Language of this policy
This English text is a translation provided for convenience. Where it conflicts with the Korean version, the Korean version prevails — except where mandatory law in your country of residence provides otherwise.
At a glance
Article 1 (General and scope)
RAWGO (주식회사 로우고, the "Company") takes the privacy of its users seriously and complies with the Korean Personal Information Protection Act ("PIPA") and other applicable law. This policy applies to all of the Company's services — the desktop app, the website (cheesebrd.com) and VR tour pages published by users. Processing by external services reached from the Service, such as Google sign-in or a payment provider's checkout, is governed by those providers' own policies.
Article 2 (Personal data we process)
1. Data you provide
2. Data generated through use of the Service
- Content you upload or create — images, text, 3D models, video, documents, prompt inputs
- Board and project structure and generation history
- Cheese grants, deductions and balance; pass or subscription tier and status; payment history (authorisation result, amount, currency, timestamp)
- Support and dispute records
3. Data collected automatically
- IP address, access time, usage records, request processing logs
- Operating system, app version and device information (for fault diagnosis and compatibility)
- Error and crash logs
We do not collect advertising identifiers and do not use third-party advertising or behavioural analytics tools.
4. Visitor data on pages published by users
Where a user publishes a VR tour with an enquiry form, visitors may submit their name, contact details (phone number or email address — at least one), message, preferred visit time, and their consent together with the time it was given. For that data the publishing user is the controller and the Company acts as a processor (article 11).
Article 3 (Purposes and legal bases)
Where we rely on legitimate interests we assess in advance whether that interest overrides your rights and limit processing to what is necessary. Marketing consent can be withdrawn at any time without affecting your use of the Service. Under the Network Act the Company marks advertising messages in the subject line and reconfirms your consent every two years from the date you gave it.
Article 4 (Retention and destruction)
We destroy personal data without delay once the purpose of processing has been achieved.
Records retained under Korean law
Electronic files are deleted by a method that prevents recovery and printed material is shredded or incinerated. Data remaining in backups is removed on the backup rotation cycle.
Article 5 (Disclosure to third parties)
We do not sell personal data or disclose it for advertising purposes. We disclose it only where:
- you have consented in advance; or
- a statute so requires, or an investigative authority requests it following the procedure and method prescribed by law.
Where we receive a request from an investigative authority we verify that it meets the statutory requirements, disclose only the minimum necessary, and endeavour to notify you unless prohibited by law.
Article 6 (Processors and international transfers)
1. Domestic processors
2. International transfers
The providers below process personal data on our behalf using facilities located outside Korea. Under article 28-8(1)3 of PIPA these are transfers for processing and storage necessary to perform the contract and improve user convenience, disclosed as follows.
[email protected]
[email protected]
[email protected]
policies.google.com
[email protected]
[email protected]
When and how data is transferred: over the network, each time the Service is used, a generation is requested, a payment is made or an email is sent.
The transfer to Tripo (Holymolly Ltd) happens only when you run 3D model generation. Nothing is transferred there for users who do not use that feature.
- Our agreements with these providers require them to follow our instructions on data protection, restrict sub-processing, maintain security measures, and return or destroy data when the agreement ends.
- These transfers are processing and storage needed to perform the contract, so they are made by disclosure in this policy under article 28-8(1)3 of PIPA and no separate consent is taken. If you do not want your data transferred abroad, you may terminate the service agreement.
- We update and republish this policy when the list of providers changes.
Article 7 (User content and AI processing)
- Content you upload or create is private by default and is not visible to other users unless you publish it yourself.
- We do not use your content to train our AI models.
- When you use an AI feature, the images and prompts you submit are sent to the providers listed in article 6 for processing. We apply contractual terms with those providers excluding the use of transmitted data for model training.
- We may inspect content only where necessary to operate the Service and comply with the law — for example when responding to a report of manifestly illegal material such as child sexual abuse material. We do not otherwise read your content.
Article 8 (Automated decision-making)
- We do not make decisions that significantly affect your rights or obligations by fully automated means alone.
- We do analyse usage patterns automatically to prevent payment fraud and abuse, which may place a payment or generation request on temporary hold. Final decisions such as restricting or terminating an account are made following human review.
- If you believe an automated process has disadvantaged you, you may request an explanation of, or refuse, that decision under article 37-2 of PIPA and article 22 of the GDPR. Write to [email protected]; absent a legitimate reason not to, a person will review it again.
Article 9 (Your rights and how to exercise them)
- You may at any time request access to your personal data, request rectification or erasure, request restriction of processing, withdraw consent, request portability, request an explanation of or refuse an automated decision, and object to processing.
- Exercise these rights in your account settings or by writing to [email protected]. We respond within 10 days, or one month where the GDPR applies.
- You may act through a legal representative or an authorised agent; we will need documentation of that authority.
- We may ask for the minimum information needed to verify your identity.
- A request may be refused only where the law limits the right — for example transaction records we are required to retain — and we will tell you the reason.
Article 10 (Children)
We do not collect personal data from children under 14, and children under 14 may not register. If we learn that we hold such data we destroy it without delay. Outside Korea the local minimum age applies — for example 13 in the United States and 16, or the age set by the member state, in the European Economic Area.
Article 11 (Visitor data on pages published by users)
- Where a user uses the enquiry form feature, that user is the controller of visitor data and the Company is a processor.
- We process visitor data solely to deliver and store it for that user, and never for our own marketing or model training.
- Visitor data is deleted automatically once the retention period set by the user (180 days by default) has passed.
- To store and deliver visitor data we sub-process it to the providers listed in article 6 (including Supabase and Cloudflare, located outside Korea); the user consents to this under article 15 of the Terms. The same duties apply to sub-processing: no use beyond the purpose, security measures, restricted access, and return or destruction when the engagement ends.
- Because visitor data is transferred abroad, the user is responsible for telling visitors who receives it, in which country, for what purpose, which items and for how long. We provide default consent and notice wording in the lead form for the user to use as-is.
- Visitors wishing to access or delete their data should contact the user operating the page; requests received by us are forwarded to that user.
Article 12 (Cookies and similar technologies)
- The website uses browser storage only to remember your language preference. It sets no advertising or behavioural analytics cookies.
- The desktop app uses local storage to keep you signed in, remember interface settings and cache data for performance. This is stored on your device and removed when you sign out or clear the cache.
- You may block storage in your browser settings, though some features may then not work correctly.
Article 13 (Security measures)
- Organisational — minimising the number of staff who handle personal data, access rights management, an internal management plan and periodic review.
- Technical — encryption in transit (HTTPS/TLS), one-way hashing of passwords, row-level security on the database, retention of access logs, and server-side custody of privileged keys.
- No card data — payment instrument details are handled by the payment providers and never stored by us.
- Physical — servers run in our providers' data centres under their physical security controls.
Article 14 (Contact)
You may raise any privacy enquiry, complaint or request for redress at the address above, and we will respond without delay.
Article 15 (Remedies)
Users outside Korea may complain to their local supervisory authority.
Article 16 (Breach notification)
1) Notifying you
If we become aware of a personal data breach we notify affected users within 72 hours of the data affected, when and how it happened, steps you can take to limit harm, our response, the redress procedure and a contact point.
2) Reporting to the regulator
Where the breach affects 1,000 or more data subjects, involves sensitive data or unique identifiers, or results from unlawful external access, we also report it to the Personal Information Protection Commission or the Korea Internet & Security Agency.
3) European Economic Area
Where users in the EEA are affected we notify the supervisory authority within 72 hours of becoming aware under article 33 of the GDPR, and notify the data subjects without undue delay under article 34 where the risk to their rights and freedoms is high.
Article 17 (Region-specific notices)
1. European Economic Area and United Kingdom
- Controller: RAWGO (주식회사 로우고), 107-702, 110 Jingeononam-ro 759beon-gil, Onam-eup, Namyangju-si, Gyeonggi-do, Republic of Korea · [email protected]
- Current availability: the Company does not offer the Service to residents of the European Economic Area or the United Kingdom. What follows applies if we begin offering it there.
- EU representative (GDPR art. 27): appointed before the Service is offered in the European Economic Area, with the name and contact details recorded here on appointment.
- International transfers: the Republic of Korea benefits from a European Commission adequacy decision (adopted 17 December 2021, confirmed on review in July 2026), so transfers from the EEA to Korea require no Standard Contractual Clauses. For transfers to other countries we apply Standard Contractual Clauses or another valid mechanism.
- Your rights: access, rectification, erasure, restriction, portability, objection and rights concerning automated decisions. You may lodge a complaint with the supervisory authority where you live or work.
- Withdrawing consent: where we rely on consent you may withdraw it at any time, without affecting processing carried out beforehand.
2. California residents
- We do not sell personal information and do not share it for cross-context behavioural advertising.
- We do not collect sensitive personal information for the purpose of inferring characteristics.
- You have the right to know what categories of personal information we collect, use and disclose, to request deletion or correction, and not to be discriminated against for exercising those rights. Write to [email protected].
Article 18 (Changes to this policy)
We announce changes, and the date they take effect, on the Service and the website at least 7 days in advance — or 30 days where a change is unfavourable to users. Earlier versions are available on request.
This policy takes effect on 28 July 2026.