monosemy

Privacy Policy

Effective for existing Users: September 29, 2026

Monosemy Privacy Policy v4

Publication date: August 29, 2026, 10:00 KST
Effective date for new Users: August 29, 2026, 10:00 KST
Effective date for existing Users: September 29, 2026, 00:00 KST

Monote Labs Co., Ltd. (the "Company") complies with the Personal Information Protection Act and other applicable laws and processes the personal information of users of Monosemy and its related web and application services (the "Service") as follows.

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information being processed will not be used for purposes other than those stated below. If a purpose of use changes, the Company will take necessary measures in accordance with applicable law, such as obtaining separate consent.

  1. Membership registration and management
  • Confirming intent to register, identifying and authenticating members, managing accounts, maintaining and managing membership status, preventing misuse, providing notices and notifications, and handling inquiries and grievances
  1. Provision of the Service
  • Creating, storing, and synchronizing notes; processing handwriting, sketches, images, and text; providing AI-based note analysis, summarization, search, conversion, and generation; providing and improving Trial Features; customer support; and error handling
  1. Service improvement and research
  • Analyzing use of the Service, improving errors and performance, improving user experience, and improving the quality of AI Features
  • Improvement and research of AI models and features are conducted only where the User has given separate consent (Section 2.4).
  1. Security and prevention of misuse
  • Detecting abnormal use, preventing account takeover and service abuse, responding to security incidents, and handling disputes
  1. Notifications and event operations
  • Sending service operation notices, announcing service changes, sending push notifications, and operating friend-invitation programs or events
  1. Provision of Paid Services
  • If Paid Services are offered in the future, processing payments, withdrawals, refunds, settlement, and retention of transaction records

2. Categories of Personal Information Processed and Legal Bases

The Company processes the minimum personal information necessary to provide the Service.

2.1 Membership Registration and Account Management

Categories processed:

  • Email address
  • Password or authentication information that replaces a password
  • When Google or Apple social login is used, the identifier, email address, and profile information received from the provider to the extent necessary to provide the Service
  • Display name, intended use and user type, and how the User learned about the Service, if entered by the User

Purposes:

  • Membership registration, login, identification, account management, and prevention of misuse

Legal bases:

  • Article 15(1)4 of the Personal Information Protection Act: processing necessary to enter into and perform a contract
  • Consent of the data subject for intended use, user type, and referral source, which are optional input fields

2.2 Use of the Service and Provision of AI Features

Categories processed:

  • Notes, handwriting, sketches, images, text, and files created, entered, or uploaded by the User
  • Handwriting input information such as stroke coordinates, stroke order, and pressure
  • Requests, commands, questions, and conversations exchanged with AI Features
  • Answers, summaries, organized notes, analyses, conversions, and other AI Output generated through AI Features
  • Note creation, modification, and deletion times; feature usage records; and in-app interaction records

Purposes:

  • Providing note features, storing and synchronizing User Content, providing AI Features, customer support, error identification, and service improvement

Legal bases:

  • Article 15(1)4 of the Personal Information Protection Act: processing necessary to perform the service agreement
  • Article 15(1)6 of the Personal Information Protection Act: processing necessary to pursue the legitimate interests of the personal information controller, limited to the temporary collection for responding to security threats described below

Processing:

  • Note content and conversations that pass through the Company's servers to provide AI Features are deleted as soon as the processing purpose is achieved and are not separately stored on the Company's servers. Information of Users who consent to improvement and research under Section 2.4 is handled as described in that Section.
  • Processing-result information other than conversation content, including whether a request succeeded or failed, response time, tool-call results, model used, and token usage, is processed under Section 2.3 for error analysis and quality improvement.
  • Staged and temporary processing in response to security threats: The Company does not ordinarily store or review note content or conversations for incident-response purposes. Even after becoming aware of an urgent security threat such as a security incident, account takeover, or system misuse or abuse, the Company first reviews content-free error, access, and request metadata and security indicators. Only where those records are insufficient to identify the cause and there is an imminent risk of further harm may the Company temporarily collect and review processing records relating to the information in this Section, including note content and conversations passing through its servers, limited to the minimum scope and period directly related to the incident. At collection, the Company minimizes exposure of personal and sensitive information through automated masking and other safeguards, limits access to personnel designated in advance for incident response, and records the reason, subject, and time of access. It destroys collected records and working copies as soon as the purpose is achieved. If the Company learns that sensitive information is included, it does not use that information in the analysis and deletes it without delay unless law provides a legal basis for the processing or the User has separately consented.

2.3 Information Collected Automatically

Categories processed:

  • IP address, access date and time, service usage records, error logs, and performance logs
  • Whether an AI request succeeded or failed, response time, tool-call results, model used, and token usage, excluding conversation content
  • Device information, operating system, app version, device installation identifier, and language and region settings
  • Cookies or similar identifiers
  • User identifiers assigned for service analytics and error monitoring, and records of in-app and web service events
  • Country and region estimated from the access IP address
  • Push-notification token

Purposes:

  • Providing the Service, security, error response, quality improvement, statistical analysis, and sending push notifications

Legal bases:

  • Article 15(1)4 of the Personal Information Protection Act: processing necessary to perform the service agreement
  • Article 15(1)6 of the Personal Information Protection Act: processing necessary to pursue the legitimate interests of the personal information controller, only to the extent those interests do not override the rights of the data subject

2.4 Use for Improvement and Research of AI Models and Features (Optional Consent)

Categories processed:

  • Handwriting input information (coordinates, stroke order, and pressure), sketches, note content, AI conversations, recognition results, corrections made by the User to recognition results, and the User's responses to automatic input suggestions, to the extent necessary for improvement and research of AI models and features

Purposes:

  • Developing handwriting and sketch recognition models and user-intent classification models
  • Reviewing AI response quality, analyzing causes of errors, and improving AI Features
  • Service research and statistical analysis

Legal basis:

  • Article 15(1)1 of the Personal Information Protection Act: consent of the data subject

Processing: ① The Company collects and processes only information of Users who have separately consented to its use for improvement and research of AI models and features. This consent is optional, and a User who does not consent may use all features of the Service without restriction.

② The Company anonymizes information at the time of collection and stores it in a form that cannot identify a specific individual. It does not store account identifiers or other information that would permit tracing the information back to a specific User, and it does not attempt re-identification by any means.

③ Before storage, the Company operates a process that automatically detects and removes personal information that may be included in content. Current detection targets include contact information (email addresses and telephone numbers), financial information (payment-card and bank-account numbers), and unique identification information (resident registration and passport numbers). The Company continually expands and improves the range and accuracy of detection. Because automated detection is imperfect, the Company cannot guarantee that every item of personal or sensitive information will be completely removed.

④ A User may withdraw consent at any time through the app settings or by emailing privacy@monote.it. Withdrawal immediately stops any further collection. Information already collected, however, is stored in a form that cannot identify a specific individual under paragraph ②, so the Company cannot identify an individual User's information and cannot provide individual access, correction, or deletion. The Company explains this when obtaining consent.

⑤ The following information is excluded from improvement and research regardless of consent:

  • Information from accounts indicated as belonging to a person under 14
  • Information from Users who have not registered for an account
  • Information from accounts for which withdrawal of membership has been requested

⑥ The Company does not collect or use sensitive information for improvement or research. If it learns that sensitive information is included during processing, it destroys that information without delay. Other matters concerning sensitive information are governed by Section 2.7.

⑦ The Company designs its storage structure so that no User-level linkage remains in information used for improvement and research, and continually reviews and supplements technical and administrative safeguards to reduce the possibility of re-identification.

⑧ The Company uses AI models developed through this process to provide and improve the Service. A trained model is not personal information because it is in a form that cannot identify a specific individual.

2.5 Events and Marketing

Categories processed:

  • Email address, push-notification token, invitation code, information about the relationship between referrer and referred User, and event-participation and reward-payment history

Purposes:

  • Friend invitations, referral rewards, event operations, and notices about service news and benefits

Legal basis:

  • Consent of the data subject

The Company sends commercial advertising only with the User's prior consent, and the User may withdraw that consent at any time. The Company does not send advertising from 9:00 p.m. to 8:00 a.m. the following day. Notices and announcements necessary to use the Service are not commercial advertising and may be sent regardless of marketing consent.

2.6 If Paid Services Are Provided

The Service is currently provided free of charge in principle. If the Company later provides Paid Services, subscriptions, Credits, paid AI Features, or additional storage, it may process the following information and will amend and publish this Policy at that time.

Categories processed:

  • Transaction-identification information provided by an app-market operator or payment processor in relation to a payment method
  • Payment amount, payment date and time, product name, refund and cancellation history, receipts, and transaction records

Purposes:

  • Providing Paid Services, payment, refunds, settlement, customer support, and retention of transaction records required by law

Legal bases:

  • Article 15(1)4 of the Personal Information Protection Act: performance of a contract
  • Compliance with obligations under the Act on the Consumer Protection in Electronic Commerce and other applicable laws

2.7 Sensitive Information and Unique Identification Information

① The Company does not intentionally collect sensitive information concerning health, philosophical beliefs, political opinions, membership in or withdrawal from a labor union or political party, genetic information, or criminal records.

② The Company does not collect unique identification information such as resident registration numbers.

③ Sensitive information may nevertheless be included when a User writes freely in notes. The Company does not separately classify such information or use it beyond the purpose of collection. When information is used for improvement and research under Section 2.4, the Company applies the automated detection and removal process described in paragraph ③ of that Section and continually expands its scope.

④ Because the automated detection and removal process may not be technically complete, the Company recommends that Users not enter sensitive information into the Service.

⑤ If the Company learns that sensitive information is included during a security-threat response under Section 2.2, it does not use that sensitive information in the analysis and destroys it without delay unless law provides a legal basis for the processing or the User has separately consented.

3. Processing and Retention Periods

The Company processes and retains personal information within the retention period required by law or agreed to by the data subject.

  1. Member information
  • Retention: until 30 days after the request to withdraw membership
  • A User may request account restoration during the 30 days following a withdrawal request. Member information is destroyed after that period.
  1. User Content and backup data
  • Retention: until deleted by the Member or until 30 days after a withdrawal request
  • Backup data of an account that has not accessed the Service for at least one year may be deleted after advance notice.
  1. Service usage records, access records, and error logs
  • Retention: until the processing purpose is achieved. Access records, however, are retained for no longer than one year from collection.
  • If necessary to investigate a security incident, prevent misuse, or handle a dispute, the records may be retained until that purpose is achieved.
  • Information pseudonymized or anonymized so that an individual cannot be identified may continue to be retained and used for service analytics and operational statistics under Sections 8 and 9.
  1. Information processed with consent for improvement and research of AI models and features
  • Because the information is anonymized at collection under Section 2.4 and stored in a form that cannot identify a specific individual, personal-information retention periods do not apply.
  • Withdrawal of consent immediately stops any further collection.
  • Use and management of the information are governed by Section 9.
  • Information collected before August 10, 2026 under the previous Privacy Policy is destroyed without delay if the User requests destruction or withdraws membership.
  1. Note content and conversations passing through the Company's servers to provide AI Features
  • Deleted as soon as the processing purpose is achieved and not separately stored.
  • Information of Users who consent to improvement and research under Section 2.4 is governed by paragraph 4 above.
  • Information temporarily collected to respond to a security threat under Section 2.2 is destroyed as soon as the purposes of cause analysis and prevention of further harm are achieved.
  1. Consent and withdrawal history
  • Retention: three years after withdrawal of membership
  • Basis: proving consent and handling disputes
  1. Inquiry and dispute-handling records
  • Retention: three years after completion
  • Basis: the Act on the Consumer Protection in Electronic Commerce
  1. Information pseudonymized under Section 8
  • Retention: until the purpose of processing the pseudonymized information is achieved
  • When that purpose is achieved, the Company destroys or anonymizes the information in accordance with applicable law and internal standards.
  1. Paid-Service transaction records
  • Records concerning contracts or withdrawal of subscription: five years
  • Records concerning payment and supply of goods or services: five years
  • Records concerning consumer complaints or dispute handling: three years
  • Basis: the Act on the Consumer Protection in Electronic Commerce

4. Procedures and Methods for Destruction of Personal Information

① When personal information becomes unnecessary because its retention period has expired or its processing purpose has been achieved, the Company destroys it without delay.

② Personal information in electronic-file form is deleted by a secure method that prevents recovery or reproduction.

③ Personal information recorded on paper is shredded or incinerated.

④ When a Member requests withdrawal of membership, the Company destroys account information and backup data after the 30-day restoration period specified in paragraphs 1 and 2 of Section 3.

⑤ Information collected for improvement and research under a previous Privacy Policy is destroyed immediately upon a withdrawal request under the proviso to paragraph 4 of Section 3. It is not restored even if the User restores the account during the restoration period in paragraph ④.

⑥ Pseudonymized and anonymized information is separately managed in accordance with applicable law and internal standards.

5. Provision of Personal Information to Third Parties

The Company does not provide Users' personal information to third parties, except where:

  1. the User has consented in advance;
  2. a statute specifically provides for the disclosure or disclosure is unavoidable to comply with a legal obligation; or
  3. an investigative authority, supervisory authority, court, or other competent authority lawfully requires it.

The Company does not provide Users' personal information for a third party's own purposes and, in particular, contractually prohibits processors from using Users' information to train their own AI models.

If the Company transfers personal information in connection with a transfer of all or part of its business, a merger, or similar transaction, it gives advance notice under Article 27 of the Personal Information Protection Act of the transfer, the name, address, and contact information of the recipient, and the methods and procedures available to a User who does not want the transfer.

Entrustment of personal information processing and international transfers necessary to provide the Service are described in Sections 6 and 7.

6. Entrustment of Personal Information Processing

The Company may entrust the following personal information processing operations to provide the Service smoothly.

ProcessorEntrusted operationCategories processed
Amazon Web Services Korea LLC or Amazon Web Services, Inc.Cloud infrastructure, server operation, and data storage (Seoul Region, ap-northeast-2)Account information, User Content, service usage records
Supabase, Inc.Authentication, account management, database, note backup, and usage-quota management (using AWS Seoul Region infrastructure)Account information, authentication information, backed-up User Content, service usage records
Cloudflare, Inc.Object storage (R2), network, security, and content deliveryUser Content, connection information, stored data
Google LLCSocial login, AI processing (Gemini), map-widget display and place search, push notifications (Firebase Cloud Messaging), analytics, and operational toolsLogin identifiers, AI request information, place-search terms entered in the map widget, push tokens, service usage information
Anthropic, PBCProvision of AI FeaturesUser Content and requests entered into AI Features
Groq, Inc.Provision of AI Features (widget conversion and recommendations)User Content and requests entered into AI Features
OpenRouter, Inc.AI model routing and embedding generationUser Content and requests entered into AI Features
OpenAI OpCo, LLC and OpenAI, LLC (through OpenRouter)AI processing and output generation using OpenAI large language modelsUser Content and requests entered into an AI Feature that selects or is routed to such a model
RunPod, Inc.GPU processing for handwriting and image recognitionHandwriting images, document images
Brave Software, Inc.Provision of web-search resultsSearch terms entered by the User
Serper.devProvision of web- and image-search resultsSearch terms entered by the User
Wolfram Alpha LLCFormula computation and solutionFormulas entered by the User
Desmos Studio PBCGraph-widget displayFormulas entered by the User
Kakao Corp.Map display and place searchPlace-search terms entered by the User
Apple Inc.Sign in with Apple and push-notification functions (APNs)Login identifiers, push tokens
PostHog, Inc.Service analytics and statistics (EU Frankfurt Region)User identifier, in-app and web service event records, device and browser environment information, country and region estimated from IP address
Sentry (Functional Software, Inc.)Error and performance monitoring (EU Region)Error events, device, operating-system and app-version information, User identifier

For AI model routing and embedding generation through OpenRouter, Inc., actual computation is sub-entrusted to infrastructure providers connected by OpenRouter. Providers currently identified for the model paths used by the Company are GMI Cloud, Cloudflare, Perplexity, OpenAI, Microsoft Azure, Amazon Web Services, and Alibaba Cloud. The Company excludes SiliconFlow from routing. The Company does not opt in to OpenRouter prompt or response storage and applies a data-collection-deny setting to every request so requests are not sent to providers that permit model-training use or separate retention of input content. If the provider list or processing conditions change, the Company updates this Policy before actual transmission.

When entering into an entrustment agreement, the Company documents matters required by Article 26 of the Personal Information Protection Act, including prohibition on processing personal information beyond the purpose of the entrusted operation, security safeguards, restrictions on sub-entrustment, management and supervision of the processor, and liability for damages. The Company manages and supervises processors to ensure that personal information is handled safely.

If an entrusted operation or processor changes, the Company discloses the change in this Policy without delay.

7. International Transfers of Personal Information

The Company may transfer personal information internationally as follows to provide the Service.

Legal bases for international transfers:

  • Article 28-8(1)3 of the Personal Information Protection Act: entrustment or storage necessary to perform a contract where the matters specified in paragraph 2 of that Article are disclosed in this Policy
  • Separate consent where otherwise required
RecipientCountryCategories transferredPurposeTiming and methodRetention and use period
Cloudflare, Inc.United States and othersUser Content, stored data, connection informationObject storage (R2), network, and securityNetwork transmission when the Service is usedUntil termination of the entrustment agreement or achievement of the processing purpose
Anthropic, PBCUnited StatesUser Content and request information entered into AI FeaturesAI processing and output generationAPI transmission when an AI Feature is usedDeleted within 30 days after the processing purpose is achieved; content suspected of violating terms may be retained for up to two years; not used for model training
Groq, Inc.United StatesUser Content and request information entered into AI FeaturesAI processing and output generationAPI transmission when an AI Feature is usedNot retained in principle; temporarily retained for up to 30 days only for service reliability and abuse investigation, then deleted; not used for model training
OpenRouter, Inc.United StatesUser Content and request information entered into AI FeaturesAI model routing and embedding generationAPI transmission when an AI Feature is usedFor the period specified in the entrustment agreement; the Company applies settings for no data retention and no model-training use
OpenAI OpCo, LLC and OpenAI, LLC (through OpenRouter)United States and othersUser Content and request information entered into AI FeaturesAI processing and output generation using OpenAI large language modelsAPI transmission through OpenRouter when such a model is usedThe Company applies OpenRouter's data-collection-deny setting. If an exception occurs in which that setting is not applied, the information may be retained for up to 30 days in OpenAI's default abuse-monitoring logs and is not used for model training
Infrastructure providers connected by OpenRouter, Inc. (see Section 6)Country in which each provider is locatedUser Content and request information entered into AI FeaturesAI model computation and embedding generationAPI transmission through OpenRouter when an AI Feature is usedNo retention or model-training use under the data-collection-deny setting applied by the Company
RunPod, Inc.United StatesHandwriting images, document imagesGPU processing for handwriting and image recognitionAPI transmission when recognition is requestedDeleted immediately after processing; not used for model training
Google LLCUnited States and othersSocial-login identifier, information entered into AI Features, map-widget search terms, push tokens, service usage informationLogin, AI processing, map display, push notifications (FCM), and service operationNetwork transmission when the Service is usedRetained for abuse-prevention monitoring and then deleted, including 55 days for AI processing through Gemini API and up to 60 days for embeddings through Vertex AI; not used for model training under paid API terms. Social-login and FCM tokens are retained while the relevant function is provided
Brave Software, Inc.United StatesSearch terms entered by the UserProvision of web-search resultsAPI transmission when search is usedAs provided in that company's privacy policy
Serper.devUnited StatesSearch terms entered by the UserProvision of web- and image-search resultsAPI transmission when search is usedAs provided in that company's privacy policy
Wolfram Alpha LLCUnited StatesFormulas entered by the UserFormula computation and solutionAPI transmission when calculation is usedAs provided in that company's privacy policy
Desmos Studio PBCUnited StatesFormulas entered by the User, connection informationGraph-widget displayNetwork transmission when the widget is usedAs provided in that company's privacy policy
Apple Inc.United States and othersSign-in identifiers, push tokensLogin and push notificationsNetwork transmission when the relevant function is usedPush notifications are deleted immediately after delivery; undelivered notifications are temporarily retained for up to 30 days and then automatically deleted. Device tokens remain valid while the app is installed and are invalidated when the app is deleted; detailed periods are governed by Apple's privacy policy
PostHog, Inc.GermanyUser identifier, in-app and web service event records, device and browser environment information, country and region estimated from IP addressService analytics and statisticsNetwork transmission when the Service is usedUp to 24 months from collection
Sentry (Functional Software, Inc.)GermanyError events, device, operating-system and app-version information, User identifierError and performance monitoringNetwork transmission when an error occursUp to 90 days

A User may refuse international transfers. If the User refuses international processing entrustment or storage essential to providing the Service, however, use of some or all features, including AI Features, social login, push notifications, and storage, may be restricted.

International-transfer refusal and inquiries: privacy@monote.it

8. Processing of Pseudonymized Information

Under Article 28-2 of the Personal Information Protection Act, the Company may pseudonymize and use personal information for statistical preparation, scientific research, and preservation of records in the public interest.

Processing purposeCategories usedRetention and use period
Service quality improvement and statistical analysisService usage records, error logs, feature usage recordsUntil the analysis purpose is achieved

Information for improvement and research of AI models and features under Section 2.4 is anonymized at collection and therefore is not pseudonymized information under this Section. It is governed by Section 9.

When processing pseudonymized information, the Company implements the following safeguards:

  1. Separate storage of pseudonymized information and additional information, or destruction of additional information when unnecessary
  2. Separation of access rights and access control for additional information
  3. Creation and retention of pseudonymized-information processing records
  4. Prohibition on re-identification and, if re-identification occurs, suspension of processing, retrieval, and destruction
  5. Establishment of an internal management plan and staff training

9. Use of Anonymized Information

The Company may use information anonymized so that a specific individual cannot be identified, even when combined with other information, for service improvement, statistical analysis, research, and development and advancement of AI models.

Information collected for improvement and research of AI models and features under Section 2.4 is anonymized at collection and managed under this Section.

Because anonymized information is not personal information, personal-information retention and destruction requirements do not apply. The Company nevertheless continually assesses the adequacy of anonymization, does not attempt re-identification, and implements and continually supplements technical and administrative safeguards to prevent the possibility of re-identification.

10. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them

A User may exercise the following personal-information rights against the Company at any time:

  1. Request access to personal information
  2. Request correction of errors
  3. Request deletion
  4. Request suspension of processing
  5. Withdraw consent
  6. Request withdrawal of membership and account deletion

Rights may be exercised by emailing privacy@monote.it or through an in-app menu. The Company acts without delay in accordance with applicable law.

Withdrawal of membership and account deletion may be requested directly through the settings menu in the app. Procedures and periods following a withdrawal request are governed by Section 3.

The exercise of certain rights, such as access, correction, deletion, and suspension of processing, may be restricted for information that has been pseudonymized or anonymized so that a specific individual cannot be identified, under Article 28-7 of the Personal Information Protection Act. In particular, improvement and research information anonymized at collection under Section 2.4 cannot be attributed to an individual User and therefore cannot be individually accessed, corrected, or deleted. The User may withdraw consent to stop future collection.

The Company does not permit children under 14 to register or use the Service unless it provides a separate procedure for obtaining consent from a legal representative. If the Company permits children under 14 to use the Service in the future, it will establish a procedure for obtaining the legal representative's consent.

11. Installation, Operation, and Rejection of Automatic Personal Information Collection Mechanisms

The Company may use cookies or similar technologies, including identifiers assigned in the mobile app for analytics and error diagnostics, to provide the Service, maintain login status, ensure security, analyze use, and improve errors.

A User may reject or delete cookies used in the web Service through browser settings. Rejecting cookies may restrict use of some parts of the Service.

Analytics and error-diagnostic collection in the mobile app cannot be rejected through device settings. A User may request suspension of processing by emailing privacy@monote.it. After verifying the request, the Company stops collection for that User.

12. Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of personal information:

  1. Administrative measures
  • Establishing and implementing an internal management plan, managing access rights to personal information, and training responsible personnel
  1. Technical measures
  • Managing access rights to personal-information processing systems, access control, encryption, retaining and reviewing access records, installing and operating security programs, and vulnerability assessment
  1. Physical measures
  • Access control for locations and systems where personal information is stored
  1. Measures for improvement and research information
  • Anonymization at collection without storage of User identifiers, operation and continual expansion and improvement of automatic personal-information detection and removal before storage, prohibition on re-identification attempts, and access control

13. Chief Privacy Officer

The Company designates the following Chief Privacy Officer to oversee personal-information processing and handle privacy inquiries, complaints, and requests for relief:

  • Chief Privacy Officer: Dongho Kim
  • Position: Representative Director
  • Contact: privacy@monote.it

Privacy inquiries may be submitted to the contact above, and the Company responds and takes action without delay.

14. Remedies for Infringement of Rights

A User may contact the following institutions for relief or consultation concerning infringement of personal information:

  1. Personal Information Dispute Mediation Committee: 1833-6972
  2. Personal Information Infringement Report Center: 118 without an area code
  3. Supreme Prosecutors' Office: 1301 without an area code
  4. Korean National Police Agency: 182 without an area code

15. Changes to This Privacy Policy

If the Company changes this Privacy Policy, it gives notice of the changes, reasons, and effective date through in-Service notices, the website, email, or another appropriate method.

The principal changes from the previous version (v3, effective August 10, 2026) are:

  1. Added PostHog (service analytics) and Sentry (error and performance monitoring) as processors and international-transfer recipients, and specified analytics and monitoring User identifiers among automatically collected information
  2. Specified that records relating to processing may be temporarily collected and reviewed only after the Company becomes aware of an urgent security threat such as a security incident, and stated the legal basis of legitimate interests together with minimum-scope limits and destruction as soon as the purpose is achieved
  3. Added Kakao Corp. (map display and place search) as a processor
  4. Specified that PostHog processes country and region information estimated from the access IP address in the categories collected and in the entrustment and international-transfer disclosures
  5. Specified the international-transfer retention and use periods for PostHog and Sentry as up to 24 months from collection and up to 90 days, respectively
  6. Added OpenAI large language model providers routed through OpenRouter as processors and international-transfer recipients and specified providers currently used on the relevant model paths. Consistent with the operational Privacy Policy dated August 10, 2026, SiliconFlow is not included in the list of recipients
  7. Divided Section 11 between the web and mobile app and explained how to request suspension of analytics and error-diagnostic collection in the app

The Company publishes this Privacy Policy at 10:00 KST on August 29, 2026. For a new User who first enters into a service agreement at or after that time, this Policy applies from the time the Company first processes that User's personal information. For a User whose service agreement was formed before that time, the Privacy Policy dated August 10, 2026 (v3) applies through September 28, 2026 (KST), and this Policy applies beginning at 00:00 KST on September 29, 2026 after a 30-day advance-notice period. The Company informs existing Users of the changes, reasons, effective date, and how to exercise their rights through both an in-Service notice and email. Processing that legally requires separate consent is not conducted based solely on publication of this Policy or a User's silence; the Company obtains separate consent.


Supplemental Disclosures for Users Outside Korea

These supplemental disclosures preserve information that was included in the prior English version for users outside Korea. They supplement, and do not replace or limit, the complete translation above.

Location and International Processing

Monote Labs is based in the Republic of Korea, and our primary servers are located there. If you use Monosemy from outside Korea, your information is transferred to and processed in Korea and in the other countries described in Sections 6 and 7.

Korea and other destination countries may not provide the same level of data protection as the state or country where you live. We use contractual protections with our vendors to safeguard information wherever it is processed.

Additional Privacy Statements

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your content to serve advertising.

We do not use your personal information to make decisions that produce legal or similarly significant effects about you.

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

We will not discriminate against you for exercising your privacy rights. We may ask for information to verify your identity before acting on a request.

Children Outside Korea

Account creation requires confirmation that the User is 14 or older. If we learn that we have collected personal information from a child under 14 without consent required by applicable law, we will delete it. If you believe a child has provided personal information to us, contact privacy@monote.it.

Additional Security Notice

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

State-Specific Disclosures

Washington residents. Our handling of consumer health data is described in our separate [Consumer Health Data Privacy Policy], as required by the My Health My Data Act.

Nevada residents. We do not sell personal information as defined by Nevada law. You may submit a verified opt-out request to privacy@monote.it.

California residents. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act. The categories of personal information we collect, the purposes for which we use them, and the categories of recipients are described in Sections 1 through 7. You may exercise the rights described in Section 10 by emailing privacy@monote.it.

Additional Notice of Changes

We will post changes to this Policy on the relevant policy page and update the displayed date. If a change is material, we will provide additional notice through the Service, by email, or by another appropriate method before it takes effect.

Contact Us

Monote Labs Co., Ltd.
B215, Decacorn I 7, B2F, 222 Wangsimni-ro, Seongdong-gu, Seoul, Republic of Korea (HIT Building, Hanyang University)
Business registration number: 846-87-03739

Privacy inquiries: privacy@monote.it
General support: support@monote.it