfer arrangements, we will update the relevant parts of this Privacy Policy.

Article 16 (Provider-Specific API Disclosures)

  1. OpenAI. When you select or use a feature powered by OpenAI, we transmit only the data needed to fulfill your request. We use OpenAI's API under terms that do not permit that API data to be used to train public models. See https://openai.com/policies/terms-of-use and https://openai.com/policies/privacy-policy.
  2. Anthropic. When you select or use a feature powered by Claude, we transmit only the data needed to fulfill your request. We use Anthropic's commercial API, and data sent through that API is not used to train Anthropic's generative models. See https://www.anthropic.com/legal/commercial-terms, https://www.anthropic.com/legal/privacy, and https://www.anthropic.com/legal/aup.
  3. Meta and TikTok. We access only data covered by the permissions you grant, do not sell API data or disclose it for an unrelated third party's independent purpose, and follow each provider's applicable platform terms and privacy policy.
  4. Pinterest. The Service acts as an API relay and does not retain Pinterest content or API response data after fulfilling your request. During connection setup, the list of available ad accounts and OAuth credentials may be stored in encrypted temporary records for up to 15 minutes so that you can select an account without exposing credentials to your browser. We retain the selected ad account identifier and name and the encrypted OAuth access and refresh tokens needed to maintain the connection. When you disconnect Pinterest, those stored credentials are deleted without undue delay and the Service stops using them; you may separately revoke the authorization in Pinterest account settings. We do not resell or redistribute Pinterest content or Pinterest-derived data. The Service is not endorsed, sponsored by, or affiliated with Pinterest. See https://policy.pinterest.com/en/terms-of-service, https://policy.pinterest.com/en/privacy-policy, and https://developers.pinterest.com/terms/.

Article 17 (Deletion and Destruction)

  1. We delete personal data without undue delay when the processing purpose is complete or the applicable retention period expires, except for data that must be retained by law.
  2. Electronic records are deleted using methods designed to prevent recovery, and paper records are shredded or securely destroyed.
  3. Data retained solely to meet a legal obligation is separated from actively used service data and is not used for another purpose.

Article 18 (Privacy Officer and Remedies)

ItemDetails
Privacy OfficerSungyup Ko, CEO
Privacy Officer email[email protected]
Customer privacy inquiries[email protected]

You may contact us to exercise your rights or raise a privacy complaint. If you are in the Republic of Korea, you may also seek assistance from the Personal Information Infringement Report Center (https://privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (https://www.kopico.go.kr, 1833-6972), the Supreme Prosecutors' Office, or the Korean National Police Agency. Users elsewhere may contact their local data protection authority.


Google API Limited Use Compliance Statement

Pango Neuro's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Pango Neuro:

  • Only requests access to Google user data that is necessary for the features described in this application.
  • Does not use Google user data for serving advertisements.
  • Does not allow humans to read Google user data unless the user has given explicit permission, it is necessary for security purposes, or it is required by law.
  • Does not use or transfer Google user data to develop, improve, or train generalized AI or ML models.
  • Does not sell Google user data to third parties.

Pango GY Co., Ltd.

CEO: Sungyup Ko, Seungjae Yoo · Business Reg. No. 740-87-01471

Mail-Order Sales Business Registration No. 2025-Seoul-Gangnam-03752

Address: 4F, 622 Eonju-ro, Gangnam-gu, Seoul, Republic of Korea · Email: [email protected]