이전 버전입니다. 현재 개인정보처리방침 보기
코스모스팜 소프트웨어는 조립스페이스 서비스를 제공하기 위해 필요한 최소한의 개인정보를 처리하며, 개인정보 보호 관련 법령을 준수합니다.
1. 처리하는 개인정보 항목
| 구분 | 항목 | 수집 방법 |
|---|---|---|
| 회원가입 | 이름, 이메일, 휴대폰 국가번호, 휴대폰 번호, 이용약관 동의 일시, 개인정보처리방침 동의 일시 | 회원 입력 |
| 인증과 보안 | 이메일, 비밀번호 해시와 솔트, 2단계 인증 링크 발급·검증 기록, 로그인 일시, IP 주소, 브라우저 정보, 접속 위치 추정 정보, 세션 식별자, 리프레시 기록 | 서비스 이용 과정에서 자동 생성 |
| 프로젝트 운영 | 프로젝트 이름과 슬러그, 프로젝트 번호, 배포 기록, 서버 상태, 사용량, 소유자 및 멤버 정보, API 토큰 식별 정보, MCP/CLI 연결 기록 | 회원 입력 및 서비스 이용 과정에서 생성 |
| 커뮤니티와 스터디 | 게시글, 댓글, 스터디 제목과 설명, 참여 정보, 작성자 표시명 | 회원 입력 |
| 고객지원 | 문의 내용, 답변 내용, 첨부 자료, 처리 이력 | 회원 문의 및 상담 과정 |
| 결제 | 결제수단 식별 정보, 결제 승인·취소·청구 기록, 프로젝트 소유 계정 정보 | 결제대행사 및 서비스 이용 과정 |
회사는 신용카드 번호 전체, CVC, 카드 비밀번호를 직접 저장하지 않습니다. 결제 처리는 결제대행사를 통해 처리될 수 있습니다.
2. 개인정보 처리 목적
- 회원 식별, 가입 의사 확인, 비밀번호 로그인, 2단계 인증, 세션 유지, 계정 보안
- 프로젝트 생성, 서버 배포, DB·스토리지 연결, MCP/CLI/API 연결, 사용량 확인
- 요금과 결제 조건 관리, 유료 기능 제공, 결제, 정산, 미납 관리
- 커뮤니티와 스터디 운영, 부정 이용 방지, 신고 처리
- 장애 대응, 보안 사고 탐지, 토큰 유출 대응, 서비스 품질 개선
- 공지, 약관 변경 안내, 로그인 알림, 새로운 위치에서 로그인한 경우 보안 알림 발송
- 법령상 의무 이행, 분쟁 대응, 기록 보존
3. 보유 및 이용 기간
회원정보는 회원 탈퇴 시 지체 없이 삭제하거나 복구할 수 없는 방식으로 익명화합니다. 프로젝트, 웹서버, DB, 스토리지, MCP/CLI/API 토큰도 탈퇴 또는 프로젝트 삭제 시 삭제 또는 폐기됩니다. 결제, 정산, 분쟁 대응에 필요한 최소 프로젝트 식별 스냅샷과 사용량 집계는 관련 법령과 정산 목적에 필요한 기간 동안 별도로 보관될 수 있습니다.
다만 다음 정보는 법령상 의무 이행, 분쟁 대응, 부정 이용 방지를 위해 필요한 기간 동안 보관할 수 있습니다.
- 계약 또는 청약철회 등에 관한 기록: 5년
- 대금결제 및 재화 등의 공급에 관한 기록: 5년
- 소비자 불만 또는 분쟁처리에 관한 기록: 3년
- 접속 로그 등 통신사실확인자료: 관련 법령이 정한 기간
- 부정 가입, 악성 프로젝트, 보안 사고 대응 기록: 사고 대응과 재발 방지를 위해 필요한 기간
4. 개인정보의 제3자 제공
회사는 원칙적으로 회원의 개인정보를 제3자에게 판매하거나 임의로 제공하지 않습니다. 다만 회원의 동의가 있거나 법령상 의무가 있는 경우, 수사기관·법원·감독기관의 적법한 요청이 있는 경우, 결제·분쟁 처리에 필요한 경우에는 필요한 범위에서 제공할 수 있습니다.
5. 개인정보 처리위탁과 국외 이전
회사는 안정적인 서비스 제공과 향후 기능 확장을 위해 아래와 같이 개인정보 처리를 위탁하거나 국외 인프라에서 처리할 수 있습니다. 실제 이용하는 수탁자와 업무 범위는 서비스 기능, 회원이 선택한 연동, 운영 환경에 따라 달라질 수 있습니다.
| 수탁자 | 업무 | 이전 또는 처리 국가 | 보유 기간 |
|---|---|---|---|
| PostHog, Inc. | 서비스 이용 분석 및 제품 개선 | 미국 | 서비스 이용 목적 달성 또는 적용되는 보관 정책에 따른 기간 |
| Cloudflare, Inc. | 서버, DB, 스토리지, 로그, 분석, 보안, 백업 등 클라우드 인프라 운영 | 미국 등 Cloudflare 글로벌 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| Google Workspace | 업무용 이메일, 고객 문의 접수, 문서 관리, 내부 협업 | 미국 등 Google 글로벌 인프라 소재 국가 | 회원 탈퇴, 문의 처리 완료 또는 법령상 보관 기간까지 |
| Google Cloud Platform | 서버, DB, 스토리지, 로그, 분석, 보안, 백업 등 클라우드 인프라 운영 | 미국 등 Google 글로벌 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| Amazon Web Services, Inc. | 서버, DB, 스토리지, 로그, 분석, 보안, 백업 등 클라우드 인프라 운영 | 미국 등 AWS 글로벌 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| Oracle Cloud Infrastructure | 서버, DB, 스토리지, 로그, 분석, 보안, 백업 등 클라우드 인프라 운영 | 미국 등 Oracle 글로벌 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| 네이버클라우드 주식회사 | 서버, DB, 스토리지, 로그, 분석, 보안, 백업 등 클라우드 인프라 운영 | 대한민국 등 NAVER Cloud 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| Resend, Inc. | 인증 링크, 보안 알림, 서비스 공지, 거래성 이메일 발송 | 미국 등 Resend 및 하위 처리자 인프라 소재 국가 | 발송 및 기록 보존 목적 달성 시까지 |
| 삼정데이타서비스(주) | 인증 링크, 보안 알림, 서비스 공지, 거래성 이메일 발송 | 대한민국 | 발송 및 기록 보존 목적 달성 시까지 |
| PlanetScale, Inc. | 서비스 DB 운영, 프로젝트·계정·사용량 데이터 저장 및 관리 | 미국 등 PlanetScale 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| Neon, Inc. | 서비스 DB 운영, 프로젝트·계정·사용량 데이터 저장 및 관리 | 미국 등 Neon 인프라 소재 국가 | 회원 탈퇴 또는 위탁 목적 달성 시까지 |
| 사이드톡 | AI 상담, 고객 문의 접수, 상담 이력 관리, 프로젝트 연동 상담 기능 제공 | 대한민국 또는 서비스 제공자의 인프라 소재 국가 | 상담 처리 완료, 연동 기능 제공 또는 법령상 보관 기간까지 |
| 결제대행사 | 결제수단 등록, 승인, 취소, 청구, 정산 | 대한민국 또는 결제대행사 인프라 소재 국가 | 법령 및 결제대행사 정책에 따른 기간 |
| 문자·알림톡·AI 상담 등 연동 서비스 | 회원이 선택한 프로젝트 기능 제공 | 각 서비스 제공자의 인프라 소재 국가 | 연동 기능 제공 및 법령상 보관 기간 |
국외 이전은 서비스 제공에 필수적인 클라우드 인프라 사용으로 발생할 수 있으며, 회원은 서비스 이용을 통해 이에 동의합니다. 회사는 수탁자가 개인정보를 안전하게 처리하도록 필요한 범위에서 관리합니다.
6. 쿠키, 세션, 토큰
조립스페이스는 로그인 상태 유지를 위해 보안 쿠키를 사용합니다. 로그인 유지에 체크하지 않으면 브라우저 세션 쿠키를 사용하며, 브라우저를 닫으면 쿠키가 사라질 수 있습니다. 로그인 유지에 체크하면 최대 30일 동안 유지되는 쿠키가 발급될 수 있고, 접속이 계속되는 경우 보안 목적의 갱신 절차가 수행될 수 있습니다.
MCP/CLI/API 토큰은 브라우저 로그인 쿠키와 별도로 관리됩니다. 회원은 프로필에서 토큰과 로그인 기록을 확인하고, 필요하면 토큰 사용 중지, 로그인 강제 로그아웃 또는 재발급을 할 수 있습니다.
7. 이용자의 권리
회원은 언제든지 자신의 개인정보를 열람, 정정, 삭제, 처리정지 요청할 수 있습니다. 프로필 화면에서 이름과 휴대폰 번호를 수정할 수 있으며, 이메일은 로그인 식별자로 사용되므로 직접 변경할 수 없습니다.
회원 탈퇴를 요청하면 개인정보와 프로젝트가 삭제되고 복구할 수 없습니다. 법령상 보관이 필요한 정보는 별도 분리하여 보관한 뒤 보관 기간 종료 시 삭제합니다.
8. 아동의 개인정보
조립스페이스는 만 14세 미만 아동을 대상으로 서비스를 제공하지 않습니다. 만 14세 미만 아동의 가입 또는 개인정보 제공 사실을 확인하면 해당 정보를 삭제하고 계정 이용을 제한할 수 있습니다.
9. 개인정보 보호조치
- 인증수단, 세션, 토큰을 분리하여 관리
- API 토큰 암호화 저장 및 토큰 폐기 기능 운영
- 서비스 접근 권한 제한과 관리자 접근 통제
- HTTPS 통신, 보안 쿠키, SameSite 설정, CSRF 방어
- 로그인 기록, 새로운 위치 로그인 알림, 강제 로그아웃 기능 제공
- 보안 사고 또는 토큰 유출 의심 시 토큰 폐기와 계정 보호 조치
10. 개인정보 보호책임자
개인정보 보호책임자: 채찬
이메일: [email protected]
전화: 070-4791-9449
회원은 개인정보 침해 신고나 상담이 필요한 경우 개인정보보호위원회, 한국인터넷진흥원 개인정보침해신고센터 등 관계 기관에 문의할 수 있습니다.
11. 방침 변경
이 개인정보처리방침은 서비스 변경, 법령 개정, 수탁자 변경, 개인정보 처리 방식 변경에 따라 수정될 수 있습니다. 중요한 변경은 서비스 화면 또는 이메일로 안내합니다.
시행일 2026. 09. 15.
This is a previous version. View the current Privacy Policy
Cosmosfarm Software processes the minimum personal information necessary to provide JoripSpace and complies with applicable privacy laws.
1. Personal Information We Process
| Category | Information | Collection method |
|---|---|---|
| Registration | Name, email address, mobile country code, mobile phone number, and timestamps of agreement to the Terms of Service and Privacy Policy | Provided by the Member |
| Authentication and security | Email address, password hash and salt, two-factor authentication link issuance and verification records, sign-in time, IP address, browser information, estimated access location, session identifier, and refresh records | Generated automatically while using the Service |
| Project operations | Project name and slug, project number, deployment records, server status, usage, owner and member information, API-token identifiers, and MCP/CLI connection records | Provided by the Member and generated while using the Service |
| Community and study groups | Posts, comments, study-group title and description, participation information, and author display name | Provided by the Member |
| Customer support | Inquiry and response content, attachments, and handling history | Collected during Member inquiries and support |
| Payments | Payment-method identifiers, authorization, cancellation and billing records, and information about the account that owns the project | Provided by payment processors and generated while using the Service |
The Company does not directly store full credit-card numbers, CVCs, or card passwords. Payments may be processed through a payment processor.
2. Purposes of Processing
- Identifying Members, confirming intent to register, password sign-in, two-factor authentication, session maintenance, and account security
- Creating projects, deploying servers, connecting databases and storage, MCP/CLI/API connectivity, and displaying usage
- Managing fees and payment conditions, providing paid features, payments, settlement, and overdue amounts
- Operating the community and study groups, preventing misuse, and handling reports
- Incident response, security-incident detection, token-leak response, and Service-quality improvement
- Notices, notice of amended terms, sign-in alerts, and security alerts for sign-ins from new locations
- Compliance with legal obligations, dispute handling, and record retention
3. Retention and Use Period
Upon account closure, Member information is deleted without undue delay or anonymized in an irreversible manner. Projects, web servers, databases, storage, and MCP/CLI/API tokens are also deleted or revoked when the account or project is deleted. A minimal project-identity snapshot and usage totals needed for payments, settlement, or dispute handling may be retained separately for the period required by applicable law and settlement purposes.
The following information may nevertheless be retained for the period necessary to comply with law, handle disputes, and prevent misuse:
- Records of contracts or withdrawal from purchases: 5 years
- Records of payment and supply of goods or services: 5 years
- Records of consumer complaints or dispute resolution: 3 years
- Connection logs and other communications-confirmation data: the period prescribed by applicable law
- Records concerning fraudulent registration, malicious projects, and security-incident response: the period necessary for incident response and prevention of recurrence
4. Provision to Third Parties
As a rule, the Company does not sell or arbitrarily provide Members' personal information to third parties. It may provide information to the extent necessary with the Member's consent, to comply with law, in response to a lawful request from an investigative agency, court, or supervisory authority, or for payment and dispute handling.
5. Processing Contractors and International Transfers
To provide a stable Service and support future expansion, the Company may entrust personal-information processing to the following providers or process it using infrastructure outside Korea. The providers and scope actually used may vary by Service feature, integrations selected by the Member, and operating environment.
| Provider | Purpose | Transfer or processing location | Retention period |
|---|---|---|---|
| PostHog, Inc. | Service usage analytics and product improvement | United States | For the period required for the service purpose or under the applicable retention policy |
| Cloudflare, Inc. | Operation of cloud infrastructure including servers, databases, storage, logs, analytics, security, and backups | United States and other countries where Cloudflare operates global infrastructure | Until account closure or completion of the entrusted purpose |
| Google Workspace | Business email, customer inquiries, document management, and internal collaboration | United States and other countries where Google operates global infrastructure | Until account closure, completion of the inquiry, or expiry of the statutory retention period |
| Google Cloud Platform | Operation of cloud infrastructure including servers, databases, storage, logs, analytics, security, and backups | United States and other countries where Google operates global infrastructure | Until account closure or completion of the entrusted purpose |
| Amazon Web Services, Inc. | Operation of cloud infrastructure including servers, databases, storage, logs, analytics, security, and backups | United States and other countries where AWS operates global infrastructure | Until account closure or completion of the entrusted purpose |
| Oracle Cloud Infrastructure | Operation of cloud infrastructure including servers, databases, storage, logs, analytics, security, and backups | United States and other countries where Oracle operates global infrastructure | Until account closure or completion of the entrusted purpose |
| NAVER Cloud Corp. | Operation of cloud infrastructure including servers, databases, storage, logs, analytics, security, and backups | Republic of Korea and other countries where NAVER Cloud operates infrastructure | Until account closure or completion of the entrusted purpose |
| Resend, Inc. | Sending authentication links, security alerts, Service notices, and transactional email | United States and other countries where Resend and its subprocessors operate infrastructure | Until completion of delivery and record-retention purposes |
| Samjung Data Service Co., Ltd. | Sending authentication links, security alerts, Service notices, and transactional email | Republic of Korea | Until completion of delivery and record-retention purposes |
| PlanetScale, Inc. | Operating Service databases and storing and managing project, account, and usage data | United States and other countries where PlanetScale operates infrastructure | Until account closure or completion of the entrusted purpose |
| Neon, Inc. | Operating Service databases and storing and managing project, account, and usage data | United States and other countries where Neon operates infrastructure | Until account closure or completion of the entrusted purpose |
| Sidetalk | AI support, customer inquiries, support-history management, and project-integrated support features | Republic of Korea or countries where the provider operates infrastructure | Until support is complete, the integration has been provided, or the statutory retention period expires |
| Payment processors | Payment-method registration, authorization, cancellation, billing, and settlement | Republic of Korea or countries where the payment processor operates infrastructure | As required by law and the payment processor's policy |
| Integrated SMS, AlimTalk, and AI-support services | Providing project features selected by the Member | Countries where each provider operates infrastructure | For the period needed to provide the integration and comply with law |
International transfers may occur through cloud infrastructure essential to providing the Service. Members consent to these transfers by using the Service. The Company takes appropriate steps to oversee the providers' secure processing of personal information.
6. Cookies, Sessions, and Tokens
JoripSpace uses secure cookies to maintain sign-in status. If “Keep me signed in” is not selected, a browser-session cookie is used and may disappear when the browser is closed. If it is selected, a cookie lasting up to 30 days may be issued, and continued access may trigger renewal procedures for security purposes.
MCP/CLI/API tokens are managed separately from browser sign-in cookies. Members can review tokens and sign-in history from their profile and, when necessary, disable a token, force sign-out, or issue a replacement.
7. Your Rights
Members may request access to, correction or deletion of, or suspension of processing of their personal information at any time. A Member may edit their name and mobile phone number from the profile page. The email address is used as a sign-in identifier and cannot be changed directly.
When a Member requests account closure, personal information and projects are deleted and cannot be recovered. Information required by law is segregated and retained, then deleted when its retention period expires.
8. Children's Personal Information
JoripSpace does not provide the Service to children under 14. If the Company learns that a child under 14 registered or provided personal information, it may delete that information and restrict the account.
9. Security Measures
- Separate management of authentication methods, sessions, and tokens
- Encrypted storage and revocation of API tokens
- Restricted Service access and administrative access controls
- HTTPS communications, secure cookies, SameSite settings, and CSRF protection
- Sign-in history, alerts for sign-ins from new locations, and forced sign-out
- Token revocation and account-protection measures following a security incident or suspected token leak
10. Privacy Officer
Privacy Officer: Chae Chan
Email: [email protected]
Phone: 070-4791-9449
Members who need to report or seek advice about a privacy infringement may contact relevant authorities, including the Personal Information Protection Commission and the Korea Internet & Security Agency's Privacy Infringement Report Center.
11. Changes to this Policy
This Privacy Policy may be amended following changes to the Service, laws, service providers, or personal-information processing practices. Material changes will be announced through the Service or by email.
Effective September 15, 2026
This English version is provided for convenience only. If there is any discrepancy or ambiguity, please refer to the Korean version.