Cheeseboard
Features Pricing Download
KO EN
Get Started
Legal

Privacy Policy

What we collect, why, how long we keep it and how to have it deleted.

Terms Privacy Refunds

Language of this policy

This English text is a translation provided for convenience. Where it conflicts with the Korean version, the Korean version prevails — except where mandatory law in your country of residence provides otherwise.

At a glance

Question
Answer
What do you collect?
Your email address, usage records, payment status and the work you create.
Do you hold my card number?
No. Toss Payments handles Korean payments and Paddle handles overseas subscriptions; we never store card numbers.
Do you train AI on my work?
No. We do not use your content to train AI models.
Do you sell or share my data for ads?
No. We neither sell personal data nor disclose it for advertising.
Does my data leave the country?
Yes. Our servers and AI providers are overseas. Details in article 6.
How do I delete it?
Close your account, or email [email protected].

Article 1 (General and scope)

RAWGO (주식회사 로우고, the "Company") takes the privacy of its users seriously and complies with the Korean Personal Information Protection Act ("PIPA") and other applicable law. This policy applies to all of the Company's services — the desktop app, the website (cheesebrd.com) and VR tour pages published by users. Processing by external services reached from the Service, such as Google sign-in or a payment provider's checkout, is governed by those providers' own policies.

Article 2 (Personal data we process)

1. Data you provide

Context
Data
Required?
Sign-up (email)
Email address, password (stored encrypted), account creation date
Required
Sign-up (Google)
Google account email address, account identifier
Required
Support enquiries
Email address, message, attachments
Required
Tax invoice request
Business registration number, company name, contact details
Optional

2. Data generated through use of the Service

  • Content you upload or create — images, text, 3D models, video, documents, prompt inputs
  • Board and project structure and generation history
  • Cheese grants, deductions and balance; pass or subscription tier and status; payment history (authorisation result, amount, currency, timestamp)
  • Support and dispute records

3. Data collected automatically

  • IP address, access time, usage records, request processing logs
  • Operating system, app version and device information (for fault diagnosis and compatibility)
  • Error and crash logs

We do not collect advertising identifiers and do not use third-party advertising or behavioural analytics tools.

4. Visitor data on pages published by users

Where a user publishes a VR tour with an enquiry form, visitors may submit their name, contact details (phone number or email address — at least one), message, preferred visit time, and their consent together with the time it was given. For that data the publishing user is the controller and the Company acts as a processor (article 11).

Article 3 (Purposes and legal bases)

Purpose
Data used
Legal basis
Identifying members, account management, sign-in
Email, password, account identifier
Performance of a contract (GDPR art. 6(1)(b))
Providing the Service, storing and syncing content, running AI requests
User content, usage records
Performance of a contract
Payment and settlement, granting, deducting and refunding Cheese
Payment status, Cheese ledger, email
Performance of a contract; legal obligation
Responding to enquiries, handling disputes
Email, message, usage records
Performance of a contract; legitimate interests
Preventing fraud and payment abuse, keeping the Service stable
Access logs, usage patterns, payment history
Legitimate interests (GDPR art. 6(1)(f))
Improving quality, analysing errors, producing statistics
Error logs, usage records
Legitimate interests
Sending transactional and account notices
Email
Performance of a contract
Sending marketing and event information
Email
Separate consent (GDPR art. 6(1)(a))
Meeting legal obligations (transaction records, tax)
Payment and transaction records
Legal obligation

Where we rely on legitimate interests we assess in advance whether that interest overrides your rights and limit processing to what is necessary. Marketing consent can be withdrawn at any time without affecting your use of the Service. Under the Network Act the Company marks advertising messages in the subject line and reconfirms your consent every two years from the date you gave it.

Article 4 (Retention and destruction)

We destroy personal data without delay once the purpose of processing has been achieved.

Data
Retention
Account data (email, credentials)
Destroyed without delay (within 5 days) when the account is closed. Only a one-way hash of the email address is kept for 30 days, to prevent abusive re-signup and duplicate sign-up benefits, then destroyed
User content saved to boards
Until you delete it or close your account
Generation history
Deleted once the tier retention period passes (Free 30 / Basic 90 / Pro 180 days)
Accounts dormant for 12 months or more
Account and remotely stored content deleted after 30 days' notice
Fraud and payment abuse records
Minimum identifiers only, kept 1 year to prevent recurrence, then destroyed
Visitor enquiries on published pages
Deleted after the period set by the publishing user (default 180 days)

Records retained under Korean law

Statute
Records
Period
Act on Consumer Protection in Electronic Commerce
Contracts and withdrawal of offer
5 years
Act on Consumer Protection in Electronic Commerce
Payment and supply of goods or services
5 years
Act on Consumer Protection in Electronic Commerce
Consumer complaints and dispute handling
3 years
Act on Consumer Protection in Electronic Commerce
Labelling and advertising
6 months
Standard for Securing Personal Data Safety, art. 8
Access logs of the personal data processing system
1 year
Framework Act on National Taxes and tax law
Books and supporting documents
5 years

Electronic files are deleted by a method that prevents recovery and printed material is shredded or incinerated. Data remaining in backups is removed on the backup rotation cycle.

Article 5 (Disclosure to third parties)

We do not sell personal data or disclose it for advertising purposes. We disclose it only where:

  1. you have consented in advance; or
  2. a statute so requires, or an investigative authority requests it following the procedure and method prescribed by law.

Where we receive a request from an investigative authority we verify that it meets the statutory requirements, disclose only the minimum necessary, and endeavour to notify you unless prohibited by law.

Article 6 (Processors and international transfers)

1. Domestic processors

Processor
Work entrusted
Retention
Toss Payments Inc.
Korean-won payment processing and payment authentication
Statutory retention period

2. International transfers

The providers below process personal data on our behalf using facilities located outside Korea. Under article 28-8(1)3 of PIPA these are transfers for processing and storage necessary to perform the contract and improve user convenience, disclosed as follows.

Recipient
Data transferred and purpose
Country · retention
Supabase, Inc.
[email protected]
Email, credentials, subscription and Cheese ledger, usage records, published-page enquiries / authentication and database storage
United States · until the processing agreement ends or data is destroyed
Cloudflare, Inc.
[email protected]
User content files, access data / object storage (R2), content delivery, domain and mail routing
United States (global network) · until you delete it or close your account
Railway Corp.
Generation request data, content being processed / server compute and job processing
United States · until processing completes (transient)
Paddle.com Market Limited
[email protected]
Email, billing details, transaction records / overseas subscription payment and tax processing
United Kingdom · statutory retention period
Features and Labels, Inc. (fal.ai)
Images and prompts you submit / AI image and video generation
United States · deleted after processing per the provider's policy
Google LLC / Google Cloud
policies.google.com
Images and prompts you submit, account identifier at sign-in / AI generation and analysis (Gemini, Vertex AI), Google sign-in
United States · deleted after processing per the provider's policy
Holymolly Ltd (Tripo)
[email protected]
Images you submit / 3D model generation
Hong Kong (developed and operated by VAST, based in Beijing, China) · the provider states no fixed retention period
Brevo (Sendinblue SAS)
[email protected]
Email address, send records / authentication and notification email
France · until the processing agreement ends

When and how data is transferred: over the network, each time the Service is used, a generation is requested, a payment is made or an email is sent.

The transfer to Tripo (Holymolly Ltd) happens only when you run 3D model generation. Nothing is transferred there for users who do not use that feature.

  1. Our agreements with these providers require them to follow our instructions on data protection, restrict sub-processing, maintain security measures, and return or destroy data when the agreement ends.
  2. These transfers are processing and storage needed to perform the contract, so they are made by disclosure in this policy under article 28-8(1)3 of PIPA and no separate consent is taken. If you do not want your data transferred abroad, you may terminate the service agreement.
  3. We update and republish this policy when the list of providers changes.

Article 7 (User content and AI processing)

  1. Content you upload or create is private by default and is not visible to other users unless you publish it yourself.
  2. We do not use your content to train our AI models.
  3. When you use an AI feature, the images and prompts you submit are sent to the providers listed in article 6 for processing. We apply contractual terms with those providers excluding the use of transmitted data for model training.
  4. We may inspect content only where necessary to operate the Service and comply with the law — for example when responding to a report of manifestly illegal material such as child sexual abuse material. We do not otherwise read your content.

Article 8 (Automated decision-making)

  1. We do not make decisions that significantly affect your rights or obligations by fully automated means alone.
  2. We do analyse usage patterns automatically to prevent payment fraud and abuse, which may place a payment or generation request on temporary hold. Final decisions such as restricting or terminating an account are made following human review.
  3. If you believe an automated process has disadvantaged you, you may request an explanation of, or refuse, that decision under article 37-2 of PIPA and article 22 of the GDPR. Write to [email protected]; absent a legitimate reason not to, a person will review it again.

Article 9 (Your rights and how to exercise them)

  1. You may at any time request access to your personal data, request rectification or erasure, request restriction of processing, withdraw consent, request portability, request an explanation of or refuse an automated decision, and object to processing.
  2. Exercise these rights in your account settings or by writing to [email protected]. We respond within 10 days, or one month where the GDPR applies.
  3. You may act through a legal representative or an authorised agent; we will need documentation of that authority.
  4. We may ask for the minimum information needed to verify your identity.
  5. A request may be refused only where the law limits the right — for example transaction records we are required to retain — and we will tell you the reason.

Article 10 (Children)

We do not collect personal data from children under 14, and children under 14 may not register. If we learn that we hold such data we destroy it without delay. Outside Korea the local minimum age applies — for example 13 in the United States and 16, or the age set by the member state, in the European Economic Area.

Article 11 (Visitor data on pages published by users)

  1. Where a user uses the enquiry form feature, that user is the controller of visitor data and the Company is a processor.
  2. We process visitor data solely to deliver and store it for that user, and never for our own marketing or model training.
  3. Visitor data is deleted automatically once the retention period set by the user (180 days by default) has passed.
  4. To store and deliver visitor data we sub-process it to the providers listed in article 6 (including Supabase and Cloudflare, located outside Korea); the user consents to this under article 15 of the Terms. The same duties apply to sub-processing: no use beyond the purpose, security measures, restricted access, and return or destruction when the engagement ends.
  5. Because visitor data is transferred abroad, the user is responsible for telling visitors who receives it, in which country, for what purpose, which items and for how long. We provide default consent and notice wording in the lead form for the user to use as-is.
  6. Visitors wishing to access or delete their data should contact the user operating the page; requests received by us are forwarded to that user.

Article 12 (Cookies and similar technologies)

  1. The website uses browser storage only to remember your language preference. It sets no advertising or behavioural analytics cookies.
  2. The desktop app uses local storage to keep you signed in, remember interface settings and cache data for performance. This is stored on your device and removed when you sign out or clear the cache.
  3. You may block storage in your browser settings, though some features may then not work correctly.

Article 13 (Security measures)

  1. Organisational — minimising the number of staff who handle personal data, access rights management, an internal management plan and periodic review.
  2. Technical — encryption in transit (HTTPS/TLS), one-way hashing of passwords, row-level security on the database, retention of access logs, and server-side custody of privileged keys.
  3. No card data — payment instrument details are handled by the payment providers and never stored by us.
  4. Physical — servers run in our providers' data centres under their physical security controls.

Article 14 (Contact)

Item
Detail
Data Protection Officer
Kang Duseok (Representative)
Telephone
+82 10-6803-6833
Email
[email protected]
Access requests
[email protected]

You may raise any privacy enquiry, complaint or request for redress at the address above, and we will respond without delay.

Article 15 (Remedies)

Body
Website
Phone
Privacy Infringement Report Centre
privacy.kisa.or.kr
118
Personal Information Dispute Mediation Committee
kopico.go.kr
1833-6972
Supreme Prosecutors' Office Cybercrime Division
spo.go.kr
1301
National Police Agency Cyber Bureau
ecrm.police.go.kr
182

Users outside Korea may complain to their local supervisory authority.

Article 16 (Breach notification)

1) Notifying you

If we become aware of a personal data breach we notify affected users within 72 hours of the data affected, when and how it happened, steps you can take to limit harm, our response, the redress procedure and a contact point.

2) Reporting to the regulator

Where the breach affects 1,000 or more data subjects, involves sensitive data or unique identifiers, or results from unlawful external access, we also report it to the Personal Information Protection Commission or the Korea Internet & Security Agency.

3) European Economic Area

Where users in the EEA are affected we notify the supervisory authority within 72 hours of becoming aware under article 33 of the GDPR, and notify the data subjects without undue delay under article 34 where the risk to their rights and freedoms is high.

Article 17 (Region-specific notices)

1. European Economic Area and United Kingdom

  • Controller: RAWGO (주식회사 로우고), 107-702, 110 Jingeononam-ro 759beon-gil, Onam-eup, Namyangju-si, Gyeonggi-do, Republic of Korea · [email protected]
  • Current availability: the Company does not offer the Service to residents of the European Economic Area or the United Kingdom. What follows applies if we begin offering it there.
  • EU representative (GDPR art. 27): appointed before the Service is offered in the European Economic Area, with the name and contact details recorded here on appointment.
  • International transfers: the Republic of Korea benefits from a European Commission adequacy decision (adopted 17 December 2021, confirmed on review in July 2026), so transfers from the EEA to Korea require no Standard Contractual Clauses. For transfers to other countries we apply Standard Contractual Clauses or another valid mechanism.
  • Your rights: access, rectification, erasure, restriction, portability, objection and rights concerning automated decisions. You may lodge a complaint with the supervisory authority where you live or work.
  • Withdrawing consent: where we rely on consent you may withdraw it at any time, without affecting processing carried out beforehand.

2. California residents

  • We do not sell personal information and do not share it for cross-context behavioural advertising.
  • We do not collect sensitive personal information for the purpose of inferring characteristics.
  • You have the right to know what categories of personal information we collect, use and disclose, to request deletion or correction, and not to be discriminated against for exercising those rights. Write to [email protected].

Article 18 (Changes to this policy)

We announce changes, and the date they take effect, on the Service and the website at least 7 days in advance — or 30 days where a change is unfavourable to users. Earlier versions are available on request.

This policy takes effect on 28 July 2026.

Back to home Contact us
Cheeseboard

Make with AI. Organize on the board.

Terms Privacy Refunds

RAWGO (주식회사 로우고) · Representative: Kang Duseok · Business Registration No. 501-81-24799 · Mail-order Business No. [to be filed]
Business address: 107-702, 110 Jingeononam-ro 759beon-gil, Onam-eup, Namyangju-si, Gyeonggi-do, Republic of Korea · Tel. +82 10-6803-6833
Hosting provider: Cloudflare, Inc. · © 2026 Cheese board

Contact: [email protected]