QuizGen.kr
Switch to Korean

Privacy Policy (Every I)

This English version is an unofficial translation provided for convenience. In the event of any discrepancy between this translation and the Korean version, the Korean version prevails.

Every I Co., Ltd. (the “Company”) establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (“PIPA”) to protect data subjects’ personal information and to handle related grievances promptly and smoothly. This policy applies to QuizGen (https://quizgen.kr, the “Service”) operated by the Company.

  • Notice date: June 22, 2026
  • Effective date: June 29, 2026

Summary

  • Data processed: email, password, (for social login) profile information, content data, usage data, payment-related information
  • Purposes: membership management · AI quiz generation/scoring · payment · customer support · service improvement
  • Third-party provision: not provided in principle (except legal exceptions)
  • Entrustment / overseas transfer: entrusted to Google Cloud / Firebase etc.; data stored in the Taiwan (asia-east1) region (Articles 5 & 6)
  • Data subject rights: access, correction, deletion, suspension of processing, data portability, and explanation/objection/re-processing regarding automated decisions
  • Data Protection Officer: Ji Jun (CEO) / [email protected]

Article 1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Processed personal information is not used for purposes other than those below, and where the purpose of use changes, the Company takes necessary measures such as obtaining separate consent pursuant to Article 18 of PIPA.

  1. Verifying intent to register, member identification/authentication, maintaining and managing membership, and preventing misuse
  2. Providing the Service, including AI-based quiz generation, automated scoring, and feedback
  3. Payment and subscription management for paid services and refund processing
  4. Responding to customer inquiries and providing technical support
  5. Service usage statistics analysis and service improvement / new service development
  6. Compliance with legal obligations and security / access-log management

Article 2. Categories of Personal Information Processed

2.1 Items collected during registration and use

  • Self sign-up (required): email address, password (stored one-way encrypted)
  • When using social login (Google): email address, name, profile image, and other information from the Google account that the user consents to provide
  • For paid payment: payment-related information (card issuer, amount, payment date, etc.). However, actual payment details such as card numbers are not stored directly by the Company and are processed through the payment gateway (PG).

2.2 Items processed during use of the Service

  • Content data: text, documents (e.g., PDF), URLs, video/images, and question/answer content entered or uploaded by the user, and generated quizzes, scoring, and feedback results
  • Usage data (automatically collected): access IP address, cookies, service usage records, access date/time, browser/device information (OS, model, etc.), and abnormal/fraudulent use records

Content data is processed only for quiz generation/scoring and result provision; temporary processing such as non-member attempts is automatically deleted after the purpose is achieved.

2.3 Sensitive information and unique identifiers

The Company does not collect or process sensitive information under Article 23 of PIPA (such as ideology/beliefs, health, and genetic/biometric information) or unique identifiers under Article 24 of the same Act (resident registration number, passport number, driver’s license number, alien registration number).

Article 3. Processing and Retention Period

The Company processes and retains personal information within the retention/use period required by law or consented to by the data subject, and destroys it without delay once the retention period expires.

Processing activityRetention periodBasis
Member information (email, etc.)Until membership withdrawal; destroyed within 30 days after withdrawalMembership service contract
Content data (entered questions, etc.)Until the quiz/scoring purpose is achieved (member-stored data until withdrawal)Service provision
Service usage logsUp to 12 months, then destroyedService improvement / security
Records on contracts and withdrawal of offer5 yearsAct on E-Commerce
Records on payment and supply of goods5 yearsAct on E-Commerce
Records on consumer complaints / dispute handling3 yearsAct on E-Commerce

Article 4. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope specified in Article 1 and provides it to third parties only where Articles 17 and 18 of PIPA apply, such as the data subject’s consent or special provisions of law. The Company does not provide personal information externally except in the following cases.

  1. Where the user has consented in advance
  2. Where there is an obligation to submit under applicable law
  3. Where a request from an investigative agency, etc. is lawfully received under applicable law

Article 5. Entrustment of Personal Information Processing

For the smooth provision of the Service, the Company entrusts personal information processing tasks as follows.

TrusteeEntrusted workRetention / use period
Google LLC (Google Cloud Platform / Firebase)Cloud infrastructure (data storage, database, hosting, authentication)Until termination of the entrustment contract
Google LLC (reCAPTCHA Enterprise)Prevention of automated sign-up and fraudulent use (bot blocking)Until termination of the entrustment contract
Google LLC (Firebase Analytics / Google Analytics)Service usage statistics analysis (collection/analysis of visit, click, and other usage behavior)Event data: 2 months; user data: 14 months (auto-deleted)
OpenAI, L.L.C.AI quiz generation, automated scoring, and audio/video transcriptionUpon completion of the purpose (per-request processing)
(Planned) Domestic payment gateway (PG)Payment processing and payment record managementRetention period under applicable law

When entering into entrustment contracts, the Company specifies in writing, pursuant to Article 26 of PIPA, matters such as prohibition of processing beyond the entrusted purpose, technical/managerial safeguards, restriction on re-entrustment, supervision of the trustee, and liability for damages, and supervises whether the trustee processes personal information safely.

Article 6. Overseas Transfer of Personal Information

For cloud infrastructure operation and AI-based quiz generation, scoring, and transcription, the Company transfers personal information overseas (entrustment/storage) as follows. This overseas entrustment/storage is satisfied through disclosure in this Privacy Policy pursuant to Article 28-8(1) of PIPA. In all cases, the time and method of transfer is transmission over the information and communications network at the time of Service use.

TransfereeCountryItems transferredPurpose of useRetention / use period
Google LLC (Google Cloud Platform / Firebase)Taiwan (asia-east1 region)Member information (email, etc.), content data, usage dataData storage, database, hosting, authenticationUntil termination of the entrustment contract or end of the retention period
OpenAI, L.L.C.United StatesContent data (entered text, documents, URLs, images; data extracted from audio/video; answers, etc.)AI quiz generation, automated scoring, and audio/video transcriptionUpon completion of request processing (not retained or used for model training)
Google LLC (Firebase Analytics / Google Analytics)United StatesCookie identifiers, device/browser information, service usage records (page visits, clicks, and other behavioral information)Service usage statistics analysisEvent data: 2 months; user data: 14 months (auto-deleted)

The Company does not provide or use users’ content data for AI model training; the above processing is limited to providing the Service requested by the user, such as quiz generation, scoring, and transcription. Users must take care not to upload materials containing others’ personal or sensitive information without a lawful basis.

Data subjects may object to overseas transfer via the Data Protection Officer’s contact (Article 11). However, since overseas transfer is essential to providing the Service, use of the relevant Service may be restricted upon objection.

Article 7. Procedures and Methods of Destruction

The Company destroys personal information without delay when it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.

  • Electronic files: permanently deleted by technical means that prevent recovery or reproduction
  • Paper documents: shredded or incinerated

Where retention is required by law, such personal information is moved to a separate database or stored separately in a different location.

Article 8. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them

Data subjects may exercise the following rights regarding their personal information at any time.

  • Access, correction/deletion, suspension of processing, and data portability
  • Membership withdrawal and withdrawal of consent

Rights may be exercised in writing, by email, etc. pursuant to Article 41(1) of the Enforcement Decree of PIPA, and the Company will act without delay (within statutory deadlines). For the personal information of children under 14, a legal representative may exercise these rights on their behalf. Identity verification is conducted upon request and processed under applicable law.

  • Email: [email protected]
  • Online: My Page > Manage Personal Information / Withdraw Membership

Article 9. Installation, Operation, and Refusal of Automatic Collection Devices (Cookies)

The Company uses essential cookies for user authentication and saving preferences, and uses Google’s analytics tool (Firebase Analytics / Google Analytics) as follows for service usage statistics analysis.

ProviderData collectedPurposeRetention periodCountry
Google LLC (Firebase Analytics / Google Analytics)Cookie identifiers, device/browser information, page visits, clicks, and other service usage recordsService usage statistics analysisEvent data: 2 months; user data: 14 monthsUnited States

Users may select “Reject” on the cookie consent banner shown on first visit to immediately stop the collection of the above analytics cookies, and may delete or block stored cookies at any time via browser settings.

  1. Chrome: Settings > Privacy and security > Cookies and other site data
  2. Safari: Preferences > Privacy > Manage Website Data
  3. Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
  4. Firefox: Settings > Privacy & Security > Cookies and Site Data

Essential cookies required for functions such as maintaining login are not subject to refusal. If analytics cookies are refused, some customized services, such as maintaining login, may be restricted.

Article 10. Measures to Ensure the Security of Personal Information

The Company takes the following managerial, technical, and physical measures to ensure the security of personal information.

  • Establishing and implementing an internal management plan and minimizing/training staff who handle personal information
  • Managing access privileges to the processing system and retaining access logs
  • Encrypting key information such as passwords and encrypting transmission (SSL/TLS)
  • Operating intrusion prevention/detection systems and conducting regular security checks
  • Operating backup and disaster recovery and controlling physical access

Article 11. Data Protection Officer and Grievance Handling

The Company designates a Data Protection Officer as below to take overall responsibility for personal information processing and to handle data subjects’ complaints and remedy of damages.

Data subjects may submit personal-information-related inquiries, complaints, and remedy requests arising during use of the Service to the contact above, and the Company will respond and handle them without delay.

Article 12. Automated Decision-Making

Pursuant to Article 37-2 of PIPA, the Company provides the following information regarding AI-based automated scoring.

  • Subject: AI-assisted automated scoring of, and feedback generation for, descriptive (essay-type) answers
  • Decision criteria: evaluation based on the correct answers/scoring criteria provided by the quiz author and the answer content entered by the test-taker
  • Decision procedure: answer input → evaluation against the AI model’s scoring criteria → score/feedback output → review/modification by the quiz author (e.g., teacher)
  • Decision method: assisted scoring using an external AI (generative language model) API; the final score is confirmed through the author’s review/modification

Data subjects (e.g., test-takers) may request an explanation of the criteria and reasons for an automated decision, and may object to the decision or request re-processing with human intervention. The Company responds to explanation requests within 15 days of the request, and notifies the result of re-processing requests within 30 days of completion (extendable up to 60 days where justified). Rights may be exercised at [email protected].

Article 13. Remedies for Infringement of Data Subjects’ Rights

To obtain remedy for personal information infringement, data subjects may apply to the following organizations for dispute resolution or consultation.

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • Privacy Infringement Report Center: 118 / privacy.kisa.or.kr
  • Supreme Prosecutors’ Office Cyber Investigation: 1301 / www.spo.go.kr
  • National Police Agency Cyber Bureau: 182 / ecrm.police.go.kr

Article 14. Changes to This Privacy Policy

This Privacy Policy applies from the effective date and may be amended due to changes in law, policy, or the Service. Changes are announced via the Service’s notices at least 7 days in advance (at least 30 days in advance for material changes that are disadvantageous to users), and for material changes the Company may individually notify members by email.

Revision history

  • October 11, 2025: Initial effect
  • June 29, 2026: Strengthened overseas transfer, automated decision-making, remedies for infringement, and updated processing entrustment
  • July 9, 2026: Specified use of Google Analytics (Firebase Analytics) by name in the entrustment, overseas transfer, and cookie provisions, including data items and retention periods

Company Information

  • Name: Every I Co., Ltd.
  • CEO: Ji Jun
  • Business Registration Number: 534-87-03461
  • Address: B102, 116 Samseongyo-ro 16-gil, Seongbuk-gu, Seoul, Republic of Korea
  • Contact: +82-10-5394-6082 / [email protected]