Privacy Policy
Effective Date: May 15, 2026
Bigtablet, Inc. (the "Company")
This English translation is provided for the convenience of Users. In the event of any discrepancy between the Korean and English versions, the Korean version prevails.
Bigtablet, Inc. establishes and discloses this Privacy Policy as set out below in order to protect Users' personal information and to handle related grievances promptly and smoothly, in accordance with applicable laws including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection.
Article 1 (Items of Personal Information Collected and Methods of Collection)
1. Items collected at membership registration
| Category | Items collected | Required / Optional | Remarks |
|---|---|---|---|
| At registration | Email address, password, name (nickname), consent records for the Terms of Service and this Privacy Policy (whether consent was given, date and time of consent) | Required | |
| At registration | Profile photo, name of affiliated organization, job title, mobile phone number, landline number, fax number, consent to receive promotional information (push notifications and email) | Optional | |
| At identity verification | Identity verification unique value (DI) | Required (when using the Pro Plan free trial) |
2. Items collected automatically in the course of Service use
| Category | Items collected |
|---|---|
| Device information | Device model name, OS type and version, app version |
| Usage records | Date and time of Service use, access logs, feature usage records, Credit usage history |
| Network information | IP address, connection environment |
3. Items collected upon payment for a Paid Subscription
| Payment method | Items collected |
|---|---|
| In-app purchase (IAP) | Payment date and time, subscription product name, transaction number (payment instrument information such as card numbers is processed directly by Apple/Google and is not collected by the Company) |
| Direct payment (Team Plan) | Payment date and time, payment method type, card issuer name, transaction approval number (the full card number is processed by the payment gateway, and the Company retains only masked information) |
4. Items collected in connection with core Service features
| Category | Items collected | Remarks |
|---|---|---|
| Recording data | Meeting recording audio files | Stored on the User's device and on the Company's servers |
| STT results | Speech-to-text conversion outputs | Converted on the Company's own servers; post-processing is performed via Google Cloud Vertex AI (Gemini) after the User's prior consent has been obtained |
| AI summary results | AI-generated meeting summaries and follow-up schedules | Processed via Google Cloud Vertex AI (Gemini) after the User's prior consent has been obtained |
| Notes | Real-time notes entered directly by the User | |
| Calendar integration | Google Calendar schedule information (with the User's consent) | Accessed via the Google Calendar API |
| Customer information | Name, email address, mobile phone number, landline number, fax number, affiliation, job title | Entered by the User for the purpose of sending meeting results and managing customers |
5. Methods of collection
- Entered directly by the User during registration for and use of the Service
- Generated and collected automatically during use of the Service
- Collected through an identity verification agency
- Collected via API when Google Calendar integration is enabled
- Entered directly by the User, including the contact details of third parties, through the meeting customer management feature
6. Notice regarding the entry of third-party information
Where a User enters the personal information of a third party, such as a customer, the User is responsible for securing lawful authority to collect and use that information and for notifying the data subject. The Company processes third-party information entered by a User solely for the purposes of sending meeting results and managing customers, in accordance with the User's instructions, and does not use it for any other purpose.
Under Article 20 of the Personal Information Protection Act, the data subject of third-party information may request that the Company notify them of the source of collection, the purpose of processing, and their right to request suspension of processing, and may request access to, correction or deletion of, or suspension of the processing of that information by the methods set out in Article 8.
Article 2 (Purposes of Collection and Use of Personal Information)
The Company uses the personal information it collects for the following purposes:
| Purpose | Details |
|---|---|
| Provision of the Service | Meeting recording, STT conversion, generation of AI summaries, generation of follow-up schedules, calendar integration, delivery of meeting results by email, customer management and contact |
| Member management | Processing of registration and withdrawal, identity verification, prevention of misuse, response to customer inquiries |
| Subscription and payment management | Processing of Paid Subscription payments, refund processing, fee settlement, management of payment records |
| Service improvement | Analysis of usage statistics, improvement of Service quality, development of new features (no identifying information other than the internal user ID is used) |
| Notices and announcements | Notification of Service changes, notification of amendments to the terms, delivery of marketing information (with separate consent) |
| Compliance with legal obligations | Retention of records under applicable laws, including the Act on Consumer Protection in Electronic Commerce |
Article 3 (Retention and Use Period of Personal Information)
1. General principle
Personal information is destroyed without delay once the purpose of its collection and use has been achieved. However, where retention is required under applicable laws, the information is retained for the periods set out below.
2. Retention under applicable laws
| Item retained | Legal basis | Retention period |
|---|---|---|
| Records on contracts or withdrawal of offers | Act on Consumer Protection in Electronic Commerce | 5 years |
| Records on payment and the supply of goods | Act on Consumer Protection in Electronic Commerce | 5 years |
| Records on consumer complaints or dispute resolution | Act on Consumer Protection in Electronic Commerce | 3 years |
| Personal information relating to Service use (log records) | Protection of Communications Secrets Act | 3 months |
| Records on labeling and advertising | Act on Consumer Protection in Electronic Commerce | 6 months |
3. Identity verification information
- The DI collected through PASS identity verification when applying for the Pro free trial is retained for 1 year after withdrawal of membership, for the purpose of preventing misuse.
- Records of the PASS identity verification process are destroyed within 14 days after withdrawal.
4. Information generated during use of the Service
- Original recording files are retained for 1 year from the date of recording.
- Recording data, summaries, STT results, User information, and customer information are destroyed within 14 days from the date of withdrawal of membership (where a retention obligation applies under applicable laws, destroyed after the expiry of that period).
- When a meeting is deleted, the associated recording data is deleted together with it.
- Consent records for the receipt of promotional information are destroyed within 14 days from the date of withdrawal of consent or withdrawal of membership.
- Download click records are destroyed within 400 days.
- Transcription data held on the AI STT processing servers is deleted within 7 days of completion of processing. The conversion output is retained within the Service so that the User can view it, and is destroyed within 14 days from the date of withdrawal of membership.
- Access records of personal information handlers are retained for 1 year from the date of their creation.
5. Deactivated Organizations
- Destroyed within 1 year after deactivation of a Team Plan Organization (where a retention obligation applies under applicable laws, destroyed after the expiry of that period).
Article 4 (Provision of Personal Information to Third Parties)
As a general principle, the Company does not provide Users' personal information to external parties. The following are exceptions:
1. Where the User's prior consent has been obtained
| Recipient | Purpose of provision | Items provided | Retention period | Remarks |
|---|---|---|---|---|
| Google LLC (Calendar API) | Calendar integration for follow-up schedules | Schedule title, date and time, location | Until the integration is disconnected | The integration is automatically disconnected when the Paid Subscription ends. Once the Google Calendar integration is disconnected, the imported Google Calendar events can no longer be viewed within the Service. |
2. Where required by law
- Where there is a court warrant or a lawful request from an investigative authority
- Where there is an obligation to provide the information under applicable laws
Article 5 (Entrustment of Personal Information Processing)
The Company entrusts personal information processing tasks as follows in order to provide the Service smoothly:
| Entrusted party | Entrusted task | Retention period |
|---|---|---|
| Toss Payments Co., Ltd. | Team Plan payment processing and settlement | Until termination of the entrustment agreement |
| NICE Information Service Co., Ltd. | Identity verification | Immediately upon completion of verification |
| Google LLC (Gmail SMTP) | Delivery of meeting results by email and delivery of Service notification emails | Immediately upon completion of delivery |
| Google LLC (Firebase) | App error and crash diagnostics, analysis of Service usage statistics, delivery of push notifications | Until termination of the entrustment agreement |
| Google LLC (Google Cloud Vertex AI, Gemini) | Generation of AI-based meeting summaries and follow-up schedules, generation of meeting titles, post-processing of STT transcripts (only where the User's prior consent has been obtained) | Deleted immediately upon completion of API processing (retained for up to 7 days if API processing fails) |
| Google (GCP) | Data storage and server operation | Until termination of the entrustment agreement |
When entering into an entrustment agreement, the Company specifies in the contract, in accordance with the Personal Information Protection Act, matters such as the prohibition on processing personal information for purposes other than performing the entrusted task, measures to ensure security, restrictions on sub-entrustment, and the management and supervision of the entrusted party, and supervises whether the entrusted party processes personal information safely.
Article 6 (Overseas and Domestic Transfer of Personal Information)
The Company transfers personal information overseas and domestically in order to provide the Service, as set out below.
| Item | Details |
|---|---|
| Recipient | Google LLC (Google Cloud Vertex AI, Gemini) |
| Country of transfer | The United States and other countries in which Google Cloud regions are located. Note: because the Company uses the Vertex AI global endpoint, the country of processing is determined by the regions available at the time of the request and is not fixed to any particular country. The list of countries in which regions are located is available at https://cloud.google.com/about/locations. |
| Date and method of transfer | Transmitted in real time over the network when generation of an AI-based meeting summary or follow-up schedule, generation of a meeting title, or STT post-processing is requested |
| Items transferred | The STT transcription output of the meeting audio (text data in JSON format) |
| Purpose of transfer | Generation of AI-based meeting summaries and follow-up schedules, generation of meeting titles, post-processing of STT transcripts |
| Retention and use period | Deleted immediately upon completion of API processing (retained for up to 7 days if API processing fails; otherwise handled in accordance with Google's data processing policies) |
| Contact | https://support.google.com/policies/contact/general_privacy_form |
| Item | Details |
|---|---|
| Recipient | Google (GCP) |
| Country of transfer | Republic of Korea |
| Date and method of transfer | Transmitted over the network when the Service is used |
| Items transferred | Recording data (encrypted when stored), Service usage records |
| Purpose of transfer | Storage and backup of Service data |
| Retention and use period | Until withdrawal of membership or expiry of the retention period |
| Contact | https://support.google.com/policies/contact/general_privacy_form |
| Item | Details |
|---|---|
| Recipient | Google LLC (Firebase) |
| Country of transfer | United States |
| Date and method of transfer | Transmitted in real time over the network when the app is launched, when an error occurs, and when a push notification is sent |
| Items transferred | Internal identification information (the internal member ID generated for the purpose of identifying Members at registration), app instance identifier, push token, app usage records (screen views and feature usage history), error diagnostic information (error codes, screen on which the error occurred, stack traces), device information (model, OS version, app version), and country of access based on IP address |
| Purpose of transfer | Ensuring app stability (error and crash diagnostics), analysis of Service usage statistics and quality improvement, delivery of push notifications |
| Retention and use period | App usage records: 2 months from the date of collection. User identification information such as internal identification numbers: 14 months from the date of last activity. Error diagnostic information: 90 days. Push tokens: deletion is requested upon withdrawal of membership or upon opting out of notifications, and destruction takes place within 180 days of the request. |
| Contact | https://support.google.com/policies/contact/general_privacy_form |
For overseas transfers, the Company implements protective measures in accordance with Article 28-8 of the Personal Information Protection Act and enters into agreements on the protection of personal information with recipients.
Before transferring personal information to a third-party AI service, the Company obtains separate prior consent from the User; where consent is not given, the data is not transmitted. Users may withdraw that consent, or refuse the overseas transfer, at any time through customer support, in which case recording analysis features such as the provision of STT conversion results and the generation of AI summaries cannot be used.
Article 7 (Procedure and Method of Destruction of Personal Information)
1. Procedure for destruction
The Company destroys personal information without delay once the purpose of its collection and use has been achieved and the retention period has expired. Where retention is required under applicable laws, the information is stored separately in a distinct database and destroyed upon expiry of the applicable period.
2. Method of destruction
| Storage format | Method of destruction |
|---|---|
| Electronic files | Permanently deleted by a method that makes recovery impossible (backup copies are deleted successively in accordance with the backup retention cycle) |
| Paper documents | Shredded or incinerated |
| Recording files | The original files and all copies are deleted by a method that makes recovery impossible |
Article 8 (Rights and Obligations of Users and Legal Representatives, and How to Exercise Them)
1. Rights of Users
Users (or their legal representatives), as well as the data subjects of third-party information entered by a User, may exercise the following rights at any time:
- The right to request access to their personal information
- The right to request correction or deletion of their personal information
- The right to request suspension of the processing of their personal information
- The right to withdraw consent
2. How to exercise these rights
- Directly, through the settings screen within the Service, using the registered Member's account
- By request to the customer support email (
cs@bigtablet.com) or through the Q&A board on the website - By written request, email, or other method under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act
3. Processing period
The Company processes a request to exercise these rights within 10 days from the date of receipt. Where processing is delayed for justifiable reasons, the Company notifies the User of those reasons.
4. Exercise through an agent
Where a User's legal representative or a duly authorized person exercises these rights, that person must submit a power of attorney in the form prescribed by the Enforcement Rule of the Personal Information Protection Act.
Article 9 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information:
| Measure | Details |
|---|---|
| Administrative measures | Establishment and implementation of an internal personal information management plan, minimization of the number of employees who handle personal information and provision of training to them, and periodic internal audits |
| Technical measures | Encryption of data in transit (TLS), encryption of stored data (AES-256), one-way encrypted storage of passwords (bcrypt), management and restriction of access privileges, installation and updating of security programs, and retention of access logs with protection against forgery and alteration |
| Physical measures | Access control for work devices and document storage areas; physical security of data centers is handled by the cloud provider |
| Protection of recording data | Recording data is encrypted in transit using TLS and is encrypted with AES-256 when stored in cloud storage. Communications between internal processing servers apply HMAC-SHA256 signatures and request body hash verification in order to block unauthorized requests and the forgery or alteration of data, and nonce and timestamp verification is used to prevent replay attacks. |
Article 10 (Operation of Cookies and Automatic Collection Devices)
1. Purpose of using cookies
When Users access the web services (such as the organization management page), the Company uses only essential cookies (session cookies) to maintain login status and improve convenience of use, and does not use cookies for analytics or advertising purposes.
2. How to refuse cookies
Users may refuse the storage of cookies or delete cookies through their web browser settings. However, where the storage of cookies is refused, use of certain Service features that require login may be restricted.
3. Advertising identifiers
The Company does not collect advertising identifiers (Android ADID/AAID or iOS IDFA) and does not use them to provide personalized advertising.
Article 11 (Personal Information of Children Under the Age of 14)
- The Company does not provide the Service to children under the age of 14 and, in accordance with its Terms of Service, restricts membership registration by children under the age of 14.
- At membership registration, the Company obtains confirmation from the User that they are aged 14 or older, and the Company does not operate any separate procedure for collecting or using the personal information of children under the age of 14.
- Where the Company confirms that a User is under the age of 14, it restricts that Account's use of the Service and destroys the personal information collected without delay.
- A legal representative may request access to, correction or deletion of, or suspension of the processing of a child's personal information by the methods set out in Article 8.
Article 12 (Special Protection of Recording Data and Use of Third-Party AI Services)
- Because recording data may contain sensitive business information belonging to Users, the Company applies enhanced protective measures to it.
- Processing flow for voice data
- Recording → STT conversion on the Company's own servers (the original audio is not transmitted externally) → STT post-processing (Google Cloud Vertex AI) → generation of the AI summary and meeting title based on the converted text (Google Cloud Vertex AI) → delivery of results to the User
- Protection of the original audio
- Original recording audio files are processed only within the server environment operated by the Company and are not transmitted to external providers. The storage and backup of recording data is carried out through the cloud processors set out in Articles 5 and 6, and the data is encrypted when stored.
- Access control for the Company's handlers
- Within the scope necessary to respond to User inquiries and to resolve Service errors, a minimum number of personnel granted authority for that purpose may access recording data, STT transcripts, AI summaries, and notes.
- Each access is logged and retained with the date and time of access, the handler, the data accessed, and the reason for access, and such information is not used for any purpose other than handling inquiries and resolving errors.
- The Company reviews handlers' access privileges periodically and blocks access by unauthorized personnel.
- In order to provide AI summaries, meeting title generation, follow-up schedule recommendations, and STT transcript post-processing, the Company transmits the STT transcription output of the meeting audio (text data in JSON format) to Google LLC (Google Cloud Vertex AI) as set out in Articles 5 and 6. The User's account information, the original audio files, and customer information are not transmitted.
- The Company obtains the prior consent referred to in Article 6 when the User first uploads a recording file. Where the User does not consent, no data is transmitted and the Company does not provide the provision of STT conversion results, AI summaries, meeting title generation, or follow-up schedule recommendations.
- Data transmitted to the third-party AI service is not used to develop, improve, or train Google's artificial intelligence or machine learning models.
Article 13 (Google Integration Services)
- Where a User uses the Google Calendar integration feature, the Company requests only the minimum permissions necessary to provide the Service, through Google's OAuth authentication.
- The scope of access obtained through the integration is limited to the following, and the Company does not access other information stored in the User's Google account:
- Retrieval of the User's calendar list (calendar names and identifiers)
- Creation, reading, modification, and deletion of calendar events
- The Company does not create or delete calendars themselves, nor change calendar sharing permissions (access controls), and does not access other information stored in the User's Google account (such as Gmail, Contacts, or Drive).
- The Company's use of raw and derived data obtained through Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
- The Company does not use data obtained through Google Workspace APIs to develop, improve, or train generalized (non-personalized) artificial intelligence or machine learning models.
- The Company does not use data obtained through Google integrations for advertising purposes and does not sell or transfer such data to third parties for purposes other than providing the Service.
- Users may disconnect the integration at any time through the settings within the Service or through their Google account settings, and the integration is automatically disconnected when a Paid Subscription ends. Upon disconnection, the Company deletes the schedule information imported into the Service, immediately deletes the stored access and refresh tokens and any cached information relating to the integration, and then requests that Google revoke the tokens. After disconnection, events can no longer be viewed within the Service, but existing events remain viewable in Google Calendar.
Article 14 (Chief Privacy Officer)
The Company has designated a Chief Privacy Officer as set out below in order to protect Users' personal information and to handle complaints relating to personal information:
| Item | Details |
|---|---|
| Name | Minho Park |
| Position | CTO |
| Contact | 053-424-9994 / cs@bigtablet.com |
Users may report to the Chief Privacy Officer any inquiries, complaints, or requests for remedy relating to the protection of personal information that arise during use of the Service.
Article 15 (Remedies for Infringement of Rights)
Users who require reporting or consultation regarding infringement of their personal information may contact the following organizations:
| Organization | Contact | Website |
|---|---|---|
| Privacy Infringement Report Center (Korea Internet & Security Agency) | 118 (no area code) | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | kopico.go.kr |
| Cyber Investigation Division, Supreme Prosecutors' Office | 1301 (no area code) | spo.go.kr |
| Cyber Investigation Bureau, National Police Agency | 182 (no area code) | ecrm.police.go.kr |
Article 16 (Amendment of this Privacy Policy)
- This Privacy Policy may be amended in accordance with changes in applicable laws, policies, or the Service.
- Where this Privacy Policy is amended, the Company will give notice of the changes by in-Service announcement and by email at least 7 days before the effective date. However, where there is a material change to Users' rights, notice will be given at least 30 days in advance.
- Previous versions of this Privacy Policy are available within the Service.
Addendum
- This Privacy Policy takes effect on May 15, 2026.