Privacy Policy
DroFi (the "Company") takes your privacy seriously and complies with applicable laws, including the Personal Information Protection Act of Korea. The essence of this service is delivering the design context your team writes to the AI you choose — and we disclose that data flow transparently below. In case of any discrepancy, the Korean version of this policy prevails.
1. What we collect and how
(1) On sign-up and login: your email address; when using social login (Google, Kakao, etc.), the email, name (nickname) and profile identifier passed by that provider. (2) Collected automatically during use: access logs (IP, timestamps), browser and device information, and service usage records. We use browser storage (localStorage) to keep you signed in. (3) Content you enter or upload (blocks, memos, documents, etc.) is stored to provide the service. (4) If paid billing is introduced, the items and methods of collecting payment information will be announced separately through a revision of this policy before it takes effect.
2. Why we process it
Member identification, authentication and account management; providing the service (storing and structuring your content and delivering context); responding to inquiries; keeping the service secure (preventing abuse); and — only with your separate opt-in consent — using training data to improve AI suggestion quality (Section 5).
3. Delivery of your content to external AI, and cross-border transfer
(1) Digest and export context is transmitted to the external AI providers you personally choose to connect (Anthropic, OpenAI, Google, etc.). Where your data flows is determined by your connection choices, and each provider's own privacy policy applies to their processing. (2) When you use server-provided AI features (automatic suggestions, extraction, etc.), the context needed for processing is transmitted to Anthropic PBC (United States), the Company's processing subcontractor — items transferred: the portion of your design context required for the feature; method: encrypted transmission at the time of use; retention: destroyed after processing in accordance with that provider's policy. (3) Blocks you have marked as sensitive or excluded from context, and documents you have marked as no-export, are excluded from these transmissions.
4. Protection of secrets
When blocks, memos or fields are saved, we detect and block or warn on credential patterns (API keys, tokens, private keys) and personal-identifier patterns (such as resident registration numbers), and we redact tokens and context bodies in server logs. These are supplementary measures and their completeness is not guaranteed; the responsibility not to enter secrets or sensitive personal data rests with the user (Terms, Article 2).
5. Use of training data (opt-in)
Only if you opt in at sign-up or in settings, we use the following to improve AI suggestion quality (better suggestions and recommendations): your verdicts on AI suggestions (approve, edit, reject), the difference between the AI's original suggestion and your final version, and related execution metadata (model used, token counts, etc.). Account identifiers are pseudonymized with one-way encryption (HMAC), secret and personal-data patterns are filtered before recording, and training data is kept in storage separate from your team's design data. Declining has no effect on your use of the service, and only data from consenting users is recorded. You can withdraw consent at any time in settings or by email; collection stops immediately upon withdrawal.
6. Retention and destruction
(1) When you delete your account, your personal information is retained for 30 days to allow recovery from accidental deletion, then destroyed without delay. You can export your data from account settings before leaving. (2) Information that must be preserved under applicable law is kept for the legally required period: access logs (Protection of Communications Secrets Act, 3 months), consumer complaint and dispute records (E-Commerce Act, 3 years), and the like. (3) Electronic files are destroyed by irreversible means.
7. Your rights
You may request access to, correction or deletion of, or suspension of processing of your personal information at any time. You can export your data and delete your account directly from account settings; other requests sent to the contact below are handled without delay. Children under 14 may not sign up for the service.
8. Security measures
Every object access is checked against project scope and enforced with database row-level security (RLS) to block cross-tenant access. Access tokens are bound to a project and default to read-only. Actions that move data outward — context exports, token use — are recorded in an audit log.
9. On-premises / self-hosting
For organizations handling regulated or confidential data, we offer on-premises/self-hosted configurations under a no-lock-in principle, so your organization directly controls any outbound data movement.
10. Privacy officer and contact
Privacy officer: the CEO · Contact: hello@drofi.ai. In Korea, privacy complaints may also be directed to the Personal Information Dispute Mediation Committee (1833-6972) or the Privacy Incident Report Center (privacy.kisa.or.kr, 118).
11. Changes to this policy
Changes will be announced in the service or by email at least 7 days before taking effect (30 days for changes unfavorable to users).