Privacy Policy (Every I)
This English version is an unofficial translation provided for convenience. In the event of any discrepancy between this translation and the Korean version, the Korean version prevails.
Every I Co., Ltd. (the “Company”) establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (“PIPA”) to protect data subjects’ personal information and to handle related grievances promptly and smoothly. This policy applies to QuizGen (https://quizgen.kr, the “Service”) operated by the Company.
- Notice date: September 4, 2026
- Effective date: September 11, 2026
Summary
- Data processed: email, password, (for social login) profile information, content data, usage data, payment-related information (including purchaser name, mobile phone number, and email)
- Purposes: membership management · AI quiz generation/scoring · payment · customer support · service improvement
- Third-party provision: not provided in principle (except legal exceptions)
- Entrustment / overseas transfer: member and payment-related data are stored in the Seoul (ap-northeast-2) region of Supabase, Inc.; quiz, answer, and transcription data and files uploaded by users are stored in the Taiwan (asia-east1) region of Google Cloud / Firebase; and data is transferred to Mixpanel, Inc. and OpenAI, L.L.C. (both in the United States) for usage analytics and AI processing (Articles 5 & 6)
- Data subject rights: access, correction, deletion, suspension of processing, data portability, and explanation/objection/re-processing regarding automated decisions
- Data Protection Officer: Ji Jun (CEO) / [email protected]
Article 1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. Processed personal information is not used for purposes other than those below, and where the purpose of use changes, the Company takes necessary measures such as obtaining separate consent pursuant to Article 18 of PIPA.
- Verifying intent to register, member identification/authentication, maintaining and managing membership, and preventing misuse
- Providing the Service, including AI-based quiz generation, automated scoring, and feedback
- Payment and subscription management for paid services and refund processing
- Responding to customer inquiries and providing technical support
- Service usage statistics analysis and service improvement / new service development
- Compliance with legal obligations and security / access-log management
Article 2. Categories of Personal Information Processed
2.1 Items collected during registration and use
- Self sign-up (required): email address, password (stored one-way encrypted)
- When using social login (Google): email address, name, and profile image from the Google account that the user consents to provide
- When using social login (GitHub): email address, username (login ID), and profile image from the GitHub account that the user consents to provide
- For paid payment (required): purchaser name, purchaser mobile phone number, purchaser email address, order number, subscription plan name, payment method type, payment amount, payment currency, the date and time of payment request, approval, completion and cancellation, and payment failure reasons. However, payment authentication details such as card numbers and expiry dates are not stored directly by the Company and are processed by the payment gateway (PG).
- When submitting feedback or an inquiry: feedback or inquiry content and a reply email address when the user requests a reply or submits an Enterprise inquiry. General feedback can be submitted without an email address.
2.2 Items processed during use of the Service
- Content data: text, documents (e.g., PDF), URLs, video/images, and question/answer content entered or uploaded by the user, and generated quizzes, scoring, and feedback results
- Usage data (automatically collected): access IP address, cookies, service usage records, access date/time, browser/device information (OS, model, etc.), and abnormal/fraudulent use records
Content data is processed only for quiz generation/scoring and result provision; temporary processing such as non-member attempts is automatically deleted after the purpose is achieved.
2.3 Sensitive information and unique identifiers
The Company does not collect or process sensitive information under Article 23 of PIPA (such as ideology/beliefs, health, and genetic/biometric information) or unique identifiers under Article 24 of the same Act (resident registration number, passport number, driver’s license number, alien registration number).
Article 3. Processing and Retention Period
The Company processes and retains personal information within the retention/use period required by law or consented to by the data subject, and destroys it without delay once the retention period expires.
| Processing activity | Retention period | Basis |
|---|---|---|
| Member information (email, etc.) | Until membership withdrawal. After withdrawal completes, only the email address and the withdrawal timestamp are kept for 7 days to check the rejoin restriction, and are then destroyed | Membership service contract; prevention of abusive re-registration |
| Content data (entered questions, etc.) | Until the quiz/scoring purpose is achieved. Quizzes, questions, and answers stored by a member are destroyed in bulk 7 days after the member’s withdrawal completes | Service provision |
| Service usage logs | Up to 12 months, then destroyed | Service improvement / security |
| Feedback or inquiry content and an optionally provided reply email address | 3 years from submission | Customer support and service improvement; the Act on E-Commerce where the submission constitutes a consumer complaint or dispute |
| Records on contracts and withdrawal of offer | 5 years | Act on E-Commerce |
| Records on payment and supply of goods | 5 years | Act on E-Commerce |
| Records on consumer complaints / dispute handling | 3 years | Act on E-Commerce |
When a member requests withdrawal, the Company immediately deletes the login account and converts every quiz the member had made public into a private quiz. Quizzes, questions, and answers stored by the member are destroyed 7 days after the withdrawal completes. During those same 7 days the member cannot re-register with the same email address; this measure prevents abuse through repeated withdrawal and re-registration.
Article 4. Provision of Personal Information to Third Parties
The Company processes personal information only within the scope specified in Article 1 and provides it to third parties only where Articles 17 and 18 of PIPA apply, such as the data subject’s consent or special provisions of law. The Company does not provide personal information externally except in the following cases.
- Where the user has consented in advance
- Where there is an obligation to submit under applicable law
- Where a request from an investigative agency, etc. is lawfully received under applicable law
Article 5. Entrustment of Personal Information Processing
For the smooth provision of the Service, the Company entrusts personal information processing tasks as follows.
| Trustee | Entrusted work | Retention / use period |
|---|---|---|
| Google LLC (Google Cloud Platform / Firebase) | Cloud infrastructure (member authentication, file storage, quiz / question / answer / scoring and audio-video transcription and work databases, administrator account and session data, content cache, hosting) | Until termination of the entrustment contract |
| Supabase, Inc. | Storage and operation of the member information and payment-related databases (payment, refund, subscription, and usage-quota records) (Seoul region) | Until termination of the entrustment contract or end of the retention period |
| Google LLC (reCAPTCHA Enterprise) | Prevention of automated sign-up and fraudulent use (bot blocking) | Until termination of the entrustment contract |
| Google LLC (Firebase Analytics / Google Analytics) | Service usage statistics analysis (collection/analysis of visit, click, and other usage behavior) | Event data: 2 months; user data: 14 months (auto-deleted) |
| Mixpanel, Inc. | Service usage statistics analysis (collection/analysis of screen views, feature use, and other usage behavior) | Upon completion of the purpose or termination of the entrustment contract (deleted under Mixpanel’s data retention policy) |
| Google LLC (Cloud Vision) | Optical character recognition (OCR) of characters contained in images and documents uploaded by users | Upon completion of request processing (per-request processing) |
| SMTP2GO Inc. | Delivery of authentication and notification emails and receipt of feedback or inquiries (password reset, inquiry responses, etc.) | Upon completion of delivery or termination of the entrustment contract |
| DuckDuckGo, Inc. | External web search for quiz generation (search keyword lookup) | Upon completion of request processing (per-request processing) |
| OpenAI, L.L.C. | AI quiz generation, automated scoring, and audio/video transcription | Upon completion of the purpose (per-request processing) |
| KG Inicis Co., Ltd. | Approval, inquiry, cancellation, and refund processing for credit cards and other payment methods, and payment record management | Retention period under the Act on the Consumer Protection in Electronic Commerce (5 years for payment settlement records) |
When entering into entrustment contracts, the Company specifies in writing, pursuant to Article 26 of PIPA, matters such as prohibition of processing beyond the entrusted purpose, technical/managerial safeguards, restriction on re-entrustment, supervision of the trustee, and liability for damages, and supervises whether the trustee processes personal information safely.
Article 6. Overseas Transfer of Personal Information
For cloud infrastructure operation and AI-based quiz generation, scoring, and transcription, the Company transfers personal information overseas (entrustment/storage) as follows. This overseas entrustment/storage is satisfied through disclosure in this Privacy Policy pursuant to Article 28-8(1) of PIPA. In all cases, the time and method of transfer is transmission over the information and communications network at the time of Service use.
| Transferee | Country | Items transferred | Purpose of use | Retention / use period |
|---|---|---|---|---|
| Google LLC (Google Cloud Platform / Firebase) | Taiwan (asia-east1 region) | Member authentication data (email, password hash, social login profile), files uploaded by users, quizzes/questions/answers/scoring results, audio and video transcription data, content cache data, administrator account/session data | Member authentication, file storage, quiz/answer/transcription databases, content cache and administrator databases, hosting | Until termination of the entrustment contract or end of the retention period |
| Mixpanel, Inc. | United States | Randomly generated identifier stored in the browser by Mixpanel (distinct_id), device/browser/OS information, approximate region inferred from the access IP address, and service usage records (screen views, feature use, and other behavioral information) | Service usage statistics analysis and feature improvement | Upon completion of the purpose or termination of the entrustment contract (deleted under Mixpanel’s data retention policy) |
| Google LLC (Cloud Vision) | United States | Images and documents uploaded by users and the character data recognized from them | Optical character recognition (OCR) of images and documents | Upon completion of request processing (not separately retained) |
| SMTP2GO Inc. | United States | Recipient email address, email subject and body, which may include feedback or inquiry content and an optionally provided reply email address | Delivery of authentication and notification emails and receipt of feedback or inquiries | Upon completion of delivery or termination of the entrustment contract |
| DuckDuckGo, Inc. | United States | Search keywords derived from the user’s input for quiz generation | External web search to obtain quiz sources | Upon completion of request processing (not separately retained) |
| OpenAI, L.L.C. | United States | Content data (entered text, documents, URLs, images; data extracted from audio/video; answers, etc.) | AI quiz generation, automated scoring, and audio/video transcription | Upon completion of request processing (not retained or used for model training) |
| Google LLC (Firebase Analytics / Google Analytics) | United States | Cookie identifiers, device/browser information, service usage records (page visits, clicks, and other behavioral information) | Service usage statistics analysis | Event data: 2 months; user data: 14 months (auto-deleted) |
The member and payment-related databases are stored in the Seoul (ap-northeast-2) region of the cloud database provided by Supabase, Inc. and are therefore kept within the Republic of Korea, so they do not constitute an overseas transfer under Article 28-8 of PIPA. However, personnel of Supabase, Inc. located outside Korea may remotely access those databases for incident response and technical support. Even in that case, the Company performs its trustee supervision duties under Article 26 of the same Act and applies safeguards such as access-privilege controls and retention of access logs.
The Company does not provide or use users’ content data for AI model training; the above processing is limited to providing the Service requested by the user, such as quiz generation, scoring, and transcription. Users must take care not to upload materials containing others’ personal or sensitive information without a lawful basis.
Data subjects may object to overseas transfer via the Data Protection Officer’s contact (Article 11). However, since overseas transfer is essential to providing the Service, use of the relevant Service may be restricted upon objection.
Article 7. Procedures and Methods of Destruction
The Company destroys personal information without delay when it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.
- Electronic files: permanently deleted by technical means that prevent recovery or reproduction
- Paper documents: shredded or incinerated
Destruction following membership withdrawal proceeds in the following order.
- Immediately upon the withdrawal request: the login account (authentication data) is deleted and existing sessions are invalidated
- Immediately upon the withdrawal request: every quiz the member had made public is converted to private so that other users can no longer view it
- 7 days after the withdrawal completes: quizzes, questions, and answers stored by the member are destroyed in bulk
- The email address and withdrawal timestamp kept during those 7 days are used solely to check the rejoin restriction and are destroyed once the period elapses.
Where retention is required by law, such personal information is moved to a separate database or stored separately in a different location.
Article 8. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them
Data subjects may exercise the following rights regarding their personal information at any time.
- Access, correction/deletion, suspension of processing, and data portability
- Membership withdrawal and withdrawal of consent
Rights may be exercised in writing, by email, etc. pursuant to Article 41(1) of the Enforcement Decree of PIPA, and the Company will act without delay (within statutory deadlines). For the personal information of children under 14, a legal representative may exercise these rights on their behalf. Identity verification is conducted upon request and processed under applicable law.
Right to data portability: Pursuant to Article 35-2 of PIPA, data subjects may request that their personal information processed by the Company be transmitted to themselves or to another personal information controller. Such requests may be submitted via the email address or My Page below; the Company informs the data subject of the transmittable items and the machine-readable file format, and then processes the request within the statutory deadline. Data subjects may check the receipt and processing status of their transmission requests and the transmission history through the same channels.
Department receiving and handling access requests
- Department: Office of the CEO (also serving as Data Protection Officer)
- Person in charge: Ji Jun (CEO)
- Email: [email protected]
- Online: My Page > Manage Personal Information / Withdraw Membership
Article 9. Installation, Operation, and Refusal of Automatic Collection Devices (Cookies)
The Company uses essential cookies for user authentication and saving preferences, and uses Google’s analytics tool (Firebase Analytics / Google Analytics) and the analytics tool of Mixpanel, Inc. as follows for service usage statistics analysis.
Cookies and local storage items essential to providing the Service
- quizgen-language: remembers the display language selected by the user (until the user deletes it).
- sidebar_state: remembers whether the sidebar is expanded or collapsed (until the user deletes it).
- Firebase authentication token: maintains the login session (until logout or token expiry).
- quizgen.cookieConsent: records the user’s consent or refusal for analytics cookies in browser local storage (until the user deletes it).
| Provider | Data collected | Purpose | Retention period | Country |
|---|---|---|---|---|
| Google LLC (Firebase Analytics / Google Analytics) | Cookie identifiers, device/browser information, page visits, clicks, and other service usage records | Service usage statistics analysis | Event data: 2 months; user data: 14 months | United States |
| Mixpanel, Inc. | Randomly generated identifier stored in the browser by Mixpanel (distinct_id), device/browser/OS information, approximate region inferred from the access IP address, and service usage records such as screen views and feature use | Service usage statistics analysis and feature improvement | Upon completion of the purpose or termination of the entrustment contract | United States |
The Mixpanel analytics tool is used with both autocapture and session recording disabled, and processes only the statistical items defined by the Company.
Users may select “Reject” on the cookie consent banner shown on first visit to immediately stop the collection of the above analytics cookies. Choosing Reject immediately stops collection by both Google Analytics and Mixpanel and keeps the rejection in effect on subsequent visits, and users may delete or block stored cookies at any time via browser settings.
- Chrome: Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
When a user generates a quiz from a YouTube video, the Company embeds the YouTube player to provide a video preview. The Company uses YouTube’s privacy-enhanced mode (youtube-nocookie.com) so that cookies based on viewing history are not set; however, communication records such as the user’s access IP address may be transmitted to Google LLC when the video is played.
Cookies essential to providing the Service, such as those for maintaining login, security, and language settings, are not subject to refusal. Even if analytics cookies are refused, basic functions of the Service such as maintaining login remain available.
Article 10. Measures to Ensure the Security of Personal Information
The Company takes the following managerial, technical, and physical measures to ensure the security of personal information.
- Establishing and implementing an internal management plan and minimizing/training staff who handle personal information
- Managing access privileges to the processing system and retaining access logs
- Storing passwords using one-way encryption and applying transmission encryption (SSL/TLS)
- Applying bot blocking (reCAPTCHA) to prevent automated sign-up and fraudulent use
- Physical access control, intrusion prevention/detection, backup, and disaster recovery for servers and databases are satisfied by the safeguards that the cloud providers used by the Company (Google LLC and Supabase, Inc.) apply to their own data centers and managed services. The Company verifies and manages the status of those providers’ security measures pursuant to Article 26 of PIPA.
Article 10-2. Notification of Personal Information Breach
If the Company becomes aware that personal information has been lost, stolen, leaked, forged, altered, or damaged, or becomes aware of the possibility thereof, the Company notifies the affected data subjects of the following without delay and reports to the Personal Information Protection Commission or the Korea Internet & Security Agency, pursuant to Article 34 of PIPA.
- The categories of personal information affected
- The time of the incident and the circumstances
- Information on measures data subjects can take to minimize harm
- The Company’s response measures and remedy procedures
- The department and contact for reporting damage, if any has occurred (Article 11)
- How to claim damages and how to apply for dispute mediation (see the bodies listed in Article 13)
If the affected categories and circumstances are not yet confirmed at the time of notification, the Company first notifies what has been confirmed and then notifies additional findings without delay.
Article 11. Data Protection Officer and Grievance Handling
The Company designates a Data Protection Officer as below to take overall responsibility for personal information processing and to handle data subjects’ complaints and remedy of damages.
- Name: Ji Jun
- Title: CEO
- Phone: +82-10-5394-6082
- Email: [email protected]
Data subjects may submit personal-information-related inquiries, complaints, and remedy requests arising during use of the Service to the contact above, and the Company will respond and handle them without delay.
Pursuant to Article 30-3 of PIPA, the owner and the representative of the Company bear ultimate responsibility for the Company’s processing of personal information, secure the personnel and budget necessary for personal information protection, and ensure that the Data Protection Officer can perform their duties independently.
Article 12. Automated Decision-Making
Pursuant to Article 37-2 of PIPA, the Company provides the following information regarding AI-based automated scoring.
- Subject: AI-assisted automated scoring of, and feedback generation for, descriptive (essay-type) answers
- Decision criteria: evaluation based on the correct answers/scoring criteria provided by the quiz author and the answer content entered by the test-taker
- Decision procedure: answer input → evaluation against the AI model’s scoring criteria → score/feedback output → review/modification by the quiz author (e.g., teacher)
- Decision method: assisted scoring using an external AI (generative language model) API; the final score is confirmed through the author’s review/modification
Data subjects (e.g., test-takers) may request an explanation of the criteria and reasons for an automated decision, and may object to the decision or request re-processing with human intervention. The Company responds to explanation requests within 15 days of the request, and notifies the result of re-processing requests within 30 days of completion (extendable up to 60 days where justified). Rights may be exercised at [email protected].
Article 13. Remedies for Infringement of Data Subjects’ Rights
To obtain remedy for personal information infringement, data subjects may apply to the following organizations for dispute resolution or consultation.
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Center: 118 / privacy.kisa.or.kr
- Supreme Prosecutors’ Office Cyber Investigation: 1301 / www.spo.go.kr
- National Police Agency Cyber Bureau: 182 / ecrm.police.go.kr
Article 14. Changes to This Privacy Policy
This Privacy Policy applies from the effective date and may be amended due to changes in law, policy, or the Service. Changes are announced via the Service’s notices at least 7 days in advance (at least 30 days in advance for material changes that are disadvantageous to users), and for material changes the Company may individually notify members by email.
Revision history
- October 11, 2025: Initial effect
- June 29, 2026: Strengthened overseas transfer, automated decision-making, remedies for infringement, and updated processing entrustment
- July 9, 2026: Specified use of Google Analytics (Firebase Analytics) by name in the entrustment, overseas transfer, and cookie provisions, including data items and retention periods
- September 11, 2026: Reflected migration of the member and payment-related databases to Supabase (Seoul region), disclosed adoption of the Mixpanel usage analytics tool, confirmed KG Inicis Co., Ltd. as the payment gateway, specified the purchaser information collected for paid payments, added the items collected via GitHub social login, newly disclosed the entrustment and overseas transfer for SMTP2GO (email delivery), Google Cloud Vision (character recognition) and DuckDuckGo (external search), added the names of essential cookies and a notice on the YouTube player, updated the security measures, detailed how to exercise the right to data portability and the department handling access requests, added the breach notification provision (Article 10-2), stated the ultimate responsibility of the owner and representative (Article 30-3), and specified the 7-day rejoin restriction, the point at which public quizzes are converted to private, and the timing of quiz destruction upon membership withdrawal
Company Information
- Name: Every I Co., Ltd.
- CEO: Ji Jun
- Business Registration Number: 534-87-03461
- Address: B102, 116 Samseongyo-ro 16-gil, Seongbuk-gu, Seoul, Republic of Korea
- Contact: +82-10-5394-6082 / [email protected]