Skip to content

Privacy Policy

Effective date: September 13, 2026 (revised September 6, 2026 — notice period of 7 days)

A further revision adding Article 2 items 9–11 and an Article 11 exception is scheduled to take effect October 5, 2026 (noticed September 21, 2026 — 14-day notice period).

Didymus Lab (the "Service") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act (Act No. 19234, as amended in 2023), in order to protect users' personal information and to handle related grievances promptly and smoothly.

This English translation is provided for your convenience. The Korean version is the legally binding text.

How the content you provide is protected

  • · Scripture passages and notes are used only to generate, evidence-audit, and revise your reports. Didymus Lab does not provide them for model training; provider-side retention and model-improvement terms depend on the applicable contract and account data controls.
  • · We do not provide your data to third parties for marketing or sales purposes.
  • · Notes and other free-text request content on every plan are stored encrypted with AES-256-GCM.
  • · When you withdraw, your email, name, and church name are de-identified immediately, and usage records are fully deleted after 6 months.
  • · However, your Kakao/Google account unique ID is retained rather than deleted immediately, for fraud prevention purposes (such as preventing repeated claims of free credits via withdrawal and re-registration).

Article 1 (Items of Personal Information Collected and Methods of Collection)

The Service collects the following personal information.

CategoryItems CollectedMethod of Collection
Membership registration[Required] Name, phone number, church, position, email address, Kakao·Google account unique ID
(All items above are required at sign-up; there are no optional items.)
Kakao/Google OAuth authentication and registration form input
Service useScripture passage, sermon type, sermon date, additional requests, feedback contentRequest form and feedback form input
Waitlist applicationName, email address, affiliated church, contact (optional), desired planWaitlist application form input
PaymentBusiness registration number or mobile phone number for cash receipt issuanceUpon separate request
Automatic collectionAccess IP, access date and time, service usage recordsAutomatically collected by the system

Membership registration

[Required] Name, phone number, church, position, email address, Kakao·Google account unique ID

All items above are required at sign-up; there are no optional items. · Kakao/Google OAuth authentication and registration form input

Service use

Scripture passage, sermon type, sermon date, additional requests, feedback content

Request form and feedback form input

Waitlist application

Name, email address, affiliated church, contact (optional), desired plan

Waitlist application form input

Payment

Business registration number or mobile phone number for cash receipt issuance

Upon separate request

Automatic collection

Access IP, access date and time, service usage records

Automatically collected by the system

Article 2 (Purposes of Collection and Use of Personal Information)

The personal information collected is used only for the following purposes.

  • Member identification, Kakao/Google OAuth authentication, and service provision
  • Receiving requests and delivering reports
  • Delivering notices related to the Service, report completion notifications, and other communications (via email)
  • Sending important service notices such as dossier completion via KakaoTalk Alimtalk (using the phone number — never for advertising or marketing)
  • Receiving feedback and providing responses
  • Issuing cash receipts (upon request)
  • Service improvement and statistical analysis (after de-identification)
  • Preventing illegal or fraudulent use and handling violations of the terms of service
  • Using audit findings for quality improvement (added October 5, 2026): after pseudonymization (removing requester-identifying information and masking report-cover and congregation-specific proper nouns), machine-generated evidence-audit findings on reports may be used to improve error-detection criteria and to build internal quality benchmarks. You may opt out of this use at any time from My Page → Edit my account, in which case your data is excluded from this use going forward (opt-out; on by default).
  • Pseudonymized use for research and trend analysis (added October 5, 2026): free-text content such as request notes, evaluation comments, and sermon profiles is used only for the purposes above. Where used for clustering or trend analysis to improve the service, it is processed only after pseudonymization under the Personal Information Protection Act Art. 28-2, in a form from which no specific individual can be identified, and only where you have given separate, explicit consent from My Page → Edit my account (opt-in; off by default). You may withdraw this consent at any time.
  • External publication (added October 5, 2026): the pseudonymized/statistical results above may be used in blog posts, white papers, or joint research with academic institutions only in aggregated form that cannot identify a specific individual or church, and only where a minimum-aggregation-unit threshold is met. Information that could identify an individual member is not provided to third parties (including research institutions such as seminaries), except with that member's separate prior consent.

Article 3 (Retention and Use Period of Personal Information)

Personal information is destroyed promptly once the purpose of its collection and use has been achieved. However, it is retained for the following periods where required by applicable law.

  • Member information: destroyed promptly upon membership withdrawal or service termination (provided that, where necessary for dispute resolution, it is retained until the dispute is resolved). However, the Kakao/Google account unique ID is retained even after withdrawal, for the fraud-prevention purpose described in Article 2, and is used solely to detect re-registration.
  • Service usage records (request history): 6 months after withdrawal
  • Waitlist application information: destroyed promptly upon completion of registration or withdrawal of the application
  • E-commerce records (contracts, withdrawal of subscription, payment): 5 years (Act on Consumer Protection in Electronic Commerce)
  • Records of consumer complaints and dispute handling: 3 years (Act on Consumer Protection in Electronic Commerce)
  • Access logs: 3 months (Protection of Communications Secrets Act)

Article 4 (Provision of Personal Information to Third Parties)

As a rule, the Service does not provide users' personal information to third parties. The following cases are exceptions.

  • Where the user has consented in advance
  • Where investigative authorities or others request it pursuant to law

Article 5 (Outsourcing of Personal Information Processing)

The Service outsources the following tasks to external providers.

Outsourced PartyOutsourced TaskRetention and Use Period
Vercel Inc.Web server hosting, file (PDF) storageTerm of the outsourcing agreement
Supabase Inc.Database (PostgreSQL) server operationTerm of the outsourcing agreement
Resend Inc.Email delivery (notifications, announcements)Term of the outsourcing agreement
Anthropic PBCAI report generation and revision (processing of the Scripture passage, request content and options, generated report content, and the member's name, church and role used for the report cover)Term of the outsourcing agreement
OpenAI, L.L.C.AI report generation, evidence audit, and revision (processing of request information, generated report content, and evidence-audit artifacts)Applicable service agreement and account data-retention settings
Kakao Corp.Member authentication (OAuth 2.0)Term of the outsourcing agreement
Google LLCMember authentication (OAuth 2.0)Term of the outsourcing agreement
Apple Inc.Member authentication (Sign in with Apple)Term of the outsourcing agreement
PortOne Korea Co., Ltd. and payment gateways (PG)Electronic payment processing (card payment handling and transfer of payment information)Term of the outsourcing agreement
Slack Technologies, LLCInternal review and operations notifications (member name, church and e-mail shown to operators in the review workspace)Term of the outsourcing agreement
Cloudflare, Inc.Bot protection for public comment forms (Turnstile — IP address and browser signals)Term of the outsourcing agreement
Solapi Co., Ltd.KakaoTalk Alimtalk delivery and delivery-result processing (phone number, template variables, and delivery result)One year from the date of delivery

Vercel Inc.

Web server hosting, file (PDF) storage

Term of the outsourcing agreement

Supabase Inc.

Database (PostgreSQL) server operation

Term of the outsourcing agreement

Resend Inc.

Email delivery (notifications, announcements)

Term of the outsourcing agreement

Anthropic PBC

AI report generation and revision (request information, generated report content, and cover identity information)

Term of the outsourcing agreement

OpenAI, L.L.C.

AI report generation, evidence audit, and revision (request information, generated report content, and evidence-audit artifacts)

Applicable service agreement and account data-retention settings

Kakao Corp.

Member authentication (OAuth 2.0)

Term of the outsourcing agreement

Google LLC

Member authentication (OAuth 2.0)

Term of the outsourcing agreement

Apple Inc.

Member authentication (Sign in with Apple)

Term of the outsourcing agreement

PortOne Korea Co., Ltd. and payment gateways (PG)

Electronic payment processing (card payment handling and transfer of payment information)

Term of the outsourcing agreement

Slack Technologies, LLC

Internal review and operations notifications (member name, church, and e-mail)

Term of the outsourcing agreement

Cloudflare, Inc.

Bot protection for public comment forms (IP address and browser signals)

Term of the outsourcing agreement

Solapi Co., Ltd.

KakaoTalk Alimtalk delivery and delivery-result processing (phone number, template variables, and delivery result)

One year from the date of delivery

Vercel, Supabase, Resend, Anthropic, OpenAI, Google LLC, Apple Inc., Slack Technologies and Cloudflare operate infrastructure in the United States, so personal information may be transferred overseas. Didymus Lab does not provide report content for model training. Each AI provider's own retention and model-improvement processing is governed by the applicable service agreement and account data-control settings. Kakao maintains its servers in the Republic of Korea. Solapi discloses Biztalk Co., Ltd. and DK Techin Co., Ltd. as service providers involved in KakaoTalk Alimtalk delivery; depending on the delivery route, they may process phone numbers, message content, and images.

Common overseas-transfer details

Recipients and contacts: Vercel Inc. (privacy policy), Supabase Inc. (privacy policy), Resend Inc. (privacy policy), Google LLC (privacy policy), Apple Inc. (privacy contact), Slack Technologies, LLC (privacy policy), and Cloudflare, Inc. (privacy policy).

Country, timing, and method: United States; transferred over an encrypted network when the relevant hosting, storage, e-mail, authentication, internal-review notification, or bot-protection function is used.

Items, purpose, and retention: the items and purposes are limited to those stated for each recipient in the outsourcing table above. They are retained for the period stated in that table and then deleted or de-identified under the provider's contract and policy.

Refusal and effect: a member may refuse by not using the relevant feature or by requesting suspension under Article 6. Core functions that depend on the relevant provider, including account authentication, report storage/delivery, or service notices, may become unavailable.

Overseas transfer details for AI processing

Recipients and contacts: Anthropic PBC (privacy@anthropic.com) and OpenAI, L.L.C. (OpenAI Privacy Portal).

Country, timing, and method: United States; transmitted over an encrypted network when a report is generated, evidence-audited, or revised.

Items transferred: name, church, role, internal user/request identifiers and account-access category; Bible passage, sermon schedule/type, notes or questions, selected options; generated report content and evidence-audit artifacts; and, if selected, a style directive derived from the Sermon Profile.

Purpose and retention: report generation, evidence audit, and revision. Data is retained only for the period required by the applicable provider agreement and account data-retention controls, then deleted or de-identified under those terms.

Refusal and effect: a member may refuse the transfer by not submitting the request or, in the mobile app, by leaving the consent control unchecked. The relevant AI report request cannot be processed, but existing reports and other account functions remain available.

Advance consent for third-party AI processing

Before every mobile report request, the app presents an unchecked consent control and asks for explicit permission to send information to one or more of Anthropic PBC's Claude and OpenAI, L.L.C.'s Codex, depending on the active generation, evidence-audit, and revision route. The transferred items are the member's name, church, role, internal user and request identifiers, and account-access category; the Bible passage, sermon schedule and type, notes or questions in that request; selected report options; generated report content and evidence-audit artifacts; and, only when selected, a style directive derived from the member's sermon profile. The app does not send payment-card information, phone numbers, or the member's email address to the AI providers for report processing.

Refusal prevents only that AI report request; existing reports and account functions remain available. Consent is not saved as a blanket permission and is requested again for each new request. A member may withdraw consent for future processing by leaving the control unchecked, and may request suspension of processing or account deletion under Article 6.

Article 6 (Rights and Obligations of Data Subjects and How to Exercise Them)

Users may exercise the following rights. (Articles 35 through 37 of the Personal Information Protection Act)

  • Right of access: the right to request access to one's own personal information processed by the Service
  • Right to correction and deletion: the right to request correction or deletion of personal information that is inaccurate or no longer necessary
  • Right to suspension of processing: the right to request that the processing of personal information be suspended
  • Withdrawal of consent: the right to withdraw consent to the collection and use of personal information at any time

To exercise these rights, please send an email request to didymus@didymuslab.com, and we will act on it. We will notify you of the outcome within 10 days of receiving the request.

Article 7 (Destruction of Personal Information)

  1. Personal information whose retention period has elapsed or whose processing purpose has been achieved is destroyed without delay.
  2. Electronic files: permanently deleted in a manner that renders recovery impossible
  3. Paper documents: shredded or incinerated

Article 8 (Technical and Administrative Measures for the Protection of Personal Information)

  • Authentication security: Kakao OAuth 2.0 authentication is supported, and for email registration, passwords are stored only as bcrypt one-way hashes (no plaintext is retained)
  • Session management: session IDs are issued from cryptographically secure random values
  • Data encryption: notes and other free-text request content on every plan are stored encrypted with AES-256-GCM
  • Communication encryption: HTTPS (TLS) is applied
  • Access control: direct database access is blocked for anyone other than the operator
  • Regular security reviews and vulnerability checks

Article 9 (Use of Cookies)

  1. The Service uses session cookies to maintain login status.
  2. Session cookies are deleted upon logout. When "keep me logged in" is enabled, they are retained for up to 7 days.
  3. The Service does not use cookies for advertising or tracking purposes.
  4. Users may refuse cookies through their browser settings, but login will not be possible if they do.

Article 10 (Personal Information Protection Officer)

For inquiries, complaints, and remedies related to the processing of personal information, please use the contact below.

Company: Didymus Lab Inc.

CEO: Kyungmin Kim

Business Registration No.: 141-86-03786

Phone: +82 70-8027-4214

Address: 10F-104, 14 Teheran-ro 26-gil, Gangnam-gu, Seoul, Korea (WeWork Building, Yeoksam-dong)

Personal Information Protection Officer: Didymus Lab Operator

Email: didymus@didymuslab.com

To report or seek advice regarding infringement of personal information, you may contact the Personal Information Protection Commission (privacy.go.kr, dial 182 without an area code).

Article 11 (Processing of User-Uploaded Content — Sermon Manuscripts)

Where a member voluntarily uploads their own sermon manuscripts to use the Sermon Profile feature, the Service processes them as follows.

  • Purpose limitation: Uploaded sermons and the sermon profile derived from them are used solely to build that member's own sermon profile and to generate the materials that member requests.
  • No secondary use: They are never used to create materials for other users, nor to train the Service's AI models for general purposes. Exception (added October 5, 2026): statistics or trend analysis (such as style clustering) that has been fully pseudonymized so that no specific individual can be identified is excepted from this restriction; even then, only the already-generated, de-identified sermon-profile metrics are used, never the original uploaded manuscript, and only where you have given the separate opt-in consent described in Article 2 item 10.
  • Limited AI processing: The original uploaded manuscript is not sent to Anthropic or OpenAI merely because the Sermon Profile feature is enabled. When a member explicitly applies the profile to a report request, only the derived style directive may be included in the applicable AI request after the Article 5 consent.
  • Copyright: Copyright in the sermons remains entirely with the member; the Service holds only the right to process them for the purposes above.
  • Consent and withdrawal: Style learning is performed only with the member's separate opt-in consent, which may be withdrawn at any time.
  • Storage and destruction: Manuscripts are stored encrypted. A member may delete uploaded sermons or the derived profile at any time, and upon account withdrawal the uploaded sermons and sermon profile are destroyed immediately.

Date of notice: September 6, 2026

Effective date: September 13, 2026

Pending revision — noticed September 21, 2026, effective October 5, 2026: adds Article 2 items 9–11 and the Article 11 exception described above, and the stats-analysis opt-out / content-clustering opt-in in My Page → Edit my account.

Revision history: Revised September 6, 2026 (effective September 13, 2026) — disclosed OpenAI Codex processing for report generation, evidence audit, and revision; added overseas-transfer details; completed the mobile processor list; and aligned the encryption description with all-plan free-text encryption · Revised September 4, 2026 (effective September 11, 2026) — added Apple Inc., Slack Technologies and Cloudflare and clarified Anthropic processing · Revised August 31, 2026 — specified AI-request items and per-request mobile consent (previous revision August 25, 2026 · initial notice April 15, 2026 · initially effective May 1, 2026)