Privacy Policy
Effective date: July 23, 2026
Data controller
Company name 도핑연구소 · CEO 김신혁 · Business registration No. 307-41-00675
Service name Bosskit · Mail-order business reg. no. 2020-성남중원-0458
도핑연구소 (the "Company") complies with the Personal Information Protection Act and other relevant laws, and processes users' personal information as follows.
1. Personal information collected
(Required) Email address, name, password (stored encrypted). (Upon social login) The email address, name, profile picture URL, and account identifier from your Google account. (Upon payment) Payment approval information via the payment gateway (card issuer name, approval number, etc.). Sensitive payment information such as card numbers is not stored on the Company's servers. (Automatically collected) IP address, access logs, device/browser information, cookies, task (agent) execution records. (Entered or uploaded by the user) The full text of instructions you send to employees and of conversations with them, the full text and summaries of company materials you upload, task deliverables, the organization and employee memory automatically derived from these, and images or files attached to support inquiries. If you include personal information in any of these, that personal information is stored along with them and may be transferred to AI model providers under Articles 4 and 5. (Early access) If you join the pre-launch waitlist, your email address and consent record (whether you gave the required and optional consents, the time of consent, and the consent text version). (Optional) External AI model API keys (BYOK) and external service integration credentials registered by the user are stored encrypted.
2. Purpose of use
Personal information is used for member identification and login, providing the Service and settling credits/fees, executing tasks and delivering outputs, responding to customer inquiries, preventing fraudulent use and responding to security incidents, and statistical analysis to improve the Service. Emails collected through the waitlist are used only to announce the launch and progress updates; promotional messages are sent only to those who separately consented.
3. Retention and use period
Upon withdrawal of membership, personal information is destroyed without delay. However, the following records are retained for the applicable period before destruction pursuant to relevant laws: records of contracts, withdrawal of subscription, payment, and supply of goods: 5 years; records of consumer complaints and dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce); records of access: 3 months (Protection of Communications Secrets Act). Waitlist emails are kept until 3 months after launch, and are destroyed without delay if you ask to unsubscribe earlier.
4. Outsourcing of processing
The Company outsources personal information processing as follows for smooth service delivery: cloud infrastructure and database hosting (Railway), AI model calls (Anthropic, OpenAI), isolated runtime environments (E2B), email delivery (Brevo), and payment processing (Groble). If you register your own API key (BYOK), that model provider is added. If a processor changes, this will be announced through this Policy.
5. Overseas transfer of personal information
Content entered by a user during task execution may be transferred to a model provider located overseas for AI model processing. The recipients and their countries are Anthropic (United States) and OpenAI (United States); in addition, infrastructure hosting is Railway (United States), the isolated runtime environment is E2B (United States), and email delivery is Brevo (France). The items transferred are the input and context data necessary to perform the task, which includes the instructions, conversations, company materials, and organization memory listed under the entered-or-uploaded-by-the-user items in Article 1. The purpose of transfer is to generate the model's response, the transfer occurs at the time a task runs, and the retention period follows each provider's own policy. When BYOK is used, data is sent directly to the model provider designated by the user. Users may decline such overseas transfer, but in that case, use of the related features may be restricted.
6. Rights of users and legal representatives
Users may view or correct their own personal information at any time, and may request deletion via the withdrawal option in the settings menu. Users may request suspension of processing or withdrawal of consent, and may delete their registered BYOK keys or integration credentials at any time.
7. Destruction procedure and method
Personal information for which the retention period has elapsed or the processing purpose has been achieved is destroyed without delay. Electronic files are deleted using methods that prevent recovery, and printed materials are shredded or incinerated.
8. Measures to ensure security
The Company implements administrative and technical safeguards such as one-way encryption of passwords, encrypted storage of API keys and integration credentials, access control and data isolation between organizations, and retention and inspection of access records.
9. Use of cookies
The Company uses cookies and local storage to maintain login sessions and for the convenience of using the Service. Users may refuse to allow storage through their browser settings, but in that case, some features such as login may be restricted.
10. Data protection officer
Data Protection Officer: 김신혁 (CEO). Inquiries, and requests to view, correct, or delete personal information, can be submitted through the in-service inquiry channel, and will be processed without delay.
11. Changes to this Policy
If the content of this Policy is added, deleted, or amended, notice will be given through an in-service announcement at least 7 days before the effective date.
Last updated: July 23, 2026