Privacy Policy

Effective Date: May 15, 2026

Bigtablet, Inc. (the "Company")

This English translation is provided for the convenience of Users. In the event of any discrepancy between the Korean and English versions, the Korean version prevails.

Bigtablet, Inc. establishes and discloses this Privacy Policy as set out below in order to protect Users' personal information and to handle related grievances promptly and smoothly, in accordance with applicable laws including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection.


Article 1 (Items of Personal Information Collected and Methods of Collection)

1. Items collected at membership registration

CategoryItems collectedRequired / OptionalRemarks
At registrationEmail address, password, name (nickname), consent records for the Terms of Service and this Privacy Policy (whether consent was given, date and time of consent)Required
At registrationProfile photo, name of affiliated organization, job title, mobile phone number, landline number, fax number, consent to receive promotional information (push notifications and email)Optional
At identity verificationIdentity verification unique value (DI)Required (when using the Pro Plan free trial)

2. Items collected automatically in the course of Service use

CategoryItems collected
Device informationDevice model name, OS type and version, app version
Usage recordsDate and time of Service use, access logs, feature usage records, Credit usage history
Network informationIP address, connection environment

3. Items collected upon payment for a Paid Subscription

Payment methodItems collected
In-app purchase (IAP)Payment date and time, subscription product name, transaction number (payment instrument information such as card numbers is processed directly by Apple/Google and is not collected by the Company)
Direct payment (Team Plan)Payment date and time, payment method type, card issuer name, transaction approval number (the full card number is processed by the payment gateway, and the Company retains only masked information)

4. Items collected in connection with core Service features

CategoryItems collectedRemarks
Recording dataMeeting recording audio filesStored on the User's device and on the Company's servers
STT resultsSpeech-to-text conversion outputsConverted on the Company's own servers; post-processing is performed via Google Cloud Vertex AI (Gemini) after the User's prior consent has been obtained
AI summary resultsAI-generated meeting summaries and follow-up schedulesProcessed via Google Cloud Vertex AI (Gemini) after the User's prior consent has been obtained
NotesReal-time notes entered directly by the User
Calendar integrationGoogle Calendar schedule information (with the User's consent)Accessed via the Google Calendar API
Customer informationName, email address, mobile phone number, landline number, fax number, affiliation, job titleEntered by the User for the purpose of sending meeting results and managing customers

5. Methods of collection

  • Entered directly by the User during registration for and use of the Service
  • Generated and collected automatically during use of the Service
  • Collected through an identity verification agency
  • Collected via API when Google Calendar integration is enabled
  • Entered directly by the User, including the contact details of third parties, through the meeting customer management feature

6. Notice regarding the entry of third-party information

Where a User enters the personal information of a third party, such as a customer, the User is responsible for securing lawful authority to collect and use that information and for notifying the data subject. The Company processes third-party information entered by a User solely for the purposes of sending meeting results and managing customers, in accordance with the User's instructions, and does not use it for any other purpose.

Under Article 20 of the Personal Information Protection Act, the data subject of third-party information may request that the Company notify them of the source of collection, the purpose of processing, and their right to request suspension of processing, and may request access to, correction or deletion of, or suspension of the processing of that information by the methods set out in Article 8.


Article 2 (Purposes of Collection and Use of Personal Information)

The Company uses the personal information it collects for the following purposes:

PurposeDetails
Provision of the ServiceMeeting recording, STT conversion, generation of AI summaries, generation of follow-up schedules, calendar integration, delivery of meeting results by email, customer management and contact
Member managementProcessing of registration and withdrawal, identity verification, prevention of misuse, response to customer inquiries
Subscription and payment managementProcessing of Paid Subscription payments, refund processing, fee settlement, management of payment records
Service improvementAnalysis of usage statistics, improvement of Service quality, development of new features (no identifying information other than the internal user ID is used)
Notices and announcementsNotification of Service changes, notification of amendments to the terms, delivery of marketing information (with separate consent)
Compliance with legal obligationsRetention of records under applicable laws, including the Act on Consumer Protection in Electronic Commerce

Article 3 (Retention and Use Period of Personal Information)

1. General principle

Personal information is destroyed without delay once the purpose of its collection and use has been achieved. However, where retention is required under applicable laws, the information is retained for the periods set out below.

2. Retention under applicable laws

Item retainedLegal basisRetention period
Records on contracts or withdrawal of offersAct on Consumer Protection in Electronic Commerce5 years
Records on payment and the supply of goodsAct on Consumer Protection in Electronic Commerce5 years
Records on consumer complaints or dispute resolutionAct on Consumer Protection in Electronic Commerce3 years
Personal information relating to Service use (log records)Protection of Communications Secrets Act3 months
Records on labeling and advertisingAct on Consumer Protection in Electronic Commerce6 months

3. Identity verification information

  • The DI collected through PASS identity verification when applying for the Pro free trial is retained for 1 year after withdrawal of membership, for the purpose of preventing misuse.
  • Records of the PASS identity verification process are destroyed within 14 days after withdrawal.

4. Information generated during use of the Service

  • Original recording files are retained for 1 year from the date of recording.
  • Recording data, summaries, STT results, User information, and customer information are destroyed within 14 days from the date of withdrawal of membership (where a retention obligation applies under applicable laws, destroyed after the expiry of that period).
  • When a meeting is deleted, the associated recording data is deleted together with it.
  • Consent records for the receipt of promotional information are destroyed within 14 days from the date of withdrawal of consent or withdrawal of membership.
  • Download click records are destroyed within 400 days.
  • Transcription data held on the AI STT processing servers is deleted within 7 days of completion of processing. The conversion output is retained within the Service so that the User can view it, and is destroyed within 14 days from the date of withdrawal of membership.
  • Access records of personal information handlers are retained for 1 year from the date of their creation.

5. Deactivated Organizations

  • Destroyed within 1 year after deactivation of a Team Plan Organization (where a retention obligation applies under applicable laws, destroyed after the expiry of that period).

Article 4 (Provision of Personal Information to Third Parties)

As a general principle, the Company does not provide Users' personal information to external parties. The following are exceptions:

1. Where the User's prior consent has been obtained

RecipientPurpose of provisionItems providedRetention periodRemarks
Google LLC (Calendar API)Calendar integration for follow-up schedulesSchedule title, date and time, locationUntil the integration is disconnectedThe integration is automatically disconnected when the Paid Subscription ends. Once the Google Calendar integration is disconnected, the imported Google Calendar events can no longer be viewed within the Service.

2. Where required by law

  • Where there is a court warrant or a lawful request from an investigative authority
  • Where there is an obligation to provide the information under applicable laws

Article 5 (Entrustment of Personal Information Processing)

The Company entrusts personal information processing tasks as follows in order to provide the Service smoothly:

Entrusted partyEntrusted taskRetention period
Toss Payments Co., Ltd.Team Plan payment processing and settlementUntil termination of the entrustment agreement
NICE Information Service Co., Ltd.Identity verificationImmediately upon completion of verification
Google LLC (Gmail SMTP)Delivery of meeting results by email and delivery of Service notification emailsImmediately upon completion of delivery
Google LLC (Firebase)App error and crash diagnostics, analysis of Service usage statistics, delivery of push notificationsUntil termination of the entrustment agreement
Google LLC (Google Cloud Vertex AI, Gemini)Generation of AI-based meeting summaries and follow-up schedules, generation of meeting titles, post-processing of STT transcripts (only where the User's prior consent has been obtained)Deleted immediately upon completion of API processing (retained for up to 7 days if API processing fails)
Google (GCP)Data storage and server operationUntil termination of the entrustment agreement

When entering into an entrustment agreement, the Company specifies in the contract, in accordance with the Personal Information Protection Act, matters such as the prohibition on processing personal information for purposes other than performing the entrusted task, measures to ensure security, restrictions on sub-entrustment, and the management and supervision of the entrusted party, and supervises whether the entrusted party processes personal information safely.


Article 6 (Overseas and Domestic Transfer of Personal Information)

The Company transfers personal information overseas and domestically in order to provide the Service, as set out below.

ItemDetails
RecipientGoogle LLC (Google Cloud Vertex AI, Gemini)
Country of transferThe United States and other countries in which Google Cloud regions are located. Note: because the Company uses the Vertex AI global endpoint, the country of processing is determined by the regions available at the time of the request and is not fixed to any particular country. The list of countries in which regions are located is available at https://cloud.google.com/about/locations.
Date and method of transferTransmitted in real time over the network when generation of an AI-based meeting summary or follow-up schedule, generation of a meeting title, or STT post-processing is requested
Items transferredThe STT transcription output of the meeting audio (text data in JSON format)
Purpose of transferGeneration of AI-based meeting summaries and follow-up schedules, generation of meeting titles, post-processing of STT transcripts
Retention and use periodDeleted immediately upon completion of API processing (retained for up to 7 days if API processing fails; otherwise handled in accordance with Google's data processing policies)
Contacthttps://support.google.com/policies/contact/general_privacy_form
ItemDetails
RecipientGoogle (GCP)
Country of transferRepublic of Korea
Date and method of transferTransmitted over the network when the Service is used
Items transferredRecording data (encrypted when stored), Service usage records
Purpose of transferStorage and backup of Service data
Retention and use periodUntil withdrawal of membership or expiry of the retention period
Contacthttps://support.google.com/policies/contact/general_privacy_form
ItemDetails
RecipientGoogle LLC (Firebase)
Country of transferUnited States
Date and method of transferTransmitted in real time over the network when the app is launched, when an error occurs, and when a push notification is sent
Items transferredInternal identification information (the internal member ID generated for the purpose of identifying Members at registration), app instance identifier, push token, app usage records (screen views and feature usage history), error diagnostic information (error codes, screen on which the error occurred, stack traces), device information (model, OS version, app version), and country of access based on IP address
Purpose of transferEnsuring app stability (error and crash diagnostics), analysis of Service usage statistics and quality improvement, delivery of push notifications
Retention and use periodApp usage records: 2 months from the date of collection. User identification information such as internal identification numbers: 14 months from the date of last activity. Error diagnostic information: 90 days. Push tokens: deletion is requested upon withdrawal of membership or upon opting out of notifications, and destruction takes place within 180 days of the request.
Contacthttps://support.google.com/policies/contact/general_privacy_form

For overseas transfers, the Company implements protective measures in accordance with Article 28-8 of the Personal Information Protection Act and enters into agreements on the protection of personal information with recipients.

Before transferring personal information to a third-party AI service, the Company obtains separate prior consent from the User; where consent is not given, the data is not transmitted. Users may withdraw that consent, or refuse the overseas transfer, at any time through customer support, in which case recording analysis features such as the provision of STT conversion results and the generation of AI summaries cannot be used.


Article 7 (Procedure and Method of Destruction of Personal Information)

1. Procedure for destruction

The Company destroys personal information without delay once the purpose of its collection and use has been achieved and the retention period has expired. Where retention is required under applicable laws, the information is stored separately in a distinct database and destroyed upon expiry of the applicable period.

2. Method of destruction

Storage formatMethod of destruction
Electronic filesPermanently deleted by a method that makes recovery impossible (backup copies are deleted successively in accordance with the backup retention cycle)
Paper documentsShredded or incinerated
Recording filesThe original files and all copies are deleted by a method that makes recovery impossible

Article 8 (Rights and Obligations of Users and Legal Representatives, and How to Exercise Them)

1. Rights of Users

Users (or their legal representatives), as well as the data subjects of third-party information entered by a User, may exercise the following rights at any time:

  • The right to request access to their personal information
  • The right to request correction or deletion of their personal information
  • The right to request suspension of the processing of their personal information
  • The right to withdraw consent

2. How to exercise these rights

  • Directly, through the settings screen within the Service, using the registered Member's account
  • By request to the customer support email (cs@bigtablet.com) or through the Q&A board on the website
  • By written request, email, or other method under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act

3. Processing period

The Company processes a request to exercise these rights within 10 days from the date of receipt. Where processing is delayed for justifiable reasons, the Company notifies the User of those reasons.

4. Exercise through an agent

Where a User's legal representative or a duly authorized person exercises these rights, that person must submit a power of attorney in the form prescribed by the Enforcement Rule of the Personal Information Protection Act.


Article 9 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information:

MeasureDetails
Administrative measuresEstablishment and implementation of an internal personal information management plan, minimization of the number of employees who handle personal information and provision of training to them, and periodic internal audits
Technical measuresEncryption of data in transit (TLS), encryption of stored data (AES-256), one-way encrypted storage of passwords (bcrypt), management and restriction of access privileges, installation and updating of security programs, and retention of access logs with protection against forgery and alteration
Physical measuresAccess control for work devices and document storage areas; physical security of data centers is handled by the cloud provider
Protection of recording dataRecording data is encrypted in transit using TLS and is encrypted with AES-256 when stored in cloud storage. Communications between internal processing servers apply HMAC-SHA256 signatures and request body hash verification in order to block unauthorized requests and the forgery or alteration of data, and nonce and timestamp verification is used to prevent replay attacks.

Article 10 (Operation of Cookies and Automatic Collection Devices)

1. Purpose of using cookies

When Users access the web services (such as the organization management page), the Company uses only essential cookies (session cookies) to maintain login status and improve convenience of use, and does not use cookies for analytics or advertising purposes.

2. How to refuse cookies

Users may refuse the storage of cookies or delete cookies through their web browser settings. However, where the storage of cookies is refused, use of certain Service features that require login may be restricted.

3. Advertising identifiers

The Company does not collect advertising identifiers (Android ADID/AAID or iOS IDFA) and does not use them to provide personalized advertising.


Article 11 (Personal Information of Children Under the Age of 14)

  1. The Company does not provide the Service to children under the age of 14 and, in accordance with its Terms of Service, restricts membership registration by children under the age of 14.
  2. At membership registration, the Company obtains confirmation from the User that they are aged 14 or older, and the Company does not operate any separate procedure for collecting or using the personal information of children under the age of 14.
  3. Where the Company confirms that a User is under the age of 14, it restricts that Account's use of the Service and destroys the personal information collected without delay.
  4. A legal representative may request access to, correction or deletion of, or suspension of the processing of a child's personal information by the methods set out in Article 8.

Article 12 (Special Protection of Recording Data and Use of Third-Party AI Services)

  1. Because recording data may contain sensitive business information belonging to Users, the Company applies enhanced protective measures to it.
  2. Processing flow for voice data
    • Recording → STT conversion on the Company's own servers (the original audio is not transmitted externally) → STT post-processing (Google Cloud Vertex AI) → generation of the AI summary and meeting title based on the converted text (Google Cloud Vertex AI) → delivery of results to the User
  3. Protection of the original audio
    • Original recording audio files are processed only within the server environment operated by the Company and are not transmitted to external providers. The storage and backup of recording data is carried out through the cloud processors set out in Articles 5 and 6, and the data is encrypted when stored.
  4. Access control for the Company's handlers
    • Within the scope necessary to respond to User inquiries and to resolve Service errors, a minimum number of personnel granted authority for that purpose may access recording data, STT transcripts, AI summaries, and notes.
    • Each access is logged and retained with the date and time of access, the handler, the data accessed, and the reason for access, and such information is not used for any purpose other than handling inquiries and resolving errors.
    • The Company reviews handlers' access privileges periodically and blocks access by unauthorized personnel.
  5. In order to provide AI summaries, meeting title generation, follow-up schedule recommendations, and STT transcript post-processing, the Company transmits the STT transcription output of the meeting audio (text data in JSON format) to Google LLC (Google Cloud Vertex AI) as set out in Articles 5 and 6. The User's account information, the original audio files, and customer information are not transmitted.
  6. The Company obtains the prior consent referred to in Article 6 when the User first uploads a recording file. Where the User does not consent, no data is transmitted and the Company does not provide the provision of STT conversion results, AI summaries, meeting title generation, or follow-up schedule recommendations.
  7. Data transmitted to the third-party AI service is not used to develop, improve, or train Google's artificial intelligence or machine learning models.

Article 13 (Google Integration Services)

  1. Where a User uses the Google Calendar integration feature, the Company requests only the minimum permissions necessary to provide the Service, through Google's OAuth authentication.
  2. The scope of access obtained through the integration is limited to the following, and the Company does not access other information stored in the User's Google account:
    • Retrieval of the User's calendar list (calendar names and identifiers)
    • Creation, reading, modification, and deletion of calendar events
  3. The Company does not create or delete calendars themselves, nor change calendar sharing permissions (access controls), and does not access other information stored in the User's Google account (such as Gmail, Contacts, or Drive).
  4. The Company's use of raw and derived data obtained through Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
  5. The Company does not use data obtained through Google Workspace APIs to develop, improve, or train generalized (non-personalized) artificial intelligence or machine learning models.
  6. The Company does not use data obtained through Google integrations for advertising purposes and does not sell or transfer such data to third parties for purposes other than providing the Service.
  7. Users may disconnect the integration at any time through the settings within the Service or through their Google account settings, and the integration is automatically disconnected when a Paid Subscription ends. Upon disconnection, the Company deletes the schedule information imported into the Service, immediately deletes the stored access and refresh tokens and any cached information relating to the integration, and then requests that Google revoke the tokens. After disconnection, events can no longer be viewed within the Service, but existing events remain viewable in Google Calendar.

Article 14 (Chief Privacy Officer)

The Company has designated a Chief Privacy Officer as set out below in order to protect Users' personal information and to handle complaints relating to personal information:

ItemDetails
NameMinho Park
PositionCTO
Contact053-424-9994 / cs@bigtablet.com

Users may report to the Chief Privacy Officer any inquiries, complaints, or requests for remedy relating to the protection of personal information that arise during use of the Service.


Article 15 (Remedies for Infringement of Rights)

Users who require reporting or consultation regarding infringement of their personal information may contact the following organizations:

OrganizationContactWebsite
Privacy Infringement Report Center (Korea Internet & Security Agency)118 (no area code)privacy.kisa.or.kr
Personal Information Dispute Mediation Committee1833-6972 (no area code)kopico.go.kr
Cyber Investigation Division, Supreme Prosecutors' Office1301 (no area code)spo.go.kr
Cyber Investigation Bureau, National Police Agency182 (no area code)ecrm.police.go.kr

Article 16 (Amendment of this Privacy Policy)

  1. This Privacy Policy may be amended in accordance with changes in applicable laws, policies, or the Service.
  2. Where this Privacy Policy is amended, the Company will give notice of the changes by in-Service announcement and by email at least 7 days before the effective date. However, where there is a material change to Users' rights, notice will be given at least 30 days in advance.
  3. Previous versions of this Privacy Policy are available within the Service.

Addendum

  1. This Privacy Policy takes effect on May 15, 2026.