BrainyLabs collects only the minimum personal information required to operate GoTEM AI Planner. You can access, correct, delete, port, or restrict processing of your data at any time. Users under the age of 14 are not allowed to register. Contact: cs@brainylabs.kr.
1. Data Controller
- Entity: BrainyLabs (a brand of LifeLi Holdings)
- Address: Seoul, Republic of Korea (full business registration to be updated)
- Data Protection Officer: BrainyLabs CS Team
- Contact: cs@brainylabs.kr
2. Data We Collect
2.1 Account & Authentication
- Required: email, password (bcrypt hashed), nickname
- Optional: date of birth (age verification + chronotype estimation), gender, profile image
- Social login: Google/Apple identifier (sub), email, display name
2.2 Service Usage
- Four-axis data: sleep, exercise, diet, mood scores (0–100)
- Blocks: title, start/end time, category, cognitive load tier (T1–T5), completion status
- Brain Efficiency scores (daily, weekly)
- AI analysis output (daily GoTEM report, weekly pattern report)
- Feedback and support tickets
- Optional BrainyCards sync (same email): aggregated learning stats only
2.3 Payment Information
- Web (Toss): payment token, order ID, amount, last-4 of card (full card never stored)
- iOS: Apple receipt ID, transaction ID
- Android: Google Play subscription ID, order token
- Unified subscription state: RevenueCat user ID
2.4 Automatic Collection
- IP address, user agent, OS/browser version, device model
- Service logs (access timestamps, navigation paths), error logs
- Push tokens: FCM (Android/Web), APNs (iOS)
- Cookies / local storage for session and user preferences
3. How We Use Your Data
- Account authentication and management
- Providing GoTEM AI analysis (golden time, block recommendation, four-axis evaluation)
- Subscription billing, refunds, invoicing
- Sending weekly reports and trial-end notifications
- Customer support and dispute resolution
- Aggregated analytics for service improvement (PII removed)
- Fraud and security threat detection
- Compliance with legal obligations
4. Retention
Active user data is kept for 90 days in hot storage, then 1 year in archive. Upon account deletion, data is hard-deleted immediately. Payment and dispute records are retained for 5 years and 3 years respectively, as required by Korean e-commerce law. Access logs are kept for 3 months.
5. Third-Party Processors
- Supabase Inc. — database & auth infrastructure (EU/Korea region)
- Google LLC (Gemini API) — AI inference (PII removed before transmission, US/EU)
- Anthropic PBC (Claude API) — AI inference backup (US)
- Toss Payments — web payment processing (Korea)
- Apple Inc. — iOS in-app purchase, APNs push (US)
- Google LLC — Play Billing, FCM push (US)
- RevenueCat Inc. — unified subscription management (US)
- Vercel Inc. — web hosting & CDN (global edge)
For cross-border transfers, we rely on user consent or GDPR Standard Contractual Clauses (SCCs) as applicable.
6. Your Rights
- Right of access — request a copy of your data
- Right to rectification / erasure
- Right to restrict processing
- Right to data portability — export as JSON/CSV
- Right to withdraw consent (for optional processing)
- Right not to be subject to fully automated decision-making (GDPR Art. 22)
Requests via cs@brainylabs.kr or in-app [Settings → Data Management]. We respond within 10 business days (30 days for GDPR requests).
7. Security
- TLS 1.3 encryption in transit
- Passwords stored with bcrypt (cost ≥ 12)
- Sensitive tokens encrypted at rest (AES-256)
- Least-privilege access control, IAM-based operator roles
- Tamper-evident access logs
- Annual vulnerability assessments
- Breach notification within 72 hours (GDPR Art. 33)
8. Cookies
We use cookies/local storage only for essential session management, security, and user preferences. We do not use third-party advertising trackers.
9. Children
10. Changes
We will notify you of material changes at least 7 days in advance (30 days for changes adverse to users) via this page, an in-app notice, and email.
11. Complaints
For privacy complaints, contact us first. Korean users may also contact KISA (privacy.kisa.or.kr / 118). EU users have the right to lodge a complaint with their national supervisory authority.