Privacy Policy
Tenacious Inc. ("the Company," "we," "us," or "our") deeply values the privacy of our global users and is fully committed to protecting your personal information in accordance with major global privacy regulations, including the EU GDPR, California CCPA/CPRA, and the Personal Information Protection Act of the Republic of Korea.
This Privacy Policy transparently outlines the purposes of processing, retention periods, and specific rights you hold regarding your personal information collected during your use of the Stocknow service ("the Service"). The Company respects the privacy rights granted by the laws of your country of residence and continuously enhances technical and administrative security measures to ensure your data remains secure.
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. The processed personal information will not be used for any purposes other than those stated below. If the purpose of use changes, necessary measures, such as obtaining separate consent in accordance with applicable laws, will be implemented.
- User Registration and Management: Confirmation of user intent to register, identification and authentication for membership services, verification of parental consent for users below the legal minimum age of their respective country of residence, and maintenance/management of membership status.
- Service Provision: Delivery of customized services, verification of payments for paid services, recurring and subscription management, content provision tailored to specific Membership levels, and operation of community features.
- Service Improvement: Analysis of service usage history and AI Agent interactions to improve service quality and develop new features.
- Prevention of Unauthorized/Abusive Use: Retention of records regarding unauthorized use and registration data (unique user ID, authentication token, email address, etc.) to detect and prevent severe violations of the Terms of Service or abnormal data scraping.
- Marketing and Advertising Information: Delivery of marketing, promotional, and advertising information, and announcements regarding new service launches.
- Legal Compliance: Collection and retention of personal information as required by applicable laws of the user's residence or requests from legitimate law enforcement authorities.
- Miscellaneous: Handling user inquiries, complaints, and dispute resolutions.
2. Retention and Preservation Period of Personal Information
[Global General Principle]
In principle, the Company retains and uses your personal information only for the duration necessary to provide the Service, or until you request account deletion (termination of membership). Once the purpose of processing is achieved or the account is closed, your personal information will be permanently destroyed without delay, unless further retention is required by applicable local laws.
- Account Data & Service Usage Logs (Required) - Unique user ID, authentication token, email address, integration data permitted during social login, app usage logs, etc. : Retained until account deletion (termination of membership).
- Payment & Subscription Processing Info (Required) - Credit card information transmitted for payment processing and the last 4 digits of the card number retained for card verification. : Retained until financial transaction completion or removal of the payment method.
- AI Agent Dialogue Logs (Optional) - Prompts and dialogue information directly entered into the AI Agent by the user. : Retained until the purpose of service improvement is achieved after anonymization, or until account deletion.
- Marketing & Advertising Data (Optional) - Name, phone number, email address. : Retained until withdrawal of consent or account deletion.
[Country-Specific Legal Retention Exceptions]
Notwithstanding the global general principle, if the Company is obligated to preserve records under the applicable laws of a specific jurisdiction, the relevant user's data will be stored securely and separately for the periods specified below:
- For Users Holding Republic of Korea Nationality or Transactions Occurring Within the ROK Jurisdiction:
- Records on Contracts, Subscription Withdrawals, Payments, and Supply of Goods/Services: Retained for 5 years (Act on Consumer Protection in Electronic Commerce).
- Records on Electronic Financial Transactions: Retained for 5 years (Electronic Financial Transactions Act).
- Records on Consumer Complaints or Dispute Resolutions: Retained for 3 years (Act on Consumer Protection in Electronic Commerce).
- Records on Labels, Displays, and Advertisements: Retained for 6 months (Act on Consumer Protection in Electronic Commerce).
- Service Connection Logs (System Logs & IP address): Retained for 3 months (Protection of Communications Secrets Act).
3. Third-Party Disclosures and International Data Transfers
In principle, the Company does not disclose users' personal information to third parties. However, exceptions apply in the following cases:
- When prior consent is obtained from the user or member.
- When legitimately requested by domestic or foreign judicial/law enforcement authorities in accordance with applicable laws.
- Within the scope of integration with platforms such as Apple App Store and Google Play Store during paid service transactions, where transaction details (e.g., payment identifier, subscription status) may be shared or verified with the respective platform.
[Notice on International Data Transfers] To provide a stable global service infrastructure, the Company utilizes global cloud facilities such as Amazon Web Services (AWS). In this process, your data may be transferred to and stored in a country outside of your residence (including the location of the Company's global data centers). By using the Service, users are deemed to have consented to this international transfer.
4. Delegation of Personal Information Processing (Data Processors)
To ensure efficient service operations and improvements, the Company delegates personal information processing to external professional vendors as follows. We ensure through data processing agreements that personal information is securely managed in compliance with applicable regulations.
- Amazon Web Services, Inc.: Data retention and cloud computing infrastructure operations (US and global regions).
- Amplitude, Inc.: De-identified analysis and improvement of app usability.
- Apple Inc. / Google LLC: Integration of in-app purchases and subscription processing systems (When using platform in-app payment methods).
- NICE Payments Co., Ltd.: Credit card, digital wallet, and financial transaction processing (When using web or alternative direct payment methods).
- PayPal Holdings, Inc. : Credit card, digital wallet, and financial transaction processing (When using web or alternative direct payment methods).
- Toss Payments Co., Ltd.: Credit card, digital wallet, and financial transaction processing (When using web or alternative direct payment methods).
- Google LLC (Analytics/Firebase): Statistical analysis and application error tracking.
- OpenAI, L.L.C. / Anthropic PBC / Google LLC: API integration for providing AI Agent functionalities. (Data entered is transferred in a de-identified format and is contractually protected from being reused for general training of external AI models).
5. Measures to Secure the Safety of Personal Information
- Cloud Security Measures: The Company stores and manages personal information through the cloud infrastructure of Amazon Web Services (AWS). AWS complies with internationally certified security standards and implements various security measures, including data encryption, access controls, and intrusion detection systems.
- Encryption: Personal information is securely encrypted both at rest and during network transmission using industry-standard encryption algorithms.
- Access Control: Access permissions to personal information are restricted to the minimum necessary personnel essential for business operations, and all access logs are securely maintained.
6. Protection of Children’s Personal Information
The Service strictly restricts registration and use by children under the age of 13 (or the minimum age of registration stipulated by the laws of the user's country of residence, e.g., 16 in certain European regions). The Company does not knowingly collect personal information from children at the registration stage. If it is discovered that a child’s data has been collected, the respective account and all associated data will be permanently and immediately deleted.
7. Procedures and Methods for Destruction of Personal Information
- Destruction Procedure: Personal information whose retention period has expired or whose processing purpose has been achieved will be destroyed without delay.
- Destruction Method: Electronic files are permanently deleted using technical methods that render them unrecoverable, and printed paper documents are destroyed via shredding.
8. Rights of Users and Methods of Exercise
- Information Verification and Modification: Users can verify their registration profiles through 'My Page' within the app. Due to the nature of social logins (Google, Apple), detailed profile updates must be conducted through the account settings of the respective third-party platforms.
- Account Deletion & Erasure Request (Right to be Forgotten): Users can request account closure and data deletion at any time via the account deletion feature within the app. The Company will destroy the data without delay unless legal retention obligations apply.
- Global User Specific Rights (GDPR / CCPA, etc.): Global users residing in regions such as the European Union (EU) or California, USA, may exercise distinct rights according to local laws, including the right to restrict processing, the right to data portability, and the right to opt-out of the sale or sharing of personal information.
- Method of Exercising Rights: All exercises of rights, including requests to restrict processing of AI-entered logs, can be submitted via email to the Data Protection Officer (hello@stocknow.ai). Actions will be taken without delay upon identity verification.
9. Installation and Operation of Automatic Data Collection Technologies
The Company installs and operates automatic data collection technologies (such as SDKs) within the app to ensure stable operations and feature deliveries.
- Collected Items: IP address, device information, OS version, access timestamps, app usage logs, crash logs, network status, advertising identifiers (ADID or IDFA), and user event logs.
- Limitations: Users can opt-out of advertising identifier (ADID/IDFA) collections via their device settings. However, basic system information (IP, device info) essential for service delivery cannot be opted out of without restricting the use of the app.
10. Opting Out of Personalized Advertising Collections
- Android: Settings > Google > Ads > Opt out of Ads Personalization (or Reset/Delete Advertising ID).
- iOS: Settings > Privacy & Security > Tracking > Toggle off 'Allow Apps to Request to Track'.
11. Data Protection Officer (DPO) & Contact Information
- Data Protection Officer / Representative: Joonhoe Choi
- Email Address: hello@stocknow.ai
12. Amendments to the Privacy Policy
Any changes to this Privacy Policy will be notified via the announcements section within the Service. Modified policies shall take effect at least 7 days after the date of notification, and any material changes unfavorable to users will be announced 30 days prior.
13. Measures Regarding Dormant Accounts (Applicable to Republic of Korea Users Only)
In accordance with the applicable laws of the Republic of Korea, the personal information of users holding Korean nationality who have not logged into the Service for over one (1) year may be separated or destroyed. Prior notification will be sent to the registered email address before account dormancy occurs. (For global users, the retention guidelines apply as long as a continuous service relationship is maintained).
14. Remedies for Infringement of Rights and Interests
Users may contact the following entities to seek remedies for privacy infringements:
- Global Users: Users are encouraged to first seek resolution through the Company's official support channel (hello@stocknow.ai). If unresolved, users may file a complaint with the Data Protection Authority (DPA) of their country of residence or seek remedies through a court of competent jurisdiction.
- Republic of Korea Users: Privacy Infringement Report Center (privacy.kisa.or.kr) / Personal Information Dispute Mediation Committee (www.kopico.go.kr) / Cybercrime Investigation Division of the Supreme Prosecutors' Office (www.spo.go.kr) / Cyber Bureau of the National Police Agency (www.police.go.kr).
[ADDENDUM]
This policy shall take effect on August 15, 2026.